By Lynn Räbsamen, CFA | Advisory Board Member, CFA Institute | Author, Artificial Stupelligence
The Financial Stability Board (FSB) asked the industry what AI is delivering. The industry’s own answer: it still cannot measure it.
Technology moves faster than regulation. That is not new. What is new is the size of what has been built in the gap: frameworks, inventories, champion networks, chief AI officers. All of it scaling ahead of any published figure showing what the AI returned.
The apparatus built to control AI has outgrown the evidence that AI is worth controlling.
12 “Sound Practices” for Responsible AI Adoption
It sits on page 20, in a FSB Consultation about aligning skills to AI strategy. The FSB describes large internationally active financial groups that have set concrete targets to track AI adoption.
Hard benefits like productivity and cost. Softer benefits like staff capacity. Then the concession:
These institutions acknowledge that finding suitable metrics remains challenging, particularly around value realization.
That is not a critic’s claim. It is the regulator recording what the largest banks in the world told it.
The FSB published Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report on 10 June 2026. 12 practices. The first 4 cover organization-wide governance, 5 through 10 cover the AI lifecycle, and 11 and 12 cover cyber and third-party risk.
The document is explicitly non-binding. It states it is not intended to establish an international standard and does not absolve any institution of its local obligations. Comments closed 22 July 2026. All 124 public responses were published on 6 August 2026. A final report is expected later this year as a United States G20 deliverable.
Michelle Bowman, who chairs the FSB’s Standing Committee on Supervisory and Regulatory Cooperation, asked respondents a direct question: does the report strike the right balance on proportionality, given that what suits a G-SIB does not suit a community bank?
She got an answer. It is not the one the drafting suggests she expected.
Who Actually Showed Up
I classified all 124 respondents by what the filing entity is. The rule is mine, but reasonable people could sort a few of these differently.
| Category | Count |
| Regulated financial institutions filing in their own name | 19 |
| AI and technology vendors | 31 |
| Trade associations and industry federations | 30 |
| Private individuals | 17 |
| Nonprofits, standards bodies, academia, law firms | 10 |
| Consultancies and advisory firms | 10 |
| Public authorities and supervisors | 4 |
| Small firms I could not verify | 3 |
The 19 regulated institutions break down as 11 banks and bank holding companies, 3 payment and e-money firms, 3 financial market infrastructures, 1 insurer, and 1 crypto exchange.
Vendors and consultancies filed 41 responses. Regulated financial institutions filed 19.
The people selling AI governance outnumbered the institutions carrying the risk by more than 2 to 1.
UBS, LSEG and JPMorgan each note that their substantive input went through trade associations. The largest institutions did not decline to give evidence. They gave it collectively and unattributed.
Of the 19 regulated institutions filing in their own name, 2 supplied case studies from their own operations. Those 19 are the only responses I read in full. The other 105 came from associations, vendors, consultancies and private individuals, and may well contain case studies of their own. They would just be somebody else’s.
Adoption Is Not Return
UBS, where I spent part of my career, disclosed more than almost anyone in the set, and did so voluntarily. Over 560 live AI use cases and roughly 900 more in development. Nine transformational initiatives known internally as Big Rocks. A Chief AI Officer appointed in 2025. A hub-and-spoke operating model established in 2026, with a central AI office setting standards and divisional heads driving delivery. More than 1,000 AI champions. Regional AI factories. Over 1,000 senior leaders through a leadership program with Oxford. Nearly 90% of financial advisor teams on its STAAT platform. A Group AI Policy updated 1 April 2026, moving from use-case-level risk management to a system-based approach.
Every one of those is an input. Not one is a return.
The One That Is
Now read Wise, a payments firm, in the same consultation. Flagged-account resolution cut from 6 hours to under 5 minutes on average, a 98.6% reduction. AML payment pattern analysis handling time down 12%. Proof-of-address checks 95% automated at 99.4% accuracy. All production AI traffic through a centralized gateway with inputs and outputs logged. Deliberately model-agnostic across frontier providers, to avoid concentration risk at the model layer. And a hard routing rule that sends vulnerable customers straight to human agents, bypassing AI entirely.
The most remarkable sentence is Wise’s observation that removing the human from initial verification improved consumer outcomes, because human review would have kept legitimate customers suspended longer. Some checks are worse for having a person in them.
B3, the Brazilian exchange, clearinghouse, depository and trade repository, supplied 4 case studies including a year-by-year timeline: machine learning in surveillance alerts from 2022, a 2023 pilot transcribing participant phone recordings, supervised models cutting false positives in 2024, structured extraction from unstructured documents, coding assistants.
Its sharpest insight is that agentic AI can strengthen governance itself. Its risk function is building agents to assess risk, including the risk of other AI proposals.
Both firms that answered with their own operational evidence are nonbanks. FSB asked specifically for nonbank case studies. It is a note worth making:
The firms with the least legacy governance produced the most legible evidence.
Governance built for scale seems to cost something in the ability to measure ROI.
Built For Goliath
The FSB says these practices scale down. The small banks that answered say they do not.
Friendship State Bank wrote that the case studies point toward large, international or G-SIB institutions, and found them hard to relate to a smaller bank.
Commencement Bank said the studies are less actionable from an implementation standpoint and do not show how governance structures get established or how controls scale.
Merchants Bancorp produced the sharpest observation in the set: AI risk is now largely a third-party and ecosystem problem, not solely a model development problem. It also named a concrete hole. A workflow using a copilot agent gets approved. The data source later changes. Nobody has defined what triggers reassessment. It also reported vendor unwillingness to share full information and limited visibility into training data.
Community Trust Bancorp answered 6 of the 8 consultation questions with the single word “Yes.” Its one substantive contribution: a team member suggested the report include examples of failures, because you learn what to avoid from where others failed.
The report contains 12 case studies and 12 successes. Zero failures. The only respondent who asked to see one answered most of the questionnaire with “Yes.”
Goliath Is Stuck
Individually, each request is reasonable. Together they are a position.
UBS asks that case studies be framed as illustrative rather than expected, to stop them hardening into de facto supervisory expectation.
Visa asks the FSB to avoid implying that agentic AI is inherently high risk, notes it has used machine learning since 1993, and argues that verifying an agent’s identity and authority may matter as much as governing the model.
Manulife argues meaningful oversight does not always require a human reviewing every output where controls and accountability are properly designed. That is the same argument I made in my post: Singapore Moves First on Agentic AI: whether human oversight survives scale. It also asked the FSB how to run thousands of use cases, which controls can be automated, and when AI overseeing AI is appropriate.
JPMorgan rejects the FSB’s “synthetic employees” framing outright and offers an 8-part agentic governance framework instead, covering attribution, containment, agent identity, zero trust, escalation boundaries, continuous assurance, circuit breakers and named human accountability. Its best line is conceptual: agentic AI may shift risk from bounded model outputs toward execution-time governance.
Meanwhile the South African Reserve Bank asks the FSB to add “synthetic employees” to the glossary. Same consultation, same phrase, opposite direction.
One large-firm ask deserves credit. UBS notes that regulators are themselves expanding AI use, sometimes alongside requests for access to supervised entities’ data and systems, and argues supervisors should follow principles consistent with those applied to firms. That is a fair point and none of the other 19 regulated institutions made it.
The consultation asked what AI is delivering. From the firms best placed to answer, it received a negotiation about wording.
David Might Actually Win
Here is the part the smaller respondents did not realize they were making.
They can run one use case that produces, rather than an enterprise rollout that must be justified across five divisions. Their workflows are small enough to see end to end, which is the precondition for knowing whether anything improved. They carry no governance apparatus whose cost scales with headcount and whose return nobody has published. There is no 1,000-person champion network to fund and no Chief AI Officer to justify.
Their exposure is real and different. It is vendor dependency, exactly as Merchants Bancorp described it. But that is a procurement problem with a procurement answer.
Deutsche Börse supplied it. It asked the FSB to recognize that foundation model providers are not traditional IT outsourcing, because a model update can silently change how a deployed system behaves. It asked for contractual rights to advance notice of model changes and the right to pin model versions. A 200-person bank can put that in a contract next quarter without hiring anyone.
Two further Deutsche Börse points are worth stealing. One: shadow AI is better handled by offering an attractive governed alternative than by prohibition alone. Two: agents break access control, because they query pooled data on someone else’s behalf. And the system cannot see whose. Deutsche Börse says the FSB should treat this as a first-order security problem rather than assume existing controls still work.
Governance Vs. Measurement
No business owner would sign a recommendation that reported the size of the research budget and omitted the return.
That is what most of these filings are. Use case counts, headcount, program names, policy update dates.
Governance has scaled beautifully. Measurement has not moved.
The one fix anyone proposed, publishing what did not work, came from the smallest institution in the room, in a filing that otherwise said “Yes” six times.
The final report lands later this year. The question worth asking before is not whether your institution has an AI policy. It is whether anyone in the building can tell the board what the AI returned.
This article was partially drafted by AI and reviewed by a human.
For more insights about what AI can or cannot do, check out my book “Artificial Stupelligence: The Hilarious Truth About AI“.
Subscribe here to be the first to receive my insights.







