Logo
FrontierNews.ai

China's New AI Finance Rules: What Banks Must Do Now

China has moved from general digital-finance rules to dedicated AI supervision for banking and insurance, with new requirements for model governance, data security, and human oversight taking effect in 2025 and 2026. Financial institutions operating in the world's second-largest economy now face a multi-layered regulatory framework that encourages AI adoption while imposing strict guardrails on how banks and insurers deploy, test, and monitor artificial intelligence systems.

What Are China's New AI Finance Rules?

In June 2026, China's National Financial Regulatory Administration (NFRA) published the Guiding Opinions on the Safe Development and Application of AI in Banking and Insurance, marking a significant shift in how the country regulates financial AI. This is the first dedicated banking and insurance AI supervision document in China, signaling that regulators have moved beyond generic data-security rules to address AI-specific risks.

The new guidance requires banking and insurance institutions to establish robust governance frameworks covering data security, model risk management, and human oversight mechanisms. For high-risk use cases such as credit approval, underwriting, and trading, institutions must implement enhanced controls. The rules also support prudent adoption of generative AI while imposing safeguards relating to transparency, privacy protection, outsourcing, and cybersecurity.

How Do These Rules Build on Existing Data-Security Laws?

China's AI finance regulatory landscape is not entirely new. Financial institutions have been subject to multiple layers of rules since 2024, including the Personal Information Protection Law (PIPL), Cybersecurity Law, and Data Security Law (DSL). However, the NFRA's December 2024 Measures for the Data Security Management of Banking and Insurance Institutions added teeth to these frameworks by requiring covered institutions to build full-lifecycle data-security frameworks and classify data as core, important, or general.

The December 2024 measures went beyond generic data governance by requiring centralized control of AI model development and application, a gate for external model and algorithm products, and pre-launch review of the reasonableness, legitimacy, explainability, and risk of models and data use. Institutions using AI in business must provide explanations or disclosures about how data affects outcomes and maintain mitigation and fallback arrangements.

The People's Bank of China (PBOC) followed with its own business-area data rule in June 2025, extending sector-specific data governance to payment and settlement, credit reporting, anti-money laundering, cross-border RMB transactions, the interbank market, and financial statistics. For AI-related use cases, the PBOC rules are especially relevant where models draw on payments data, anti-money laundering data, credit information, transaction data, or cross-border RMB data.

Steps for Banks and Insurers to Achieve Compliance

  • Establish Board Accountability: Senior management and board members must take ownership of data security and AI governance, ensuring that compliance is embedded at the highest levels of the organization rather than treated as a technical or operational matter.
  • Classify and Protect Financial Data: Institutions must classify all financial data as core, important, or general, then conduct prior data-security assessments for higher-risk processing activities and maintain centralized control over how data is used in AI models.
  • Implement Model Risk Management: Banks and insurers must establish centralized governance over the entire AI lifecycle, including model development, training, testing, deployment, monitoring, evaluation, and retirement, with pre-launch review of model explainability and risk.
  • Maintain Human Oversight for High-Risk Decisions: For credit approval, underwriting, trading, and other high-risk use cases, institutions must ensure human review and decision-making authority, not relying solely on AI recommendations.
  • Label AI-Generated Content: As of September 2025, all AI-generated or synthetic content must be explicitly and implicitly labeled, including customer-facing financial chatbots, robo-advice interfaces, AI-generated marketing, and fraud alerts, with penalties for deleting or tampering with required labels.
  • Manage Cross-Border Data Transfers: For multinational financial groups, an effective cross-border data strategy must assess whether datasets constitute important data, whether applicable thresholds are triggered, and whether security assessments or standard contractual clauses apply.

Why Is China Encouraging AI in Finance While Tightening Rules?

China's regulatory approach reflects a deliberate balancing act. The NFRA's Implementation Plan for High-Quality Development of Digital Finance in the Banking and Insurance Sectors expressly promotes "AI + finance" initiatives, intelligent approval models, digital infrastructure, and data use. At the same time, regulators are stressing algorithm and model risk, data security, cybersecurity, and protection of consumers and smaller users.

This dual approach encourages banks and insurers to accelerate the development of AI by building enterprise-level AI platforms and establishing centralized governance over the entire AI lifecycle. However, the regulatory trajectory is clear: as AI adoption accelerates, guardrails around data classification, model governance, explainability, personal information protection, algorithmic fairness, outsourcing, and cross-border data use will only strengthen.

For financial institutions operating in China, the message is straightforward. Regulators are not blocking AI adoption; they are requiring that banks and insurers deploy AI responsibly, with transparent decision-making, robust data protection, and human oversight for high-risk decisions. Institutions that build compliance into their AI governance frameworks from the start will be better positioned to navigate the evolving regulatory landscape and maintain trust with customers and regulators alike.