Circular

Dear CEO Letter on AI Issues - July 2026 (2026-07-07)

Guernsey Financial Services Commission (GFSC) · Guernsey

Issued 2026-07-03

Current version last checked: 2026-07-27

Summary

This is a Dear CEO letter from the GFSC's Director of Technology addressing ongoing technology risk in light of advanced AI-driven vulnerability discovery tools. It does not create new rules but reinforces existing expectations under the Bailiwick's principles-based regulatory framework regarding technology risk management and patching.

  • Nature of risk: AI vulnerability discovery tools do not create new weaknesses but expose existing ones in systems relied upon by firms, customers and markets.
  • Ongoing responsibility: Firms must treat technology risk as an evolving exposure requiring continuous monitoring, review and updates, not a static, one-off assessment.
  • Patching regime: Firms should understand their IT patching regime and confirm it remains appropriate, including the ability to rectify weaknesses in a significantly shortened timeframe without reducing checks and controls.
  • Outsourcing: Where a firm uses a third-party outsourced provider, it should ensure that provider can meet the firm's ongoing needs in this changing environment.
  • Governance: The letter should be brought to the attention of the firm's Board and senior management.

No new rules, fees or specific compliance deadlines are introduced; the letter is a supervisory expectations reminder tied to the Commission's existing AI policy statement and principles-based framework.

Key obligations

  • Firms should understand their organisation's IT patching regime and confirm it remains appropriate, including capacity to remediate vulnerabilities in a significantly shortened timeframe without reducing checks and controls
  • Firms using third-party outsourced providers should ensure those providers can meet the firm's ongoing technology risk management needs
  • Firms should treat technology risk as an evolving, ongoing exposure subject to continuous monitoring and review rather than a static, one-off assessment
  • CEOs should bring this letter to the attention of their Board and senior management

Applies to

financial services firms (GFSC licensees)

Topics

Version history

2026-07-12

source file (current)