Israel AI Regulation in Financial Sector Report
Interim report on AI regulation in the financial sector (Office of Legal Counsel and Legislative Affairs, Ministry of Justice)
Israel
RAI-IL-NA-IRAFSXX-2024An interagency interim report published 4 November 2024 by a task force led by the Office of Legal Counsel and Legislative Affairs (Ministry of Justice) together with the Ministry of Finance, Bank of Israel, the Israel Securities Authority, the Capital Market, Insurance and Savings Authority and the Competition Authority. The report is a risk‑based, sector‑specific framework of recommendations for the supervised financial sector addressing explainability, human oversight, privacy, competition, financial stability and supervisory approaches; it was published for public comment (deadline 15 December 2024).
Summary
Background and purpose: On 4 November 2024 an interagency Task Force published an interim report examining uses of artificial intelligence (AI) in the financial sector in Israel and proposing a sector‑specific, risk‑based regulatory approach. The report is the product of collaboration among the Office of Legal Counsel and Legislative Affairs at the Ministry of Justice, the Ministry of Finance, the Competition Authority, the Israel Securities Authority, the Capital Market, Insurance and Savings Authority (רשות שוק ההון), and the Bank of Israel’s Banking Supervision Department. It was issued for public comment (closing 15 December 2024) and aims to inform the design of supervisory guidance and, where necessary, regulation for supervised entities.
Scope and approach: The report focuses on three activity areas with immediate and material AI use: (1) investment advice and portfolio management; (2) credit decisioning and underwriting by banks and credit providers; and (3) insurance underwriting and pricing. It also addresses cross‑cutting issues — financial stability, competition and market structure, consumer protection, privacy and data protection, cybersecurity, and fraud/disinformation risks. The Task Force endorses a risk‑based, proportionate approach: lightweight regulatory measures for low‑impact applications (e.g., simple chatbots for customer service) and stronger obligations for AI uses that materially affect consumers or raise systemic risk (e.g., automated credit denial, automated underwriting, or large‑scale model reuse that might drive correlated behaviour).
Key recommendations: The report recommends a set of general principles and practical measures: (i) mandatory mapping and documentation of AI uses by supervised entities; (ii) a graded explainability regime — general system transparency for most uses with case‑by‑case obligations for decisions that materially affect customers; (iii) human oversight calibrated to risk (a graduated model of human involvement); (iv) mandatory risk assessments including privacy impact assessments and model validation/test regimes; (v) vendor and third‑party management expectations; (vi) disclosure and consumer notification obligations to avoid “AI‑washing”; (vii) measures to mitigate concentration risks and encourage access to training data; (viii) strengthening suptech/market surveillance tools; and (ix) recommendations on liability and remedial frameworks to ensure consumer redress and clarify responsibilities between providers and vendors.
Regulatory posture and next steps: The Task Force recommends using a mix of tools that favor flexible, sectoral measures: supervisory guidance, directives, targeted rules, temporary regulations and experimental sandboxes. It also recommends close coordination between sectoral supervisors (Bank of Israel, ISA, רשות שוק ההון) and the Privacy Protection Authority on data protection matters. The interim nature of the report means it is not itself prescriptive law; rather it sets out recommendations for regulators to adopt through guidance, supervisory expectations or legislation if needed. The report's publication initiated a public consultation period and signals likely further sectoral guidance and potential regulatory instruments in 2025 depending on responses and follow‑up work by the relevant authorities.
Full article
Read full text ↗Overview
The Interagency Task Force interim report (published 4 November 2024) assesses current and anticipated uses of artificial intelligence in Israel's financial sector and recommends a risk‑based, sector‑specific regulatory framework. Prepared by the Office of Legal Counsel and Legislative Affairs (Ministry of Justice) together with the Ministry of Finance, the Competition Authority, the Israel Securities Authority (ISA), the Capital Market, Insurance and Savings Authority and the Bank of Israel, the report both (a) surveys legal and regulatory issues (privacy, consumer protection, financial stability, competition, cybersecurity) and (b) proposes practical supervisory tools and obligations for supervised entities. The report was published for public comment until 15 December 2024 and intends to inform subsequent regulatory guidance, supervisory expectations, and potential targeted regulation for high‑impact applications. The official interim report and associated press materials are published by the task force and are available from the primary public announcement and the full report file. For the official announcement see the Bank of Israel press release and for the full interim report see the government publication. Bank of Israel — Joint press release (4 Nov 2024) and Interim report PDF (official publication).
Definitions
The report adopts a practical definition of "AI" consistent with international practice: systems that infer from data how to generate outputs (predictions, classifications, recommendations or decisions) that may influence individuals or markets. It distinguishes automated decision‑making (fully automated actions without human review) from decision‑support tools (systems that assist humans). It defines "material decisions" as outcomes with direct and substantial impacts on customers (e.g., credit refusals, insurance denials, investment suitability determinations). The document clarifies terms such as explainability (systemic vs. case‑specific explanation), human oversight (real‑time vs. ex‑post), model validation/testing, and systemic or correlated risk (risks arising when many market actors use similar models or base models leading to homogeneous behaviour).
Governance and Institutional Framework
The report recommends strengthening institutional arrangements and cooperation between sectoral supervisors: the Bank of Israel for banking supervision, the Israel Securities Authority for investment services, the Capital Market, Insurance and Savings Authority for insurance and savings, and the Ministry of Finance on policy coordination. The Office of Legal Counsel and Legislative Affairs (Ministry of Justice) is identified as the legal coordinator in developing model legal interpretations and cross‑regulator alignment. The Task Force calls for an AI coordination mechanism (or centre) to assist sectoral supervisors, disambiguate responsibilities with the Privacy Protection Authority on data matters, and to maintain a public register of supervisory guidance. See the joint announcement by the participating authorities for institutional details: Bank of Israel — joint press release and the primary report file at gov.il (Interim report). The report emphasizes that existing statutory powers of sectoral supervisors remain the primary enforcement route; the Task Force encourages the use of guidance, directives and targeted temporary regulations rather than immediate horizontal, ex‑ante statutory bans.
Key Focus Areas
The report identifies and analyses the principal legal and supervisory risks associated with AI deployment in finance. These include: (1) Consumer protection and discrimination — algorithmic bias in credit/insurance outcomes; (2) Explainability and accountability — the "black‑box" problem and obligations to provide meaningful explanations where decisions materially affect customers; (3) Privacy and data protection — risks of re‑identification, large‑scale profiling and training data provenance; (4) Financial stability and systemic risk — model homogeneity, correlated failures and market shocks resulting from widespread adoption of common foundation models; (5) Competition and market structure — concentration of model vendors and access to proprietary datasets; (6) Cybersecurity and model integrity — adversarial attacks, data poisoning and supply‑chain vulnerabilities; (7) Fraud and disinformation — deepfakes and social engineering facilitating fraud at scale; and (8) Operational resilience and vendor management — third‑party risk and service continuity. For each area the report outlines practical supervisory responses, such as enhanced risk mapping, targeted disclosure requirements, model testing, incident reporting, vendor due diligence, and measures to promote data accessibility and competition while maintaining privacy safeguards.
Implementation Framework
The Task Force proposes a multi‑instrument implementation framework anchored in four pillars: (A) Risk‑based supervisory expectations and guidance — sectoral supervisors should publish expectational guidance that calibrates obligations to risk; (B) Regulatory sandboxes and controlled experiments — to enable innovation under supervision and rapid learning; (C) Targeted rules and temporary regulations — for specific high‑risk applications (for example, fully automated credit refusal routines) where existing frameworks are insufficient; and (D) Market surveillance and suptech — investment in supervisory automation tools to detect model drift, correlated behaviours, and market anomalies. The framework expects supervised entities to conduct regular model validation and back‑testing, maintain thorough documentation (model cards, data lineage, versioning, test results), and to integrate privacy‑by‑design and security‑by‑design processes. The Task Force also advocates clear vendor management practices (contractual SLAs, audit rights, and contingency planning) and promotes cross‑regulator memoranda of understanding to enable information sharing and coordinated supervisory action.
Monitoring and Evaluation
Monitoring is both internal (firm‑level governance and testing) and external (regulatory surveillance). The report recommends that supervisors adopt a layered monitoring approach: routine reporting for moderate‑risk applications; event‑driven reporting and enhanced oversight for high‑risk uses; and system‑level monitoring to detect market‑wide concentration or correlated model failures. Supervisory monitoring tools should include standardized reporting templates, requirement of model inventory registers, sample audit trails for high‑impact decisions, and periodic thematic reviews. The Task Force recommends development of suptech capabilities to automate anomaly detection and to integrate signals across the regulated population, enabling early warnings for systemic risk or fraud patterns. It also recommends periodic public reporting on supervisory findings and an iterative review cycle to update guidance based on technological and market developments.
Penalties, Liability, and Appeals
The interim report recognizes that liability and enforcement mechanisms are primarily grounded in existing sectoral statutes and general obligations under consumer protection, privacy, anti‑discrimination and prudential laws. It recommends clarifying supervisory expectations so that failure to meet documented supervisory guidance may result in administrative measures (directives, enforcement actions), including fines where statute permits, restrictions on activities, or license conditions. The Task Force suggests strengthening avenues for consumer redress — e.g., clearer rules on responsibility between financial institutions and AI vendors, mandatory incident disclosure obligations and remediation duties, and guidance on evidentiary standards for algorithmic harms. It also recommends regulators establish defined administrative appeal routes and to publish enforcement policies for algorithmic breaches to ensure procedural fairness and legal certainty.
Relationship to Other Instruments
The report situates its recommendations within the existing legal ecosystem: it runs alongside Israel’s broader AI Policy and national programme, privacy law, consumer protection statutes, competition law and sectoral prudential rules. The Task Force explicitly recommends coordination with the Privacy Protection Authority on data protection obligations and with the Competition Authority regarding potential anti‑competitive effects of concentrated model suppliers. Where EU rules (such as the EU AI Act) or OECD standards are relevant, the report advises alignment to encourage interoperability and avoid fragmentation. The report is intended to complement (not replace) existing sectoral rules and to serve as a blueprint for sectoral supervisory action and potential legislative changes only when necessary.
International Alignment
The Task Force emphasizes international alignment and references international instruments and practices to promote consistency and regulatory interoperability. It recommends benchmarking against the EU AI Act's risk‑based classification and OECD AI principles, encourages cross‑border supervisory cooperation (especially concerning globally supplied models), and proposes adopting common standards for documentation, testing and vendor due diligence where feasible. The report highlights the need to monitor developments in major jurisdictions (EU, UK, US) and to participate in international fora to promote coherent regulatory outcomes and to reduce compliance burdens stemming from divergent rules.
Implementation Timeline
| Milestone | Target date |
|---|---|
| Interim report published (public consultation opens) | 2024-11-04 |
| Public comment deadline | 2024-12-15 |
| Review of submissions & follow-up recommendations | Q1 2025 (expected) |
| Issuance of sectoral supervisory guidance (first tranche) | Q2 2025 (expected) |
| Launch of sandboxes/experiments | H2 2025 (expected) |
| Consideration of targeted regulation / temporary rules (if needed) | 2025-2026 (ongoing) |
Sources and References
| Source | Type |
|---|---|
| Interim report on AI regulation in the financial sector — full report (Hebrew) | Primary Source |
| Joint press release — Bank of Israel (4 Nov 2024) | Primary Source |
| Israel Securities Authority — notice (Interagency Task Force publication) | Primary Source |
| OECD — alignment and recommendations (context) | Secondary Source |
Requirements for a company
What an organisation has to do under Israel AI Regulation in Financial Sector Report, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
7- Map all AI uses across business lines.Supervised financial entities.
- Conduct regular risk assessments for AI systems.Supervised financial entities.
- Adopt robust governance and ensure board oversight of AI risks.Supervised financial entities.
- Implement thorough testing and validation for AI systems.Supervised financial entities.
- Establish clear vendor management practices for AI systems.Supervised financial entities.
- Provide clear disclosures to customers regarding AI use and material impacts.Supervised financial entities.
- +1 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Israel AI Regulation in Financial Sector Report, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Supervised financial entities. | Map all AI uses across business lines. “Map AI uses across business lines” | — | Compliance Checklist | Important |
| 2 | Supervised financial entities. | Conduct regular risk assessments for AI systems. “Conduct risk assessments” | — | Compliance Checklist | Important |
| 3 | Supervised financial entities. | Adopt robust governance and ensure board oversight of AI risks. “Adopt governance and board oversight” | — | Compliance Checklist | Important |
| 4 | Supervised financial entities. | Implement thorough testing and validation for AI systems. “Implement testing and validation” | — | Compliance Checklist | Important |
| 5 | Supervised financial entities. | Establish clear vendor management practices for AI systems. “Establish vendor management” | — | Compliance Checklist | Important |
| 6 | Supervised financial entities. | Provide clear disclosures to customers regarding AI use and material impacts. “Provide disclosures to customers” | — | Compliance Checklist | Important |
| 7 | Supervised financial entities. | Report security incidents and material model failures to regulators. “Report incidents to regulators” | — | Compliance Checklist | Important |
Related Regulations
Israel’s Policy on Artificial Intelligence Regulation and Ethics (Ministry of Innovation, Science and Technology and Ministry of Justice) - 'Responsible Innovation' AI policy
Israel92% similar
White Paper: Principles of Policy, Regulation and Ethics in Artificial Intelligence (Ministry of Innovation, Science and Technology) - (White Paper published for public consultation)
Israel91% similar
FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence
Switzerland90% similar
Central Bank AI Guidelines
Qatar90% similar
Israel AI Regulation Overview
Israel90% similar
© Regulations.AI · updated on 13-Jun-2026