Heinbro

AI in an SFC-Licensed Firm: The Risks, and Why You Need an AI Policy

AI in an SFC-licensed firm in Hong Kong: risks, SFC expectations and the need for an AI policy

AI tools can help a licensed firm with research, summarising and first drafts, but they are not a safe substitute for professional compliance advice, and the SFC now expects firms that use AI to govern it properly. In two circulars, one in November 2024 on the use of generative AI language models and one in June 2026 on AI-enabled cyberattacks, the SFC set out clear expectations: senior management is responsible, using AI for high-risk purposes such as investment advice or research must be notified to the SFC, and the cyber and data risks of AI, including data leakage and prompt override, must be managed. The practical result is that any licensed firm using AI needs written policies and procedures. Use AI as an assistant, never as your compliance adviser, and put a proper AI policy in place.

AI has moved from novelty to everyday tool inside financial firms. That is not a problem in itself, but for an SFC-licensed business it raises two separate issues: the risk of relying on AI for answers it cannot be trusted to give, and the growing set of expectations the SFC has about how firms govern their use of AI. This article covers both, and explains why every licensed firm using AI now needs a policy.

Why relying on AI for compliance answers is risky

It is easy to see the appeal. AI is fast, free and answers in a confident, authoritative tone. But that confidence is not a measure of accuracy, and in a regulated business the gap between the two is where the risk lives. Three problems matter most.

It gets Hong Kong regulation wrong. General-purpose AI is trained on the whole internet, most of which is not Hong Kong regulatory material. In practice it invents or misremembers specific SFC rules and thresholds, relies on out-of-date positions, and quietly imports concepts from US or UK law that do not apply here. An answer that is broadly true elsewhere can be wrong in exactly the particulars that matter.

It cannot be held accountable. An AI tool bears no responsibility for its answer and offers no recourse if it is wrong, so all of the risk sits with the user. The SFC holds the firm and its Responsible Officers accountable for how the regulated business is run. "The AI told me" is not a defence.

It does not know your firm. Even a broadly correct answer is generic. AI has no knowledge of your actual licence conditions, regulated activities or group structure, and regulatory questions usually turn on exactly those details.

The safe rule is simple: treat AI as a starting point, never the final word, and rely on a licensed, accountable adviser for anything that affects your licence, filings or Responsible Officers.

Confidentiality and data risk

Compliance questions are rarely generic, so to get a useful answer people paste in the real material: client details, board papers, draft filings, ownership structures. Anything entered into a public AI tool leaves your control. For a firm handling regulated client information that is a serious risk in its own right, and, as we will see, it is a risk the SFC has now named directly.

What the SFC now expects: governing your use of AI

The SFC has made clear that using AI is not a free-for-all. Two circulars set the direction.

The November 2024 circular on generative AI language models (ref 24EC55) sets out four core principles for licensed corporations that use generative AI: senior management responsibility and governance, AI model risk management, cybersecurity and data risk management, and third-party provider risk management. It treats certain uses as high-risk, in particular using an AI model to provide investment recommendations, advice or research to clients, because a flawed output can lead to unsuitable recommendations. Firms intending to use AI in these high-risk ways are reminded of their obligation to notify the SFC under the Securities and Futures (Licensing and Registration) (Information) Rules.

The June 2026 circular on AI-enabled cyberattacks (ref 26EC32) then reminds licensed firms that AI cuts both ways. It warns that AI is making cyberattacks faster, cheaper and more sophisticated, and that the firm's senior management, including the Manager-In-Charge of Information Technology, is ultimately responsible for managing those risks. Importantly, it states that a firm's own use of AI language models can amplify cyber risks and introduce new ones, specifically naming adversarial attacks, data leakage and system prompt override, and requires these to be addressed within the firm's cybersecurity framework.

Read together, the message is consistent: if your firm uses AI, the SFC expects that use to be governed, secured and, in high-risk cases, notified. That expectation applies whether the AI is built in-house, provided by a group company or a third party, or open source.

Every licensed firm using AI needs a policy

The practical consequence of these circulars is that a licensed firm using AI, even informally, needs documented policies and procedures that show how it governs that use. A workable AI policy typically covers who is accountable, which use cases are permitted and which are off-limits, how high-risk uses are identified and notified to the SFC, how confidential and client data is protected, how third-party AI tools are assessed, and how the cyber risks the SFC has flagged are managed. Without this, a firm that uses AI, however lightly, has a gap that will show up in a review or an SFC mock audit.

In light of the June 2026 circular, Heinbro has prepared an AI policy and set of procedures for licensed firms, aligned to the SFC's expectations. You do not need to be on our Ongoing Regulatory Support service to use it: we can prepare an AI policy for your firm as a standalone piece of work, and help you put the surrounding procedures in place. Every licensed firm needs one, and we can help you navigate it. This sits alongside our wider AML and CFT compliance support.

Where AI genuinely helps

None of this means AI has no place. Used well, it is a capable assistant: summarising a long document, drafting a first version of an internal note, or giving a rough orientation before a professional conversation. The difference between help and hazard is simply whether that use sits inside the policy and controls set out above, rather than happening off the books.

Frequently asked questions

Does the SFC require licensed firms to have an AI policy?

The SFC's November 2024 and June 2026 circulars expect firms that use AI to govern it properly, covering senior management responsibility, model risk, cybersecurity and data risk, and third-party risk. In practice that means documented policies and procedures. A firm using AI without them has a compliance gap.

Do we have to tell the SFC that we use AI?

For high-risk use cases, such as using an AI model to provide investment advice, recommendations or research to clients, firms are reminded of their obligation to notify the SFC under the Information Rules. Other uses still need to be governed and secured, even where notification is not required.

Can I use ChatGPT to answer SFC compliance questions?

It is fine for a rough orientation or to summarise material, but not for decisions. AI gives general information that is sometimes wrong and never tailored to your licence, so confirm anything important with a qualified adviser.

Is it safe to paste company or client documents into AI tools?

No. Material entered into public AI tools leaves your control, and the SFC has specifically flagged data leakage as an AI-related risk to be managed. Keep sensitive documents out of consumer AI tools.

Can Heinbro help us put an AI policy in place?

Yes. We have prepared an AI policy and procedures aligned to the SFC's circulars, and we can tailor one for your firm even if you are not on our Ongoing Regulatory Support service.

Scroll to Top