On 10 June the Financial Stability Board published a consultation report on the responsible adoption of AI, setting out twelve sound practices for financial institutions. Comments closed on 22 July. The final version is expected in October.
It is worth reading for reasons that go beyond the compliance calendar. The FSB is careful to say the document creates no new international standard and prescribes no particular approach to adoption. What it does provide is an unusually concrete account of what an institution should be able to demonstrate about an AI system already running in production, written for boards and senior management rather than for model risk teams alone.
For institutions in Latin America, the timing matters more than it might elsewhere. Brazil’s central bank placed the study of AI risks and impacts on its 2025/2026 regulatory agenda and has signalled that formal rules will not arrive before the end of 2026. That leaves a stretch of several quarters in which the FSB toolkit is the most detailed reference available, and in which the institutions that treat it as a design input will be the ones with evidence already assembled when local supervision catches up.
This edition looks at what the twelve practices actually ask for, particularly the parts written with agentic systems in mind, and what an operation needs in place to answer them without a reconstruction project.
References: FSB, Sound Practices for Responsible Adoption of Artificial Intelligence (consultation report), June 2026; Banco Central do Brasil, regulatory priorities agenda 2025/2026.
AI in Finance: What the Toolkit Asks You to Prove
The twelve practices are organised in three blocks. The first four cover organisation-wide governance. Practices five through ten address risk management across the stages of AI development and deployment. The last two deal with cyber, ICT and third-party risk. Running through all of them are proportionality, clear accountability, data governance, explainability and human oversight.
The section on agentic AI is the one most likely to change how a live operation is configured. The report describes steps institutions are already taking: assigning individual identifiers to AI agents, restricting an agent’s ability to interact with external systems without human approval, and placing controls on the execution of financial transactions, especially where customer funds are involved. Those are configuration decisions, not policy statements. An institution that already knows which version of which agent handled a given conversation, which external endpoints that version was permitted to call, and who approved the release, is most of the way there. An operation whose agents run as an undifferentiated fleet behind a vendor API will spend the fourth quarter reassembling that history from logs and email threads.
The risks the FSB catalogues are familiar to anyone who has taken an AI project through a risk committee: growing dependence on a small number of external providers, correlated market behaviour, cyber exposure, model risk, data quality and governance gaps. Alongside those sit conduct and consumer protection concerns, including unsuitable recommendations and the practical difficulty of supervising a process nobody watches end to end. The direction of travel is consistent elsewhere: in May, the Bank of England, the FCA and HM Treasury issued a joint statement on frontier models and cyber resilience that added no new rules but reinforced existing expectations on governance, vulnerability management and third-party risk.
Regional supervisors are reading the same signals. Brazil’s Financial Stability Committee has flagged AI models capable of probing weaknesses in the financial system, and indicated interest in coordinated public and private work on defensive uses of the same technology.
There is a useful counterweight to the assumption that governance slows institutions down. The first Evident AI Index for Banks in Latin America, published in late July, places Nubank, Itaú Unibanco, Bradesco and Banco do Brasil in the top four positions among twenty institutions assessed, with seven Brazilian names in the set. Nubank stands out for talent density, with over 5% of its workforce in AI-related roles, roughly three times the regional average. Itaú holds the largest absolute number of AI professionals in the sample and is credited with investment in governance and responsible-use controls. Bradesco has expanded internal capability through its Bridge platform and BIA assistants, with AI-supported credit analysis reported to have contributed more than R$1 billion in additional revenue. Banco do Brasil had over 2,000 AI solutions in production by the first quarter, spanning machine learning, generative AI and autonomous agents.
The institutions with the most AI running are also the ones with the most governance around it. Scale and control arrived together, which is the more interesting finding in the index.
A practical way to test readiness before October: pick a date three months back and a specific customer interaction. Can the operation say which agent version was live, what its instructions were, which external systems it was allowed to reach, where personal data was redacted, what happened when the primary model failed, and who signed off on the version that was running? If assembling that takes a week of engineering time, the gap is in the platform rather than in the policy.
References: FSB consultation report, June 2026; Freshfields, AI in financial services: emerging regulatory expectations, June 2026; Bloomberg Professional Services, Global Regulatory Brief, July 2026; Evident AI Index for Banks in Latin America, July 2026; Banco Central do Brasil, Comef minutes, 2026.
Coru® Product: ADI Platform
Most of what the FSB describes as sound practice has to exist in the layer where agents are built, released and observed. ADI Platform, built by Coru®, was designed with that layer as the product.
Identity and isolation. Every agent belongs to an organisation and, where relevant, to a client of that organisation, with tenant isolation enforced server-side. Operator access runs through granular role-based permissions with audit logs, so the question of who changed what and when has an answer that does not depend on memory.
Versioning as a release process. Any edit marks an agent as a draft. Changes are visible before saving, publication produces a numbered version, and versions can be compared side by side or rolled back immediately. Sensitive changes can go out as a canary release to a percentage of traffic while metrics are watched. This is the mechanism that makes “which version was live on that date” a lookup instead of an investigation.
Guardrails in two layers. A mandatory layer that cannot be disabled covers prompt injection, blocking of personal data exfiltration, and detection of mental health crisis signals with an operational alert. A configurable layer lets each institution decide which filters to apply and at what strictness, including topic focus that keeps the conversation inside authorised subjects, with a defined response or an automatic handoff to a human at each limit.
Human approval over what an agent can reach. External actions are declared explicitly: system tools such as transfer to human and end of call, HTTP integrations with the institution’s systems, and MCP servers enabled for that client. What an agent can touch outside the conversation is an enumerated, reviewable list rather than an emergent property of a prompt.
Traceability of every interaction. Full transcripts, AI-generated summaries at close, defined extraction fields per conversation, signed webhook events, and dashboards covering agent operations, cost and security. The evidence a supervisor would ask for accumulates as a by-product of running, without an export project.
Third-party concentration and continuity. Model orchestration is provider-agnostic, with fallback models attempted in order when the primary fails. Deployment can be shared multi-tenant or a dedicated cloud per institution, multicloud by design, with observability separable into another region or provider. Practices eleven and twelve of the FSB toolkit are largely about this kind of dependency.
Managed or self-service, same platform. Institutions that prefer Coru® to build and operate their agents get the loop managed for them. Institutions building their own use the same platform, the same controls and the same audit trail, with no lock-in.
Coru Weekly Picks
Film Recommendation: Margin Call (2011)
A single night inside an investment bank as an analytical result travels from the desk that produced it to the people with authority to act on it. The film is unusually precise about escalation: what each level understands, what gets simplified on the way up, and how much depends on whether anyone in the chain can explain the output they are being asked to approve. Everything the FSB says about accountability and human oversight is easier to operationalise after watching a fictional version of it fail.
Book Recommendation: The Checklist Manifesto, Atul Gawande
Gawande’s subject is what happens in complex, high-stakes work when expertise is abundant and consistency is not. His argument is that written practice, applied at defined moments, outperforms individual judgment under pressure, and that the resistance to it is usually about professional identity rather than evidence. Twelve sound practices from an international body will land as either a paperwork exercise or an operating discipline, and the difference is close to what this book describes.
Between now and October there is time to build the evidence rather than the explanation. Institutions that use the consultation period as a specification will find the final report describes something they already run.
At Coru, we don’t just build technology; we build context. We understand that in Latin America, financial intelligence is inseparable from cultural nuance. By combining global-scale AI with local-market precision, we help your operation turn complex data into decisive, profitable actions.
Explore more at coru.com