PRODCOB

AI at Scale in Banking: The Decision Supply Chain

Why scaling AI in banking depends on trusted data, identity, fraud controls, and auditable evidence moving together not on the model alone.

Banks are no longer debating whether artificial intelligence belongs in financial services.

That debate is largely over.

The harder question is whether banks can move AI from controlled demonstrations, employee copilots and isolated models into the systems that actually make consequential decisions payments, fraud intervention, customer authentication, servicing, underwriting, operations and controls without creating a level of operational uncertainty that the institution cannot defend.

That is a very different problem.

It is tempting to describe it as an AI problem. I do not think it is.

The more useful mental model is a decision supply chain.

A banking decision begins with data. It passes through identity, context, rules, models and policy. It results in an action. And eventually someone operations, risk, audit, compliance, a customer, or a regulator may ask why that action occurred.

If the bank cannot reconstruct that chain, the AI may be sophisticated, but the operating model is not industrialized.

That distinction matters because three transformations are now colliding:

Industrializing AI at scale.

Defending identity and trust against AI-enabled fraud.

Replacing fragmented, batch-oriented operational data flows with faster decisioning.

Banks often manage these as separate programs.

Increasingly, they are the same program viewed from different angles.

Infographic: key statistics on AI at scale in banking, including fraud losses, FedNow real-time payments growth, staffing shifts at Ally and TD, and the $30B AI risk threshold from Fed/OCC/FDIC guidance
Sources: FTC, Federal Reserve, FedNow, Ally, TD Bank, OSFI, and Fed/OCC/FDIC interagency guidance. See article for full citations.

The Current State: AI Adoption Is Ahead of AI Industrialization

Financial institutions are clearly moving beyond experimentation.

But the public evidence suggests that most institutions are still expanding AI cautiously rather than handing over material decisions to autonomous systems.

The Bank of Canada’s 2026 Financial System Survey is particularly useful because it cuts through some of the market excitement. Nearly all respondents reported using AI, but most characterized their use as limited or moderate. AI was commonly being applied to information gathering, analysis, document workflows and internal operations. Respondents generally did not report using AI to replace human judgment in critical decisions because of the potential financial, legal and reputational consequences. They also identified data quality, privacy, cybersecurity, model risk, explainability and concentration among cloud and AI providers as concerns.

That feels much closer to the reality inside regulated institutions than the narrative that autonomous AI is about to run the bank.

Several banks illustrate what industrialization actually looks like.

Ally expanded its proprietary Ally.ai platform across more than 10,000 employees in 2025 after beginning with controlled use cases. The bank reported mandatory generative-AI risk and controls training, model-risk review, monitoring and controls incorporated alongside development. Its call-summarization capability had been integrated into workflows supporting approximately five million customer calls.

Capital One describes standardized cloud platforms for data management, model development and operationalization as foundational to its AI strategy. Its current AI work includes graph machine learning for fraud, retrieval systems, recommendation systems and agentic experimentation rather than treating LLM access itself as the differentiator.

Scotiabank provides an unusually clear public description of the architecture behind its strategy. Scotia Intelligence combines Navigator, its employee-facing assisted-AI capability; Harbour, its centralized data platform; and Lighthouse, an AI delivery platform and control plane through which developers access models and build agents. Security organizations establish the guardrails around that environment. Scotiabank has also publicly said it is not currently allowing fully autonomous agents to make decisions without human involvement.

TD has taken another variation of the same path. Its 2025 annual report described more than 2,500 AI and data scientists, engineers and specialists, alongside cloud-data modernization, internal AI assistants, automated decisioning and a stated ambition to generate $1 billion in value from its AI strategy. In July 2026, TD also published enterprise Responsible AI Principles covering accountability, fairness, explainability, data use, reliability, quality and security across the lifecycle.

Different banks. Different architectures.

But the pattern is remarkably consistent.

The institutions trying to scale AI are simultaneously investing in data platforms, governance, reusable AI infrastructure, security controls and workforce operating models.

That is industrialization.

Deploying another model is not.

The Regulatory Direction Is Becoming More Risk-Based, Not Less Serious

There is an important regulatory development in the United States that technology leaders should understand carefully.

In April 2026, the Federal Reserve, OCC and FDIC replaced the longstanding SR 11-7 model-risk guidance with revised risk-based model-risk-management guidance. The revised guidance is expected to be most relevant to banking organizations above $30 billion in assets and emphasizes proportionality based on the institution’s model-risk profile.

Notably, generative AI and agentic AI are explicitly outside the scope of that particular model-risk guidance because of their rapidly evolving nature.

That should not be interpreted as generative AI being outside risk management.

The Federal Reserve explicitly notes that banks’ other governance and risk-management practices should determine appropriate controls over tools and systems that fall outside the formal model guidance.

Canada is taking a somewhat different route.

OSFI’s revised Guideline E-23, effective May 1, 2027, explicitly encompasses AI and machine-learning techniques within its broader approach to model risk. It expects institutions to identify models, maintain inventories, determine risk ratings, document dependencies and data sources, monitor models through their lifecycle, and account for externally supplied models as well.

The details differ.

The direction does not.

Regulators increasingly expect institutions to know what they are operating, why it is appropriate, who owns the risk, what dependencies exist and whether the outcome can be monitored.

That maps directly to the decision supply chain.

Fraud, Identity and Trust: AI Changes the Economics of Attack

The second transformation is less comfortable.

AI improves banking productivity.

It also improves criminal productivity.

A bank may use generative AI to summarize a servicing call. A criminal can use the same class of technology to generate phishing campaigns, synthesize documents, clone voices or construct convincing identities at scale.

Federal Reserve Governor Michael Barr warned in 2025 that deepfakes could effectively reproduce an individual’s identity rather than merely forge a credential. He argued that banks would need increasingly sophisticated combinations of authentication, transaction monitoring, voice analysis, facial recognition, behavioral biometrics and other signals.

The numbers help explain the concern.

The Federal Trade Commission reported approximately $16 billion in total reported fraud losses in 2025, around 25% higher than 2024. Imposter scams alone accounted for approximately $3.5 billion in reported losses. Bank impersonation was a major component of business impersonation losses.

Federal Reserve Financial Services has separately highlighted the growing difficulty of new-account fraud as criminals combine compromised personally identifiable information, synthetic identities and generative AI.

This changes how banks should think about identity.

Historically, identity was frequently treated as an onboarding problem.

Verify the customer. Establish credentials. Authenticate the session.

That remains necessary.

It is increasingly insufficient.

In an AI-enabled fraud environment, identity becomes a continuously changing confidence assessment.

Who is requesting the transaction?

From what device?

Is the behavior consistent?

Was the beneficiary recently created?

What relationship exists between accounts?

What network signals are available?

Does the transaction resemble previous behavior?

Was the customer socially engineered even though authentication technically succeeded?

That last question is particularly uncomfortable.

A perfectly authenticated customer can still authorize a fraudulent transaction.

Authentication answers whether credentials are valid.

It does not always answer whether the customer’s intent is legitimate.

Instant Payments Make That Distinction More Important

Real-time payments compress the time available to detect and stop fraud.

In the United States, FedNow allows participating institutions to move funds within seconds, continuously, 24 hours a day. By the second quarter of 2026, the service processed almost 5 million settled payments representing approximately $275 billion, according to Federal Reserve Financial Services statistics.

As adoption increases, fraud controls must operate increasingly close to the decision itself.

That is why FedNow’s expanding risk capabilities matter. In April 2026, Federal Reserve Financial Services introduced a network intelligence API that provides participating institutions with receiver-account information observed across the service before an instant payment is sent.

Canada’s Real-Time Rail provides another useful signal about where payment architecture is moving.

The RTR is scheduled for a phased launch beginning in Q4 2026. Payments Canada is building centralized fraud services into the infrastructure, including confirmation of payee, a real-time transaction safety score, fraud-risk information and ecosystem-level fraud reporting. Industry solution-assurance testing was underway by July 2026.

There is a broader design lesson here.

Faster payments require faster trust decisions.

And faster trust decisions require data to reach the decision point before the transaction does.

That is where fraud, AI and data architecture converge.

The Banking Backbone Problem

Most large banks do not lack data.

They have enormous amounts of it.

The difficulty is getting the right data, with the right meaning, entitlement and quality, to the right decision service at the right time.

Years of mergers, product-specific platforms, regulatory programs and technology transformations leave institutions with predictable complexity: multiple customer identifiers; duplicate reference data; batch interfaces; mainframe systems; point-to-point integrations; separate fraud platforms; separate servicing platforms; separate data warehouses; different definitions of the same business entity; and reconciliation processes that exist partly because nobody completely trusts the system upstream.

This is where another popular assumption fails.

The answer is not simply to make everything real time.

That can make the environment worse.

“Real Time” Is Not a Target Architecture

There are decisions where milliseconds or seconds matter.

Card authorization is an obvious example.

Fraud scoring for an instant payment may need to occur in the transaction path.

Authentication risk may need to change during a session.

Those are genuinely time-sensitive.

Other activities need fresh information but not sub-second processing.

Operations teams may need new events within seconds or minutes. Customer-service applications may need recent changes quickly. Fraud investigators may need updated relationships or network intelligence as cases evolve.

Then there are processes where deterministic completeness matters more than immediacy.

Financial reconciliation. Regulatory reporting. Ledger close. Certain control attestations. Historical aggregation.

Making those systems streaming simply because streaming technology exists introduces complexity without creating equivalent business value.

The better target state is decision-time data.

Make information available at the speed required by the decision consuming it.

No faster merely for architectural elegance.

No slower because legacy interfaces happen to operate overnight.

What the Decision Supply Chain Looks Like

In a mature environment, operational transactions remain anchored in authoritative systems of record.

Changes are exposed through APIs, change-data-capture mechanisms or domain events rather than repeatedly copied through bespoke interfaces.

Those events feed governed data products with explicit ownership and common semantics.

Streaming capabilities serve the use cases that genuinely require immediacy. Batch pipelines remain where completeness, efficiency or reconciliation requirements make them appropriate.

Identity, device, customer, transaction, fraud and behavioral signals become available to decision services through controlled interfaces.

Rules engines, traditional machine-learning models, graph analytics and generative or agentic systems consume that information according to their use case.

A policy layer determines what the system is permitted to do.

Higher-risk actions may require human authorization.

Actions generate new events.

And those events include enough information to reconstruct the decision later: data version, model or rule version, policy applied, confidence, override, approver and final outcome.

That final component is frequently neglected.

Banks spend enormous effort governing inputs while treating evidence as something to reconstruct afterward.

At scale, evidence should be a product of execution.

If the bank must manually reconstruct how a consequential AI-assisted decision happened six months later, the control architecture is already too weak.

Why Apparently Sensible AI Programs Fail

Many AI programs start by collecting use cases.

Every business unit submits ideas.

A central committee prioritizes them.

A platform team acquires models.

Governance establishes review processes.

Teams run pilots.

The bank announces dozens or hundreds of AI initiatives.

Activity increases rapidly.

Industrialization often does not.

The failure is subtle.

The organization optimizes for use-case throughput rather than reusable decision infrastructure.

Every new use case discovers the same missing capabilities: data access; customer identity resolution; document ingestion; entitlements; model routing; prompt filtering; logging; evaluation; human approval; exception handling; monitoring; third-party controls; cost management; and audit evidence.

Teams solve them locally.

The next team solves them again.

Eventually, the bank has an AI estate that resembles the integration estate it spent the previous decade trying to simplify.

The technology changed.

The operating mistake did not.

The Opportunity Is Much Larger Than Generative AI

None of this argues for moving slowly.

The opportunity is significant precisely because AI can now act across parts of the bank that traditional automation struggled to handle.

Unstructured documents can be interpreted. Investigations can be prioritized. Complex data can be summarized. Software can be generated and tested. Policies can be searched contextually. Customer interactions can be personalized. Fraud networks can be analyzed through graph relationships. Operational anomalies can be detected earlier. Controls can move from periodic evidence collection toward continuous monitoring. And humans can concentrate on exceptions rather than processing every case identically.

There are already useful examples.

Capital One reported in 2026 that its DataAgents approach reduced one particular analysis process from an estimated nine months to ten days. Importantly, its own engineering account also documents AI-generated mistakes incorrect field casing, references to nonexistent columns and excessive confidence which were caught during human validation. The company calculated an 18-to-27-times speed improvement after that validation was included.

That is a more useful AI case study than a perfect demonstration.

The AI was not trustworthy because it never made mistakes.

The process was trustworthy because the operating model expected mistakes and detected them before production.

That distinction is fundamental.

How I Would Approach Industrialization

I would not begin with an enterprise objective such as “deploy agentic AI.”

That describes technology, not an outcome.

I would select a small number of consequential decision journeys where the current economics or risk are visibly broken.

Fraud intervention. Account-opening investigation. Payment exception handling. Customer servicing. Control testing. AML investigation support.

Choose journeys where success can be measured in operating cost, cycle time, losses, false positives, customer friction or control effectiveness.

Then trace the decision supply chain backward.

What information drove the decision? Which source owns it? How current must it be? How is identity established? Which rules apply? Which model contributes? What external providers are involved? When is human judgment required? What evidence must survive? What happens if any component is unavailable?

That exercise usually exposes the architecture that actually needs investment.

Not the architecture presented in the AI strategy deck.

A Practical 24-Month Implementation Path

The first 90 days: establish the truth

Do not spend the first quarter designing an enterprise AI architecture in isolation.

Select two or three high-value decision journeys and map their complete lineage from source data through outcome.

Establish the inventory of models, AI systems, agents, data products, material rules, third parties and decision owners involved.

Define baseline measures before changing anything: decision latency, manual touch rate, false-positive rate, exception volume, customer abandonment, fraud loss, rework, availability and evidence completeness.

Assign a business owner for the decision not merely a technology owner for the model.

At the same time, establish minimum reusable controls around model access, identity, data entitlements, prompt and output logging, evaluation, monitoring and human escalation.

The first milestone should not be “AI deployed.”

It should be one decision journey that is measurable and reconstructable end to end.

Three to six months: create reusable infrastructure

Now invest below the use case.

Introduce or extend CDC and event interfaces around the necessary operational systems.

Create governed data products around the entities the decisions repeatedly require.

Separate AI applications from individual model providers through controlled gateways where practical.

Centralize policy enforcement, model access, observability and cost measurement.

Connect fraud and identity signals rather than allowing each channel to build its own view of trust.

Introduce automated reconciliation between streaming decisions and authoritative systems.

And require high-risk use cases to demonstrate replay: can the institution reproduce the relevant inputs and explain why the system behaved as it did?

Six to twelve months: scale patterns, not pilots

The temptation here will be to add dozens of unrelated AI applications.

Resist it.

Expand into adjacent decision journeys that reuse the same data products, identity services, AI control plane, monitoring and evidence architecture.

Automate evaluation and control testing.

Measure model drift and data drift separately.

Track human overrides.

Measure false positives and false negatives.

Test kill switches.

Test degraded operating modes when the model, vendor or cloud service is unavailable.

Treat third-party model concentration and portability as architectural risks rather than procurement issues.

Twelve to twenty-four months: introduce bounded autonomy

Only after the institution understands how systems behave under normal and abnormal conditions should higher levels of autonomous action become attractive.

Autonomy should expand according to consequence.

An internal agent creating a draft document is not equivalent to an agent moving customer money.

A coding assistant is not equivalent to a credit-decision system.

A fraud-investigation agent recommending cases is not equivalent to an agent freezing accounts without review.

The question should not be:

Can the agent perform the task?

It should be:

What is the maximum consequence if it performs the task incorrectly, and can we detect, stop and recover from that outcome?

That is a risk question rather than an AI question.

Which is exactly why banks are equipped to answer it.

What the Evidence Is Telling Us

Across the United States and Canada, the public evidence increasingly points in the same direction.

AI adoption is accelerating, but human judgment remains prominent for material decisions.

Banks that are moving toward scale are building centralized data capabilities, reusable AI platforms and control planes rather than distributing unrestricted model access.

Regulators are moving toward risk-proportionate governance, but accountability is not disappearing.

Fraud is becoming increasingly identity-centric and AI-enabled.

Instant payments are reducing the time between decision and settlement, forcing risk intelligence closer to the transaction.

And AI’s value increasingly depends on the quality, accessibility and governance of the data surrounding it rather than the model alone.

This is why I believe industrializing AI, modernizing banking data and rebuilding identity and fraud controls cannot remain separate transformation agendas.

They converge at the same place: the decision.

The Executive Question Has Changed

A few years ago, leadership teams were asking:

What can AI do for the bank?

That was a reasonable question for an emerging technology.

It is no longer sufficient.

The more consequential questions now sound different.

Can we identify the decisions where AI genuinely improves economics or risk? Can the data arrive with sufficient quality and speed? Can we establish who or what is acting? Can the system distinguish legitimate intent from technically valid authentication? Can policy constrain what an AI system is allowed to do? Can humans intervene before consequences become irreversible? Can operations recover if the AI dependency disappears? Can risk and audit reconstruct what happened without interviewing six engineering teams? And can we scale that capability without rebuilding the same controls for every use case?

Those are not AI questions.

They are questions about whether the bank has built a reliable decision supply chain.

The institutions that solve that problem will not necessarily be the banks using the most AI.

They will be the banks capable of putting AI into increasingly consequential decisions without losing control of how those decisions are made.

That is the difference between adopting artificial intelligence and industrializing it.

Executive Takeaway

The mistake is treating AI scale, fraud modernization and real-time data as three transformation programs.

They are becoming one operating capability.

Trusted data establishes the facts. Identity establishes who is acting. Analytics and AI establish context and recommendations. Policy determines what is permitted. Humans retain accountability where consequences justify it. Operational systems execute. And evidence records what happened.

When those elements operate as one decision supply chain, banks can move faster without asking risk functions to reconstruct control after the fact.

Until then, adding more AI may increase activity.

It will not necessarily increase institutional capability.


This article reflects the author’s analysis of publicly available information and is intended for educational and professional discussion purposes. It does not represent the views of any employer or financial institution and should not be interpreted as legal, regulatory, investment, financial or compliance advice. Regulatory requirements and supervisory expectations vary by jurisdiction, institution and use case and should be evaluated with appropriate legal, risk and compliance professionals.