From the journal

Canada's OSFI Issues 2026 Bulletin on Generative and Agentic AI Risks for Financial Institutions

Canada's Office of the Superintendent of Financial Institutions has issued a Technology Risk Bulletin addressing risks that generative and agentic artificial intelligence systems pose to federally regulated financial institutions. The bulletin identifies hallucination, autonomous code deployment, data leakage, and third-party concentration risk as primary threats. It maps these risks to existing OSFI binding guidelines: B-13 on technology and cyber risk, E-21 on operational resilience, and B-10 on third-party risk.

3 min read

Canada's Office of the Superintendent of Financial Institutions (OSFI) issued a Technology Risk Bulletin on the implications of generative and agentic artificial intelligence for technology risk, cybersecurity, and operational resilience at federally regulated financial institutions (FRFIs). The bulletin is supervisory guidance issued under OSFI's mandate in the Office of the Superintendent of Financial Institutions Act. It does not amend OSFI's binding guidelines; instead, it applies existing obligations to AI-specific risk scenarios.

The bulletin maps AI-related risks to three existing binding guidelines. Guideline B-13 (Technology and Cyber Risk Management, effective January 1, 2024) requires FRFIs to maintain sound technology and cyber risk governance; the bulletin identifies hallucination of model outputs and autonomous deployment of AI-generated code as B-13-scope cyber and technology risks. Guideline E-21 (Operational Risk Management, as revised) requires operational resilience controls; the bulletin states that FRFIs must extend those controls to AI-driven processes where agentic systems execute automated decisions without human review at each step. Guideline B-10 (Third-Party Risk Management, 2023) applies when FRFIs procure generative AI capabilities from cloud providers or hosted model vendors.

The bulletin applies to all OSFI-supervised entities: banks and federally chartered trust and loan companies under the Bank Act, domestic and foreign insurance companies under the Insurance Companies Act, and federally regulated pension plans under the Pension Benefits Standards Act, 1985. Banks deploying large language model-based customer service or automated compliance screening tools must assess hallucination risk and implement output validation controls under B-13. Insurers using AI in underwriting or claims processing must address data accuracy and auditability. Any FRFI procuring generative AI through a third-party vendor must conduct enhanced due diligence and ongoing monitoring under B-10.

OSFI characterises agentic AI, which chains decisions and executes actions autonomously across systems, as amplifying existing technology and cyber risks by compressing the interval available for human review. FRFIs that allow agentic AI to deploy code into production environments or execute transactions without human confirmation at each step should reassess their operational resilience controls. OSFI has not specified a compliance deadline for addressing gaps identified against the bulletin's sound practices; institutions are expected to address gaps within existing annual risk management cycles.

Licentium advises financial institutions and fintech operators on AI governance and regulatory compliance in Canadian and international markets. Work we undertake includes B-13 and B-10 gap assessments for AI systems, agentic AI deployment risk reviews, third-party AI vendor due diligence programmes, and regulatory submissions to OSFI.

Source: OSFI, Technology Risk Bulletin: Generative and Agentic Artificial Intelligence: Implications for Technology, Cyber Security, and Operational Resilience (2026)

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.