01Japan's 130-firm survey: 93% use AI, but customer-facing deployment remains limited
A survey conducted by Japan's Financial Services Agency (FSA) between October and November 2024 found that 93.1% of the 130 responding financial institutions had deployed either conventional AI or generative AI in some form. The dominant applications were internal: document summarization, translation, and FAQ retrieval. Credit assessment and underwriting were cited as areas where AI was advancing risk management, but services directly touching customers remained at an early stage.
The findings formed the basis of the AI Discussion Paper (DP) version 1.0, published in March 2025. After seven sessions of an AI Public–Private Forum held between June and December 2025, the FSA released version 1.1 in March 2026. The update added a four-part risk framework for customer-facing generative AI services, clarified rules on the handling of non-public information, and introduced use cases involving AI agents. Crucially, the DP is not a binding regulation — it is described as a "preliminary discussion of key issues." That framing sets it apart from the EU's approach.
02The FSA chose principles and dialogue, not prescriptive rules
The FSA's method is to observe first and set rules later. When the DP 1.1 outlines standards for financial institutions using AI in material decisions, it lists five items: (1) responses proportionate to the nature of the AI, (2) awareness of training data, (3) documentation of reference data when using retrieval-augmented generation, (4) prompt management, and (5) logging and monitoring of outputs. Each is a principle — a statement of what matters — rather than a technical specification.
This design reflects Japan's supervisory tradition. Financial regulation in Japan has operated through sector-specific supervisory guidelines and examination manuals. Because AI cuts across banking, securities, and insurance, it resists neat categorization within those silos. The FSA's solution was to leave the existing supervisory architecture intact while layering AI-specific issues through structured dialogue. The seven forum sessions gathered case studies from banks, broker-dealers, and insurers, building a shared understanding without yet imposing obligations.
03The EU AI Act designated credit scoring and insurance underwriting as high-risk
The EU AI Act (Regulation (EU) 2024/1689) entered into force in August 2024. Its most consequential provision for finance is Annex III, which classifies certain AI systems as high-risk. Annex III designates two financial uses: AI systems intended to evaluate the creditworthiness of natural persons or establish their credit scores, and AI systems used for risk assessment and pricing in life and health insurance. AI used solely for fraud detection is excluded.
Providers of high-risk AI systems must comply with obligations spanning risk management (Article 9), data governance (Article 10), technical documentation (Article 11), record-keeping (Article 12), transparency and instructions for use (Article 13), human oversight (Article 14), accuracy and robustness (Article 15), quality management (Article 17), and conformity assessment (Article 43). Penalties for non-compliance reach up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.
04The Digital Omnibus deferred high-risk obligations to December 2027
High-risk obligations under the AI Act were originally set to apply from August 2, 2026. The EU reached a political agreement on the Digital Omnibus on AI in May 2026, and the resulting Regulation (EU) 2026/1744 was published in the Official Journal on July 24, 2026, entering into force on July 27. The amendment deferred the compliance date for stand-alone Annex III high-risk AI systems — including credit scoring and insurance underwriting — to December 2, 2027, a 16-month extension. AI embedded in regulated products listed in Annex I received a longer grace period, until August 2028.
Industry lobbying drove the deferral: many providers argued they needed more time to build conformity assessment processes. However, several obligations remained on schedule. The prohibited-practices regime under Article 5 has applied since February 2025. General-purpose AI (GPAI) provider obligations have been in force since August 2025. Transparency and AI-content labeling duties under Article 50 applied from August 2026. What was deferred is the detailed set of provider and deployer obligations for high-risk systems — not the regulatory framework itself.
| Dimension | Japan (FSA) | EU AI Act | United States |
|---|---|---|---|
| Legal force | None (DP is a discussion document) | Binding (fines for non-compliance) | Existing law applied (SR 11-7, etc.) |
| AI-specific classification | None | High-risk (credit, insurance) | None (subsumed under model risk) |
| Timeline | Phased dialogue (2025–) | High-risk obligations: Dec. 2027 | Existing guidance in effect |
| Accountability locus | Financial institution (self-governance) | AI provider (primary obligations) | Financial institution (model owner) |
05The US: no unified federal AI law, relying on SR 11-7 and the NAIC Model Bulletin
The United States has no federal statute specifically regulating AI in financial services. Banking regulators — the OCC, Federal Reserve, and FDIC — apply SR 11-7, the 2011 guidance on model risk management, to AI systems. SR 11-7 establishes a framework for managing risk across model development, implementation, and use. Although it predates modern AI, its broad definition of "model" has allowed regulators to extend it to machine-learning systems.
In May 2025, the Government Accountability Office (GAO) published report GAO-25-107197, reviewing how federal financial regulators oversee AI. The report confirmed that institutions use AI for credit decisions, fraud detection, algorithmic trading, and customer service, and that supervisors rely on risk-based examinations and existing guidance. It identified two gaps at the National Credit Union Administration (NCUA): model risk management guidance that is "limited in scope and detail," and a lack of authority to examine technology service providers — a significant gap given credit unions' reliance on third-party AI vendors. GAO recommended that NCUA update its guidance and that Congress grant it examination authority over technology providers.
For insurance, the National Association of Insurance Commissioners (NAIC) adopted a Model Bulletin on the Use of AI Systems by Insurers in December 2023. By August 2025, 24 states had adopted it. The bulletin requires insurers to establish AI governance and risk management programs and to explain how AI is used in underwriting, pricing, marketing, and claims. Because adoption is state-by-state, coverage remains uneven.
06Credit and insurance AI draw regulatory attention because they determine individuals' access to finance
All three jurisdictions focus on credit and insurance because these decisions directly shape individuals' economic lives. A low credit score can block a mortgage. An inflated premium can price a person out of life insurance. When AI produces these outcomes without transparent reasoning, affected individuals lose the ability to challenge the decision.
The EU's choice to classify life and health insurance as high-risk while excluding property and casualty insurance is consistent with this logic. Denial of life or health coverage can affect a person's survival or access to medical care. Property insurance compensates for damage to objects — a different category of harm. The FSA's DP similarly calls for responses calibrated to the degree of risk, rather than treating all AI applications identically.
The link to pharmaceutical and healthcare industries is direct. Health insurance underwriting AI may reference policyholders' medical histories and, increasingly, outputs from AI-assisted diagnostic tools. If a generative AI system used in clinical decision support feeds data into insurance underwriting, the provenance and accuracy of that data become determinants of premium fairness. The EU AI Act's requirements for data governance and human oversight are designed to govern precisely this kind of data chain.
07Three practical steps every financial institution should take now
Despite differences among the three frameworks, the practical groundwork is largely the same.
First, build an AI model inventory. Catalog every AI model in use across the organization, recording its purpose, training data, update frequency, and accountable owner. The EU AI Act's technical documentation requirement, the FSA DP's call for output logging and monitoring, and SR 11-7's model inventory obligation all begin with the same step: knowing what you have.
Second, design an explanation pathway. When AI is used in credit decisions or insurance pricing, prepare a route through which customers can understand why a particular outcome was reached. Article 13 of the EU AI Act requires transparency not as a ban on complexity, but as a duty to provide information that enables users to interpret results. In Japan, the FSA raised explainability in the AI Public–Private Forum. In the US, the Consumer Financial Protection Bureau (CFPB) has intensified its monitoring of lending discrimination, reinforcing the need for auditable decision trails.
Third, establish a cross-functional team to track regulatory developments. The Digital Omnibus bought 16 months of additional time, but the December 2027 deadline is fixed. The FSA has signaled further revisions to the DP. The American Bankers Association has called for updates to SR 11-7. Waiting for final rules before acting is not viable. Legal, risk, and IT departments need a joint mechanism for monitoring and preparing.
- Japan's FSA AI Discussion Paper 1.1 is a dialogue-based discussion document grounded in a 130-firm survey, distinct in character from the EU AI Act's binding obligations and the US approach of applying existing guidance. What the three share is a focus on accountability and data management for AI decisions that affect individuals' access to credit and insurance.
- The EU AI Act classifies credit scoring and life/health insurance AI as high-risk, imposing technical documentation, human oversight, and conformity assessment obligations on providers. The Digital Omnibus deferred these obligations to December 2027, but transparency duties and the prohibited-practices regime are already in force.
- Regardless of jurisdiction, financial institutions should build an AI model inventory, design explanation pathways for customer-affecting decisions, and create a cross-functional team to track regulatory evolution. Laying this groundwork before rules are finalized makes it possible to comply across all three frameworks.
The FSA chose dialogue. The EU chose classification and obligation. The US chose the extension of existing law. The methods differ, but the question is the same: when AI decides whether someone gets a loan or what premium they pay, who explains and how. Preparing to answer that question cannot wait until regulations are finalized. The next installment, Part 6, examines model risk management itself — the discipline of explainability, validation, and governance that underlies every regulatory framework discussed here.
- Financial Services Agency (Japan). AI Discussion Paper (Version 1.1) — Preliminary Discussion of Key Issues for Sound Use of AI in Finance. March 2026. https://www.fsa.go.jp/news/r7/sonota/20260303/aidp.html
- Financial Services Agency (Japan). AI Discussion Paper (Version 1.0) Summary. March 2025. https://www.fsa.go.jp/news/r6/sonota/20250304/aidp_summary.pdf
- European Parliament and Council. Regulation (EU) 2024/1689 (AI Act), Annex III. Official Journal of the European Union, 2024. https://artificialintelligenceact.eu/annex/3/
- European Parliament and Council. Regulation (EU) 2026/1744 (Digital Omnibus on AI). Official Journal of the European Union, July 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- GAO. Artificial Intelligence: Use and Oversight in Financial Services (GAO-25-107197). May 2025. https://www.gao.gov/assets/gao-25-107197.pdf
- NAIC. Model Bulletin: Use of Artificial Intelligence Systems by Insurers. December 2023. https://content.naic.org/sites/default/files/cmte-h-big-data-artificial-intelligence-wg-ai-model-bulletin.pdf.pdf
- Board of Governors of the Federal Reserve System / OCC. SR 11-7: Guidance on Model Risk Management. 2011. https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm
- PwC Japan. Overview and Internal Audit Implications of FSA AI Discussion Paper v1.1. 2026. https://www.pwc.com/jp/ja/knowledge/column/ai-governance/ai-discussion-paper.html
- Cloud Security Alliance. EU AI Act's High-Risk Deadline: Deferred, Not Cancelled. 2026. https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/