Skip to main content

OSFI considers minimum AI safety standards for Canadian banks

9 OCTOBER 2026·2 MIN READ·4 SOURCES

Canada’s banking regulator, OSFI, is considering an AI safety code for financial institutions as frontier models and autonomous agents create new risks for the financial system. The proposal could establish minimum standards, but no draft or formally approved release timeline exists.

OSFI considers minimum AI safety standards for Canadian banks

Key takeaways · 4

  • 01

    OSFI is considering a safety code that would set minimum standards for financial institutions using AI.

  • 02

    The proposed code could create a broad safety baseline and perimeter for innovation.

  • 03

    There is no draft or approved release timeline; consultation could begin as early as spring.

  • 04

    OSFI wants a common minimum level of resilience to reduce the chance that one institution’s weaknesses spread to counterparties.

A proposed baseline, not a published rule

OSFI is considering developing an AI safety code for financial institutions, moving beyond its earlier, largely hands-off approach toward minimum standards for how banks use AI.[1] Routledge said the OSFI team was working on creating the code during a Wednesday conference held by the Global Risk Institute.[2] The code could set broad, high-level standards intended to provide a basic level of safety and protection for the financial system, while establishing a wide perimeter for innovation.[2] That framing suggests a system-wide floor rather than a detailed prescription for every AI application; the evidence does not specify what requirements the code would contain.

Risks include attacks and agent behaviour

OSFI’s concerns include frontier models’ potential use in cyberattacks or illicit activity, as well as the ability of autonomous agents to operate with minimal human oversight.[1] OSFI said frontier models can locate and exploit vulnerabilities and enable coordinated, large-scale attacks across systems and third-party ecosystems.[4] These risks matter beyond a bank’s own systems: OSFI has highlighted technology and third-party exposures, and says cross-border dependencies are likely to increase.[3][4] The evidence describes potential risks, not a finding that a particular attack has occurred.

Timing and design remain unsettled

There is no draft of the proposed code and no formally approved timeline for its release.[1] Consultation could come as early as spring, but that is a possibility rather than a confirmed date.[1] Routledge said the code would go beyond OSFI’s previous AI advisory reports and would likely build on its work with the Global Risk Institute and the Financial Stability Board.[1] OSFI’s stated aim is to set a minimum level of safety or resilience across the financial system, reducing the chance that weaknesses at one institution spread to counterparties.[1] For teams planning AI controls, the practical point is to prepare for consultation without treating a proposed standard as settled policy.

Banks face uneven readiness and shared accountability

Canadian banks are generally prepared for AI-related risks, although some are further ahead than others.[1] Separately, Evident ranked all five of Canada’s largest banks among the top 30 of 50 global financial institutions for AI adoption.[2] OSFI says frontier AI can improve productivity and risk management, but institutions should strengthen governance, controls and testing as capabilities advance.[3] Boards and senior management remain accountable for managing AI-related risks.[3] The regulator says Canada’s financial system remains resilient, supported by strong capital, liquidity, governance and risk management.[3] OSFI also plans to prioritize hiring experts in emerging risks, particularly AI and digital technology.[1]

A common safety floor could influence how banks govern, test and oversee AI, including systems supplied by third parties. For professionals, the immediate signal is to keep strengthening controls while watching for consultation: the code’s requirements and timeline are not yet settled.

Why it matters
Daily session

Put this to work — one session a day, built for your industry.

Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.

Start free

How this developed

  1. 9 October 2026

    OSFI considers minimum AI safety standards for Canadian banks

Sources

AI fluency, one session a day, built for your work.