What’s holding back AI adoption in financial services?

AI

AI has moved from experiment to expectation across financial services. Banks, insurers and investment firms are investing heavily in the technology, yet widespread adoption remains harder than the hype suggests. The challenge is no longer whether AI can deliver value, but whether firms can deploy it safely, at scale and with enough confidence to change how work actually gets done.

From fragmented data and legacy infrastructure to regulatory uncertainty, skills gaps and concerns over accountability, the barriers are as much organisational as they are technical. As financial institutions move beyond pilots and begin embedding AI into core processes, the question is becoming more pointed: what is really standing in the way of adoption, and what will it take to move from experimentation to meaningful transformation?

We recently asked industry leaders what’s holding back AI adoption in financial services and why in the first of a two-part series.

The Global State of RegTech 2026 – a report co-authored by RegTech Analyst and Parker Lawrence Research – delved into this key topic during the report. You can download the full report here.

As part of the report, vendors and institutions were challenged on a number of key areas within the FinTech market, with the central discussion point being what they see as holding back AI adoption in financial services.

How to differentiate between AI risks

Which AI risks are genuine barriers to adoption, and which are overstated? In the opinion of John Byrne, founder of Corlytics, he starts by stating that some concerns around AI may indeed be exgerated.

He said, “The technology itself is not inherently the risk. Instead, organisations should focus on how AI is governed and controlled.

“One of the most significant risks for financial institutions is model risk. Just as banks validate credit, market and operational risk models, AI models should be subject to similar oversight and scrutiny. Regulators such as the Prudential Regulation Authority (PRA) and the US Federal Reserve have already established model risk management principles that are likely to be increasingly applied to high-risk AI systems.”

Byrne detailed that cybersecurity, data privacy and the protection of proprietary information remain key concerns, specifically whenAI models are trained on sensitive data or integrated into critical decision-making processes.

He continued explaining that data quality is another significant obstacle. “AI models do not necessarily perform best with the largest datasets; they perform best with the highest-quality datasets. Poorly governed, inconsistent or synthetic data can undermine performance and erode trust in outcomes.”

Another challenge he stressed is the shortage of skilled professionals capable of validating AI models. As firms move beyond proofs of concept and seek to scale AI initiatives, Byrne explained, the need for subject matter expertise, governance frameworks and ongoing model oversight becomes increasingly important.

Karavel co-founder and CEO Pedro Sousa, meanwhile, views this issue from previous conversations the company has had with firms.

He said, “We speak to regulated firms on a weekly basis on AI adoption and so we have a good finger on the pulse of what they’re thinking. There is certainly a sense of unease around the ‘explicability’ of AI.

“Many compliance executives still feel like AI is a sort of ‘magic black box’. They understand the input and the output, but there’s some discomfort around not understanding what happens in the middle part. How did it arrive at that conclusion? What did it look at to get there?”

In the words of Sousa, it’s a hard sell to ask compliance professionals to hand over the metaphorical keys to parts of their jobs if they’re unable to gain enough confidence in the processes that will be used to do that job.

“Lack of transparency and accountability are definitely major factors in a reluctance to adopt AI into their companies,” explained Sousa.

In terms of barriers which are overstated, Sousa remarks that he sees the risk of control frameworks or governance as somewhat exaggerated.

He said, “Most people understand that there are inherent risks associated with the use of AI, and those are already accepted and factored in from the start. Anyone who is looking at AI solutions, has already moved past those concerns and has accepted a measure of risk that they’re comfortable with, so I think this barrier is somewhat overstated.”

For Aurimas Bakas, founder and CEO of Copla, his view on this topic is that a key understated one is data readiness.

He remarked, “UK and European firms put it at 21%, the lowest of the four regions. The July research in this series had institutions ranking internal data quality among their highest barriers to RegTech adoption generally, at 47%. Those two figures describe the same firms and the same data estates.

“Our read is that firms apply a lower bar to data when the subject is AI, and the quality of the underlying inventory determines what the model can honestly tell them.”

Bakas then remarks ‘the genuine one’, and the most regionally distinctive, is unintended data leakage at 46% in the UK and Europe, against 29% in North America and 25% in APAC.

“That concern is a third-party question underneath,” said Bakas. “Leakage in an AI context usually means firm data moving to or through a model provider, which makes it a matter of contractual terms, subprocessor chains and where data physically sits. EU firms have a framework for that already through DORA and GDPR, and UK firms have the operational resilience and third-party expectations the FCA and PRA have built out. The concern is well founded, and the tooling that addresses it is vendor governance tooling.”

He adds that model performance at 49% is real and manageable, through human confirmation on anything that becomes a reportable determination.

Daniel Farias, VP of Sales and Marketing at TransWorldCompliance, stated that the  survey data on financial institutions’ AI concerns tells us that model performance and reliability rank as the top concern almost everywhere — 58% in APAC, 55% in MENA, around half in the UK, Europe, and North America.

He said, “That’s not institutions being cautious for the sake of it. When your output is a CRS or FATCA report going to a tax authority, you can’t operate under a “the model was probably right” standard. Precision is required, and a hallucinated field or a misclassified account results in a regulatory breach with a specific penalty attached to it. That risk is real.”

The concept that AI is risky because its new is true, Faras quipped, but it’s not the only reason. AI is risky, he stated, because it doesn’t yet meet the bar this industry has always required.

“Adequacy of governance frameworks is actually the highest-ranked concern in APAC at 62%, and it’s second nearly everywhere else. Most AI deployed today doesn’t come with the audit trail, the explainability, or the governance maturity that compliance has spent two decades building for every other kind of automation,” said Faras.

How firms should prioritise risk

Looking ahead, how should financial firms prioritise governance, compliance and model risk?

Bakas’s response is at first succinct: start with the inventory.

He said, “Adequacy of AI governance frameworks sits at 43% for UK and European firms, and in our experience the frameworks that hold up are the ones that route AI through the third-party process a firm already runs. An AI model supporting an important business service is a third-party arrangement, so the governance questions are ones firms answer already for critical providers: who owns the relationship, what the contract says about change and exit, where the data goes, how concentrated the firm is in that provider.”

Bakas adds that model risk then becomes the specialist layer above it, covering performance monitoring, validation, and revalidation when a provider updates the model.

He went on, “On compliance, UK and Europe register the lowest regional concern about regulatory compliance and supervisory expectations, at 36%. We read that as a fair reflection of the position. Much of what supervisors will ask for falls under third-party and operational resilience obligations firms already carry, with the EU AI Act adding requirements for higher-risk uses on top. The groundwork for both sits in the same place.”

Farias, meanwhile, said that firms should prioritise these areas in the specific order of governance, compliance and model risk.

He explained, “Governance first, because it’s the framework everything else must sit inside; if you don’t have a clear answer for who’s accountable when a model gets something wrong, nothing downstream matters. Compliance second, because in AEOI reporting specifically, “the algorithm decided” is not an answer that regulators will accept; every validation, every exception, every remediation needs to be traceable back to a rule a human can point to.

“Model risk comes after that, not because it’s less important, but because you can’t meaningfully manage the risk of a system if you haven’t first built accountability and auditability around.”

Farias stressed what he sees from a lot of institutions is a sign of getting things backwards, by starting with the technology and retrofitting governance onto it later.

He said, “That’s expensive and, in a regulated reporting context, often too late, because by the time you’re explaining an exception to an auditor, the governance conversation should already be finished. Firms that are moving carefully are the ones treating regulatory compliance (47% concern in both UK/Europe and North America) and transparency (40-48% across regions) as prerequisites to deployment, not features to bolt on afterward.”

Lastly on this point, Byrne exclaimed that the real question is not whether AI can generate intelligent answers, but whether those answers are explainable, repeatable and robust enough for mission-critical decisions.

He remarked, “Many organisations can successfully build an AI proof of concept. Far fewer can operationalise and maintain AI at scale. This is why governance of AI validation and models is key.”

When AI is scaled, this introduces new challenges, including model validation, version control, data management, vendor dependencies and regulatory compliance.

“Organisations can quickly become reliant on third-party AI providers whose models evolve continuously, creating uncertainty around performance and governance,” said Byrne.

He remarked, “For financial services firms, repeatability is often more important than achieving the most advanced reasoning capability. If a model produces different results without a clear explanation, it becomes difficult to trust the output in regulated decision-making environments. Robust governance and resilience of validation models ensures consistency and repeatability.”

What needs to change

What needs to change before AI can scale safely across financial services?

Farias responds by outlining two connected things that are key in this area.

“First, the technology itself needs to close the explainability gap; this means to be able to show its work in a form a regulator or an internal auditor can actually follow, step by step, not “improve its accuracy” in the abstract. Second, and this is the part the industry doesn’t talk about enough: the maturity bar needs to be set by the compliance function, not by how fast the technology is improving elsewhere. Financial institutions don’t need AI that’s impressive. They need AI that’s boring, predictable, explainable, and provably accurate on the same data every time,” he said.

For the TWC VP, this isn’t a rejection of technology, but instead is an adjustment of priorities.

He said, “When AI can meet the same standard of security, auditability, and regulatory acceptance that proven automation already meets today, only then does it have a real place in compliance workflows.”

In the meantime, however, Farias believes the responsible position, and the one taken by TWC, isn’t to bet a filing deadline or a regulatory relationship on a system that can’t yet explain itself, but to keep using what already works, stay close to what the technology can do, and adopt it deliberately once it clears that bar rather than because it cleared a headline.

Making his final point, Byrne said the next phase of AI adoption will be defined by governance rather than experimentation.

He explained, “Firms need AI models that are explainable, traceable and subject to rigorous validation processes. Strong governance frameworks, combined with high-quality data and effective model risk management, will help organisations move from isolated pilots to enterprise-wide adoption.”

As regulatory expectations evolve, businesses must be able to monitor and respond to changing requirements. Success will belong not to those who deploy AI the fastest, but to those who can demonstrate that their AI is governed, validated and aligned with regulatory expectations.

“Ultimately, AI’s future in financial services depends less on the sophistication of the models and more on the confidence institutions can place in the outcomes they produce,” he said.

Byrne concluded, “AI has moved from experimentation to enterprise priority, yet widespread adoption across financial services remains slower than many expected. While concerns about AI are often framed around futuristic risks, the reality is more practical: firms are grappling with governance, data quality, model validation, output accuracy requirements and scalability challenges.”

A mixed bag

AI may dominate the conversation in financial services, but that does not mean institutions have figured out how to use it effectively.

RelyComply argues that years of “sporadic and excitable investment” have left many organisations with a collection of AI tools that do not work together. The result is a familiar cycle: technology fails to deliver, confidence falls, and business leaders become more reluctant to invest again.

Without automation delivering tangible ROI, AI can quickly start to look like a costly experiment rather than a means of making teams more effective, saving time and driving growth.

That challenge is becoming harder as AI capabilities advance faster than many institutions can modernise their underlying infrastructure. Legacy systems and fragmented customer data remain significant obstacles, while inconsistent approaches to AI regulation add another layer of complexity. At the same time, criminals are becoming increasingly sophisticated in their use of generative AI.

“Without integration, making upgrades to AI-backed onboarding and monitoring processes is far more difficult,” RelyComply says, making it harder not only to implement new capabilities but also to secure executive buy-in.

Technology, however, is only half the equation. Financial institutions need to know how AI is reaching its conclusions, who is accountable for those decisions and whether systems continue to perform as intended over time. For RelyComply, explainable AI and effective oversight are therefore essential, particularly where sensitive customer data and financial crime decisions are involved.

“AI governance has been a missing puzzle-piece,” the company argues, describing it as the groundwork for turning AI from an experiment into something genuinely actionable.

That means institutions need a more structured approach to embedding AI into risk and compliance workflows, supported by clear ownership and appropriate controls. As regulatory frameworks around responsible AI continue to develop, designing AML processes around explainable models with clearly defined accountability could provide an important starting point.

RegTech also has a role to play. Solutions that can connect fragmented customer data, work across existing infrastructure and provide greater control over AI-driven AML processes could help institutions overcome some of the barriers created by legacy technology.

RelyComply believes successful AI adoption will require more than individual institutions buying better tools. RegTechs, regulators and governments will need to work together around more consistent standards and interoperable systems.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.