Global Regulator & Central Bank News Roundup
Edition 272026Week of July 6
Global developments
The Financial Action Task Force has mapped at least 84 public-private partnerships and found that mature, legally grounded models can improve financial crime detection, suspicious transaction reporting, investigations and asset recovery. Effective arrangements require clear legal gateways, reciprocal information sharing, secure technology and data protection safeguards, while cross-border operational sharing remains constrained by legal, technical and trust barriers. FATF encourages jurisdictions to develop partnerships progressively and test privacy-enhancing technologies without treating them as a substitute for governance or legal authority.
The Financial Action Task Force has published a global review of public-private partnerships and data protection arrangements for combating money laundering, terrorist financing and proliferation financing. It identifies at least 84 partnerships operating at different stages of maturity and finds that well-designed operational models can accelerate the exchange of actionable intelligence, improve suspicious transaction reporting and investigations, and support criminal disruption and asset recovery. The report does not prescribe a single model, noting that partnerships vary according to their legal framework, purpose, governance, membership and the information shared. The most effective arrangements combine a clear legal basis, reciprocal public-private information flows, defined governance and accountability, and secure, auditable technology aligned with data protection requirements. Strategic sharing of typologies, red flags and emerging risks is the most common starting point, while more than half of jurisdictions report deeper operational exchanges involving case-specific, transactional or customer due diligence information. Cross-border operational sharing remains uneven because of legal gateways, data-transfer requirements, interoperability constraints and limited trust, while poorly governed sharing can contribute to blanket de-risking, financial exclusion and risks to due process and fundamental rights. FATF encourages jurisdictions to begin with pilot projects or informal strategic exchanges, then expand membership, scope and operational capabilities as safeguards mature. It also advocates stronger engagement between anti-money laundering and data protection authorities, clearer rules covering purpose limitation, retention, access and deletion, and further testing of privacy-enhancing technologies, while stressing that technology does not replace a lawful basis and robust governance.
INTERPOL said Operation First Light 2026, spanning 97 countries and territories, led to 5,811 arrests and the interception of USD 293 million linked to social engineering scams and related money laundering. Authorities identified more than 142,000 victims, blocked 31,014 bank accounts and solved 23,715 cases. The operation also used raids, account freezes and INTERPOL’s I-GRIP payment-blocking tool to disrupt both fiat and virtual-asset flows.
INTERPOL has published the results of Operation First Light 2026, a global anti-fraud operation targeting social engineering scams and related money laundering between 15 January 2026 and 30 April 2026. The operation involved 97 countries and territories and resulted in 5,811 arrests, the interception of USD 293 million in illicit assets and the identification of more than 142,000 victims worldwide. The campaign covered scams including business email compromise, sextortion, romance, impersonation and investment fraud. After an initial intelligence-sharing phase, participating authorities carried out more than three months of operational activity against high-value targets. Measures included raids, blocking or freezing bank accounts and virtual wallets, requests for INTERPOL Notices and Diffusions, and use of INTERPOL’s Global Rapid Intervention of Payments stop-payment mechanism to halt illicit fiat and virtual-asset flows. Across the operation, authorities analyzed 152,808 cases, solved 23,715 cases, identified 15,606 suspects, blocked 31,014 bank accounts and issued 99 Notices and Diffusions. Case examples highlighted the range of conduct targeted. In Eswatini, police arrested 82 people and dismantled a network linked to illegal online gambling, money laundering and impersonation scams, prompting deployment of an INTERPOL Operational Support Team to help analyze seized digital evidence. In Thailand, police uncovered a romance-scam laundering scheme involving cross-chain cryptocurrency swaps, with one suspect’s wallet processing more than USD 122.5 million in 10 months, while authorities in Singapore and Oman used I-GRIP to block a USD 6.6 million transfer tied to a business email compromise case.
The Bank for International Settlements Innovation Hub has developed a proof-of-concept dashboard that links granular firm and shipment data with macroeconomic sources to identify supply chain bottlenecks, concentration and shock-transmission risks. Built on more than 15 billion historical observations, it provides standardised metrics across firms, ports, industries and economies. The modular framework is designed for adaptation by central banks and other public institutions.
The Bank for International Settlements Innovation Hub has published Project Insight, a proof-of-concept dashboard developed with the Hong Kong Monetary Authority, the Organisation for Economic Co-operation and Development and DIW Berlin to strengthen monitoring of global value chains. It combines firm-level shipment, supply chain, ownership and entity data with public trade and macroeconomic sources, enabling policymakers to trace dependencies from individual firms and ports to industries and economies and assess bottlenecks, concentration and shock-transmission channels relevant to inflation and financial stability. The underlying 2018-24 data comprise more than 15 billion observations, including over 300 million seaborne packages and shipments between more than one million entities and roughly half of global containerised maritime trade by volume. Standardised indicators cover shipment trends, port congestion, counterparty and product concentration, and the network centrality of key firms, ports, industries and economies. Filters by time, product, economy and trade direction allow users to move from aggregate patterns to specific exposures and relationships. The project is a foundation rather than a comprehensive live monitoring system. Its modular data architecture, cleaning methods and reusable dashboard components are intended to help central banks and other public institutions incorporate their own granular supply chain data into macro-financial analysis.
The Bank for International Settlements’ Financial Stability Institute finds that Basel III’s common minima mask material differences in the capital requirements applied to 29 G-SIBs across seven jurisdictions. In 2025, average Common Equity Tier 1 requirements ranged from about 8% to 11% of risk-weighted assets and total requirements from nearly 12% to 17%, alongside substantial differences in risk measurement and leverage frameworks. Meaningful comparisons must therefore assess capital ratios, risk-weighted assets, leverage constraints and supervisory expectations together.
The Bank for International Settlements’ Financial Stability Institute has published a cross-jurisdictional analysis of risk-based and leverage ratio capital requirements for 29 global systemically important banks across seven jurisdictions from 2014 to 2025. The banks account for about 70% of global banking system assets. Using a harmonised data set compiled from public disclosures, the analysis finds that Basel III’s common minimum standards coexist with materially different national capital stacks. In 2025, these stacks contained four to eight components, with average Common Equity Tier 1 requirements ranging from about 8% to 11% of risk-weighted assets and total capital requirements ranging from nearly 12% to 17%. Headline capital ratios are not directly comparable because jurisdictions also differ in how they calculate risk-weighted assets. Average risk-weighted asset density was around 30% for G-SIBs in the European banking union, Canada, Japan, Switzerland and the United Kingdom, compared with about 45% in the United States and 55% in China. The differences reflect both banks’ underlying portfolios and national constraints on internal models. Applying more comparable risk-measurement approaches reduces the dispersion, while the data suggest that some authorities may partly offset less conservative risk measurement with higher capital ratio requirements. Actual capital ratios are also more homogeneous than formal requirements, reflecting supervisory expectations, distribution thresholds, peer benchmarking and banks’ own management buffers. Leverage ratio frameworks show similar variation in their minima, buffers, eligible capital and exposure measures, with average end-2025 requirements ranging from 3.5% to 5%. The analysis concludes that cross-border comparisons should jointly assess capital ratio requirements, risk-weighted asset methodologies, binding and non-binding buffers, leverage constraints and supervisory expectations. National reforms and differing timelines for the Basel III output floor may change these comparisons, while Basel Committee work to improve access to supervisory data could increase transparency.
The Organisation for Economic Co-operation and Development finds that AI foundation-model markets have become more dynamic, with more providers, better performance and a nearly 80% fall in quality-adjusted text-model prices from January 2024 to April 2026. It nevertheless warns that concentrated control of compute, data and skills, combined with vertical integration and first-mover advantages, could entrench a small number of firms across the AI value chain. The OECD recommends sustained monitoring, scrutiny of acquisitions and partnerships, and stronger domestic and cross-border regulatory coordination.
The Organisation for Economic Co-operation and Development (OECD) has published a policy brief assessing competition in artificial intelligence markets. It finds a mixed picture: foundation-model markets have become more dynamic as performance improved, prices fell and specialised providers challenged technology incumbents, but concentration in critical inputs, first-mover advantages and vertical integration create persistent competition risks across the AI value chain that are expected to intensify. Between January 2024 and April 2026, the number of developers focused on language models for cognitive tasks rose from 9 to 47, active text-to-text models increased from 22 to 453, and the OECD's quality-adjusted price index for those models fell by nearly 80%. However, AI capacity and investment remain concentrated, particularly in hardware and cloud infrastructure. The three largest cloud providers held 74% of the global cloud market in 2023, while NVIDIA accounted for 90% of the GPU market, creating risks of preferential access, bundling, foreclosure and higher switching costs as leading firms expand across multiple layers of the value chain. The brief also cautions that lower per-token prices may not reduce the effective cost of AI use because agentic systems consume substantially more tokens. The OECD recommends sustained market monitoring, easier access to data, compute and skills, fewer investment barriers for small and medium-sized enterprises, greater transparency and interoperability, and closer scrutiny of acquisitions and partnerships that could lock in users or exclude rivals. It also calls for cross-border cooperation among competition authorities and coordination with energy and digital regulators to address bottlenecks across the value chain.
The Group of Thirty announced that Pablo Hernández de Cos, General Manager of the Bank for International Settlements and former Governor of the Bank of Spain, has joined its membership. Hernández de Cos previously served on the European Central Bank Governing Council and chaired the Basel Committee on Banking Supervision from 2019 to 2024.
The Group of Thirty announced that Pablo Hernández de Cos, General Manager of the Bank for International Settlements and former Governor of the Bank of Spain, has joined its membership. Hernández de Cos brings significant experience in macroeconomics, fiscal and monetary policy, financial stability, international banking regulation and European monetary governance. He served as Governor of the Bank of Spain and a member of the European Central Bank Governing Council from 2018 to 2024. He also chaired the Basel Committee on Banking Supervision from 2019 to 2024.
Active global consultations
The Financial Stability Board is seeking feedback on a proposed, non-binding set of 12 proportionate sound practices to support responsible artificial intelligence adoption by all types of financial institutions while enabling sustained value creation and limiting risks to financial stability. The consultation responds to the accelerating use of traditional AI, generative AI and agentic AI across financial services, and to the risks and vulnerabilities that may arise as adoption scales. The practices are organized around two areas: (1) Practices addressing organization-wide governance including board and senior management oversight, alignment with business strategy and risk appetite, clear accountability, incorporation of AI risks into risk management frameworks, effective documentation and organizational adaptability as AI evolves. (2) Practices across the AI lifecycle, covering how financial institutions assess, select, deploy, monitor and retire AI models and systems. These practices focus on materiality and risk assessment, data governance, explainability, transparency, performance management and human oversight. They also address AI-related cyber and ICT risks and third-party AI risks, including those linked to performance, data quality, supply chains, concentration and business continuity.
The Financial Stability Board is seeking feedback on a proposed, non-binding set of 12 proportionate sound practices to support responsible artificial intelligence adoption by all types of financial institutions while enabling sustained value creation and limiting risks to financial stability. The consultation responds to the accelerating use of traditional AI, generative AI and agentic AI across financial services, and to the risks and vulnerabilities that may arise as adoption scales. The practices are organized around two areas: (1) Practices addressing organization-wide governance including board and senior management oversight, alignment with business strategy and risk appetite, clear accountability, incorporation of AI risks into risk management frameworks, effective documentation and organizational adaptability as AI evolves. (2) Practices across the AI lifecycle, covering how financial institutions assess, select, deploy, monitor and retire AI models and systems. These practices focus on materiality and risk assessment, data governance, explainability, transparency, performance management and human oversight. They also address AI-related cyber and ICT risks and third-party AI risks, including those linked to performance, data quality, supply chains, concentration and business continuity.
The Board of the International Organization of Securities Commissions is consulting on proposed good practices for regulators and equity trading venues to address how market liquidity is evolving during the trading day, especially the growing concentration of trading in end-of-day auctions. The consultation is based on a global stocktake of equity market liquidity patterns and responds to potential implications for market integrity, operational resilience and investor protection, including reduced liquidity during continuous trading, heightened volatility around the close, risks of “marking the close,” cross-asset manipulation and pressure on trading venues during concentrated trading windows. IOSCO’s proposed good practices cover five areas: continued assessment of trades executed in end-of-day auctions, post-close sessions and other mechanisms that guarantee execution at the closing price; stronger operational risk and resilience arrangements, including business continuity and disaster recovery plans, capacity headroom, cybersecurity programs and real-time system monitoring; risk-based market surveillance that incorporates intraday liquidity metrics and addresses manipulation risks across trading phases and related derivatives markets; calibration and review of volatility control mechanisms to account for liquidity concentrations and significant shifts in liquidity dynamics; and supervisory approaches that assess how trading venues monitor and respond to risks arising from changing intraday liquidity patterns.
The Board of the International Organization of Securities Commissions is consulting on proposed good practices for regulators and equity trading venues to address how market liquidity is evolving during the trading day, especially the growing concentration of trading in end-of-day auctions. The consultation is based on a global stocktake of equity market liquidity patterns and responds to potential implications for market integrity, operational resilience and investor protection, including reduced liquidity during continuous trading, heightened volatility around the close, risks of “marking the close,” cross-asset manipulation and pressure on trading venues during concentrated trading windows. IOSCO’s proposed good practices cover five areas: continued assessment of trades executed in end-of-day auctions, post-close sessions and other mechanisms that guarantee execution at the closing price; stronger operational risk and resilience arrangements, including business continuity and disaster recovery plans, capacity headroom, cybersecurity programs and real-time system monitoring; risk-based market surveillance that incorporates intraday liquidity metrics and addresses manipulation risks across trading phases and related derivatives markets; calibration and review of volatility control mechanisms to account for liquidity concentrations and significant shifts in liquidity dynamics; and supervisory approaches that assess how trading venues monitor and respond to risks arising from changing intraday liquidity patterns.
The FATF is consulting on non-binding implementation guidance for the strengthened Recommendation 16 payment-transparency standard adopted in June 2025. The draft Guidance explains how countries and financial institutions should apply the revised "travel rule" across domestic and cross-border payments or value transfers, including MVTS, VASPs, card transactions, cross-border cash withdrawals, instant payments, digital wallets and mobile money. It clarifies the payment chain, information requirements, structured data expectations, virtual account and origin-of-funds issues, data protection and privacy safeguards, as well as three options for alignment checks to detect misdirected payments.
The FATF is consulting on non-binding implementation guidance for the strengthened Recommendation 16 payment-transparency standard adopted in June 2025. The draft Guidance explains how countries and financial institutions should apply the revised "travel rule" across domestic and cross-border payments or value transfers, including MVTS, VASPs, card transactions, cross-border cash withdrawals, instant payments, digital wallets and mobile money. It clarifies the payment chain, information requirements, structured data expectations, virtual account and origin-of-funds issues, data protection and privacy safeguards, as well as three options for alignment checks to detect misdirected payments.
Regional developments
The Hong Kong Securities and Futures Commission has ordered internet brokers and virtual asset trading platform operators to replace OTP-based client login and device binding with phishing-resistant authentication. Firms must implement the change as soon as practicable and within 12 months, while large internet brokers are expected to act immediately. The circular also requires stronger monitoring, incident response and client alert measures, with senior management accountable for control lapses.
The Hong Kong Securities and Futures Commission (SFC) has issued a circular setting cybersecurity standards for internet brokers and SFC-licensed virtual asset service providers to protect client internet trading accounts from phishing and account takeover. Firms must stop using one-time passwords for client login and device binding and adopt authentication methods suited to their platforms and risk profiles that reduce or mitigate phishing risks. Acceptable examples include passkeys and devices linked to client accounts through robust verification. Firms must implement the new methods as soon as practicable and no later than July 8, 2027, while large internet brokers are expected to adopt them immediately. Existing clients do not need to rebind devices that are already bound. Firms should generally limit each account to three passkeys and three bound devices. The SFC also requires stronger detection, notification and incident management controls. Firms should promptly notify clients of successful logins and higher-risk events, including access from a new device, device binding and the creation or revocation of passkeys, using multiple communication channels where applicable. Monitoring should cover suspicious logins, abnormal trading and fund or virtual asset withdrawals, using thresholds and red flags informed by client profiles, historical behaviour, device use and login patterns. Hacking procedures must provide for immediate containment, protection of client assets, notification of affected clients and immediate reporting to the SFC, followed by root cause analysis, documented remediation and measures to prevent recurrence. The SFC will hold firms responsible for client losses where inadequate controls fail to prevent, detect or stop large-scale unauthorized transactions following hacking incidents.
The Asia/Pacific Group on Money Laundering (APG) has released a report detailing how transnational cyber scam hubs combine online fraud, human trafficking for forced criminality and money laundering, generating tens of billions of USD annually. It identifies mule accounts, unlicensed remittance networks and virtual assets as key laundering channels, while highlighting major gaps in cross-border cooperation, asset recovery and cryptocurrency tracing. The report sets out red flags and calls for stronger financial analysis, enhanced due diligence and faster public-private and international coordination.
The Asia/Pacific Group on Money Laundering (APG) has published a report mapping how cyber scam hubs combine large-scale online fraud with human trafficking for forced criminality and how the resulting proceeds move through the financial system. The report finds that these transnational operations exploit special economic zones and other low-oversight locations, opaque corporate structures and gatekeepers, and corruption. They have targeted scam victims in more than 100 jurisdictions and are estimated to generate annual proceeds in the tens of billions of USD. Financial flows commonly involve mule accounts, unlicensed remittance networks and virtual assets, with rapid layering through peer-to-peer transfers, over-the-counter brokers, offshore or weakly supervised virtual asset service providers and crypto ATMs. Among APG member respondents, 76% identified mule accounts, 71% identified the exploitation of virtual assets and virtual asset service providers, and 59% identified illegal or unlicensed remittance systems. Investigations remain heavily dependent on victim complaints, while cross-border cooperation, asset recovery and cryptocurrency tracing are major constraints. Only two jurisdictions considered themselves successful in tracing and seizing related proceeds. The report provides financial, recruitment and operational red flags and identifies specialist financial and blockchain analysis, rapid multi-agency and international coordination, stronger public-private partnerships, enhanced due diligence and legal or institutional reform as key practices. It also calls for further work on the decentralisation of scam operations, the growing use of artificial intelligence and deeper engagement with civil society and victim-support organisations.
The Central Bank of the Philippines has issued recommendations for supervised institutions to strengthen cybersecurity controls against emerging risks from frontier artificial intelligence systems. The guidance focuses on attack surface visibility, foundational controls, stronger authentication, proactive exposure reduction, AI-enabled defensive capabilities and business continuity readiness.
The Central Bank of the Philippines has issued recommendations for all supervised institutions on managing emerging cybersecurity risks from frontier artificial intelligence systems. The memorandum warns that these systems may enable faster, more adaptive and scalable cyber threats, including the identification of software vulnerabilities, generation of exploit pathways and execution of multi-stage cyberattacks with minimal human intervention. Supervised institutions are expected to keep cybersecurity and technology risk management frameworks robust against AI-enabled threats. The recommendations focus on improving visibility over external assets, cloud services, identities, critical applications and software dependencies; strengthening credential hygiene, multi-factor authentication, least-privilege access and device hardening; reducing exposure through micro-segmentation, zero trust controls, faster patching, replacement of end-of-life systems and limits on unnecessary internet exposure; and moving administrative and privileged access away from passwords, SMS and push-based authentication. Institutions are also encouraged to use AI-enabled defensive capabilities for patch management, threat hunting, exposure management and security orchestration, deploy virtual patching for critical systems, and update business continuity arrangements for AI-enabled threats. The recommendations are framed as complements to existing information technology and cybersecurity risk management requirements under the Manuals of Regulations for banks and non-bank financial institutions. Supervised institutions are also recommended to formally develop an AI Governance Framework proportionate to their AI use, operational complexity and risk profile, following the principles in BSP Memorandum No. M-2026-031.
China's National Financial Regulatory Administration is consulting on a 72-article cybersecurity framework for banking and insurance institutions and financial holding companies. The draft would mandate group-wide governance, recurring risk testing and audits, six-month log retention, and tighter incident and critical infrastructure controls. Level 3 or higher incidents would be reportable within two hours, or within one hour when they occur within critical information infrastructure.
China's National Financial Regulatory Administration has launched a consultation on draft cybersecurity management measures for banking and insurance institutions and financial holding companies. The framework would integrate cybersecurity into comprehensive risk management, require group-wide oversight of domestic and overseas branches and subsidiaries, and assign clear responsibilities to governing bodies, senior management, the cybersecurity function, an independent risk management function and internal audit. Certain other supervised entities, including foreign bank and foreign insurer branches, would apply the measures by reference. The proposed rules cover network architecture, asset and access management, secure software development and system changes, supply-chain and outsourcing controls, data and personal information protection, continuous monitoring, incident response and recovery. Institutions would have to retain security logs for at least six months, analyze vulnerability remediation at least quarterly, conduct cybersecurity risk assessments and internet penetration tests annually, and undertake a cybersecurity audit at least every three years. Cybersecurity information would also form part of the annual information technology report submitted to the regulator or its local offices by January 15. Level 3 or higher cybersecurity incidents would have to be reported within two hours, followed by a formal written report within 24 hours. Critical information infrastructure operators would face a one-hour reporting deadline for such incidents and additional requirements covering operation and maintenance in China, 24/7 security monitoring, annual exercises, in-house system development capabilities, control of key technologies, and yearly testing and risk assessments.
The Monetary Authority of Singapore is consulting on flexible investment rules and a new Alternative Funds Appendix to accelerate approvals of novel retail fund types while retaining core investor protections. It expects to set fund-type guardrails in about three months, after which compliant funds of the same type could be authorised within 21 days. Initial proposals cover futures-based single-commodity funds and a wider range of single-country government bond funds.
The Monetary Authority of Singapore (MAS) is consulting on amendments to the Code on Collective Investment Schemes that would enable a wider range of new fund types to be offered to retail investors through a more flexible approval framework. A proposed Alternative Funds Appendix would allow funds with novel structures, extensive derivatives use or concentrated exposures to deviate from existing investment requirements, subject to fund-specific safeguards, enhanced disclosures and applicable distribution controls. Core requirements covering areas such as asset safeguarding, liquidity and fair dealing would continue to apply. Issuers would consult the authority before applying for authorisation. For most new fund types, the authority expects to establish the relevant guardrails in about three months, after which funds of the same type that meet those requirements could be authorised within 21 days. Initial examples include futures-based single-commodity funds, which would require at least 90% exposure to gold, silver, platinum, crude oil or iron ore and be subject to derivatives limits and risk disclosures. The proposals would also broaden access to single-country government bond funds by removing credit-rating criteria while retaining index inclusion, minimum issuance diversification and concentration-risk disclosures. The authority also proposes recognising comparable foreign funds.
The South Korea Financial Services Commission finalized a roadmap that will require ESG disclosures in corporate business reports from 2028 for KOSPI-listed companies with at least KRW10 trillion in consolidated assets, expanding to KRW5 trillion in 2029 and potentially KRW2 trillion later. The package includes an initial safe harbor, mandatory third-party verification from 2030 and a three-year delay to scope 3 emissions reporting for each cohort.
The South Korea Financial Services Commission (SFC) announced the final roadmap for sustainability disclosure, agreed with the government and the ruling Democratic Party of Korea, which accelerates the move to mandatory ESG reporting for major KOSPI-listed companies. ESG disclosures will be filed as part of corporate business reports under the Financial Investment Services and Capital Markets Act, starting in 2028 for companies with total consolidated assets of at least KRW10 trillion and expanding in 2029 to those with at least KRW5 trillion. After reviewing market practice in 2028 and 2029, authorities will consider lowering the threshold further to KRW2 trillion from 2030. The phased timetable would cover 291 companies including affiliates in 2028 and 3,171 in 2029. The roadmap also sets the liability, assurance and emissions-reporting framework. For the first disclosure year, companies may exclude affiliates that each account for less than 10 percent of both consolidated assets and sales to ease the move to consolidated reporting. During the first three years, companies will be exempt from damages, administrative sanctions and criminal penalties under the act for the full content of sustainability disclosures, although intentional greenwashing will still be subject to damages and administrative sanctions. After that, a narrower safe harbor will apply to uncertain information such as forecasts, emissions estimates and third-party data if disclosures were made faithfully and on reasonable grounds. Third-party verification will become mandatory from 2030, two years after reporting begins. Scope 3 emissions disclosure will be delayed by three years for each reporting cohort, beginning in 2031 for the KRW10 trillion group, 2032 for the KRW5 trillion group and 2033 for any future KRW2 trillion group, while small businesses that are not high-carbon emitters will be exempt. Authorities also paired the roadmap with implementation support and legislative follow-through. Measures include pilot testing and best-practice guidance, a climate-risk platform targeted for 2028, sector-specific scope 3 guidance for 15 key export industries, about 1,000 Life Cycle Inventory datasets by 2028, supply-chain ESG data infrastructure and expanded consulting and funding support. The Korea Exchange will upgrade its voluntary disclosure channel for companies outside the mandatory regime, and authorities will examine broader use of ESG disclosure data by institutional investors and financial firms. A revision bill to the Financial Investment Services and Capital Markets Act is to be prepared as early as July, alongside a working group to develop the legal changes and third-party verification framework.
The European Systemic Risk Board warned that frontier AI models are creating a structural increase in systemic cyber risk for the EU financial system. The models may give attackers a short to medium-term advantage by accelerating vulnerability discovery, compressing remediation windows from weeks to hours and overloading existing vulnerability and incident management frameworks. The risk is amplified by common technology exposures, critical third-party dependencies, potential disruption of payment, clearing and settlement functions, and EU reliance on non-EU AI providers.
The European Systemic Risk Board (ESRB) published a warning on systemic cyber risks to the EU financial system from frontier AI models, after its General Board assessed systemic cyber risk as severe in June, up from elevated in March. The warning treats recent advances in frontier AI models as a structural increase in systemic cyber risk because they can materially change the scale and structure of cyber threats, while no fully effective mitigation framework currently exists. These models may ultimately strengthen cyber resilience, but in the short to medium term they can give threat actors an advantage by reducing the cost, time and expertise needed to discover vulnerabilities, develop exploits and conduct complex attacks. The risk stems from several reinforcing channels. Frontier AI models can accelerate the discovery of high and critical severity vulnerabilities across major operating systems, widely used software, legacy systems, open source components and ICT environments underpinning financial infrastructure. They can also compress defensive time buffers by enabling rapid reverse engineering of patches and shortening the period between disclosure, exploitation and widespread automated attacks from weeks to hours. This could force institutions to choose between rapid patching that risks operational disruption and slower testing that leaves critical systems exposed. The systemic risk arises because financial institutions share technology stacks, critical third-party providers, cloud infrastructure, cybersecurity vendors and open source dependencies. Common exposures could turn incidents that are normally idiosyncratic into correlated disruptions across multiple institutions, with more serious consequences if payment systems, clearing and settlement, financial market infrastructures or other operational bottlenecks are impaired. The concentration of leading AI providers outside the European Union also creates strategic dependency and geopolitical risk, including potential limits on access to frontier AI capabilities. The ESRB calls for coordinated action by AI providers, software providers, security firms, open source maintainers, financial institutions and national and EU authorities, and says relevant authorities should reflect these risks in supervisory and oversight work. The warning follows a wave of similar measures by national authorities across Europe and abroad, including newly issued statements by the Guernsey Financial Services Commission and the Central Bank of the Philippines.
The European Securities and Markets Authority has launched a Common Supervisory Action on the digital operational resilience of crypto-asset service providers, centred on custody services. National Competent Authorities will review a risk-based sample of authorised firms from the second half of 2026 to the first half of 2027, focusing on distributed ledger technology risks such as key management, transaction controls, incident response, smart contracts and third-party dependencies. ESMA will compile the findings into a final report for its Board of Supervisors in the second half of 2027.
The European Securities and Markets Authority (ESMA) has launched a Common Supervisory Action to examine the digital operational resilience of crypto-asset service providers, with a specific focus on custody services. The exercise will assess how mature authorised providers’ resilience frameworks are in relation to custody activities, reflecting ESMA’s view that both digital operational resilience and crypto-asset service providers are priority risk areas. National Competent Authorities will conduct the review on a risk-based sample of authorised crypto-asset service providers from the second half of 2026 to the first half of 2027. The assessment will focus on risks linked to distributed ledger technology, including governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and reliance on third-party providers. ESMA said the action is intended to strengthen supervisory convergence in a fast-evolving market segment. Findings gathered by National Competent Authorities will be consolidated into a final report for submission to ESMA’s Board of Supervisors after the exercise ends in the second half of 2027.
The European Insurance and Occupational Pensions Authority (EIOPA) published seven IRRD instruments, bringing 15 of the 19 mandated measures to finalised and submitted status. The package strengthens recovery planning and sets rules for key resolution processes. Final consultations on resolution valuation standards remain open until 20 October 2026, ahead of the IRRD becoming operational in January 2027.
The European Insurance and Occupational Pensions Authority (EIOPA) published four guidelines and three draft regulatory technical standards under the Insurance Recovery and Resolution Directive (IRRD), bringing 15 of the 19 mandated instruments to finalised and submitted status. It also opened the final consultation round on the remaining four mandates, consolidated into two draft standards on resolution valuations, ahead of the IRRD becoming operational in January 2027. The published measures address both recovery planning and the execution of resolution. The guidelines define the stress scenarios and indicators insurers should use to assess the credibility of recovery plans, while setting parameters for simplified obligations and the disclosure of confidential information. The draft standards establish independence requirements for valuers, standard terms for recognising resolution stay powers in contracts governed by third-country law and methods for valuing derivative liabilities. The final consultations cover the three valuations required under the IRRD. One draft standard sets methods for valuing assets and liabilities and calculating additional-loss buffers for provisional valuations. The other governs the post-resolution assessment of whether shareholders, policyholders and other creditors would have received better treatment under normal insolvency proceedings
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism has issued final draft standards to harmonize how EU supervisors classify and enforce AML and CFT breaches across the financial and non-financial sectors. The framework introduces four severity categories, common criteria for sanctions and major administrative measures, and procedural rules for periodic penalty payments. The standards will be submitted to the European Commission for adoption and are drafted to apply from 10 July 2027, with a later start for football clubs and football agents.
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has issued final draft regulatory technical standards establishing a common EU framework for enforcing breaches of anti-money laundering and counter-terrorist financing requirements. The framework applies across the financial and non-financial sectors and is intended to produce consistent enforcement outcomes across member states while preserving supervisory judgment and proportionality. Supervisors would assess breaches against common indicators, classify their gravity into four categories and apply specified criteria when setting pecuniary sanctions or selecting administrative measures. Category three and four breaches would be treated as serious, repeated or systematic. Sanction levels would reflect factors including cooperation, remediation, responsibility, benefits derived, third-party losses, previous breaches and financial strength. The standards also set criteria for business restrictions, authorization withdrawal or suspension and governance changes, alongside procedural requirements for periodic penalty payments, including the right to be heard, daily, weekly or monthly calculation and a five year collection limitation period.The draft provides for application from 10 July 2027, except for football clubs and football agents, which would be covered from 10 July 2029. It would not apply to enforcement proceedings initiated before 10 July 2027. In addition to the release of the final standard, AMLA also launched a new consultation on draft standards to determine when a suspicious activity report concerns another European Union country and should be shared with that country’s Financial Intelligence Unit. The proposal is aimed at harmonising cross-border FIU information sharing, which currently depends on national practices that can create delays and legal uncertainty. The draft rules set objective criteria for identifying cross-border cases and for deciding how information should be shared. Reports could be transmitted either in full as a cross-border report or as a limited set of key data through a cross-border dissemination.
The European Banking Authority has finalised harmonised authorisation and reporting requirements for third-country branches under the Capital Requirements Directive. Applications will require detailed information on the branch’s business plan, governance, capital, liquidity and booking arrangements, supported by a non-opposition statement from the relevant third-country supervisor. The Guidelines apply from 11 January 2027, while supervisory reporting begins with the 31 March 2027 reference date.
The European Banking Authority (EBA) has finalised Guidelines and reporting specifications for third-country branches under the Capital Requirements Directive, establishing a more harmonised framework for their authorisation, prudential assessment and supervisory reporting across the European Union. Authorisation applications must include a three-year business plan under baseline and stress scenarios, details of governance and risk management, capital endowment, liquidity and booking arrangements, and information on the prudential standing of the third-country head undertaking. A non-opposition statement from the relevant third-country supervisor must be included or obtained through supervisory cooperation. Competent authorities should complete their assessment within six months after an application is deemed complete and no later than 12 months after receipt. The reporting package provides validation rules, a data point model and XBRL taxonomies for third-country branch supervisory reporting. The Guidelines apply from 11 January 2027, while supervisory reporting begins with the 31 March 2027 reference date.
The UK Financial Conduct Authority has published The Mills Review on how AI could move retail financial services toward continuous, delegated and agent-led models by 2030 and beyond. The review sees major changes across firm operations, consumer journeys, competition and fraud and cyber risk, with benefits for access, efficiency and personalisation balanced by risks around accountability, market power, exclusion and system-wide dependencies. It recommends clarifying the regulatory perimeter and accountability for more autonomous AI, strengthening system-wide oversight, scaling the FCA’s AI Lab and AI-enabled supervision, and building trusted foundations for agentic finance, including consent, identity, liability and public-interest consumer support.
The UK Financial Conduct Authority (FCA) has published The Mills Review, a Board-commissioned assessment of how AI could transform retail financial services by 2030 and beyond. The review frames the central shift as a move from human-led, episodic financial activity to AI-enabled, continuous and delegated services, in which consumers and firms increasingly rely on AI systems to analyse information, recommend actions and, over time, act within pre-set limits. It uses an autonomy spectrum to show how humans may move from operators and collaborators to approvers or observers, with risks shifting from accuracy and reliance toward consent, accountability, auditability and redress. The review identifies advances in AI capability as the systemic driver and applies that lens to four market shifts. Firms are expected to embed AI across operations, customer support, underwriting, compliance, claims, product design and outcome monitoring, making governance and model risk management core capabilities. Consumer journeys may become agent-led, with AI helping address the advice gap, protection gap, low switching, financial exclusion and excess cash holdings, but also creating risks around over-reliance, unequal access, opaque personalisation, bias, deceptive design and unclear recourse. Competition may shift toward control of AI-mediated interfaces, upstream model and cloud dependencies, data access and agent integration. Fraud and cyber risks are expected to become faster, cheaper, more scalable and more persuasive, while defensive, supervisory and intelligence-sharing capabilities will need to keep pace. The review concludes that the FCA’s principles-based, outcomes-focused framework remains a sound foundation, including the Consumer Duty, Senior Managers Regime and operational resilience rules, but that pressure points emerge as AI moves toward more autonomous action and shared system-wide dependencies. It sets out seven priority recommendations: secure and adapt the regulatory perimeter, strengthen system-wide coordination and oversight, monitor the transition to autonomous models and adapt frameworks, scale up the FCA’s AI Lab, enable the foundations for agentic finance, build an AI-enabled agentic supervisory model, and develop a trusted public-interest AI-enabled financial capability service.
The Swiss Financial Market Supervisory Authority issued guidance on quantum computing after finding that Swiss financial institutions are aware of encryption risks but generally lack concrete migration plans. FINMA recommends post-quantum cryptography roadmaps by mid-2027, supported by risk analysis, cryptographic inventories, protection of critical data, crypto-agility and coordination with external service providers
The Swiss Financial Market Supervisory Authority (FINMA) published guidance on quantum computing, setting out survey findings and recommended measures for managing the cyber risks posed by cryptographically relevant quantum computers. Based on a survey of 60 Swiss financial institutions, FINMA found that institutions are generally aware of the risks to encryption but are mostly still at an early stage in preparing for migration to quantum-safe encryption. The survey found that around two-thirds of respondents expect quantum computing cyber risks to directly affect them within seven years and expect a quantum computer to be able to crack RSA 2048-bit encryption within 24 hours within ten years at the latest. However, 72% had not yet planned or implemented quantum-safe encryption measures, only 8% had a specific roadmap, and most lacked sufficiently forward-looking planning. FINMA recommends a board-approved strategy and implementation plan, institution-specific risk analysis, a continuously updated cryptographic inventory, prioritised protection of critical data against “harvest now, decrypt later” attacks, crypto-agility for ICT systems and applications, and engagement with external service providers. FINMA recommends that supervised institutions draw up a post-quantum cryptography roadmap by mid-2027 at the latest. It will continue monitoring quantum computing developments and will give the topic greater prominence in ongoing supervisory activities.
HM Treasury has designated Microsoft, Google Cloud, Amazon Web Services and Oracle entities as Critical Third Parties from 13 July 2026. Their systemic services to the UK financial sector will come under joint oversight by the Bank of England, Prudential Regulation Authority and Financial Conduct Authority.
HM Treasury has designated four global cloud service and technology providers as Critical Third Parties under the UK financial sector’s operational resilience regime. From 13 July 2026, the systemic services they provide to banks, insurers and financial market infrastructures will come under joint oversight by the Bank of England, Prudential Regulation Authority and Financial Conduct Authority, reflecting concerns that disruption at a major provider could affect multiple firms at once. The designated firms are Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL and Oracle Corporation UK Limited. The new regime applies only to the critical services they provide to the financial sector, not to their wider operations. It gives regulators powers to gather information, assess resilience and work with providers to address risks to service continuity, including by making and enforcing provider-specific rules where needed. HM Treasury said the designations follow evidence gathering and engagement with the firms, and that financial firms remain responsible for managing risks arising from their third-party suppliers. HM Treasury said the regime is intended to operate on a rolling, risk-based basis, meaning further providers may be designated where disruption could threaten UK financial stability or confidence in the financial system.
The Bank of France and European research partners issued a joint declaration to strengthen cooperation between science, finance and public institutions on nature-related risks. The declaration calls for more systematic integration of biodiversity dependencies, impacts and risks into financial decision-making, supported by scientific data, stronger analytical capabilities and knowledge sharing.
The Bank of France, the Foundation for Biodiversity Research, Biodiversa+, the BiodivRestore Knowledge Hub and the CO-OP4CBD and RESPIN projects have issued a joint declaration to strengthen cooperation between science, finance and public institutions on nature-related risks. The declaration frames biodiversity loss as a material economic and financial stability concern, noting that more than half of global GDP, around USD 44 trillion, directly depends on ecosystem services, while global financial flows remain misaligned with biodiversity objectives. The declaration calls for a shift from risk awareness to risk preparedness by integrating nature-related dependencies, impacts and risks more systematically into financial decision-making. It emphasizes stronger dialogue between scientific, financial and public-sector actors, better use of scientific knowledge and data, enhanced analytical capabilities and improved knowledge sharing. The signatories also link the initiative to the Kunming-Montreal Global Biodiversity Framework, with a focus on aligning financial flows and economic systems with biodiversity objectives.
The Austrian National Bank said its cash access initiative has reached 66 OeNB ATMs, bringing improved cash access to more than 80,000 people in previously underserved municipalities. All machines have been installed in locations that previously had no ATM, and the central bank aims to expand the network to as many as 120 by the end of 2026.
The Austrian National Bank reported that, one year into its nationwide cash access initiative, the opening of an OeNB ATM in Güttenbach has increased the number of active machines to 66 and improved access to cash for more than 80,000 people in previously underserved municipalities. The program is focused on rural and other underserved areas, and all 66 ATMs installed so far have been placed in municipalities that previously had no ATM. Since July 2025, the central bank has installed on average more than one cash dispenser a week. In Güttenbach, the average distance residents had to travel to the nearest ATM fell from 4.4 kilometers to 0.6 kilometers after the new machine was installed. The OeNB said the initiative is intended to preserve choice between cash and digital payments while closing local service gaps, with local retailers, associations, restaurants, service providers and households benefiting from nearby cash access. The Austrian National Bank plans to continue the rollout and aims to expand the network to as many as 120 OeNB cash dispensers by the end of 2026. Separately, banks have agreed with the Austrian Association of Municipalities to safeguard their existing cash dispenser locations.
The Dutch Authority for the Financial Markets found that online embedded insurance journeys often steer consumers toward buying cover that may be unsuitable or duplicative. Its review of 22 journeys identified repeated prominence of insurance, frictionless take-up, weaker visibility of the no-insurance option and limited or hard-to-access information on key terms and overlap risks. The authority urged providers and platforms to redesign these choice environments more carefully.
The Dutch Authority for the Financial Markets (AFM) has published research finding that online choice environments for embedded insurance often push consumers toward taking out cover that may not be suitable. The main risk is that consumers buy insurance linked to a product or service without receiving enough balanced information, including where the cover may overlap with existing policies and create overinsurance. The authority called on providers and platforms to design these journeys more carefully so consumers can make appropriate choices. The findings are based on observations of 22 online choice environments. Across these journeys, insurance was often made very easy to buy, presented prominently and repeatedly, and paired with a less visible or less accessible option not to insure. Many platforms also used behavioural prompts such as emphasis on certainty and protection, social proof such as most chosen, and time pressure during the purchase process. Information was typically layered in a way that left the top level sparse and the underlying material complex or hard to access, with benefits highlighted more clearly than limits, duration, costs and possible overlap with existing insurance. Although this review did not assess compliance with legal requirements, the authority said the way these choice environments are designed could lead providers or platforms to fall short of legal standards that it can enforce. Its report sets out further recommendations, including making information clear and accessible and presenting options in a balanced way.
Council of Europe MONEYVAL’s review of Armenia finds stronger AML and counterterrorist financing arrangements, including effective targeted financial sanctions and improved international cooperation, but highlights weaknesses in virtual asset supervision, beneficial ownership transparency, suspicious activity reporting, money-laundering prosecutions and asset recovery. Armenia has been placed in enhanced follow up and must implement a recommended action roadmap over the next three years and report back to MONEYVAL.
The Council of Europe’s anti-money laundering body, MONEYVAL, has published its assessment of Armenia, finding stronger understanding of money laundering and terrorist financing risks, satisfactory national policies and strategies, and a robust regime for targeted financial sanctions related to terrorism and proliferation financing. At the same time, the report identifies material gaps in foreign threat analysis, virtua -asset risks, real-estate risk assessment, operational cooperation, beneficial ownership transparency, money-laundering enforcement and asset recovery. Based on the effectiveness and technical compliance ratings, Armenia has been placed in the enhanced follow-up process. The report says Armenia generally provides high-quality and timely international cooperation and has become more proactive with foreign counterparts, particularly in corruption cases, although that approach is not applied systematically to associated offences such as drug trafficking. Controls to stop criminals and their associates entering the regulated financial sector are viewed positively, but supervision of virtual asset service providers and non-public investment funds needs further work, while oversight of designated non-financial businesses and professions was assessed as having limited effectiveness and weak sanctions. MONEYVAL also calls for completion of the beneficial-ownership register and verification of the information it contains. Armenia’s Financial Intelligence Unit was commended for stronger staffing, IT resources and intelligence output, but suspicious activity reporting from the private sector needs to improve, and investigators should place greater emphasis on the money laundering dimension of criminal cases. Although reforms have increased money-laundering investigations and prosecutions, especially in corruption-related matters, prosecutions remain constrained by a restrictive interpretation of the offence and convictions are still low. MONEYVAL has given Armenia a roadmap of key recommended actions to complete within three years and requires it to report back on the progress made.
The Dubai Financial Services Authority is consulting on reforms to its Collective Investment Fund regime, including a shift from fixed specialist fund classifications toward risk-based requirements and disclosure. The proposals cover credit strategies, venture capital funds, delegated asset management, master-feeder structures, External Fund Managers, employee investment and fund reporting periods.
The Dubai Financial Services Authority (DFSA) has published proposals to amend its Collective Investment Fund regime after a review of the framework, which was established in 2006 and has not been comprehensively reviewed since 2010. The proposals would move the regime away from fixed specialist classifications for Exempt Funds and Qualified Investor Funds toward requirements based on activities, risks and safeguards, while retaining a disclosure-focused approach and applying certain risk management requirements more broadly across Fund Managers. Key proposals include removing specialist class requirements for certain Money Market Funds, Private Equity Funds and Credit Funds, while retaining safeguards for funds with strategies involving Providing Credit. The DFSA also proposes to align the base capital requirement for such credit strategies with other Fund Managers at USD40,000 and remove the dedicated Credit Fund fee structure. Other measures would extend the Venture Capital Fund Manager regime to funds dedicated to investing in Venture Capital Funds, clarify that delegated investment management under a Managing Assets authorisation can include Dealing in Investments as Agent and Arranging Deals in Investments where necessary, broaden aspects of the master-feeder regime, remove the External Fund Manager regime, permit certain employees involved in investment management to invest directly or indirectly in relevant private funds, and extend the first annual reporting period for newly established funds to 18 months. In addition to these proposals, the DFSA is also seeking initial feedback on possible future policy work relating to tokenised fund units, tokenised Money Market Funds and long-term investment funds for retail or restricted retail investors under a separate section of the consultation paper.
The U.S. Securities and Exchange Commission (SEC) has set up a Retail Fraud Working Group within the Division of Enforcement to intensify action against fraud targeting retail investors. The group will focus on proactive case generation across areas including offering frauds, pump-and-dump schemes, market manipulation, and adviser and broker-dealer misconduct. It will also coordinate with domestic and foreign counterparts and support investor education outreach.
The U.S. Securities and Exchange Commission has created a Retail Fraud Working Group to strengthen the Division of Enforcement’s efforts to identify and combat misconduct aimed at retail investors. The group is intended to concentrate staff and resources across the agency on fraud affecting everyday investors and to support more proactive enforcement case generation. Its remit covers offering frauds, pump-and-dump schemes, market manipulation, and breaches of duties to customers by investment advisers and broker-dealers. The working group will also coordinate with the SEC’s regulatory partners and foreign counterparts, and will take part in investor education outreach with the Office of Investor Education and Assistance. It will be led by Division of Enforcement Deputy Director Kate Zoladz and Asset Management Unit Assistant Director Kim Frederick.
The U.S. Federal Reserve has established five task monetary policy forces covering communications, balance sheet policy, economic data, productivity and jobs, and inflation frameworks. The groups will operate independently and report their findings to the Federal Open Market Committee. External co-leaders have now been appointed, including Mervyn King, Raghuram Rajan, Marc Andreessen and Thomas Sargent.
The U.S. Federal Reserve has established five monetary policy task forces to examine core elements of monetary policy conduct. Their work will cover communications under uncertainty, the costs and institutional implications of the balance sheet regime, the quality and timeliness of economic data, the effects of artificial intelligence and other general-purpose technologies on productivity and employment, and the drivers of inflation. Supported by Federal Reserve staff, the groups will operate independently and provide evidence-based findings and candid feedback to the Federal Open Market Committee. The Federal Reserve has now assigned external co-leaders from economics, business and former central bank leadership to direct the work. They include former Bank of England Governor Mervyn King on communications, former Reserve Bank of India Governor Raghuram Rajan on balance sheet policy, technology investor Marc Andreessen on productivity and jobs, and Nobel laureate Thomas Sargent on inflation frameworks. Further information on the task forces and their work will be published periodically.
Monetary policy developments
Decisions during the week of July 6 were slightly more varied than in the preceding week, with central banks responding differently to the temporary easing in oil prices and supply concerns that had prevailed before military activity intensified again later in the week. The Bank of Israel cut its rate 25 bp to 3.50% as inflation remained near the midpoint of the target range, expectations softened and activity recovered, although its forecast assumed no renewed fighting with Iran. The Reserve Bank of New Zealand, by contrast, raised the OCR 25 bp to 2.50%, judging that inflation would remain above target for several quarters and that easier financial conditions warranted less policy support, despite the partial reopening of the Strait of Hormuz and lower oil prices. Poland, Malaysia, Peru and Serbia maintained rates while assessing whether earlier cost pressures would continue to recede, although renewed U.S.-Iran military exchanges and fresh risks to Hormuz shipping make that assumption now less secure. Romania and Egypt retained restrictive settings given still-elevated inflation and weak demand.