EU AI Act: Why banks shouldn’t spend the next two years preparing for yesterday’s AI

0
13

By Adrian Congiu, VP Head of Product Management, Mambu

Two years after the EU AI Act came into force, the case for AI in financial services and the parameters for its responsible use are becoming clearer. Banks increasingly understand the baseline need for explainability, accountability and human oversight, but the most interesting question is whether their technology can actually deliver those things as AI evolves.

The implementation timeline gives financial institutions valuable time to prepare. But AI development has shown no signs of slowing down. Models will continue to improve, agentic systems will become more capable and regulatory expectations from the industry will continue to grow.

Join The European Business Briefing

New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.

Subscribe

For banks, the biggest risk isn’t missing the next regulatory deadline. It’s spending the next two years preparing for yesterday’s AI and deferring the benefits that a compliant AI capability can deliver. 

AI governance is becoming an architecture challenge

While it is tempting to treat AI governance primarily as a regulatory exercise, trustworthy AI depends on what sits underneath those controls.

Banks need to demonstrate where data came from, what systems accessed it and who is accountable when something goes wrong. As AI moves from generating insights towards performing operational tasks that requirement becomes more demanding.

An AI agent investigating a transaction or orchestrating a banking workflow may interact with multiple systems in seconds. Governing that activity requires deep audit trails and traceability, potentially down to individual interactions with core banking data. Surface-level monitoring is unlikely to be enough to provide that oversight, should things go wrong. For many financial institutions, this is exposing a deeper problem. The technology foundations that supported banking for decades were not designed for an environment in which intelligent systems continuously access data and initiate actions in real time.

Don’t build for a regulatory finish line

The EU AI Act will not be the last word on AI governance. Standards are still developing, guidance will evolve and new AI capabilities will create questions regulators have not yet had to address. Banks should therefore resist designing their AI infrastructure around a single compliance milestone. The objective should be continuous adaptability rather than ticking off a checklist.

That preparation mindset shift means asking whether data is accessible and trusted, whether systems communicate through APIs and whether new controls can be introduced without rebuilding the underlying architecture. Legacy infrastructure can make each of these requirements harder. 

When data is fragmented across tightly coupled systems or dependent on batch processes, introducing AI becomes an integration project before it becomes an innovation project. Modernisation should create an environment where banks can respond to the next regulatory requirement as readily as the current one.

The shift to agentic AI

The infrastructure question becomes more urgent as banking moves from generative AI towards agentic AI. While many current applications summarise information, assist employees or identify patterns, AI agents will increasingly be expected to perform multi-step tasks, interact with banking systems and potentially execute actions within clearly defined controls.

For that to happen safely, agents need real-time access to structured data, APIs through which systems can communicate, orchestration capabilities and clear audit trails. Human oversight must also be built into workflows where judgement, nuanced thinking or regulatory accountability demands it. This is where architecture starts to determine what is possible. If banks try to operate entirely within the constraints of legacy infrastructure, what AI can achieve will inevitably be capped.

Modernisation doesn’t require a big bang

Banks should be wary of carrying out a risky “big bang” core replacement programme. Large-scale transformations introduce their own operational risks and can take years to deliver value. A more pragmatic approach is to modernise progressively, running cloud-native and composable technology alongside existing infrastructure over time. This allows banks to improve access to data and introduce API-first services without betting the institution on a single migration event. 

It also recognises that most banks should not attempt to build every component themselves. Digital-native banks may have the engineering resources and culture to develop significant parts of their technology stack internally, but that model is difficult to reproduce. Specialist technology partners can allow institutions to modernise at a pace that would otherwise be difficult to sustain.

Use the next two years to build for continuous change

Regulation is often framed as something that slows innovation. In this case, the preparation window can create the opposite opportunity. Banks can use it to address the foundations that trustworthy AI requires: clean and accessible data, composable services, real-time connectivity, orchestration, explainability and auditability. 

Financial institutions should therefore challenge assumptions about what AI will be able to do and prepare their infrastructure accordingly. The pacesetters will not necessarily be those that adopt every new capability first, but those that can adopt useful capabilities safely as they emerge.

The implementation delay gives financial institutions a real opportunity to modernise the technology foundations that can accommodate whatever comes next. Because the biggest risk isn’t missing the next regulatory deadline, it’s reaching it with an architecture designed for yesterday’s AI.

LEAVE A REPLY

Please enter your comment!
Please enter your name here