
The Hong Kong Monetary Authority (HKMA), alongside the SFC, IA, MPFA and Cyberport, has launched the upgraded Generative AI Sandbox++ (GenA.I. Sandbox++). Building on the 2024 pilot version, the expanded sandbox extends coverage from banking to securities, wealth management, insurance, MPF and stored-value payment facilities. HKMA CEO Eddie Yue called it a landmark of the FinTech 2030 strategy, demonstrating Hong Kong’s push for responsible generative AI innovation.
The expansion signals a shift from scattered AI trials to large-scale cross-industry financial AI deployment. Focused on risk management, anti-fraud and customer experience, the sandbox rolls out HKMA’s “Managing AI with AI” strategy, which uses AI to offset AI-native risks. Financial Secretary Paul Chan noted sandboxes are Hong Kong’s signature cross-sector regulatory tool: innovators test AI tools in controlled settings to spot risks early, with access to tailored regulatory guidance, technical support and Cyberport’s supercomputing GPU resources.
Yet computational resources alone cannot balance innovation and risk. Generative AI is embedded across core financial workflows, including smart customer service, anti-fraud modelling, investment valuation and insurance claims. Traditional testing fails to address model drift—gradual decay of predictive power as real-world data shifts. Fraud detection logic, for example, can become outdated within six months; without ongoing monitoring, flawed systems remain undetected.
This is the core challenge of “Managing AI with AI”. HKMA has set up a cross-industry task force to monitor and remediate AI risks. Unlike fixed-output conventional software, generative AI yields uncertain results, rendering classic input-output testing ineffective. Regulators require banks to classify AI tools into internal, customer-facing and decision-support systems, and embed prompt design, output control and model validation into governance. AI testing therefore must cover the full product lifecycle: pre-launch design validation, plus post-launch continuous monitoring and automated regression tests.
A Hong Kong FinTech Association April white paper surveyed 103 financial and fintech firms, recording a 38% local AI adoption rate versus the 26% global average. Over 75% of Hong Kong banks have deployed or trialled AI for credit, risk and client services. Key adoption barriers include talent shortages, weak data governance and disjointed system integration. Paul Chan stressed a core rule: AI only aids decisions, and humans retain final authority.
Against this backdrop, AI testing has become vital fintech infrastructure. As Cyberport’s official AI testing provider, Smart Testin delivers full-lifecycle compliance-focused quality assurance for finance and government clients via its “People-Tools-Services” model.
Its evaluation system follows the GB/T 25000.10-2016 standard, assessing eight dimensions including functionality, performance and data security. It operates a cloud testing hub with over 10,000 cross-platform devices (Android, iOS, HarmonyOS), Cantonese-speaking specialists and cross-border dedicated test networks. Multilingual audit-ready reports (Simplified Chinese, Traditional Chinese, English) meet Hong Kong’s local compliance demands. The platform leverages LLMs to auto-generate test scripts, reuse code across systems and identify UI elements, supporting frequent iterations of financial apps.
Yu Deshui, Deputy General Manager of Smart Testin Hong Kong, said Sandbox++ pushes firms to prioritise stable, secure and compliant AI over mere AI adoption, introducing three new testing requirements:
1.Full-chain quality oversight covering model inputs, outputs and decision pipelines, replacing fragmented functional checks;
2.Sustained automated validation with model drift tracking and recurring regression tests, instead of one-off pre-launch audits;
3.Audit-orientated data tracking, with all test records traceable for regulatory on-site inspections.
He added fintech firms compete on innovation speed outwardly, but long-term competitiveness rests on robust full-lifecycle quality governance.
Globally, Gartner projects 70% of enterprises will adopt AI-enhanced testing by 2028, up from just 20% in early 2025. This 50-percentage-point jump reflects a broader shift from manual labour to AI-powered testing platforms, aligning perfectly with HKMA’s sandbox regulatory goals. An AI project’s move from sandbox to live production hinges not on model performance limits, but on credible, sustained risk assurance from testing and governance frameworks.
Zhang Pengfei, Smart Testin Partner and Hong Kong Head, stated testing vendors now act as cross-industry quality governance partners linking regulatory rules and engineering practice, rather than simple bug finders. Hong Kong’s strict rules for cybersecurity, audit trails and data integrity match BIS guidance requiring digital financial infrastructure to meet traditional market infrastructure safety standards. Smart Testin secures test data via end-to-end SSL encryption and provides formal data deletion certificates.
GenA.I. Sandbox++ is merely the starting line for Hong Kong’s responsible AI agenda. Sustainable financial AI growth depends on parallel progress in innovation and quality governance. Regulators deliver a controlled testbed, while professional testing infrastructure acts as an essential hidden safety net. Moving forward, Hong Kong’s financial AI competition will centre on embedding responsible innovation into every code iteration, development cycle and audit report—from sandbox trials to full production, from ad-hoc spot checks to continuous full-lifecycle governance.