You Threw a Form 56-1 Into ChatGPT and Trusted the Summary — the Bank of Thailand Flatly Forbids Financial Institutions From Doing That
Retail investors drag a 56-1 into an LLM, ask whether the financials look good and whether to buy, get a polished summary that cannot point to its own sources, and trade on it. Meanwhile the Bank of Thailand has issued AI risk management guidelines covering both generative and agentic AI, anchored on the four FEAT principles, requiring a human in the loop wherever AI touches loan approval. This piece translates the regulator's standard into four hard rules a retail investor can apply immediately when talking to AI about their own money.
You Threw a Form 56-1 Into ChatGPT and Trusted the Summary — the Bank of Thailand Flatly Forbids Financial Institutions From Doing That
Retail investors drag a 56-1 into an LLM, ask whether the financials look good and whether to buy, get a polished summary that cannot point to its own sources, and trade on it. Meanwhile the Bank of Thailand has issued AI risk management guidelines covering both generative and agentic AI, anchored on the four FEAT principles, requiring a human in the loop wherever AI touches loan approval. This piece translates the regulator's standard into four hard rules a retail investor can apply immediately when talking to AI about their own money.
Friday night. You drag a 120-page Form 56-1 into a chat window and type the sentence hundreds of thousands of Thais type every week:
"สรุปให้หน่อย งบบริษัทนี้ดีไหม น่าซื้อไหม" [summarize it, are the financials good, is it a buy — you have handed over the decision and asked for the reasoning as a courtesy]
Ten seconds later you have a five-bullet summary. Well written. A number attached to every claim. Ten times easier to read than the document itself. You finish it. You hit buy on Monday.
Now ask one question: which page of that file did those numbers come from?
If you cannot answer — and most people cannot, because the summary arrived with no page numbers attached — you just made a real money decision on text that cannot be traced back. The figures may be real and lifted straight from the document. They may be figures the model assembled because they sounded plausible (the technical term is hallucination). From the summary alone, you cannot tell the two apart.
I validate risk models inside Thai banks under the regulator's eye. Here is how badly financial institutions fear the thing you just did: badly enough that the Bank of Thailand issued a guideline specifically to control it.
1. The two paths for pointing AI at a filing
🔴 THE RETAIL TRAP — what most people do on a Friday night
Drag the Form 56-1 (120 pages) into the chat
│
▼
"Summarize this. Are the financials good? Is it a buy?"
│
▼
AI digests the whole book → returns 5 bullets + clean-looking numbers
│ ⚠️ No page numbers, no links, no way to tell real from invented
▼
Trust the summary → hit buy on Monday
│
▼
If a number is wrong, you find out from the loss (and still not why)
🟢 THE INSTITUTIONAL STANDARD — what the regulator makes banks do
Type the question in plain language: "What does management say about liquidity?"
│
▼
Semantic search runs across the whole document corpus
│
▼
Returns the verbatim source text + company + year + page number + 56-1 link
│ ✅ Every line clicks back to the original
▼
A human reads the full context → decides → owns the outcome
The difference is not which AI is smarter — both paths may run the same model. The difference is who makes the decision, and whether the answer can be traced back to a source. That is the core of what the BOT has just put on paper.
2. What happened: the BOT laid down AI rules for financial institutions
Per the US-ASEAN Business Council, "On September 12, the Bank of Thailand (BOT) released its AI Risk Management Guidelines for Financial Service Providers" — the BOT issued the set after a public consultation on the draft that closed on 30 June 2025. Get its status right: "The voluntary document also encourages financial services providers to notify customers of AI involvement" — a guidance document, voluntary, not a statute with penalties behind it.
The spine is unambiguous. US-ABC describes the guidelines as "outlining AI governance best practices (e.g., fairness, ethics, accountability, and transparency principles) and AI system development and security controls" — the four FEAT principles: fairness, ethics, accountability, transparency, alongside development and security standards for the system itself.
Why it matters to us: in model risk work, "voluntary" does not mean "skip it." What a regulator publishes as guidance today is usually the baseline you get asked about in next year's examination. For a retail investor it means something else: the people in this country who see AI risk most clearly are not the ones afraid of technology. They are the ones managing other people's money.
3. FEAT, translated into four hard rules for an investor
FEAT was drafted for institutions with compliance teams ten people deep. Almost all of the logic inside it compresses down onto one person and one portfolio. This is the translation I use myself:
| The regulator's principle | What the bank has to do | Your hard rule when you talk to AI about stocks |
|---|---|---|
| Fairness | The model must not discriminate against any group of customers. | Do not ask a question that dictates its own answer — "บอกหน่อยว่าหุ้นนี้ดียังไง" [tell me what is good about this stock — and it will go find you good things, because that is what you ordered]. Ask neutral: ผู้บริหารเขียนถึงความเสี่ยงอะไรไว้บ้าง [which risks did management put in writing themselves]. |
| Ethics | Use AI in ways that do not damage customers. | Do not give AI a job it should not hold. It is a research clerk, not an investment adviser, and not a fortune-teller. |
| Accountability | Someone must be identifiable as answerable for the model's output. | You own that buy order, not the chatbot. If you cannot explain your own reasoning without falling back on "the AI said so," you are not ready to press the button. |
| Transparency | Be able to explain where the output came from. | The hardest rule of the four: no source = it does not exist. Every number has to point at a document and a page. If it cannot point, treat it as not yet data. |
The first three are discipline on the part of whoever is asking. The last one is about the tool — however disciplined you are, if the tool refuses to tell you where the answer came from, you cannot satisfy Transparency at all.
4. The guidelines name "agentic AI" outright — not just the old credit models
Older model risk standards were written with statistical and credit models in mind. The BOT definition is wider. The law firm Tilleke & Gibbins summarizes it as "AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI." — LLMs and agentic AI (systems that execute multi-step work on their own) sit explicitly inside the perimeter, not just legacy credit scorecards.
Regional regulators are moving the same way. Singapore's MAS AIRM guidelines and India's RBI draft model risk framework both pull the newer AI into scope, while some national frameworks still carve gen AI out. That gap is what a risk team has to read correctly.
Why it matters to us: once agentic AI is named in the text, "it is only an assistant, not a model" stops working as a defense. Retail investors run the identical defense on themselves — it is just helping me summarize, it is not deciding for me — when in practice, if you hit buy because of that summary, it already decided for you.
5. The most important line: a human stays in the loop on loan approval
The line I think matters most to anyone in lending is human oversight. Tilleke quotes it: "When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes." — read literally: if AI touches loan approval or account opening, a person has to sit inside the decision process. The system does not get to close the decision by itself.
This is the same principle I have applied validating credit models all along — the model proposes, but there must be a point where a person reviews, explains the reasoning, and overrides when the output makes no sense. (I laid out the same frame from the build side in an NLP early-warning system inside a bank.)
And this is where I want you to stop for a second:
Banks have risk teams. Validation teams. Internal audit. A regulator checking the checkers. Enormous capital and models tested over years — and they still will not let AI close a loan approval without a human in the loop.
Then on Friday night you let one chatbot — with no validation team, nobody checking it, and no willingness to tell you which page a number came from — decide for you about your own savings.
Why it matters to us: human in the loop becomes ceremony the moment the person clicks approve without understanding how the model got there. The real point is not having a button for someone to press; it is making the AI's output explainable in reverse until the person overseeing it can make a decision that means something. For your portfolio, that person in the loop is exactly one person, and they are reading this line.
6. Govern the whole AI lifecycle and notify the customer — not just at deploy
The guidelines do not look only at the moment a model goes live. Tilleke summarizes: "Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases." — control starts by setting risk appetite before you begin and runs through continuous risk assessment and control across the whole service life, tuned per use case. Not one document filed once.
The other side is customer rights. Tilleke states: "In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features." — customers should be told when AI is involved, and given a way to turn the AI features off or go around them.
Why it matters to us: "control the whole lifecycle" is the phrase every model validation person knows best, because a model is not risky only on go-live day. It is risky when the data shifts, when customer behavior shifts, when nobody is watching it. The retail version of this rule: do not assume a tool that was accurate last month is accurate forever. Models get updated quietly. The only defense is to keep clicking through to the source, not to stop checking because "it has been right so far."
7. The 2026 direction: the financial rules are in force and an AI Governance Center is coming
The big picture this year is that financial-sector rules are no longer a future problem. Thailand Business News (March 2026) reports sector-specific rules covering "financial services, addressing algorithmic decision-making, risk modelling, and customer-facing AI in banking and fintech." — algorithmic decision-making, risk modelling, and customer-facing AI at banks and fintechs, all inside the fence.
The national framework is coming behind it: "a comprehensive national AI framework currently in development, with enactment projected within the next few years." with a dedicated supervisor attached — "Oversight of this framework will fall to a newly created body: the AI Governance Center." Insurance is moving in parallel — AppMan (July 2026) states that "the OIC has introduced AI governance guidelines to balance innovation with consumer protection." The OIC has issued its own AI governance guidance.
Why it matters to us: the direction is clear — the supervisory floor is rising from recommended to expected. And note what none of these rules do: not one of them bans AI. They require that you can explain where the answer came from, and that someone is accountable for it — a standard a retail investor can pick up for free today, without waiting to be forced into it.
8. So I built the tool to the same rule: no black box
When it came time to build my own filings search tool, I had two options — build the version that demos well (let the AI read the whole book and summarize it into a nice paragraph about why this stock is interesting), or build the version that passes the standard I use to review models inside a bank.
I took the second, and that means Boom Leverage Terminal deliberately does not do things plenty of customers ask for:
- It will not tell you whether a stock is a buy — that is a decision, not a search, and Accountability says the decider has to be the one who can absorb the outcome.
- It will not return an answer without a source — every result is the verbatim source text from the MD&A, with company name, year, period, page number, and a link to the Form 56-1 as published by the SEC (Thailand's Securities and Exchange Commission). Every line clicks back to full context.
- It will not smooth the language to read better — some sentences you see are cut off raw mid-sentence. That is what the document actually looks like, not an article an AI rewrote.
Put another way: it is a research clerk that is very good at finding documents and has no standing whatsoever to opine on your money — the human in the loop is you, exactly as the guidelines say the loan officer makes the final call.
And in fairness to the technology, the limitation on my side: semantic search always returns something that "looks relevant," and sometimes the match is superficial or from the wrong context — which is precisely why it has to put the source passage in front of you every time. If a passage is off point, you see it in two seconds. That is not true of a summary, which hides its errors inside fluent prose. (I wrote the same verification discipline out in detail in why any number from an AI has to clear three layers of checks, and a real case in AI agents starting to move real money inside the banking system.)
9. Turn AI from portfolio fortune-teller into research clerk
The whole thing in the fewest words: the BOT has laid down AI rules covering both generative and agentic AI, anchored on the four FEAT principles, requiring human oversight wherever AI touches loan approval, and requiring risk control across the full lifecycle plus notice of customer rights. Today it is guidance. The 2026 direction is that it becomes the expected standard. The advantage does not go to whoever has the most AI. It goes to whoever can make their AI explain itself, be audited, and name someone accountable.
For your portfolio, that compresses into changing one command — stop typing "สรุปให้หน่อยว่าน่าซื้อไหม" [summarize it and tell me whether to buy — an order to decide on your behalf] and start typing "หาให้หน่อยว่าผู้บริหารเขียนเรื่องนี้ไว้ว่าอย่างไร" [find me what management wrote about this — an order to fetch evidence you can check yourself].
Try it tonight, free: open Boom Leverage Terminal, type the risk that scares you most about a stock you hold, in plain Thai. It returns the actual paragraph from the 56-1 with the source link to click through — start free, 10 credits/day, no card required — then set it against the summary a general chatbot gives you and decide which one you would put on the table and say "I checked this" about.
If one line survives this article, make it this one: no source = it does not exist — that is the rule the regulator applies to banks that manage the whole country's money, and it should be the rule you apply to your own.
For anyone working data/risk in Thai finance, this is our ground: the skill of setting a measurement frame, establishing a baseline, and testing whether a model creates real value or just looks good is the same skill used to hold AI to this standard · Team and institutional access (seats · Excel export · API) at the Enterprise page or contact@boomleverage.com
This content is for education and sourced news summary. It is not legal or investment advice. Work from the BOT's original documents when you have to comply in practice.
Sources
- Thailand Drafts AI Risk Management Guidelines for Financial Service Providers — Tilleke & Gibbins
- Thailand Issues New AI Guidance for Financial Services — US-ASEAN Business Council
- Thailand Navigates a New AI Era: What Businesses Must Know in 2026 — Thailand Business News
- AI Governance Guidelines in Thailand (BOT & OIC 2026) — AppMan
Read next
80% of Financial Firms Now Run AI. Only 40% See Higher Profit — Is the AI Reading Your Filings Actually Improving Your Portfolio?
Read more AI in FinanceAI Agents Are Now Moving Real Money Inside Banks — And It's the Same Risk Your Portfolio Runs Every Day
Read more MD&AOne Red Flag Was Never Enough: I Counted 104,153 Lines Thai Companies Wrote About Themselves, and All Six Lenses Lit Together Only 9 Times
Read more