Mayer Brown·FINANCIAL REGULATION

Hong Kong SFC Issues AI-Era Cybersecurity Circular for Licensed Firms

Hong Kong SFC-licensed entities must reassess cyber controls now that the regulator has issued formal AI-era resilience expectations.

The Securities and Futures Commission has published a circular setting out heightened cybersecurity expectations for licensed corporations operating in Hong Kong, with explicit guidance on risks introduced by artificial intelligence. Key takeaways include the need for board-level oversight of AI usage, robust third-party and cloud risk management, incident reporting protocols, and controls addressing AI-specific threats such as model manipulation and data poisoning. Firms should map AI deployments across the enterprise, update cybersecurity policies, and ensure senior management accountability. The circular signals closer supervisory scrutiny and likely follow-up through on-site inspections and thematic reviews, making prompt gap analysis and remediation essential for compliance.

hong-kong-sfcai-cybersecurityregulated-entities

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.