The Bank for International Settlements published a paper on March 26, 2026 identifying and mapping the role of data in AI use in financial services, per the ICMA's AI regulatory tracker — a deliberate framing that locates the supervisory problem not in model architectures but in the data feeding them, which is the same location compliance programs put their controls. The paper joins a busy BIS output line on financial AI, including its collaboration with the Cambridge Centre for Alternative Finance on a 2026 global adoption report.
3G Times publishes information, not advice; policy papers inform supervision but create no obligations until rulemakers act.
What the publication signals
Central-bank attention to AI in finance has moved through three stations: novelty surveys, risk catalogs, and now the plumbing. A paper organized around data's role — its sourcing, quality, concentration, and governance — reads as the supervisory community accepting that model-level oversight travels poorly while data-level oversight travels well: the same lineage questions an institution answers for one model (where did this training data come from, who curates it, what is its freshness) answer it for the estate. For compliance officers, that is familiar ground: BSA-style recordkeeping, model-risk documentation, and privacy regimes already regulate data paths, and a BIS framing that centers data extends the existing toolset rather than demanding a new one.
Why data governance is the hinge
The sector's 2025-2026 experience made the hinge explicit. Vendor models arrive with opaque training lineage; institutions fine-tune on customer data that privacy law constrains; synthetic and third-party data sets enter through procurement with unknown provenance; and the same few cloud-and-model providers concentrate the upstream supply. Supervisors cannot examine what they cannot trace, and what they can trace is data documentation. The compliance translation: procurement artifacts for data (source, license, refresh cadence, permitted uses), lineage records binding training sets to models, and drift monitoring that watches inputs as attentively as outputs. Institutions with SR 11-7-grade model files already hold half the answer; the BIS lens adds the data plane those files assumed.
What does this mean in practice?
- Extend model documentation upstream. The model file should name its training data's sources and permissions with the same rigor it names its validation.
- Treat data vendors as vendors. Due diligence, SBOM-style inventories for data sets, and contract terms on provenance and refresh.
- Watch the standard-setters' calendar. BIS papers are the Basel process's thinking-out-loud; institutions that read them early price future expectations into today's architecture.
The reading matters because it will be echoed: national supervisors quote BIS framing in speeches, examiners absorb it into question sets, and the Basel-adjacent standards process converts vocabulary into expectations on its own calendar.
No rule changed on March 26. But the supervisory conversation now has a data-shaped center of gravity, and the institutions that already document their data like they document their models find themselves, unusually, ahead of the paper.
For more context, read Zero Trust Meets Duty of Confidentiality: Legal Questions in Granular Access Design.
For more context, read iso 20022 fedwire migration.
For more context, read open banking api liability.

