Four regulators across Asia-Pacific expect financial institutions to treat customers fairly. None of the four wrote that expectation with an AI model in mind. Each fair-dealing regime assumes, without saying so, that a person made the call: an adviser, an underwriter, a relationship manager whose judgement can be reconstructed after the fact from a file note. AI-driven decisioning does not obviously break that assumption. It quietly removes the person the assumption was built around.
Four Markets, One Unstated Assumption
Singapore is furthest along in noticing the gap, if not yet in closing it. The Monetary Authority of Singapore's Guidelines on Fair Dealing, which took effect on 30 May 2024, set out five outcomes financial institutions must deliver, including suitable products and "competent representatives." The Guidelines on Provision of Digital Advisory Services already place suitability of advice next to "governance and supervision of algorithms" as parallel requirements — an acknowledgement that the two now sit in the same document because they can no longer be assumed to sit with the same person. The 2018 FEAT Principles, still non-binding, go further than most regional guidance by giving customers a channel to question an AI-driven decision. What Singapore has not yet done is fold suitability and algorithmic decisioning into a single conduct obligation. They are adjacent, not merged.
Hong Kong's Securities and Futures Commission is the most explicit regulator in the region about where the old assumption strains. Its 12 November 2024 circular on generative AI language models classifies investment recommendations and advice as a high-risk use case, and requires a human-in-the-loop review of the output. In the same paragraph, the circular concedes that a blanket human-in-the-loop requirement may be impractical for some activities, and allows firms to apply it case by case. That is a regulator admitting, in its own guidance, that the file note cannot simply be preserved by inserting a person back into the loop after the fact. The requirement bends because the assumption underneath it no longer holds cleanly.
Indonesia's Financial Services Authority has taken the ethics-code route rather than the conduct-rule route. Its Code of Ethics Guideline on Responsible and Trustworthy AI was updated in December 2024, adding explicit generative-AI coverage and a new fairness principle. The guideline sits above existing consumer-protection rules for lending and payments rather than inside them, and remains guidance rather than binding conduct law. The one place an AI-specific disclosure duty has actually been written into a regulation is narrower than it sounds: alternative credit-scoring rules require that every credit score distributed to a consumer be accompanied by an explanation of that score. Everywhere else, the pre-AI consumer-protection architecture is expected to stretch to cover AI decisioning without amendment.
Malaysia is the clearest case of the pattern this piece is naming. Bank Negara Malaysia's Policy Document on Fair Treatment of Financial Consumers, revised on 27 March 2024, contains no AI-specific language at all. Its obligations run through "representatives and agents" who must be trained to recognise customer needs and exercise judgement — language written for a person in the room. AI is instead being addressed entirely through a separate track: the revised Policy Document on Risk Management in Technology, which took effect on 28 November 2025 and added a new appendix covering risk governance for AI and other emerging technologies, alongside a separate 2025 discussion paper on AI in the financial sector. Fair treatment and AI governance are two different documents, written by two different logics, that do not reference each other.
The File Note That Does Not Exist
Fair-dealing obligations were never really enforced by the regulation's text. They were enforced by what a compliance team could reconstruct afterwards: the adviser's note on why a product was recommended, the underwriter's rationale for a rating, the relationship manager's record of a conversation about risk appetite. That reconstruction is what makes an obligation like suitability auditable rather than aspirational. Remove the person and the reconstruction does not automatically transfer to the model. A model can log an output. It does not, by default, produce the kind of reasoned account a regulator or a court would recognise as a judgement.
This is not an argument that AI-driven decisions are inherently unfair, or that any institution currently deploying them is falling short of its obligations. Most of the AI-specific guidance surveyed here — Hong Kong's high-risk human-in-the-loop requirement, Indonesia's explainability requirement for every distributed credit score — exists precisely because regulators have already started to notice the gap and are building bridges across it, case by case. The observation is structural: the bridge is being built one use case, one market, and one regulator at a time, and none of the four has yet decided what a fair-dealing file note looks like when there was no human moment to record.
What This Means for Financial Services Boards
The practical risk does not sit in any single jurisdiction's suitability test. It sits in the handoff between an institution's group-level conduct policy, still written around a human decision-point, and its group-level AI deployment, which was built for speed and scale rather than for reconstructing a judgement afterwards. A thematic review that asks to see the file note behind a declined loan, a mis-sold product, or a pricing decision will, in a growing number of cases, find a model output rather than a person's reasoning. Whether that satisfies the fair-dealing obligation in each of the four markets is a live, unresolved question, not a settled one. Hong Kong's own circular says as much.
Most AI conduct reviews still ask whether each market's AI guidance has been implemented. Few ask whether the institution's fair-dealing framework, as written, still assumes a human decision-point that AI has already removed in practice, or who is accountable for closing that gap before a regulator or a complainant does.
Many institutions will only discover which side of that question they sit on the way these gaps are usually discovered: after a complaint, a thematic review, or an audit that happens to ask for the reasoning behind an automated decision rather than the decision itself. The alternative is to ask the question now, while the answer is still a design choice.
Sources
- MAS, Guidelines on Fair Dealing: Board and Senior Management Responsibilities for Delivering Fair Dealing Outcomes to Customers, effective 30 May 2024.
- MAS, Guidelines on Provision of Digital Advisory Services [CMG-G02].
- MAS, Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of AI and Data Analytics, 12 November 2018.
- Securities and Futures Commission of Hong Kong, Circular to Licensed Corporations: Use of Generative AI Language Models, issued 12 November 2024, effective immediately.
- OJK, Code of Ethics Guideline on Responsible and Trustworthy Artificial Intelligence in the Financial Technology Industry, updated December 2024; OJK Regulation No. 29 of 2024 on Alternative Credit Scoring.
- Bank Negara Malaysia, Policy Document on Fair Treatment of Financial Consumers, 27 March 2024; Policy Document on Risk Management in Technology, revised 28 November 2025 (Appendix 9, Emerging Technology Governance); Discussion Paper on Artificial Intelligence in the Malaysian Financial Sector, August 2025.
Editorial Note
This article is a business and organisational commentary, not a legal document. It does not constitute, and must not be relied upon as, legal advice or legal counsel of any kind, and no lawyer-client or advisory relationship is created by reading it.
It is written from a practitioner's vantage point and based on publicly available regulatory instruments and official guidance in English as of mid-2026. It should be read as an architectural diagnosis of organisational design, not as an assessment of any institution's legal position or as commentary on whether good conduct is or is not being discharged in any specific case. Readers and institutions should seek independent legal advice and validate any specific regulatory requirement against the authoritative texts applicable in their jurisdiction before acting on it.