FSB AI Sound Practices: Consultation Closes, Final Report Next

On 6 August 2026 the Financial Stability Board published the public responses to its consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). The FSB AI sound practices were put out for comment on 10 June 2026, the comment window closed on 22 July 2026, and the FSB now says it expects to publish the final report in the coming months. Nothing in that sequence creates a filing obligation, which is exactly why it is easy for reporting teams to file it under “read later”. That would be a mistake for anyone who already carries AI governance, model risk, or third-party dependency expectations under a binding regime.

The consultation creates no direct obligation. The FSB is an international coordinating body whose decisions are not legally binding, and this consultation expressly states that the sound practices are not intended to establish an international standard. The breadth of submissions shows stakeholder engagement, but it does not establish that national authorities will adopt the final practices or use them as a supervisory reference point.

Related reading: EU AI Act compliance for financial institutions.

The dates that anchor this file

  • 10 June 2026: the FSB published Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report, with an accompanying press release.
  • 22 July 2026: deadline for written comments. The window is closed.
  • 6 August 2026: the FSB published the individual public responses received.
  • Final report: the FSB’s 10 June press release states that it will be published in October 2026; the 6 August responses page says it is expected ‘in the coming months’. No specific day in October has been announced, and the FSB has not yet published its overview of responses.

What the FSB AI sound practices actually propose

The consultation report sets out what the FSB describes as a menu of 12 sound practices that financial institutions could apply as they adopt AI. They are aimed at all types of financial institutions, from insurers to market infrastructures, and the FSB groups them around two axes: organisation-wide AI governance, and the management of risks across the stages of the AI lifecycle, from development through deployment and into ongoing use. The FSB notes that it and relevant standard-setting bodies emphasise proportionate, risk-based and technology-neutral approaches to monitoring and addressing AI risks.

The status of the document is the single most important thing to get right. The FSB states that the sound practices are not intended to establish an international standard, to impose a prescriptive approach to responsible AI adoption, or to influence a firm’s decision to adopt any particular AI technology. In plain terms, the practices are a reference menu that a board can choose from and adapt, and a firm does not report against them, certify to them, or submit a return to the FSB. Binding obligations arise under applicable law. The FSB says the draft builds on and is broadly compatible with existing and ongoing work; it does not state that the practices eliminate duplication with each applicable regime.

The sound practices create no direct FSB reporting obligation or sanction. A national supervisor may refer to FSB material or address similar governance issues under its own legal framework, as the CSSF communiqué illustrates, but the consultation does not establish that national supervisors generally will convert the practices into examinable expectations.

Who responded, and why the breadth matters

The published response list is broad. Named respondents include JPMorgan Chase, Credit Agricole, Visa, Mastercard, Deutsche Börse Group, B3, the World Federation of Exchanges, Binance, Wise, techUK, the Institute of International Finance, the Global Financial Markets Association, the American Bankers Association, the Japanese Bankers Association, the Bank Policy Institute with the Institute of International Bankers, Insurance Europe, the Global Federation of Insurance Associations, Better Markets and Finance Watch.

The breadth of respondents demonstrates cross-sector engagement with the consultation. It does not establish what the FSB will conclude or how any authority will apply the final report. The draft itself is addressed to all types of financial institutions, subject to proportionality, so non-bank firms should assess relevance against their activities, risk profile and applicable legal perimeter.

One boundary is worth stating clearly, because it is easy to overclaim. Publishing the responses is not the same as the FSB summarising them. The document history for the consultation lists an “overview of responses” as a separate, still-to-come output, and the individual submissions are published as filed. Until the FSB releases that overview or the final report, any statement about “what the industry concluded” is inference from the raw submissions, and it should be labelled as such.

Frontier and agentic AI: the gap the consultation flagged itself

The consultation asks whether the practices strike an appropriate balance between risks from all forms of AI and risks from emerging, more complex forms such as GenAI and agentic AI. Separately, the FSB press release states that the draft was not developed specifically to address recent frontier-AI risks, although some practices may help. Whether frontier or agentic AI receives stronger treatment in the final report remains unresolved.

The surrounding regulatory calendar explains why. On 7 July 2026 the ESRB published its warning of 25 June 2026 that frontier AI models could strain cyber resilience in the financial system, and later that month the European Supervisory Authorities issued a joint statement on frontier AI models urging financial entities to establish governance structures, review their risk appetite frameworks and prepare timely response plans for AI-enabled threats, anchored in the ICT risk management requirements of the Digital Operational Resilience Act. Our note on the ESRB frontier AI warning and DORA cyber risk reporting traces how that concern connects to incident reporting. Read together, these interventions suggest the FSB will face pressure to say more about agentic and frontier systems, and that firms should not assume the final report keeps the same technology-neutral distance from them.

For a practitioner, the useful takeaway here is a documentation gap more than a new control to build: governance drafted only for today’s supervised AI use cases may read as incomplete once frontier and agentic tooling reaches production, and the FSB is signalling which way the wind is blowing.

Why non-binding still creates work: the regimes it threads into

The FSB sound practices sit alongside binding regimes with separate scopes and application dates. Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, applies generally from 2 August 2026, but Chapter III, Sections 1 to 3, other than Article 6(5), apply to Annex III high-risk systems from 2 December 2027. Annex III covers AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, excluding systems used to detect financial fraud; Article 6(3) provides that an Annex III system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making, and one of four specified conditions is met: it performs a narrow procedural task; improves the result of a previously completed human activity; detects decision-making patterns or deviations without replacing or influencing the prior human assessment without proper human review; or performs a preparatory task to an Annex III assessment. Annex III systems that perform profiling of natural persons are always high-risk. For high-risk AI systems used by financial institutions in direct connection with providing regulated financial services, the relevant national financial supervisor is generally the market-surveillance authority; national authorities supervising SSM credit institutions should report relevant information to the ECB. DORA has applied since 17 January 2025 to in-scope financial entities and covers ICT risk, major ICT-related incident reporting and qualifying ICT third-party arrangements. Firms should map the FSB themes separately to the controls required under each applicable regime.

The CSSF is one confirmed example of a national supervisor referring supervised entities to the FSB consultation. On 7 July 2026 it invited supervised entities to review the ESRB warning and FSB consultation and stated that, in line with DORA’s ICT-risk-management requirements or other relevant national regulations, it expects all management-body members to establish governance structures supporting effective management of frontier-AI-related risk. Our summary of the CSSF AI communique and DORA ICT risk management sets out that expectation in full. This is a Luxembourg example: the CSSF linked its expectation to DORA or other relevant national regulations while inviting entities to review the FSB and ESRB material. It does not establish a general conversion pattern across national supervisors.

The FSB paper adds no return to the reporting calendar. Whether similar governance topics are already examinable depends on the entity, activity and applicable legal and supervisory perimeter; the consultation does not itself standardise those requirements.

The three risk themes worth mapping now

Whatever the final wording, three themes run through the FSB’s AI work and the supervisory material around it, and they are the sensible places to concentrate documentation before the final report lands.

The first is governance and accountability. The organisation-wide AI governance axis of the FSB sound practices addresses board and senior-management oversight. The CSSF, ESAs and ECB separately address management-body governance for frontier-AI-related cyber or ICT risk within their respective scopes: CSSF-supervised entities, financial entities within DORA’s scope and ECB significant institutions. Firms should document model approval, deployment and risk-appetite responsibilities against each framework that applies to them.

The second is the AI lifecycle and model risk. The FSB organises its practices around development, deployment and ongoing use, which maps closely to how supervisors think about model validation and monitoring. Where AI models influence prudential or regulatory outputs, the existing model risk framework is the natural home for them. Our note on AI model risk in prudential reporting works through that boundary.

The third is third-party dependency and cyber resilience. The G7 Cyber Expert Group notes that the financial-sector impact of an incident at a widely used AI provider depends on the nature and criticality of the AI services used and their substitutability. Under DORA, an AI-related arrangement belongs in the register of information only where it is a contractual arrangement for an ICT service provided by an ICT third-party service provider. Mandatory external reporting applies only to ICT-related incidents classified as major under Article 18 and Commission Delegated Regulation (EU) 2024/1772; notification of significant cyber threats is voluntary.

How the same conversation is playing out beyond Europe

The FSB consultation sits alongside other official work. IOSCO’s public-reports index lists a final Supervisory Toolkit for AI Use in Capital Markets dated 25 May 2026; the G7 Cyber Expert Group’s September 2025 statement expressly does not set guidance or regulatory expectations; MAS and ABS announced a cyber and technology-resilience taskforce on 28 July 2026; and Japan’s FSA describes its March 2026 AI Discussion Paper version 1.1 as preliminary and as a basis for ongoing dialogue and future policy. These outputs have separate mandates and statuses. Our coverage of the MAS and ABS AI cyber and technology resilience taskforce is one example of a domestic supervisor moving in parallel with the international bodies.

For a group operating across jurisdictions, the FSB text can provide a common comparison framework. The consultation seeks coordination, cooperation and information-sharing, but it does not establish that IOSCO, the ESAs, the ECB or national supervisors will adopt identical requirements. Firms should compare the final report with each applicable local framework rather than assume convergence.

What the final report is likely to sharpen, and what it will not

My working assumption, based on the FSB’s own consultation questions and the parallel ESRB and ESA interventions, is that the final report keeps its non-binding character and its lifecycle structure while sharpening two things: the treatment of frontier and agentic AI, and the language on third-party concentration and cyber resilience. Those are the areas where the FSB flagged uncertainty and where other bodies have since raised the temperature.

The consultation states that the sound practices are not intended to establish an international standard or prescriptive approach and creates no FSB reporting template. The final report has not yet been published, so it is not established that supervisors will use it as a benchmark. Firms may use the consultation as a voluntary gap-analysis aid while continuing to assess compliance against applicable law and supervisory requirements.

Frequently Asked Questions

Does the FSB consultation create a new reporting obligation for financial institutions?

No. The FSB sound practices are non-binding and the FSB states they are not intended to establish an international standard or a prescriptive approach. There is no return to file with the FSB. Any reporting obligation touching AI arises from binding regimes such as the EU AI Act or DORA. The FSB paper itself adds none.

When will the FSB publish the final report?

The FSB’s 10 June press release says the final report will be published in October 2026. The 6 August responses page says it is expected in the coming months. No specific day in October is stated, and the FSB has not yet published its overview of responses.

Are the individual consultation responses public, and can I rely on a summary of them?

The individual responses were published on 6 August 2026 and can be read as filed. The FSB has not yet published an overview of responses, so any characterisation of an industry-wide position is an inference drawn from the raw submissions, and it is not an FSB conclusion. Treat it accordingly until the overview or final report appears.

Do the sound practices apply only to banks?

No. The FSB frames the practices for all types of financial institutions. The response list includes respondents from banking, insurance, market infrastructure, payments and investment-sector associations, among others; separately, the consultation itself states that the sound practices are intended for all types of financial institutions, subject to proportionality.

How do the FSB practices interact with the EU AI Act and DORA?

They operate at different levels. The FSB practices are non-binding. The AI Act is binding, but the Chapter III, Sections 1 to 3 requirements, other than Article 6(5), for Annex III high-risk systems apply from 2 December 2027. DORA already applies to in-scope financial entities and covers ICT-risk management, mandatory reporting of ICT-related incidents classified as major, voluntary notification of significant cyber threats and contractual arrangements for ICT services provided by ICT third-party service providers. Mapping FSB themes to those controls may support a gap analysis, but does not itself demonstrate compliance with either Regulation.

What is the position on frontier and agentic AI?

The FSB press release states that the practices were not developed specifically for recent frontier-AI risks, although some may help. Consultation Questions 3 and 4 ask about GenAI, agentic AI and newer types of AI. The July 2026 ESRB and ESA interventions are relevant context, but the FSB has not announced that it will reinforce this area in the final report.

If a firm adopts the sound practices, does that satisfy its supervisor?

Adoption is not a safe harbour. Supervisors apply their own legal frameworks, and the sound practices are a reference rather than a compliance test. A firm demonstrates compliance against the applicable binding legal and supervisory framework. The FSB themes may be used as a voluntary organising structure, but they do not replace applicable Union law, national law or supervisory requirements.

Key Takeaways

  • The FSB published the public responses to its AI sound practices consultation on 6 August 2026; the comment window closed on 22 July 2026 and the final report is expected in October 2026.
  • The consultation sets out a menu of 12 sound practices for all types of financial institutions, grouped around organisation-wide AI governance and the AI lifecycle.
  • The practices are non-binding: the FSB states they are not intended to establish an international standard or a prescriptive approach, and firms do not report against them.
  • The FSB has not yet published its overview of responses, so treat any “industry consensus” as inference from raw submissions, not an FSB finding.
  • The draft asks specifically about GenAI and agentic AI, while the FSB press release says the practices were not developed specifically for recent frontier-AI risks. The ESRB published its warning of 25 June on 7 July 2026, and the ESAs issued their statement on 31 July 2026; whether the FSB strengthens these areas remains unresolved.
  • Binding obligations must be assessed instrument by instrument: DORA already applies to in-scope financial entities, while the AI Act’s Chapter III, Sections 1 to 3 requirements, other than Article 6(5), for Annex III high-risk systems apply from 2 December 2027 under Regulation (EU) 2026/1744.
  • Concentrate documentation on three themes before the final report: board-level accountability, AI lifecycle and model risk, and third-party dependency and cyber resilience.
  • Adopting the sound practices is not a supervisory safe harbour; compliance is demonstrated against the applicable binding regime, with the FSB themes as structure.

Sources and References

Watch the final report, not the calendar

There is no template to build and no deadline to diarise from the FSB paper itself. The action it calls for is preparatory: use the consultation structure to check that board-level AI accountability, model lifecycle controls, and third-party dependency and incident pathways are documented and examinable under the regimes that already apply to your firm. When the FSB publishes the final report in October 2026, firms should compare it with the consultation before relying on existing documentation, with particular attention to any changes concerning frontier or agentic AI.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts