Regulatory activity across Asia's fintech and payments landscape remained active this month, with key themes including cyber and operational resilience and artificial intelligence.
This bulletin contains a very brief summary of a selection of the regulatory developments across the region. To receive a more detailed breakdown of these developments, please subscribe to our monthly newsletter below.
Key developments by jurisdiction:
Hong Kong SAR:
The HKMA issued various reports and circulars addressing:
the AI adoption by banks for the purposes of AML/CFT monitoring (with an expectation that banks deliver measurable results within 24 months);
Group 1 classification conditions for cryptoassets on permissionless chains; and
The importance of banks staying vigilant amid evolving cybersecurity threats.
The HKMA is also conducting a joint review (with the FSTB) into the adoption of DLT in Hong Kong’s fixed income market.
Mainland China:
The NFRA issued Guiding Opinions on the Safe Development and Application of Artificial Intelligence in the Banking and Insurance Industries, setting out 32 guiding measures across seven areas.
The Cyberspace Administration of China finalised Guidelines for the Classification and Grading of Financial Information Service Data, establishing a three-tier framework covering business data, user data and enterprise data.
Singapore:
MAS and ABS launched a PayNow Generation 2 study exploring enhancements to Singapore's instant payments infrastructure, with an implementation roadmap due by end-2026.
MAS also published a consultation paper on proposed amendments to the Notices on Technology Risk Management. The proposed changes would require all financial institutions to meet enhanced standards to strengthen their technology resilience.
Japan:
Following the submission of the crypto asset legislation, the JVCEA amended its articles of incorporation and certain rules and newly established guidelines for intermediary business activities, with the new and amended rules taking effect on 30 June 2026.
Thailand:
The BOT issued a notification requiring payment service operators to maintain comprehensive, risk-based customer risk management policies.
The BOT also issued a notification prescribing the format, channel, frequency and timeline for mandatory reporting of abnormal financial transaction data, applicable to commercial banks and regulated payment service operators.
UAE:
The UAE CMA issued a decision permitting entities licensed by the UAE Central Bank (other than insurance companies) to conduct virtual asset service provider activities or operate alternative trading systems in or from the UAE.
Click here to request a copy of the full fintech & payments update.

/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-07-01-10-05-52-711-6a44e6804d141be5967eb61e.jpg)
/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-07-30-14-14-01-121-6a6b5c290617b6eacbc3ac2b.jpg)
/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-07-30-14-06-04-378-6a6b5a4ce94c938b93be656f.jpg)
/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-03-16-09-26-04-830-69b7ccac0f5150d9ca0d7301.jpeg)
