Farewell Address of Commissioner Kristin N. Johnson
Commissioner Kristin N. Johnson
September 03, 2025
Thank you to Aaron Klein, Miriam K. Carliner Chair—Economic Studies, Senior Fellow—Center on Regulation and Markets and Brookings Institute for kindly inviting me to join you this afternoon. Thank you for your thoughtful introduction.
A Critical, High-Stakes Moment
There is no better place to close out my tenure as a Commissioner at the Commodity Futures Trading Commission (CFTC or Commission) than with a conversation on the future of financial regulation.[1] It is a privilege to join you at Brookings. You have demonstrated an unparalleled commitment to convening stakeholders and the public to explore significant questions such as—what does the future of financial markets look like?
As someone who spent part of my career as a lawyer in private practice, in-house at a large financial institution, as an academic, and now a regulator—I know exactly how important great conversations are for developing transformative policy insights.
We gather at a critical moment in the history of our nation and a unique time in the evolution of financial markets and the role of financial markets regulation.
It has never been more important for the public to be engaged and have a voice in the role of financial market regulation. The decisions that Congress and regulators will make during the next few years will shape our national economy, the global economy, and the role of the United States in the global economy for generations to come.
The stakes are high. And, if I only have one piece of wisdom to share, it would be the following—Get it right. Measure twice, cut once.
Deciding the course for financial markets and financial markets regulation simply requires remembering why we regulate and the catastrophic consequences that may follow if we fail to regulate well.
Throughout my tenure as a Commissioner at the CFTC, I have prioritized two pillars that anchor the foundation of financial markets regulation—consumer protection and market stability.
Consumer Protection and Growth—Twin Pillars, Anchoring Values
Some may try to challenge the notion that these values work together and argue that sustainable growth and consumer protection are in tension, at odds, or mutually exclusive. I reject the notion that these anchoring values are in conflict and instead argue that each is a necessary component of a healthy financial system.
Recall, in 2008, on a September day, similar to the cool, crisp weather we are enjoying today, lawyers for Lehman Brothers entered a federal court building, and one of the most storied financial institutions in our nation’s history filed for bankruptcy protection. The filing served as a catalyst, precipitating the events of a global financial crisis.
According to the Federal Reserve Bank of New York, around the same time “[i]n September 2008, the Federal Reserve extended credit to American International Group, Inc. (AIG) to preserve the stability of an already fragile U.S. economy and to protect the U.S. taxpayer from the potentially devastating consequences of the company's disorderly failure. From that initial intervention, the New York Fed and the U.S. Department of the Treasury worked with AIG to stabilize the company so that it no longer posed a systemic risk and to ensure repayment of taxpayer assistance.”[2]
A little over a decade later, on a similar day in the fall of 2022, after cascading losses and multiple collapsed crypto firms, lawyers for FTX marched into a federal court building seeking bankruptcy protection.
What should we take away from these crises?
Lessons Learned from Crises
If we fail to rightly prioritize consumer protection or market stability on the road to capturing the benefits of innovation or growth, the results can be devastating.
When I share the story of Lehman or AIG or the more contemporary story of FTX, I emphasize that certain guardrails or safety measures may well have helped prevent the 2008 financial crisis and certainly could go a long way to ensuring that developing digital asset markets function in a manner that is consistent with consumer protection and market stability and integrity.
To achieve sustainable growth and get it right, we must measure twice, cut once.
The Costs of Risk Management and Corporate Governance Failures
Crises have the potential to create catastrophic costs for customers, creditors, investors, markets, and the domestic and global economies. The factors that lead to corporate governance and risk management failures are often clearly identifiable, easily predicted, and often preventable. Firms that experience significant corporate governance and risk management failures often seek bankruptcy protection, only to later re-emerge from bankruptcy to solicit and expose new customers to devastating losses because the firms continue relying on the same deeply deficient (and possibly non-existent) governance, compliance, and risk management programs. Unfortunately, unless these firms learn from this experience and adopt a culture of compliance that effectively alters behavior and closes gaps in risk management and corporate governance, they will find themselves repeating the same cycle.
We’ve Seen This Movie (or Bankruptcy) Before
For almost a decade, but with increasing frequency in recent years, international media headlines repeatedly (sometimes weekly, and sometimes almost daily) present a new cautionary tale. The cautionary tales are woven together by a set of common threads.
An almost 30-year-old CEO launches an international crypto-exchange. Within a few years, the founder and the exchange achieve crypto-celebrity status. At its peak, the exchange captures significant market share—processing a sizable percentage of global coin or token transactions. The firm, organized in a jurisdiction outside of the United States, lacks many aspects of traditional corporate governance including oversight by a qualified, informed, engaged and independent board of directors.
All too often, the corporate governance and, compliance systems—including anti-money laundering and know your customer programs, and conflicts of interest policies that prohibit or limit certain transactions (particularly self-serving loans)—may be weak or may not exist at all.
Like lightning striking, in an instant, the exchange suspends trading, shutters the windows for withdrawals, silences traffic on its website, and files for bankruptcy protection—leaving customers infuriated, investors stunned, and creditors scrambling in a footrace to the courthouse.
Interconnectedness among crypto-firms amplified by fragile or non-existent risk management, corporate governance failures, and conflicts of interests at individual firms fuels the likelihood of crises.
In the late spring of 2022, a “run” on the fourth largest stablecoin and tenth largest cryptocurrency, TerraUSD (“UST”), led to a precipitous decline in the value of UST and, in tandem, a sell-off of LUNA, its companion token. A broad market sell-off and cascading losses followed. With the onset of a “crypto winter,” a number of highly-influential and central crypto-firms lunged toward bankruptcy. With significant exposure to the TerraLUNA ecosystem, Three Arrows Capital (“3AC”), a Singapore-based crypto-hedge fund, defaulted on a loan to crypto-lender Voyager Digital. On July 1, 2022, less than one week after the default, 3AC filed for bankruptcy protection. Almost on cue, within a week, Voyager halted trades, deposits, and withdrawals and filed for bankruptcy protection. Eight days later, another crypto-lender, Celsius Network, also filed for bankruptcy.
In November 2022, FTX and BlockFi joined the list of crypto-firms seeking bankruptcy protection; and the list continued to grow.
A week after FTX filed for bankruptcy, I delivered a keynote address at the annual meeting of the Federal Reserve Bank of Chicago Financial Markets Group. I emphasized the need for proactive adoption of internal governance and risk management measures that introduce important know-your-customer and customer identification program obligations, financial resource requirements, limitations on the use and treatment of customer funds, internal controls and conflicts of interest policies designed to address transactions with affiliates. I admonished firms that have failed to implement recovery and resilience programs. Businesses operating in our markets must have a day-one plan for how to address a capital shortfall.
Later that same week, at Stanford Law School’s Crypto-Policy Conference, I explained the need for the Commission to have a seat at the table as the court and creditors considered an appropriate buyer in the sale of non-debtor LedgerX. While there has been a general acknowledgement of the need for any buyer to be “familiar with” the Commodity Exchange Act (CEA) and CFTC regulations and a historic acquiescence to Commission inquiries, regulations only provide that the CFTC receive notice of the transfer of equity ownership. Particularly in times of crises, such a low threshold may not be sufficient to ensure that the Commission receives meaningful access and material information regarding all relevant aspects of the transaction in real time.
Customer Protections Look Similar in Most Markets
Don’t lie. Don’t cheat. Don’t steal.
Customer protection is a foundational and core principle of our market regulatory framework. Several specific provisions of the CEA direct the CFTC to adopt regulation to this effect.
Customer funds consist of margin collateral posted by customers of futures commission merchants (FCMs) to cover exposure under their futures contracts. Section 4d(a)(2) of the CEA requires each FCM to segregate from its own assets all money, securities, and other property deposited by futures customers to margin, secure, or guarantee futures contracts and options on futures contracts traded on designated contract markets.
In addition, Section 4d(a)(2) of the CEA requires an FCM or the custodian of customer funds to treat and deal with customer funds as belonging to the customer, and prohibits an FCM from using the funds deposited by a futures customer to margin or extend credit to any person other than the futures customer that deposited the funds. After the collapse of MF Global and Peregrine Financial Group, the Commission thoughtfully and meticulously supplemented the protections embedded in Commission regulations 1.20 through 1.30, and 1.32 to enhance customer protections and transparency at the FCM level.
Two Hard Truths
First, governance and risk management failures can and often do lead to crises, including liquidity crises. Second, apart from undermining the reputational integrity of the industry and fueling calls for harsh regulatory and legislative action, these failures all too often impose tremendous costs that fall disproportionately on customers.
In my final months at the Commission, we also witnessed a surge in new applicants and registered market participants in prediction markets. These prediction market contracts enable retail investors to take a position on everything from U.S. elections to whether Michigan would take New Mexico in the season opener in Ann Arbor last weekend (as an alumnae of the law school, I will admit that I am glad to see that Michigan did secure that win).
I am disappointed that during my time at the Commission we were not able to successfully advance a final rule that addressed the introduction of political event contracts. Activity in markets in most recent months underscores my concerns and the concerns of others about prediction markets.
As of today, we have too few guardrails and too little visibility into the prediction market landscape. Because the target audience for these contracts is retail customers and some market participants seem to be marching down a path to offer leveraged, margined prediction market contacts to retail investors, there is an urgent need for the Commission to express in a clear voice our expectations related to these contracts.
A bi-partisan group of members of Congress indicated that they agreed with that the CFTC should not be required to police election contacts and expressed concerns about betting on the outcome of democratic elections. There are also a number of legal questions surrounding these contracts that the Commission should use the rulemaking process with embedded notice and comment period obligations to create effective regulation to address.
Finally, the “rent or buy” my license in derivatives markets is booming as prediction markets promise to eclipse crypto markets in volumes of retail customers’ cash captured. The Commission has recently witnessed a number of newly created and legacy firms seeking licenses to offer event contracts. In a number of instances, these businesses approach the Commission seeking licenses to offer traditional products, only to quickly shift once a license is in hand and seek to self-certify prediction market contracts. In other contexts, firms that have received a license quickly auction their newly minted license to others.
Never Let a Good Crisis Go to Waste
I referenced the financial crisis of 2008 earlier. As I return to academia, I appreciate that some of my students were not yet born when Enron collapsed and others may have been in elementary school during the 2008 global financial crisis. One of my goals as a teacher is to ensure that our students are well-versed in the history of financial markets regulation and that they understand my commitment to never let a good crisis go to waste.
Innovation, Cutting-Edge Technologies Impacting Market Stability and Market Integrity
To that end, during my time at the Commission, I have worked diligently to ensure that we advance our understanding of the innovation and cutting-edge technologies that have the potential to disrupt markets and create systemic risk concerns. While I will focus on cyber threats here, I have regularly advocated for financial market regulators to think critically about operational resilience and third-party risk management as well as concentration risks among third parties.
As I explained earlier, innovation and market stability should work together—enabling one to foster the other. I can identify at least a dozen of valuable use cases for artificial intelligence in financial markets—surveillance and compliance use cases immediately spring to mind.
However, as we integrate AI into financial markets, we must be aware of bad actors’ ability to use AI to perpetuate fraud. We must also be aware of risks that arise as hackers integrate or embed AI into necessary technology, facilitating cyber threats.
I have advocated for the CFTC and other U.S. federal regulators to collaborate in convening conversations regarding the integration of AI in financial markets. I worked with the Commission staff to develop the Commission’s request for comment on AI. I also supported Treasury in developing a request for information on the integration of AI in financial markets.
I have also advocated for some specific policy interventions that I believe may separate the wheat from the chaff.
First, for U.S. financial market regulators, coordination and cooperation are imperative. We must harmonize expectations. Second, we should enhance information sharing. Third, we need to strengthen crisis recovery and response. Finally, we must tackle concentration risk and supply chain vulnerabilities.
Even for these complex issues, the adage offered at the outset of my remarks still replies. Get it right—Measure twice.
Conclusion
In closing allow me to acknowledge the Commission’s most significant asset, its secret weapon—a Navy-seal styled (in some cases, literally) team of the most capable and talented lawyers, economists and professionals that I have had the privilege of working with—the CFTC staff. In a moment in time when it is easy to forget, it was the Commission staff that worked around the clock during the financial crisis to help get our markets back on track and to build the blueprint for a regulatory framework that has stood the test of a pandemic and significant geopolitical conflicts. Facing these issues alongside persistent inflation, our markets have demonstrated resilience. I credit markets’ resilience, at least in part, to the regulatory reform that followed the financial crisis in 2008 and the individuals who built those reforms by hand.
I also deeply grateful to President Biden and the many Senators that supported me during my confirmation process for my current role as a Commissioner at the CFTC as well as my nomination to join the U.S. Department of Treasury.
I am also thankful to everyone in my village. When I think of your support and sacrifices, I am overwhelmed with gratitude. I am hopeful that I made you proud and served you well.
[1] The views I share today are my own and not the views of the Commission, my fellow Commissioners or the CFTC staff. A portion of this speech is adapted from previously delivered remarks.
Commissioner Kristin Johnson Announces Departure from CFTC
Commissioner Kristin N. Johnson
August 26, 2025
For the last three and a half years, it has been an honor and a privilege to serve as a CFTC Commissioner. The CFTC is a small-but-mighty agency that punches above its weight, performing integral regulatory and supervisory functions. Recall how the CFTC demonstrated global regulatory leadership in response to the global financial crisis in 2010 - working with the International Organization of Securities Commissions and the Committee on Payments and Market Infrastructures through a series of international regulatory convenings as well as unprecedented domestic rule-making efforts, we developed the world's blueprint for swaps market reforms.
In the face of a global pandemic and significant geopolitical conflicts, our markets demonstrated significant resilience. Our bi-partisan Commission, characterized by consensus-driven decision-making, illustrates the strength of independent, democratic institutions and the value of well-calibrated, carefully-tailored regulation. Our markets' successful navigation of new and unprecedented challenges offers proof that our reforms have worked well and served our nation's economy as well as the global economy.
A key factor in the Commission's successful oversight of derivatives markets has been the effectiveness and determination - I'd call it grit - of the dedicated public servants who comprise the Commission's staff. The talented and dedicated CFTC staff work tremendously hard each day to ensure the resilience, integrity, and stability of derivatives markets. Standing on the front lines, the hardworking members of the CFTC staff supervise markets that help to ensure the production and harvesting of food that feeds our nation, access to energy needed to fuel homes, schools, businesses, as well as religious, community, and government institutions, and effective risk management that enables the execution of trillions of dollars in transactions daily throughout global financial markets.
The Commission and Commission staff serve as the tireless cop on the beat, effectively surveilling markets to identify and enforce against market manipulation and stamp out fraud - both Ocean's Eleven styled schemes as well as garden variety fraud perpetrated by fraudsters who seek to disrupt markets or distort market pricing or to target the most vulnerable investors through predatory campaigns aimed at retirees, rural, religious, or immigrant communities, or college students or recent graduates hoping to build a nest egg, among others.
This year marks the 50th Anniversary of the CFTC, but our history building derivatives markets regulation dates back to a much earlier time in our nation's history. At the turn of the century, Congress recognized the need for federal regulation in derivatives markets. As markets evolve, it is critical that the Commission receive necessary investments in infrastructure and technology as well as increased investments in our most valuable assets - the Commission staff who help to realize and reinforce our mission - customer protection, market integrity, market resilience, and market stability. As we witness transformative changes in markets characterized by accelerated development and deployment of innovative technologies, it is critical to ensure that we commit resources to upskill Commission staff to ensure a robust workforce proficient in the technology that will define the future of financial markets and journey ahead for our nation's economy.
To those who served with me at the Commission, I’m proud of what we’ve accomplished together. I carry with me an abiding respect, tremendous admiration, and deep appreciation for each one of you. Your commitment to our mission and to one another is nothing short of inspiring. Support one another. Stay focused on the work of ensuring the stability of our markets and the economy and continue to build the careful, transparent, informed, and consensus-driven regulatory framework that reflects the Commission's legacy for the past five decades.
I owe a tremendous debt of gratitude to the members of the Market Risk Advisory Committee (MRAC), the MRAC Subcommittees, the MRAC Chair Alicia Crighton, co-chairs of each of the Subcommittees, as well as my staff and Commission staff who served as designated federal officers and alternate designated federal officers for the MRAC Committee and Subcommittees. The invaluable work of the multi-stakeholder coalition of industry (exchanges, clearinghouses, futures commission merchants, among others), public interest advocates, and academics would not have been possible without your commitment, dedication, and contributions.
Earlier this year, I shared a statement indicating that I am forever grateful for President Biden's generous decision to nominate me to serve as a CFTC Commissioner and as an Assistant Secretary for Financial Institutions in the United States Department of the Treasury. I am also deeply thankful for the U.S. Senate's unanimous confirmation of my nomination to serve as a CFTC Commissioner and for the many Senators, Members, Senate Committee on Agriculture, Nutrition & Forestry and Senate Committee on Banking, Housing and Urban Affairs Members as well as Senate and Congressional staff members who have engaged with me and my office.
For nearly two decades, I have advocated for effective regulation of our markets. During my term of service, I proposed innovative initiatives for evaluating cyber threats, the integration of artificial intelligence in financial markets, domestic and international collaboration through regulators' roundtables and colleges, and critical market structure and customer protection reforms that will be exceptionally important, if not necessary, if the mandate for the Commission expands to include supervisory oversight of emerging digital asset markets.
In a moment when such significant changes to markets and market structure are contemplated, I am concerned that the expert staff at the Commission receive the support and investments needed to be successful.
In advancing an agenda in the name of growth, it is critical not to dismantle the foundational resilience that supports financial stability and protects the broader economy. Sustainable growth depends on, or better stated, is built upon a regulatory framework that ensures markets remain resilient in the face of volatility, uncertainty, and stress. The goals of growth and market integrity are not mutually exclusive. There is no true conflict between advancing the potential for growth and preserving market stability or integrity. It is possible to prioritize both goals. And, in every instance, consistent with our mission, regulation or any efforts to deregulate or streamline regulation should not leave customers or markets vulnerable to fraud.
Having had the honor and privilege of serving our nation at one of the world's premier financial market regulators, I do not plan to shy away from the work that we started. In fact, I am inspired to dig in and do more. I hope to identify new ways to be of service to customers, markets, and our nation.
Commissioner Johnson to Deliver Opening Remarks at the “Can AI Streamline Regulation and Reduce Compliance Burdens?” conference at the Milken Convening Center, The George Washington University
Statement of Commissioner Kristin Johnson: Recap of 2025 Regulators Roundtable on Financial Markets Innovation and Supervision of Emergent Technology
Commissioner Kristin N. Johnson
August 05, 2025
On July 14, 2025, in my role as Commissioner of the Commodity Futures Trading Commission (CFTC or the Commission), I convened a roundtable of market and prudential regulators including central bankers and consumer protection authorities from the United States, United Kingdom, and Europe in London, England – the 2025 Regulators Roundtable on Financial Markets Innovation and Supervision of Emergent Technology (Regulators Roundtable).
The Regulators Roundtable was followed by a separate Public-Private Roundtable on Surveillance and Supervision in the Age of AI and Digital Assets moderated by Bénédicte Nolens, Head of BIS Innovation Hub Hong Kong Centre, which I attended alongside regulators, market participants, and technology experts. Both events were held under the Chatham House Rule. The following summary offers key themes and takeaways from the roundtables as well as other recent convenings where participants discussed similar themes.[1]
I. 2025 Regulators Roundtable on Financial Markets Innovation and Supervision of Emergent Technology
At the Regulators Roundtable, participants examined the integration of artificial intelligence (AI), cyber risk and operational resilience, oversight of third-party service providers, the increasing adoption of digital assets, and transformations in market structure. The Regulators Roundtable further developed themes explored by Commission staff requests for information and advisories on the integration of AI as well as robust governance frameworks and recent recommendations by the advisory committee that I have sponsored for the last three years – the CFTC’s Market Risk Advisory Committee (MRAC).
Key Themes and Takeaways
1. Artificial Intelligence and Regulatory Oversight
Participants discussed the growing adoption of AI in trading, risk management, surveillance, and compliance. The use of AI tools, particularly through third-party vendors, has increased efficiency and, in some contexts, accessibility, but also introduced novel risks related to explainability, bias, and governance.
During the roundtables, I emphasized the need for fit-for-purpose regulatory frameworks that account for AI’s systemic implications. I highlighted the importance of international alignment, referencing standards such as the CPMI-IOSCO Principles for Financial Market Infrastructures (PFMIs). Participants supported enhancing supervisory visibility in AI applications and encouraged post-deployment monitoring and scenario-based testing.
2. Cybersecurity and Operational Resilience
Cyber risk remains a top concern. Recent high-profile disruptions include:
The 2023 ransomware attack on ION Derivatives, which impacted global derivatives clearing and risk reporting; the 2024 CrowdStrike software failure, which caused global outages across banking, aviation, and healthcare sectors; and the 2025 Bybit cyberattack on a third-party infrastructure vulnerability resulting in over $1.5 billion in digital asset losses.
I emphasized the importance of cyber resilience, which must address both external attacks and internal technology failures. Participants agreed that supervisory frameworks should incorporate continuous testing, incident response planning, and firm-level accountability.
3. Proposed CFTC Operational Resilience Framework
In December 2023, the CFTC unanimously approved a rule proposal requiring that futures commission merchants, swap dealers, and major swap participants implement an Operational Resilience Framework designed to address risks relating to information and technology security, third-party relationships, and preventing disruptions to business operations.
I provided an update on the proposed rule, which would require futures commission merchants, swap dealers, and major swap participants to implement a technology and information security program; a third-party relationship management program; and a business continuity and disaster recovery plan.
The proposed rule seeks to ensure that critical operations continue in the face of disruptions. I also highlighted the MRAC Central Counterparty (CCP) Risk & Governance Subcommittee’s recommendations to expand operational safeguards to derivatives clearing organizations (DCOs), including enhanced oversight of critical third-party service providers and a requirement for third-party providers to comply with the PFMIs. The Subcommittee’s December 2024 report, Recommendations on DCO System Safeguards Standards for Third-Party Service Providers, proposes modernizing CFTC Rule 39.18 by requiring DCOs to establish a Third-Party Relationship Management Program. The updated rule would require DCOs to implement lifecycle vendor oversight policies, conduct pre-selection resilience assessments, and identify and monitor critical third-party service providers.[2]
4. Third-Party Risk Management and Infrastructure Concentration
Participants agreed that growing reliance on cloud, cybersecurity, and AI service providers may introduce new risk management concerns. For several critical infrastructure services, there are a limited number of third-party providers capable of supporting the volume and scale of transactions for many registered market participants. Attendees emphasized that traditional risk management practices must be updated to address growing reliance on technology infrastructure. Some attendees raised questions regarding the potential for service provider disruptions, e.g., cyber threats, to create systemic risk concerns.
Participants shared insights from the ongoing implementation of the Digital Operational Resilience Act (DORA), highlighting efforts to establish regulatory oversight of critical information and communication technology (ICT) service providers.[3]
5. Digital Assets, Stablecoins, and Market Structure
The discussion explored how tokenization, stablecoins, and distributed ledger technology (DLT) are transforming financial markets. Participants emphasized that innovation should not compromise core market protections, such as customer protection, segregation of customer assets, settlement finality, and netting.
Participants noted stablecoin usage in cross-border payments, particularly in emerging markets, may present an area of growing systemic interest. Participants suggested U.S. dollar-denominated stablecoins may increase efficiency and financial inclusion. Participants noted, however, several concerns and outlined potential challenges. Participants emphasized the importance of international coordination to balance innovation with macroeconomic and financial stability objectives.
6. Incident Response, Testing, and Information Sharing
Participants stressed that risk is dynamic, requiring ongoing testing, reporting, and scenario planning. Effective operational resilience depends on comprehensive business continuity plans, simulation exercises, and timely cross-border communication.
Participants also discussed the development of standardized information-sharing protocols between regulators and technology providers. Collaborative incident response playbooks and shared threat intelligence were cited as essential tools in responding to future disruptions.
Conclusion of the 2025 Regulators Roundtable
The Regulators Roundtable underscored the need for coordinated, forward-looking regulatory frameworks that keep pace with technological change. Participants reached broad consensus on the importance of embedding AI governance and transparency into supervisory models; addressing cyber risk as a systemic concern; examining operational resilience requirements to address disruptions of critical third-party providers; and harmonizing oversight across borders, especially in digital assets and infrastructure.
The Regulators Roundtable discussions and dialogue at other events have reaffirmed my commitment to international engagement, proactive supervision, and safeguarding market integrity in a rapidly evolving environment.
II. Summary of Surveillance and Supervision in the Age of AI and Digital Assets Public-Private Roundtable and Other Recent Public-Private Conference Commentary
Bénédicte Nolens moderated a public–private roundtable on July 14, 2025 exploring how AI and digital assets are reshaping financial surveillance, compliance, and supervision. The roundtable convened global market participants, technology providers, and regulators to discuss the challenges and opportunities emerging from the growth in AI-enabled crime and evolving market infrastructures. The public-private roundtable was conducted under the Chatham House Rule.
Below, find several key themes and insights from the roundtables and recent conference commentaries.
Key Themes and Takeaways
1. AI and the Evolution of Financial Crime
Advanced AI surveillance tools may be deployed to detect market abuse, including market manipulation (e.g., spoofing, wash trading), supervise trading activity in real time, reduce false positives and investigative workloads, and provide auditable and explainable alerts using Large Language Models (LLMs), including multilingual data analysis. AI may also prove instrumental in identifying broader risks, such as sanctions evasion, fraud, and geopolitical threats.
Attendees at the roundtable highlighted that AI is rapidly accelerating the speed and sophistication of financial crime. The transition from human-led schemes to AI-driven threats has transformed the compliance landscape. Participants outlined a progression from manual, traceable crypto crimes in the early 2010s to today’s AI-powered laundering, synthetic identities, and multi-chain hacks.
Compliance professionals are increasingly turning to AI to keep pace with this threat environment. Platforms leveraging behavioral detection, obfuscation analysis, and on-chain intelligence are being deployed to improve disruption and attribution. However, surveillance systems remain challenged by fragmented data sources and limited interconnectivity between on-chain and off-chain trading venues.
2. Bridging Surveillance Gaps in Crypto Markets
Participants noted structural disconnects in crypto market oversight, pointing out that while the industry often references the transparency of blockchain data as a safety and supervision mechanism, historically a significant percentage of trading occurs off-chain. A significant percentage of crypto trading activity occurs within centralized exchanges, which in some cases manage customer transactions internally without recording each trade on a public blockchain. Additionally, some operational processes, such as order matching, custody, and margining, may be conducted off-chain for speed, cost-efficiency, or business confidentiality, resulting in limited transparency for regulators and market observers.[4]
The discussion also examined forms of manipulation and fraud — such as wash trading (a form of trading in which trading activity or rumors are designed to artificially inflate the price of an asset). Participants discussed the potential for AI-generated content on social media to amplify the effects of wash trading and expressed concerns regarding hard coded smart contract rug pulls (where the developers of a project implant code within the smart contract underlying a digital asset that allows them to lure investors to deposit funds they can never withdraw, as well as back doors that suddenly disappear, taking all investor funds with them).
Participants shared examples from recent enforcement investigations and emphasized the threat of new and more complex forms of market manipulation in traditional securities and derivatives markets as well as crypto markets, particularly in markets servicing retail investors.
A participant cited a recent example of market manipulation in an account takeover in Japan involving over $700 million. Perpetrators hacked thousands of individual accounts, but instead of trying to empty the accounts (which would have likely triggered fraud monitoring systems), the fraudsters used the accounts to trade and inflate prices of illiquid assets, then captured profits by selling preemptively established long positions on the same assets via legitimate accounts.[5]
3. Enhancing Supervision with Explainable AI
Participants emphasized the value of using LLMs for cross-lingual monitoring and pre-trade communications surveillance. Participants noted that the tension between model performance and explainability remains. Governance frameworks and human-in-the-loop systems were emphasized as essential to building trust in AI-generated alerts and compliance outcomes.
4. AI Governance and Data Infrastructure Challenges
Discussions explored various legal and regulatory frameworks to address the evidentiary and technical challenges posed by AI-driven compliance systems. Some proposed co-designed models with regulators, while others suggested the establishment of centralized public sector data hubs to integrate fragmented market surveillance.
5. Risks and Responsibilities in a Fragmented Ecosystem
The discussions underscored concerns over the delegation of supervisory responsibility to private vendors. Participants cautioned against overreliance on proprietary solutions without corresponding public oversight and technical capacity. A number of commentators emphasized enhancing regulators’ expertise and skills in supervising innovation in financial markets, cross-sector coordination, and accountability for AI deployment in sensitive financial market infrastructures.
Looking Ahead
While AI’s capacity for pattern detection and surveillance continues to advance, there appears to be consensus that gaps in model transparency, data integration, and supervisory readiness must be addressed in tandem. Explainability, governance, and modernized regulatory design were identified as cornerstones of safe innovation in the digital era.
III. Takeaways from the Roundtable and Recent Conference Commentary
The Role of Collaboration
Collaboration was a frequent theme mentioned by participants at roundtables and commentators at recent conferences. Cross-border coordination can help ensure consistency in supervisory expectations, while collaboration between public and private sectors can accelerate adoption of robust surveillance tools and practices. Periodic convenings such as the Regulators Roundtable provide valuable opportunities for regulators to share emerging risks, coordinate responses, and align on international standards. Meanwhile, engagement with market participants, particularly those obligated to perform surveillance under registration requirements, can foster innovation and improve supervisory outcomes. Surveillance technology offers a particularly promising area for collaboration, as co-designed frameworks may yield tools that are both effective and acceptable to regulators.
Conclusion
The Regulators Roundtable and recent conference commentary offer a timely and productive forum for exploring the technological, operational, and regulatory shifts shaping global financial markets. Participants reaffirmed the shared responsibility to adapt supervisory frameworks to evolving risks while preserving financial stability and market integrity. As the financial sector continues its digital transformation, a foundation of international cooperation, regulatory clarity, and public-private dialogue will be essential. Continued engagement on emerging technologies, operational resilience, and surveillance innovations will help ensure that markets remain fair, transparent, and resilient in the digital age.
***
For more information on the CFTC’s Market Risk Advisory Committee (MRAC), including committee reports, meeting agendas and recordings, membership and subcommittee details, please visit: https://www.cftc.gov/About/AdvisoryCommittees/MRAC
Commissioner Kristin N. Johnson sponsors the MRAC. MRAC advises the Commission on matters relating to evolving market structures and risks affecting market infrastructure, including s clearinghouses, exchanges, intermediaries, market makers and end-users. Members include representatives of clearinghouses, exchanges, intermediaries, market makers, end-users, academia, and regulators.
[1] The Regulators Roundtable and the development of this summary benefitted significantly from the contributions of Alessandro Cocco, Senior Policy Advisor at the Federal Reserve Bank of Chicago; Bénédicte Nolens, Head of BIS Innovation Hub Hong Kong Centre; and Danielle Abada and Christopher Lamb, Senior Counsel to Commissioner Johnson. The summaries integrate observations from domestic and international market and prudential regulators and market participants at several recent conferences including TradingHub’s RegHub Summit London 2025 and the DigiAssets 2025 Conference, among others. The summaries of views expressed by moderators or attendees do not necessarily reflect the views of or endorsement by the Commission, Commissioner Kristin Johnson, other domestic or federal affiliated regulatory authorities, or firms.
[3] The European Supervisory Authorities (EBA, EIOPA, and ESMA) are advancing a European oversight framework for critical ICT third-party service providers (CTPPs), with the aim of designating these providers and initiating formal supervisory engagement by the end of 2025. See The ESAs provide a roadmap towards the designation of CTPPs under DORA, European Insurance and Occupational Pensions Authority (Feb. 18, 2025), https://www.eiopa.europa.eu/esas-provide-roadmap-towards-designation-ctpps-under-dora-2025-02-18_en.
Commissioner Johnson Hosted the Regulators’ Roundtable: Financial Markets Innovation and Supervision of Emergent Technology in London
July 18, 2025
LONDON — On July 14, 2025, Commodity Futures Trading Commission Commissioner Kristin Johnson convened the third annual international financial markets regulation roundtable in London. The agenda and engagement focused on rapidly evolving technologies — with emphasis on the increasing integration of artificial intelligence, the proliferation of cyber threats, and the rapid adoption of digital assets across global financial markets.[1]
During the Emergent Technologies Roundtable, Commissioner Johnson explained “AI holds significant promise for making financial services more inclusive, efficient, and accessible. But its deployment must be underpinned by robust governance, ethical design, and global regulatory collaboration. For global regulatory leadership … the challenge is to balance innovation with stability, openness with security and privacy protections, and the benefits of automation with the value of human oversight.”
Reflecting on the need for effective governance, Commissioner Johnson explained that “governance — at the firm level and the system level — matters more than ever. Fintechs must invest in model risk management, ethical design, and responsible data practices. Supervisory approaches must evolve to keep pace with the changes occurring in the markets subject to our supervision.”
The Roundtable also explored issues of operational resilience in the face of mounting cyber attacks launched by sophisticated actors operating from dark corners in many jurisdictions around the world with the potential to severely disrupt local and global financial markets. “Cyber resilience is a critical gateway issue for protecting market integrity, and an area where we need to be ‘all hands on deck’ on both sides of the pond. Cyber resilience is only as strong as its weakest link. It is important to stay vigilant and collaborate closely on best practices and lessons learned,” Commissioner Johnson said.
According to Commissioner Johnson, “convening regulators offers an exceptional opportunity for colleagues to share learning and understanding on emerging and persistent issues that directly impact market integrity, stability, and security. It has been my pleasure to coordinate an annual conversation among regulators each year of my service as a Commissioner.”
Roundtable attendees included representatives of the Federal Reserve Bank of Chicago, the Bank of England, the Financial Conduct Authority, Banco de España (the central bank of Spain), the European Securities and Markets Authority, Deutsche Bundesbank (the central bank of the Federal Republic of Germany), the Comisión National del Mercado de Valores (the Spanish Securities Market Commission),the City of London, the Financial Action Task Force, the Cambridge Centre for Alternative Finance, and the London School of Economics Law School, among others.
The attendees discussed a number of issues, including regulatory responses to cyber threats and operational resilience for systemically important financial institutions and market participants; risk management concerns and effective oversight of non-financial institution third party service providers; the impact of increasing reliance on AI; and strategies to enhance integrity, stability, and accountability in global financial markets.
“I extend my gratitude to the roundtable attendees,” Commissioner Johnson continued. “Hopefully, the insightful dialogue inspires harmonization, coordination, and collaboration across financial banking and market regulation.”
Opening Remarks of Commissioner Kristin Johnson: Regulators Roundtable on Financial Markets Innovation and Supervision of Emergent Technology
Commissioner Kristin N. Johnson
July 14, 2025
It is truly my pleasure to welcome you all today to the Regulators Roundtable on Financial Markets Innovation and Supervision of Emergent Technology. My sincere and tremendous gratitude to everyone who has gathered here in London today. This year marks the third year that I have had the privilege of convening an exceptional group of senior prudential and market regulators representing diverse jurisdictions around the world.
Our discussion this afternoon will focus on forces that are rapidly transforming the financial services sector of the global economy with particular emphasis on two elements of the increasingly digitized financial services sector—the integration of artificial intelligence and the threat of cyber risks.
For each of us—whether we’re shaping monetary policy, evaluating compliance with current regulatory guidelines, enforcing transparency and accountability in banking, capital markets, derivatives markets or digital asset markets, or supervising the next generation of digital finance platforms—the topics on today’s agenda are top of mind.
Today we are continuing the conversations launched during the previous roundtables. Each of these topics have only become more important in the year since we last gathered.
AI in Financial Markets and Financial Markets Regulation
AI holds significant promise for making financial services more inclusive, efficient, and accessible. But its deployment must be underpinned by robust governance, ethical design, and global regulatory collaboration. For global regulatory leadership—including this august group convened today—the challenge is to balance innovation with stability, openness with security, and automation with human oversight.
Improving Accuracy, Efficiency, and Operational Resilience
Evidence suggests that AI improves accuracy, efficiency, and operational resilience and that AI-driven systems may outperform traditional approaches. Some potential applications include:
Fraud Detection and Risk Management
Anomaly Detection: AI systems can detect unusual transaction patterns in real-time, flagging potential fraud or cyber threats more effectively than traditional rule-based systems.
Behavioral Biometrics: Advanced models track behavioral traits (typing speed, swipe patterns) to authenticate users and reduce identity theft.
Process Automation
Intelligent Document Processing (IDP): AI extracts, classifies, and processes information from unstructured documents (e.g., loan applications, KYC documents), reducing processing time and human error.
Trade Surveillance & Market Monitoring: AI can sift through vast quantities of data to detect signs of market manipulation, insider trading, or compliance breaches with greater precision.
Enhancing Compliance with Regulation and Reducing the Costs of Compliance
AI promises to reduce transaction and compliance costs by dynamically routing orders to the best venues, reducing slippage and lowering transaction costs. Evidence suggests that AI improves accuracy, efficiency, and operational resilience. AI-driven systems may outperform traditional approaches for detecting fraud, managing risks, executing back-office services, verifying identity, surveilling markets for evidence of market manipulation, insider trading, and compliance breaches.
AI also promises to enhance supervisory technology for regulators—automating data collection, analysis, and reporting, reducing frictions with regulatory compliance, and enabling more dynamic regulation at reduced costs. AI may facilitate efficient, faster-paced updating and modernization of regulation. AI may also offer continuous monitoring and enhanced real-time confirmation of compliance, reducing reliance on less frequent, periodic audits, and facilitating market participants and regulators’ ability to identify regulatory breaches earlier and potentially reducing the number and size of regulatory breaches.
Reducing Transaction and Compliance Costs
Transaction Costs
Smart Routing and Algorithmic Trading: AI optimizes trade execution by dynamically routing orders to the best venues, reducing slippage and transaction costs.
Compliance and Regulatory Reporting
RegTech Solutions: AI-powered regulatory technology automates data collection, analysis, and reporting, easing the burden of compliance with dynamic regulations.
Continuous Monitoring: AI systems can provide real-time compliance checks rather than periodic audits, leading to faster resolution and fewer regulatory breaches.
Industry Use Cases
While the financial services industry has integrated predictive technologies in risk assessment and predictive analytics for decades, over the last several years, we have witnessed a transformational shift in the diversity of use cases. In 2017, JPMorgan Chase launched a contract intelligence platform that automates review of commercial credit agreements, reducing by hundreds of thousands of hours the human resources annually required to complete credit agreement reviews.[2] HSBC, and a number of other financial institutions, have integrated AI in their transaction monitoring and anti-money laundering (AML) platforms to detect anomalies across millions of transactions in real-time, increasing accuracy in their assessment of suspicious activity reports.[3] Similar to other financial services firms, Mastercard has launched cyber risk and fraud detection software that relies on AI to analyze 75 billion transactions per year to block fraud in milliseconds.[4]
Risks and Considerations for Policymakers
In testimony before Congress, published academic literature, and a series of speeches during my tenure as a Commissioner at the CFTC, I have outlined and encouraged regulators to explore a number of risks and considerations.
For example, we face real concerns around bias in AI models, especially when it comes to lending and underwriting. There is a need for greater transparency and explainability, so that AI driven decisions are subject to the rigorous accountability standards that we typically apply in our supervisory oversight. And as AI becomes more embedded in core infrastructure, cyber resilience becomes a systemic concern, not just an operational one.
There is also the matter of concentration risk. As more institutions rely on a handful of foundational AI models or platforms, we must ask: what happens when those systems fail or are compromised? I outline a few additional risks below:
Bias and Fairness
Model Transparency: AI decisions, especially in lending or insurance, must be explainable to ensure non-discriminatory practices.
Data Integrity: Models are only as good as the data they are trained on—bad data can perpetuate historical inequalities.
Cybersecurity and Resilience
Adversarial AI: As AI becomes embedded in core infrastructure, it's also a target for manipulation—highlighting the need for robust, secure design.
Systemic Concentration: Overreliance on a few AI platforms or vendors could increase systemic vulnerabilities.
Governance and Accountability
Model Risk Management: Institutions must manage the full lifecycle of AI models—development, validation, deployment, and monitoring—with strong oversight.
Cross-Border Coordination: Global consistency in AI governance frameworks will be crucial to avoid regulatory arbitrage and ensure responsible innovation.
Next Steps in Governing AI
Governance—at the firm level and the system level—matters more than ever. Fintechs must invest in model risk management, ethical design, and responsible data practices. Supervisory approaches must evolve to keep pace with the changes occurring in the markets subject to our supervision.
Regulatory agencies in the US are increasingly deploying AI to review large volumes of data and detect emerging risks by identifying outliers. Using AI in this capacity, often referred to as “suptech,” may offer regulators more effective tools to combat fraud, market manipulation, illicit finance, money-laundering and other long-standing threats to the integrity of our markets.
Cyber Risks
I have encouraged diverse stakeholders to be mindful of potential cyber risks that may impact individual firms or the broader financial markets ecosystem.[5]
We continue to discuss these risks. As we consider them, let’s think about the potential implications of interdependence and the possibility of contagion—the threat that a domino effect of risks may occur at an accelerated speed.
Operational Resilience
Over the past few years, we have made progress in preparing ourselves to take on these challenges. The Commission issued a proposed rule, unanimously supported, to create an operational resilience framework for futures commission merchants, swap dealers, and major swap participants to “identify, monitor, manage, and assess risks relating to information and technology security, third-party relationships, and emergencies or other significant disruptions to normal business operations” in December 2023.[6]
Cyber resilience is a critical gateway issue for protecting market integrity, and an area where we need to be “all hands on deck” on both sides of the pond. Cyber resilience is only as strong as its weakest link. As most cyber threats may be launched against financial institutions in many nations, it is important to stay vigilant and collaborate closely on best practices and lessons learned.
Third-Party Risk Management
As I discussed in recent remarks, the Market Risk Advisory Committee that I sponsor at the CFTC has been actively focused on cyber resilience and third-party risk management issues.[7]When the Commission released its proposed operational resilience framework, a subcommittee workstream of the MRAC recognized that there may have been some important gaps in operational resilience with respect to other market participants, such as central counterparties regulated by the CFTC, and took up the mantle to continue to examine areas not fully addressed by the Commission. The CCP Risk & Governance Committee organized recommendations that were presented to the commission that “would improve upon the existing framework and require that derivatives clearing organizations establish, implement, and maintain a third-party relationship management program.”[8]
Many aspects of the recommendations were informed by internationally recognized best practices and international standard setting bodies, such as the Bank for International Settlements Principles for Financial Market Infrastructure. Once again, this highlights the importance of international collaboration, in setting the standard for best practices, and for developing policies that are familiar to global market participants.
I look forward to discussing today the latest developments in third party risk management, such as new principles on third-party risk supervision issued by the European Securities and Markets Authority (ESMA) just last month.[9]
International Coordination and Cooperation
As we move across the landscape of emerging technologies and the attendant risks, it is increasingly clear that international cooperation is not optional—it is essential. Innovative technologies and the risks that may arise as a result of digitization are not bound by jurisdictional, territorial, or national boundaries. The threats or risks born in one nation may quickly ripple across continents.
A vulnerability in a third-party service provider can contemporaneously compromise multiple financial institutions. A sophisticated actor can launch a cyber-attack from anywhere in the world, orchestrating the consequences such that they impact any one nation or group of nations simultaneously.
Let me highlight a few ways we are already working together on these issues, and where we must go further.
First, harmonizing regulatory expectations.
We need to align our supervisory approaches across jurisdictions to ensure that cyber risk is being addressed consistently. The Financial Stability Board, CPMI-IOSCO, and other international standard setting bodies have already announced important principles—but implementation must be global, not fragmented.
Standards like NIST, ISO 27001, and the FSB’s cyber incident response guidance should form the backbone of our shared expectations. It is worth exploring mutual recognition of cyber audits and certifications for third-party providers, especially cloud platforms.
Second, information sharing.
Timely, secure, and actionable intelligence must flow across borders—not just between regulators, but also with the private sector. There are institutions that are helping to build these bridges, but we need to enhance real-time alert systems and threat-sharing protocols. Silence, in the cyber domain, is a vulnerability.
Third, we must strengthen crisis response and recovery.
Too often, we focus on prevention. But in today’s threat landscape, we must assume that breaches will occur—and focus on how we respond.
That means building interoperable incident response plans. Conducting joint cyber drills and tabletop exercises simulations and establishing trusted communications channels that can activate instantly in the event of a cross-border incident.
Fourth, we must tackle concentration risk and supply chain vulnerabilities.
Many of our institutions rely on the same cloud providers, fintech APIs, and software stacks. We need a coordinated approach to supervising these critical third parties—through shared resilience testing, pooled audits, and transparent incident reporting.
And finally, we must invest in cyber capacity building, especially in emerging and developing economies. Because in a globally interconnected system, our resilience is only as strong as the weakest link. Let us support these markets with the tools, training, and frameworks they need—not just to defend themselves, but to contribute to the global cyber defense ecosystem.
In Conclusion — Looking Ahead
The cyber threat landscape is evolving quickly—AI-powered attacks, deepfakes, quantum computing threats, and vulnerabilities in decentralized finance are no longer theoretical.
To meet these challenges, we must act together—with speed, with coordination, and with trust. This is no small ask, and we can’t do it alone.
Let us make cybersecurity a shared responsibility. Let us foster the partnerships—public and private, domestic and international—that are essential to securing our financial future.
Because in today’s world, cyber resilience is not just a technology issue—it is a financial stability imperative.
Finally, our convenings and conversations must continue. Trust can be a competitive advantage if we let it—a most potent tool in our toolbox to help us unlock the potential of new technology while also maintaining effective governance structures that give us the confidence and stability to keep moving forward.
I am hopeful as we continue to convene, as regulators, and with the broader communities we serve, that we can develop standards and best practices that can be relied on around the globe.
I look forward to hearing the different thoughts and approaches that will be shared today on these issues that are top of mind for our markets globally.
[1] The thoughts and perspectives that I share with you today are my own; they are not the views and perspectives of my fellow Commissioners, the Commission, or the staff of the CFTC.
[5]See, e.g., Keynote Remarks of Commissioner Johnson for Governing Data at Iowa Innovation and Business Law Center and Yale Law Journal of Law & Technology at Yale Law School: Twin Peaks—Emerging Technologies (AI) and Critical Third Parties (Apr. 4, 2025), https://www.cftc.gov/PressRoom/SpeechesTestimony/opajohnson16; Opening Remarks of Commissioner Kristin N. Johnson at GAIM Ops AI Summit: Using AI To Combat Cybersecurity and Fraud Risks (Apr. 7, 2025), https://www.cftc.gov/PressRoom/SpeechesTestimony/opajohnson17.
[6] CFTC, Operational Resilience Framework for Futures Commission Merchants, Swap Dealers, and Major Swap Participants, 89 Fed. Reg. 4706 (proposed Jan. 24, 2024).
Remarks of Commissioner Kristin N. Johnson at George Washington University
Artificial Intelligence in Financial Markets: Enhancing Compliance, Supervision, and Enforcement
Commissioner Kristin N. Johnson
July 08, 2025
Thank you to the George Washington University Regulatory Studies Center, Roger Nober, Susan Dudley, and the organizers of today’s event for allowing me to join virtually. As many of you are aware, I have spent the last several years engaging regulators and market participants from jurisdictions around the world on issues at the core of today’s discussion.[1]
How might advances in artificial intelligence (AI) increase inclusion and customer experiences and democratize access to financial services, improve the accuracy and efficiency of financial services, and potentially reduce transaction costs as well as the costs of compliance?
These issues, among several other potential benefits and risks associated with the adoption of innovative technologies, are top of mind for me and many other senior regulators, chief executive officers, chief technology officers, chief information security officers, chief compliance officers, and chief risk managers around the world.
According to an International Monetary Fund paper exploring the benefits and risks of AI in finance, AI and machine learning (ML) technologies alongside other
[r]ecent technological advances in computing and data storage power, big data, and the digital economy are facilitating rapid AI/ML deployment in a wide range of sectors, including finance. The COVID-19 crisis has accelerated the adoption of these systems due to the increased use of digital channels.
AI/ML systems are changing the financial sector landscape. Competitive pressures are fueling rapid adoption of AI/ML in the financial sector by facilitating gains in efficiency and cost savings, reshaping client interfaces, enhancing forecasting accuracy, and improving risk management and compliance. AI/ML systems also offer the potential to strengthen prudential oversight and to equip [regulators] with new tools. . . .[2]
Indisputably, AI is rapidly transforming the financial sector, particularly in the areas of compliance, market surveillance, and regulatory enforcement. What once seemed the creative imaginings of science fiction or fantasy novels and films—forward-looking notions of a futuristic world—has now become a practical and increasingly essential tool across the financial market ecosystem. Market participants and regulators alike are leveraging AI and ML to improve risk management, detect misconduct, and strengthen the integrity of the markets.
Let’s explore the use of AI in compliance, bad actors’ potential misuse of AI, opportunities for supervisory technology (suptech) in enforcement, and a path forward.
AI and Industry Compliance
Financial institutions have been at the forefront of AI adoption, especially in compliance functions. AI is widely used in anti-money laundering (AML) efforts, where algorithms analyze transaction patterns across millions of credit card statements, bank statements, and account details to detect anomalies that may go unnoticed by traditional systems. ML models have dramatically reduced false positives in AML alerts[3]; this has long been a challenge for compliance teams who may now rely on AI to learn by reviewing training data and distinguish between benign and suspicious activity more precisely and more efficiently.
AI also supports compliance with complex cross-border financial regulations. Financial services firms deploy ML to monitor transactions for potential sanctions violations, helping ensure that transactions align with regulatory requirements based on origin, amount, frequency, and other risk factors.[4]
Some firms have also embraced AI in communications surveillance, using platforms that offer digital communications governance to review internal communications for signs of fraud or misconduct. By automating these reviews, firms are better equipped to identify red flags early and maintain robust compliance programs.
A recent Government Accountability Office (GAO) report released in May of 2025—Artificial Intelligence: Use and Oversight in Financial Services—identifies six increasingly common activities for which financial services firms may choose to integrate AI models, including automated trading, countering threats and illicit finance, credit decisions, customer service, investment decisions, and risk management.[5]
The GAO report indicated that AI may be used to “detect and mitigate cyber threats through real-time investigation of potential attacks, flagging and blocking of new ransomware, and identification of compromised accounts and files” as well as to “identify fake IDs, recognize different photos of the same person, and screen clients against sanctions and other lists; analyze transaction data … and unstructured data (such as email, text, and audio data) to detect evidence of possible money laundering, terrorist financing, bribery, tax evasion, insider trading, market manipulation, and other fraudulent or illegal activities.”[6]
For many of these use cases, financial services firms rely on generative AI. However, for use cases that require a high degree of reliability or explainability—the ability to understand how and why an AI system produces decisions, predictions, or recommendations—firms are rightly reticent to employ generative AI models.
Regulators Use of AI for SupTech
The benefits of AI are not limited to the private sector. U.S. regulatory agencies—including the Commodity Futures Trading Commission (CFTC), the Board of Governors of the Federal Reserve System (Federal Reserve), the Federal Deposit Insurance Corporation (FDIC), the Securities and Exchange Commission (SEC), and the National Credit Union Administration (NCUA)—have begun integrating AI tools into their supervisory functions.
These agencies use AI to analyze vast quantities of financial data, identify outliers, and detect emerging risks.[7] For example, AI can flag inconsistencies in data submissions from financial institutions, or surface patterns that indicate potential regulatory violations. This use of AI, often referred to as “suptech” (supervisory technology), enhances regulators’ ability to carry out their oversight responsibilities efficiently and proactively.
Over the course of last year, the CFTC undertook extraordinary efforts to begin to clarify the Commission’s understanding of registrants’ use of AI and the potential benefits and limitations of the Commission’s implementation of AI for supervisory, surveillance, and enforcement purposes. In January of 2024, I worked with Commission staff to issue a Request for Comment distributed to our market participants to better understand the real-time adoption of AI models.[8] Following the Request for Comment, in December of 2024, the Commission issued a staff advisory on Use of Artificial Intelligence in CFTC-Regulated Markets.[9] One of the most significant takeaways from the staff advisory, which was echoed in executive orders issued by the prior administration, underscore the obligation for CFTC-regulated entities to maintain compliance with applicable statutory and regulatory requirements whether they choose to deploy AI or any other technology.
Addressing the Dark Side of AI
While AI has the potential to enhance compliance and supervision, it also introduces new risks. Alongside the promise of AI, we must consider the limitations and potential perils of implementing AI quickly without appropriate guardrails. Many of you in the room today, former Commissioner Berkovitz and Professor Cary Coglianese, among others, have participated in joint studies published by the Administrative Conference of the United States (ACUS) or independently published or presented on these limits.
In previous speeches, I have outlined concerns regarding the implementation of AI models without effective guardrails and governance interventions.
In a speech earlier this summer, I began to explore the specific concerns that may emerge as firms and regulators integrate agentic AI.[10] The discussion today, in fact, may largely focus on the integration of agentic AI models in compliance, surveillance, and enforcement. If so, I am hopeful that, in parallel to efforts to explore the benefits, panelists examining “AI’s Role in Regulation Post-Chevron” and “Regulatory Functions Most Amenable to AI-Drive Process Improvement” will also examine important concerns such as the limits of synthetic data, ghosts or hallucinations, data leakage, increasingly undetectable video and voice deepfakes, data accuracy, data security, and data integrity, among others.
Some bad actors are paving the road for regulators and enforcement actions using AI technology. . But, in many cases, the bad actions are simply traditional, garden variety fraud with an AI white-label.
“AI washing”—the practice of exaggerating or misrepresenting AI capabilities to attract investors or customers[11]—is among the most concerning marketing and solicitation issues that financial market regulators currently face. Firms may claim to use advanced AI models to generate high returns when, in reality, they rely on rudimentary trading bots or nonexistent systems.[12]
Enforcement in Action
The CFTC has actively pursued enforcement actions against fraudulent actors who misuse or misrepresent AI. In a landmark case, the Commission obtained a $1.7 billion penalty—its largest ever—against a South African company that defrauded investors through a fraudulent multilevel marketing scheme.[13] The company falsely claimed to use a proprietary AI trading bot to generate high returns on Bitcoin investments. In reality, there was no proprietary trading bot and the firm engaged in minimal trading activity, most of which was unprofitable, and misappropriated investor funds.
This and other cases underscore the CFTC’s ability to tackle AI-related misconduct using existing legal tools. The Commodity Exchange Act (CEA) provides a robust and flexible framework that prohibits fraudulent and manipulative practices regardless of the underlying technology. For example, CEA Section 4c(a) outlaws disruptive practices such as spoofing,[14] while CEA Section 6(c)(1) and Regulation 180.1 give the Commission broad anti-fraud and anti-manipulation authority.[15] These provisions are intentionally technology-neutral, allowing the CFTC to remain agile as new innovations emerge.
The Commission has demonstrated, through its prior enforcement actions, that markets and market participants engaged in activities that are regulated by the Commission are expected to comply with applicable statutory and regulatory requirements, even when such activities occur with cryptocurrencies or through the use of AI. The technology-neutral approach of the CEA and CFTC regulations allows these provisions to be used to combat fraud in any shape, manner, or form.
The Strategic Importance of Suptech
A recent survey by the Financial Stability Institute (FSI) and the Bank for International Settlements Innovation Hub found that only 3 out of 50 supervisory authorities surveyed did not have ongoing suptech initiatives.[16] Those with a comprehensive suptech strategy were significantly more likely to deploy tools critical to supervision.[17]
This underscores the importance of not only embracing AI on a case-by-case basis, but also developing cohesive strategies for integrating AI into regulatory and supervisory workflows. By investing in data infrastructure, fostering inter-agency collaboration, and recruiting AI-savvy talent, regulators can better equip themselves to meet the demands of increasingly complex markets.
Finding a Pathway Forward
I am looking forward to exploring the following principles and their role in our principles-based regulatory framework that I outlined in a speech last year. [18] As I have previously explained, there are many things that the Commission can do immediately to enhance our understanding of AI and help guide the development of effective guardrails that foster responsible development of AI.[19]
Heightened Penalties
As a CFTC Commissioner, I am also deeply concerned about the potential for abuse of AI technologies to facilitate fraud in our markets. As we examine the development of and limitations on the legitimate uses of AI in our markets, it is also important for the CFTC to emphasize that any misuse of these technologies will draw sharp penalties.
In fact, I continue to call for the Commission to consider introducing heightened penalties for those who intentionally use AI technologies to engage in fraud, market manipulation, or the evasion of our regulations.
In many instances, our statutes provide for heightened civil monetary penalties where appropriate.
I propose that the use of AI in our markets to commit fraud and other violations of our regulations may, in certain circumstances, warrant a heightened civil monetary penalty.
Bad actors who would use AI to violate our rules must be put on notice and sufficiently deterred from using AI as a weapon to engage in fraud, market manipulation, or to otherwise disrupt the operations or integrity of our markets. We must make it clear that the lure of using AI to engage in new malicious schemes will not be worth the cost.
Recommendation for an Inter-Agency Task Force
At the end of 2023, the previous administration announced the creation of an AI Safety Institute, which was to be established within the National institute of Standards and Technology (NIST), housed within the Commerce Department.[20]
Shortly thereafter, I proposed the creation of an inter-agency task force composed of financial regulators including the CFTC, SEC, Federal Reserve, Office of the Comptroller of the Currency, Consumer Financial Protection Bureau, FDIC, Federal Housing Finance Agency, and NCUA to develop guidelines, tools, benchmarks, and best practices for the use and regulation of AI in the financial services industry.[21]
Addressing the perils of AI, while harnessing its promise, is a challenge that will require a whole-of-government approach, with regulators working together across diverse agencies. I continue to advocate for agencies working together to provide their essential experience and expertise to help guide the development of AI standards for the financial industry.
Conclusion
The CFTC, in particular, is well positioned to lead in this space. Its principles-based and technology-neutral approach to regulation allows for flexible oversight that supports innovation while safeguarding market integrity. The Commission's mission—to foster open, transparent, competitive, and financially sound markets—naturally aligns with the adoption of cutting-edge technology.
AI is no longer a futuristic concept—it is a central feature of modern financial markets. Used responsibly, AI enhances compliance, improves oversight, and enables faster and more effective enforcement. The CFTC’s technology-neutral framework allows it to keep pace with innovation while maintaining essential investor protections and market integrity.
Thanks again for allowing me to share my thoughts with you today. I anticipate you will have an energetic, generative, and thoughtful discussion on the panels and following the presentations this afternoon.
[1] The views I share today are my own and not the views of the Commission, my fellow Commissioners or the CFTC staff.
[16] Jermy Prenio, Peering through the hype—assessing suptech tools’ transition from experimentation to supervision, Financial Stability Institute at 5 (June 2024), https://www.bis.org/fsi/publ/insights58.pdf.
Statement of Commissioner Kristin N. Johnson Regarding CFTC Settlement with LJM Funds Management Ltd.
Commissioner Kristin N. Johnson
July 01, 2025
Today, the Commodity Futures Trading Commission (Commission or CFTC) and the Securities Exchange Commission (SEC) announced settlement agreements with LJM Funds Management Ltd., LJM Partners Ltd. (together with LJM Funds Management Ltd., LJM), Anthony J. Caine (Caine), and Anish Parvataneni (collectively, Defendants). As described in the Complaint,[1] the Defendants violated multiple provisions of the Commodity Exchange Act (CEA) and the Commission’s Regulations by engaging in deceptive and manipulative practices in connection with transactions involving commodities over an extended period of time.[2]
As stated more comprehensively in the Complaint, Defendants’ violations of the CEA and Regulations were rooted in deceptive and manipulative practices.[3] Defendants made intentional and reckless decisions to make false or misleading statements when describing their risk management practices to prospective and existing commodity pool participants.[4] In doing so, Defendants significantly downplayed worst-case losses by stating they were, in the most aggressive analysis, capped at 40%, when internal emails show that one of LJM’s controlling persons, Caine, knew that losses could reach 100%.[5] Further, Defendants advertised that their risk management included historical analysis when their risk management did not, committing a series of acts which put investors’ hard-earned funds at levels of risk they were not adequately informed of.[6]
Further, Defendants continuously misled investors about the risk profile of its portfolio over the course of two years by maintaining that its risks remained consistent with historical practices.[7] Instead, Defendants’ risk profile had significantly deviated from their traditional norms and nearly doubled the size of potential losses associated with a significant drop in the S&P and an upward spike in volatility – which is exactly what happened. None of these changes were disclosed to investors and, eventually, it was the investors who paid the price, suffering substantial losses due to the Defendants’ conduct as LJM collapsed.
Careful risk management enables market participants to detect and address the kinds of volatility that led to LJM’s collapse. Effective risk management oversight enhances the integrity and stability of global derivatives markets.
Where risk management fails or is completely neglected, we must endeavor through enforcement actions to achieve greater accountability, reduce repeated compliance failures through both general and specific deterrence,[8] and enable the Commission to maximize the use of limited resources.
LJM’s Implosion
In late 2017, Defendants knew that LJM’s portfolio risk was increasing and that their investment strategies left investor assets vulnerable to a market move. Defendants were also aware that the risk profiles for certain of their investment strategies were becoming increasingly risky but made no efforts to reduce the risk levels of their investment strategies or disclose to investors that their risk of loss was skyrocketing. Instead of telling investors the truth and revealing the risks that investors faced, Defendants intentionally misrepresented the rising risk levels that threatened investors’ assets.
LJM’s high-risk investment strategies imploded on February 5-6, 2018, when the Chicago Board Options Exchange (CBOE) Volatility Index (VIX) spiked more than 20 points. LJM lost almost $1 billion in customer assets and LJM shuttered its doors.
Deterring Deceptive and Manipulative Practices
LJM intentionally deceived commodity pool and mutual fund investors. The penalties imposed should reflect our commitment to protecting investors and serve to deter future misconduct by the Defendants and dissuade any future bad actors from electing to deceive investors by misrepresenting risk levels associated with their investment strategies.
Many hard-working investors who suffered significant losses as a result of LJM’s misrepresentations may question whether today’s settlement achieves these goals. I continue to have questions regarding the Commission’s calculation of civil monetary penalties, particularly in enforcement matters that involve intentional, willful deception of vulnerable investors. I have previously raised my concerns regarding the methodology for calculating civil monetary penalties and urged CFTC staff leadership and my fellow Commissioners to provide greater clarity and transparency regarding the Commission’s civil monetary penalty calculation methodology. In addition, I have consistently questioned the impact of lower penalties. Reduced penalties may not achieve deterrence, which is a foundational goal of our enforcement regime.
It has been suggested that we can distinguish the poor risk management decisions at LJM from a sham business that was created solely for the purpose of separating unwitting investors from their money. I disagree. Investors in LJM’s commodity pools and mutual funds selected their investment based on what was represented to them as a lower risk profile. Defendants’ choice to then expose investors’ assets to excessive risk levels violated the compact of trust and confidence that the investors had with LJM. Even if the risk management decisions could be excused, the affirmative acts of deception should not be overlooked.
Promoting Customer Protection Through Disclosure and Supervision
If our mission is to protect investors from the devastating effects of fraud, the businesses that set out to engage in fraud cannot be distinguished from those that start out well-intentioned but later adopt deception as a mantra. A well-heeled firm that has gained the public’s trust and confidence by demonstrating the ability to operate in accordance with the rigorous compliance and reporting obligations of U.S. financial markets regulation that later transforms into a vehicle of garden-variety fraud is, perhaps, more concerning than the fly-by-night fraudster selling snake-oil from the trunk of his car.
Disclosure has served as a foundation in U.S. financial markets regulation for almost a century for a reason. Creating sunlight in contexts where conflicts of interest and asymmetries of information flourish in the shadows is one of most time-tested means of protecting customers, preserving investor capital, and fostering healthy markets.
Moreover, supervision is a cornerstone of customer protection. From its inception in the 1970s, the Commission has emphasized that supervision is a linchpin in our regulatory framework. Under Regulation 166.3, each Commission registrant “must diligently supervise the handling by its partners, officers, employees and agents (or persons occupying a similar status or performing a similar function) of all commodity interest accounts carried, operated, advised or introduced by the registrant and all other activities of its partners, officers, employees and agents (or persons occupying a similar status or performing a similar function) relating to its business as a Commission registrant.”[9]
I commend the Division staff who investigated and resolved this case and worked with the SEC on a parallel case.
[1] Complaint, CFTC v. LJM Funds Management Ltd, et al., No. 1:21-cv-02863 (N. D. Ill. May 25, 2021), ECF No. 1 (Complaint).
[3] Id. The deceptive and manipulative practices and failure to supervise described in the Complaint violated Sections 4o(1)(A)-(B); 4c(b); and 6(c)(1) of the CEA and Regulations 33.10, 180.1(a), and 166.3.
[4] Specifically, Section 4o(1)(A)-(B) of the CEA states that it is unlawful for a commodity pool operator (CPO) or a commodity trading advisor (CTA) to “employ any device, scheme, or artifice to defraud any client or pool participant or prospective pool participant.” 7 U.S.C. § 6o(1)(A)-(B). Section 4c(b) of the CEA and Regulation 33.10 make it unlawful for a person to enter into a transaction that involves any commodity regulated under the CEA known as an “option” contrary to any other rule or regulation of the Commission which would prohibit such transaction and makes it unlawful to directly or indirectly cheat, defraud, or deceive any other person in connection with such transactions. 7 U.S.C. § 6c(b); 17 C.F.R. § 33.10. Further, Section 6(c)(1) of the CEA makes it unlawful to use “any manipulative or deceptive device, in contravention of such rules and regulations as the Commission shall promulgate” in connection with the contract of sale of commodity or future delivery of a commodity in interstate commerce. 7 U.S.C. § 9(1); see also 17 C.F.R. § 180.1(a).
[5] Complaint ¶¶ 46-79. In an internal email, Caine admitted “In extreme cases, theoretically we model to 100% loss.” Complaint ¶ 55.
[8] References to general deterrence describe the effect on the general public of observing consequences of compliance failures or misconduct and the impact of such observations on their future conduct. Specific deterrence refers to the impact of a consequence on the future behavior or conduct of a party that has engaged in conduct that leads to a penalty.
[9] 17 C.F.R. § 166.3. See also Adoption of Customer Protection Rules, 43 Fed. Reg. 31886, 31889 (July 24, 1978)(“the basic purpose of the rule is to protect customers by ensuring that their dealings with the employees of Commission registrants will be reviewed by other officials in the firm.”).
Commissioner Kristin N. Johnson’s Keynote Remarks at the CCP AGM 2025
Addressing Cyber-Risks, Managing Critical Third-Party Relationships, and Reinforcing CCP Resilience
Commissioner Kristin N. Johnson’s
June 19, 2025
It is a pleasure to join CCP Global for your Annual General Meeting. Joining you today marks the third time that I have had the opportunity to address this important group at the center of the global derivatives markets. Addressing this body in Madrid, Spain in June of 2022 marked one of the earliest keynote addresses that I delivered during my time in service as a Commissioner only months after I joined the Commission.[1]
During my speech in Madrid, I reflected on then-recent market stress resulting from geopolitical events and a global pandemic. In February and March of 2020, our markets faced concerning shocks from the rise of a global pandemic[2] and regulatory responses to contain it.[3] Markets witnessed unprecedented volatility coupled with extreme volumes of trading and at times tight liquidity, placing extraordinary pressure on market infrastructures. Responding to these events, central counterparties CCPs carefully assessed initial and variation margin requirements and ultimately increased initial margin requirements (particularly for equity products) as an integral part of their market risk mitigating solutions.
Facing these challenges, CCPs navigated the risks presented, deploying the carefully developed tools at hand with deep and continuous engagement with global regulators. As a result of effective reforms adopted almost a decade before the pressures of recent geopolitical events and a global pandemic at the start of this decade, our financial system demonstrated remarkable resilience. As noted by the Financial Stability Board (FSB) – “Banks and FMIs, particularly CCPs, held up well and were largely able to absorb rather than amplify the shock.”[4]
In many ways, market conditions during these events stress tested CCP resilience reforms implemented pursuant to the 2009 G20 Pittsburg Summit and the Principles for Financial Market Infrastructure (PFMI) codified under local laws such as the Dodd-Frank Wall Street Reform and Consumer Protection Act and European Market Infrastructure Regulation.[5]
Turning back to the present, it is fitting that we gather here today in a building that has served as a gathering place for government and industry for hundreds of years. My understanding is that the building began as a convent in 1411, but later, in the 17th Century became the meeting place for the administrative board for the Admiralty of Amsterdam. And, in the mid-1600s, became known as a City Hall and served as the seat of Amsterdam’s government.
In the spirit of reflecting on the significant contributions of the CCP Global community and the issues that you will discuss and explore during your general meeting, I hope to highlight the work of the advisory committees of the CFTC. Over the last few years, your members have supported and served on a number of the CFTC advisory committees. Having a full complement of five Commissioners for the last three and a half-years means that we put lots of you to work. As the current remaining Commissioners, Acting Chair Pham and I are continuing our commitment to advance important multi-stakeholder dialogues through our role as advisory committee sponsors. I am hopeful that we may even find a path to collaborate with joint sessions hosted by the two advisory committees that we sponsor.
Today, please allow me to focus my remarks on the importance of our Commission’s advisory committees and highlight some of the suggestions put forth by the Market Risk Advisory Committee (MRAC) following deep engagement on these issues, especially those focused on operational resiliency and derivatives clearing organizations (DCOs) system safeguards, and DCO wind down and recovery plans.
I know that many of you are familiar with the MRAC and other CFTC advisory committees from your service and support as members of their Committees and Subcommittees. The MRAC was established on May 6, 2014 in accordance with the Federal Advisory Committee Act (FACA) after the Commission determined that MRAC was necessary and in the public’s interest.[6] MRAC’s purpose is to support the Commission in “promoting [] integrity, resilience, and vibrancy of the U.S. derivatives markets through sound regulation, as well as the monitoring and management of systemic risk.”[7] Since MRAC’s inception, each sponsoring Commissioner has recognized the vital role this advisory committee plays in the development of Commission rules and regulations and utilized MRAC to put forth important reports and recommendations.[8]
The MRAC has a diverse membership with deep experience across all corners of the derivatives space, including representatives of clearinghouses, exchanges, intermediaries, market makers, end-users, academia, public interest advocates, and regulators. Diversity of membership in our advisory committees is critically important to their success and will be vital as we address jurisdiction over emerging markets and novel asset classes as well as the continuous evolution of complex liquidity and market risk issues. Without perspectives from every side of the integral issues that these committees address, we run the risk of limiting our supervision and oversight and missing out on the opportunity to effectively address emerging risks to market stability and integrity.
The benefits of multi-stakeholder gatherings to address emerging market risks cannot be overstated. Sharing a wide variety of perspectives across our markets to engage in deep, thoughtful, and actionable solutions enables regulators and market participants to be prepared to navigate risks with minimal disruptions and maximum resiliency for strong and vibrant derivatives markets in the U.S. and across the world.
This, in essence, is why I believe you all meet here on an annual basis as well – because you recognize the value of deliberative engagement. Allow me to share briefly on two issues that are top of mind for me and that the MRAC has made significant progress addressing– operational resilience of our derivatives markets and orderly wind down and recovery for DCOs.
Navigating the Cyber Landscape for CCPs
Cybersecurity risks are growing in our markets and must be proactively managed and addressed. In its 2024 Systemic Risk Barometer Survey, the Depository Trust and Clearing Corporation (DTCC) noted that cyber risk was a top five systemic risk to the global economy.[9] Similarly, in May 2024, the International Monetary Fund (IMF) stated that in the past 20 years, the financial sector has suffered over 20,000 cyber-attacks resulting in $12 billion in losses, and noted that there is a growing inequality between cyber resilient organizations and those that lack the resilience to withstand and prevent attacks.[10] Recent events demonstrate the chaos that cybersecurity events can cause for our markets, resulting in billions in losses.
As many of you are aware, in January of 2023, ION Cleared Derivatives (ION) experienced a significant cyberattack. ION provides important back-office services for many global futures commission merchants (FCMs) and other market participants. ION’s effective operations and successful provision of these critical services enable many market participants to clear and settle a significant volume of global transactions on a daily basis. The cyberattack on ION triggered a series of disruptions across markets. Those who rely on ION to perform critical functions were taken offline and many had to rely on manual trade processing. The outage similarly delayed the Commission’s ability to deliver timely the Commitments to Traders reports.
Two years later, in a very different corner of markets, on February 21, 2025, Bybit, a popular cryptocurrency exchange, lost nearly $1.5 billion in losses in mostly Ether from a hacking incident.[11] The Bybit hack represented one of the single largest losses by any cryptocurrency exchange since the first Bitcoin was mined.
The hackers identified a vulnerability in Bybit’s transaction approval process hosted through smart contract logic in off chain infrastructure. What appeared to be a routine transfer from Bybit’s Ethereum cold wallet ended up being a rerouting of the transaction to the hacker’s wallets. What kinds of vulnerabilities have enabled hackers to capture hundreds of millions of dollars in cryptocurrency? Commonly deployed tactics include phishing, supply chain compromises, and private key thefts.
In the context of the Bybit hack, reports indicate that the hackers accessed critical Bybit systems through a third party provided critical infrastructure system and used this access point to inject malicious software that detected and modified outgoing transactions in real time.[12] Hackers appear to have gained access to an off chain Safe user interface provided by a third-party service provider.[13]
To provide guardrails for these types of issues, in December 2023, the Commission unanimously approved a proposed rule that would create an operational resilience framework for FCMs, swap dealers (SDs) and major swap participants (MSPs) to “identify, monitor, manage, and assess risks relating to information and technology security, third-party relationships, and emergencies or other significant disruptions to normal business operations”.[14] The proposed rule included three components: (1) an information and technology security program; (2) a third-party relationship program; and (3) a business continuity and disaster recovery plan. Each of these components was designed to deliver frameworks to establish protections to FCMs, SDs, and MSPs and, in an event like the ION Derivatives cyberattack, a plan to continue business as normal while post-mortem checks are completed.
I want to highlight one of the risks that the proposed ORF seeks to address – concentration risks associated with critical third-party service providers. As early back as 2019, the FSB released a report on third-party dependencies in cloud services and considerations on financial stability implications, including implications of market concentration on competition.[15] These risks can be heightened for smaller or medium sized firms, who may lack both the resources to develop technology in house as well as the bargaining power to negotiate with limited service providers in many cases.
Evidence, as well as our experience in working towards the operational resilience framework, indicates that this may be more pronounced in the markets we regulate where there may be even more limited vendors that can provide the sophisticated technologies often used in the derivatives industry. This is not only a potential issue for compliance with regulations and risk management, but also a business risk for market participants.
The Central Counterparty (CCP) Risk & Governance Subcommittee of MRAC recognized the need for a rule like ORF to create a regulatory framework for cybersecurity preparedness and business continuity for cyberattacks and built out a proposal to expand the scope to include DCOs and bolster system safeguards for critical third-party service providers.[16]
MRAC’s Recommendation on DCO System Safeguards for Critical Third-Party Service Providers
The DCO System Safeguards recommendations are an example of MRAC’s proactive response to a potential risk identified. The recommendations also highlight the value of the CFTC advisory committees and the potential for diverse stakeholders who may have divergent perspectives to work together to make real progress towards making our markets more resilient.
A technology and operations workstream of the CCP Risk & Governance Subcommittee began evaluating issues related to cybersecurity and third-party risk management in early 2023. In March of that year, MRAC held a “first-of-its-kind” public meeting to discuss the cybersecurity event at ION Cleared Derivatives that led to a ripple effect across our markets. This was the first chance for experts across our industry to come together following the ION cyberattack to evaluate the event and begin to map out next steps to ensure cyber preparedness among market participants, service providers, and other sources that have the potential to impact our markets.
At the meeting, Futures Industry Association (FIA) President and CEO Walt Lukken announced the creation of a new Cyber Risk Taskforce, the National Futures Association (NFA) President and CEO Tom Sexton discussed NFA’s role in standard setting to mitigate cyberthreats, and we heard from other experts including those from the White House’s Office of the National Cyber Director, the Financial Industry Regulatory Authority (FINRA), and of course, the CFTC, on strategies to enhance the security and resilience of financial markets in the face of new and evolving cyber threats.
Later the same year, the FIA Cyber Risk Taskforce issued an After Action Report outlining the challenges facing our markets.[17] Key findings in the report include a lack of communication amongst market participants in the wake of a cyber incident and the need to connect our market with the broader financial sector to learn from and share the best operational resilience strategies for cyber events. The After Action Report made six recommendations based on their findings: (1) the creation of an “Industry Resilience Committee” to help develop information channels with respect to operational and cyber resilience; (2) connecting our industry with sector-wide specialist groups who focus on operational resilience across our markets; (3) a self-reflective review of our market participant’s policies and procedures for cyber incidents; (4) the establishment of procedures for sharing critical data and information during cyber incidents; (5) identification of ways to assess risk to create more robust operational resilience frameworks; and (6) participation in regularly held cyber preparedness exercises.[18]
The CCP Risk & Governance Committee recognized that there may have been some important gaps in operational resilience and took up the mantle to continue to examine areas not fully addressed by the Commission. The Subcommittee’s recommendations highlight the importance of cyber resilience in DCOs and the need for a more robust regulatory framework. These recommendations, which the MRAC voted to advance to the Commission, would improve upon the existing framework and require that DCOs establish, implement, and maintain a third-party relationship management program.
The CCP Risk & Governance Committee’s report focuses on CFTC Rule 39.18, which establishes system safeguard standards for DCOs and addresses outsourcing but does not expressly discuss third-party relationships. The CCP Risk and Governance recommendations build upon the framework of Rule 39.18 by adding a third-party risk management program to (b)(2). The proposal suggests that a robust third party relationship management program that identifies, assesses, mitigates, and monitors the full risks that are associated with using third party arrangements for critical services should include robust risk management frameworks like policies and procedures that cover the lifecycle of the relationship, personnel assigned to onboarding and diligence of the third party relationships, risk-based monitoring, and more.
The recommendations build upon the philosophy of the DCO Core Principles, lessons learned and best practices from voices across the industry, and international standard setting bodies. As noted in the report,
These principles are intended to reflect lessons learned from industry efforts and best practices in derivatives, the guidance notes in Form DCO, the NFA interpretive guidance, lessons learned from the wider context of third-party relationship management, as well as the principles enunciated in the PFMIs. Incorporating these principles in Commission regulations would enable the Commission to update its regulatory framework with respect to critical third party service providers and to bring its regulations in line with internationally accepted standards, while maintaining a principles based approach to regulation.[19]
Operational resilience, and especially third-party risk management, is a key issue for me, which I continue to track closely and to discuss frequently with my colleagues at the CFTC and at other agencies, as well as with market participants that we regulate, and at events like these. I frequently request that we take these issues seriously and continue to consider actionable steps to address them. As I’ve noted previously, “effectively combatting cyber threats will require a coordinated effort among regulators and industry,” and I am committed to continuing to foster conversations about how we can work together to make our markets safer and more resilient.[20]
I expect that MRAC will continue to consider issues related to cyber resilience and third-party risk management, including as the risks continue to evolve and AI-enhanced cybersecurity creates new or heightened risks.
DCO Recovery and Wind Down: Parallelism with International Standards
Similarly, the CCP Risk and Governance Subcommittee has outlined supplemental reforms that complement Commission staff work that aims to ensure recovery and orderly wind-down of DCOs as part of the post-crisis reforms and important robust preventative resilience framework. Since reforms adopted in the U.S. under the Dodd-Frank Act, international standard-setting bodies have adopted principles, guidance, and standards to support and inform national policymakers on CCP regulation.[21] The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO and together with CPMI, CPMI-IOSCO) and the FSB have published numerous reports on these issues on resilience, recovery, and resolution.[22] In 2012, CPMI-IOSCO published a report setting forth 24 principles that financial market infrastructures, like CCPs, should apply, with the goal of enhancing safety and efficiency.[23] The principles, called the Principles for Financial Market Infrastructures (or PFMI), set forth four foundational pillars for managing financial risk associated with CCPs: governance arrangements of CCPs, comprehensive risk management frameworks, financial resources allocated to loss absorption, and stress testing for both credit and liquidity exposures.
The FSB issued guidelines[24] as well and worked together with CPMI-IOSCO to assess CCP financial resources in connection with recovery and resolution.[25] In the following years, the Commission took up a similar path, issuing a proposed rule that would apply guidelines and requirements for recovery and orderly wind down plans that are already required for systemically important DCOs (SIDCOs) and Subpart C DCOs to all DCOs.[26]
The Proposed DCO Recovery and Wind-Down Rule is robust and important to the Commission and its market participants. Again, MRAC and the CCP Risk & Governance Subcommittee identified four main areas to recommend enhancements: supervisory stress testing of recovery and wind-down plans; conducting recovery scenarios and analysis; inclusion of non-default loss (NDL) in recovery and wind-down plans; and porting of customer positions and collateral during a CCP resolution and clearing member default.[27]
The MRAC’s Recommendations on DCO Recovery and Orderly Wind-Down Plans; Information for Resolution Planning
At its April 2024 meeting, the MRAC approved another set of recommendations from the CCP Risk & Governance Subcommittee on DCO recovery and orderly wind-down plans and advanced them to the Commission. The recovery and resolution workstream worked on these recommendations in parallel with the Commission developing the Proposed DCO Recovery and Wind-Down Rule and aimed to support the staff in its drafting and the Commission in its consideration of such a rule.
The report included background about the importance of DCOs and CCPs in derivatives markets and actions taken both domestically and internationally to strengthen their resilience, some of which I have shared with you here today. The recommendations in the report demonstrate the depth of expertise available to the Commission through advisory committees and the inclusive nature of all participating viewpoints. For example, the recommendation to implement supervisory stress tests came with a caveat – while subcommittee members representing end-users, FCMs, and academia believed that stress tests should be required to take place annually, subcommittee members representing DCOs did not believe that the frequency of reverse stress tests should be annual but should be determined by Commission staff.[28] This is a prime example of why continued participation and robust discussion amongst all viewpoints is a necessity when evaluating the complex issues that face our markets. Although the Commission has yet to complete a final rulemaking on this topic, I hope that the recommendations made by MRAC in this report can provide a roadmap for future engagement.
The Work Continues
I will not have sufficient time today to share all of the details about all of the reports or recommendations that that MRAC has advanced during my time at the Commission, but if you will indulge me, I would like to say a word about some of the other projects that have been completed over the past two years.
The Market Structure Subcommittee developed a report and recommendations on the Treasury cash-futures basis trade and effective risk management practices, which the MRAC voted to advance to the Commission. The report takes a thoughtful and comprehensive look at the basis trade, including its mechanics and parties involved, the disruptions experienced in March 2020 during broader COVID-19-related market turmoil, and its impacts on the broader economy), and identifies both benefits and risks before the recommending effective risk management practices associated with the cash-futures basis trade.[29]
At the most recent MRAC meeting, Josh Frost, then-Assistant Secretary for Financial Markets at the Treasury Department, and members of the Treasury Borrowing Advisory Committee spoke about the importance of Treasury markets and their role in price discovery and liquidity across the financial system, drawing on perspectives from a number of participants in the ecosystem, including both asset managers and hedge funds that participate in the basis trade. This discussion was a good example of the importance of the work of the MRAC on topics that have real implications for our market ecosystem, and the value of bringing together different voices to achieve a deeper, more informed understanding of important issues and how best we can address them.
To take one more example, earlier last year, the MRAC Market Structure Subcommittee issued a report sharing results from a survey of data on FCMs spanning 2003-2023,[30] which showed some interesting trends in capacity and concentration. At a recent trade association meeting, FIA Boca, I described issues that I believe are critical for the Commission to consider as we begin to explore clearing U.S. Treasuries.
The data collected in the MRAC Market Structure Subcommittee report outlines industry concentration in the market for FCM services despite the growth of the industry. For example, the survey showed a disproportionate amount of increase in bank-affiliated FCMs and increased concentration of broker-dealer-FCMs that are dully registered with the Securities and Exchange Commission. All of the top ten industry positions in terms of holdings of customer funds were associated with banks or broker-dealers, and they accounted for more than 80% of all customer funds.
Conclusion
We must continue to support our advisory committees and robust multi-stakeholder engagement. Each significantly benefit the stability and integrity of our markets.
Before closing, I would like to personally thank everyone that has supported the MRAC in any way, through service as an MRAC member, participation on a workstream to advance a set of recommendations to the Commission, by serving as an expert presenter at a meeting, or just tuning into the CFTC YouTube page to watch a meeting – thank you for dedicating your time. If you have not served on an advisory committee, I encourage you to consider service and the potential to contribute to the important engagement that service offers.
The broader CFTC community is part of what makes this agency so special and enables us to punch above our weight. It has been an honor to work with and learn from all of you, and I look forward to seeing what we can accomplish together next.
[1] Commissioner Johnson to Deliver Keynote Address at the 2022 CCP12 Annual General Meeting in Madrid (June 22, 2022), https://www.cftc.gov/PressRoom/Events/opaeventjohnson062222; Commissioner Johnson to Provide a Keynote Speech and Participate in a Fireside Chat at the CCP-12 Annual General Meeting (June 14, 2023), https://www.cftc.gov/PressRoom/Events/opaeventjohnson061523. As in my previous speeches, the views I express today are my own and not the views of the Commission, my fellow Commissioners or the staff of the CFTC.
[5] See CFTC Regulation 39.13, applying a principles-based approach to managing procyclicality, and Article 41 of EMIR and Article 28 of the Regulatory Technical Standards, requiring CCPs to implement specific margin procyclicality mitigants.
[16] Recommendations on DCO System Safeguards Standards for Third Party Service Providers, Central Counterparty Risk and Governance (CCP) Subcommittee, Market Risk Advisory Committee of the U.S. CFTC (Dec. 2024) (available at https://www.cftc.gov/PressRoom/Events/opaeventmrac121024).
[19] Recommendations on DCO System Safeguards Standards for Third Party Service Providers, Central Counterparty (CCP) Risk and Governance Subcommittee, MRAC (Dec. 2024) (available at https://www.cftc.gov/PressRoom/Events/opaeventmrac040924).
[21] Recommendations on Derivatives Clearing Organizations Recovery and Orderly Wind-Down Plans; Information for Resolution Planning, CCP Risk and Governance Subcommittee, MRAC (Aug. 2024) (available at https://www.cftc.gov/PressRoom/Events/opaeventmrac040924).
[23] CPMI-IOSCO, Principles for Financial Market Infrastructures (April 16, 2012), https://www.bis.org/cpmi/publ/d101.htm; see also CPMI-IOSCO, Resilience and Recovery of Central Counterparties (CCPs): Further Guidance on the PFMI – Consultative Report (August 16, 2016), https://www.bis.org/cpmi/publ/d149.htm; CPMI-IOSCO, Implementation Monitoring of PFMI: Level 3 Assessment – Report on the Financial Risk Management and Recovery Practices of 10 Derivatives CCPs (August 16, 2016), https://www.bis.org/cpmi/publ/d148.htm.
[26] CFTC, Derivatives Clearing Organizations Recovery and Orderly Wind-Down Plans; Information for Resolution Planning, 88 Fed. Reg. 48968 (proposed July 28, 2023) (Proposed DCO Recovery and Wind-Down Rule).
[27] Recommendations on Derivatives Clearing Organizations Recovery and Orderly Wind-Down Plans; Information for Resolution Planning, CCP Risk and Governance Subcommittee, MRAC (Aug. 2024) (available at https://www.cftc.gov/PressRoom/Events/opaeventmrac040924).