Japan's Financial Services Agency has spent roughly a year and a half building a distinctive answer to a question every financial regulator now faces: how much of AI governance should be written into binding rules, and how much should be left to supervised dialogue. On March 3, 2026, the FSA published version 1.1 of its AI discussion paper, "Preliminary Discussion Points for Promoting the Sound Utilization of AI in the Financial Sector," updating the version 1.0 paper it released on March 4, 2025. Neither version imposes a single new binding obligation on banks, insurers, or fintechs. That is not an oversight. It is the point.

What the discussion paper is

The FSA describes the document as "an initial overview of the current state and challenges of AI utilization in financial institutions," not a rulebook. Version 1.0 grew out of a dedicated survey, the "Survey on Use and Risk Management of Generative AI by Japanese Financial Institutions," which the FSA ran from October 3 to November 15, 2024, and which drew responses from 130 firms, roughly 40 percent deposit-taking institutions, with Financial Instruments Business Operators and insurance companies each accounting for a little over 10 percent. The survey found that generative AI adoption had already outpaced adoption of conventional AI at many respondents, with more than 70 percent of surveyed institutions having introduced general-purpose generative AI for tasks such as summarization and translation, and roughly half using off-the-shelf generative tools largely as supplied rather than customized in-house.

Between June and December 2025, the FSA ran an "AI Public-Private Forum" that brought market participants into direct discussion with the agency on AI utilization, risk management and governance practices, and areas where the application of existing regulation needed clarification. Version 1.1 folds those findings back into the paper, adding, according to Japanese-language commentary on the update, specific considerations for financial institutions using generative AI in customer-facing services. The FSA is explicit that this remains preliminary: it states that "technological advancements and evolving business landscapes may significantly alter the identified challenges," and it is soliciting further comment from stakeholders at a dedicated address maintained by its Fintech and Innovation Office.

What it covers

The paper maps AI use across two broad tiers. Conventional AI techniques, fraud detection, market analysis and forecasting, and marketing, are described as already well established across Japanese financial institutions. Generative AI is treated as the newer and more consequential layer, with institutions moving from internal productivity tools toward customer interaction, business process automation, risk management support, and, in some cases, entirely new financial services built around the technology.

Against that backdrop, the paper catalogs a consistent set of risks: explainability and transparency gaps, bias in model outputs, data quality and management weaknesses, cybersecurity exposure, the potential for AI to be misused in financial crime, and the risk that AI-driven errors could affect financial system stability. It gives particular attention to hallucination, the tendency of generative models to produce confident but false output, framing it as especially difficult to regulate because it originates in the design of the model rather than in any external fraud or misconduct. This risk is most consequential in services offered directly to retail customers, where consumers have limited ability to challenge an automated result; the paper points to life-plan advice as an existing example of generative AI used directly with customers in Japanese finance. Because of that risk, the paper notes that most current generative AI deployments in Japanese finance do not present model output directly to customers; instead, a human reviews and approves it before release, a pattern the FSA refers to as "human in the loop."

A non-binding, dialogue-based approach

The FSA has been unusually direct about its regulatory philosophy for AI. Its stated position is technology-neutral: existing laws and supervisory rules apply to AI-enabled activity in the same way they apply to any other means of conducting financial business, regardless of the technology used to reach a decision. Where the agency judges that AI's particular characteristics genuinely require new treatment, it says it is prepared to revise specific laws, guidelines, or supervisory frameworks, and it has signaled openness to providing "safe harbors" so institutions can pilot AI applications with a clearer sense of the regulatory boundary. The discussion paper format, updated iteratively through the Public-Private Forum rather than issued as a finished standard, is itself a deliberate choice to keep policy adaptable while the technology and the FSA's own understanding of its risks continue to move.

This sits squarely within the structural pattern across Japan's AI-specific policy layer. The AI Promotion Act (Act No. 53 of 2025), Japan's first national AI statute, is a promotion and framework law carrying no penalties or prohibitions, and its only business-facing duty is a non-binding endeavour obligation to cooperate with government AI measures. The joint METI and MIC AI Guidelines for Business, now at version 1.2 as of March 31, 2026, is voluntary, functioning as a de facto standard of care rather than an enforceable rule. The FSA's discussion paper follows the same logic in the financial sector specifically: it maps risk and gathers evidence but leaves enforcement to instruments that were not written with AI in mind.

What actually binds

That last point matters for anyone assessing real legal exposure. The obligations that carry legal force for AI use in Japanese financial services come from law that predates, and does not mention, AI as such. The Act on the Protection of Personal Information governs any AI system that processes customer data, including credit scoring, underwriting, and KYC models, and the Personal Information Protection Commission has separately warned businesses about generative AI service use in a 2023 alert. The Financial Instruments and Exchange Act was amended in 2017, with the amendment taking effect in April 2018, to require firms engaged in algorithmic "High-Speed Trading" to register with the FSA, a binding rule that has applied to a category of algorithm-driven trading activity for several years, independent of the newer AI-specific policy layer. Sector statutes such as the Banking Act and the Insurance Business Act continue to govern the institutions themselves, regardless of whether a given decision is produced by a person or a model. For banks, insurers, and fintechs, the discussion paper is best read as a map of where the FSA's supervisory attention is heading, layered on top of a set of existing statutes that already determine what is actually required.

How this compares to Singapore and Australia

Japan's approach sits closer to Singapore's than to Australia's. The Monetary Authority of Singapore published its FEAT principles, covering fairness, ethics, accountability, and transparency in the use of AI and data analytics, on November 12, 2018. Like the FSA paper, FEAT is non-binding guidance aimed at the financial sector specifically, and it has since been operationalized through the Veritas initiative, which MAS leads in partnership with an industry consortium, rather than through new statute. Both regulators have chosen principles and dialogue over rulemaking, though Singapore's framework is now several years older and more settled than Japan's still-evolving discussion paper.

Australia illustrates a different model. The Australian Prudential Regulation Authority's Prudential Standard CPS 230, Operational Risk Management, took effect on July 1, 2025, replacing the earlier outsourcing and business continuity standards. CPS 230 is not an AI-specific rule, but it is legally binding on APRA-regulated banks, insurers, and superannuation funds, and it captures AI risk indirectly by treating AI vendors as material service providers subject to board-level accountability, oversight, and contractual control. Where Japan and Singapore have chosen to leave AI-specific conduct to voluntary guidance, Australia has chosen to fold AI risk into an existing, binding operational risk regime. The practical effect for a firm operating across all three markets is that documentation built to satisfy CPS 230's third-party risk requirements will typically go further than anything the FSA or MAS currently mandates for AI specifically.

Practical implications for banks, insurers, and fintechs in Japan

For institutions operating in Japan, the discussion paper's non-binding status does not make it safe to ignore. The FSA has told the market plainly that it intends to keep revising this document as it learns more, and its own language, "preliminary," "initial," "may significantly alter", signals that today's discussion points are a reasonable preview of tomorrow's supervisory expectations. Several practical steps follow directly from the paper's content.

First, institutions should treat human-in-the-loop review as the current baseline for any generative AI output reaching a retail customer, since hallucination is hardest to catch precisely where consumers have the least ability to challenge an automated result. Second, governance documentation should map each AI use case against the specific existing statute that actually governs it, APPI for personal data processing, the FIEA registration regime for anything resembling algorithmic trading, sector law for the underlying financial activity, rather than treating the discussion paper itself as the compliance reference point. Third, institutions with a stake in how the FSA's thinking develops should engage directly, whether through the Public-Private Forum process or through the comment channel the FSA maintains for the discussion paper, since the agency has structured this as an iterative, input-driven process rather than a closed consultation. Finally, firms building governance programs that also operate in Singapore or Australia should recognize that Japan's framework will likely remain principles-based and non-binding for the foreseeable future, and should size their AI governance investment to the standard actually being enforced today, which in most cases is APPI, sector law, and ordinary prudential supervision, while tracking the discussion paper as the clearest available signal of where enforceable rules may eventually land.

The FSA's own framing captures its intent well: in the version 1.0 discussion paper, the agency states that "in the course of promoting innovation initiatives, the FSA will ensure that administrative actions do not unduly discourage FIs. We will address any issues through dialogue and other means to facilitate problem-solving." Version 1.1 is the clearest evidence yet that this is a genuinely iterative process, and institutions operating in Japan's financial sector should expect further revisions, rather than a single definitive standard, in the versions still to come.

Primary sources

Related articles