Field report 03 · September 2026
Financial Institutions AI 2026: from controlled access to accountable action
A practical decision guide for bank, credit union, insurer, payments, wealth, risk, compliance, operations, and technology leaders—with regulatory data, named deployments, workflow economics, customer-harm controls, and a 90-day plan for assigning decision rights.
Open the 18-page PDFResearch cutoff: 18 September 2026. No form wall. PDF opens in a new window.

Measured signals
The numbers—and who was counted
75%
Already using AI
Share of 118 firms in the Bank of England/FCA 2024 survey; a UK regulatory sample, not a global market estimate.
33%
Third-party use cases
Share of reported AI use cases implemented by a third party, up from 17% in the regulators’ 2022 survey.
2%
Fully autonomous
Share of reported use cases with fully autonomous decision-making. Broad adoption does not mean broad autonomy.
The explanation is an output
Credit and other adverse decisions need a specific, accurate reason tied to the factors actually used. A score or generic checklist is not enough.
Authority matters more than fluency
Retrieve, draft, recommend, and execute are different permissions. Each step changes the evidence, record, review, and customer-remediation burden.
Third-party concentration is operating risk
A vendor model, cloud, data source, or hidden feature can change many workflows at once. Inventory and change rights belong in the business case.
Queue capacity belongs in the model
A better fraud threshold can still fail if false positives swamp analysts. The report prices review, correction, redress, and exception work.
The regulatory signal
AI use is broad; accountable autonomy remains narrow
The same Bank of England/FCA survey found that 55% of use cases had some automated decision-making, yet only 2% were fully autonomous. It also found 46% of respondent firms had only a partial understanding of the AI technologies they used. The practical response is not to ban AI; it is to document who may decide, which version was used, where the information came from, and how a customer can challenge or correct the result.
Named operator cases
The result, the limitation, and the lesson
Morgan Stanley
The firm reported 98% adoption across financial-advisor teams for an internal assistant that answers from approved sources, then added meeting notes and customer-record drafting with client consent.
Read with
The public evidence is a company disclosure, not an independent estimate of productivity, accuracy, complaints, or client outcomes.
Start with approved source material and reviewed work products before recommendations or execution.
JPMorganChase
LLM Suite reached more than 200,000 employees in a controlled environment, creating a common access and development layer.
Read with
Seat and use-case counts do not show sustained adoption, portfolio economics, or the distribution of failures.
A central platform can reduce shadow use, but every workflow still needs its own owner and evidence.
Bank of America Erica
The bank reported more than 3 billion interactions, nearly 50 million users, a 700-response library, and more than 75,000 updates.
Read with
These are company-reported service and engagement measures without independent customer-outcome analysis.
A limited set of customer requests, maintained answers, and a designed human handoff scale better than unrestricted improvisation.
Inside the field edition
Evidence and tools for a live decision
Every chart distinguishes measured evidence, organization-reported claims, and illustrative economics. The final pages are worksheets, not a closing sales pitch.
- Regulatory adoption and business-significance data
- Six-part financial-institution AI market map
- Levels of AI decision authority—from finding information to taking action
- Three named deployment case studies
- Evidence comparison table
- Worked complaint-triage economics
- Vendor evidence checklist for regulatory review
- 90-day trial that starts without affecting live work
- Customer-conduct and resilience scorecard
- Eight common failure patterns
- Adverse-action incident scenario exercise
- Methods and linked source list
A practical operating path
From baseline to a defensible scale decision
01
Baseline the decision
Sample cycle time, quality, overrides, complaints, losses, queue age, and customer segments before introducing the system.
02
Declare authority
Write down permitted data, users, outputs, excluded populations, and the highest action the system may take.
03
Shadow current work
Compare recommendations and reasons without changing customer outcomes. Measure queue load and disagreement.
04
Expose reviewed output
Train users, capture edits and overrides, and preserve the source behind any customer-facing statement.
05
Scale or stop by workflow
Do not average away harm. Require stable value, specific explanations, staffed exceptions, and a tested rollback.
Common questions
What operators usually need to know next
What is the best first generative-AI use case for a financial institution?
An internal knowledge assistant that uses only approved sources, or a reviewed drafting process, is usually easier to control than underwriting, personalized advice, transaction execution, or complaint closure. The first use case should already have an owner, a source of truth, a reviewer, and measurable work.
Can a bank use a black-box model for credit decisions?
Complexity does not remove the obligation to provide accurate, specific principal reasons for adverse action. The institution also needs fair-lending, model-risk, data, and operational controls appropriate to the use.
How should a bank measure AI ROI?
Measure incremental cycle time, quality, losses, approvals, complaints, correction work, exception capacity, redress, and technology operations against a defined baseline. Do not treat generated volume or user access as realized value.
What should stop an AI pilot?
Examples include inaccurate customer reasons, a meaningful decline in results for a customer group, data leaving the approved system, an uncontrolled vendor change, a customer-record update that cannot be reversed, or an exception queue beyond the institution’s capacity.
Put the report next to the pilot plan
No form wall. The PDF always opens in a new window.