Report name:

Supervision of Artificial Intelligence in Finance: Challenges, Policies and Practices, OECD Artificial Intelligence Papers, No. 54, January 2026

Who wrote this report?

This report is published by the OECD Directorate for Financial and Enterprise Affairs, with contributions from financial regulators and public authorities including authorities such as the Bank of Japan, the U.S. Treasury, and ASIC. It builds on the 2024 OECD Survey on AI in Finance, covering 49 OECD and Non-OECD jurisdictions, making it one of the most comprehensive cross-country analyses of how AI is being supervised in practice.

Unlike many AI policy reports, this paper is not concerned with whether AI should be regulated. It starts from the premise that AI is already embedded in financial systems, and instead focuses on a more practical question: how existing rules are interpreted and enforced when faced with increasingly complex AI systems.

Best quote

“It is at this level of practical interpretation and implementation of AI policies in finance that challenges may arise, given the intrinsic characteristics of AI innovation, particularly advanced forms of AI.”

Key takeaways

The report’s central argument is that the real governance challenge lies not in regulation, but in supervision. Most OECD countries believe existing financial regulations are broadly sufficient because they are designed to be technology-neutral. However, difficulties arise when supervisors must apply these rules to AI systems that are opaque, adaptive, and evolving rapidly. This challenge is particularly pronounced for generative AI systems, whose stochastic outputs and risk of hallucinations are harder to supervise than traditional predictive models.

A second key insight is that AI is stretching the limits of technology-neutral regulation. While rules may remain unchanged, supervision increasingly requires more AI-specific interpretation and guidance, particularly as systems become harder to audit or explain.

The report also identifies a set of recurring supervisory challenges, including model risk management, explainability, governance, data quality, and supervisory capacity. These challenges mirror those faced by firms, but become more complex at the oversight level.

Importantly, the OECD highlights structural blind spots, particularly the growing reliance on third-party AI providers. These actors often sit outside direct regulatory oversight, creating risks around concentration, transparency, and accountability.

Overall, the report suggests that the solution is not more regulation, but better interpretation, stronger institutional capacity, and adaptive supervisory tools.

What’s in this report?

The report is structured around three themes: how AI is supervised, what challenges arise, and what practices may help address them.

The first section focuses on translating policy into effective oversight. It draws a clear distinction between regulation (rules on paper) and supervision (how those rules are applied in practice). Across jurisdictions, supervision is typically risk-based and technology-neutral. However, challenges emerge due to regulatory layering and institutional complexity. For example, in the EU, financial institutions may need to comply simultaneously with sector-specific rules and broader AI frameworks, making supervision more complex. The report also highlights increasing coordination challenges as multiple authorities become involved in AI oversight.

The second section outlines key supervisory challenges. One of the most important is the opacity and complexity of AI systems, which can make it difficult for supervisors to understand how decisions are made or to assess compliance. Even though existing model risk frameworks remain applicable, applying them to AI is not straightforward because models may be continuously evolving and difficult to interpret.

The report also highlights challenges related to data and monitoring, including the lack of standardised information on AI use and limited visibility into system-wide risks. Governance issues are equally important. Supervisors report difficulty in operationalising concepts such as “human oversight,” particularly as AI systems become more autonomous. The report notes that such safeguards may be ineffective in practice if users defer to AI outputs they do not fully understand, a phenomenon linked to automation bias. A notable example cited is research showing that AI-generated explanations can increase user confidence even when outputs are incorrect.

The final section focuses on supervisory practices that can help balance innovation and stability. The report notes that in many areas, regulators believe appropriate rules already exist, but firms still face ambiguity in how to apply them. As a result, the OECD recommends clarifying existing frameworks rather than introducing overly prescriptive new rules.

It also highlights the growing use of regulatory sandboxes and testing environments. For example, the UK Financial Conduct Authority’s AI Live Testing initiative allows firms to test AI models in real-world conditions under supervisory guidance. In addition, the report emphasises the importance of building supervisory capacity. Most OECD jurisdictions are already investing in training and upskilling supervisors.

Another emerging trend is the use of AI by regulators themselves (SupTech). The report notes that the European Central Bank is exploring over 40 generative AI use cases to support supervisory work, including document analysis and risk monitoring. Finally, it stresses the importance of cross-border and cross-sector coordination, given the global and interconnected nature of AI systems.

Why should you read this report?

This report is particularly valuable because it shifts the focus from designing AI regulation to implementing it effectively. It shows that the key challenge is not the absence of rules, but whether institutions have the capacity, clarity, and tools to enforce them in a rapidly evolving technological environment.

For government audiences, this is a critical insight. AI governance is not just a legal or technical issue, it is fundamentally a question of institutional capability and coordination. The report highlights how data gaps, skill shortages, vendor dependencies, and fragmented oversight structures can all undermine effective supervision.

More broadly, while the report focuses on finance, its lessons extend to other sectors. It offers a useful lens for thinking about how governments can adapt existing regulatory systems to new technologies without stifling innovation.

Who is this report for?

This report is most relevant for financial regulators, supervisors, central banks, and policymakers working on AI governance and digital regulation. It is also useful for public-sector professionals interested in how institutions adapt to emerging technologies, particularly in high-risk, regulated environments.

Find the full report: Link


Make sure to share your own thoughts with the author by leaving a comment below