In the same eighteen-month window, four financial regulators across Asia-Pacific have each published, updated, or proposed AI, data-governance, or technology-risk requirements that matter directly to financial institutions. Each instrument is internally coherent within its own jurisdiction. What they do not provide is a shared cross-border logic for institutions that operate across all four markets at once.
Singapore's Monetary Authority issued proposed Guidelines on Artificial Intelligence Risk Management for consultation in November 2025. Hong Kong's Monetary Authority has continued to build expectations through circulars and related supervisory materials, including a March 2026 circular requiring board-endorsed digital transformation strategy. Indonesia's Financial Services Authority maintains onshore data-centre and disaster-recovery expectations for banks while the broader Personal Data Protection Law still awaits final implementing regulation. Malaysia, by contrast, does not impose a blanket localisation rule, but combines sector-specific technology-risk expectations with a 2025 adequacy-based framework for cross-border personal-data transfer.
Four Regimes, Four Logics
What matters for a regional institution is not whether any one regime is better than another. It is that each regime assumes a different organising logic: Singapore treats AI as another risk type inside an existing supervisory architecture; Hong Kong accumulates expectations through circulars and adjacent guidance; Indonesia starts from a residency and control foundation that predates most AI-specific discussion; Malaysia permits cross-border movement in principle but requires a defensible judgement under sector-specific technology-risk expectations and broader transfer guidance. The rest of this piece is not a comparison of laws. It is a diagnosis of what happens when a single institution has to live inside all four logics at once without a function whose job is to own the map.
Singapore treats AI governance as an extension of an existing supervisory architecture rather than as a separate legislative project. The Monetary Authority of Singapore issued proposed Guidelines on Artificial Intelligence Risk Management for consultation in November 2025, and as of mid-2026 those Guidelines remain not yet finalised. The proposed instrument sits inside the existing technology and risk-governance framework rather than outside it. It draws on the same logic that has already shaped supervisory expectations around technology risk, outsourcing, and the FEAT principles of fairness, ethics, accountability, and transparency.
The practical significance is not that Singapore has invented a distinct AI regime from scratch. It is that AI is being absorbed into a regulatory system that already assumes named governance, documented controls, board visibility, and operational accountability. That makes Singapore's approach comparatively legible: AI is treated as another risk category, governed through an existing supervisory discipline. Once the proposed Guidelines are finalised, specific expectations will attach to oversight, lifecycle controls, and data governance.
Hong Kong has taken a more fragmented, circular-by-circular approach. Guidance has accumulated since 2019 through successive notices and circulars on issues including big data analytics, consumer protection, and generative AI. Most recently, a circular issued 9 March 2026 (Ref. B1/15C) states that HKMA expects each authorized institution's board of directors to formally oversee and endorse a strategic plan on digital transformation and digitalisation of finance within six months. The deadline is 9 September 2026. Other sectoral regulators maintain their own, only partially aligned expectations. There is no overarching AI legislation comparable to the EU AI Act. The logic is additive: new use cases are addressed through additional supervisory materials, layered onto whichever existing framework is closest.
Even within Hong Kong, authorised institutions face overlapping expectations from HKMA and other sectoral and privacy authorities, each publishing its own guidance on data and technology use; that internal fragmentation is a microcosm of the wider regional picture.
Indonesia starts from a different foundation again. In financial services, questions about AI governance sit on top of a control architecture in which data-centre and disaster-recovery expectations have long carried operational and supervisory weight, particularly for banks, while the broader Personal Data Protection Law introduces a separate layer of consent, processing, and cross-border transfer obligations. As of mid-2026, the law's implementing regulation has completed the Ministry of Law's harmonisation process and awaits presidential approval; it has not yet taken effect. Institutions are operating with a live statute but without the full implementing layer many practitioners expected to have by now.
That makes Indonesia foundational rather than additive. Before an institution can get comfortable with any regional AI use case, it has to determine how the relevant data, infrastructure, and control model fit with local residency and supervisory expectations first. The issue is not that the Indonesian framework is incoherent. It is that cross-border operating models often assume technical flexibility by default, whereas Indonesia forces the residency and control question to be answered much earlier in the design sequence.
Malaysia runs almost the inverse logic to Indonesia. There is no blanket data localisation requirement, and the core issue is not where data must always sit but under what conditions regulated institutions can host, manage, and transfer systems and data while remaining inside sector-specific technology-risk and outsourcing expectations. In financial services, Bank Negara Malaysia's existing framework is best understood as a technology-risk and operational-control architecture, not as a standalone AI regime. Cross-border personal-data transfer now sits under the 2025 Guidelines on Cross-Border Personal Data Transfer, which replaced the old whitelist approach with an adequacy-based assessment model.
That makes Malaysia permissive in principle but conditional in practice. Transfers are possible, but they require a defensible assessment against "substantially similar" and related protection criteria rather than a simple tick-box test. Regulated institutions still need to reconcile those transfer judgments with sector-specific operational and outsourcing controls. The coordination problem, then, is not legal prohibition so much as interpretive stitching: the institution has to connect general transfer guidance and financial-sector control expectations into one operating posture before an AI use case, vendor arrangement, or data flow crosses the border.
The Function That Does Not Exist
Ask a typical regional financial institution who owns AI and data compliance across its Singapore, Hong Kong, Indonesia, and Malaysia operations, and the honest answer is usually that there is no single, named owner in the sense that matters. Each market's compliance function is competent, resourced, and accountable to its local regulator. What is often missing is explicit accountability for the combined picture of how those requirements interact once one AI model, vendor arrangement, or data flow cuts across all four jurisdictions at once.
This is not primarily a resourcing failure. It is an organisational design choice that made sense when financial regulation was still treated largely as a domestic matter. It becomes much harder to defend once regional operations are normal, shared platforms are common, and AI is named or implied as a governance issue on different timelines across multiple markets.
The group-level technology or AI strategy document, written centrally, typically assumes a single governance posture. The reality on the ground is four regulatory logics operating on different philosophies, at different stages of maturity, and on different timetables. The strategy document and the compliance map were written by people who were not in the same room, in exactly the same way this series has already shown at data-architecture level and in something as mundane as device procurement.
A fair objection is that local regulators expect local ownership, not a single regional command centre, and that some institutions have invested heavily in central regulatory architecture already. Both points are true. The argument here is not that local teams should be replaced, or that no one is doing this well. It is that, in many institutions, there is still no clearly defined function whose job is to own the cross-market map and its seams, where AI models, contracts, and data flows cut across regimes.
What This Means for Financial Services Boards
The practical risk is not that any single jurisdiction's requirements will automatically be missed. Local compliance teams are usually well aligned to their own regulator's expectations. The risk sits at the seam: the AI use case approved in Singapore under one risk framework, the vendor contract negotiated under Hong Kong's supervisory logic, the data design that has to satisfy Indonesian residency expectations, and the cross-border transfer assessment in Malaysia that depends on a defensible judgement rather than a simple safe list. Each piece, examined on its own, may be defensible. In many institutions, the combination is rarely examined as a whole, because no one is explicitly tasked with owning that combination.
Seam failures of this kind do not usually announce themselves as cross-jurisdictional governance failures. They surface as something more mundane: a thematic review in one market that turns up a vendor arrangement whose AI and data-handling terms were agreed under a different jurisdiction's logic; an outsourcing audit that exposes a gap between the group-level policy and what the local entity has actually documented; a model risk inquiry that reveals the use case was approved in Singapore but the data pipeline runs through infrastructure governed by Indonesian residency expectations that no one on the Singapore team had mapped. The regulatory inquiry tends to find the symptom. The underlying cause (that no function was accountable for the combined picture) tends only to become visible once someone is asked to explain the whole arrangement on a single sheet of paper.
In practice, the function does not require a large team. It requires a named mandate: someone whose job description explicitly includes accountability for mapping how the institution's AI models, vendor relationships, and data flows interact with all four regulatory logics at once, with the authority to raise inconsistencies before they become incidents.
A board reviewing its AI governance should ask a more precise question than whether the institution is compliant in each market separately. The more useful question is who is accountable for reconciling the institution's posture across the seams where models, contracts, vendors, and data flows cross jurisdictions, and whether that person or function has both the authority and the budget to do it.
Many institutions only discover the gap the way governance gaps are often discovered: after an incident, a regulatory inquiry, or an audit that happens to look across markets rather than within one. The alternative is to ask the question now, while the answer is still a design decision rather than a remediation programme.
Sources
- MAS, Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management, issued 13 November 2025; consultation closed 31 January 2026; not yet finalised as of mid-2026. A related MAS consultation proposing revisions to the Technology Risk Management Notice was issued 10 June 2026, closing 31 July 2026.
- HKMA materials including big-data and AI-related circulars and the 2026 Fintech 2030 strategy, most recently Circular Ref. B1/15C (issued 9 March 2026), stating HKMA's expectation that authorized institutions' boards formally endorse a digital transformation strategy by 9 September 2026; supervisory expectations communicated through circulars and related guidance rather than a standalone AI law.
- Indonesia OJK requirements on data-centre and disaster-recovery expectations for banks, alongside the PDP Law framework; implementing regulation has completed the harmonisation process and awaits presidential approval, not yet in force as of mid-2026.
- Malaysia technology-risk and outsourcing framework in financial services, together with the 2025 Guidelines on Cross-Border Personal Data Transfer replacing the earlier whitelist structure with an adequacy-based model.
Editorial Note
This article is a business and organisational commentary, not a legal document. It does not constitute, and must not be relied upon as, legal advice or legal counsel of any kind, and no lawyer-client or advisory relationship is created by reading it.
It is written from a practitioner's vantage point and based on publicly available regulatory instruments and official guidance in English as of mid-2026. It should be read as an architectural diagnosis of organisational design, not as an assessment of any institution's legal position. Readers and institutions should seek independent legal advice and validate any specific regulatory requirement against the authoritative texts applicable in their jurisdiction before acting on it.