AI in banking and financial services: compliance, operations and service (2026).
Where AI is delivering for banks, lenders, fintechs and wealth firms, from KYC files and compliance monitoring to customer service, and the rules that apply when AI touches credit and customers.
Financial services was an early adopter of machine learning for fraud detection and credit scoring. The newer opportunity is different: the reading, checking and writing that sits around every customer, loan and regulation. Onboarding files, policy documents, regulatory updates, credit memos, complaints and service questions are all language work. That’s exactly what modern AI systems do well, if they’re built with the controls a regulated firm needs.
Where AI is delivering in financial services
KYC, onboarding and AML files
AI reads identity documents, company filings, ownership structures and source-of-funds evidence. It extracts what the file needs, cross-checks it and flags gaps or inconsistencies for an analyst. It also drafts the narrative for alerts and case reviews, so investigators start from a structured summary rather than a raw data dump.
Compliance monitoring and regulatory change
Assistants that answer staff questions from your own policies and procedures, with references, and systems that track regulatory publications, summarise what changed and map it to the policies affected. A compliance officer decides what to do; the system makes sure nothing is missed.
Credit and underwriting support
Drafting credit memos from financial statements, bank data and application documents, for an underwriter to review. The decision stays with a person, and the memo makes the reasoning auditable.
Customer service
Assistants that answer account, product and process questions from approved content, in the customer’s language and channel, and hand over to a person for anything sensitive, complex or a complaint.
Internal knowledge
Product terms, procedures, rate sheets and past decisions made searchable in plain language, with answers that cite the source and admit when the source is silent.
The rules that apply
- EU AI Act. AI that evaluates the creditworthiness of individuals or sets their credit score is high-risk under Annex III, with obligations from 2 December 2027 after the Digital Omnibus delay. Fraud detection is specifically excluded from that category. Customer-facing assistants must tell people they’re talking to AI now. See our EU AI Act guide.
- UK. The FCA says it won’t create extra AI rules; the Consumer Duty and the Senior Managers and Certification Regime apply to AI as they do to everything else. UK GDPR’s automated-decision safeguards, in force since 5 February 2026, apply to significant decisions such as credit. Our UK AI rules guide has the detail.
- US. Colorado’s SB 26-189 covers automated decision-making in financial and lending decisions from 1 January 2027, with notice, explanation of adverse outcomes, correction and human review. California’s CCPA rules on automated decision-making technology require compliance from 1 January 2027. Existing fair-lending and adverse-action rules still apply to any credit decision AI touches.
What a regulated firm should insist on
| Control | Why it matters |
|---|---|
| Answers only from approved sources, with citations | Customers and staff can’t be given invented terms, rates or advice |
| A full audit trail of inputs, outputs and approvals | Model risk management, regulators and complaints |
| Evaluation sets, including adversarial cases, run before every release | Evidence that changes don’t degrade accuracy or safety (see evals before features) |
| Strict data boundaries | Customer data stays in approved regions and systems, with minimal data in prompts and logs |
| Defence against manipulation | Uploaded documents and messages treated as untrusted input (prompt injection) |
| A route to a person | Complaints, vulnerable customers and any adverse decision |
Where to start
Most firms get the fastest, safest return from internal work first: KYC file preparation, alert narratives, policy question-answering and regulatory change tracking. A trained person reviews every output, the volume is high and the time saved is easy to measure. Customer-facing assistants follow once the controls have been proven internally.
In a regulated firm, the audit trail isn’t overhead. It’s what lets you use AI at all.
Questions financial firms ask
Can we use public models with customer data?
Through enterprise APIs with the right contractual terms, data residency and no training on your data, many firms do. Some keep the most sensitive work on open-weight models in their own environment. Keep the model replaceable either way.
How do we satisfy model risk management?
Treat the AI system like any other model: document its purpose and limits, validate it on a representative evaluation set, monitor it in production, and review it when it changes. A well-built system produces that evidence as it runs.
Will regulators accept AI-drafted credit memos or alert narratives?
Regulators look at the decision and who made it. A memo drafted by AI and reviewed, edited and signed by an accountable person is still that person’s work, and the audit trail shows it.
Modulus Labs AI builds compliance, onboarding and service systems for banks, lenders and fintechs, with audit trails and human review built in. Tell us about the workflow, and we’ll reply within one business day.