Banks are building AI capability faster than at any point in the industry's history. Bank of America's virtual assistant Erica has now handled more than 3.2 billion client interactions since launch. JPMorgan’s 2026 technology budget of $19.8 billion, up 10% on 2025, names AI as a key driver. DBS reports its 430 AI use cases generated S$1 billion in economic value in a single year, while Standard Chartered reports 296 AI use cases, including 28 generative AI applications. Across the industry, AI is moving from individual deployments towards a broader enterprise capability.

Yet the number of use cases is not what separates leaders from laggards. Two operating models are emerging as banks seek to scale AI. ‘AI-native’ banks are built from the ground up on distributed, automated infrastructure, this includes some newer digital banks. ‘AI-augmented’ banks, on the other hand, retrofit AI onto existing systems designed for a pre-AI era. Either path can support scale but the outcome depends on the strategic choices and the underlying transformation that enables AI to scale as an operating model.

AI has already made banking processes faster and more efficient. Now, leading banks are testing out agentic AI systems that execute sequences of tasks autonomously. Scaling these systems will require stronger architecture and a rethink of workflows, roles and governance, rather than simply more use cases to legacy systems.

The risks are also expanding. Left unsupervised, the greater danger is not a single bad model but an AI system acting autonomously, making decisions at machine speed, with risk compounded by an industry reliant on the same small set of AI providers. Regulators have yet to converge on a shared approach, which means autonomous workflows are being built on current rules, rather than those that may govern them as these systems mature.

AI is changing banking operations rapidly

This research draws on three sources of evidence. Findings on where and how banks are deploying AI are based on 89 project entries submitted to the TAB Global AI Excellence Awards 2026. Analysis of these entries and interviews conducted by The Asian Banker with banks inform the assessment of institutional strategies. Regulatory developments and industry-wide statistics are drawn from independent research and secondary sources.

AI adoption is concentrated where data is structured and decisions are repeatable, but it is no longer confined to these areas.  Use cases have expanded from automation and operational support into frontline decisioning and role-specific models, increasingly influencing how decisions are made rather than simply automating existing processes.

Product and business model: AI is progressing beyond process improvement to enable capabilities that banks previously lacked. It brings together previously siloed customer, product, credit and market intelligence into a single workflow, providing broader context for decision-making. OCBC's relationship manager (RM) credit copilot provides advanced document processing and information synthesis for credit application workflows. It has expanded from a single use case into a scalable, productised solution deployed across multiple functions, showing how banks can develop AI capabilities that extend beyond individual use cases.

A second pattern is specialisation, with models designed to perform specific tasks. Nubank's proprietary credit-decisioning model enables the bank to reach segments that conventional scoring models cannot serve, expanding its market reach. The example shows how purpose-built AI can address customer segments that generic scoring tools were never designed to serve.

Risk, fraud and compliance: Risk management is shifting from static, rules-based checks to adaptive, predictive systems. Intelligent data extraction and AI-driven assessment speed up lending decisions, as AI applications span assessment, origination, underwriting and model risk governance. GenAI also speeds up credit memo drafting and RM-facing insights, while real-time decision engines are becoming a benchmark in personal credit. A key shift is how banks balance automation with human oversight and monitor AI applications. GXBank's dual GenAI framework automates fraud management processes, strengthens risk assessments and generates data driven recommendations for review. This pattern is emerging across leading banks, with AI automating analysis while humans retain responsibility for reasoning and review.

Operational excellence and infrastructure: The biggest enablers for AI scale are the underlying data and core foundation, cloud infrastructure and model management capability. These foundations determine whether a model can go from pilot to production in weeks rather than years. Leading banks are building model platforms that support faster deployment of use cases. ICBC built its large language model (LLM) framework around institutional knowledge engineering, orchestrating multiple agents across functions under a single governance-embedded architecture. In another example, Pudao Credit has industrialised AI by automating model development, validation and deployment, extending advanced risk modelling capability to other financial institutions. These institutions treat AI infrastructure as a product that can be industrialised and reused. Digital employees and agent teams are also emerging as a new execution layer for some of the leading banks. 

Customer experience and engagement: The industry is shifting from cost deflection to revenue generation with personalisation based on real time customer insights and intent. AI as an interaction layer helps customers navigate services through natural language and intent rather than menus. Use cases span contact-centre cost reduction, revenue growth through personalisation and financial inclusion. Bank Mandiri deploys an AI-powered personalisation engine within its Livin Super App that uses behavioural and transactional data to tailor recommendations, customer interface elements and prompts at scale, with the aim of increasing engagement.

Frontier innovation: Leading banks are moving into more advanced AI applications, including pilots in agentic AI where autonomous systems execute multi-step workflows, orchestrate tasks and coordinate human-AI collaboration. For instance, China Construction Bank (CCB) implemented end-to-end automation for negotiation, risk validation, approval and settlement, in repo trading. Agentic AI use cases remain early, but they signal a shift from AI assisting processes towards AI executing parts of them.

How leading banks are scaling AI

The banks furthest along in scaling AI are not simply adding more AI applications but rebuilding the underlying architecture for reuse. They can take either an AI-native or AI-augmented approach. The outcome depends on how strategically each bank adapts its architecture, governance and operating model to its starting point.

Digital banks built on distributed, automated infrastructure have a head start in developing AI-native capabilities. WeBank runs a unified AI engineering platform with end-to-end lifecycle management covering data processing, model management, training and deployment as well as application monitoring. This enables the bank to replicate and deploy AI capabilities across automated operations, intelligent decision-making and customer engagement at scale. Ryt Bank in Malaysia was built as an AI-native bank, with customer engagement centred on personalised, conversational and real-time interactions across digital channels.

Meanwhile, most traditional banks face the more complex AI-augmented path. The obstacles include existing legacy systems, data frameworks that are not integrated for AI, workflows not designed for real-time decisioning and a persistent skills gap. Addressing these challenges requires a genuine strategic rethink, not simply a larger budget.

Some banks have made more progress in this transition. Standard Chartered has anchored its approach in governance and reusability. Wealth management and corporate banking were among the first functions to go live, according to Alvaro Garrido, Chief Operating Officer, Technology & Operations, who said the bank's AI Factory now gives teams a library of reusable components for agentic workflows and document processing, overseen by an AI safety team embedded across functions.

Techcombank applies a similar discipline to its engineering approach. Its Chief Technology Officer Tran Hoang Quan said the bank is building a modular AI agent platform and redesigning parts of its software development lifecycle to shorten business analysis timelines and improve efficiency. The platform runs within Techcombank's secure cloud environment and is designed for reuse, reducing the time to build an agent from eight months to less than a week. "The most important part is to get the data right," he said.

Kasikornbank illustrates a different route to scale: through people as well as platforms. Embedding GenAI into everyday workflows allows staff across 22 divisions to build hundreds of use cases themselves. The bank scaled from roughly 55 use cases and 31 full-time-equivalent (FTE) hours in time savings in 2024 to 500 use cases and 191 FTE avoided in 2025 — a tenfold increase in use cases within a year. It achieved this through proactive enterprise engagement and by grouping similar requests across departments into its shared infrastructure rather than building each one separately. "Data and AI would not be useful at all if you do not create visible impact," said Tiravat Assavapokee, Executive Vice President, Data Intelligence and IT Integration Division.

Leading banks focus on AI factories, model and agent platforms as shared infrastructure, governance built into data and deployment from the start, and mixed-model architectures rather than single-provider bets, coordinated through centres of excellence. The advanced deployments have moved beyond single-purpose assistants into multi-agent orchestration. What separates the leaders is not platform, governance or talent alone — it is how deliberately each bank choses a path and builds around that strategy.

Managing the emerging risk frontier

The AI industry that supplies banks with agentic AI technology shows the rapid pace of development and the difficulty of containing these systems.

In April 2026, Anthropic withheld its Claude Mythos Preview model from general release after internal safety testing found that it could autonomously identify and exploit software vulnerabilities, including zero-days, at a level the company judged too capable for commercial release. It launched Project Glasswing, an initiative that brought together selected partners to secure the world’s most critical software and put these capabilities for defensive purposes. On 9 June it launched Fable 5, a Mythos-class model with safeguards for general use. On 12 June, the US government, citing national security authorities, issued an export control directive that suspended all access to Fable 5 and Mythos 5 for foreign nationals. On 1 July, Fable 5 became available again to users globally while Mythos 5 access was restored for a group of US organisations.

A separate incident occurred in July 2026, when OpenAI disclosed that a combination of models, including GPT?5.6 Sol and a pre-release model, broke out of an isolated test environment by exploiting a previously unknown vulnerability and reached the production infrastructure of Hugging Face. Following the disclosure, Anthropic reviewed more than 141,000 evaluation runs and identified three incidents in which a model accessed the internet and then gained unauthorised access to the production infrastructure of three different organisations through a misconfigured third-party test environment. None of these incidents occurred inside a bank, but inside the organisations building the autonomous, agentic systems that banks are now deploying. These show that containment assumptions can fail even under controlled conditions.

The attack surface also expands as quickly. Deepfake identity fraud, AI-generated synthetic identities and coordinated account-takeover campaigns increasingly overlap. Some banks already counter these threats as attackers use AI-based facial-substitution technology to swap fraudster features onto legitimate identity documents during digital account opening. Fraud teams now build detection specifically for AI-substituted faces, as banks increasingly use AI to counter AI-driven fraud.

Bias and opacity are the harder, less visible risks. Algorithmic bias in lending is already producing litigation. Explainability has become one of the most-cited concerns in AI compliance. Newer model-level threats add another layer of risk. Memory poisoning can corrupt an agent's long-term knowledge base, while prompt injection can trick a model into ignoring its own safety guardrails. Human oversight thus remains necessary, but at machine speed and machine scale, it is no longer enough on its own.

Vendor concentration raises its own governance question. A small number of cloud and foundation-model providers now support a large share of the industry's AI capability. A single vendor failure or breach is no longer an isolated event. Regulators are increasingly treating this as a systemic risk, not simply a procurement issue. Some banks in the region also evaluate open-weight or domestically hosted models, partly to reduce dependence on a handful of frontier-model providers concentrated in a single jurisdiction.

Regulators are taking different approaches

The Financial Stability Board's June 2026 consultation sets out 12 sound practices for responsible AI adoption, covering organisation-wide governance as well as management of different stages of AI development and deployment across the AI lifecycle. It advocates human oversight but notes that monitoring and detecting AI actions in real-time can be very difficult since an AI agent can take hundreds of intermediate steps in pursuit of its goals. It recommends that in some cases, effective monitoring may require augmentation with another AI agent. The recommendation points to a broader challenge: human oversight alone may not scale to monitor agentic AI.

In November 2025, the Monetary Authority of Singapore (MAS) proposed guidelines on AI risk management to guide financial institutions (FIs) on the responsible use of AI. These set out supervisory expectations across four areas: oversight of AI risk management, key AI risk management systems, policies and procedures, AI life cycle controls, and the capabilities and capacity needed to use AI responsibly. In August 2026 MAS confirmed that guidelines apply to all AI use cases by FIs, including agentic AI.

Regulatory approaches vary. India's central bank, the Reserve Bank of India, released a June 2026 draft of its ‘Guidance on Regulatory Principles for Model Risk Management’ that would require every regulated entity to build "kill-switch arrangements" to override, suspend, or deactivate AI models. It calls for a board-approved risk management framework and accountability for high-risk systems, and makes clear that a bank cannot transfer that accountability onto a vendor, even where the model itself is third-party built.

The EU AI Act lays down harmonised rules on AI to improve the functioning of the internal market and promote the uptake of human-centric and trustworthy AI. Compliance is phased: prohibited practices took effect from February 2025, obligations for general-purpose AI models took effect from August 2025 and high-risk system obligations under Annex III, originally due from August 2026, were deferred to December 2027. Transparency obligations, however, remain on the original August 2026 timeline.

Meanwhile the US takes a more cautious approach. The Federal Reserve, together with the Office of the Comptroller of the Currency (OCC) and Federal Deposit Insurance Corporation (FDIC), recently issued SR 26-2, the first rewrite of American bank model-risk guidance in fifteen years. It describes generative and agentic AI as "novel and rapidly evolving" and excludes them from its scope. As a result, banks need to manage these technologies through broader risk-management and governance frameworks.

Different regulators have different approaches. For a bank operating across these jurisdictions, the need to comply with multiple, divergent regulatory frameworks is itself a risk.

The seven pillars of an AI-driven bank

Becoming an AI-driven bank is not a single initiative; it is a multi-front transformation. Across the programmes examined, seven pillars recur, spanning how a bank builds and scales its AI capabilities.


Foundation: build once, scale everywhere: Banks that scale AI rapidly invest in a unified, model-agnostic orchestration layer, real-time unified data platforms and reusable, cloud-native infrastructure, ahead of peers. As agentic AI moves from single-task copilots to multi-agent systems, this foundation becomes a prerequisite for scaling use cases.

From pilots to production: The institutions that scale AI effectively treat AI-driven banking as a core operating mode, not a portfolio of pilots. They prioritise structured, repeatable decisions first, then extend AI's role as confidence builds. Reusable components, governance and review processes also allow faster deployment without rebuilding the same foundations for each use case.

Govern by design, not exception: Banks that build governance into AI systems from the outset move faster. Controls and revocable permissions work best when they are designed in from the start rather than bolted on later, while model validation and audit trails operate independently. Increasingly, AI systems also monitor other AI systems, working alongside human oversight rather than replacing it. Explainability and model-risk oversight remain standing disciplines. Governance also extends to data quality, access management and vendor and infrastructure concentration.

Regulatory strategy: design for the most demanding requirement: Regulators do not converge on a common approach, so banks operating across markets need to design their governance to accommodate the most demanding applicable requirements across jurisdictions. This includes board-level accountability for high-risk systems before it becomes mandatory, as well as appropriate disclosure to customers and regulators.

Workforce and process: redesign the work, not just the tools: Scaling AI must be accompanied by a genuine reorganisation of roles and workflows, not a tool rollout layered onto existing processes. To drive real value, banks need to question how a process should be redesigned, not simply where AI can make the existing processes faster. Continual embedded upskilling and reskilling will be decisive in competitive positioning.

Impact analysis: prove value, not just velocity: The sector's defining credibility problem is not whether AI works but whether banks can prove its value. Productivity metrics and usage figures accumulate faster than finance-owned measures of return on investment (ROI), revenue impact and cost structure. Banks with stronger measurement frameworks distinguish between how fast AI deploys and how much value it delivers.

Build trust for agent customers: A frontier most banks have yet to build for is the emerging reality of AI agents as counterparties. As personal AI agents begin comparing products and negotiating terms across institutions on customers' behalf, delegation and consent frameworks built for human-facing authority do not automatically extend to autonomous agents. Banks will need agentic payment and settlement infrastructure, cross-institution interoperability standards and frameworks for autonomous transactions. Banks also need to prepare for agent-to-agent interactions before they become widespread, rather than retrofit systems once they emerge.

Governance, architecture and the ability to scale are not three separate workstreams to be resourced independently — they are parts of the same strategy. The banks that scale AI effectively are not necessarily those with the most use cases, but those that build the foundation to support them.