A look at the BMA’s AI consultation paper
The Bermuda Monetary Authority released an August 14 consultation paper for comment titled The Responsible Use of Artificial Intelligence in Bermuda’s Financial Services Sector. The BMA has asked for all comments in response to be received at policy@bma.bm by October 30.
As a technology, cyber and privacy compliance consultant in Bermuda, I find the document extremely helpful in a way that the BMA may not have intended. But first, let’s consider its context.
If you think global privacy law and regulation alignment was a challenge, the diversity of international AI regulation takes the consolidation of diverse compliance requirements to a new dimension of complexity.
Whereas international privacy laws are based on a common group of core principles of conduct, protection and individual rights, global AI regulation runs a very wide gambit of intervention, from mere statements of expected responsible conduct at one end of the spectrum to draconian rules of permitted and restricted AI use at the other end.
More than 70 jurisdictions in the world have introduced some form of AI use policies, guidance or suggested safeguards, and in a few cases in the form of laws concerning the acceptable use of AI. The vast majority of those laws are materially different from one another.
The reason for that confusing international morass is because most jurisdictions have resisted multilateral attempts to build any consensus towards developing a common set of AI use principles and compliance framework.
Even the European Union, which is one of the few jurisdictions to pass AI laws and use regulations, has some derision within its membership when it comes to AI oversight. For example, Denmark, Finland, Italy and Slovenia have each passed their own AI use laws and regulations. France, Germany, Ireland and the Netherlands are each actively developing their interpretation of AI use in their respective corners of the EU.
In the interest of promoting tech innovation, most industrialised nations have taken a softer “suggestive” approach to AI oversight and regulation. Britain is a good example.
Despite the many British government reports concerning the need for AI use oversight over the past eight years, it has decided to take a sector-led approach to AI use regulation. For example, the Financial Conduct Authority in Britain first published its guidance for responsible AI use in 2022 as a discussion paper, and then in 2025 as a guidance note, which was updated in February this year.
Instead of imposing any new laws and regulations, the FCA asserts that the safe and responsible use of AI already falls within the existing framework for prudent operational conduct of its registrants and is already within the purview of existing regulations.
Rather than introducing new AI rules, the FCA explains that its “regulatory approach is to identify and mitigate risks … including from a regulated firm’s reliance on different technologies, and the harms these could potentially create for consumers and financial markets.”
In a welcome collaborative and consultative manner, the BMA’s paper builds on the feedback from its 2025 discussion paper on AI regulation by proposing a technology-neutral prescription for governance oversight that is consistent with its existing cybersecurity, outsourcing and resilience guidance for operational risk management.
In that regard, Part A proposes that the BMA’s regulatory approach will ensure that its use fits within the four walls of the BMA’s existing operational risk management framework, without new licensing requirements, and within the BMA’s usual supervisory activities.
Part B of the paper stipulates that the guidance will apply to both the internal use of AI by registrants as well as to AI services that are provided to registrants by either commercial or affiliated third parties, thus creating an important intersection with the BMA’s outsourcing and resilience regulations.
However, the BMA’s approach does present a bit of a conundrum. If its approach to operational risk management is truly technology-neutral, then why the focus on AI?
In the real world of fintech, information technology systems lie on a continuum of complexity, business dependency, transparency and operational risk. Nowhere along that real life continuum is there a marker for AI. Some comparatively simple IT can pose enormous operational risks, while some software that is marketed as AI is actually very proven, stable and established technology.
For example, the use of simple bots in the form of a web scraper (which have existed for more than 30 years), which gathers competitive market information, may also carry risks of copyright infringement, privacy infringement, denial of service attacks, or even gathering a huge amount of data that is very difficult to assess the reliability of. However, those bots don’t come close to constituting AI.
The BMA’s existing principles of risk evaluation and management, meaningful governance oversight, performance testing, operational monitoring, data and privacy management, cybersecurity and risk proportionality all arguably apply to every form of IT, of which AI is certainly a more identifiable subset along the risk spectrum.
For financial registrants in Bermuda, the potentially transformative capabilities of all intelligent IT systems must be considered within the BMA’s existing framework of responsible use and governance, including AI as it is developing.
When reading the consultation paper, one quickly sees the practical reality that the use of any advanced or complex IT might trigger the additional governance and risk management considerations that are prescribed by the paper, regardless of whether that particular IT constitutes “AI”, per se.
Therefore, perhaps the greatest compliance value of the consultation paper lies in its provision of much more detailed and developed guidance concerning the BMA’s existing views on the prudent, diligent and responsible use of all IT that registrants use in the course of their business, whether it is cloud computing, SaaS solutions, complex data analytics software or true AI applications.
That compliance value can arguably be illustrated by substituting “IT” for “AI” in the paper’s extremely helpful diagram on page 16 titled “Illustrative Process for Applying this Guidance Note to an AI Use case”. Doing so, the content of that diagram seems to equally apply to any IT solution that might be unproven, unique, transformative, complex or will engender a high degree of business reliance.
Rather than the document being seen by registrants as the BMA imposing yet another layer of technology regulation on top of its existing cybersecurity, data protection, disaster recovery, outsourcing and resilience prescriptions, perhaps the consultation should be seen as providing, in a technology-neutral and principles-based manner, a much needed elaboration, explanation and detailed guidance for all complex, transformative, dependency imposing, and operationally risky technologies deployed by registrants, for which AI is but one prevalent and illustrative example.
Not only does the consultation document offer valuable guidance for the prudent management of all IT systems, including AI, we must also trust that the BMA will live by all of the excellent IT development, use, cybersecurity, resilience and operational risk management prescriptions for IT systems that it imposes on its registrants.
• Duncan Card is the CEO of the Advisory Group in Bermuda (www.advisory.bm), which provides technology, cybersecurity, outsourcing, resilience and privacy compliance advice and solutions. This article is not intended to provide any advice
