AI Hallucination ResearchFindings by audienceSectorsInternational / MultilateralPayment InstitutionsTechnology & Data › Promoting the Harmonisation of Application Programming Interfaces to Enhance Cross-Border Payments: Recommendations and Toolkit
Payment Institutions × Technology & Data — International / Multilateral · Last updated 11 Jun 2026 · methodology v2.3 · Hallucination Register
Share / Print X LinkedIn Email

AI Hallucination on Promoting the Harmonisation of Application Programming Interfaces to Enhance Cross-Border Payments: Recommendations and Toolkit for Technology & Data teams at Payment Institutions firms in international jurisdictions

Technology and data teams at payment institutions implementing ISO 20022 message changes under the CPMI API harmonisation programme are increasingly using AI to draft message-schema change notes, generate API specification documents against CPMI recommendations, prepare data-model impact assessments on structured-address formats, populate engineering change-control tickets with regulator-stated cutover dates, and validate vendor-supplied implementation roadmaps against CPMI source. The RLB Specialist Panel tested how that AI usage performs against the regulator's own primary text on CPMI's October 2024 d224 report and the related CPMI Brief and speech series.

The audit surfaced four substantive failure modes that the AI subjects delivered with regulator-fluent confidence.

Stakeholder Taxonomy Fabrication and Fabricated Date-and-Format Commitment on CPMI API Harmonisation for Cross-Border Payments. Two frontier AI models tested by the RLB Specialist Panel returned confident, citable answers across the panel's CPMI substrate-bound question set on the October 2024 d224 report and the related CPMI Brief and speech series. The panel binds each AI finding to verbatim regulator-issued source text held as primary substrate.

Across the 2 findings in this Technology & Data teams at Payment Institutions briefing, the AI subjects built a recommendation-by-recommendation stakeholder breakdown from category names rather than the regulator's actual recommendation text; introduced a specific November 2026 cutover commitment for structured ISO 20022 addresses that does not appear in the regulator's text.

An engineering change-control ticket that records a November 2026 CPMI structured-address cutover triggers a real implementation programme against a regulator commitment the regulator never issued. An API specification document built on an AI-fabricated per-recommendation stakeholder taxonomy mis-routes integration ownership against the 10 CPMI recommendations.

The findings are published with immutable RLB Citation IDs: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q008-Opus47, RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q009-Sonnet46. The full audit is published at the CPMI API Harmonisation for Cross-Border Payments hub on RegLegBrief.com.

This is the consolidated view of findings. Click the Citation IDs or 'see details →' on any item for the full details for each finding.

  1. Invented per-recommendation stakeholder taxonomy
    RLB-F-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q008

    Engineering and data teams at payment institutions translate d224 recommendations into backlog items against the API gateway, the ISO 20022 schema, the address-normalisation pipeline and the data-lineage register. Opus 4.7 returns a clean per-recommendation stakeholder taxonomy reconstructed from category labels rather than the recommendation text. A backlog scoped off that taxonomy routes tickets to the wrong squad, drops recommendations the AI silently elided, and produces a capability-to-recommendation matrix that breaks on architecture review against the primary text.

    see details →
  2. Fabricated ISO 20022 cutover
    RLB-F-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q009

    PI engineering and data work on ISO 20022 address-format readiness is materially staffed: schema validation, address normalisation, fallback handling for unstructured legacy messages. Sonnet 4.6 commits to a November 2026 structured-address cutover the d230 text does not state. A backlog ticket or readiness epic that quotes the AI line books engineering cycles against a regulatory deadline the regulator did not document, and may displace real CBPR+ work in the queue.

    see details →

Every finding on this page compares an AI subject's account of the rule against the regulator's verbatim text from the regulator's own portal. Both are linked. Each delta, its root causes, and impact analysis are documented and published with immutable Citation IDs.