Wilfred Ng
Partner

Wilfred Ng is a Partner in Bird & Bird’s Corporate and Commercial Department based in Hong Kong. He is a bilingual (Chinese and English) technology, media, telecoms and data protection lawyer experienced in all areas of commercial, transactional, and regulatory work in the TMT sector. Wilfred has more than 10 years’ experience advising clients on a variety of commercial and transactional matters in the sectors of cloud services, financial services, media, telecommunications, retail, healthcare and public institutions. These include negotiating and preparing complex technology contracts, licensing and development arrangements, collaboration, integration and managed services agreements, as well as advising on regulatory considerations arising from the adoption, integration and transfer of technology solutions such as data privacy, data transfer, cybersecurity and localisation issues.

Prior to re-joining the firm, Wilfred was a Senior Legal Counsel with Tencent and assisted in co-founding its International Privacy and Data Protection Team. He advised on all aspects of international data protection and privacy issues arising from the company’s international, ex-PRC presence. Before the in-house role, he was part of Bird & Bird’s Commercial team in Hong Kong, having spent time on secondment to the London office’s Commercial team.

Hwee Yong Neo
Lawyer

Hwee Yong Neo is a Technology, Media and Telecoms lawyer in our Commercial department in Hong Kong. Neo is also a Co-Chair of the Legal & Professional Committee of the Artificial Intelligence Association of Hong Kong.

Hwee Yong frequently advises international clients and conglomerates on various technology and telecoms related legal, transactional and regulatory matters concerning different types of services, systems and technologies. This includes advising clients on sports betting and gambling issues in various games, competition or promotional arrangements as well as regulatory overviews. Other aspects include artificial intelligence (including generative AI) and the various practical, legal and regulatory matters surrounding the development, use and implementation of AI.

Hwee Yong also advises clients on various commercial transactions, data protection and cybersecurity matters, as well as clients in the financial services and payment services sector concerning regulatory requirements such as payment licences and regulated outsourcing.

Jennifer Lau
Lawyer

Jennifer Lau is a lawyer specialising in data protection, technology, media, and telecommunications within the Commercial Department at Bird & Bird in Hong Kong.

Jennifer’s practice is centred around advising international clients and major corporate groups on a wide array of legal issues, including data privacy, cybersecurity, technology, and market entry strategies across diverse sectors such as media, telecommunications, retail, consumer goods, healthcare, and financial services.

With a keen focus on data protection, Jennifer has assisted clients with the development and implementation of comprehensive data privacy compliance programs. This includes localising suites of data privacy disclosure documents, policies, and data transfer agreements, as well as managing multijurisdictional surveys on data privacy compliance issues. Jennifer’s expertise extends to conducting gap analyses between data protection laws of different jurisdictions, enabling clients to navigate complex regulatory landscapes effectively. Additionally, Jennifer has guided clients through data breach incidents and Privacy Commissioner investigations, ensuring robust responses and compliance.

Rachel Tang
Lawyer

Rachel Tang is a lawyer specialising in technology, media and telecoms (TMT), and data privacy in Bird & Bird’s Commercial Department in Hong Kong.

Rachel’s practice centres around all things technology-related – she advises leading global groups across the TMT, financial services and healthcare/life science sectors on a range of commercial, transactional and regulatory needs. Rachel regularly advises clients on complex data privacy matters, including multi-jurisdictional data privacy surveys, health checks and remediation work, data breach regulatory reporting and investigations, and novel issues around product rollouts. She also frequently advises clients on cross-border technology transactions, including negotiating software licensing agreements and data protection agreements.

Rachel’s expertise also extends to advising clients on other regulatory matters, such as payment licensing, cybersecurity and legal risks and strategies around the use and implementation of artificial intelligence. She also supports international clients on general commercial matters, including contract negotiations with its vendors.

AI IN FINANCIAL SERVICES

Financial services (“FS”) is always one of the sectors effecting and affected by digital technologies. With the proliferation of Artificial Intelligence (“AI”) and generative AI (“GenAI”) technology, many FS firms are leading the charge on AI adoption and coming up with innovative ways to integrate this new technology into everyday services.

As a leading financial hub, Hong Kong is no stranger to such AI adoption. In a survey published in April 2025 by the Hong Kong Institute for Monetary and Financial Research, 75% of the 55 financial institution respondents are designing, or have already implemented, use cases for GenAI, with the proportion being even greater among large firms (83%), noting however that the use cases concentrated in internal and non-customer facing applications.

The regulatory rules for the use of AI in the FS sector in Hong Kong stem from a combination of existing laws and new or updated guidance from regulatory authorities such as the Privacy Commissioner for Personal Data (“PCPD”), the Hong Kong Monetary Authority (“HKMA”) and the Securities and Futures Commission (“SFC”).

Setting the scene

AI has been a key area of focus for the Hong Kong Government. In its 2025/26 Budget Speech, the Hong Kong Government hailed AI as “at the core of developing new quality productive forces” and announced an AI strategy focused both on developing AI research locally and on applying AI to other industries.

Recent initiatives in the FS sector in Hong Kong include the following:

  • In February 2024, the Hong Kong Government announced the allocation of HK$ 3 billion (approx. US$ 382 million) to implement a three-year AI subsidy scheme (“AISS”), leveraging on a state-of-the-art and largest AI supercomputing centre (“AISC”) in Hong Kong to be operated by Cyberport, Hong Kong’s digital tech hub and AI accelerator. Subsequently, the AISC and AISS were officially launched in Q4 of 2024.
  • In October 2024, the Financial Services and the Treasury Bureau (“FTSB”) issued a policy statement highlighting its continued commitment in promoting the responsible use of AI in the FS sector, including the use of homegrown solution such as InvestLM developed by the Hong Kong University of Technology and Science which will be made available to the FS sector.
  • In December 2024, the HKMA in collaboration with Cyberport and the AISC, launched Hong Kong’s first GenAI sandbox where 70% of the participants were established banks in Hong Kong. Key use cases revolved around enhancing risk management, anti-fraud measures and customer experience.
  • In February 2025, the Hong Kong Government announced the allocation of HK$ 1 billion (approx. US$ 127 million) earmarked to establish the Hong Kong AI Research and Development Institute, which will be formulated by the Digital Policy Office (“DPO”).
  • In February 2025, the Hong Kong Generative AI Research and Development Center (“HKGAI”) (established under the Hong Kong Government’s InnoHK in 2023) launched HKGAI V1 which is Hong Kong’s first large language model (“LLM”). The HKGAI later debuted a series of AI research projects based on the HKGAI V1 LLM at InnoEX 2025, including HKChat, LexiHK, HKPilot, HKMeeting, HKEcoLink and Hum2Song.
  • In April 2025, the HKMA and Cyberport launched the second cohort of GenAI sandbox to accelerate AI in the FS sector. A key addition to the second cohort is the introduction of a platform comprising a series of practical workshops that facilitates early engagements between banks and technology providers called Collaboratory.
  • In May 2025, SFC and the Hong Kong Stock Exchange jointly launched TECH, a channel dedicated to the listing of technology and biotechnology companies.

Hong Kong’s Regulatory Regime

There is currently no overarching legislation similar to the EU AI Act in Hong Kong governing the use of AI. When considering the use and implementation of AI, FS firms should consider the legal and regulatory implications under existing Hong Kong laws and guidelines published by industry regulators, including in the FS sector.

The key sources of regulations and guidance that will apply to the use of AI in the FS sector are set out below.

(i) Data Protection

Where the use of AI involves the collection and processing of personal data, the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”) is applicable. According to the compliance checks conducted by the PCPD into 60 organisations in February 2025, of which 10 were from the banking and finance sector, 48 organisations – 80% of the total – used AI during their day-to-day operations, and 50% of those used AI systems to collect and/or use personal data. At the same time, the PCPD’s checks found no contravention of the PDPO.

Under the PDPO, a data user (the equivalent term of ‘data controller’ in Hong Kong) must comply with the six Data Protection Principles (“DPPs”) unless otherwise required or permitted. For instance, in the context of AI, data users are required to ensure that their customer and employee privacy policies are sufficient to cover use of personal data for AI training purposes (otherwise, express consent may be required). Further, the DPPs also require data users to adhere to data retention and data security obligations, as well as respecting the rights of data subjects to access and correct their personal data held by the data users.

While a breach of the DPPs is not in itself an offence, it may prompt the PCPD to serve an enforcement notice on the contravening data user, requiring it to take actions to remedy and prevent the recurrence of the contravention. Failure to comply with such an enforcement notice would constitute a criminal offence.

Furthermore, since the PDPO gives data subjects rights of access to and correction of their personal data, the extent to which these rights can be exercised and complied by data users will need to be examined carefully. In practice, to retrieve the original dataset from AI models comes with operational and technical difficulties. To this end, it should also be noted that the PDPO requires data users as a statutory obligation to erase personal data no longer required.

In addition to the DPPs, the PDPO prescribes other statutory obligations on the use of personal data for the purposes of direct marketing and data matching procedures. With the increasing reliance on AI-assisted data analytics processes, user acquisition and profiling solutions, FS firms should pay heed to these statutory requirements when using personal data for AI-enabled processing purposes.

The PCPD has issued non-statutory guidelines in relation to AI:

  • In August 2021, the PCPD published the “Guidance on the Ethical Development and Use of Artificial Intelligence” (“2021 Guidance”), which is aimed at assisting developers of AI systems to comply with the PDPO.
  • In 2024, the PCPD issued “Artificial Intelligence: Model Personal Data Protection Framework” (“2024 Guidance”), which is particularly relevant for organisations that procure, implement and use AI systems from third parties (instead of those that develop AI in-house, which is covered in the 2021 Guidance).

Both guidance documents contain broadly similar recommendations on compliance with the PDPO (e.g. DPP considerations such as lawful collection, accuracy, security, transparency, and access or correction rights, risk-based methodologies requiring organizations to tailor AI governance and oversight mechanisms according to the nature and severity of potential harms).

Both guidelines also emphasise human oversight requirements as well as similar core ethical concepts (e.g. respectful, beneficial and fair use of AI). The 2024 Guidance additionally recommends requirements such as content labelling and watermarking, developing and implementing an AI Incident Response Plan, additional considerations on integration and hosting (e.g. on prem or cloud-based solutions).

In March 2025, the PCPD also issued the “Checklist of Guidelines for the use of Generative AI by Employees” which aims to help organisations develop internal policies or guidelines for the use of GenAI by employees at work while complying with the PDPO.

(ii) Industry-specific guidelines

Particularly relevant to the FS sector are the guidelines issued by the industry regulators, namely the SFC, HKMA, Insurance Authority (“IA”) and Mandatory Provident Fund Schemes Authority (“MPFSA”).

Guidelines from the SFC

In November 2024, the SFC published the “Circular to Licensed Corporations – Use of Generative AI Models”, addressed to licensed corporations offering services leveraging on AI Language Models (“AI LM”) as well as AI LM-based third-party products. The circular affirms the SFC’s support for the responsible use of AI and AI LMs while warning of new and amplified risks presented by AI LMs (such as hallucination risks) on top of existing AI-related risks (such as the risk of cyberattack).

To mitigate these risks, the circular articulates four “Core Principles”:

  • Senior management responsibilities: it is the responsibility of senior management to ensure that effective policies, procedures and internal controls are implemented throughout the full lifespan of an AI LM and that there are fit and proper staff for oversight and risk management.
  • AI model risk management: licensed corporations should subject AI LMs to adequate validation, conduct comprehensive end-to-end testing to measure model performance, enact an ongoing review and monitoring regime, and (if the corporation also undertakes model development activities) have a separate model development function. The risk mitigation measures should be proportionate to the magnitude of the risks and the materiality of the impact; for example, high-risk use cases may require a human in the loop as an additional safeguard against hallucinations.
  • Cybersecurity and data risk management: in addition to implementing effective policies, procedures and internal controls, the SFC recommends additional measures, such as conducting periodic adversarial testing and encrypting non-public data at rest and in transit.
  • Third party provider risk management: where the AI LM is provided by an external service provider, the licensed corporation should ensure that the allocation of responsibilities between the parties is clearly defined and that the provider has the necessary skills, expertise, resources and controls to deliver the product or service to an acceptable standard. Additional measures (e.g. supply chain vulnerability and data leakage risk assessments) may be necessary in certain situations, such as when the development or deployment of the provider’s AI LMs involves the use of the provider’s data or software.

Furthermore, the adoption of AI LMs in high-risk use cases are likely to trigger notification requirements under the Securities and Futures (Licensing and Registration) (Information) Rules (Cap. 571S). The SFC recommends that intermediaries discuss such plans with the SFC as early as possible, ideally at the business planning and development stage.

Guidelines from the HKMA

As early as November 2019, the HKMA had already issued circulars setting out high-level principles on the use of AI applications by the banking industry and guiding principles on consumer protection aspects in relation to the use of big data analytics and AI. The high-level principles cover matters including governance, application design and development, as well as on-going monitoring and maintenance. On the other hand, the guiding principles focus on four major areas, namely governance and accountability, fairness, transparency and disclosure, and data privacy and protection.

Since then, the HKMA has periodically issued various circulars and research papers relating to AI. These include:

  • In April 2024, the HKMA published guidance on design, implementation and optimisation of transaction monitoring systems.1Hong Kong Monetary Authority – Insights for Design, Implementation and Optimisation of Transaction Monitoring Systems. See: https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-andcircular/ 2024/20240417e2a1.pdf. The guidance recognises that authorized institutions can use AI to check the quality of data and improve the accuracy of transaction monitoring systems for the purposes of anti-money laundering and countering financing of terrorism, and cites the high-level principles enunciated in the HKMA’s circular in 2019 as reflecting sound industry practices and similar to those formulated by leading overseas authorities.
  • In May 2024, the HKMA issued its insights in relation to manpower management in the age of AI.2Hong Kong Monetary Authority – Manpower Management in the Age of Artificial Intelligence. See: https://www.hkma.gov.hk/eng/news-and-media/insight/2024/05/20240523/. The HKMA urged the banking industry to proactively plan ahead for manpower development to adapt to the forthcoming changes brought by AI, as well as assess the impact of technological advancement and changing customer needs on the requirements of different job roles. The HKMA itself has taken steps to ensure that its policy guidelines are up-to-date, and will embark on research studies in collaboration with the industry in relation to AI.
  • In August 2024, the HKMA issued a circular to all authorised institutions regarding consumer protection in the context of use of GenAI.3Hong Kong Monetary Authority – Consumer Protection in respect of Use of Generative Artificial Intelligence. See: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20241107-1-EN/20241107-1-EN.pdf. Echoing the SFC’s concerns regarding the risk of hallucination, the circular set out additional principles under the four key areas examined in the HKMA’s guiding principles in November 2019.
  • In September 2024, the HKMA issued a circular and annex explaining how the use of AI can improve the effectiveness and efficiency of monitoring money laundering and terrorist financing risks.4Hong Kong Monetary Authority – Use of Artificial Intelligence for Monitoring of Suspicious Activities. See: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20241122-3-EN/20241122-3-EN.pdf and https://brdr.hkma. gov.hk/eng/doc-ldg/docId/getPdf/20241122-4-EN/20241122-4-EN.pdf.
  • In September 2024, the HKMA published a research paper with further recommendations,5Hong Kong Monetary Authority – Generative Artificial Intelligence in the Financial Services Space. See: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20241118-4-EN/20241118-4-EN.pdf. such as implementing the suggested practices across the entire deployment value chain (including pre-deployment, deployment, and post-deployment), and establishing a strong feedback loop to facilitate feedback collection, analysis, and implementation.

Separately, depending on the specific use case, the use of GenAI tools in the banking sector may also trigger additional considerations from the perspective of the HKMA.

For instance, companies may need to take into account outsourcing considerations pursuant to the HKMA’s Supervisory Policy Manual SA-2 which is not AI-specific and relates to all outsourcing arrangements where a third party undertakes to provide to an authorised institution a service previously carried out by the institution itself or as part of a new service to be launched by the institution.

The IA and MPFSA

The IA has yet to establish a specific regulatory framework for AI, although it has indicated that putting one in place is a priority target. That said, the use of AI can nevertheless engage the IA’s other regulations. For example, an insurer would have to assess the risks associated with its use of AI pursuant to the IA’s Guidance on Enterprise Risk Management (GL21).

Furthermore, the adoption of AI should be reflected in the insurer’s mandatory inherent risk assessment under the Guideline on Cybersecurity (GL20), with the implementation of AI (among other technologies) for the first time within 12 months being expressly an indicator of risk. If the AI service is provided by a third party, the Guideline on Outsourcing (GL14) may also apply, attracting additional obligations such as those regarding risk assessments and monitoring and control.

On a related note, the International Association of Insurance Supervisors (“IAIS”) issued an application paper on the supervision of artificial intelligence in July 2025, which addresses considerations relating to the use of AI systems in the insurance industry and offers guidance on sound practices. The IA is a member organisation of the IAIS and so is likely to be guided by IAIS materials in addition to the existing approaches by the HKMA and SFC.

Similarly, the MPFSA does not currently have an extensive AI regulatory framework in place. Nevertheless, the MPFSA has issued Guidance on Offering Robo-Advisor Service in response to the partnership between MPF approved trustees and principal intermediaries. Namely, robo-advisor services are generally considered a way of giving regulated advice and hence such services remain subject to the same requirements as applicable to other regulated activities conducted by registered intermediaries. In its guidance, the MPFSA set out six key guiding principles for MPF approved trustees and principal intermediaries to observe: governance and oversight of algorithms, transparency and disclosures of necessary information, provision of suitable advice, risk matching, confidentiality of scheme member information, and complaint handling.

(iii) Guidance and Policy Statement from the Hong Kong Government

The DPO is a government agency which oversees the formulation of policies on digital government, data governance and information technology. In recent years, the DPO has taken various initiatives in the AI space, including:

  • In July 2024, the DPO issued its Ethical Artificial Intelligence Framework. Initially developed for internal adoption within the Hong Kong Government, the framework was subsequently customised for general reference by the public and is therefore relevant for organisations in the financial services sector to consider. The framework consists of a tailored AI framework for ethical use of AI and big data analytics when implementing AI projects, as well as a template to assess the implications of AI applications.
  • In April 2025, the DPO published its Hong Kong Generative Artificial Intelligence Technical and Application Guideline. The guideline was formulated by the Hong Kong Generative AI Research and Development Center on commission and provides relevant codes and practices on the use of GenAI technologies. The guideline provides industry-specific recommendations for various industries when using GenAI. For the FS sector, the guideline specifically focused on the need for fairness and transparency in the use of GenAI. Furthermore, financial service providers are recommended to allow users to opt into using GenAI knowingly with the option to opt out at any time.

(iv) Other considerations

As mentioned above, depending on the use case and circumstances on the use of AI, additional considerations based on existing laws in Hong Kong (which are not FS or AI specific) may apply.

For instance, one of the key considerations is on intellectual property in the context of training data. From the start of the AI model lifecycle, the use of copyright protected material to train AI models raises potential copyright infringement issues.

The Hong Kong Government stated that it was in the process of drafting detailed legislative proposals and was aiming to introduce an amendment bill to the Legislative Council within the first half of 2025 regarding a specific copyright exception for text and data mining which would be relevant in the context of AI model training. The exception will cover both commercial and non-commercial uses, but will be subject to restrictive conditions and an “opt-out” option for copyright owners to balance interests.

To assist developers and users of AI systems, the Hong Kong Government has also planned to release a set of guidelines with practical suggestions and specific examples on copyright protection and infringement issues relating to GenAI, as well as the relevant application of the copyright-related legal principles in different scenarios.

Looking forward

Between existing industry enthusiasm and the pro-AI approach adopted by the Hong Kong Government and regulatory agencies, we expect to see a continued increase in the adoption of AI technologies in the FS sector. As GenAI technology further develops and matures, FS firms will be at the forefront of leveraging on the enhanced reliability of AI models, extending its uses cases to both external (customer-facing) and internal (administrative and organisational) applications. Industry regulators have been quick to react, taking the lead in issuing new guidance and recommendations in the face of constantly evolving capabilities. In recent years, Hong Kong businesses have actively adopted disruptive and cutting-edge technologies offered by technology solution providers based in Mainland China, serving as a gateway to the global market. We anticipate the Hong Kong FS sector will continue to be a pioneer and testing ground for such innovations. Sitting at the intersection between Mainland China and the global markets, Hong Kong has certainly manoeuvred itself into a promising position to capitalise on further opportunities in the development, regulation and use of AI.