Financial services has outgrown its security model

AI security in financial services

Artificial intelligence is changing financial services at a remarkable pace. Across banking, insurance and capital markets, organisations are using AI to accelerate decision-making, remove operational bottlenecks, and improve customer experiences. What is changing at a far slower rate is the governance and security models needed to support that transformation.

Increasingly, financial institutions are introducing powerful AI capabilities into environments that were never designed for them. This imbalance is creating a new kind of risk: enterprises moving faster than their controls can safely support. The answer is not to slow down, but to adopt security models that secure operations and enable innovation at the same time.

The governance gap behind AI adoption

Financial services has always operated within a tightly regulated environment. However, advances in AI are exposing its limits as a reactive system. Frameworks such as DORA set important expectations around operational resilience and cyber risk, but they were largely shaped around known categories of risk rather than capabilities that evolve month to month. Regulation tends to follow emerging threats rather than anticipate them.

The problem is that AI develops differently. New models, applications, and use cases are appearing continuously, often spreading across organisations before governance teams have fully assessed the implications. That leaves firms balancing competing pressures. On one side there is the demand to innovate and remain competitive. While on the other is the responsibility to maintain trust, resilience and compliance.

As that gap widens, the risk increases. And in a sector where confidence underpins every transaction, the speed of technological change can quickly outstrip the frameworks designed to oversee it.

Financial services is accelerating faster than its controls

The industry is already realising huge benefits, and the examples are concrete. In insurance, intelligent systems help underwriters assess information more efficiently and let claims teams process cases faster, turning a review that once took days into one that clears in minutes. Customer service operations are being reshaped by AI assistants that resolve routine enquiries in moments. Investment and trading functions are embracing tools that surface patterns, analyse market movements and support decision-making at scales previously unattainable.

These advances are shortening processes that once took days into minutes or seconds. That progress is real. Yet speed alone does not create value in financial services. The sector runs on trust, and faster outcomes matter only when strong controls and effective oversight sit behind them.

When speed multiplies risk

An inaccurate AI-generated output is rarely confined to a single workflow, and its impact can stretch across customer interactions and affect risk assessments across interconnected systems. When those systems are highly automated and moving at machine speed, problems can spread before teams can intervene.

It is not just the enterprise feeling the AI tailwind. Threat actors are accelerating too, using AI to identify vulnerabilities, automate reconnaissance and increase the pace of attacks. At the same time, organisations are stripping friction out of decision-making in pursuit of efficiency. Tasks that once required multiple layers of review are being automated, and the human checkpoints that used to catch mistakes before they scaled are disappearing. That is the real multiplier. The risk is not simply that AI is fast. It is that decisions now happen faster, across more connected systems, with fewer chances to intervene than many organisations are prepared for.

Legacy infrastructure creates drag

Many institutions face a further challenge. While AI capabilities may be modern, the infrastructure supporting them often is not. Across the financial sector, legacy environments remain deeply embedded within core operations, with many platforms having been extended and adapted over years rather than appropriately redesigned. As a result, security models are often inconsistent, with older perimeter-based approaches deployed alongside distributed, AI-centric workflows.

AI introduces new demands on these environments. Models require access to large volumes of data, often drawn from multiple systems. APIs, integrations and data connectors create additional pathways between applications, and every new connection expands the potential attack surface. This creates an uncomfortable mismatch. Advanced AI capabilities are being deployed on foundations that were never built for the connectivity, speed and data flows now required. The result is a level of complexity that can obscure vulnerabilities and create exposure that organisations may not fully understand.

Redesigning security to keep pace with innovation

The answer is not to slam the brakes on AI adoption. Financial institutions cannot afford to sit on the sidelines while competitors advance. What they need is a security strategy that evolves alongside innovation rather than scrambling to catch up afterwards.

That starts by reducing unnecessary exposure. AI systems should only have access to the applications, services and data required to perform their intended functions. Access pathways must be reviewed continuously and unnecessary connections eliminated wherever possible.

Security can no longer rely on assumed trust, based on network location. Organisations need approaches that verify access rigorously and consistently, regardless of whether the request comes from a human user, a workload or an AI-driven process.

Why Zero Trust matters in an AI economy

This is where Zero Trust earns its place. As organisations connect more systems and automate more decisions, the opportunities for lateral movement grow, and a single compromise can open the door to multiple environments if controls are not designed to contain it.

Zero Trust limits that exposure by ensuring access is granted only when justified and continuously validated. It helps organisations control how applications, workloads and users interact, while reducing the likelihood that a breach in one area can spread across the business.

This becomes urgent as agentic AI emerges. These systems act autonomously and interact directly with applications, data and processes, which means managing access for non-human identities will soon matter as much as managing it for employees. The unsolved problem is how you enforce least privilege for an agent that decides its own data access at runtime. No security strategy can guarantee a breach never happens. What matters is containing its impact when it does.

Leadership must be AI literate

Technology alone will not solve this challenge. Business and security leaders need a practical understanding of how AI behaves, where it creates value and where risks emerge. That does not require deep technical expertise, but it does require curiosity and engagement.

The organisations navigating this transition most successfully are often led by individuals who have spent time exploring AI firsthand in safe, appropriate environments. Practical experience creates context that cannot be gained from reports or briefings alone. AI represents one of the most significant technology shifts in decades. Leaders making decisions about investment, governance and risk need enough familiarity with the technology to make informed judgements about its role within their organisations.

The burden of responsibility is shifting

AI is reshaping financial services faster than regulation can evolve. That places the burden of responsibility squarely on the organisations deploying it. To stay competitive, they must pair innovation with resilience and keep security embedded at every stage of adoption, not bolted on afterwards.

James Tucker, Head of CISOs International, Zscaler

James Tucker

James Tucker is Head of CISOs International at Zscaler, working with European security leaders on zero trust, strategy, and AI. 

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE