Written by Gowtham Raj, Director at TartLabs, who leads AI, mobile, and custom software engagements for fintech, banking, and enterprise clients.
Disclosure: TartLabs builds the kind of systems described here commercially. Where that shapes a view, it is flagged in the "Our take" notes.
The Short Answer
Most of what AI in finance has actually changed sits behind the glass, not on it. The customer-facing chatbot gets the press; the systems earning their keep are the ones deciding whether a transaction clears, whether a file gets read by a person, and whether a loan application is scored in four seconds or four days.
That distinction explains an otherwise strange pair of numbers. 81% of financial services firms surveyed by the Cambridge Centre for Alternative Finance (CCAF) are adopting AI at some level. Only 14% say it is transformational to their strategy. The gap is not hesitation. It is the difference between running AI somewhere in the estate and rebuilding a product around it.
This is written for banking and fintech product leads, CTOs, and founders sizing up a build. On returns, it covers which AI applications actually pay back in 2026 and why fintechs keep converting adoption into profit faster than incumbents. On regulation, it covers what changed in the calendar this year, because one widely-cited deadline moved and guidance published before August has not caught up. On architecture, it covers what agentic AI means for a payments roadmap, why the "95% of pilots fail" figure is misread, and the decisions that separate a system still running in year three from a pilot quietly shelved.
Key Takeaways
- 81% of surveyed financial services firms are adopting AI at some level and 40% report advanced adoption, yet only 14% see AI as transformational to their strategy and competitive advantage (Cambridge Centre for Alternative Finance, 2026 Global AI in Financial Services Report, April 2026, n=628 across 151 jurisdictions)
- Four of the top five AI use cases in financial services are back-office: process automation (79%), data visualisation (75%), software engineering (75%), and data and knowledge management (69%). Fraud detection (57%) and credit risk modelling (54%) lead the risk and compliance group (CCAF 2026, same survey)
- Fintechs lead incumbents on advanced AI adoption by 47% to 30%, and 56% of fintechs report higher profitability from AI versus 34% of traditional financial institutions (CCAF 2026, same survey)
- The EU AI Act's high-risk deadline moved. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and pushed Annex III obligations, which cover creditworthiness assessment, from 2 August 2026 to 2 December 2027. Article 50 transparency duties took effect on 2 August 2026 as originally scheduled
- Deepfakes now account for one in five biometric fraud attempts, and Deloitte projected in 2024 that generative-AI-enabled fraud losses in the US would rise from $12.3 billion in 2023 to $40 billion by 2027, a 32% CAGR (Entrust 2026 Identity Fraud Report, November 2025; Deloitte Center for Financial Services, May 2024)
- The much-quoted "95% of AI pilots fail" figure comes from a non-peer-reviewed 2025 MIT NANDA paper built on 52 interviews and 153 survey responses, and it measured absence of documented P&L impact, not failure. Treat it as directional, not as a base rate
What Counts as an "AI App" in Finance
The phrase covers everything from a support chatbot to a trading system. Three layers sit underneath it, and they are worth separating. Most stalled projects trace back to the same mistake: one layer resourced properly, the other two assumed to be somebody else's job.
The decision layer is the model doing the actual work: scoring a transaction for fraud, ranking a credit file, extracting terms from a document, classifying a support ticket. This is what people picture when they say AI. It is also, increasingly, the part you do not build. 63% of surveyed industry respondents run internal workflows on external foundation models rather than training their own (CCAF 2026).
The data and integration layer feeds the decision layer and carries its output somewhere consequential. That means core banking connectors, KYC providers, transaction histories, document stores, and the case management system a human analyst actually opens. This layer is where projects die. Data availability and quality is the leading pain point hindering AI adoption, cited by 40% of industry respondents overall and 49% of traditional financial institutions specifically, against 34% of fintechs (CCAF 2026).
The application layer is what a person actually uses. The mobile app, the analyst console, the underwriter's queue, the customer's dispute flow. It holds the thresholds that decide what counts as an exception, the override controls, and the audit trail that settles a regulator's question eighteen months later.
Commercially, "AI app" means the third layer, built on informed choices about the first two. Buy a model API, skip the application layer, and you have a demo. No operations team will accept it. That is the failure pattern we see most often when a stalled build lands on our desk.
Where the Measurable Returns Actually Are
Adoption is broad and uneven, and the shape of it tells you more than the headline. The 2026 Global AI in Financial Services Report was produced by CCAF with the BIS, IMF, World Economic Forum, and World Bank Group. It draws on 628 respondent organisations across 151 jurisdictions. Its headline structural finding is that four of the top five financial services AI use cases are back-office functions.
Four kinds of AI apps carry a defensible business case in 2026, separated from the rest by a margin wide enough to steer scoping.
1. Fraud and financial crime, where the economics are hardest to argue with
Fraud detection is the risk use case furthest along at 57%, and it is the one where the counterfactual is easiest to price. A rules engine produces a known false-positive rate and a known volume of manual reviews. Both are line items, so an improvement converts directly into money.
Mastercard, working with Financial Times Longitude, surveyed 300 senior fraud and risk executives in 2026. 42% of card issuers and 26% of acquirers reported saving more than $5 million in fraud losses over two years through AI, and 83% of industry leaders said AI had reduced false positives and customer churn.
The pressure driving that spend is worth stating plainly, because that pressure now runs in both directions. Attackers have the same tools. The Entrust 2026 Identity Fraud Report, published in November 2025 and drawn from more than a billion identity verifications across 195 countries and over 30 industries, found deepfakes linked to one in five biometric fraud attempts, injection attacks up 40% year over year, and deepfaked selfies up 58% during 2025. Deloitte's Center for Financial Services projected in May 2024 that generative-AI-enabled fraud losses in the United States would rise from $12.3 billion in 2023 to $40 billion by 2027, a compound annual growth rate of 32%.
The consequence for a product team is blunt. Document-and-selfie onboarding, adequate for years, no longer stands on its own. Liveness detection, injection-attack resistance, and device signals stopped being differentiators and became table stakes. Retrofitting them is squarely AI development work, not a vendor swap.
2. Credit decisioning, where speed is the product
Credit risk modelling sits at 54% adoption. The value shows up as cycle time, not a better default rate. An underwriting flow that takes three days loses applicants to whoever answers in three minutes. AI-assisted document extraction, bank statement parsing, and alternative data scoring compress the gap between application and decision, and in consumer and SME lending that compression is the product. Most of that work is integrating AI features into existing software rather than greenfield modelling.
This is also the use case with the most regulatory weight attached, which the next section covers.
3. Customer support, the front-office exception
At 74%, AI-powered customer support is the only front-office use case near the top of the list, and the fintech-incumbent gap here is stark: 82% versus 67% (CCAF 2026). The likeliest explanation is architectural rather than cultural. Answering "why was I charged this" requires the assistant to reach the transaction record, and a fintech built in the last decade can expose that through an API in a sprint. A bank on a forty-year-old core cannot.
We have covered the build patterns for this in detail in our guide to AI customer support automation.
4. Internal engineering and operations, the quiet winner
Software engineering is the industry's most mature AI application, with 42% fully deployed and 33% in development (CCAF 2026). It rarely appears in strategy decks. It changes no customer-facing product, so nobody presents it. It is also where a large share of the realised value sits.
NVIDIA's sixth annual State of AI in Financial Services survey, published on 22 January 2026 and covering more than 800 industry professionals, found 65% of respondents actively using AI. The year before it was 45%. 89% reported AI both increasing revenue and lowering costs, with 52% naming operational efficiency as the largest gain and 48% naming employee productivity.
Our take: On finance builds, the highest-confidence first project is almost never the one the board is excited about. It is a back-office process with a measurable current cost, an owner who wants it fixed, and clean enough data to start. Ship that, get the baseline numbers, and the argument for the ambitious build makes itself. Start with the ambitious build and you will be arguing from a demo.
The Fintech Gap Is Wider on Outcomes Than on Adoption
The most consistent finding across the 2026 data is that the divide between fintechs and traditional institutions is substantial on every measure the CCAF survey reports. Within that single-year snapshot, the gap on outcomes is wider than the gap on adoption, which is the more useful half of the finding: it is not that incumbents have failed to start, it is that starting has bought them less.
| Measure (CCAF 2026) | Fintechs | Traditional FIs | Gap |
|---|---|---|---|
| Advanced AI adoption (Scaling or Transforming) | 47% | 30% | 17 pts |
| Reached the "Transforming" stage | 19% | 6% | 13 pts |
| Active agentic AI adoption | 57% | 45% | 12 pts |
| AI-powered customer support in use | 82% | 67% | 15 pts |
| Report increased profitability from AI | 56% | 34% | 22 pts |
| Rely mainly on on-premises or local cloud | 23% | 39% | 16 pts less legacy-bound |
Two mechanisms explain most of it, and neither is about talent density.
The first is data access. Legacy architecture is a documented constraint rather than an excuse: traditional institutions remain more reliant on on-premises or local cloud deployments at 39%, against 23% of fintechs (CCAF 2026). Where the transaction record sits behind a nightly batch export, real-time AI is not an option regardless of how good the model is.
The second is that spending correlates with outcome more tightly than most cost-conscious pilots assume. Among organisations spending more than $100,000 a year on AI, 62% have reached advanced maturity, and 62% of that higher-spending group report increased profitability, against 39% of lower-spending organisations reporting the same profitability gain (CCAF 2026). There is a counterweight worth registering, and the report states it plainly: 53% of surveyed industry respondents "spend under USD 100,000 annually on AI yet still report high maturity in GenAI and agentic AI" (CCAF 2026). Low spend does not preclude maturity when the expensive part is somebody else's model.
What Actually Changed in the Regulatory Calendar This Year
If you read one section closely, make it this one, because guidance published earlier in 2026 is now out of date on a point that matters.
For two years, every financial-services AI roadmap shared one fixed point: 2 August 2026, when Annex III high-risk obligations under the EU AI Act became applicable. Creditworthiness assessment of natural persons is an Annex III use case. That put most consumer lending models directly in scope.
That date moved. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July, six days before the original deadline. Standalone Annex III high-risk systems, credit scoring included, now apply from 2 December 2027. High-risk AI embedded in products already covered by EU product-safety law moves to 2 August 2028.
What did not move matters just as much. Article 50 transparency obligations took effect on 2 August 2026 as originally scheduled, and they apply by system function rather than risk tier. In a finance app that means disclosing when a customer is interacting with an AI system rather than a person, and labelling AI-generated synthetic content. Those duties are live now.
| Date | Obligation | Applies to | Status |
|---|---|---|---|
| 2 August 2026 | EU AI Act Article 50 transparency duties: disclose AI interaction, label synthetic content | Any AI system by function, regardless of risk tier | In force now |
| 13 November 2026 | India DPDP consent manager framework becomes operational | Data fiduciaries handling personal data in India | Upcoming |
| 13 May 2027 | India DPDP Act full substantive compliance; penalties up to Rs 250 crore per violation | Data fiduciaries handling personal data in India | Upcoming |
| 2 December 2027 | EU AI Act Annex III high-risk obligations, including creditworthiness assessment | Standalone high-risk AI systems | Deferred from 2 August 2026 |
| 2 August 2028 | EU AI Act Annex I high-risk obligations | AI embedded in products covered by EU product-safety law | Deferred from 2 August 2027 |
For teams building in or for India, two other instruments matter more than the EU calendar.
The Reserve Bank of India's FREE-AI framework, the report of its Committee on a Framework for Responsible and Ethical Enablement of Artificial Intelligence, was released in August 2025. It sets out seven guiding "Sutras" and 26 recommendations grouped under six pillars: infrastructure, policy, capacity, governance, protection, and assurance. It is principles-based, not prescriptive. So the question banks and NBFCs are actually working through in 2026 is narrower: how do you evidence compliance across governance, vendors, and model risk oversight?
The Digital Personal Data Protection Rules were notified on 13 November 2025 under gazette notification G.S.R. 846(E). The consent manager framework becomes operational on 13 November 2026, and full substantive compliance is enforceable from 13 May 2027, with penalties reaching ₹250 crore per violation. Liability sits with the data fiduciary even where a processor does the actual handling, which is a contractual matter as much as a technical one when the model runs on somebody else's infrastructure.
None of this is a reason to defer a build. It is a reason to make explainability, logging, and consent traceability architectural choices at the start rather than a retrofit in 2027, and 79% of surveyed regulators already rate explainability as critical or important to their objectives while only 50% of industry firms have adopted explainable AI methods (CCAF 2026).
Agentic AI Is the Genuine 2026 Shift
Agentic AI means systems that take multi-step actions rather than returning an answer. This is where the frontier actually moved this year. 52% of surveyed financial services firms are in active adoption, with 23% at scaling or transforming stages and 29% still piloting (CCAF 2026). NVIDIA's survey puts 42% using or assessing agentic AI, and 21% have already deployed agents.
The payments rails moved with it. Google donated its Agent Payments Protocol to the FIDO Alliance on 28 April 2026, publishing AP2 v0.2 with support for "Human Not Present" payments, where an agent executes a purchase on pre-authorised instructions. The same week, the FIDO Alliance announced an Agentic Authentication Technical Working Group drawing on initial contributions from Google (AP2) and Mastercard (Verifiable Intent). Competing efforts from Visa and an OpenAI-Stripe collaboration are reportedly converging on the same problem: how a merchant verifies that an agent is acting with a real customer's authority.
The near-term implication is narrower than the hype suggests. It is also more concrete. Agent-initiated transactions will arrive at your fraud and authorisation systems, and those systems treat non-human traffic as suspect by default. Deciding how you tell an authorised agent from a bot is a 2026-2027 roadmap item, not a 2030 one.
The risk side deserves equal weight. 55% of industry respondents cite loss of human oversight as a top risk, and traditional institutions are markedly more concerned than regulators about it, 60% versus 42% (CCAF 2026). That concern is well-placed. Software engineering is simultaneously the industry's most mature AI application and, on CCAF's reading, a primary cyber risk transmission vector, since the volume and velocity of AI-generated code make traditional manual reviews increasingly ineffective (CCAF 2026).
The "95% of AI Pilots Fail" Number Does Not Mean What You Think
Few statistics circulate more widely than the claim that 95% of AI pilots fail. Vendor decks, board papers, most of this year's banking commentary. It is worth pulling apart, because the number and what it measured are both commonly misstated.
It comes from The GenAI Divide: State of AI in Business 2025, a preliminary paper from MIT's NANDA initiative, widely reported in August 2025. Its evidence base was a systematic review of more than 300 publicly disclosed AI initiatives, 52 structured interviews, and 153 survey responses collected from senior leaders at four conferences between January and June 2025. It was not peer-reviewed, the deployments were not randomly sampled, and analysts questioned the methodology almost immediately.
What the 95% measured was the absence of documented profit-and-loss impact. That is a meaningfully different claim from failure, and much of it is explained by pilots that never established a pre-deployment baseline. A project with no measured "before" cannot produce a measured "after", regardless of whether it worked.
The directional finding does hold, and it matches what the CCAF data shows independently: 55% of industry respondents and 63% of regulators find it difficult to measure the value of AI deployment, rising to 76% among large financial institutions (CCAF 2026). The problem is real. It is a measurement problem, not a technology one, and the fix is cheap if applied at the right moment.
Our take: The most valuable hour on any finance AI project is spent before a line of code, writing down the current-state numbers: manual review volume, false-positive rate, average handling time, decision cycle time, cost per file. Teams that skip it end up nine months later unable to answer the CFO's only question. It is also, uncomfortably often, the hour that reveals nobody actually knows the baseline, which is itself the finding.
Building an AI App That Survives Contact With a Bank
Given a real business case and a named owner, a short list of decisions determines whether the system is still in use in year three.
- Design the human override before the model. Every consequential decision needs a route for a person to reverse it, and a record of who did and why. This is a regulatory requirement under most frameworks and, more practically, it is what lets operations trust the system enough to leave it switched on.
- Log the decision, not just the outcome. Store the inputs, model version, score, threshold in force, and action taken. Reconstructing why a specific customer was declined eighteen months ago is a question you will be asked, and the answer has to exist without archaeology.
- Treat the integration as the project. With data quality cited as the leading barrier by 49% of traditional institutions, the model is rarely the long pole. On the finance builds we have delivered, the great majority of the effort goes into data plumbing and integration rather than modelling, and the estimates that assume the reverse are the ones that slip.
- Instrument for the baseline from day one. Capture the current-state metrics in the same system that will later report the improvement, so the comparison is like-for-like rather than a reconciliation argument.
- Decide build versus buy per layer, not per project. Almost nobody should train a foundation model. Plenty of teams should own their feature pipeline, thresholds, and decision logic, because that is where the domain knowledge and the regulatory exposure both sit. Our comparison of custom AI development and off-the-shelf AI covers where that line usually falls.
- Scope the first release to one decision. One queue, one product, one segment. It produces evidence in a quarter rather than a promise in a year, which is what our AI MVP development guide is built around.
If direction is settled and capacity is the constraint, dedicated development teams in India can carry delivery, and our engineering teams can carry the modelling layer where that falls inside scope.
The Bottom Line
Whether AI works in finance stopped being the interesting question. With 81% of firms adopting it at some level and 89% of NVIDIA's respondents reporting both revenue gains and cost reductions, the technology has become ordinary. What remains uncommon is a deployment that visibly changed how the institution operates, which is why only 14% call AI transformational to their strategy.
Two things make 2026 a materially different year to build in. The regulatory floor shifted rather than rose: the EU's high-risk deadline slid to December 2027 while the transparency duties landed on schedule in August, which buys engineering time on model governance but none at all on disclosure. And the agentic layer became real enough to plan for, with the payments industry standardising agent authorisation through the FIDO Alliance this spring.
The builds that work start from the far end. Find the decision currently being made slowly or badly, write down what it costs today, name who will own making it differently, and only then reason backwards to the smallest model that changes it. To scope what that looks like for your product, contact TartLabs.




