The People's Bank of China's clearing house just drew a line in the sand. On August 24, 2024, the Payment & Clearing Association of China released its Self-Regulatory Convention for Intelligent Payment Applications. The document is short. The implications are not. This is the first national-level framework attempting to codify how artificial intelligence intersects with the movement of money. The market has barely reacted. That is a mistake.
For years, the narrative around AI in payments has been about speed, convenience, and the magic of frictionless transactions. The convention reframes the entire conversation. It is not about what AI can do. It is about who is allowed to let it do anything. The core provision is deceptively simple: any intelligent payment application touching account management, transaction processing, or clearing and settlement must be operated by a licensed institution. Banks, licensed non-bank payment firms, and clearing organizations qualify. Pure technology companies do not.
This is not a new regulatory philosophy. It is the extension of the 'disconnect direct' and 'licensed operation' mandates from the 2018 era into the age of large language models. The intent is precise. It closes the loophole where tech firms could claim to be 'technology service providers' while effectively running core payment rails. The convention forces a structural separation. AI can be the engine, but the steering wheel remains in the hands of the licensed.
My audit experience from the 2017 ICO era tells me this pattern is familiar. When regulators move from silence to codification, they are not reacting to a single event. They are responding to a pattern of risk accumulation. The convention is a preventive strike. It acknowledges that AI in payments is no longer experimental. It is systemic. And systemic technology requires systemic accountability.
The core mechanism here is 'licensed operation plus responsibility lock.' The convention does not merely restrict who can operate. It assigns liability. Member institutions bear primary responsibility for account security, transaction security, and fund security. This is the critical clause. It means a licensed institution cannot hide behind an AI vendor's black box when a model fails. If an algorithm makes a bad decision, the license holder pays. The ledger remembers what the narrative forgets.
This responsibility lock has a direct technical consequence. It forces an architectural principle that is not explicitly written but is logically implied: the decoupling of AI systems from core payment infrastructure. A licensed institution cannot allow an experimental model to destabilize the settlement engine. The result will be a dual-speed IT architecture. A stable, auditable core. A flexible, innovative AI layer. The two must not mix. This is not a technical preference. It is a survival requirement.
Consider the risk landscape. The convention's emphasis on 'primary responsibility' for security directly implicates AI-driven risk control systems. The industry trend has been to replace rule-based engines with machine learning models. These models are more effective at detecting fraud. They are also less explainable. The convention's liability framework creates a regulatory demand for explainable AI. If a model denies a legitimate transaction or fails to catch a fraudulent one, the institution must be able to explain why. 'The algorithm did it' is not a defense. It is an admission of negligence.
This is where the market misreads the signal. The conventional wisdom is that the convention is a brake on innovation. It is not. It is a reallocation of value. The convention transforms AI capability from a competitive differentiator into a compliance threshold. In the old game, having a better fraud model was a way to win market share. In the new game, having a compliant fraud model is the price of entry. The winners will be those who can turn compliance into a product. The losers will be those who treat it as a cost center.
The contrarian angle is that the 'soft law' nature of the convention is its greatest strength, not its weakness. A self-regulatory convention lacks the binding force of a departmental regulation. Critics will call it toothless. They are wrong. The convention was developed through extensive consultation with member institutions. This process builds consensus. It creates a shared understanding of acceptable behavior. When the inevitable upgrade to formal regulation arrives, the industry will have already internalized the standards. The transition will be seamless. The convention is not the destination. It is the training ground.
This is the pattern of Chinese financial regulation. It tests the waters with soft law, observes the industry response, and then codifies what works. The 12 to 18-month window is the observation period. The signals to watch are clear. If the central bank or the financial regulator issues a formal classification system for AI financial applications, the convention has served its purpose. If the association publishes specific algorithmic filing and audit requirements, the compliance burden becomes concrete.
The business model implications are significant. The convention redraws the value chain in intelligent payments. Licensed institutions capture the core value: accounts, transactions, clearing. Technology companies are pushed to the periphery: model training, data annotation, infrastructure. This is a deliberate rebalancing. The large tech firms that already hold payment licenses, Alipay and WeChat Pay, are largely unaffected. They are already inside the tent. The pure AI companies, the ones without licenses, are now outside looking in. Their path forward is not independent operation. It is deep partnership with a licensed institution.
This creates a new B2B market. Licensed institutions will need to productize their AI compliance capabilities. A bank that has built a robust model risk management framework can sell that framework to a smaller bank. A payment giant with a proven anti-fraud system can offer it as a service to regional institutions. This is the 'compliance tech' opportunity. It is not as glamorous as consumer AI, but it is more durable. We do not build in the dark; we audit the light.
The concentration risk is real. Smaller licensed institutions will struggle with the compliance costs. AI audits, model filings, and liability tracing mechanisms are expensive. The head institutions have the resources to absorb these costs. The tail institutions do not. Expect consolidation. Expect mergers. Expect the market share of the top three players to increase. This is not necessarily a bad outcome. A payment system with fewer, stronger, and more compliant players is more stable. But it is a risk that regulators must monitor. The 'too big to fail' problem does not disappear because the industry is consolidated. It becomes more acute.
The international dimension is often overlooked. The convention aligns with global trends in AI governance. The EU AI Act classifies certain AI systems as high-risk. The NIST AI Risk Management Framework in the United States provides voluntary guidance. China is now moving toward a similar structure for payments. This convergence is not accidental. It reflects a shared recognition that AI in finance is a systemic risk that requires systemic oversight. Chinese payment institutions expanding overseas will face dual compliance pressure. They must meet domestic requirements and local regulations. This is a burden. It is also an opportunity. The compliance expertise developed in China can be exported as a competitive advantage.
What does this mean for the next narrative? The convergence of AI and payments is not slowing down. It is being disciplined. The era of unregulated experimentation is over. The era of structured innovation has begun. The institutions that thrive will be those that treat compliance not as a constraint but as a design principle. They will build AI systems that are not only effective but also explainable, auditable, and reversible. They will understand that the ledger remembers what the narrative forgets.
The question for the market is not whether the convention will slow down AI adoption. It will not. The question is who will capture the value created by compliant AI. The answer is the licensed institutions that can turn their compliance burden into a service offering. The answer is the technology companies that can adapt to a supporting role. The answer is the regulators who have learned to guide innovation without killing it.
We are witnessing the codification of the intangible. The convention is an attempt to translate the abstract promise of AI into the concrete language of liability, licensing, and audit. It is a governance experiment. It will not be perfect. There will be gaps. There will be unintended consequences. But it is a necessary step. The alternative is a race to the bottom, where the fastest AI deployment wins, regardless of the risk. That is not a future worth building.
Codifying the intangible: how art becomes asset, how code becomes law, how AI becomes accountable. The convention is a document. It is also a signal. The signal is that the era of AI exceptionalism in payments is over. The era of AI accountability has begun. The institutions that internalize this shift will lead the next cycle. The ones that do not will be audited out of existence. The ledger does not lie.