Select Page
Quantum update 67: Hong Kong SFC Chairman Delivers Keynote on People, Standards and AI at HKSI Institute | June 2026

Hong Kong SFC Chairman Delivers Keynote on People, Standards and AI at HKSI Institute

On 6 March 2026, the SFC published keynote remarks by Chairman Dr Kelvin Wong titled People, Standards and AI: Strengthening Hong Kong's Financial Backbone, delivered at the Hong Kong Securities and Investment Institute Chairman's Cocktail. The Chairman characterised HKSI as part of Hong Kong's regulatory backbone, noting that its Licensing Examination for Securities and Futures Intermediaries is the gateway to an SFC licence.

  • He confirmed the launch of the expanded GenA.I. Sandbox++ jointly across four regulators, the SFC, the HKMA, the Insurance Authority and the Mandatory Provident Fund Schemes Authority, providing a supported environment for firms to test AI applications responsibly.
  • The Chairman identified three AI risks, bias, opaque ‘black box’ decisions, and operational vulnerabilities, and set three priorities for HKSI: raising competence on complex products including digital assets, nurturing professional judgment beyond examination knowledge, and broadening the talent pipeline. He concluded that people, not rules alone, keep markets fair.

(Source: https://www.sfc.hk/-/media/EN/files/COM/Speech/CHs-speechHKSI-Institute-Chairmans-Cocktailspeech-in-printed-version-clean.pdf)

 

Australian Federal Court Orders Binance Australia Derivatives to Pay AUD 10 Million Penalty for Wholesale Client Misclassification

On 27 March 2026, the Federal Court of Australia ordered Oztures Trading Pty Ltd, trading as Binance Australia Derivatives, to pay a pecuniary penalty of AUD 10 million by order of Justice Moshinsky, following admitted contraventions of the Australian Corporations Act 2001 (Cth). The proceedings, brought by the Australian Securities and Investments Commission in the Victoria Registry (VID1381/2024), concerned the misclassification of 524 retail clients as wholesale clients over a nine-month period.

  • Of 611 account holders during the offer period (7 July 2022 to 21 April 2023), 524 did not provide sufficient information to confirm they were not retail clients under section 761G of the Corporations Act — over 85 per cent of the Australian client base. The largest group, 460 clients, was incorrectly classified as meeting the Sophisticated Investor Test.
  • Because the clients were misclassified, Oztures issued no Product Disclosure Statement, made no Target Market Determination, and maintained no compliant internal dispute resolution system. Binance admitted contraventions of sections 912A(1)(a), (b), (f) and (g), 994B(1) and 1012B(3), with combined client harm estimated at approximately AUD 12.56 million in trading losses and fees.
  • ASIC Chair Joe Longo framed the outcome as a clear warning to global financial services entities establishing operations in Australia, emphasising that all firms — including those dealing in crypto and digital assets — must operate compliant client onboarding systems from the outset. Oztures had paid approximately AUD 13.1 million in compensation and voluntarily cancelled its AFS licence in April 2023.

(Source: https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-055mr-binance-australia-derivatives-ordered-to-pay-10-million-penalty-for-onboarding-failures-causing-millions-in-client-trading-losses/)

 

Hong Kong SFC Reprimands and Fines Impression Investment HK$2 Million Under Section 194 SFO

On 9 April 2026, the SFC announced disciplinary action against Impression Investment Limited and its former responsible officer under section 194 of the Securities and Futures Ordinance. Impression, a licensed Type 9 (asset management) corporation, was reprimanded and fined HK$2 million, and former director, responsible officer and manager-in-charge Mr Liu Shan was banned for eight months, from 2 April to 1 December 2026.

  • The case concerned staff personal account dealing across three Cayman-incorporated funds during the period January 2016 to March 2021. The SFC found Liu had conducted over 2,500 personal transactions without pre-trade approval, including 601 executed on the same day as, or within one trade day before, dealing in the same securities for the fund he managed, alongside breaches of IPO-participation and 30-day holding-period requirements under the Fund Manager Code of Conduct.
  • The SFC found Impression had written staff dealing policies that were neither implemented nor enforced before 2021, with a complete absence of effective monitoring controls. Impression's failures were attributed to Liu's neglect of his duties as responsible officer and senior management. The action reinforces the supervisory expectation that written policies must be implemented and enforced in practice.

(Source: https://apps.sfc.hk/edistributionWeb/gateway/EN/news-and-announcements/news/enforcement-news/doc?refNo=26PR55)

 

Hong Kong HKMA Grants First Stablecoin Issuer Licences to Anchorpoint Financial and HSBC

On 10 April 2026, the Hong Kong Monetary Authority announced the grant of stablecoin issuer licences under the Stablecoins Ordinance to Anchorpoint Financial Limited and The Hongkong and Shanghai Banking Corporation Limited, with effect from the date of announcement. The HKMA simultaneously activated the Register of Licensed Stablecoin Issuers on its website.

  • The Stablecoins Ordinance establishes a dedicated licensing regime for issuers of fiat-referenced stablecoins, with the HKMA as licensing and supervisory authority, addressing reserve asset management, redemption rights, anti-money laundering, governance, operational resilience and consumer protection. The grants operationalise the Ordinance from a framework into a live supervisory regime.
  • The dual grant, a non-bank fintech entity alongside a global banking institution, signals the regime’s openness across the institutional spectrum. Chief Executive Eddie Yue framed the licences as an important milestone for Hong Kong’s digital asset development, with both licensees expected to launch business in the coming months. The HKMA reminded the public to transact only through regulated channels and to remain vigilant to fraud.

(Source: https://www.hkma.gov.hk/eng/news-and-media/press-releases/2026/04/20260410-4/)

 

Hong Kong SFC: ASPIRe in Action — VA Licensing Bill, CrypTech, UAE MoU and Tokenised Fund Trading on VATPs

On 20 April 2026, the SFC published the keynote ASPIRe in Action: Advancing Hong Kong's Digital Asset Journey, delivered by Dr Eric Yip, Executive Director of Intermediaries, at the Hong Kong Web3 Festival 2026. Marking 14 months since publication of the ASPIRe Roadmap, he tracked delivery across its five pillars under the guiding principle of ‘same business, same risks, same rules’.

  • Dr Yip confirmed that virtual asset trading platforms can now offer secondary on-platform trading of tokenised SFC-authorised funds, describing Hong Kong as among the first major jurisdictions to provide a clear pathway for retail TradFi products to use Web3 infrastructure. He flagged the planned 2026 VA licensing bill covering dealing, advisory, management and custody, anchored to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, as the top legislative priority.
  • He confirmed the January 2026 Memorandum of Understanding with the Capital Market Authority of the United Arab Emirates as a template for cross-border joint supervision, noted that the CrypTech supervisory-technology initiative is moving to proof of concept, and indicated a forthcoming market consultation on Financial Resources Requirements for digital assets. The three core risks driving this work are money laundering, cybersecurity and market manipulation.

(Source: https://www.sfc.hk/-/media/EN/files/COM/Speech/Speech–EDINT-at-Web3-Festival-2026SEclean.pdf)

 

Hong Kong SFC Secures HK$1 Billion Shareholder Compensation Agreement with PwC Hong Kong Over China Evergrande Audit Failures

On 23 April 2026, the SFC announced that it had reached agreement with PricewaterhouseCoopers Hong Kong for shareholder compensation of HK$1 billion regarding false financial statements of China Evergrande Group for FY2019 and FY2020. The SFC concluded there was market misconduct under section 277 of the Securities and Futures Ordinance. It is the first occasion on which auditors of a defunct listed company are providing compensation to minority shareholders.

  • The SFC found that China Evergrande prematurely recognised property-sale revenue, overstating audited annual revenue by RMB213.9 billion (44.79 per cent) for FY2019 and RMB350.2 billion (69.03 per cent) for FY2020, such that reported profits should in fact have been substantial losses. The agreement with PwC HK is concluded without admission of liability, with compensation allocated through an independent administrator.
  • The SFC made six findings on the auditor's role, including failures of independence, professional scepticism and site-inspection procedures. The action was supported by cooperation with the Ministry of Finance and the China Securities Regulatory Commission, reflecting the cross-border machinery now applied to Hong Kong-listed issuers with Mainland operations.

(Source: https://apps.sfc.hk/edistributionWeb/gateway/EN/news-and-announcements/news/enforcement-news/doc?refNo=26PR62)

 

Hong Kong SFC Launches Section 214 SFO Action Against Former China Automotive Directors Over Fictitious Mainland Trade Payments

On 29 April 2026, the SFC announced the commencement of legal proceedings against former senior executives of China Automotive Interior Decoration Holdings Limited and its subsidiary in the Court of First Instance under section 214 of the Securities and Futures Ordinance. The action targets Mr Wong Ho Yin, a former director, and Ms So Lung Ying, former general manager of subsidiary Giant Faith Holdings Limited.

  • The SFC alleges that, between December 2019 and January 2020, Wong signed cheques for three payments totalling HK$14.6 million, recorded as remittances to a Mainland company for the purchase of food products, which the SFC contends amounted to misappropriation of corporate funds rather than settlement of genuine trade payables.
  • The SFC seeks director disqualification orders against both individuals, section 214 permits disqualification for up to 15 years, and a HK$14.6 million compensation order against Wong. The proceedings sit alongside the Evergrande and Impression Investment actions, signalling sustained regulatory pressure on listed-company governance and related-party cash flows.

(Source: https://apps.sfc.hk/edistributionWeb/gateway/EN/news-and-announcements/news/enforcement-news/doc?refNo=26PR66)

 

Australia APRA Issues AI Risk and Governance Expectations for Banks, Insurers and Superannuation Trustees

On 30 April 2026, the Australian Prudential Regulation Authority, the prudential supervisor responsible for the stability, competitiveness and efficiency of Australia's financial system, issued the APRA Letter to Industry on Artificial Intelligence (AI), addressed to all APRA-regulated entities, including banks, insurers and superannuation trustees. The letter follows targeted supervisory engagement conducted in late 2025 with selected large financial institutions to assess the extent of AI adoption and the prudential risks arising from it. It sets out APRA’s observations on governance, cyber security, operational resilience, supplier concentration and assurance, together with supervisory expectations for Boards and accountable executives in relation to AI deployment and oversight.

Rising AI Adoption Across Australia’s Financial Sector

  • APRA observed that AI adoption is accelerating across regulated industries as entities integrate AI into software engineering, claims triage, fraud detection, customer interaction, loan processing and productivity enhancement.
  • The regulator acknowledged that AI presents great opportunity for productivity and efficiency, and that a failure to adopt AI may place businesses at a strategic disadvantage.
  • APRA cautioned that the same technology has the potential to create new risks and escalate existing challenges, identifying differing levels of maturity in governance, risk management and operational resilience across entities, and concluding that assurance practices are not keeping pace with the scale, speed and complexity of AI.

APRA Observations on Board Oversight and AI Governance

  • APRA found that, although Boards demonstrated strong interest in AI's potential benefits and strategic imperatives, many Boards are still developing the technical literacy required to provide effective challenge on AI-related risks and oversight.
  • The regulator noted an overreliance on vendor presentations and summaries without sufficient examination of key AI risks such as unpredictable model behaviour and the impact on critical operations.
  • APRA set a minimum expectation that Boards maintain sufficient understanding and literacy with respect to AI in order to set strategic direction and provide effective challenge and oversight.
  • APRA further expects Boards to oversee an AI strategy that is consistent with the entity's risk appetite and tolerance settings.

Cyber Security and the AI-Driven Threat Landscape

  • APRA observed that AI adoption is materially changing the cyber threat landscape for regulated entities, identifying common attack pathways including prompt injection, data leakage, insecure integrations, exploit injection, and the manipulation or misuse of autonomous AI agents.
  • The regulator noted that identity and access management capabilities have not yet adjusted to non-human actors such as AI agents, and that AI-assisted software development is straining the effectiveness of change and release management controls.
  • APRA identified gaps in security testing programmes, delays in remediation activities such as patching and configuration management, and increasing use of enterprise AI tools outside approved control frameworks.
  • The letter indicated that entities may consider strengthening privileged access management, timely patching, hardened configurations, automated vulnerability discovery, penetration testing, and controls over agentic and autonomous workflows.

AI Lifecycle Management and Operational Governance

  • APRA observed that some entities continue to treat AI risk as just another technology, an approach that may not fully account for the distinct characteristics of predictive systems, adaptive model behaviour, ethical considerations such as inherent bias, and privacy and data risks.
  • The regulator identified weaknesses in post-deployment monitoring, model behaviour monitoring, change management and the decommissioning of AI capabilities.
  • APRA indicated that entities may consider governance arrangements that address ownership and accountability across the AI lifecycle;
  • maintenance of an inventory of AI tooling and AI use cases;
  • human involvement for high-risk decisions and accountability; and
  • staff training concerning AI use, misuse, limitations and secure practices.

Supplier Concentration and Third-Party AI Dependency Risks

  • APRA observed that some entities are heavily dependent on a single provider for multiple AI use cases, with limited evidence of tested exit and substitution strategies for critical AI providers.
  • Contractual arrangements often lacked specific provisions addressing audit rights, model updates and deviations, incident notification, or changes to data handling.
  • APRA noted that upstream AI dependencies, including foundation models and fourth-party service providers, are frequently opaque, limiting an entity's ability to independently assess model performance, bias, resilience and security.
  • The regulator stated that entities may consider maintaining visibility over the full AI supply chain and monitoring concentration risk, including plausible and systemic failure scenarios.

Gaps in AI Assurance and Internal Audit Functions

  • APRA stated that existing assurance approaches remain fragmented and continue to rely on point-in-time and sample-based methods, despite such methods being ill-suited to probabilistic models that learn, adapt and degrade over time.
  • The regulator observed that few entities had implemented continuous validation or monitoring capable of identifying model drift, bias, failure modes or control breakdowns, and that internal audit and risk management functions may lack the specialist skills and tools required for AI assessment.
  • APRA indicated that entities may consider integrated assurance across cyber security, data governance, model performance risk, operational resilience, privacy and conduct risks, supported by enhanced technical capability within second-line risk management and internal audit.

Timeline of APRA’s AI Supervisory Engagement and Forward Plan

  • In late 2025, APRA conducted targeted engagements with major banks, insurers and superannuation trustees to evaluate AI adoption and risk management practices.
  • Following these reviews, APRA issued the industry-wide letter on 30 April 2026 to communicate its observations across the regulated sector.
  • APRA noted that it is engaging with the Council of Financial Regulators, government agencies and regulated entities concerning the potential for increased cyber threats from high-capability AI frontier models, a category the letter describes by reference to a named frontier model.
  • The regulator stated that it is finalising its forward plan for the supervision of AI risks, including entity prudential reviews, thematic activities and AI supplier engagement, framing the letter as reinforcing its principle-based prudential framework so that existing expectations on governance, operational resilience, risk management and information security continue to apply to AI-enabled systems and processes.

Potential Regulatory Implications for APRA-Regulated Entities

  • APRA concluded that it will apply its supervisory focus to entities' AI adoption and the management of resulting risks.
  • Where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, APRA may consider stronger supervisory action and, where appropriate, pursue enforcement.
  • The regulator encouraged entities to engage with its Non-Financial Risk Team regarding unexpected or heightened AI-related risk concerns, including where existing risk management approaches may be challenged.

(Source: https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai)