The readiness gap: Banking's AI ambition outruns persistent capability
This time it's different
Executives in every industry are pushed to move faster on AI, but fewer are asked to move more cautiously or safely. The risks in banking feel higher because the regulators are often right at the door and decisions involve other people's money and livelihoods. Of course, the challenges in financial services are also facing healthcare, insurance and many other industries.
Research shows the ambition-vs-readiness gap is increasing pressure in banking. A global survey of nearly 1,500 senior finance and business leaders across industries found 88% thought AI will be the most transformative force in their field within two years.¹ Meanwhile, a study of 148 financial institutions by Wolters Kluwer – a firm whose business is helping banks stay on the right side of regulators – found only about a third had already put AI to work in live operations. Of these, far fewer had a clear, funded plan for its future.² Two independent studies, run by different organizations, reach similar conclusions: pressure is growing and deployment in banking is outrunning readiness beyond a factor of three.
Agentic AI just raised the potential cost of the gap
Last year, the readiness gap was uncomfortable, since then the pressure has only increased. Banking will put AI to work, and it might proceed before data is ready or proper guardrails are established.
The Cambridge Centre for Alternative Finance's 2026 global study found 52% of financial services firms are already piloting or scaling agentic AI systems. These systems don't just predict but also act, and 81% of respondents expect agentic AI to be meaningfully achieved by 2030.³ Many external firms are pushing their AI agents but few reveal what it takes to govern them. Shadow and skunkworks AI projects, which are organic, homegrown AI efforts within the organization – but perhaps beyond proper oversight or controls – are still a real concern. Today the growth of AI agents is generating exponential growth of shadow AI.⁴
AI is moving faster than regulators
In April, the Federal Reserve, OCC and FDIC jointly issued SR 26-2 federal guidance, revising model risk management standards for banks with assets exceeding $30 billion. The new guidance explicitly excludes generative and agentic AI as too novel and fast-moving to codify. 5
In Europe, the Digital Omnibus pushed the EU AI Act deadline for high-risk systems out to December 2, 2027. 6 The EU rules are written but the enforcement clock is extended for high-risk systems for over a year. On both sides of the Atlantic, regulators just conceded they can't keep pace with the technology.
While the rules are delayed the risk is not. Accountability now sits inside organizations and most aren't ready to hit pause. Every ungoverned agent or model put in production this year is AI governance debt; like all debt, it compounds quietly until it comes due. The organizations that pay it down ahead of schedule will be the ones still moving fast when the examiners arrive.
The skills gap is a governance gap in disguise
Most readiness conversations center on data infrastructure, risk frameworks and vendor selection. Legitimate priorities, to be sure. However, the governance operating model: the human layer, judgment, literacy and the ability to walk back an AI issue or audit is equally foundational and far harder. You can buy a model. You cannot buy the processes and institutional knowledge needed to provide enterprise governance for AI and the assets AI is dependent on.
What closing the gap actually requires
One semantic model will rule above the many. Every platform now ships its own semantic model, specialized for that platform. The speed of change can't absorb the friction of siloed governance. What's needed is a single enterprise lens across data, AI, risk, legal and the operating units: a governing semantic model that sits above the data platforms and niche tools. This layer is where transparency lives, and provides solid mooring to build a long-term foundation for a financial institution’s AI ambitions.
Governance should be embedded in the workflow, not bolted on. Risk is created in daily decisions, so governance must live in the context where decisions are made. It cannot be a separate checkpoint; it must be part of how AI is designed, approved, deployed, monitored, tested, validated and changed.
Complete an honest capability assessment at your institution.
Most organizations are over-indexing on deployment and under-investing in people and training. A frank audit of where generative AI literacy actually sits; across risk, finance, compliance and technology must precede any serious scaling plan. More organizations will stand up permanent Value Leader roles to measure and drive the business value AI delivers, because value that isn't demonstrated is investment that isn't defended.
A shared, evidence-based definition of what AI-ready means across departments is required for progress. For a business unit, ready means a use case works. For risk, ready means a clear line of sight to explainability, auditability and accountability, which is often the same evidence-based approach regulators expect. Aligning on a proper cross-department definition of what greenlights a model for production before models and agents go live isn't diligence for its own sake, it is what keeps speed from becoming exposure.
AI Governance readiness is a competitive advantage, not just an expense
Solid AI Governance readiness plays offense, not just defense. Most institutions have deployed AI; few can say it has changed their competitive position. The difference isn't budget or ambition, it's the difference between those who sweated the process and training prework, and those that rushed through the launch. Banks that will emerge successful put one governance layer above their business and data silos, and build it into daily decisions to confirm results and trust before regulators expect them. Their governance debt is paid down.
All industries face a challenge to bring the benefits and efficiencies of AI to their business processes and customers. Banking may simply just be answering these questions before other industries, which means there is much for other industries to learn from their deployments. Whatever your industry, the gap between ambition and execution closes the same way everywhere: not with a bigger AI budget, but with the discipline to govern at the speed you deploy. We suggest you start before the bill arrives.
Sources
1. AICPA & CIMA, Future-Ready Finance Survey (1,446 senior finance leaders).
2. Wolters Kluwer, Q1 2026 Banking Compliance AI Trend Report. wolterskluwer.com/en/news/survey-indicates-financial-institutions-that-align-with-regulators-are-able-to-adopt-ai-successfully
3. Cambridge Centre for Alternative Finance, 2026 Global AI in Financial Services Report. jbs.cam.ac.uk/faculty-research/centres/alternative-finance/publications/2026-global-ai-in-financial-services-report/
4. https://www.helpnetsecurity.com/2026/04/14/ai-adoption-safety-transparency-report/
5. SR 26-2 (Federal Reserve, OCC, FDIC, April 2026) and Treasury-supported Financial Services AI Risk Management Framework (Cyber Risk Institute, February 2026).
6. Council of the EU, Digital Omnibus final approval, June 29, 2026. freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber
Related articles
Keep up with the latest from Collibra
I would like to get updates about the latest Collibra content, events and more.
Thanks for signing up
You'll begin receiving educational materials and invitations to network with our community soon.

