August roundup of regulatory developments and compliance news

A monthly roundup of the most important regulatory, legal and supervisory developments shaping QA, software testing, AI governance and digital resilience across banking and financial services.


It has been a fairly quiet month with many regulators across North America, Europe and Asia enjoying their summer break.

Nevertheless, the latest developments reinforce a theme that has been building throughout 2026: regulators increasingly expect financial institutions to translate AI and cyber-risk policies into practical testing, monitoring and operational controls.

From Singapore’s new industry taskforce and the FCA’s examination of future AI supervision to Europe’s transparency requirements and warnings about frontier AI, attention is shifting towards the evidence firms can produce that their technology remains secure, resilient and under control.

MAS launches resilience taskforce

The Monetary Authority of Singapore and the Association of Banks in Singapore have established the AI-Driven Cyber and Technology Risk Taskforce, an industry-wide initiative intended to strengthen financial-sector resilience against threats created by frontier AI.

The taskforce brings together MAS, ABS, DBS, OCBC, UOB, Singapore Exchange, NETS and Banking Computer Services. Its work will include sharing AI cybersecurity use cases, improving cyber-defence capabilities and developing practical guidance for financial institutions.

Crucially for quality engineering teams, the group will also conduct proof-of-concept trials to explore and validate advanced AI-enabled defensive tools. The initiative therefore places testing at the centre of Singapore’s response to faster, more scalable and increasingly sophisticated AI-driven attacks.

Bailey writes resilience letter

Bank of England Governor Andrew Bailey has put stress testing, penetration testing and pre-deployment AI assessment at the centre of the response to growing cyber threats.

Andrew Bailey

His intervention also raises a broader regulatory question: how can financial authorities provide verifiable assurance that their own systems work without disclosing sensitive security information?

Bailey said banks must “strengthen their detection efforts and responses, patch vulnerabilities faster, and be able to recover when things do go wrong.”

Crucially for testing teams, these expectations cannot be met through policies or assurances alone. “As a regulator we require that banks prove to us that they can do this through stress tests and penetration testing,” Bailey wrote.

Bailey also used his letter to call for stronger international cooperation on the assessment of advanced AI systems.

“It is also why the Bank has called for stronger international coordination around testing frontier AI models before wider deployment,” he stated.

EU rules create testing obligations

The European Commission’s voluntary Code of Practice on Transparency of AI-Generated Content has added another layer to Europe’s emerging AI assurance regime.

Ahead of Article 50 transparency obligations applying from 2 August, the Code provides practical measures for marking and detecting AI-generated or manipulated content and labelling deepfakes and certain AI-generated text. These include machine-readable information, provenance mechanisms, watermarking and other technical controls.

For banks, those controls must remain accurate and auditable as content passes through APIs, document conversions, cloud platforms and third-party applications.

Regression and integration testing may therefore need to demonstrate that labels and provenance information survive software releases and remain attached throughout the content lifecycle.

Alongside DORA, BaFin’s resilience guidance and the requirements covering high-risk AI, the Code reinforces the shift towards continuous testing as evidence that AI governance controls remain effective after deployment.

FCA zooms in on AI assurance

The UK’s Financial Conduct Authority’s Mills Review has called for new approaches to testing, assurance and monitoring as increasingly autonomous AI systems enter retail financial services.

The FCA in London

Rather than proposing a separate body of AI regulation, the FCA is examining whether existing frameworks, including the Consumer Duty, the Senior Managers and Certification Regime, operational resilience requirements and the Critical Third Parties regime, remain suitable for an AI-enabled financial sector.

The review highlights accountability, auditability and safe deployment while warning that autonomous and interconnected AI may amplify existing risks.

It also suggests that supervising AI-enabled firms will require deeper technical expertise and new forms of testing, assurance and continuous monitoring.

BIS issues frontier AI warning

The Bank for International Settlements has warned that frontier AI is increasing the speed, scale and complexity of cyberattacks, while the economic balance may favour attackers even when the same technology strengthens defensive capabilities.

Banks, payment systems and financial market infrastructures are particularly exposed because they depend on complex combinations of proprietary software, open-source components and third-party suppliers. A vulnerability affecting one organisation could consequently spread across an interconnected financial system.

The BIS said the swift adoption of advanced AI to review codebases and remediate vulnerabilities is essential. For software testing teams, the warning increases the importance of continuous vulnerability discovery, adversarial testing and faster validation of patches before attackers can exploit newly identified weaknesses.

HK addresses recovery-testing failures

Hong Kong’s Securities and Futures Commission has reprimanded and fined Luk Fook Securities HK$2.1 million over inadequate cybersecurity controls connected to a ransomware attack.

Hong Kong

The incident affected critical infrastructure including file servers, domain controllers, email servers, trading applications and accounting systems.

According to the regulator, the firm took approximately three weeks to complete the phased restoration of its systems.

The enforcement action demonstrates why cybersecurity compliance extends beyond preventing an initial breach.

Financial firms must also test backup integrity, recovery sequencing, identity controls and the ability to restore important services within acceptable timeframes. Documented resilience testing may become decisive evidence when regulators assess whether a firm was adequately prepared.

MAS prepares firms for quantum resilience

MAS is preparing supervisory expectations, milestones and timelines for financial institutions to migrate towards quantum-resilient security.

Although powerful quantum computers are not yet operating at the scale required to compromise widely used encryption, financial institutions hold data and operate infrastructure with long lifecycles. Migration programmes may therefore need to begin well before the threat becomes immediate.

For QA and engineering teams, the transition will require more than replacing cryptographic algorithms. Firms will need inventories of affected systems, compatibility testing across legacy platforms, validation of third-party integrations and extensive regression testing to ensure that new encryption controls do not interrupt payments, authentication or other critical services.

European supervisors raise systemic AI cyber warning

The European Supervisory Authorities have backed a European Systemic Risk Board warning that frontier AI models are transforming the cybersecurity landscape.

The regulators warned that advanced models can help threat actors increase the speed and scale of attacks, reduce the expertise required to exploit vulnerabilities and support more complex operations against financial infrastructure.

The development extends the frontier-AI debate beyond individual institutions and into systemic resilience. Testing programmes may need to consider correlated failures, shared technology dependencies and attacks that affect multiple firms or providers simultaneously, rather than validating each system in isolation.

HKEX requires post-release network testing

Hong Kong Exchanges and Clearing has moved its securities-market backbone network upgrade towards production following a series of market rehearsals, including connectivity checks and simulated system failover.

The Securities and Futures Commission subsequently issued an update on post-release testing arrangements associated with the launch. Exchange participants must prepare for production validation rather than treating successful pre-release rehearsals as the final assurance point.

The programme provides a clear example of continuous resilience testing around critical market infrastructure. Connectivity, failover behaviour and participant readiness must be validated before implementation and checked again after release, when the upgraded network is operating under production conditions.


NEXT MONTH

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


READ MORE


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS