No spam - just the latest insights!
Join over 30,000 industry professionals who subscribe for free
Subscribe for free!
We'll never share your information or send you spam
Wilfred Ng is a Partner in Bird & Bird’s Corporate and Commercial Department based in Hong Kong. He is a bilingual (Chinese and English) technology, media, telecoms and data protection lawyer experienced in all areas of commercial, transactional, and regulatory work in the TMT sector. Wilfred has more than 10 years’ experience advising clients on a variety of commercial and transactional matters in the sectors of cloud services, financial services, media, telecommunications, retail, healthcare and public institutions. These include negotiating and preparing complex technology contracts, licensing and development arrangements, collaboration, integration and managed services agreements, as well as advising on regulatory considerations arising from the adoption, integration and transfer of technology solutions such as data privacy, data transfer, cybersecurity and localisation issues.
Prior to re-joining the firm, Wilfred was a Senior Legal Counsel with Tencent and assisted in co-founding its International Privacy and Data Protection Team. He advised on all aspects of international data protection and privacy issues arising from the company’s international, ex-PRC presence. Before the in-house role, he was part of Bird & Bird’s Commercial team in Hong Kong, having spent time on secondment to the London office’s Commercial team.
Hwee Yong Neo is a Technology, Media and Telecoms lawyer in our Commercial department in Hong Kong. Neo is also a Co-Chair of the Legal & Professional Committee of the Artificial Intelligence Association of Hong Kong.
Hwee Yong frequently advises international clients and conglomerates on various technology and telecoms related legal, transactional and regulatory matters concerning different types of services, systems and technologies. This includes advising clients on sports betting and gambling issues in various games, competition or promotional arrangements as well as regulatory overviews. Other aspects include artificial intelligence (including generative AI) and the various practical, legal and regulatory matters surrounding the development, use and implementation of AI.
Hwee Yong also advises clients on various commercial transactions, data protection and cybersecurity matters, as well as clients in the financial services and payment services sector concerning regulatory requirements such as payment licences and regulated outsourcing.
Jennifer Lau is a lawyer specialising in data protection, technology, media, and telecommunications within the Commercial Department at Bird & Bird in Hong Kong.
Jennifer’s practice is centred around advising international clients and major corporate groups on a wide array of legal issues, including data privacy, cybersecurity, technology, and market entry strategies across diverse sectors such as media, telecommunications, retail, consumer goods, healthcare, and financial services.
With a keen focus on data protection, Jennifer has assisted clients with the development and implementation of comprehensive data privacy compliance programs. This includes localising suites of data privacy disclosure documents, policies, and data transfer agreements, as well as managing multijurisdictional surveys on data privacy compliance issues. Jennifer’s expertise extends to conducting gap analyses between data protection laws of different jurisdictions, enabling clients to navigate complex regulatory landscapes effectively. Additionally, Jennifer has guided clients through data breach incidents and Privacy Commissioner investigations, ensuring robust responses and compliance.
Rachel Tang is a lawyer specialising in technology, media and telecoms (TMT), and data privacy in Bird & Bird’s Commercial Department in Hong Kong.
Rachel’s practice centres around all things technology-related – she advises leading global groups across the TMT, financial services and healthcare/life science sectors on a range of commercial, transactional and regulatory needs. Rachel regularly advises clients on complex data privacy matters, including multi-jurisdictional data privacy surveys, health checks and remediation work, data breach regulatory reporting and investigations, and novel issues around product rollouts. She also frequently advises clients on cross-border technology transactions, including negotiating software licensing agreements and data protection agreements.
Rachel’s expertise also extends to advising clients on other regulatory matters, such as payment licensing, cybersecurity and legal risks and strategies around the use and implementation of artificial intelligence. She also supports international clients on general commercial matters, including contract negotiations with its vendors.
Financial services (“FS”) is always one of the sectors effecting and affected by digital technologies. With the proliferation of Artificial Intelligence (“AI”) and generative AI (“GenAI”) technology, many FS firms are leading the charge on AI adoption and coming up with innovative ways to integrate this new technology into everyday services.
As a leading financial hub, Hong Kong is no stranger to such AI adoption. In a survey published in April 2025 by the Hong Kong Institute for Monetary and Financial Research, 75% of the 55 financial institution respondents are designing, or have already implemented, use cases for GenAI, with the proportion being even greater among large firms (83%), noting however that the use cases concentrated in internal and non-customer facing applications.
The regulatory rules for the use of AI in the FS sector in Hong Kong stem from a combination of existing laws and new or updated guidance from regulatory authorities such as the Privacy Commissioner for Personal Data (“PCPD”), the Hong Kong Monetary Authority (“HKMA”) and the Securities and Futures Commission (“SFC”).
AI has been a key area of focus for the Hong Kong Government. In its 2025/26 Budget Speech, the Hong Kong Government hailed AI as “at the core of developing new quality productive forces” and announced an AI strategy focused both on developing AI research locally and on applying AI to other industries.
Recent initiatives in the FS sector in Hong Kong include the following:
There is currently no overarching legislation similar to the EU AI Act in Hong Kong governing the use of AI. When considering the use and implementation of AI, FS firms should consider the legal and regulatory implications under existing Hong Kong laws and guidelines published by industry regulators, including in the FS sector.
The key sources of regulations and guidance that will apply to the use of AI in the FS sector are set out below.
(i) Data Protection
Where the use of AI involves the collection and processing of personal data, the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”) is applicable. According to the compliance checks conducted by the PCPD into 60 organisations in February 2025, of which 10 were from the banking and finance sector, 48 organisations – 80% of the total – used AI during their day-to-day operations, and 50% of those used AI systems to collect and/or use personal data. At the same time, the PCPD’s checks found no contravention of the PDPO.
Under the PDPO, a data user (the equivalent term of ‘data controller’ in Hong Kong) must comply with the six Data Protection Principles (“DPPs”) unless otherwise required or permitted. For instance, in the context of AI, data users are required to ensure that their customer and employee privacy policies are sufficient to cover use of personal data for AI training purposes (otherwise, express consent may be required). Further, the DPPs also require data users to adhere to data retention and data security obligations, as well as respecting the rights of data subjects to access and correct their personal data held by the data users.
While a breach of the DPPs is not in itself an offence, it may prompt the PCPD to serve an enforcement notice on the contravening data user, requiring it to take actions to remedy and prevent the recurrence of the contravention. Failure to comply with such an enforcement notice would constitute a criminal offence.
Furthermore, since the PDPO gives data subjects rights of access to and correction of their personal data, the extent to which these rights can be exercised and complied by data users will need to be examined carefully. In practice, to retrieve the original dataset from AI models comes with operational and technical difficulties. To this end, it should also be noted that the PDPO requires data users as a statutory obligation to erase personal data no longer required.
In addition to the DPPs, the PDPO prescribes other statutory obligations on the use of personal data for the purposes of direct marketing and data matching procedures. With the increasing reliance on AI-assisted data analytics processes, user acquisition and profiling solutions, FS firms should pay heed to these statutory requirements when using personal data for AI-enabled processing purposes.
The PCPD has issued non-statutory guidelines in relation to AI:
Both guidance documents contain broadly similar recommendations on compliance with the PDPO (e.g. DPP considerations such as lawful collection, accuracy, security, transparency, and access or correction rights, risk-based methodologies requiring organizations to tailor AI governance and oversight mechanisms according to the nature and severity of potential harms).
Both guidelines also emphasise human oversight requirements as well as similar core ethical concepts (e.g. respectful, beneficial and fair use of AI). The 2024 Guidance additionally recommends requirements such as content labelling and watermarking, developing and implementing an AI Incident Response Plan, additional considerations on integration and hosting (e.g. on prem or cloud-based solutions).
In March 2025, the PCPD also issued the “Checklist of Guidelines for the use of Generative AI by Employees” which aims to help organisations develop internal policies or guidelines for the use of GenAI by employees at work while complying with the PDPO.
(ii) Industry-specific guidelines
Particularly relevant to the FS sector are the guidelines issued by the industry regulators, namely the SFC, HKMA, Insurance Authority (“IA”) and Mandatory Provident Fund Schemes Authority (“MPFSA”).
Guidelines from the SFC
In November 2024, the SFC published the “Circular to Licensed Corporations – Use of Generative AI Models”, addressed to licensed corporations offering services leveraging on AI Language Models (“AI LM”) as well as AI LM-based third-party products. The circular affirms the SFC’s support for the responsible use of AI and AI LMs while warning of new and amplified risks presented by AI LMs (such as hallucination risks) on top of existing AI-related risks (such as the risk of cyberattack).
To mitigate these risks, the circular articulates four “Core Principles”:
Furthermore, the adoption of AI LMs in high-risk use cases are likely to trigger notification requirements under the Securities and Futures (Licensing and Registration) (Information) Rules (Cap. 571S). The SFC recommends that intermediaries discuss such plans with the SFC as early as possible, ideally at the business planning and development stage.
Guidelines from the HKMA
As early as November 2019, the HKMA had already issued circulars setting out high-level principles on the use of AI applications by the banking industry and guiding principles on consumer protection aspects in relation to the use of big data analytics and AI. The high-level principles cover matters including governance, application design and development, as well as on-going monitoring and maintenance. On the other hand, the guiding principles focus on four major areas, namely governance and accountability, fairness, transparency and disclosure, and data privacy and protection.
Since then, the HKMA has periodically issued various circulars and research papers relating to AI. These include:
Separately, depending on the specific use case, the use of GenAI tools in the banking sector may also trigger additional considerations from the perspective of the HKMA.
For instance, companies may need to take into account outsourcing considerations pursuant to the HKMA’s Supervisory Policy Manual SA-2 which is not AI-specific and relates to all outsourcing arrangements where a third party undertakes to provide to an authorised institution a service previously carried out by the institution itself or as part of a new service to be launched by the institution.
The IA and MPFSA
The IA has yet to establish a specific regulatory framework for AI, although it has indicated that putting one in place is a priority target. That said, the use of AI can nevertheless engage the IA’s other regulations. For example, an insurer would have to assess the risks associated with its use of AI pursuant to the IA’s Guidance on Enterprise Risk Management (GL21).
Furthermore, the adoption of AI should be reflected in the insurer’s mandatory inherent risk assessment under the Guideline on Cybersecurity (GL20), with the implementation of AI (among other technologies) for the first time within 12 months being expressly an indicator of risk. If the AI service is provided by a third party, the Guideline on Outsourcing (GL14) may also apply, attracting additional obligations such as those regarding risk assessments and monitoring and control.
On a related note, the International Association of Insurance Supervisors (“IAIS”) issued an application paper on the supervision of artificial intelligence in July 2025, which addresses considerations relating to the use of AI systems in the insurance industry and offers guidance on sound practices. The IA is a member organisation of the IAIS and so is likely to be guided by IAIS materials in addition to the existing approaches by the HKMA and SFC.
Similarly, the MPFSA does not currently have an extensive AI regulatory framework in place. Nevertheless, the MPFSA has issued Guidance on Offering Robo-Advisor Service in response to the partnership between MPF approved trustees and principal intermediaries. Namely, robo-advisor services are generally considered a way of giving regulated advice and hence such services remain subject to the same requirements as applicable to other regulated activities conducted by registered intermediaries. In its guidance, the MPFSA set out six key guiding principles for MPF approved trustees and principal intermediaries to observe: governance and oversight of algorithms, transparency and disclosures of necessary information, provision of suitable advice, risk matching, confidentiality of scheme member information, and complaint handling.
(iii) Guidance and Policy Statement from the Hong Kong Government
The DPO is a government agency which oversees the formulation of policies on digital government, data governance and information technology. In recent years, the DPO has taken various initiatives in the AI space, including:
(iv) Other considerations
As mentioned above, depending on the use case and circumstances on the use of AI, additional considerations based on existing laws in Hong Kong (which are not FS or AI specific) may apply.
For instance, one of the key considerations is on intellectual property in the context of training data. From the start of the AI model lifecycle, the use of copyright protected material to train AI models raises potential copyright infringement issues.
The Hong Kong Government stated that it was in the process of drafting detailed legislative proposals and was aiming to introduce an amendment bill to the Legislative Council within the first half of 2025 regarding a specific copyright exception for text and data mining which would be relevant in the context of AI model training. The exception will cover both commercial and non-commercial uses, but will be subject to restrictive conditions and an “opt-out” option for copyright owners to balance interests.
To assist developers and users of AI systems, the Hong Kong Government has also planned to release a set of guidelines with practical suggestions and specific examples on copyright protection and infringement issues relating to GenAI, as well as the relevant application of the copyright-related legal principles in different scenarios.
Between existing industry enthusiasm and the pro-AI approach adopted by the Hong Kong Government and regulatory agencies, we expect to see a continued increase in the adoption of AI technologies in the FS sector. As GenAI technology further develops and matures, FS firms will be at the forefront of leveraging on the enhanced reliability of AI models, extending its uses cases to both external (customer-facing) and internal (administrative and organisational) applications. Industry regulators have been quick to react, taking the lead in issuing new guidance and recommendations in the face of constantly evolving capabilities. In recent years, Hong Kong businesses have actively adopted disruptive and cutting-edge technologies offered by technology solution providers based in Mainland China, serving as a gateway to the global market. We anticipate the Hong Kong FS sector will continue to be a pioneer and testing ground for such innovations. Sitting at the intersection between Mainland China and the global markets, Hong Kong has certainly manoeuvred itself into a promising position to capitalise on further opportunities in the development, regulation and use of AI.