Download the PDF version
Artificial intelligence

Every bank has an AI strategy. None has AI where the risk lives.

Published:
9/9/2026

Every significant institution has an approved AI strategy. It runs in marketing, in customer support, in developer tooling. It does not run in any regulated, safety-critical function, least of all fraud. Banks have AI on paper and none in production where the money actually moves. That contradiction sits at the centre of the industry, and it is worth being honest about how it got there.

A structural failure, not a lack of insight

For more than a decade, the pattern has repeated across the institutions closest to the front line. Banks saw the threat, understood the implications, and assessed the risk with care. What stopped them was not a lack of insight but an industry-wide structural failure. Fraud operations have focused almost entirely on the moment money moves, because everything leading up to it — cybersecurity, identity verification, application integrity — sits outside the fraud team’s remit. Early warning signs get dismissed as someone else’s problem.

Technical teams have been able to map how attacks unfold well before the theft, only to meet internal apathy or institutional deflection. Legacy vendors built exactly what the industry asked for: reactive scoring at the moment money moves. The deeper issue was the siloed operating model that defined the demand, leaving the market optimised for transactions rather than forensics.

The barrier isn’t capability. It’s control.

Force an AI agent to operate in today’s low-visibility environments, and its decisions look less like reasoning and more like dangerous guesswork. No institution can risk an unstable agent that might corrupt data, disrupt application behaviour, or shut down transaction volume. Give the agent deep, granular visibility, though, and it moves from speculation to forensics: instead of guessing from a disconnected transaction alert, it reconstructs the entire attack chain, step by step. Its response becomes auditable, logical and safe to deploy. This is the same session-visibility principle behind a cyber-fraud fusion model.

The economics of standing still

There is an economic story underneath the caution. Research from Stanford University’s Digital Economy Lab shows that for every dollar an organisation spends on software, it absorbs roughly ten more in hidden overheads, process redesign and prolonged consulting cycles — the productivity J-curve that has shaped enterprise technology for a decade. The same research points to consistent internal resistance, with legal, HR, risk and compliance accounting for a significant share of the opposition inside large enterprises. Procurement stalls, and when official systems can’t meet operational timelines, frontline staff build their own workarounds—a parallel network of unapproved tools that move sensitive data through systems never designed for regulated environments.

“Perfect data” is a sales tactic, not a prerequisite

Legacy vendors have used this complexity to sustain dependency, arguing a bank must first build a perfectly unified, multi-year data architecture before deploying advanced automation. Yet the Stanford analysis shows that most successful enterprise automations began with data that was nowhere near ready. “Perfect data” turns out to be less a technical necessity than a commercial mechanism — the same dependency logic that keeps the fraud operating model from scaling.

The holding pattern is organisational, not technical

So the deadlock is not a technology problem. It is organisational. A question of visibility, control and who inside the bank owns the risk. Those are solvable, and who now owns fraud inside a bank is exactly the question regulation is now forcing. The institutions that answer it stop waiting for perfect conditions that were never coming, and move to Autonomous Fraud Operations already running in production.

Read more articles

Regulation

Attackers don't have a compliance deadline. Banks now have two.

Read more

Artificial intelligence

The criminals’ AI is already in production. Banking’s isn’t.

Read more

Regulation

Banking fraud regulation: who now owns fraud inside a bank

Read more