By Hilary Schmidt, International Banker
Artificial intelligence (AI) has moved from being a peripheral technology to a key strategic priority within the global banking system in recent years. Institutions are committing billions of dollars to various potential AI use cases—from fraud detection and customer-service automation to credit underwriting and trading analytics—to improve their efficiency and competitive positioning. And yet this investment surge has led to rather sluggish deployment of AI-based applications, with banks discovering that integrating AI into highly regulated, risk-sensitive environments is proving a distinct challenge.
AI has the potential to reduce operating costs, improve risk management, enhance the customer experience, create new revenue opportunities and much more. Banks are also aware that failing to invest in AI could leave them at a disadvantage relative to their peers or new entrants. As such, the sector is investing billions in the technology, with the World Economic Forum (WEF) projecting global financial AI spending to reach $97 billion by 2027, from around $35 billion in 2023.
Large institutions have been particularly active. JPMorgan Chase has invested heavily in AI tools to support areas such as document processing, fraud detection and trading analytics and has even developed internal platforms capable of analysing large volumes of legal and financial data, significantly reducing the time required to complete previously labour-intensive tasks. Goldman Sachs has similarly integrated AI into its developer tools and internal workflows, using generative models to assist with coding and operational processes and ultimately improve productivity.
Citigroup, meanwhile, has been exploring the use of AI in its risk and compliance functions but continues to stress that it is in a “human in the loop” phase of adoption, where the technology is used to assist colleagues and clients rather than make fully autonomous decisions. “The focus right now is on support tools that help people do their jobs better, not on replacing human judgement in areas like risk, compliance or client interactions,” the bank explained in November. AI is thus being used to assist decision-making rather than replace it entirely, suggesting that risk management is more important to some banks than the efficiency gains that could potentially be realised.
Despite these successful use cases, however, the transition from pilot projects to full-scale deployment for the broader industry has proven difficult. According to a survey by law firm Dentons, just 29 percent of financial-services sector respondents had a formal AI roadmap or internal strategy in place in mid-2024. Chief among the challenges faced is the need for a minimal level of transparency across key operating nodes—a level that AI has yet to meet convincingly. Given that even a single error—whether that be a flawed credit decision, a missed compliance alert or an incorrect transaction—can have significant consequences for a bank and its customers, lenders are wary of deploying automation at full scale and incurring financial losses, regulatory penalties and/or reputational damage as a result.
The opacity of “black box” AI systems—particularly in determining the provenance of AI-generated data or content—only compounds these concerns. The use of complex machine-learning (ML) models often produces outputs that are difficult to explain or justify, such that the potential benefits of automation are outweighed by the demands for control and accountability from banks and regulators, and even more so should the technology deliver significantly erroneous outputs. Should an autonomous agent make a serious mistake, moreover, determining legal liability—whether it lies with the bank or the technology provider—remains largely unresolved on the regulatory front.
Credit decisions, for example, are typically based on defined criteria that can be explained to regulators and customers. Many AI models, however, deliver results without providing clear explanations of how they are generated, making it difficult for banks to justify taking certain decisions. In the United States, the Consumer Financial Protection Bureau (CFPB) clarified that lenders cannot hide behind complex algorithms—should AI be used to deny credit, the bank must provide specific, accurate reasons for doing so.
Indeed, regulation is playing a central role in shaping how AI is deployed across global banking. Financial regulators require banks to demonstrate that their systems are robust, fair and transparent. This includes ensuring that models do not produce biased outcomes and that decisions can be explained and audited.
“Many countries are moving toward requiring that if a customer is adversely affected by an automated decision, like being denied a loan or flagged for investigation, they have the right to an explanation or a manual review. Even where it’s not law, providing at least a minimal explanation is good practice,” according to “The digital-first bank’s guide to AI in 2026”, a whitepaper from cloud-native core-banking platform Oradian. “Regulators will also expect transparency in terms of model documentation and auditability. This means maintaining detailed documentation of your AI models…and being ready to present that to regulators if asked.”
Data represents another major challenge for banks. AI systems require large volumes of high-quality data to function effectively. While banks possess extensive datasets, they are often fragmented across different systems and business units. Some lenders are investing heavily in data infrastructures to resolve this issue. Wells Fargo, for instance, has implemented a “data fabric” and master data management (MDM) to unify previously fragmented systems, enabling better risk reporting and cross-channel personalisation for its 33 million active mobile users.
Progress is gradual, however. Integrating and standardising this data is a complex and resource-intensive process. Indeed, data challenges often slow AI deployment more than the technology itself.
Banks must also weigh privacy considerations. Financial data is highly sensitive, and its use is subject to strict regulatory requirements, thereby limiting the extent to which banks can use certain types of data for AI training and analysis.
Even when AI systems are successfully deployed, they introduce new forms of operational risk, such as “model drift”, whereby the data on which an AI model was trained may no longer reflect current conditions, thus reducing the model’s accuracy. Should the data used by an AI system fail to represent the broader population accurately, it could produce outputs that significantly under- or overrepresent certain segments. Known as “model bias”, this problem represents a key roadblock for AI deployment in banks.
“For the finance industry, a hypothetical example of a representation problem could occur if spending data were used from an open-banking app with mainly male customers,” the United Kingdom’s Financial Conduct Authority (FCA) explained in a research note that explored bias in supervised machine learning. “If the algorithm generalised the spending of men across the entire population, it may be unlikely to be able to predict female spending patterns with the same accuracy. Data that does not accurately represent the population to whom the algorithm will be applied can lead to negative outcomes for some groups when used to make decisions about them.”
In a banking context, this is particularly problematic. Changes in economic conditions, customer behaviours or market dynamics continuously impact population data and, in turn, the model’s performance. Banks should thus monitor and update their AI systems in real-time, adding further layers of complexity to their management. What’s more, AI systems may identify patterns that are statistically valid but not economically meaningful, which could lead to decisions being taken that are difficult to justify to customers and/or regulators.
The use of AI also introduces new cybersecurity challenges. AI systems can be targeted by adversarial attacks, where inputs are manipulated to produce incorrect outputs. In the context of banking, this could involve attempts to bypass fraud-detection systems, exploit vulnerabilities in automated processes or develop more sophisticated attack techniques. As such, banks must continuously upgrade their systems to keep pace with evolving threats.
It would appear that US regulators are not taking this matter lightly. On April 10, reports emerged that Secretary of the Treasury Scott Bessent and Federal Reserve Chair Jerome Powell had summoned the heads of Wall Street’s biggest banks to an urgent, closed-door meeting to issue a stark warning: The latest AI model from Anthropic, named Claude Mythos, represents a potentially grave new era of cyber threats to the financial system. Powell’s participation in the meeting strongly indicates concerns about the systemic risks posed by this threat.
“We’re taking every step we can to make sure that everybody is safe from these potential risks, including Anthropic agreeing to hold back the public release of the model until our officials have figured everything out,” the National Economic Council’s director, Kevin Hassett, confirmed when asked about the Fed and Treasury Department’s meeting. “There’s definitely a sense of urgency.”
