China's financial regulators have moved from general digital-finance policy to granular AI rulemaking, with the National Financial Regulatory Administration (NFRA) issuing the country's first dedicated banking and insurance AI supervision document in June 2026. The Guiding Opinions on the Safe Development and Application of AI in Banking and Insurance require institutions to establish governance frameworks covering data security, model risk management, and human oversight, with enhanced controls for high-risk use cases like credit approval, underwriting, and trading.
Financial institutions in China already operate under a three-layer regulatory structure: horizontal AI and data rules such as the Personal Information Protection Law (PIPL), Cybersecurity Law, and Data Security Law (DSL); sectoral financial-data rules from the NFRA and People's Bank of China (PBOC); and product- and platform-specific controls covering tokenization, payments, and platform algorithms. Regulators are promoting "AI + finance" while imposing guardrails around data classification, model governance, explainability, personal information protection, algorithmic fairness, outsourcing, and cross-border data use. That combination is visible in the NFRA's digital-finance plan, the banking and insurance data-security rules, the PBOC's sectoral data rules, and the State Administration for Market Regulation's 2026 platform-antitrust guidance.
New data-security rules reshape banking and insurance
The NFRA's Measures for the Data Security Management of Banking and Insurance Institutions, effective 27 December 2024, require covered institutions to build a full-lifecycle data-security framework, classify data as core, important, or general, and run prior security assessments for higher-risk processing. For AI deployment, the rules require centralized control of model development and application, a gate for external model products, and pre-launch review of the reasonableness, legitimacy, explainability, and risk of models and data use. Institutions using AI in business must provide explanations or disclosures about how data affects outcomes and maintain mitigation and fallback arrangements.
The PBOC followed with its own Measures for Data Security in PBOC Business Areas, effective 1 June 2025, extending sector-specific governance to payment and settlement, credit reporting, anti-money laundering, cross-border RMB, the interbank market, and financial statistics. These rules matter for AI use cases that draw on payments data, AML data, credit information, or cross-border RMB data.
AI labeling and cross-border data rules
In March 2025, the CAC and other authorities issued the Measures for Labeling AI-Generated Synthetic Content, effective 1 September 2025. The measures require explicit and implicit labeling of AI-generated content and prohibit deleting, tampering with, or concealing required labels. That applies directly to customer-facing financial chatbots, robo-advice interfaces, AI-generated marketing, and fraud alerts.
Cross-border data transfers remain a compliance pressure point. The CAC's March 2024 Provisions on Promoting and Regulating Cross-Border Data Flows relaxed some requirements, but heightened obligations remain for important data, exports by critical information infrastructure operators, and larger-volume personal information transfers. For multinational financial groups training or operating AI models across jurisdictions, a cross-border data strategy must assess whether datasets constitute important data and whether CAC security assessments, standard contractual clauses, or certification requirements apply.
Sector-specific obligations
For banks, the NFRA data-security regime sits at the center of compliance, with board and senior-management accountability, internal data-security ownership, and ex ante assessments for higher-risk processing. The NFRA's digital-finance implementation plan encourages banks to build enterprise-level AI platforms with centralized governance across model development, training, testing, deployment, monitoring, evaluation, and retirement.
Insurers and insurance asset managers fall under the same NFRA data-security measures, so AI in underwriting, claims automation, fraud detection, pricing, and distribution must comply with lifecycle controls, classification rules, outsourcing governance, and personal-information protections. The NFRA's implementation plan also encourages development of data-asset and cybersecurity-related insurance products, a policy signal for insurtech and cyber-insurance product design. For insurers tracking these developments, AI for Insurance covers practical applications across the sector.
Payment institutions operate under the Regulations on the Supervision and Administration of Non-Bank Payment Institutions, effective 1 May 2024. These require licensed operation, prudential governance, and security safeguards, with business systems and backups stored in China and domestic transactions processed, settled, and stored domestically.
Why this matters for finance professionals
The practical takeaway is that AI governance in China now carries hard legal obligations, not just policy guidance. Compliance priorities include classifying data correctly, documenting the legal basis for data processing, assessing model and data risks before deployment, managing third-party providers, maintaining logs and incident response, and being able to explain AI-assisted outcomes in regulated processes. This matters most where AI touches customers, pricing, fraud controls, credit or claims outcomes, and compliance decisions. Teams deploying AI in financial services need to understand both the technical and compliance dimensions of these rules. AI for Finance covers the practical side of AI adoption for finance teams.
Multinational institutions using global data lakes, offshore model training, or centralized customer analytics should test those flows against both the CAC's outbound-data thresholds and the sectoral rules from the NFRA and PBOC. For payment institutions, data localization requirements remain a critical design constraint for AI-enabled products and operational infrastructure.
Your membership also unlocks: