4
Frequency Trading (“HFT”) by the 2000s, with algorithms enabling ultra-fast trading and
market microstructures. By the 2010s, Natural Language Processing (“NLP”) allowed for non-
structured data analysis and sentiment analysis, and ML ensemble methods became the de facto
standard for forecasting and portfolio construction. The emergence of Large Language Models
(“LLMs”) and Generative AI accelerated innovation in the 2020s, allowing AI usage to move
from trading algorithms and risk analytics to a broader suite of operational uses like scenario
generation, operational efficiency, and digital workflows spanning all three lines of defense.
While demonstrating its usefulness in a trading context, AI also showed signs of risks to come.
Unchecked algorithms produced outsized losses in short periods, highlighting both the speed
and severity of AI-based risk events. The 2010 “Flash Crash” introduced the broader public to
algorithmic risks when U.S. equity markets dropped by nearly $1 trillion before recovering in a
few minutes. Knight Capital incurred massive losses when a 2012 system update inadvertently
bought millions of shares without corresponding sell orders. The Infinium Capital losses in
2010 and the 2012 Facebook IPO glitch on NASDAQ further highlighted the potential for
technology-related risk events in the capital markets.
Global regulators responded to AI’s emergence by introducing several new laws and
regulations. In addition, several guidance papers were published, addressing a wide range of
industries and AI use cases. They included (but are in no way limited to) the following:
• In 2017, the United Kingdom’s House of Lords Select Committee on Artificial
Intelligence published “AI in the UK: ready, willing, and able?”. In that document, the
UK government outlined several ethical concerns related to the development and uses of
AI and provided recommendations related to data access, transparency, bias mitigation,
and skills development. It also issued a call to further research AI usage, public
engagement, cybersecurity, international cooperation, and ethical frameworks.
• The National Institute of Standards and Technology (“NIST”) issued “Artificial
Intelligence Risk Management Framework” in 2023. In addition to providing best
practices for AI development, it outlined NIST’s core AI Risk management elements:
strong governance, clear mapping, regular measurement, and effective management.
• The European Securities and Markets Authority (“ESMA”) issued “On the use of
Artificial Intelligence in the provision of retail investment services” in 2024. ESMA
argued for acting transparently in clients’ best interests, recommended key controls
(governance, data quality, third-party AI controls, staff training, and AI-specific risk
management), and provided business conduct requirements.
• The European Union issued its AI Act in 2024. The act adopted a risk-based approach
in determining obligations proportionate to the impact of AI Systems on health, safety,
and fundamental rights. It includes risk classifications, evaluation requirements, data
governance provisions, human oversight responsibilities, training requirements, and
enforcement provisions.
The history of AI usage in capital markets clearly recommends itself to the development of risk
management principles which market participants can readily adopt. During the paper’s
development, industry experts discussed a growing concern over AI Tool proliferation, lack of
oversight, and the need for frameworks that go beyond use-case specific controls. Drawing
from model risk management principles and adapting them to the unique challenges of AI, this
paper outlines a structured approach to AI Risk management. The CCRO advocates for
Frequency Trading (“HFT”) by the 2000s, with algorithms enabling ultra-fast trading and
market microstructures. By the 2010s, Natural Language Processing (“NLP”) allowed for non-
structured data analysis and sentiment analysis, and ML ensemble methods became the de facto
standard for forecasting and portfolio construction. The emergence of Large Language Models
(“LLMs”) and Generative AI accelerated innovation in the 2020s, allowing AI usage to move
from trading algorithms and risk analytics to a broader suite of operational uses like scenario
generation, operational efficiency, and digital workflows spanning all three lines of defense.
While demonstrating its usefulness in a trading context, AI also showed signs of risks to come.
Unchecked algorithms produced outsized losses in short periods, highlighting both the speed
and severity of AI-based risk events. The 2010 “Flash Crash” introduced the broader public to
algorithmic risks when U.S. equity markets dropped by nearly $1 trillion before recovering in a
few minutes. Knight Capital incurred massive losses when a 2012 system update inadvertently
bought millions of shares without corresponding sell orders. The Infinium Capital losses in
2010 and the 2012 Facebook IPO glitch on NASDAQ further highlighted the potential for
technology-related risk events in the capital markets.
Global regulators responded to AI’s emergence by introducing several new laws and
regulations. In addition, several guidance papers were published, addressing a wide range of
industries and AI use cases. They included (but are in no way limited to) the following:
• In 2017, the United Kingdom’s House of Lords Select Committee on Artificial
Intelligence published “AI in the UK: ready, willing, and able?”. In that document, the
UK government outlined several ethical concerns related to the development and uses of
AI and provided recommendations related to data access, transparency, bias mitigation,
and skills development. It also issued a call to further research AI usage, public
engagement, cybersecurity, international cooperation, and ethical frameworks.
• The National Institute of Standards and Technology (“NIST”) issued “Artificial
Intelligence Risk Management Framework” in 2023. In addition to providing best
practices for AI development, it outlined NIST’s core AI Risk management elements:
strong governance, clear mapping, regular measurement, and effective management.
• The European Securities and Markets Authority (“ESMA”) issued “On the use of
Artificial Intelligence in the provision of retail investment services” in 2024. ESMA
argued for acting transparently in clients’ best interests, recommended key controls
(governance, data quality, third-party AI controls, staff training, and AI-specific risk
management), and provided business conduct requirements.
• The European Union issued its AI Act in 2024. The act adopted a risk-based approach
in determining obligations proportionate to the impact of AI Systems on health, safety,
and fundamental rights. It includes risk classifications, evaluation requirements, data
governance provisions, human oversight responsibilities, training requirements, and
enforcement provisions.
The history of AI usage in capital markets clearly recommends itself to the development of risk
management principles which market participants can readily adopt. During the paper’s
development, industry experts discussed a growing concern over AI Tool proliferation, lack of
oversight, and the need for frameworks that go beyond use-case specific controls. Drawing
from model risk management principles and adapting them to the unique challenges of AI, this
paper outlines a structured approach to AI Risk management. The CCRO advocates for

















