Executive summaryIn China, financial institutions are already subject to a multi-layered regulatory framework governing data security and AI technologies, comprising:: (i) horizontal AI and ...
The PIPL, Cybersecurity Law, DSL, and regulations governing AI-related technologies and labeling requirements continue to play a critical role in regulating AI training data compliance, cross-border data transfers, algorithm governance, security assessments, filing requirements, content management, transparency, and labeling of AI-generated content in the financial industry.
In March 2024, the CAC’s Provisions on Promoting and Regulating Cross-Border Data Flows relaxed certain requirements for cross-border data transfer, but the regulations continue to impose heightened compliance obligations for the transfer of important data, exports conducted by critical information infrastructure operators (CIIOs), and larger-volume transfers of personal information. For multinational financial groups that train, test, or operate AI models across jurisdictions, an effective cross-border data strategy must therefore be grounded in a careful assessment of whether the relevant datasets constitute important data, whether applicable thresholds are triggered, and whether a CAC security assessment, standard contractual clauses or certification requirements apply.
In March 2025, the CAC, together with other authorities, issued the Measures for Labeling AI-Generated Synthetic Content, effective 1 September 2025. The measures require explicit and implicit labeling of AI-generated/synthetic content and prohibit deleting, tampering with, fabricating, or concealing required labels. That matters immediately for customer-facing financial chatbots, robo-advice interfaces, AI-generated marketing, fraud alerts, and other public-facing outputs used by banks, brokers, insurers, or fintech apps.
2) Banking and insurance got a hard-law data-security rule in late 2024The NFRA’s Measures for the Data Security Management of Banking and Insurance Institutions (effective 27 December 2024) are one of the most consequential post-2024 developments for data security and deployment of AI in finance. They require covered institutions to build a full-lifecycle data-security framework, classify data as core, important, or general, carry out prior data-security assessments for higher-risk processing, manage data outsourcing and data sharing, and report certain data-security incidents on short timelines.
Crucially for AI deployment, the NFRA measures go beyond generic data governance. They require centralized control of AI model development and application, a gate for external model/algorithm products, and pre-launch review of the reasonableness, legitimacy, explainability, and risk of models and data use. The rules also require institutions using AI in business to provide explanations or disclosures about how data affects outcomes and to maintain mitigation and fallback arrangements.
3) PBOC followed with its own business-area data rule in 2025The PBOC’s Measures for Data Security in PBOC Business Areas (effective 1 June 2025) extend sector-specific data governance to PBOC-supervised domains such as payment and settlement, credit reporting, anti-money laundering, cross-border RMB, the interbank market, and financial statistics. The rules require financial institutions and other covered entities to build data-resource catalogues, classify and grade data, identify important/core data, and adopt full-process security controls and reporting arrangements.
For AI-related use cases, the PBOC rules are especially relevant where models draw on payments data, anti-money laundering (AML) data, credit information and transaction data, or cross-border RMB data. More broadly, the Measures reinforce the regulatory expectation that financial AI systems deployed in the financial sector are subject not only to the general requirements under thethe PIPL, Cybersecurity Law, DSL, and regulations governing AI-related technologies and labeling requirements, but also to sector-specific governance, auditability, and incident-response obligations imposed directly by the financial regulators.
4) Regulators are now explicitly promoting — and constraining — “AI + finance”By late 2025, the NFRA’s Implementation Plan for High-Quality Development of Digital Finance in the Banking and Insurance Sectors had moved from general digitalization rhetoric to a concrete work program. The plan expressly promotes “AI + finance” initiatives, intelligent approval models, digital infrastructure, and data use, while also stressing algorithm/model risk, data security, cybersecurity, and protection of consumers and smaller users.
In June 2026, the NFRA published the Guiding Opinions on the Safe Development and Application of AI in Banking and Insurance, together with an official Q&A. The Guiding Opinions require banking and insurance institutions to establish robust governance frameworks, covering data security, model risk management and human oversight mechanisms, with enhanced controls for high-risk use cases such as credit approval, underwriting and trading. At the same time, the Guiding Opinions support the prudent adoption of generative AI while imposing safeguards relating to transparency, privacy protection, outsourcing and cybersecurity. The issuance of the Guiding Opinions is significant: it signals that China has now moved from general digital-finance and data-security rules to a dedicated banking/insurance AI supervision document.
Sector-specific notes1) BankingFor banks, the center of gravity for data security and AI compliance is the NFRA data-security regime complemented by its digital-finance policy framework. The 2024 NFRA measures require board/senior-management accountability, internal data-security ownership, classification of financial data, ex ante assessments for higher-risk processing, and specific governance for AI models and automated decisioning used in financial services.
At the policy level, the NFRA’s Implementation Plan for the High-Quality Development of Digital Finance in the Banking and Insurance Sectors expressly encourages banks and insurers to accelerate the development of “AI + Finance” by building enterprise-level AI platforms and establishing centralized governance over the entire AI lifecycle, including model development, training, testing, deployment, monitoring, evaluation and retirement. Financial institutions are encouraged to enhance AI-driven modelling capabilities, develop industry AI ecosystems, and expand AI applications in areas such as customer service, operations, risk management and regulatory technology. At the same time, the policy stresses that AI adoption must be accompanied by robust governance and risk controls, including classified AI management frameworks, continuous monitoring, human oversight of critical processes, model risk management throughout the model lifecycle, greater algorithm transparency and explainability, cybersecurity safeguards, and measures to prevent algorithmic bias and protect consumer rights.
2) InsuranceInsurers and insurance asset managers are covered directly by the NFRA’s 2024 data-security measures, so AI used in underwriting, claims automation, fraud detection, pricing, and distribution must sit inside the same governance architecture described above: lifecycle controls, classification/grading, outsourcing governance, personal-information protections, and ex ante security assessments for higher-risk processing.
The NFRA’s implementation plan also suggests the regulator sees insurance as part of the “AI + finance” build-out: the plan encourages digitalized service models and specifically mentions development of data-asset and cybersecurity-related insurance products as part of the broader digital-finance agenda. That is a meaningful policy signal for insurtech and cyber-insurance product design in China.
3) Payment / fintech platformsFor payment institutions, the primary regulatory framework is the Regulations on the Supervision and Administration of Non-Bank Payment Institutions (effective 1 May 2024) and the 2024 implementing rules. These require licensed operation, prudential governance, compliant systems, and security/continuity safeguards. The rules also require business systems and backups to be stored in China, and provide that domestic transactions should be processed, settled, and stored in China, while cross-border payment activity must also comply with cross-border payment / RMB / foreign exchange / data-flow rules.
Implications for financial institutionsThe clearest recent signal is that supervision is moving from general digital-finance policy to granular rulemaking. The 2024 NFRA data-security measures, the 2025 PBOC data-security measures, the 2025 AI-labeling rules, and the 2026 bank/insurance AI guidance together show an increasingly detailed supervisory architecture for AI-enabled financial activity, which has comprehensive implications for financial institutions.
First, significant regulatory obligations already arise from the interaction of sectoral data-security rules, cross-border data rules, content-labeling rules, and payment/platform rules.
Second, Chinese regulators are increasingly focused on governance, accountability and controllability. Key compliance priorities include appropriately classifying data, documenting the legal basis and purpose of data processing activities, assessing model/data risks ex ante, managing third-party providers, maintaining logs and incident response, and being able to explain AI-assisted outcomes in regulated financial processes. This is especially important where AI affects customers, pricing, fraud controls, credit/claims outcomes, or compliance decisions.
Third, cross-border operating models need early redesign. Multinational institutions using global data lakes, offshore model training, cross-border fraud platforms, or centralized customer analytics should test those flows against both the CAC’s 2024 outbound-data thresholds and the sectoral rules imposed by the NFRA and PBOC. For payment institutions in particular, compliance with China’s data localization, local processing, and local storage requirements remains a critical consideration when designing AI-enabled products, services, and operational infrastructure.
As AI continues to transform the financial services industry, our HLC China regulatory team can help clients navigate the increasingly complex regulatory landscape, assess and manage compliance risks, engage with regulators, and implement governance frameworks that support the responsible adoption of AI. We advise on financial data regulation, AI governance and model risk management, cross-border data flows, algorithm and platform compliance, outsourcing arrangements, and AI-enabled financial products and services, helping clients achieve their innovation objectives while maintaining regulatory compliance and operational resilience.
Authored by Sherry Gong, Jessie Xie, and Difan Li.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | AI regulation in financial services: navigating the EU AI Act in a layered regulatory landscape | 0 | 7.71 | 12-05-2026 |
| 2 | From principles to practice: Maturing AI supervision in Singapore’s Financial Sector | 0 | 7.02 | 03-06-2026 |
| 3 | With New AI Governance Organization, China Seeks to Formalize Its Global AI Influence | 0 | 6.57 | 20-07-2026 |
| 4 | Could regulation-trained AI aid financial services innovation? | 0 | 3 | 08-07-2026 |
| 5 | AI-driven governance essential for detecting fraud, managing high financial data volatility: Experts | 2 | 7 | 07-07-2026 |
| 6 | Regulate, Don’t Ban, Chinese AI Models | 0 | 9.57 | 03-08-2026 |
| 7 | Caution warranted over tech threat, investors’ AI exuberance | 0 | 8.96 | 19-07-2026 |
| 8 | Making the Move: How Investment Firms are Bringing AI to the Front Office | 0 | 8.49 | 08-05-2026 |
| 9 | Why AI is a risk to Communist China | 0 | 7.66 | 06-08-2026 |
| 10 | Squaring the circle - digital sovereignty’s big picture versus its operational details | 0 | 8.68 | 30-07-2026 |