SFC Sets Out Practical AI Governance Priorities for Compliance

What Is It About

The SFC’s AI governance framework is translated into six practical priorities energy and commodity trading compliance may wish to consider, covering AI ownership, human oversight, competence, records, control testing and AI agents.

Why It's Important

As AI becomes embedded in energy and commodity trading workflows, compliance needs to understand where its use affects existing obligations and whether appropriate controls can be demonstrated.

Key Takeaways

Energy and commodity trading compliance teams should identify material AI use, assign accountable owners, define human review points, retain relevant evidence, test controls and govern AI agents through permissions and audit trails.

Introduction

On 18 September 2026, Dr Kelvin Wong, the Chairman of Hong Kong’s Securities and Futures Commission (SFC), delivered a speech (click here) on AI governance, culture and competence. His central message is that organisations can use AI to improve performance, but people must remain accountable for its use. Although the speech addresses boards and listed companies in Hong Kong, it gives Compliance teams a useful framework for examining how AI is approved, used and overseen in their own organisations.

As energy and commodity trading firms introduce AI into existing workflows, Compliance needs to establish where its use affects an obligation the firm already has. Recent regulatory and practitioner discussions offer practical ways to examine ownership, human review, records and the evidence that controls are working.

A recent article (click here) by Fintech Global, a FinTech information services provider, on the future of RegTech illustrates the wider discussion.

Global regulators are placing greater scrutiny on operational resilience, senior management accountability, and algorithmic explainability. This regulatory pressure is pushing firms away from flashy, ‘black box’ solutions and toward systems that are auditable, controllable, and deeply embedded into daily operations.

RegTrail reviews the SFC speech alongside three additional perspectives published in recent months that help translate AI governance principles into practical questions for Compliance teams:

    • Legal and advisory - Reed Smith, a law firm, examines when AI outputs, chatbot exchanges and agent activity may fall within existing recordkeeping and communications obligations. Readers can access the article here.
    • Governance tooling - Theta Lake, a communication surveillance and archiving vendor, considers how firms can capture and oversee AI communications and interactions as their use of AI expands. Readers can access the first article here and the second here.
    • Enterprise AI infrastructure - In the Compliance and AI podcast, TrueFoundry co-founder and CEO Nikunj Bajaj discusses agent auditability, access controls and the growing range of tools that AI agents can use. Readers can access the podcast here.

The SFC speech leads our analysis. The other three sources are practical observations, not regulatory requirements, and each is used to help inform and translate the speech's principles into questions Compliance teams can put to its own firm. Together, they raise a question for Compliance: where does the organisation’s use of AI affect an existing regulatory obligation or control, and can the firm demonstrate how that obligation is met?

An inventory of AI use cases and their owners gives Compliance a practical starting point. It shows where AI is used in regulated work, such as preparing customer communications or investigating surveillance alerts, and who remains responsible for the outcome. Compliance can then assess the obligations affected by each material use case and determine what evidence the firm needs to show that the relevant controls worked.

An AI inventory may reveal risks or control gaps that Compliance cannot resolve alone. The board provides oversight, while business owners decide how AI is used in their activities. Risk and Technology teams assess how the systems operate and identify what could go wrong. Information Security reviews access to sensitive information. Legal and Compliance assess the records questions that arise from each use case. Compliance teams can bring the relevant findings to each team, explain their regulatory significance and help record the decisions made. That gives a firm a clearer account of its approach if a regulator later asks how a use case was governed.

Key themes from the SFC speech

Dr Wong structures his speech around governance, culture and competence.

    • On governance, he calls for boards to understand where AI is being used and who owns material deployments. They should also receive information that helps them assess risks and performance.
    • On culture, he asks boards to consider the value AI should create and the boundaries it must respect.
    • On competence, he stresses that directors need enough knowledge to challenge AI proposals and assess their results (SFC speech, pages 2-5).

The speech is addressed substantially to Hong Kong listed issuers. Its discussion of directors’ duties under Hong Kong’s Companies Ordinance should be read in that context. An energy or commodity trading firm elsewhere can reference the speech to help ask similar questions about its own AI governance. It must assess its answers against the laws and obligations that apply to its activities.

The three supporting perspectives bring these questions closer to Compliance’s day-to-day responsibilities. An AI tool might summarise a trader’s conversations with a broker or operational staff, then place that summary in a surveillance case. Another tool might help a surveillance analyst explain why an alert was closed. Compliance may also use AI to analyse a regulatory obligation before updating a policy or control. In each example, the firm needs to understand how the AI output was checked and used. It must then decide what records its existing obligations require it to keep.

We review the SFC speech and supporting sources through six AI governance priorities:

    • Make material AI use visible and assign an owner to each use case;
    • Define where human judgement and approval are required;
    • Build the competence needed to question and oversee AI use;
    • Determine which AI outputs and interactions must be retained as regulated records or communications;
    • Test whether controls continue to work as AI use expands; and
    • Govern the permissions, actions and records associated with AI agents.

 

Thanks for your interest in our content.
Enjoy the read!

Introduction

On 18 September 2026, Dr Kelvin Wong, the Chairman of Hong Kong’s Securities and Futures Commission (SFC), delivered a speech (click here) on AI governance, culture and competence. His central message is that organisations can use AI to improve performance, but people must remain accountable for its use. Although the speech addresses boards and listed companies in Hong Kong, it gives Compliance teams a useful framework for examining how AI is approved, used and overseen in their own organisations.

As energy and commodity trading firms introduce AI into existing workflows, Compliance needs to establish where its use affects an obligation the firm already has. Recent regulatory and practitioner discussions offer practical ways to examine ownership, human review, records and the evidence that controls are working.

A recent article (click here) by Fintech Global, a FinTech information services provider, on the future of RegTech illustrates the wider discussion.

Global regulators are placing greater scrutiny on operational resilience, senior management accountability, and algorithmic explainability. This regulatory pressure is pushing firms away from flashy, ‘black box’ solutions and toward systems that are auditable, controllable, and deeply embedded into daily operations.

RegTrail reviews the SFC speech alongside three additional perspectives published in recent months that help translate AI governance principles into practical questions for Compliance teams:

    • Legal and advisory - Reed Smith, a law firm, examines when AI outputs, chatbot exchanges and agent activity may fall within existing recordkeeping and communications obligations. Readers can access the article here.
    • Governance tooling - Theta Lake, a communication surveillance and archiving vendor, considers how firms can capture and oversee AI communications and interactions as their use of AI expands. Readers can access the first article here and the second here.
    • Enterprise AI infrastructure - In the Compliance and AI podcast, TrueFoundry co-founder and CEO Nikunj Bajaj discusses agent auditability, access controls and the growing range of tools that AI agents can use. Readers can access the podcast here.

The SFC speech leads our analysis. The other three sources are practical observations, not regulatory requirements, and each is used to help inform and translate the speech's principles into questions Compliance teams can put to its own firm. Together, they raise a question for Compliance: where does the organisation’s use of AI affect an existing regulatory obligation or control, and can the firm demonstrate how that obligation is met?

An inventory of AI use cases and their owners gives Compliance a practical starting point. It shows where AI is used in regulated work, such as preparing customer communications or investigating surveillance alerts, and who remains responsible for the outcome. Compliance can then assess the obligations affected by each material use case and determine what evidence the firm needs to show that the relevant controls worked.

An AI inventory may reveal risks or control gaps that Compliance cannot resolve alone. The board provides oversight, while business owners decide how AI is used in their activities. Risk and Technology teams assess how the systems operate and identify what could go wrong. Information Security reviews access to sensitive information. Legal and Compliance assess the records questions that arise from each use case. Compliance teams can bring the relevant findings to each team, explain their regulatory significance and help record the decisions made. That gives a firm a clearer account of its approach if a regulator later asks how a use case was governed.

Key themes from the SFC speech

Dr Wong structures his speech around governance, culture and competence.

    • On governance, he calls for boards to understand where AI is being used and who owns material deployments. They should also receive information that helps them assess risks and performance.
    • On culture, he asks boards to consider the value AI should create and the boundaries it must respect.
    • On competence, he stresses that directors need enough knowledge to challenge AI proposals and assess their results (SFC speech, pages 2-5).

The speech is addressed substantially to Hong Kong listed issuers. Its discussion of directors’ duties under Hong Kong’s Companies Ordinance should be read in that context. An energy or commodity trading firm elsewhere can reference the speech to help ask similar questions about its own AI governance. It must assess its answers against the laws and obligations that apply to its activities.

The three supporting perspectives bring these questions closer to Compliance’s day-to-day responsibilities. An AI tool might summarise a trader’s conversations with a broker or operational staff, then place that summary in a surveillance case. Another tool might help a surveillance analyst explain why an alert was closed. Compliance may also use AI to analyse a regulatory obligation before updating a policy or control. In each example, the firm needs to understand how the AI output was checked and used. It must then decide what records its existing obligations require it to keep.

We review the SFC speech and supporting sources through six AI governance priorities:

    • Make material AI use visible and assign an owner to each use case;
    • Define where human judgement and approval are required;
    • Build the competence needed to question and oversee AI use;
    • Determine which AI outputs and interactions must be retained as regulated records or communications;
    • Test whether controls continue to work as AI use expands; and
    • Govern the permissions, actions and records associated with AI agents.

 

Compliance Considerations

The six themes below begin with a basic question for Compliance. Does the firm know where AI is being used? Answering that requires more than a list of approved AI use cases. The firm needs to identify material uses and the people responsible for them.

For each material use case, Compliance can identify the affected obligation, agree who reviews the AI assisted work and establish what evidence will show that the review took place.

Where AI agents are deployed, a further question follows. What information and systems can an agent access, and what can it change without approval? An AI agent may do more than produce an answer. It might retrieve trading information or update a surveillance case. Compliance needs to understand what the agent is permitted to access and which actions require human approval. Business owners and Technology teams should define those limits. Compliance can assess where the agent’s actions affect regulatory obligations and escalate material gaps to Risk, Information Security or the board as appropriate.

Theme 1: Make material AI use visible and assign an owner

The SFC speech identifies a gap between use of AI and structured oversight within firms. Citing research by the Hong Kong Chartered Governance Institute, Dr Wong says that almost nine in 10 issuers refer to AI in their disclosures, while fewer than 20% report structured governance frameworks with clear oversight roles, policies and controls across the AI lifecycle. He urges boards to understand material AI deployments and receive information on their owners, risk classifications, performance, incidents and overdue remediation (SFC speech, pages 2–3).

For Compliance, visibility starts with the AI use case. A list of purchased AI products will not explain how people use them. One enterprise tool may help an employee prepare meeting notes while another could help in drafting a customer response. A third tool might aid in reviewing surveillance alerts. Each activity can affect different compliance obligations and call for a different level of review.

A useful AI inventory should describe the activity as well as the system. It should identify a business owner and explain what information the AI can access. It should also show where the output goes and what happens before someone relies on it. These details help Compliance decide which use cases need closer assessment.

An AI inventory based only on procurement approvals can miss tools already in use. Theta Lake’s enterprise guide to AI compliance solutions (click here) points out that AI features may be added to software that a firm has already approved. For example, a communications platform used by traders might introduce automatic meeting summaries without a separate AI purchase. Employees may also use an unapproved tool to draft or analyse work material. Theta Lake recommends identifying these uses so the firm can decide which need further review.

The Theta Lake webinar discussion with Zoom’s CIO (click here) provides another practical example. Zoom’s CIO describes the need to understand, before a new feature is deployed in a regulated setting, whether relevant content and context can be captured and made available for review. One example concerns changes to a participant’s displayed name during a Zoom meeting. A final transcript alone may not explain who appeared under a particular name at a particular point in the conversation. The example shows why firms should check whether their platforms preserve enough context to reconstruct an interaction accurately, including how each participant was identified at the time.

Reed Smith’s speakers describe a related challenge. Employees can create new AI functions within platforms the firm has already approved, without purchasing another tool. A platform approval therefore does not tell Compliance every purpose for which AI is being used. Business owners need a way to report when a new function begins supporting a regulated activity.

Compliance should help to decide which AI use cases require closer review because they affect a regulated activity. Technology and business teams should identify the systems and their owners. They also need a clear way to report new AI uses created within an already approved platform.

Compliance AI governance suggestions:

    • Identify where AI is used in regulated work. Start with trader and broker communications, surveillance investigations and regulatory reporting.
    • Confirm that each material use case has a business owner who can explain its purpose and how staff use its outputs.
    • Give business teams a clear route to report a new AI use or a significant change. For example, a tool approved to draft surveillance summaries should return for review before it is allowed to close alerts.
    • Ask Technology to notify Compliance when an existing platform introduces an AI feature that could affect a regulated workflow.
    • Report material uses and control gaps to senior management. Include incidents and overdue fixes so management can see where action is needed.
Theme 2: Define where human judgement and approval are required

The SFC places human accountability at the centre of AI governance. Dr Wong says boards may delegate functions, but they retain responsibility for oversight. He asks them to establish guidelines that define where human judgement must remain. Boards should also check whether the organisation’s controls support the claims it makes about AI use. In his proposed division of responsibilities, the board sets strategy and risk appetite. Management implements the arrangements, while committees provide focused challenge and assurance (SFC speech, pages 2-4).

For Compliance, “human in the loop” is useful only when the AI workflow identifies what the person must decide. A reviewer might approve a customer communication before it is sent. A surveillance analyst might assess an alert and decide whether to escalate it. Someone preparing a regulatory response might need to check an AI generated explanation against its source material.

These reviews have different purposes. Each needs an accountable owner who knows what to verify. Asking a person to glance at a large volume of AI output offers little assurance that a significant mistake will be found.

In the Theta Lake webinar, a speaker discusses how AI generated content can move from an employee’s working tool into an external communication. For an energy or commodity trading firm, it raises a question about communications with brokers and counterparties. When AI helps to draft a message, who checks its accuracy before it is sent? A trader might need to verify a description of a transaction or a statement about market conditions against the underlying facts with a third-party broker. Surveillance can review the resulting communication, but it may also face a higher volume of AI generated material. Metrigy’s representative notes that people cannot inspect every item individually as volumes grow. Firms therefore need to identify the communications that require review before sending and test whether their surveillance process can handle the rest.

Compliance should explore working with each business owner to identify the point at which an AI output could affect a regulated obligation. An internal note used only to help an employee organise their work may need a basic accuracy check by the employee without Compliance involvement. A regulatory submission needs closer review because the firm is formally reporting information to an external authority. The person signing it off should verify the figures and statements against the underlying records, rather than rely on the AI draft.

The review point changes again when AI is used in trading activity. If a trader uses AI to draft an explanation of a transaction for a broker or counterparty, the trader should check that the message is accurate and does not disclose restricted information before sending it. If a surveillance analyst uses AI to summarise a surveillance alert, the analyst must assess the supporting trading data and communications before deciding whether to close or escalate the case. Compliance’s role is to define these review requirements with the business, explain the regulatory reason for them and check that the firm retains evidence of who made the final decision.

Compliance AI governance suggestions:

    • Set the point at which a person must review or approve an AI-assisted action, such as before a message to a broker is sent or a surveillance alert is closed.
    • Agree with the business owner who must review the output before it is used. Define what that person needs to check, such as whether an AI-drafted transaction explanation matches the trade record.
    • Confirm that the workflow records who reviewed a material output, whether they changed it and what final decision they made.
    • Escalate any use case where no one can say who has authority to approve, reject or override the AI output.
Theme 3: Build the competence to challenge AI use

Dr Wong notes that boards need enough AI knowledge to ask probing questions and recognise material risks. Directors need enough understanding to ask management where AI is used, what it is allowed to do and who remains responsible for its results. They should be able to examine the information they receive about material deployments, including incidents and unresolved control gaps. Dr Wong suggests that this capability should extend across the board rather than sit with one specialist director. He recommends reflecting AI relevant skills in the board skills matrix and developing them through regular briefings, workshops and scenario exercises (SFC speech, pages 3-4).

The same principle applies to Compliance teams. Knowing that a firm uses an approved AI tool tells the team little about the risk of a particular use. If an employee uses it to draft an internal meeting note, Compliance may need to ask whether the note is checked before anyone relies on it. If the tool drafts a response to a counterparty, the questions change: who verifies its claims before the response is sent, and is the final communication retained? An AI agent that can read confidential trading information and update a surveillance case raises further questions about access and authority. Compliance needs to understand each workflow well enough to identify the regulatory obligation it affects, the point where human review is needed and the evidence the firm can produce afterwards.

In the Compliance and AI podcast, TrueFoundry’s Nikunj Bajaj describes what happens when an agent moves beyond answering questions. It may retrieve a document from Google Drive, update a record in Salesforce or ServiceNow, and send information through Slack or Teams. Each system has its own access controls. Bajaj recommends that a firm must be able to trace which tools the agent used and what actions it took. He also raises a risk that appears when AI agents work together. For example, a customer facing agent that is allowed to use information about one counterparty may ask a second agent to search the firm’s records to answer a question. If that second agent has broader access and does not receive the first agent’s restrictions, it could retrieve confidential information about another counterparty. The firm therefore needs to check that access limits still apply when an agent passes a task (and information) to another agent.

Looking ahead at how agentic AI can impact energy or commodity trading firms, consider how an energy or commodity trading firm might use an agent to prepare a response to a counterparty’s question. It retrieves a contract from a shared drive and checks the counterparty record before drafting a reply. Compliance would need to know whether the agent was authorised to access that contract and whether a person reviewed the reply before it was sent. If the agent changed a record, the firm would also need to establish what changed and why. It gives Compliance two practical questions to ask Technology: is the agent’s access limited to what it needs, and can the firm reconstruct what it did? The answers will depend on the agent’s role and the systems it can use.

Board competence also affects how directors judge whether an AI investment is delivering its intended business benefits while keeping risks within acceptable limits. The SFC asks boards to understand what problem an AI investment is intended to solve. They should consider the value it produces and the risks it creates. They also need to know what findings would justify expanding, changing or stopping it. Dr Wong suggests measuring outcomes and control quality, rather than judging progress by the number of pilots or the speed of rollout (SFC speech, pages 4-5).

Compliance can make these measures concrete by linking them to the work AI is doing. If an AI tool drafts responses to counterparties, track how often reviewers correct a material fact before sending them. A high correction rate may mean the tool is being used for tasks it cannot handle reliably, or that it lacks the information it needs. If AI helps triage surveillance alerts, examine cases that surveillance analysts reopen after the tool suggested no further review. Those cases may reveal risks that an overall count of processed alerts would hide. AI incident reporting should show whether a failure was escalated, who owns the fix and whether the same problem occurred again. Management can then judge whether the tool is improving the workflow and whether the controls around its use remain effective.

AI training should prepare people for the decisions they actually make. A board member reviewing an AI surveillance project should be able to ask what problem it solves, how the firm checks for missed cases and what results would cause management to stop or change the deployment.

As another example, a surveillance analyst needs to know where AI enters the surveillance process. If an analyst relies on an AI summary to close an alert, the reviewer should understand what source material the analyst can check and what evidence of that decision is kept. The business owner of the surveillance AI use case needs to recognise when a technology change requires fresh approval. A tool initially approved to summarise alerts, for example, presents a different risk if it is later allowed to close them automatically. Training should make those boundaries clear and tell staff how to report a proposed change before it goes live.

Compliance AI governance suggestions:

    • Use examples from regulated activities, if applicable, when training staff to recognise AI risks.
    • Ask system owners to explain what information the AI receives and what it produces.
    • Establish whether a system can take actions on its own and ask its owner to explain the limits on those actions.
    • Run practical exercises to check how staff detect and respond when AI gives an incorrect answer or an agent takes an unauthorised action.
    • Report recurring errors and control failures to those deciding whether a use case should continue.
Theme 4: Determine which AI outputs and interactions must be retained

The SFC speech says boards need reliable information about material AI use so they can challenge decisions and follow up when problems arise. Consider a firm that uses AI to summarise due diligence documents for a new commodity trading counterparty. If staff rely on that summary when approving the relationship, the firm needs to know which documents were reviewed and what checks the approver performed. A firm should retain the onboarding decision and supporting evidence required under its applicable rules and policies. The SFC speech does not set out recordkeeping rules for AI-generated material. Compliance should therefore work with Legal to decide whether the summary, the prompt used to produce it, earlier drafts or any agent logs must also be retained. The answer depends on how the material was used and the requirements that apply to the firm’s activities (SFC speech, pages 3-5).

Reed Smith’s discussion also addresses this topic. Its speakers explain that existing recordkeeping and communications rules continue to matter when firms use AI. The status of a particular output depends on its content and use. An internal working draft may raise a different question from a chatbot exchange with a customer.

The speakers also highlight gaps that can arise during AI tool approval. An AI review committee may examine privacy risks and supplier contracts but leave whether the firm can retain and retrieve AI generated material when needed for supervision or an investigation unanswered. Compliance should raise that question before any AI tool is approved, then assess the answer against the firm’s specific recordkeeping obligations.

In the Theta Lake webinar, Zoom’s CIO notes that AI can create new content from a conversation rather than simply transcribe what was said. A transcript of a trader’s conversation with a broker and an AI-generated account of that conversation may therefore need separate consideration. Compliance should assess how each is used before deciding what the firm must retain.

Theta Lake’s enterprise guide describes ways to capture the prompts employees submit to AI tools and the responses they receive. It also discusses bringing interactions from different tools into a format that investigators can search, with enough surrounding context to understand what happened. Consider a Compliance officer using AI to draft a response to a regulator. A firm should identify what the applicable rules require it to retain, including the final response and any supporting evidence that forms part of the required record. Compliance and Legal should decide whether any AI prompts, draft responses or review history also need to be kept. Technology can then test whether the chosen tools capture that material and allow the firm to retrieve it.

An AI records assessment should follow information from its source to its final use. A firm should know when a person changed AI generated material and which version was ultimately relied on. Compliance and Legal should then decide which versions and supporting material the firm must retain. Technology can confirm how staff will be able to retrieve them. Where the status of a prompt or intermediate draft is uncertain, the firm should document why it chose to keep or discard it.

Compliance AI governance suggestions:

    • Identify where AI-generated content is used in a communication with a broker or counterparty, a regulatory submission or a compliance decision.
    • Decide in conjunction with discussion with Legal, what must be retained for each material use case. Consider the final output and any prompts or drafts that played a material part in the decision.
    • Test whether staff can find and produce the required material using a real example from the workflow.
    • Ask Technology whether the tool preserves enough context to explain how an output was produced and who reviewed it.
    • Document the reasons for retaining or not retaining intermediate material. Reassess the decision if the use case or the tool’s capabilities change.
Theme 5: Test whether controls work as AI use expands

The SFC asks boards for more than just policy statements. They need information that shows whether AI is working as intended and allows them to challenge management when it is not. Dr Wong suggests reporting validation results, which show how a system performed when tested against real tasks. Boards should also see how often it produces errors and how often staff override or correct its output. These measures can reveal problems that adoption figures alone would miss. Dr Wong warns that incentives focused only on speed or cost may discourage people from reporting those problems early (SFC speech, pages 3-5).

In the Theta Lake webinar, a speaker observed that surveillance alerts at one large customer almost doubled after AI use expanded across the firm. He links the increase partly to the greater volume of AI generated content and to staff sending some outputs externally without checking them. Compliance should check whether its surveillance team can handle more alerts as employees use AI to create more communications, without delaying or drowning out the review of serious concerns.

A firm introducing AI into communications or surveillance should test the effect on its existing controls. Employees may rely on AI generated content when speaking to customers or recording an interaction. Compliance needs to know whether significant errors are being identified. If the firm also uses AI to monitor that content, it needs to understand what the monitoring system misses. It should examine whether false alerts overwhelm analysts and whether they have enough context to assess a genuine concern.

The participant name change example mentioned in Theme 1 also provides a practical control test. Where participants identity matters to a supervisory review, Technology can check whether the meeting record preserves relevant displayed name changes. Compliance can explain what identity information the review needs. It can then assess whether that history is needed to understand who communicated what during a supervisory review or investigation.

In the same discussion, Smarsh's Robert Cruz raises a practical question about AI providers. If they hold information the firm needs, how will the firm retrieve it for a regulatory request or litigation? Compliance can test this using a completed AI assisted communication with a broker or counterparty. Ask the relevant team to find the final message and any AI material the firm has decided to retain, then export it in a form that shows when it was created and who sent or approved it. If some material sits with the AI provider, test that retrieval route too. The exercise may reveal a gap between a policy that says records are available and what staff can actually produce.

Compliance should check controls where AI affects a regulated activity. For example, it could sample messages to brokers that traders drafted with AI and confirm that the required review happened before they were sent. It could then check whether the final messages were retained and monitored under the firm’s surveillance arrangements. If the firm cannot show who reviewed a message or retrieve it later, the control gap needs an owner and a deadline for correction. Reporting material gaps gives senior management evidence to consider before expanding the use of AI for that use case.

Compliance AI governance suggestions:

    • Agree with Risk and Technology which AI enabled activities to examine and what evidence should show that the controls worked.
    • Where AI supports surveillance, use past cases with known outcomes to check whether it identifies activity that required investigation. Review false alerts to see how much work they create for investigators.
    • Select a completed AI assisted surveillance case. Check whether the investigator can see the underlying information and explain the decision reached. Confirm that any required review took place.
    • Ask the relevant teams to retrieve and export the records the firm is required to keep.
    • Give failed checks to the responsible business owner. Track corrective action and escalate material or overdue gaps through existing governance channels.
Theme 6: Govern agents through permissions, actions and evidence

The SFC speech does not discuss AI agents specifically. Dr Wong does, however, urge firms to assign ownership to material AI uses and identify where human judgement must remain. Those principles raise further questions when an AI agent can act through a connected system. An agent might update a counterparty record, while a chatbot that only drafts text leaves the action to an employee. A firm needs to decide who authorises the agent’s actions, when a person must approve them and how it will establish what the agent did.

Reed Smith’s speakers discuss the difficulty of applying existing oversight and records arrangements when agents act with less immediate human involvement. One speaker describes reviewing an application where roughly half the users were AI agents, yet no one could explain why the agents had access or what they were doing. An agent is software that can take steps in other systems, often without a person approving each step. In a trading firm, that might mean updating a counterparty record or changing the status of a compliance case. If the action is later questioned, the firm needs to identify which agent took it, what it changed and who was responsible for its use. Reed Smith’s speakers suggest keeping audit trails for higher risk agents to help establish those facts. Whether a particular log must be retained as a regulatory record still depends on the applicable rules and how the agent is used.

In the Compliance and AI podcast, TrueFoundry’s Nikunj Bajaj explains that an agent may ask another tool or agent to complete part of a task. That creates a risk if the second system can access information that the first agent was not permitted to see. Technology is responsible for setting those access limits and keeping a record of the actions taken. Compliance’s role is to identify where an agent could affect a regulated activity, such as changing a counterparty record or a surveillance case. It can then ask Technology to show how access is restricted, which actions require human approval and how the firm would investigate an unexpected change.

The Theta Lake webinar considers what could happen when a customer’s AI agent interacts with a firm’s agent. Metrigy’s representative asks what compliance concerns might arise if the customer's agent makes a mistake. The discussion does not settle who would be responsible however it does show why a firm should examine such interactions before treating them as ordinary customer conversations. Before enabling that exchange, the business owner and Technology should establish what the firm’s agent may communicate or change. Compliance and Legal can then assess whether the resulting communication is subject to supervision or recordkeeping requirements.

For an energy or commodity trading firm, the controls should reflect what the agent can actually do. A meeting-scheduling agent may only need access to calendars and permission to send invitations. Its owner should check that it cannot expose confidential meeting details or invite the wrong external recipient. Compliance would not ordinarily need to approve each invitation, although meetings with brokers may still need to take place through approved communication channels. An agent that changes a counterparty record has a greater effect because other staff may rely on that information. Its changes may need review before they take effect and a record of who authorised them. If an agent helps investigate surveillance alerts, Compliance should define what it may prepare and which decisions must remain with an investigator. Business and Technology teams should implement those limits and be able to show how they work.

Firms exploring AI agents should identify each material use case and assign a human business owner with clear responsibility for what the agent may do. Compliance should identify where an agent could affect a regulated activity and ensure that use goes through the appropriate approval process. If the agent changes a record or influences a regulated decision, Technology should be able to show what it accessed and actioned. Compliance and Legal can then determine what review and evidence the firm needs under its applicable obligations.

Compliance AI governance suggestions:

    • Identify agents that can affect a regulated activity, such as drafting a message to a broker or changing the status of a surveillance case.
    • Ask the business owner and Technology to show what each material agent is permitted to access and change.
    • Agree which actions need human approval before they take effect. Technology should explain how the agent can be stopped if it acts outside those limits.
    • Work with Legal to decide what evidence is needed to explain a material action later. Check that the firm can retrieve it.
    • If the firm’s agent exchanges information with a broker’s or counterparty’s system, assess whether the exchange is subject to a communications or recordkeeping obligation. Agree who reviews material exchanges and how the required record can be retrieved.

Want to read more?