Canada's financial regulator OSFI (Office of the Superintendent of Financial Institutions) is working on binding guidelines for AI use in banks. The reason: rapid AI development and potential misuse threaten financial system stability. OSFI chief Peter Routledge announced this at a Global Risk Institute conference this week.
The essentials
- OSFI is developing a «Safety Code» – a ruleset with high standards for AI security in banking
- Trigger: Anthropic's Mythos model and reports of rogue AI agents interpreting their mandates too liberally
- All five major Canadian banks rank in the top 30 of a global AI adoption benchmark
- Routledge warns of systemic risks: if one bank makes an AI mistake, it can spread through interconnected counterparties
The Mythos Model as Catalyst
The immediate trigger was the release of Anthropic's Mythos model, which Anthropic itself restricts access to. Why? It can identify and exploit software vulnerabilities – an ideal tool for cyberattacks on financial institutions.
«That was an event that signifies the advancing capabilities of frontier AI models, which could be turned for illicit purposes and attack financial institutions. That constituted a major increase in cyber risk»,
Routledge told reporters. Adding to this are reports of autonomous AI agents interpreting their task authorizations too liberally, posing dangers to institutions.
Broad Standards, Not Bans
The planned Safety Code won't be rigid prohibitions. Instead, OSFI aims for broad, high-level standards that establish a baseline of security while preserving a «wide perimeter for innovation». Until now, OSFI had only informally asked banks to «do no harm» – guidance that no longer suffices given emerging risks.
OSFI published a report on AI implications for financial services in 2023. AI has since been listed in the regulator's annual risk outlook.
Uneven Maturity Across Banks
Routledge acknowledged that not all Canadian banks are equally prepared for AI risks. While all five major banks rank in the top 30 of a global benchmark of 50 financial institutions – significant variation exists within the system.
That's a problem: if one bank makes an AI error, the consequences can spread through networked business relationships to other institutions.
«What if one of your counterparties does something wrong? You're connected to your counterparties, and if there's poison at the counterparties, it's flowing through to you as an institution»,
Routledge explained. «Our highest utility is to try and lessen the risk that some poison gets into one institution and scatters throughout the system.»
What This Means for German Banks
Canadian regulation could become a template for European supervisors. While the EU crafts the comprehensive AI Act, Canada shows how financial regulators can target AI risks in banking. German banks should watch how OSFI shapes its Safety Code. The focus on systemic risks and the balance between security and innovation will be key.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




