AI Hallucination Research › Briefings

Briefings Blog

The running blog from the RLB Specialist Panel delves into real-world scenarios where the compliance, legal, or AI lab team interacts with frontier AI models under specific regulations. The blogs are anonymised to remove client-specific details and include insights from the RLB team analysing the hallucinations experienced in AI models while working on these cases. For example, when a model returns a confident answer that contradicts the regulator's primary text, such as a fabricated staff letter, a wrong appendix, or an inverted scope, these issues are discussed here. Each blog explains one set of findings and what it would have meant for the team that would have acted on it, sans this research initiative. This blog is frequently updated, a few times a day.

263 briefings in the archive · Subscribe via Atom: /briefings/feed.xml (this blog) · /feed.xml (all RegLegBrief publications)
Audience colours: AI Labs Practitioner (profession) Sector × Department
Audience
Jur.
Regulator
Profession
Sector
Dept
Range
Sort
Per page
Showing 5 of 263 · page 38 of 53
Saturday, 27 June 2026
Sector: Payment Institutions and Dept: Technology & Data INT BIS-CPMI

Payment Institutions Technology & Data teams: documentation and reporting gaps possible from AI reading of CPMI-IOSCO Cyber Resilience for FMIs (2016)

For Payment Institutions Technology & Data teams working with Guidance on Cyber Resilience for Financial Market Infrastructures (CPMI-IOSCO 2016): Specialist-Panel-verified findings on where AI summaries diverge from...

Technology and Data teams at payment institutions designing FMI-gateway cyber controls and cyber-resilience playbooks for payment-system access are increasingly relying on AI to generate cyber-control design documents, populate playbooks, draft architecture review papers, and prepare cyber-control mappings against the CPMI-IOSCO 2016 framework. In practice, AI is used to generate FMI-gateway cyber-control design documents, populate cyber-resilience playbooks for payment-system access, draft cyber-architecture review papers citing the CPMI-IOSCO 2016 expectations, and prepare cyber-control mapping documents against the 2016 guidance categories.

That workflow places the regulator-issued text of the 2016 guidance, its 2018-2020 derivative standards, and its current operative status at the centre of every AI-generated deliverable for payment-institution technology and data teams.

Two frontier AI models tested by the RegLeg Brief Specialist Panel produced confident, citable reconstructions of the CPMI-IOSCO 2016 Cyber Guidance (June 2016) that the regulator-issued primary text directly contradicts across nine findings spanning four failure classes: Source-Credit Fabrication (an asserted NIST Cybersecurity Framework citation that the 2016 guidance does not contain), Misattribution (the slogan 'secure the periphery, protect the core' located inside CPMI-IOSCO 2016 guidance or its 2018 wholesale-payments paper rather than the actual 2018 speech source), Anachronistic Cross-Reference (the 2016 guidance asserted as definitionally aligned with the November 2018 FSB Cyber Lexicon and the October 2020 FSB Effective Practices that postdate it), and Outdated Standing Claim (the 2016 guidance presented as the unchanged operative standard when CPMI-IOSCO has issued a May 2026 consultative document under active revision).

Questions are prepared by the RLB Specialist Panel based on real practical AI usage in the workflows payment-institution technology and data teams use AI for. The Panel binds each AI finding to verbatim regulator-issued source text held as primary substrate.

For payment-institution technology and data teams, the failure pattern is operationally consequential. A cyber-control mapping that records an asserted NIST CSF citation in the 2016 guidance documents the mapping foundation on a wrong reading of the source. A cyber-resilience playbook that records the 2016 guidance as containing forensic-analysis-database operational depth points the engineering team at a specification level the 2016 text does not contain. An architecture review that records the 2016 guidance as the unchanged operative standard misstates the regulatory horizon.

The audit's nine findings are documented with immutable RLB Citation IDs. Representative entries include RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q019-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Opus47, and RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Sonnet46. The full audit is documented at the CPMI-IOSCO 2016 Cyber Resilience Guidance hub on RegLegBrief.com.

Sector: Payment Institutions and Dept: Risk INT BIS-CPMI

Payment Institutions Risk teams: documentation and reporting gaps possible from AI reading of CPMI-IOSCO Cyber Resilience for FMIs (2016)

For Payment Institutions Risk teams working with Guidance on Cyber Resilience for Financial Market Infrastructures (CPMI-IOSCO 2016): Specialist-Panel-verified findings on where AI summaries diverge from the...

Risk teams at payment institutions managing cyber-risk exposures from FMI-gateway operations and payment-system participation are increasingly relying on AI to update the cyber-risk register, populate operational-risk scenario libraries, generate risk-committee briefings, and prepare ICAAP/ORSA cyber-narrative blocks citing the CPMI-IOSCO 2016 framework. In practice, AI is used to update cyber-risk register entries for FMI-gateway exposures, populate operational-risk scenario libraries for payment-system cyber incidents, generate risk-committee briefings on CPMI-IOSCO 2016 expectations versus actual control state, and prepare ICAAP/ORSA cyber-narrative blocks citing the 2016 framework.

That workflow places the regulator-issued text of the 2016 guidance, its 2018-2020 derivative standards, and its current operative status at the centre of every AI-generated deliverable for payment-institution risk teams.

Two frontier AI models tested by the RegLeg Brief Specialist Panel produced confident, citable reconstructions of the CPMI-IOSCO 2016 Cyber Guidance (June 2016) that the regulator-issued primary text directly contradicts across nine findings spanning four failure classes: Source-Credit Fabrication (an asserted NIST Cybersecurity Framework citation that the 2016 guidance does not contain), Misattribution (the slogan 'secure the periphery, protect the core' located inside CPMI-IOSCO 2016 guidance or its 2018 wholesale-payments paper rather than the actual 2018 speech source), Anachronistic Cross-Reference (the 2016 guidance asserted as definitionally aligned with the November 2018 FSB Cyber Lexicon and the October 2020 FSB Effective Practices that postdate it), and Outdated Standing Claim (the 2016 guidance presented as the unchanged operative standard when CPMI-IOSCO has issued a May 2026 consultative document under active revision).

Questions are prepared by the RLB Specialist Panel based on real practical AI usage in the workflows payment-institution risk teams use AI for. The Panel binds each AI finding to verbatim regulator-issued source text held as primary substrate.

For payment-institution risk teams, the failure pattern is operationally consequential. A risk-committee briefing that records the 2016 guidance as containing an explicit NIST CSF citation misstates the international standard's actual framework references. An ICAAP/ORSA cyber-narrative that records the 2016 guidance as containing forensic-analysis-database operational depth overstates the specification level of the international standard. A scenario library that records the 2016 guidance as the unchanged operative standard at the reporting date misstates the regulatory horizon.

The audit's nine findings are documented with immutable RLB Citation IDs. Representative entries include RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q019-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Opus47, and RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Sonnet46. The full audit is documented at the CPMI-IOSCO 2016 Cyber Resilience Guidance hub on RegLegBrief.com.

Sector: Payment Institutions and Dept: Compliance INT BIS-CPMI

Payment Institutions Compliance teams: documentation and reporting gaps possible from AI reading of CPMI-IOSCO Cyber Resilience for FMIs (2016)

For Payment Institutions Compliance teams working with Guidance on Cyber Resilience for Financial Market Infrastructures (CPMI-IOSCO 2016): Specialist-Panel-verified findings on where AI summaries diverge from the...

Compliance teams at payment institutions operating as direct FMI participants and as indirect participants through settlement agents are increasingly relying on AI to update FMI-participant onboarding checklists, generate cyber-incident notification protocols, and verify cyber-supervisory expectations against the CPMI-IOSCO 2016 source text. In practice, AI is used to update FMI participation onboarding checklists for payment-system access, generate cyber-incident notification protocols for payment-system gateway operations, validate cyber-supervisory expectations against CPMI-IOSCO 2016 source text, and prepare compliance reports on FMI cyber-resilience exposure.

That workflow places the regulator-issued text of the 2016 guidance, its 2018-2020 derivative standards, and its current operative status at the centre of every AI-generated deliverable for payment-institution compliance teams.

Two frontier AI models tested by the RegLeg Brief Specialist Panel produced confident, citable reconstructions of the CPMI-IOSCO 2016 Cyber Guidance (June 2016) that the regulator-issued primary text directly contradicts across nine findings spanning four failure classes: Source-Credit Fabrication (an asserted NIST Cybersecurity Framework citation that the 2016 guidance does not contain), Misattribution (the slogan 'secure the periphery, protect the core' located inside CPMI-IOSCO 2016 guidance or its 2018 wholesale-payments paper rather than the actual 2018 speech source), Anachronistic Cross-Reference (the 2016 guidance asserted as definitionally aligned with the November 2018 FSB Cyber Lexicon and the October 2020 FSB Effective Practices that postdate it), and Outdated Standing Claim (the 2016 guidance presented as the unchanged operative standard when CPMI-IOSCO has issued a May 2026 consultative document under active revision).

Questions are prepared by the RLB Specialist Panel based on real practical AI usage in the workflows payment-institution compliance teams use AI for. The Panel binds each AI finding to verbatim regulator-issued source text held as primary substrate.

For payment-institution compliance teams, the failure pattern is operationally consequential. A compliance checklist that records the 2016 guidance as containing an explicit NIST CSF citation imports a regulatory-criterion reference the source does not contain. A cyber-incident notification protocol that records the 2016 guidance as containing forensic-analysis-database operational depth misstates the specification level of the international standard. A compliance report that records the 2016 guidance as the unchanged operative standard at the reporting date misstates the regulatory horizon.

The audit's nine findings are documented with immutable RLB Citation IDs. Representative entries include RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q019-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Opus47, and RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Sonnet46. The full audit is documented at the CPMI-IOSCO 2016 Cyber Resilience Guidance hub on RegLegBrief.com.

Friday, 26 June 2026
Sector: Investment Banking and Dept: Compliance INT BIS-CPMI

Investment Banking Compliance teams: documentation and reporting gaps possible from AI reading of CPMI-IOSCO Cyber Resilience for FMIs (2016)

For Investment Banking Compliance teams working with Guidance on Cyber Resilience for Financial Market Infrastructures (CPMI-IOSCO 2016): Specialist-Panel-verified findings on where AI summaries diverge from the...

Compliance teams at investment banks operating as participants in CCPs and CSDs, and as direct counterparties to systemically important FMIs, are increasingly relying on AI to update FMI-participant onboarding records, generate cyber-incident notification briefings, and verify cyber-supervisory expectations against the CPMI-IOSCO 2016 source text. In practice, AI is used to update FMI participation onboarding records for clearing and settlement counterparties, generate cyber-incident notification briefings for trading-desk and prime-brokerage units, validate cyber-supervisory expectations against CPMI-IOSCO 2016 source text, and prepare compliance reports on cyber exposure through CCPs and CSDs.

That workflow places the regulator-issued text of the 2016 guidance, its 2018-2020 derivative standards, and its current operative status at the centre of every AI-generated deliverable for investment banking compliance teams.

Two frontier AI models tested by the RegLeg Brief Specialist Panel produced confident, citable reconstructions of the CPMI-IOSCO 2016 Cyber Guidance (June 2016) that the regulator-issued primary text directly contradicts across nine findings spanning four failure classes: Source-Credit Fabrication (an asserted NIST Cybersecurity Framework citation that the 2016 guidance does not contain), Misattribution (the slogan 'secure the periphery, protect the core' located inside CPMI-IOSCO 2016 guidance or its 2018 wholesale-payments paper rather than the actual 2018 speech source), Anachronistic Cross-Reference (the 2016 guidance asserted as definitionally aligned with the November 2018 FSB Cyber Lexicon and the October 2020 FSB Effective Practices that postdate it), and Outdated Standing Claim (the 2016 guidance presented as the unchanged operative standard when CPMI-IOSCO has issued a May 2026 consultative document under active revision).

Questions are prepared by the RLB Specialist Panel based on real practical AI usage in the workflows investment banking compliance teams use AI for. The Panel binds each AI finding to verbatim regulator-issued source text held as primary substrate.

For investment-banking compliance teams, the failure pattern is operationally consequential. A counterparty-onboarding record that records the 2016 guidance as containing an explicit NIST CSF citation imports a regulatory-criterion reference the source does not contain. A cyber-exposure briefing that records the 2016 guidance and the FSB Cyber Lexicon as definitionally aligned collapses a two-year vocabulary gap. A compliance report that records the 2016 guidance as the unchanged operative standard at the reporting date misstates the regulatory horizon at a moment when CPMI-IOSCO has issued a May 2026 consultative document.

The audit's nine findings are documented with immutable RLB Citation IDs. Representative entries include RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q019-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Opus47, and RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Sonnet46. The full audit is documented at the CPMI-IOSCO 2016 Cyber Resilience Guidance hub on RegLegBrief.com.

Sector: Corporate Banking and Dept: Compliance INT BIS-CPMI

Corporate Banking Compliance teams: documentation and reporting gaps possible from AI reading of CPMI-IOSCO Cyber Resilience for FMIs (2016)

For Corporate Banking Compliance teams working with Guidance on Cyber Resilience for Financial Market Infrastructures (CPMI-IOSCO 2016): Specialist-Panel-verified findings on where AI summaries diverge from the...

Compliance teams at corporate banks operating as FMI participants and intermediaries to systemically important payment systems are increasingly relying on AI to update FMI-participant onboarding checklists, generate cyber-incident notification protocols, and verify cyber-supervisory expectations against the CPMI-IOSCO 2016 source text. In practice, AI is used to update FMI participation onboarding checklists, generate cyber-incident notification protocols for corporate-banking participants in payment systems, validate cyber-supervisory expectations citations against CPMI-IOSCO 2016 source text, and prepare compliance reports on FMI cyber-resilience standards exposure.

That workflow places the regulator-issued text of the 2016 guidance, its 2018-2020 derivative standards, and its current operative status at the centre of every AI-generated deliverable for corporate banking compliance teams.

Two frontier AI models tested by the RegLeg Brief Specialist Panel produced confident, citable reconstructions of the CPMI-IOSCO 2016 Cyber Guidance (June 2016) that the regulator-issued primary text directly contradicts across nine findings spanning four failure classes: Source-Credit Fabrication (an asserted NIST Cybersecurity Framework citation that the 2016 guidance does not contain), Misattribution (the slogan 'secure the periphery, protect the core' located inside CPMI-IOSCO 2016 guidance or its 2018 wholesale-payments paper rather than the actual 2018 speech source), Anachronistic Cross-Reference (the 2016 guidance asserted as definitionally aligned with the November 2018 FSB Cyber Lexicon and the October 2020 FSB Effective Practices that postdate it), and Outdated Standing Claim (the 2016 guidance presented as the unchanged operative standard when CPMI-IOSCO has issued a May 2026 consultative document under active revision).

Questions are prepared by the RLB Specialist Panel based on real practical AI usage in the workflows corporate banking compliance teams use AI for. The Panel binds each AI finding to verbatim regulator-issued source text held as primary substrate.

For corporate-banking compliance teams, the failure pattern is operationally consequential. A compliance checklist that records the 2016 guidance as containing an explicit NIST CSF citation imports a regulatory-criterion reference the source does not contain. A cyber-supervisor briefing that records the 2016 guidance and the FSB Cyber Lexicon as definitionally aligned papers over the two-year gap between them. A compliance report that records the 2016 guidance as the unchanged operative standard at the reporting date misstates the regulatory horizon.

The audit's nine findings are documented with immutable RLB Citation IDs. Representative entries include RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q014-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q019-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Opus47, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020-Sonnet46, RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Opus47, and RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q022-Sonnet46. The full audit is documented at the CPMI-IOSCO 2016 Cyber Resilience Guidance hub on RegLegBrief.com.

↑ Back to top