← All posts

Building an AI risk framework for AMF-regulated asset managers

  • ai-governance
  • dora
  • eu-ai-act
  • amf
  • presidio
  • cybersecurity
  • compliance
  • consulting

Cet article est aussi disponible en français.

Asset managers regulated by the AMF have until the end of October to show they actually understand their own AI exposure, not just describe it on paper. Getting there meant untangling three separate regulatory tracks, the AMF, DORA, and the EU AI Act, into one coherent response.

Why now

Three things happened this year that turned AI risk from a talking point into a deadline.

In April 2026, Anthropic's Mythos model surfaced thousands of high-severity vulnerabilities across the industry, serious enough that the European Central Bank summoned euro-area banks' chief risk officers onto a call to explain their exposure. In June, Belgium's FSMA warned that frontier AI models have significantly lowered the threshold for attacking a regulated entity, regardless of its size. The French AMF had already flagged cyber risk as its top 2026 concern, and that summer began surveying portfolio management companies on AI cyber risk directly: governance, the cybersecurity use cases already in play, target patch times, and the share of critical vendors actually contacted about their own AI exposure. A follow-up letter set a firm deadline of 30 October for individual responses.

Timeline of three events that triggered the AMF letter: a frontier AI model reveals critical vulnerabilities, a regulator warns that attack costs have dropped, then the AMF sends its questionnaire

Three months, three warnings, one questionnaire with a deadline.

None of this sits in isolation. DORA already treats AI tooling as part of a firm's ICT estate. The EU AI Act adds its own inventory and human-oversight obligations on top.

What a public AI governance talk actually covers

I sat in on a talk by Charlene Seal at the Switzerland AI Community. The session opened on the EU AI Act, then moved into four risks she treats as the practical core of AI governance: prompt injection, sensitive information breach, misinformation, and excessive agency, each paired with controls a company can actually put in place rather than a slide of principles. Two of those four map directly onto what asset managers actually do wrong with AI day to day: pasting client positions into a public chatbot (sensitive information breach), or letting an agent read a mailbox it shouldn't (excessive agency).

Sensitive information breach splits into two problems. The first is client data: Microsoft's Presidio, an open-source SDK that detects and redacts personal data before it reaches a model or a document index. Its analyzer combines named-entity recognition with regex pattern matching and checksums, so it catches the obvious identifiers (IBANs, card numbers, national ID formats) plus free-text names and addresses, and its anonymizer masks, replaces, or encrypts what it finds before that text leaves the firm's environment.

What no detector decides for you is what counts as identifying. Under GDPR Article 4, information is personal data once someone can be identified "directly or indirectly," and in a fund context that bar is low: a role, a city, a mandate size and a birth year identify one individual long before any single field looks like PII. Presidio says as much itself, that automated detection carries "no guarantee that Presidio will find all sensitive information" and that additional protections should be employed. It lowers what escapes; it does not certify that what got through was anonymous.

A raw text snippet with a client name, IBAN, and phone number, next to the same text after Presidio redacts each sensitive span with a labeled placeholder

The difference between "an analyst pasted a client record into a chatbot" and "an analyst pasted a redacted record into a chatbot."

The second is secrets: an API key, a connection string, a whole .env file pasted into a chatbot to debug something, none of it personal data, so Presidio's default recognizers miss it. Its recognizer framework doesn't stop at patterns, though. Alongside regex and NER models, Presidio ships language-model recognizers, with Azure OpenAI, Gemini, or a local model through Ollama behind them, where what counts as sensitive is set by a prompt description and a few examples instead of a fixed pattern. That matters as much for the combination problem above as it does for an AWS key: a prompt can be told to flag whatever identifies a client in context, which no regex will ever do. Screenshots count too, which is why Presidio's image redactor runs OCR first, then the same recognizers on the text that comes out.

That covers what leaves through a prompt. For what leaves through a repository, FINMA and DORA both expect an owned incident behind a finding (who reviewed it, when, was the key actually live), not a log line, which a CI-only scanner won't give you. A managed option like GitGuardian is one way to get that trail; the right fit depends on where a firm's secrets actually sit.

The lesson

Advice about AI risk is easy to write as a slide of principles: prompt injection, sensitive information breach, misinformation, excessive agency. It only becomes useful once each one is backed by something that actually runs, not just a name.

Further reading and sources