AI has become one of the biggest investment priorities in financial services, but enthusiasm for the technology has not necessarily translated into effective adoption.
Many institutions are still dealing with fragmented data, legacy infrastructure and disconnected tools, while the capabilities of AI continue to advance at a remarkable pace. For some, early experiments have delivered limited returns, making it harder to secure the investment and executive backing needed to go further.
The challenge, then, is no longer simply whether financial services firms want to use AI. It is whether they have the technology, governance and infrastructure needed to make it work at scale.
We recently asked industry leaders what’s holding back AI adoption in financial services and why in the second of a two-part series.
The Global State of RegTech 2026 – a report co-authored by RegTech Analyst and Parker Lawrence Research – delved into this key topic during the report. You can download the full report here.
As part of the report, vendors and institutions were challenged on a number of key areas within the FinTech market, with the central discussion point being what they see as holding back AI adoption in financial services.
The genuine barriers to adoption
Which AI risks are genuine barriers to adoption, and which are the ones that are overstated?
According to Areg Nzsdejan, CEO of Cardamon, the data is clear on what firms actually worry about.
He said, “Model performance and reliability tops every region – nearly 60% of APAC institutions flagged it, close to half in UK, Europe and North America. Governance and control frameworks follow closely. These are barriers. Hallucinations in a KYC workflow or an unreliable model in transaction monitoring carry real regulatory and financial consequences.
The data, he adds, also tells us what firms are not worried about. ROI and internal expertise rank at the bottom everywhere. He said, “The business case for AI in compliance is largely accepted. The skills to use it are more available than they were. The blocker is trust – and trust comes from reliability, explainability and governance.”
In the view of Jean Voigt, head of AI at IMTF, the biggest obstacle is no longer whether AI can deliver value, but whether financial institutions can deploy it with sufficient trust, control and accountability to use it at scale.
He said, “In a regulated environment, decisions need to be explainable, auditable and defensible. Institutions therefore need to know not only that an AI model performs well, but why it produces a particular outcome, how its performance is monitored and who remains accountable for the resulting decisions.”
The findings, Dr Voigt outlines, reflect this clearly. He said that across regions, model performance and reliability, governance, explainability and regulatory compliance rank among the most significant concerns.
“Practical constraints such as data quality, legacy architecture, fragmented systems and access to skills also remain, but scaling AI ultimately requires institutions to bridge the gap between demonstrating what the technology can do and establishing the trust needed to use it confidently in critical financial processes,” said Voigt.
He added that the concerns highlighted in the research are legitimate, said Voigt. “Model reliability, explainability, data protection and governance become particularly important when AI contributes to decisions with regulatory or customer consequences.”
What can be overstated, in his view, is the idea that these risks make AI inherently unsuitable for regulated financial services.
“The real question is not whether AI is inherently too risky for financial services, but which type of AI is appropriate for a particular use case and which controls are needed around it,” said Voigt.
“This is why a hybrid approach is particularly relevant in financial crime compliance. Deterministic rules, machine learning, network analytics and generative AI each have different strengths, limitations and degrees of transparency. They do not need to replace one another. Combining them allows institutions to apply the right technology and governance framework to the right problem, while maintaining appropriate levels of transparency, control and accountability.”
For Janet Bastiman, chief data scientist at Napier AI, she explained that the state of an institution’s data readiness separates the real barriers from the reputational ones fairly neatly in the rankings.
She explained, “Model performance, accuracy and reliability tops the list in every region — 58% in APAC, 55% in MENA, 49% in the UK and Europe, 48% in North America — and that concern is well placed, though often for the wrong reason. In anti-money laundering (AML), the risk is rarely a hallucination. It is a model that produces a plausible answer from a flawed risk assessment.
“We regularly see type 3 errors, where a model treats a correlated data point as a causal one, pass testing because the outcome looks correct. Those models fail under supervisory scrutiny even when their accuracy metrics are good, which is why validation has to test the underlying risk logic and not just the output.”
Another genuine barrier for Bastiman is transparency and explainability, at 42–48% across the four regions – and in practice is the one that decides whether anything reaches production.
She said, “The concerns I would analyse more closely are the ones ranked lowest by the respondents. Demonstrating clear return on investment (15–24%) and lack of internal expertise (13–20%) are ranked low, but they are where a large share of programmes actually stall, because firms underestimate the tuning, monitoring and validation effort that follows go-live.
“AI in AML is a capability that needs maintaining, not a deployment that completes. If financial institutions due their due diligence in solution and partner selection, perhaps that explains their lack of concern but in my experience it is actually an underestimation of the complexity of the projects that drives this opinion.”
A further area suggested by the Napier AI chief data scientist surrounded ethical considerations and reputational risk, at 8–17%.
“I would argue is overstated as a blocker in this domain specifically: bias management is essential, but it is a design requirement rather than a reason to delay a project launch. Again, selecting a partner with a compliance-first approach means that ethical considerations are built into solutions and regularly validated,” she said.
Esteban Lopez, Senior Manager of Product & Technical Marketing at Theta Lake, put an interesting idea forward: ask why AI adoption is stalling in financial services and most people will point to the models: hallucinations, bias, explainability gaps. These are real, but they’re not the primary barrier. The real constraint, he believes, is governance.
He said, “Financial institutions have spent decades building risk frameworks for the things they understand. With AI, generative AI especially, new capabilities introduce new behaviour patterns with new risk, compliance, and governance challenges.
“In fact, 88% of organizations already report governance and security challenges adopting AI, including new risks like 53% of AI agents exceeding intended permissions and 47% of organizations experiencing an AI Agent-related security incident. That gap is what’s keeping pilots from reaching production. Incorrect outputs, model drift, and operational errors are familiar problems, just in unfamiliar packaging.”
Meanwhile, Joshua Broaded, head of AI at ACA Group, said that financial services firms are seeing significant adoption. He stated that ACA’s survey data shows that the vast majority of firms are providing meaningful portions of their staff with AI tools, and that employees are using those tools to do real work across a whole range of domains.
However, he believes what is key to distinguish is adoption vs impact. “Employees are getting real benefits from AI, but those benefits are often ad hoc, helping with individual problems in ways that are not consistent across employees or overtime. We are at a phase where AI usage is best described as useful tinkering. The limiter is that with a tinkering mentality, real insights and benefits tend not to be scaled across a problem set, shared with employees who are less AI-forward, or governed in ways that are defensible to a regulator. “
Broaded belives the next phase for AI will be maturing workflows so they are scalable, repeatable and well-governed.
Genuine risks, in Broaded’s view, include shadow AI. “Surveys show that meaningful numbers of employees are using unapproved AI systems. One example is a KPMG survey from 2025 showing that 44% of employees have used AI in ways that contravene policies and guidelines. Other surveys will give different headline numbers, but the trend is clear – shadow AI usage is a real and serious problem, particularly when employees are dealing with non-public personal information and material non-public information.”
Another risk is weak control environments. As Broaded states, “Many IT controls are designed with human users in mind, with a goal of giving access and authority in ways that balance the need for employees to do real work against the desire for protections against bad actors who might steal proprietary data or otherwise act inappropriately at human speeds and scales.
“Agents can operate much faster and in ways that are unintended and different from human behaviors.”
He game the example of when OpenAI agents under evaluation escaped their sandbox, reached the open web, hacked into the production environment of an AI hosting platform called Hugging Face, and then logged 17,000 actions as they tried to locate and access protected information.
“Open AI’s agents tried to solve the problem they were given in ways that most humans would not, and they acted with a speed that even a malicious human attacker could not match. IT systems have control environments that were designed for people; many of those control environments are not ready for AI agents,” he said.
Other areas suggested by Broaded were governance and workflow and friction and vendor diligence.
On the former, he said, “Financial services firms are rightly thinking carefully about governance, especially when they are exposing AI to sensitive or proprietary data, and/or when AI systems are incorporating agentic capabilities.
Beyond governance, using AI in ways that is scalable, reliable and impactful requires integration into both software and human workflow ecosystems. Building responsible workflows and appropriate data access channels takes time. Training employees on new processes takes time.
“Governance and workflow frictions mean that advances in frontier lab capabilities take time to proliferate into real workflows. Employees can use frontier capabilities to solve questions on an ad-hoc basis, but enterprise-wide development and adoption take enough time that those broad deployments are often leveraging capabilities that are many months behind the AI development frontier.”
Whilst he said that this issue isn’t necessarily a barrier to adoption, it introduces an inherent lag in how enterprise-wide tools are leveraging AI as compared to the newest capabilities of the frontier labs.
On vendor diligence, he stated that FIs are accountable for regulated activities even when those activities – or inputs to those activities – are performed by a vendor.
Broaded remarked, “We are in a period of rapidly evolving capabilities, and vendors are racing to leverage AI to solve client challenges in new ways. Firms are finding that they need to perform AI-specific vendor diligence alongside traditional SaaS diligence, looking at things like, whether firm or client data is used for training, data retention, model and system-prompt change notification, testing and performance evaluation practices, incident notification and audit rights.”
The last point is AI notetakers. “Financial institutions are rightfully being cautious about AI notetakers, including both enterprise-level meeting recordings, as well as personal devices that can record and transcribe meetings, said Broaded.
The utility of AI notetakers is real, but they raise risks around state-specific consent requirements, supervision and oversight, recordkeeping, discoverability during litigation, and reviewability during a regulatory examination.
Despite this, Broaded suggests that there are two AI risks which are overstated. “First is regulatory uncertainty. During this period of rapid technological innovation we are likely to have regulatory guidance that lags the frontier. This is not a reason to not adopt AI. Instead, firms should focus on applying sound regulatory principles to this new technology.”
The second for Broaded is hallucination. “The accuracy and completeness of AI should not be taken for granted, but it has gotten much stronger over time. Depending on the use case, human validation and/or traditional software reconciliation can detect errors in AI-generated output. Hallucination is a real risk, but it is one to design controls around, rather than a reason to not use AI at all.”
Prioritising risk
How should firms prioritise governance, compliance and model risk? On this, Broaded details that companies should start by governing AI use cases, not just AI tools.
He said, “The same AI system can be used to summarize a publicly available document, prepare a draft client communication, analyse confidential client information, or take actions inside the firm’s systems. Those uses present very different risks, even though the underlying AI tool may be the same.”
For Broaded, the prioritisation framework should consider at least four factors. These include data sensitivity, decision significance, autonomy and detectability and reversibility.
“The highest-priority use cases are generally those that combine sensitive data, significant decisions, meaningful autonomy, and errors that are difficult to detect or reverse. Firms should devote their strongest controls, testing, and governance attention to those areas,” he said.
Broaded detailed that governance also needs to be cross-functional. Compliance can, he said, evaluate regulatory obligations and supervisory requirements, but it generally cannot determine how a system has been configured, what data it can access, or how it will be monitored. Information Security, Technology, Legal, Data, Risk, and the relevant business unit each have roles to play in good governance.
In the opinion of Nzsdejan, governance needs to be built in. The firms that struggle most, he remarked, are those that deployed AI for speed and are now trying to retrofit accountability – reconstructing why a model made a decision months after the fact. That is expensive, slow, and rarely convincing to a regulator.
He said, “The UK and Europe data has one interesting outlier: unintended data leakage scores at 46%, well above APAC (25%) and North America (29%). That is almost certainly GDPR and the EU AI Act focusing minds on data flows in a way other jurisdictions haven’t yet. At Cardamon, we see this directly – data governance is one of the first questions enterprise clients raise, and it shapes how we design every deployment.”
Meanwhile, Voigt remarked that the prominence of governance and control frameworks in the findings, particularly in APAC, shows that governance cannot be treated as something that comes after AI deployment. It needs to be designed into the AI lifecycle from the outset.
He explained, “Institutions need to understand what a model is designed to do, which data it uses, how its performance is measured, where its limitations lie and when human intervention is required. Importantly, governance should be proportionate to the use case. An AI tool that summarizes information for an investigator does not create the same risk as a system making an autonomous decision about a customer.”
He added that explainability, monitoring, auditability and human oversight therefore need to be considered alongside model performance from the beginning. “Done well, governance should enable responsible AI adoption rather than become another barrier to it,” he said.
Bastiman’s recommended prioritisation approach includes defining and operationalising a risk-based configuration, ensuring explainability and managing model risk governance.
She said, “Configuration determines how many alerts exist to govern in the first place. The regional split in the responses supports treating governance as maturity-dependent rather than universal — 62% of APAC respondents cite the adequacy of AI governance and control frameworks against 30% in MENA, which reflects differing supervisory expectations more than differing underlying risk.”
What needs to change
What needs to change before AI can scale safely across financial services? In the view of Cardamon CEO Nzsdejan, explainability has to become standard.
He remarked, “The reason APAC’s governance concern is so high (62%) is that firms there are moving fast but their internal frameworks haven’t kept pace. That tension – deploy quickly, govern properly – is playing out everywhere, just at different speeds.”
The change that unlocks scale is more nuanced that any single regulatory development or a new model architecture, he said.
“It is firms internalising that AI accountability looks exactly like human accountability: clear ownership, documented rationale, and the ability to reconstruct a decision when challenged. The companies that build for that from day one will scale. Those that treat it as a later problem will keep hitting the same wall,” remarked Nzsdejan.
Bastiman believes that what has to change before AI scales safely is architectural.
She said, “Generic AI layered onto fragmented data and batch processing amplifies noise and duplicates cost; it does not reduce risk exposure. That is also the most likely explanation for lack of data readiness being under-reported at 21–29%: teams do not classify it as an AI risk until the model is already underperforming.”
She concluded by stating that AI needs to be embedded in the detection engine itself, running on connected real-time data, with meaningful human oversight and a natural-language audit trail for every output. ‘Where those foundations exist, AI scales without adding regulatory exposure. Where they do not, it makes existing exposure harder to explain,” she said.
Lopez, on the other hand, said that what is genuinely new is the accountability question: when an AI system influences a lending decision or a compliance flag, who is responsible, and how is it documented?
He said, “The firms winning will be those building model inventories, explainability frameworks, and AI governance committees now, not because it’s mandated, but because governance built ahead of any mandate is what unlocks AI at scale.”
Voigt remarked from his view, on the first point, institutions need stronger data foundations. AI cannot compensate indefinitely for fragmented, inaccessible or poor-quality data. Reliable AI depends on reliable data.
Second, he said, AI needs to become part of governed business processes rather than remain confined to isolated pilots. “That means integrating models into workflows with appropriate controls, continuous monitoring, explainability and clearly defined accountability,” remarked Dr Voigt.
He added, “Third, financial institutions need to move beyond the assumption that scaling AI means increasing autonomy. In regulated environments, greater automation does not necessarily mean removing humans from the process. A hybrid approach can allow AI to process large volumes of information, identify patterns and support decisions while keeping human expertise and accountability where they matter most.”
Voigt concluded, “The biggest challenge for AI in financial services is no longer proving what the technology can do, but establishing the trust required to use it at scale. That trust comes from understanding how AI reaches its conclusions, applying the right governance to the right use case and keeping human judgment where accountability matters.
“In regulated environments, the most valuable AI is not necessarily the most autonomous, but the AI you can understand, control and trust.”
Finally, Broaded over his view. “The first thing that needs to change is the way firms think about AI adoption.” Giving employees access to one or more enterprise AI tools is an important step, but it does not, by itself, create an enterprise AI capability.
“To make a real difference, AI needs to be integrated with proprietary data, structured software, repeatable workflows and humans in the loop at the right points. Many firms currently have some, but not all, of these elements.”
Moving up the maturity curve, Broaded said, therefore requires firms to move beyond policies and build repeatable operating processes around AI. “Firms need repeatable processes for evaluating, approving, testing, deploying, monitoring and periodically reassessing their AI use cases. A single written acceptable-use policy by itself isn’t enough.”
The same discipline needs to apply to data. “AI systems should only have access to the data and functionality required for their specific purpose,” particularly where those systems can retrieve sensitive information or take actions on a firm’s behalf.
That also means being deliberate about where human oversight sits within the process. “Firms need to specifically define who is responsible for reviewing AI output, what that person is expected to validate, and when an issue must be escalated.” Human involvement needs to be an intentional part of the workflow, rather than a vague safety net applied after the fact.
Broaded added that firms also need to rethink how workflows themselves are designed. “AI is good at unstructured information and flexible reasoning, while traditional software is often better for calculations, reconciliations, hard-coded rules, permissions, routing and recordkeeping.” The opportunity is not to replace one with the other, but to engineer workflows that bring both to bear where they are most effective.
Auditability needs to be built into those systems from the outset. “Firms need to be able to understand what data an AI system used, what it produced, which sources supported the output, what validation occurred, who approved the result and what action was ultimately taken.” Without that chain of evidence, it becomes much harder to establish whether an AI system is operating as intended or to investigate when something goes wrong.
The same principle applies to third-party providers, said Broaded. “Traditional vendor diligence often focuses heavily on the vendor at the time of procurement and then revisits the relationship infrequently. AI systems can change materially between those reviews, so more frequent AI-focused check-ins are important.”
Finally, firms need better ways to measure whether all of this is actually working. That means tracking adoption by use case, reviewer override rates, first-pass acceptance rates, defects and rework, processing times, policy deviations, data-exposure events and vendor incidents. “Those measures can help firms determine whether an AI system is doing what is intended, whether controls are working and whether its performance is changing over time.”
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





