Regulators Are Asking: 'Explain Your AI's Decision.' Can You?
HKMA, MAS, and the EU AI Act are all converging on the same requirement: AI decisions in compliance must be explainable. Most institutions running black-box AI are not ready for this.
Regulators Are Asking: "Explain Your AI's Decision." Can You?
Published: July 6, 2026
Category: AI / Governance
Reading Time: 5 minutes
A compliance officer at a bank recently told me about a situation that's becoming uncomfortably common.
Their AI transaction monitoring system flagged a transaction as suspicious. The customer complained: "Why was my account frozen?"
The bank couldn't give a clear answer. Not because they didn't want to. The AI system produced a single line of output:
"Suspicious: TRUE. Confidence: 87%."
When HKMA asked for the decision logic, there was nothing more to show.
This isn't an isolated anecdote. It's the leading edge of a regulatory wave.
What Regulators Are Saying
Hong Kong (HKMA): The supervisory principles on AI in banking require that AI-assisted decisions in compliance, credit, and risk management be explainable. Institutions must articulate how an AI system reaches its conclusions.
Singapore (MAS): Published principles on AI governance emphasizing fairness, transparency, and human accountability. The requirement extends to any AI system that makes decisions affecting customers or regulatory compliance.
European Union (EU AI Act): Financial AI applications classified as "high-risk" trigger mandatory conformity assessments, transparency obligations, and human oversight requirements.
United States (OCC/FRB): Model risk management guidance — originally written for quantitative models — is increasingly applied to AI systems. The core question is identical: can you validate and explain what your model does?
Every major regulator is converging on the same question: Can you open your AI's decision-making process to audit?
The Industry's Problem
Over the past five years, financial institutions have been in "AI adoption mode." Deploy something. Prove it works on volume. Optimize for accuracy.
The next five years will be "AI accountability mode." Regulators will demand proof that the AI is fair, unbiased, and understood by the humans who deploy it.
The gap between these modes is significant.
Most compliance AI systems in production today are "black boxes." They ingest data, apply a model, and produce an output. The reasoning path is invisible — sometimes even to the engineers who built them.
Institutions running black-box AI face increasing regulatory risk. Not because their models are wrong, but because they cannot prove they are right.
What "Explainable AI" Means in Practice
From our perspective as a compliance technology provider, explainable AI has four practical components:
1. Decision Traceability
Every AI decision must record: what data was input, what conclusion was reached, and what reasoning path was followed.
In practice: structured logging that captures model inputs, intermediate calculations, feature importance scores, and final outputs — all linked to a specific decision ID that can be retrieved and audited.
2. Confidence Transparency
A binary "suspicious/not suspicious" flag is insufficient for regulated environments.
Risk scoring should be granular: overall risk score, contributing factor breakdown, each factor's weight, and the confidence interval. A human reviewer should understand not just what the AI decided, but why.
3. Human-in-the-Loop Closure
AI flags. Human confirms or overrides. Every AI-generated alert must have a corresponding human decision recorded.
This serves regulatory compliance (auditors can verify human review of every flagged item) and model improvement (human decisions become training data for the next iteration).
4. Periodic Validation
AI models drift. Data distributions shift. New biases emerge.
Annual model validation is becoming a regulatory expectation: testing against holdout data, checking for accuracy degradation, auditing for bias across demographic segments, and documenting findings.
The UWAY Approach
When we build compliance tools with AI, our first requirement isn't maximum accuracy.
It's explainability.
The system must articulate — at a human-readable level — why it reached each conclusion. The analyst must interrogate the reasoning, accept or reject it, and document their decision.
This creates an auditable chain: AI reasons → human reviews → decision recorded.
That is what compliant AI looks like. Not the most accurate black box. The most transparent one.
A Question for Practitioners
If a regulator asked you tomorrow to explain the last 100 decisions your AI system made — could you provide a coherent, auditable answer for each one?
If the answer is no, you are not alone. But the window to address this is closing.
Tags: #AIGovernance #ExplainableAI #HKMA #MAS #Compliance #RegTech #FinTech #AI #FinancialRegulation #UWAY
UWAY Compliance Team
UWAY Innovation Limited is a Hong Kong-based compliance technology partner specializing in KYC, KYB, and AML infrastructure for Web3 and fintech firms.