Site icon Finance Derivative

Speed vs. Safety: Why Financial Services Must Rethink Security as AI Outpaces Regulation

Cyber security and personal data protection are concepts. In search of innovative technology. Biometrics for Facial Recognition Recognition of faces.

By James Tucker, Head of CISOs International, at Zscaler

Artificial intelligence is reshaping financial services at extraordinary speed. Across banking, insurance and capital markets, firms are using AI to make decisions faster, streamline operations and improve customer experience. But while the technology is accelerating, the regulatory and security frameworks around it are not keeping pace. That mismatch is creating a new systemic risk: organisations are moving faster than their controls can safely support.

The Regulatory Gap is Growing

The financial sector has always operated under regulatory scrutiny, but AI is exposing the limits of a model built to respond to change rather than anticipate it. Regulations such as DORA, which set clear expectations around operational resilience and cyber risk for financial institutions across Europe, are important and directionally right. Yet regulation, by design, tends to address the vulnerabilities that have already emerged. AI, by contrast, is being deployed in real time, with capabilities and use cases evolving faster than most policymakers can assess.

James Tucker

That creates a difficult tension for institutions. They are under constant pressure to innovate—whether to improve customer experience, drive cost efficiency, detect fraud faster or sharpen decision-making. At the same time, regulators cannot move at the speed of model deployment. The result is a widening gap between what organisations can do with AI and what their governance frameworks are equipped to oversee. In financial services, that gap matters, because speed without control is not just an operational issue; it is a systemic one.

AI is Transforming Financial Services and Insurance at Speed

The benefits of AI in financial services are real and increasingly measurable. In insurance, for example, adoption is moving quickly in areas such as underwriting and claims, where intelligent systems can assess information and support decisions far faster than traditional workflows. In fraud detection and risk analysis, AI models are helping teams analyse transactions in real time rather than relying solely on batch-based processes that identify issues after the fact.

Customer service is also being transformed, with AI copilots and automated assistants resolving queries in moments that once took hours or days to process. In trading and investment environments, AI-enhanced systems can identify patterns and surface signals at a speed no human analyst could replicate consistently. Even compliance functions, often seen as slower-moving parts of the organisation, are beginning to use AI to summarise regulatory changes and automate aspects of reporting. Together, these capabilities are compressing processes that historically took hours, days or even weeks into seconds.

That acceleration is powerful, but in financial services speed is not inherently safe. In a sector built on trust, resilience and regulatory accountability, faster decision-making only creates value if it is matched by equally strong controls.

When Acceleration Becomes Risk

This is where the risk picture changes. The faster decisions happen, the faster mistakes—and attacks—can scale. An incorrect AI output is no longer a contained error sitting in a spreadsheet or waiting for a manual review. It can propagate instantly across systems, influencing risk models, approvals, customer interactions or operational decisions before anyone has had time to intervene. In highly interconnected environments, small flaws can become large consequences very quickly.

The threat landscape is accelerating too. Adversaries are already using AI in their playbooks, and as the models increase in capability, so does their skill to identify vulnerabilities, automate reconnaissance and increase the speed at which they exploit weaknesses. At the same time, organisations are delegating more decision-making to machines, often reducing the friction that once acted as a safeguard. Human oversight is being streamlined out of the process just as the pace of execution increases. Meanwhile, regulatory frameworks written for slower, more linear systems are struggling to govern real-time AI decisioning. In this kind of environment, risk does not simply rise—it compounds.

The Legacy Infrastructure Problem

The problem is made worse by the infrastructure many institutions are asking AI to sit on top of. In too many cases, advanced AI capabilities are being layered onto legacy environments that were never designed for this level of connectivity, speed or data access. That creates vulnerabilities which are easy to underestimate because the AI itself may appear modern, while the systems underneath remain fragmented and difficult to secure.

Many organisations are still operating with core banking and operational platforms that have been extended over time rather than fundamentally redesigned. Security models are often inconsistent, with older perimeter-based assumptions sitting alongside distributed, AI-driven workflows. AI systems also require access to large volumes of data, much of it held in older environments that were not segmented with modern use cases in mind. Add APIs and connectors into the mix, and institutions create new entry points that threat actors can exploit. In effect, financial firms are combining next-generation intelligence with last-generation infrastructure—a mismatch that creates blind spots neither regulators nor security teams are fully equipped to manage.

Closing the Gap: A Security-First Approach to AI Adoption

The answer is not to slow AI adoption. Financial institutions cannot afford to stand still while the market moves forward. But they do need to secure AI differently. Innovation and security have to evolve together, not sequentially. That means moving away from broad network access and implicit trust, and towards a model based on tightly controlled, application-level access with minimal exposure of systems and data.

In practice, that starts with reducing unnecessary pathways into sensitive environments. Organisations should identify and eliminate redundant access routes, and ensure AI systems can only reach the applications and datasets they strictly need to perform their role. This is where Zero Trust becomes especially relevant. In AI-driven environments, the risk of lateral movement increases because systems are more connected, more automated and more dependent on shared data. If a breach does occur, the goal is not to assume it can be prevented entirely, but to contain the blast radius. But Zero Trust is also able to manage identity and context-aware access for non-human entities (workloads, IoT, etc) , which is the new frontier for business with the emergence of Agentic AI systems. In an AI-driven world, breaches are inevitable. What matters is how far they can spread.

Embrace Zero Trust to Contain the Blast Radius

There is also a leadership dimension to this challenge. Executives cannot govern what they do not understand, and that is especially true with agentic AI. Security and business leaders do not need to become engineers, but they do need first-hand familiarity with how these tools behave, where they create value and how they can be misused. The most effective leaders are already building that intuition through personal experimentation in safe, appropriate ways outside production environments.

That kind of experience matters because theoretical understanding is no substitute for practical judgement. AI is a technology shift on the scale of the internet, and leaders making strategic decisions about it need more than second-hand briefings. Would you trust a surgeon who’d only ever read about open heart surgery? The same principle applies. Theoretical understanding of AI is not a substitute for the practical judgement that comes from using it. The same principle applies here: professional curiosity builds literacy, and that literacy leads to better decisions. The goal is not shadow IT or parallel experimentation inside the enterprise; it is informed leadership rooted in first-hand understanding.

Speed Needs Guardrails

AI is reshaping financial services faster than regulators can follow, and that puts resilience squarely on the institutions deploying it. The winners will not be the firms that move fastest. They will be the ones still standing when the first AI-scale breach tears through someone who moved fast and built nothing underneath it. Speed is easy. It is never the speed that gets you. It is the sudden stop when it goes wrong.

Exit mobile version