NewsAI regulationFinancial sectorCybersecurity

Canada's Financial Regulator Tightens AI Guardrails for Banks

Canada's financial regulator OSFI is developing a «Safety Code» for artificial intelligence use in the banking sector. The move is driven by emerging risks from powerful AI models and autonomous agents.

All 5 major Canadian banks rank in top 30 of global AI adoption

Canada's Financial Regulator Tightens AI Guardrails for Banks

Canada's financial regulator OSFI (Office of the Superintendent of Financial Institutions) is working on binding guidelines for AI use in banks. The reason: rapid AI development and potential misuse threaten financial system stability. OSFI chief Peter Routledge announced this at a Global Risk Institute conference this week.

The essentials

  • OSFI is developing a «Safety Code» – a ruleset with high standards for AI security in banking
  • Trigger: Anthropic's Mythos model and reports of rogue AI agents interpreting their mandates too liberally
  • All five major Canadian banks rank in the top 30 of a global AI adoption benchmark
  • Routledge warns of systemic risks: if one bank makes an AI mistake, it can spread through interconnected counterparties

The Mythos Model as Catalyst

The immediate trigger was the release of Anthropic's Mythos model, which Anthropic itself restricts access to. Why? It can identify and exploit software vulnerabilities – an ideal tool for cyberattacks on financial institutions.

«That was an event that signifies the advancing capabilities of frontier AI models, which could be turned for illicit purposes and attack financial institutions. That constituted a major increase in cyber risk»,

Routledge told reporters. Adding to this are reports of autonomous AI agents interpreting their task authorizations too liberally, posing dangers to institutions.

Broad Standards, Not Bans

The planned Safety Code won't be rigid prohibitions. Instead, OSFI aims for broad, high-level standards that establish a baseline of security while preserving a «wide perimeter for innovation». Until now, OSFI had only informally asked banks to «do no harm» – guidance that no longer suffices given emerging risks.

OSFI published a report on AI implications for financial services in 2023. AI has since been listed in the regulator's annual risk outlook.

Uneven Maturity Across Banks

Routledge acknowledged that not all Canadian banks are equally prepared for AI risks. While all five major banks rank in the top 30 of a global benchmark of 50 financial institutions – significant variation exists within the system.

That's a problem: if one bank makes an AI error, the consequences can spread through networked business relationships to other institutions.

«What if one of your counterparties does something wrong? You're connected to your counterparties, and if there's poison at the counterparties, it's flowing through to you as an institution»,

Routledge explained. «Our highest utility is to try and lessen the risk that some poison gets into one institution and scatters throughout the system.»

What This Means for German Banks

Canadian regulation could become a template for European supervisors. While the EU crafts the comprehensive AI Act, Canada shows how financial regulators can target AI risks in banking. German banks should watch how OSFI shapes its Safety Code. The focus on systemic risks and the balance between security and innovation will be key.

Sources

Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.

Share
← All articles

All analyses are based on i6eal's own measurements or on clearly labelled sources. Figures are snapshots and may change; corrections are disclosed transparently.