香港《有關(guān)使用生成人工智能的消費(fèi)者保障》_第1頁
香港《有關(guān)使用生成人工智能的消費(fèi)者保障》_第2頁
香港《有關(guān)使用生成人工智能的消費(fèi)者保障》_第3頁
香港《有關(guān)使用生成人工智能的消費(fèi)者保障》_第4頁
香港《有關(guān)使用生成人工智能的消費(fèi)者保障》_第5頁
已閱讀5頁,還剩11頁未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡介

OurRef:B1/15C

B9/67C

19August2024

TheChiefExecutive

AllAuthorizedInstitutions

DearSir/Madam,

ConsumerProtectioninrespectofUseofGenerativeArtificialIntelligence

Iamwritingtoprovideauthorizedinstitutionswithasetofguidingprinciplesinrespectofuseofgenerativeartificialintelligence(“GenAI”)incustomer-facingapplicationsfromconsumerprotectionperspective.

Inviewofthedevelopmentofbigdataanalyticsandartificialintelligence(“BDAI”),theHongKongMonetaryAuthority(“HKMA”)issuedasetofguidingprinciplesinthecircular“ConsumerProtectioninrespectofUseofBigDataAnalyticsandArtificialIntelligencebyAuthorizedInstitutions”dated5November2019(“2019BDAIGuidingPrinciples”),focusingonfourmajorareas,namelygovernanceandaccountability,fairness,transparencyanddisclosure,anddataprivacyandprotection(seeAnnex1forahandysummary

1

).Theseguidingprincipleshavedemonstratedtobebeneficialtobanksandcustomers,andhelpedpromotethehealthydevelopmentofBDAIintheHongKongbankingsector,asseenintheproliferationofusecasesofBDAIrevealedinarecentsurveyconductedbytheHKMA(seeAnnex2forasummaryofthesurveyresults).Moreimportantly,the2019BDAIGuidingPrincipleshavealsohelpedenhancecustomerconfidenceinusingbankingservicesadoptingBDAI.

Inrecentmonths,theHKMAnotesanincreasinginterestofthebankingsectorinadoptingGenAIintheiroperations.GenAIisaformofBDAIthatenablesgenerationofnewcontentsuchastext,image,audio,video,codeorothermedia,

1Forguidanceonriskmanagementofauthorizedinstitutionsinrespectoftheuseofartificialintelligence(includingGenAI),pleaserefertotheHKMAcircular“High-levelPrinciplesonArtificialIntelligence”dated1November2019,whichwillbeupdatedfromtimetotimeinthelightofmarketdevelopmentandpracticalexperience.

–2–

basedonvastamountsofdata.Atthismoment,adoptionofGenAIinthebankingsectorisstillatanearlystage,withmostofthecurrentapplicationsfocusingonimprovingbanks’operationalefficiency,suchasinternalchatbotsandcoding.Nonetheless,theabilityofGenAIincontent-creationmeansthatGenAIcouldbemoreextensivelyadoptedbythebankingsectorincustomer-facingactivities.Potentialapplicationsincludebutarenotlimitedtocustomerchatbots,customisedproductandservicedevelopmentanddelivery,targetedsalesandmarketing,androbo-advisorsinwealthmanagementandinsurance.TheuseofGenAIincustomer-facingactivitieswillhaveconsumerprotectionimplications.

GenAI,beingasubfieldofBDAI,basicallysharesasetofsimilarriskdimensions.Assuch,withrespecttoconsumerprotectionincustomer-facingapplications,theHKMAexpectsallauthorizedinstitutionstoapplyandextendthe2019BDAIGuidingPrinciplestotheuseofGenAIandcontinuetoadoptarisk-basedapproachcommensuratewiththerisksinvolved.Havingsaidthat,sinceGenAIusescomplexmodels,potentialriskssuchaslackofexplainabilityandhallucination(i.e.generatingoutputsthatseemrealisticbutarefactuallyincorrect,incomplete,lackimportantinformation,orlackrelevancetothecontext)couldcauseevenmoresignificantimpactoncustomers.TheHKMAhasthereforesetoutthefollowingadditionalprinciplesundereachofthefourmajorareasaimingtoensureappropriatesafeguardsforconsumerprotectionareinplacewhenGenAIisadoptedforcustomer-facingapplications.

1.Governanceandaccountability

TheboardandseniormanagementofauthorizedinstitutionsshouldremainaccountableforalltheGenAI-drivendecisionsandprocesses,andhavethoroughlyconsideredthepotentialimpactofGenAIapplicationsoncustomersthroughanappropriatecommitteeunderthegovernance,oversightandaccountabilityframeworkofauthorizedinstitutions.Theyshouldensure,amongothers:

(a)thescopeofcustomer-facingGenAIapplicationsisclearlydefinedsuchthatGenAIusagewouldnotbeusedinunintendedareas;

(b)properpoliciesandproceduresaredevelopedontheresponsibleuseofGenAIincustomer-facingapplicationsandrelatedcontrolmeasuresareputinplace;and

(c)propervalidationoftheGenAImodelsareputinplace,inparticular,duringtheearlystageofdeployingcustomer-facingGenAIapplications,authorizedinstitutionsshouldadoptthe“human-in-the-loop”approach,i.e.having

–3–

humantoretaincontrolinthedecision-makingprocesstoensurethemodel-generatedoutputsareaccurateandnotmisleading.

2.Fairness

AuthorizedinstitutionsshouldensureGenAImodelsproduceobjective,consistent,ethicalandfairoutcomestocustomers,whichincludeensuring,amongothers:

(a)themodel-generatedoutputswouldnotleadtounfairbiasordisadvantageagainstanycustomersorgroupsofcustomers.AuthorizedinstitutionsshouldgiveconsiderationtodifferentapproachesthatmaybedeployedintheGenAImodels,suchasanonymisingcertaincategoriesofdata,deployingdatasetsthatarecomprehensiveandfairrepresentationofthepopulation,makingadjustmentstoremovebiasduringthevalidationandreviewprocess(e.g.byadopting“human-in-the-loop”),etc.;and

(b)duringtheearlystageofdeployingcustomer-facingGenAIapplications,customersareprovidedwiththeoptiontooptoutofusingGenAIandrequesthumaninterventiononGenAI-generateddecisionattheirdiscretionasfaraspracticable.Wherean“opt-out”optioncannotbeprovidedforsomereasons,authorizedinstitutionsshouldprovidechannelsforcustomerstorequestforreviewoftheGenAI-generateddecisions.Withthecontinuousevolutionoftechnology,othermeasuresthatcanyieldthesameeffectof“opt-out”optionwillalsobeacceptable.

3.Transparencyanddisclosure

AuthorizedinstitutionsshouldprovideanappropriateleveloftransparencytocustomersregardingtheirGenAIapplicationsthroughproper,accurateandunderstandabledisclosure.Accordingly,theyshoulddisclosetheuseofGenAItocustomers,and,amongothers,communicatewithcustomersontheuseandpurposeofadoptionoftheGenAImodelsaswellasthelimitationsofsuchmodels,inordertoenhancecustomers’understandingofthemodel-generatedoutputs.

4.Dataprivacyandprotection

Authorizedinstitutionsshouldimplementeffectiveprotectionmeasurestosafeguardcustomerdata.Inparticular,ifpersonaldataarecollectedandprocessedbyGenAIapplications,authorizedinstitutionsshouldcomplywiththePersonalData(Privacy)OrdinanceandpaydueregardtorelevantrecommendationsandgoodpracticesissuedbytheOfficeofthePrivacy

–4–

CommissionerforPersonalData(“PCPD”)relatedtoGenAI,including,amongothers,the“GuidanceontheEthicalDevelopmentandUseofArtificialIntelligence”publishedon18August2021andthe“ArtificialIntelligence:ModelPersonalDataProtectionFramework”publishedon11June2024.

ProactiveuseofBDAIandGenAIinenhancingconsumerprotection

BDAI,inparticularGenAI,hasthepotentialforproduct-featureoptimisationandcustomersegmentationtotheindividuallevel,therebyallowingbankstobepreciseindesigningandpromotingspecificproductsforspecificcustomersinanefficientandcustomisedmanner,posingbusinesspotentialandopportunities.Alongsimilarlogic,authorizedinstitutionsareencouragedtoexploretheuseofBDAI,includingGenAI,inenhancingconsumerprotection.Someexamplesmayincludeidentificationofcustomerswhoarevulnerableandrequiremoreprotectionandeducation;identificationofcustomerswhomayneedmoreinformationorclarificationstobetterunderstandproductfeatures,risks,andtermsandconditionsinthedisclosure;orissuanceoffraudalertstocustomersengagingintransactionswithpotentiallyhigherrisks.

Shouldyouhaveanyquestionsregardingthiscircular,pleasefeelfreetocontactMsCherryYipon2597-0495orMrMichaelLeungon2878-1186.

Yoursfaithfully,

AlanAu

ExecutiveDirector(BankingConduct)

c.c.TheChairman,TheHongKongAssociationofBanks

TheChairman,TheDTCAssociation

SecretaryforFinancialServicesandtheTreasury(Attn:MrJustinTo)

–5–

Annex1

GuidingPrinciplesintheHKMAcircular“ConsumerProtectionin

respectofUseofBigDataAnalyticsandArtificialIntelligenceby

AuthorizedInstitutions”dated5November2019

1.Governanceandaccountability

TheboardandseniormanagementofauthorizedinstitutionsshouldremainaccountableforalltheBDAI-drivendecisionsandprocesses.Accordingly,theyshouldensure,amongothers:

(a)appropriategovernance,oversightandaccountabilityframeworkwhichisestablishedanddocumented;

(b)appropriatelevelofexplainabilityoftheBDAImodelsincludinganyalgorithms(i.e.noblack-boxexcuse),andthatthemodelscanbeunderstoodbytheauthorizedinstitutions;

(c)adherencetotheconsumerprotectionprinciplessetoutintheCodeofBankingPractice,TreatCustomersFairlyCharterandotherapplicableregulatoryrequirements,asinthecaseofprovidingconventionalbankingproductsandservices.BDAIapplicationsshouldalsobeconsistentwiththecorporatevaluesandethicalstandardsofauthorizedinstitutionswhichshouldinclude,amongothers,upholdingcustomer-centriccultureandprinciples;and

(d)propervalidationbeforelaunchofBDAIapplications,andthereafteron-goingreviews,toensurethereliability,fairness,accuracyandrelevanceofthemodels,datausedandtheresults.

2.Fairness

AuthorizedinstitutionsshouldensurethatBDAImodelsproduceobjective,consistent,ethicalandfairoutcomestocustomers,whichincludeensuring,amongothers:

(a)compliancewiththeapplicablelaws,includingthoserelevanttodiscrimination;

(b)customeraccesstobasicbankingservicesarenotdeniedunjustifiablywhichwillbeagainstthespiritoffinancialinclusion;

–6–

(c)customers’financialcapabilities,situationandneeds,includingtheirlevelofdigitalliteracy,aretakenintoaccount;

(d)themodelsusedfortheBDAI-drivendecisionarerobustandhaveappropriatelyweighedallrelevantvariables;and

(e)thepossibilityofmanualinterventiontomitigateirresponsiblelendingdecisionswherenecessary(e.g.incasesinvolvinghigherrisksorimpactsfromtheautomateddecision).

3.Transparencyanddisclosure

AuthorizedinstitutionsshouldprovideappropriateleveloftransparencytocustomersregardingtheirBDAIapplicationsthroughproper,accurateandunderstandabledisclosure.Accordingly,theyshould,amongothers:

(a)makecleartocustomers,priortoserviceprovision,thattherelevantserviceispoweredbyBDAItechnologyandoftheassociatedrisks;

(b)provideproperdisclosuretocustomerssothatcustomerscouldunderstandtheapproachofauthorizedinstitutionstousingcustomerdata;

(c)makeavailableamechanismforcustomerstoenquireandrequestreviewsonthedecisionsmadebytheBDAIapplications,andensurethatanyrelatedcomplainthandlingandredressmechanismforBDAI-basedproductsandservicesareaccessibleandfair;

(d)provideexplanationsonwhattypesofdataareused,andwhatfactorsorhowthemodelsaffecttheBDAI-drivendecisions,uponcustomers’requestandwhereappropriate.Fortheavoidanceofdoubt,suchexplanationstocustomersarenotrequiredforsystemsusedformonitoringandpreventionoffraudsormoneylaundering/terroristfinancingactivities;

(e)carryoutappropriateconsumereducationtoenhanceconsumers’understandingonBDAItechnologyinbankingservices;and

(f)ensurethatrelevantcustomercommunicationsareclearandsimpletounderstand.

–7–

4.Dataprivacyandprotection

Authorizedinstitutionsshouldimplementeffectiveprotectionmeasurestosafeguardcustomerdata.Accordingly,theyshould,amongothers:

(a)ifpersonaldataarecollectedandprocessedbyBDAIapplications:

-ensurecompliancewiththePersonalData(Privacy)Ordinance(“PDPO”)includingthe6DataProtectionPrinciples,anyrelevantcodesofpracticeissuedorapprovedbythePrivacyCommissionerforPersonalData(“PCPD”)givingpracticalguidanceoncompliancewiththePDPO,andanyotherapplicablelocalandoverseasstatutoryorregulatoryrequirements;

-payregardtotherelevantgoodpracticesissuedbythePCPDrelatedtoBDAIandFintech,including,amongothers,the“EthicalAccountabilityFramework”(the“Framework”),the“DataStewardshipAccountability,DataImpactAssessmentsandOversightModels”insupportoftheFramework,andthe“InformationLeafletonFintech”;

(b)considerembeddingdataprotectioninthedesignofaproductorsystemfromtheoutset(i.e.“privacybydesign”)andcollectingandstoringonlytheminimumamountofdatafortheminimumamountoftime(i.e.“dataminimisation”);and

(c)whererequestforconsenttothecollectionanduseofpersonaldatainrelationtoabankingproductorservicepoweredbyBDAItechnologyisrequired,ensurethatsuchconsentisasclearandunderstandableaspossibleintheinterestsofensuringinformedconsent.

–8–

Annex2

SurveyonConsumerProtectioninrespectof

theUseofBigDataAnalyticsandArtificialIntelligence

InMay2024,theHKMAconductedasurveyontheuseofbigdataanalyticsandartificialintelligence(“BDAI”)includinggenerativeartificialintelligence(“GenAI”)byauthorizedinstitutions.Atotalof28authorizedinstitutionsprimarilyservingretailcustomersweresurveyedandthefollowingsummariseskeyobservationsfromthesurvey.

A.UseofBDAI

75%ofsurveyedauthorizedinstitutionsreportedadoptingorplanningtoadoptBDAIintheprovisionofgeneralbankingproductsandservices,aswellasdailyoperations.Reportedusecasesspreadacrosscustomer-facingactivities(identityauthentication,customerchatbots,creditassessment),middle-officefunctions(AMLandfrauddetection,controlsandmonitoring)andback-officefunctions(operationalautomationanddocu

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

最新文檔

評論

0/150

提交評論