Shanghai lets banks put self-trained models in front of customers
Shanghai's banking regulator just published the rules it will enforce when a bank's own model talks to a customer — and Moonshot turned the browser into something an agent can remember.
Shanghai's financial regulator has issued 16 measures that, for the first time, sketch a route for banks and insurers to put generative AI in front of customers. The document — 沪金发〔2026〕19号, signed September 18 and published on the National Financial Regulatory Administration's Shanghai bureau site on September 24 — splits into three sections: digital empowerment, infrastructure, and safeguards. The load-bearing measure is a pilot mechanism for generative AI in finance, under which Shanghai will ask to be included in a national regional pilot and let institutions roll out applications that face customers directly, in controlled environments, wired into the internet regulator's existing filing and registration systems. It comes with a toleration clause: a tiered, "inclusive and prudent" framework with differentiated tolerance for failures by risk level.
The guardrails are as specific as the permissions. Any public-facing or high-risk generative AI application must be reported to the bureau before it goes live, with model filing covering self-trained, fine-tuned, on-premises and API-call cases. External AI vendors get pulled under the existing IT outsourcing risk rules with list-based whitelist management. On the build side, the bureau pushes "general model as backstop, industry model for delivery" procurement, a one-stop internal model platform, and mixed cloud arrangements that let institutions lease rather than buy compute. It encourages them to chase government compute, model and corpus subsidies, and to set up joint innovation funds with universities. There is no new money in the document — it is a permission and process document, and the pilot itself is still only something Shanghai will "strive for."
Moonshot AI relaunched its four-month-old Kimi WebBridge as the Kimi Browser Extension — and the interesting part is that it can record what you did and save it as a reusable skill. The extension, announced September 22 for Chrome and Edge, keeps the original setup where a local agent drives your real browser, and adds a sidebar you sign into with a Kimi account to chat with Kimi about the current page. The new capability: demonstrate a repetitive workflow once and it is stored as a skill to call again, alongside a "Web to CLI" path that turns a site's interaction flow into something reusable. Moonshot's own caveat is that page redesigns and heavy dynamic loading can still break a run — take a screenshot to check the state before re-instructing.
Two details worth flagging that the Chinese coverage left out. The sidebar features sit behind a Kimi membership, while the old local-agent path stays free. And the adoption signal is real rather than promised: roughly 100,000 users and a 4.0 rating on the Chrome Web Store, with about 94,000 installs on Edge. It is a rebrand with two additions, not a new product — but it is the clearest bet yet that the durable asset in agentic browsing is the recorded workflow, not the model.
What to watch: whether Shanghai's request to join the national pilot gets an answer, and whether any bank publishes a customer-facing model before year-end.
Would you let an agent record your daily web routine as a reusable skill, or does that make you the training data? Tell us in the comments.
Sources: NFRA Shanghai bureau · Economic Information Daily · Jiemian News · Yicai · Moonshot AI · Kimi Browser Extension · QbitAI · DataCamp