Hong Kong’s securities regulator forbids a credit rating agency from taking on any consulting or advisory business that could conflict with its ratings. The same city is now building an AI institute designed upon the opposite principle.
On 26 February 2025, Financial Secretary Paul Chan earmarked a billion dollars in his budget speech for a Hong Kong Artificial Intelligence Research and Development Institute (AIRDI). Over a year later, on 12 March 2026 the government appointed a 14-member Board of Directors. Announcing the appointments, the Innovation, Technology and Industry Bureau said the institute would drive AI research, move research outcomes into commercial use, it would bridge government, universities and companies, and it would advise the government on promoting AI. The AIRDI is expected to begin full operations sometime soon, in the second half of this year.
The funding paper — the government’s case to the Legislative Council for approving AIRDI’s money, submitted in September 2025 — lists the business lines through which the institute is expected to earn its income: research collaboration, commercialisation and technology transfer; AI technology solution matching services; technical advice, training and international partnerships. It also says AIRDI “may develop rating and certification-related business” to provide AI system security and ethical assessment services, and compliance risk assessment and certification for individual systems or enterprises, including developers.
The same paper sets out how all of this gets paid for. Government funding falls from HK$298 million in year one to HK$92 million in year five, against initial operating expenditure of roughly HK$300 million per year. AIRDI is expected to make up the difference through “non-government sources” moving gradually towards self-financing.
Taken together, that means an institute expected to cover roughly 2/3rds of its costs from non-government sources within five years. The funding paper identifies those sources as commercialisation of research, market capital, and fee-based services. One of those fee-based services includes issuing safety and compliance certificates to the AI developers whose systems AIRDI would be assessing.
The abovementioned prohibition on consulting and advisory services that Hong Kong applies to rating agencies was not arrived at cheaply. Under the “issuer-pays model,” credit rating agencies are paid by the companies whose bonds they rate. When the global financial crisis hit in 2008, that arrangement’s cost became clear: the agencies had given AAA ratings to mortgage securities in freefall. Regulators concluded afterwards that this conflict could not simply be disclosed away. European law now also prohibits a rating agency from selling consultancy or advisory services to an entity it rates, on the reasoning that a firm which advises a client cannot credibly grade it.
A body that depends on fee income from the market it assesses must walk the tightrope between scrutiny and commercial interest. Even without outright misconduct, that is enough to make independence harder to trust.
The proposed organisational chart of the AIRDI, provided below, reinforces the problem. A Board sits at the top of the hierarchy with various committees beneath it. A CEO reports to the Board, a COO reports to the CEO, and six divisions sit under the COO. One of them is the AI Technical Consulting and Advisory Division.
Source: FCR(2025-26)46, “Hong Kong Artificial Intelligence Research and Development Institute,” Enclosure, p. 16.
The funding paper bundles solution matching services, AI security assessment, rating and certification, compliance risk assessment and AI consulting into a single business line. It never says which unit will run it. The only division whose name matches these tasks is the AI Technical Consulting and Advisory Division. If that reading is right, the unit selling consulting to AI developers is also the unit certifying their systems. If it is wrong, the government should say so, because nothing published so far rules it out.
When an institution has both commercial and safety mandates, commercial pressure tends to win. Research that can be commercialised, companies that can be served, and applications that can be deployed all produce visible outputs for an annual report. An assessment that finds a serious problem does not. Instead, it costs a client, creates friction, and slows everything down.
Other countries further along on the AI safety road drew the obvious inference: put safety work somewhere with no competing obligations to crowd it out.
The UK’s AI Security Institute, set up in 2023, employs researchers to evaluate advanced models and publishes what they find; the promotion of Britain’s AI industry sits with other parts of government. PM Rishi Sunak’s justification for creating the institute was that AI firms can’t be left to “mark their own homework.”
Singapore designated its AI Safety Institute in 2024 and housed it at Nanyang Technological University. Its remit is model evaluation, alignment research and international coordination. In both cases the safety body has its own leadership, a publicly funded budget, and no obligation to earn its keep from the developers whose systems it examines.
Hong Kong has good reason to care about this institutional design. As Hong Kong has emerged as a launchpad for Chinese AI champions seeking international IPOs, the credibility of safety assessment will matter more, not less. A Public First survey of more than 18,000 people across 15 countries, published in June, asked which countries’ AI models people trusted. Respondents in 11 of the 15 countries said China had overtaken the United States on capability. On trust, the answer reversed: more people distrusted Chinese models than trusted them, putting China 10th of the 15 countries tested, while American models came 2nd. Chinese AI labs do not have a capability problem in Western markets... They have a trust problem.
This demand is not only external, either. Hong Kong’s government is already deploying AI across departments, while sectoral regulators such as the HKMA, the SFC and the Privacy Commissioner are each grappling with AI in banking, markets and personal data. Yet Hong Kong has no public body that evaluates models directly — one that asks not how an AI system is used, but whether it could help synthesise a pathogen, or run a cyber operation without human direction. The inter-departmental working group reviewing the legal framework for AI will therefore need technical evidence that does not come from the industry whose legal framework it is drafting.
The good news is that the institutional direction has not yet been locked in. AIRDI’s certification business is still only proposed, its standards framework is unwritten, and the institute has not yet announced its senior hires (as of July 2026). That matters because institutional mandates are far easier to change before an organisation has built a client base and become dependent on the revenue that comes with it.
Assurance work must be funded and judged separately from the commercial work around it. There are two ways to do that.
The less disruptive approach would keep assessment inside AIRDI but wall it off internally. That would mean solutions like funding it from public money rather than from fees paid by the enterprises being assessed, preventing certification from being sold alongside consulting to the same clients, giving it its own reporting line to the Board, and imposing cooling-off periods for staff who move to AI companies they have assessed.
The more durable approach would be a separate institute, along the lines the UK and Singapore have already tested. This need not be expensive. Singapore’s institute inside a university research centre is funded by a S$50 million public grant running from 2022 to 2027, about S$10 million a year, or a fifth of what AIRDI expects to spend annually. Hong Kong could similarly house one in a university, with its own director, its own budget, and a remit narrow enough to be checkable: examine advanced models for dangerous capabilities and publish what it finds.
In a written reply to the Legislative Council on 18 March 2026, the government listed among AIRDI’s objectives “providing AI safety assessment and related consulting services.” Safety assessment and consulting, sold by one institute, to the same customers, against the same revenue target.
A safety certificate matters only if the issuer might refuse it. Under the arrangement now on the table, AIRDI would lose money by refusing a company seeking certification. That gives it a financial interest in approval, not scrutiny. A certificate issued on those terms is not a safety assessment; it is a rubber stamp. That is a strange thing to spend a billion dollars on.
AIRDI is likely to be an important part of Hong Kong’s first five-year plan for economic and social development, which is currently out for public consultation. AISHK is drafting a response that will address this proposal, alongside other measures needed to give AI safety a meaningful place in the plan’s agenda. The submission deadline is 14 August, 2026.
If you have feedback, a perspective we should consider, or a contribution you would like to make to the response, please get in touch.
This post was developed during the Successif AI Policy Strategy Fellowship. Opinions are the author’s own.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.