← All Articles

AI and Financial Services: The Partnerships Are Real. The Governance Isn't.

May 2025

I spent several years close to the financial services world, consulting, market intelligence, product strategy, and I came away with a clear picture of how the sector moves: carefully, with significant regulatory awareness, and usually about eighteen months behind where the rest of the world already is. AI was always going to follow the same pattern.

Except 2025 has been genuinely interesting, because the partnerships are actually landing. The deals announced in press releases in 2023 and 2024 are turning into live deployments. Major banks and asset managers are embedding AI into credit decisioning, fraud detection, customer service workflows, and, more quietly, into competitive intelligence and research. The technology is no longer experimental. It is operational. And the governance conversation is nowhere near keeping up.

Laptop and notebook open to a strategy document
The ecosystem deals are landing. The governance conversations are lagging badly behind them.
$340Bpotential annual value for banking from GenAI aloneMcKinsey and Company, 2023
58%of financial institutions attributing revenue growth directly to AIMcKinsey Global AI Survey, 2024
Aug 2025when EU AI Act full enforcement began for high-risk AI systems including credit scoringEuropean Commission
80+fintech acquisitions by banks in 2023 alone, worth $1.2 billionKPMG Pulse of Fintech, 2024

Here is the specific tension I keep coming back to. The EU AI Act came into full enforcement for high-risk AI systems in August 2025, and financial services is firmly in scope. Credit scoring, insurance pricing, employment screening are all explicitly listed as high-risk applications requiring conformity assessments, human oversight, and transparency documentation. These are now legal obligations, not best practice guidelines.

The challenge is that most financial institutions built their AI deployments before those frameworks were finalised. They built for capability, not for governance. The AI running inside credit decisioning systems was not designed with explainability architecture. The audit trails that regulators need to follow were not built in from the start. The retrospective compliance work happening now is genuinely painful. In some cases, the honest answer is that the system needs to be rebuilt, not audited.

The ecosystem partnerships add another layer of complexity that I think is underappreciated. When a tier-1 bank partners with an AI company to deploy a specific capability, who is responsible for governance? The bank is regulated. The AI company may not be. The model is owned by a third party. The decision affecting the customer sits with the institution. The accountability chain is genuinely murky, and regulators are only now starting to ask the questions that will untangle it.

What gives me some optimism is that the better institutions are starting to treat governance as a design input rather than an audit trail. Building explainability into the architecture from the start. Creating human-in-the-loop checkpoints not because regulation requires it, but because the systems are genuinely more trustworthy when those checkpoints exist. The institutions that get this right will move faster later, not slower, because the governance infrastructure will already be in place when they need to deploy the next capability.

Most are not there yet. The gap is going to matter more than most people currently think it will.

Sources

  • McKinsey and Company: The Economic Potential of Generative AI (2023)
  • McKinsey Global AI Survey 2024
  • European Commission: EU Artificial Intelligence Act (2024)
  • KPMG: Pulse of Fintech H2 2024
  • Basel Committee on Banking Supervision: Principles for the Sound Management of AI Risk
← Back to Articles