Published
Key points
- Japan's Financial Services Agency (FSA) published version 1.1 of its AI Discussion Paper on 3 March 2026. It updates version 1.0 (March 2025) with what was learned at the FSA AI Public-Private Forum, held from June to December 2025, and states that it does not set supervisory benchmarks or require specific actions from financial institutions.
- In the Bank of Japan's FY2026 survey (published August 2026, 150 institutions), more than 90% of financial institutions were using or trialling generative AI. In the Bank's 2024 survey, about 30% were using it and about 60% were using or trialling it.
- Version 1.1 groups risk-mitigation measures for customer-facing services into four phases: design and pre-testing, appropriate customer guidance and risk warnings, review and monitoring, and governance. The FSA says it will refer to them when it responds to consultations and enquiries from financial institutions.
- Personal data protection was the challenge most often reported as harder with generative AI. Hallucination is treated as something that will never reach zero, so common practice combines human review, citing the source behind each answer, and keeping logs.
- The FSA says it will encourage firms to follow the existing laws, supervisory guidelines, principles and guidelines that apply whether or not AI is used. The starting point is the existing governance and risk-management framework, reviewed for the risks specific to AI.
How widely Japanese financial institutions use generative AI
In two years, generative AI at Japanese financial institutions has moved from trial to everyday use. In the Bank of Japan's FY2026 survey (published 6 August 2026, covering 150 of its counterparty institutions), more than 90% of financial institutions were using or trialling generative AI. In the Bank's 2024 survey, about 30% were using it and about 60% were using or trialling it.
| Survey | Scope | Main findings |
|---|---|---|
| Bank of Japan (conducted April to May 2024) | Deposit-taking institutions and others | About 30% using generative AI; about 60% including trials; about 80% including those considering it |
| FSA (conducted October to November 2024) | 130 firms across the financial sector | Over 90% using traditional or generative AI in some form; over 70% had deployed document summarisation, translation and proofreading |
| Bank of Japan (FY2026, published August 2026) | 150 counterparty institutions | Over 90% using or trialling generative AI; few present its output directly to customers |
The FY2026 survey finds use spreading from general administrative tasks to core business that draws on customer information. Yet many institutions said their governance, third-party risk management, and safety and security still had room for improvement or were under consideration.
What the FSA AI Discussion Paper version 1.1 is
The AI Discussion Paper is the FSA's review of AI use cases, challenges and practices in the financial sector, together with the direction of its own policy. Version 1.1, subtitled Preliminary Discussion Points for Promoting the Sound Utilization of AI in the Financial Sector, was published on 3 March 2026.
| Item | Detail |
|---|---|
| Published | 3 March 2026 (version 1.0: March 2025) |
| Based on | A survey conducted in October and November 2024 (130 responses), interviews, international discussions and the AI Public-Private Forum |
| AI Public-Private Forum | Four meetings from June to December 2025, bringing together financial institutions, AI model developers, vendors, academics and government ministries |
| Status | Preliminary discussion points for dialogue, not supervisory benchmarks or required actions |
| Language | Full text in Japanese; an English summary is available |
Three additions in version 1.1
- Risk-mitigation measures for customer-facing services, grouped into four phases, which the FSA will refer to when responding to consultations and enquiries
- The view that a securities firm outsourcing AI system development to a systems subsidiary may provide customer conversation data, including non-public information
- The assessment that AI use has entered a phase of concrete initiatives led by top executives, both for efficiency and for new business
The FSA describes its basic stance as technology-neutral: existing laws apply whether or not AI is used. The paper also warns of the risk of not taking up the challenge and falling behind, and says the FSA will work to provide safe harbours by clarifying how regulations apply. For questions on how rules apply, it points to the FSA FinTech Support Desk (2,603 consultations by December 2025).
Generative AI use cases: three types
The paper sorts generative AI use cases by purpose into three types: internal use (operational efficiency), indirect use in customer services, and direct use in customer services. In the 2024 survey most firms were still at internal use, but more than half said they would also consider customer-facing use.
| Type | Typical examples | How it is run |
|---|---|---|
| Internal use (operational efficiency) | Summarising, translating and proofreading documents (deployed by over 70%); searching internal FAQs and rules (about 40%); minutes; coding assistance | Starts with general-purpose generative AI, then moves to RAG over internal rules and documents |
| Indirect use in customer services | Supporting call-centre staff; drafting and reviewing internal approval documents, such as those for lending decisions | Staff check the output before it is used; a human in the loop is mandatory in most cases |
| Direct use in customer services | Some fintech firms already give customers life-planning advice generated by AI | Most institutions remain conservative; by version 1.1, services with a narrowed scope and conditions had begun |
By version 1.1, customer-facing services with a limited scope and conditions were being offered or considered. One case presented at the forum is a service, launched in August 2025, in which an avatar combined with generative AI handles enquiries and procedures such as changes of address. For regional banks, the FSA plans a demonstration project on generative AI.
Enterprise-wide challenges: data, governance, internal rules, people and return on investment
What decides the value of generative AI is less the model than the organisation around it. The paper lists five enterprise-wide challenges: data preparation, building governance, internal rules, specialist talent and training, and return on investment.
Data
About half the respondents named securing or managing training data as a challenge, and some found that RAG did not improve accuracy because outdated internal rules were still among the documents. Forum participants warned that preparing data without a purpose can waste money, and stressed choosing between a data lake and letting AI query individual databases through technologies such as the Model Context Protocol (MCP).
Governance and internal rules
Most firms are linking the departments involved in promotion and control, and some have written AI risk-management rules that define the roles of owners and users, AI-specific risks and the control policy. In one risk-based model, low-risk internal uses are left to front-line judgement against a checklist, while customer-facing and other high-risk uses get prior review by a specialist unit. Many firms drew on version 1.0 of the AI Guidelines for Business. The paper also names agile governance, with fast cycles of risk analysis, goal setting, operation and evaluation instead of rules fixed in advance, as an important approach.
People and return on investment
Firms lack not only AI specialists but also people who can choose and run solutions and bridge the business and IT, and many worry that relying on vendors leaves no know-how in-house. On return on investment, usage-based pricing makes costs grow with use, and benefits are hard to forecast. For proofs of concept, participants suggested tracking KPIs such as users and uses against plan, measuring in short cycles but judging over a longer horizon.
Model risk, third parties and information security
Generative AI models fall under model risk management like any other model. The paper suggests applying the risk-based approach of the FSA's Principles for Model Risk Management (November 2021), for example with a model inventory of the important AI models. Validation is harder because the same input can give different outputs and foundation models come from external providers and change often; reported practices include independent validation before release and continuous performance monitoring.
Choosing third parties, and concentration risk
Few financial institutions can build their own foundation models, and more than 40% of respondents named choosing appropriate third parties as a challenge. The Financial Stability Board's November 2024 report identifies third-party dependency and concentration on particular providers as AI-related vulnerabilities that could increase systemic risk. Reported responses include applying the existing outsourcing framework, open-source foundations to avoid over-reliance on one vendor, and contracts that give the institution the intellectual property in models it commissions.
Information security
- Data leakage: customer or confidential data sent to a cloud AI service, with prompts or outputs used for the vendor's training; services with servers abroad add the management of cross-border data transfer
- Prompt injection: attacks that can make an AI system malfunction or leak confidential information
- Data poisoning and model extraction: tampering with training data or parameters, and attacks that send large numbers of queries to infer a model's internals and extract confidential information
- Shadow IT: staff or departments using external AI services without approval, which raises the risk of leakage and unauthorised access
Many firms already restrict input data and run generative AI in dedicated environments where inputs and outputs can be controlled, yet they also report that guardrails cannot fully stop adversarial input. The paper calls for an integrated response: regular vulnerability assessments and penetration tests carried out together with the legal, compliance and model risk functions, and internal audits according to risk.
Explainability, fairness, hallucination, personal data and regulation
For individual AI systems, the paper discusses five issues: explainability, fairness and bias, hallucination, personal data protection, and regulatory compliance. Personal data protection was the issue that most firms said generative AI had made harder.
Explainability and fairness
When AI informs important decisions such as credit, the institution itself must be able to verify and explain the decision, looking at the training data, the data retrieved through RAG, the prompts, and whether outputs are recorded and monitored. Since full explainability is extremely hard with generative AI, the paper stresses winning the acceptance of customers and staff according to the use case. On fairness, general-purpose models make unfairness from the model itself relatively less likely, but prompts and reference data can still introduce it.
Hallucination
Hallucination is output that is not based on actual data. If reference data is poorly maintained or not kept current, RAG and fine-tuning struggle to suppress it, and a large share of outdated information can make it more likely. Most firms assume it will never reach zero: they build in human review, include source documents in answers, and have the system say so when it finds nothing. The paper also says it is not appropriate to demand that AI must never be wrong.
Personal data protection
The paper records the views that experts gave at the forum on four situations where firms had found the rules unclear.
- Using personal data for training: drawing on a Q&A from the Personal Information Protection Commission, AI development and training may not need to be stated as a purpose of use; for using AI in inference, what matters is whether customers could reasonably anticipate it
- Entering personal data in prompts: manage the generative AI provider as a contractor handling personal data, and confirm that the data provided will not be used for additional training without the institution's instruction
- Outsourcing AI development: where the work includes handling personal data, apply necessary and appropriate oversight of the contractor
- Services with servers abroad: the cross-border transfer rule (Article 28(1) of the Act on the Protection of Personal Information) turns on where the AI provider is located, not the server; the server's location still matters for equivalent-standard systems and for understanding the external environment as a security control
Regulation: issues for securities firms
Version 1.1 also takes up a securities firm feeding customer conversation data into generative AI. The exception to the rule restricting the sharing of non-public information (Cabinet Office Order on Financial Instruments Business, Article 153(1)(vii)) for maintaining and managing electronic data processing systems has long been read to include system development, so when development is outsourced to a systems subsidiary the paper considers it not always necessary to strip non-public information first. Whether an AI recommendation counts as solicitation is judged case by case, as without AI.
What changes with AI agents
An AI agent is an AI system that acts autonomously to achieve a specific goal, with an LLM as the brain that thinks and judges, in the paper's description. The AI Guidelines for Business Ver1.2 from the Ministry of Internal Affairs and Communications (MIC) and the Ministry of Economy, Trade and Industry (METI) define it as an AI system that senses its environment and acts autonomously to achieve a specific goal.
At the forum, participants said agentic AI, in which several agents interact, could automate many processes in financial services. One firm described a platform it is building to manage four things together: agent performance monitoring, lifecycle and cost management, inventory, and permissions. The Bank of Japan's FY2026 survey likewise says that adopting AI agents and frontier AI calls for attention to risk management and governance.
Unlike an AI that only answers, an agent operates other systems through tools. The OWASP Top 10 for LLM Applications 2026 ranks Excessive Agency, where too much functionality, permission or autonomy lets an LLM trigger damaging actions, third, and lists mitigations such as these.
- Limit the tools an agent can call, and the functions in each tool, to the minimum needed
- Give tools the minimum permissions on other systems, and act within the permissions of the user on whose behalf the agent works
- Require a person to approve high-impact actions before they are taken
- Decide whether an action is allowed in the application logic, not by asking the LLM
Implementation: RAG over internal documents, closed-network and on-premises LLMs, evaluation and guardrails
There is no single way to deploy generative AI. In the FSA survey about half the firms used general-purpose generative AI as it is, while others combine it with internal data, use several models for different purposes, run open-source LLMs on their own servers, or reach proprietary services over a dedicated line in a closed network.
| Option | Characteristics | What to check |
|---|---|---|
| Cloud generative AI service (SaaS or API) | Pre-trained models usable with minimal setup; the provider updates the foundation model often | Manage the provider as a contractor handling personal data and confirm no additional training on your data; know where the provider and its servers are located |
| External service over a dedicated line in a closed network | Connects to an external generative AI service through a dedicated line rather than the open internet | Security of the connection point, logging of inputs and outputs, dependence on and concentration in one provider |
| Open-source LLM on premises | Data stays in your own environment; less dependence on a single vendor | Effort to build and operate the environment; the capacity to evaluate and update models yourself |
RAG accuracy depends on the reference data
RAG (retrieval-augmented generation) combines an LLM's text generation with a search of external information to make answers more accurate, without retraining the model. But if outdated rules remain among the documents or the sources are poorly chosen, accuracy does not improve. The basics are version control of documents and removal of withdrawn ones, showing the source with each answer, and having the system say it found nothing when no relevant document exists.
Evaluation and guardrails
The four phases of risk mitigation in version 1.1 double as a design checklist for evaluation and guardrails. Layered guardrails stop definitive claims, such as promises of guaranteed profit, and other inappropriate answers, and they are tested before release.
- Design and pre-testing: limit the answer scope with RAG, choose a more capable LLM, fine-tune and filter outputs; offer a choice of AI or human service, and start with administrative procedures
- Customer guidance and risk warnings: disclose that answers come from generative AI and may be wrong, confirm understanding before moving on, show sources, and allow a switch to a person at any time
- Review and monitoring: keep and monitor conversation logs, follow up where needed, check for biased solicitation with objective metrics, and document recommendation logic for third-party review
- Governance: company-wide structures including senior management, AI literacy down to front-line staff, a risk-based approach, and agile governance across the lifecycle
To test from an attacker's side, identify threats with the ten entries of the OWASP Top 10 for LLM Applications 2026, and follow the process in the Japan AI Safety Institute's red-teaming guide: plan and prepare, plan and run the attacks, then report results with an improvement plan.
A map of the related guidelines
When you turn AI governance into internal rules and controls, it is practical to read the AI Discussion Paper together with the documents below.
| Document | Issuer and date | Use |
|---|---|---|
| AI Discussion Paper version 1.1 (Japanese, with an English summary) | FSA, March 2026 | The FSA's concerns, use cases, practices and risk mitigation for customer-facing services |
| AI Guidelines for Business Ver1.2 (Japanese, with a provisional English translation) | MIC and METI, 31 March 2026 | A unified guideline on AI governance for AI developers, providers and users; a checklist and worksheet (Appendix 7); a definition of AI agents |
| FISC Security Guidelines on Computer Systems for Financial Institutions, 14th edition (Japanese) | FISC, March 2026 | Security standards for systems; the 14th edition revises AI, cybersecurity, post-quantum cryptography and lessons from system failures |
| Principles for Model Risk Management | FSA, November 2021 | A model risk management framework, including a model inventory |
| OWASP Top 10 for LLM Applications 2026 | OWASP, August 2026 | Identifying threats to LLM applications |
| Guide to Red Teaming Methodology on AI Safety (Japanese) | Japan AI Safety Institute; summary version 1.10, March 2025 | Planning evaluation from an attacker's point of view |
According to the AI Discussion Paper, FISC added standard items covering AI in March 2025, and its 14th edition (March 2026) again reflects AI and generative AI guidelines and reports from government and industry bodies. Across government, Japan enacted the AI Promotion Act in May 2025 and adopted the Artificial Intelligence Basic Plan in December 2025.
Putting it into practice
For a financial institution, the use case, the deployment environment, evaluation and guardrails, the inventory of AI models and external services, and the rules and evidence have to be handled as one flow. findn provides IT consulting that covers IT governance frameworks such as the FISC Security Guidelines and COBIT, and AI tool adoption, and system development that covers LLM applications grounded in company data (RAG), AI agents, model selection including Japanese LLMs, private and on-premises deployment, evaluation, guardrails and LLMOps. shachi, findn's IT governance platform for Japanese financial institutions, includes a risk ledger, an IT asset ledger, SBOM/AIBOM and an audit trail.
Questions and answers
- Do financial institutions have to follow the AI Discussion Paper?
- No. The paper says it does not set supervisory benchmarks or the specific actions required of financial institutions, and that the issues in its chapter IV do not call for any specific action immediately. Nor does it mean that AI may not be introduced until every issue it raises has been addressed. Existing laws and supervisory guidelines still apply whether or not AI is used, and the FSA says it will refer to the practices in the paper when responding to consultations, so it is a useful reference when explaining your own controls.
- Can generative AI be used with customers?
- Yes, it is not prohibited. In the 2024 survey most firms did not show generative AI output to customers directly because of the risk of hallucination, and had staff check it first; by version 1.1, services with a narrowed scope and conditions had begun. Version 1.1 organises risk mitigation into four phases: design and pre-testing, customer guidance and risk warnings, review and monitoring, and governance. If the AI recommends products, whether that counts as solicitation under the Financial Instruments and Exchange Act is judged case by case, as it would be without AI.
- How should we choose between a cloud LLM and a closed-network or on-premises LLM?
- Decide by the data involved and the use case; many firms use different models for different purposes. With a cloud generative AI service, manage the provider as a contractor handling personal data and confirm that your inputs are not used for additional training without your instruction. Cross-border transfer rules turn on where the provider is located, but security controls must also consider where the servers are. A dedicated-line connection or an on-premises open-source LLM makes inputs and outputs easier to control, but requires effort to build and run the environment and the capacity to evaluate and update models yourself.
- How should we handle hallucination?
- Assume it will never reach zero and control it through process design. Keep the documents that RAG retrieves up to date, show the source documents in answers, and have the system say so when it finds nothing. Have staff check content before it goes to customers or agents; for customer-facing services, tell customers that the answer comes from generative AI and may be wrong, and keep and monitor conversation logs. The paper also says it is not appropriate to demand that AI must never be wrong.
- What changes with AI agents?
- Agents do not only answer; they operate systems through tools and carry out tasks, so what you must control extends from outputs to actions and permissions. Keep tools and permissions to the minimum, have a person approve high-impact actions, and log what agents do. At the forum, one firm described a platform it is building to manage agent performance, lifecycle and cost, inventory, and permissions together.
Sources
- Publication of AI Discussion Paper (Version 1.1) Opens an external site (Financial Services Agency (FSA), Japan)
- AI Discussion Paper (Version 1.1), full text (Japanese) Opens an external site (Financial Services Agency (FSA), Japan)
- FSA AI Public-Private Forum (Japanese) Opens an external site (Financial Services Agency (FSA), Japan)
- Financial Institutions' Use of Generative AI and Risk Management: Results of the FY2026 Survey (Japanese) Opens an external site (Bank of Japan)
- AI Guidelines for Business Ver1.2 (Japanese, with a provisional English translation) Opens an external site (Ministry of Internal Affairs and Communications (MIC) and Ministry of Economy, Trade and Industry (METI), Japan)
- FISC Security Guidelines on Computer Systems for Financial Institutions, 14th edition (Japanese) Opens an external site (The Center for Financial Industry Information Systems (FISC))
- OWASP Top 10 for LLM Applications 2026 Opens an external site (OWASP GenAI Security Project)
- Guide to Red Teaming Methodology on AI Safety, Version 1.10, summary (Japanese) Opens an external site (Japan AI Safety Institute (AISI))
