The rapid adoption of AI is also creating a new category of cyber and operational risk. At FIBAC 2026, BCG Managing Director and Partner Hardik Shah highlighted the need for banks, regulators, and government institutions to strengthen cybersecurity, governance, shared infrastructure, and human accountability as AI adoption accelerates.
The challenge is no longer simply implementing AI securely.
It is about governing an increasingly autonomous digital banking ecosystem.
As AI becomes embedded into critical banking processes, identity becomes one of the most important layers of that governance model.
Why AI Is Becoming a Banking Security Challenge
Banks already operate some of the most complex digital ecosystems, connecting customers, employees, applications, payment systems, cloud platforms, third party providers, and regulatory infrastructure.
AI introduces another layer of complexity.
AI systems can analyse data, make recommendations, automate decisions, interact with applications, and increasingly execute tasks with limited human intervention.
This creates new questions around
• Who can access AI systems
• What data can AI systems access
• Which decisions can AI influence
• What actions can AI execute
• Who owns each AI system
• How AI activity is monitored
• How decisions can be audited
• What happens when an AI system is compromised
The challenge is therefore not simply AI governance.
It is identity governance across an AI enabled banking environment.
From Automation to AI Driven Banking H2
Traditional automation typically followed predefined rules and workflows.
AI systems can operate across larger datasets and adapt their behaviour based on context and inputs.
This creates opportunities across banking including
• Fraud detection
• Credit assessment
• Customer service
• Risk management
• Financial crime monitoring
• Personalised banking
• Loan processing
• Compliance operations
• Back office automation
• Cybersecurity
The opportunity is significant, but the consequences of an incorrect or compromised AI decision can also be significant.
In financial services, trust must therefore be built into every stage of the AI lifecycle.
The Cyber Risk Is Evolving
One of the most significant concerns highlighted at FIBAC 2026 is the changing economics of cyberattacks. BCG's Hardik Shah stated that the cost of creating cyberattacks has fallen 17 fold while attack speeds have increased significantly.
This creates a difficult environment for banks.
Attackers can increasingly use AI to accelerate
• Reconnaissance
• Social engineering
• Fraud
• Credential attacks
• Vulnerability discovery
• Malware development
• Automated exploitation
• Data extraction
At the same time, banks are using AI to strengthen their own defences.
This creates an emerging AI security race.
The organisations that can govern AI effectively will be better positioned to use it as a defensive capability without introducing uncontrolled risk.
Identity Becomes the Critical Control Layer
Banking has always depended on strong identity controls.
AI expands the identity ecosystem beyond traditional human users.
A modern banking environment can include
• Customers
• Employees
• Administrators
• Developers
• Applications
• Service accounts
• APIs
• Cloud workloads
• Machine identities
• AI agents
• Autonomous workflows
Each identity can have access to sensitive systems or data.
As AI agents become more capable, some may also require permissions to initiate actions across multiple applications.
This creates a fundamental governance requirement.
Every AI identity must have a defined owner, appropriate permissions, controlled access, and continuous monitoring.
The Risks of Uncontrolled AI Access
If AI systems are deployed without strong identity governance, banks could face
• Unauthorised access to sensitive financial data
• Excessive privileges for AI agents
• Compromised machine identities
• Manipulated AI outputs
• Fraudulent transactions
• Data leakage
• Uncontrolled third party access
• Privilege escalation
• Regulatory exposure
• Loss of customer trust
The risk becomes particularly significant when AI systems are connected to critical banking infrastructure.
A compromised AI identity could potentially become a pathway into multiple interconnected systems.
Governance Must Move Beyond Traditional Model Risk
Banks already have established governance practices for traditional predictive models, particularly in areas such as underwriting and risk assessment.
However, generative AI introduces different characteristics.
AI systems may be dynamic, probabilistic, highly interconnected, and capable of interacting with other systems.
This means governance must address
• Model transparency
• Explainability
• Data provenance
• Access control
• Identity ownership
• Human accountability
• Continuous monitoring
• Output validation
• Auditability
• Third party dependencies
The governance framework must evolve alongside the technology.
Building an Identity First AI Governance Model
A secure AI operating model for banking should include several foundational controls.
1. Establish AI Identity Ownership
Every AI system and AI agent should have a clearly defined business and technical owner.
Ownership should remain accountable throughout the AI identity lifecycle.
2. Apply Least Privilege
AI systems should receive only the permissions necessary to perform their intended function.
High risk actions should require stronger controls and appropriate approval.
3. Continuously Verify Access
Authentication should not establish permanent trust.
Access should be continuously evaluated based on identity, behaviour, device, context, risk, and requested resource.
4. Govern Non Human Identities
Service accounts, APIs, workloads, applications, and AI agents should be governed with the same level of discipline applied to human identities.
5. Monitor AI Behaviour
Organisations should continuously monitor AI interactions and identify abnormal activity, privilege escalation, unusual data access, or unexpected system behaviour.
6. Maintain Human Accountability
AI can automate processes, but accountability for high impact financial and security decisions must remain clearly defined.
Why Industry Wide Collaboration Matters
Cybersecurity cannot be treated as an isolated problem for individual banks.
The banking ecosystem depends on shared infrastructure, third party providers, technology platforms, payment networks, and interconnected services.
BCG's Hardik Shah has argued for greater industry level investment and shared cybersecurity utilities rather than expecting individual banks to address systemic cyber risk independently. He also proposed AI sandbox environments and third party and fourth party vendor registries to support controlled experimentation.
This approach could help banks test AI systems in controlled environments before exposing them to production infrastructure.
It also creates opportunities for stronger governance around
• Third party AI providers
• Fourth party dependencies
• AI infrastructure
• Shared security capabilities
• Vendor accreditation
• AI testing environments
• Industry wide threat intelligence
Zero Trust for AI Enabled Banking
Zero Trust principles become increasingly relevant as AI becomes embedded across banking environments.
Instead of assuming that an authenticated identity or trusted application should automatically receive access, organisations should continuously validate
Who is requesting access?
What is requesting access?
What resource is being accessed?
Why is access required?
What level of privilege is required?
What is the risk associated with the request?
Is the behaviour consistent with expected activity?
This approach creates a more resilient security model for both human and non human identities.
Trevonix Perspective
At Trevonix, we believe the transformation of banking through AI must be accompanied by an equally significant transformation in identity governance.
AI can improve fraud detection, accelerate decision making, personalise customer experiences, and automate complex banking operations.
But every AI capability introduces new identities, access pathways, privileges, and dependencies.
The banking organisations that successfully scale AI will therefore need to build governance into the architecture from the beginning.
This means
• Governing human and non human identities
• Applying least privilege to AI agents
• Continuously validating access
• Monitoring identity behaviour
• Securing privileged access
• Managing AI identity lifecycles
• Maintaining human accountability
• Extending Zero Trust across AI environments
AI should not operate outside the existing security architecture.
It should become part of it.
Conclusion
AI has the potential to fundamentally reshape banking, but responsible adoption will depend on whether governance and cybersecurity capabilities evolve at the same pace.
The financial sector is entering an environment where human users, applications, machines, and AI agents increasingly interact with the same critical systems.
That makes identity a foundational component of AI governance.
The question for banks is no longer simply
How do we deploy AI?
It is
Who can AI act as, what can it access, and how do we maintain control over every action it takes?
The future of secure banking will depend on answering these questions before AI becomes deeply embedded across critical financial processes.
AI can transform banking.
Strong identity governance will determine whether that transformation remains secure, accountable, and trusted.
Reference H2
Source: Economic Times CISO, AI to reshape banking, governance must evolve to curb cyber risk.


.webp)
