This summary provides a comprehensive overview of the Arrangement for Generative A.I. Sandbox ++ ("Sandbox") as released by the Hong Kong Monetary Authority (HKMA) and relevant financial regulators.
---
1. Document Overview
The GenA.I. Sandbox ++ is a collaborative regulatory initiative designed to foster innovation in the financial services sector. Its primary purpose is to provide a controlled, secure environment where regulated financial institutions can develop, test, and pilot Artificial Intelligence (A.I.) and Generative A.I. (GenA.I.) solutions. By facilitating direct dialogue between industry players and regulators, the Sandbox aims to provide early supervisory feedback, promote best practices, and accelerate the responsible adoption of cutting-edge technologies.
2. Main Content
The Sandbox focuses on high-impact use cases that demonstrate technological sophistication and benefit the broader financial ecosystem.
- Core Focus Areas:
- Risk Management: Improving creditworthiness assessments, investment suitability compliance, listing document review (for sponsors), and underwriting decisions.
- Anti-Fraud Measures: Detecting "deepfake" scams, automated identification of fraudulent messages, forgery detection during onboarding, and anomaly detection in claim documents.
- Customer Experience: Advanced chatbots for personalized interaction and real-time claim status updates.
- Safety and Risk Management: All trials must integrate A.I. safety components, specifically bias detection/mitigation, explainable A.I. (XAI), and output monitoring frameworks. Participants are encouraged to use "A.I. vs. A.I." strategies to validate and harden model robustness.
- Operational Infrastructure: Trials are conducted within a secure environment at the A.I. Supercomputing Centre operated by Cyberport.
3. Key Changes and Requirements
- Data Strategy: Adherence to "data minimization" is mandatory. Institutions are encouraged to use data masking, tokenization, public data, anonymized data, or synthetic data.
- Selection Criteria: Projects must demonstrate innovation, technical complexity, potential for industry-wide contribution, and strict adherence to ethical "fair use" principles.
- Requirement for Human Oversight: Participants are expected to manage their internal resources for project execution and technical coordination.
- Collaborative Approach: The Sandbox facilitates workshops where institutions can network with technology vendors to refine their use cases.
4. Important Dates and Timeline
- Sandbox Duration: Generally six to eight months per project, covering preparation, execution, and final reporting.
- Extensions: May be granted on a case-by-case basis.
- Submission/Process: There is no fixed application deadline, but institutions are encouraged to prioritize high-impact submissions. Processing time is variable, depending on project complexity and applicant responsiveness.
5. Impact Scope
The Sandbox is open to entities regulated by the following ordinances:
- Banking Ordinance (Cap. 155): Authorized Institutions.
- Securities and Futures Ordinance (Cap. 571): Licensed Corporations.
- Insurance Ordinance (Cap. 41): Authorized Insurers and Licensed Insurance Broker Companies.
- Mandatory Provident Fund Schemes Ordinance (Cap. 485): MPF Approved Trustees and Principal Intermediaries.
- Payment Systems and Stored Value Facilities Ordinance (Cap. 584): SVF Licensees.
6. Compliance and Reporting Requirements
- Application: Must be submitted by the regulated entity (not the tech vendor). It must include high-level design, model details, and risk assessments.
- Reporting:
- Regular Updates: Participants must provide progress reports as requested by their respective regulators.
- Final Report: A mandatory final report detailing outcomes, technical results, and "key learnings" is required at the conclusion of the trial.
- Post-Sandbox: If an institution intends to move to a full production deployment, they must follow established regulatory procedures for new technology adoption, as Sandbox admission does not constitute formal endorsement.
7. Technical Details
- Infrastructure: Access to Cyberport’s A.I. Supercomputing infrastructure.
- Data Security: Participants must implement, at minimum, encryption and access controls for any data transferred or accessed within the Sandbox environment.
- Vendor Ecosystem: No restricted vendor list exists. A catalogue is available via Cyberport, but institutions retain the freedom to select any partner or proceed independently.
- Metrics for Evaluation:
- Level of Innovation: Novelty of models/methodologies.
- Complexity: Sophistication of technical architecture.
- Scalability: Potential for the solution to be replicated by other institutions.
8. Summary of Application Channels
| Institution Type | Submission Channel | Contact Email |
| : --- | :--- | :--- |
| Authorized Institutions | HKMA Survey Tool | GenAI_sandbox@hkma.gov.hk |
| Licensed Corporations | Via Email | GenAI_sandbox@sfc.hk |
| Authorized Insurers | Insurtech Facilitation Team | insurtech@ia.org.hk |
| MPF Trustees | Via Email | GenAI_Sandbox@mpfa.org.hk |
| SVF Licensees | Via Email | pssvfo@hkma.gov.hk |
---
Key Takeaways for Participants
- Cost: The Sandbox is free; however, participants bear internal costs (staffing, tech vendor fees).
- Trial Size: The Sandbox is for experimentation and validation, not for large-scale production deployment.
- Transparency: The identities of participants and their technology partners may be disclosed to the public.
- Flexibility: The regulators reserve the right to modify Sandbox requirements based on the specific needs of the trials conducted.