Generative AI in Banking: Balancing innovation, risk, and operational readiness

Generative AI (GenAI) is moving quickly into banking. According to a 2025 survey by McKinsey, 52% of financial institutions surveyed already consider GenAI a priority, while another 39% are interested but have not yet made it a top priority.

As adoption grows, banks need to think carefully about what AI agents can access, which identities it uses, what actions it can take, and whether those activities can be traced when something goes wrong. These questions become more important as GenAI moves from pilots into day-to-day banking operations.

🔍 Key takeaways:
  • Generative AI (GenAI) is already being used across banking for customer service, fraud investigation, document review, IT workflows, and risk and compliance support.

  • The main challenges are not limited to model accuracy; banks also need to manage access, sensitive data, privileged activity, visibility, and accountability.

  • Moving from pilot to production requires strong operational controls around identity, monitoring, auditability, data protection, and human oversight.

Where is GenAI being adopted in banking?  

Banks are testing and adopting GenAI across a growing range of functions. Common use cases include customer service, document summarization, fraud investigation, software development, internal knowledge search, and support for risk and compliance teams.

Some of these use cases are relatively contained, such as helping employees summarize information. Others are more complex because they connect AI agents to internal data, applications, APIs, and business workflows.

The risk profile changes once GenAI in business contexts moves beyond generating answers and starts interacting with systems or supporting actions that can affect customers, employees, or operations.

Why does GenAI create unique risks for banks?  

Banks already operate under strict expectations around data protection, access control, accuracy, and accountability. GenAI adds another layer of complexity because its outputs are probabilistic, its behavior can be difficult to explain, and it may interact with sensitive data or connected systems.

The risks are not limited to inaccurate answers. AI systems can expose sensitive information, inherit excessive permissions, be manipulated through malicious inputs, or make it harder to reconstruct how a decision or action was reached.

McKinsey also points to concerns such as data security breaches, model hallucinations, validation issues, model and data bias, latency, data risk, and compliance obligations as factors slowing GenAI adoption in banking. In 2025, the Vice Chair for Supervision for the Federal Reserve, highlighted risks around hallucinations, inconsistent responses, sensitive-data exposure, and limited explainability, all of which can be difficult to reconcile with banking requirements for precise, controlled, and auditable decisions.

What are the risks of GenAI in banking?  

GenAI introduces a different kind of risk when it begins working with customer data, internal applications, and business workflows. In banking, the concern is less about whether GenAI occasionally gets an answer wrong and more about what happens when that error reaches a sensitive system or influences a real decision.

The main risks include:

  • Sensitive data exposure: Banks hold large volumes of personal, financial, and transaction data, often across many systems. Once GenAI is connected to those sources, weak access controls or poorly configured integrations can expose information to users, applications, or models that were never meant to see it.

  • Unreliable or misleading outputs: GenAI can produce confident answers without a reliable basis for them. That may be manageable in low-risk tasks, but it becomes much more serious when GenAI is used in fraud investigations, compliance work, customer communication, or decisions that require accuracy and consistency.

  • Excessive access and privilege: A GenAI tool may operate through an employee account, service account, API, or machine identity. If that identity has broad permissions, the AI's agent may inherit the same reach. A simple request can therefore become a much larger security problem when the system behind it has access to sensitive data or critical applications.

  • Manipulation through malicious input: Prompt injection can influence how an GenAI system interprets instructions or uses connected information. The impact becomes more significant when AI can retrieve internal data, call APIs, or trigger actions in other systems.

  • Limited visibility and accountability: GenAI-assisted activity may involve several users, services, models, and applications before a final action takes place. Without clear logs and ownership, it becomes difficult to reconstruct what happened, which information shaped the outcome, and who approved the final decision.

What are the main challenges of adopting GenAI in banking?  

Adopting GenAI in banking is not simply a matter of choosing a model and connecting it to existing systems. Banks often have to work through legacy infrastructure, fragmented data, regulatory requirements, and complex approval processes before a GenAI use case can move beyond a pilot.

  • Legacy systems and integration complexity: Many banks still rely on a mix of older core systems and newer digital platforms. Connecting GenAI to these environments can be difficult, especially when data, applications, and APIs were not designed to work together. 

  • Fragmented and inconsistent data: GenAI depends heavily on the quality of the information it receives. When customer, transaction, risk, and operational data is spread across different systems or maintained in inconsistent formats, the output becomes harder to trust.

  • Governance and regulatory uncertainty: Banks need clear rules around where GenAI can be used, what data it can access, and when human approval is required. These decisions can become complicated when internal policies, privacy obligations, model risk, and regulatory expectations all overlap.

  • Skills and ownership gaps: GenAI projects often involve IT, security, data, risk, compliance, and business teams at the same time. Without clear ownership, it can be difficult to decide who is responsible for approving use cases, reviewing risks, monitoring activity, or responding when something goes wrong.

  • Proving business value: GenAI pilots are relatively easy to start, but scaling them across a bank is more expensive and complex. Teams need to show that a use case improves productivity, customer experience, risk management, or operational efficiency enough to justify the cost and effort involved.

What operational controls do banks need for GenAI?  

As GenAI becomes more connected to banking systems and workflows, banks need clear controls around access, visibility, and accountability. These controls help limit what GenAI-connected identities can reach and make their activity easier to trace when something goes wrong.

How can banks control access to GenAI-connected systems?  

Banks need to know which users, service accounts, machine identities, or AI agents are allowed to access specific systems and what they are permitted to do. Least privilege is a good starting point. GenAI-connected identities should only have access to the data and functions required for a specific task, particularly when privileged accounts or sensitive systems are involved.

Service accounts, API permissions, and other non-human identities also need regular review. These accounts can easily become overlooked even though they may provide broad access across several systems.

How can banks monitor and audit GenAI activity?  

Access controls need to be supported by visibility. Banks should be able to see how GenAI interacts with applications, data, APIs, and user accounts over time. Authentication events, privileged access, application changes, API activity, and data access all provide useful context. During an investigation, teams should be able to trace who initiated an action, which identity executed it, what data was accessed, and whether human approval was involved.

Clear audit trails also make it easier to support incident investigations and explain how an GenAI-assisted action unfolded during internal or regulatory review.

How should banks manage privileged GenAI actions?  

Not every GenAI-assisted action carries the same level of risk. Tasks involving privileged access, system changes, sensitive data, or customer-impacting decisions deserve stronger controls.

Banks can require additional approval for high-risk actions, restrict privileged sessions, and separate routine GenAI assistance from activities that can directly change critical systems.

Why does human oversight still matter?  

GenAI may help analyze information or recommend a next step, but accountability still sits with the organization. For decisions involving fraud, compliance, access changes, or customer impact, banks need clear points where human review and approval are required.

For example, actions that affect customer access, fraud escalation, or privileged system changes should have a defined human approval point. The level of oversight should reflect the potential impact of the action, rather than applying the same approval process to every GenAI use case.

What are the benefits of GenAI in banking?  

GenAI can help banks process information faster, reduce repetitive work, and make internal knowledge easier to use. Its value is especially clear in areas where employees need to review large volumes of documents, search across fragmented information, or respond quickly to customer and operational requests.

Some of the most practical benefits include:

  • Faster customer support: GenAI assistants help service teams find relevant information, summarize customer history, and prepare responses. Employees can spend less time searching across systems and more time handling the interaction itself.

  • More efficient document review: Banks work with large volumes of policies, reports, contracts, regulatory documents, and case files. GenAI can summarize lengthy material, extract key details, and make relevant information easier to find during reviews or investigations.

  • Better support for fraud and risk teams: Fraud investigations often require analysts to piece together information from alerts, transaction records, case notes, and other sources. GenAI can help organize and summarize that information before analysts move into deeper investigation.

  • Faster software and IT workflows: Developers and IT teams can use GenAI to explain errors, draft scripts, summarize logs, create technical documentation, and assist with troubleshooting. These tasks often take considerable time in banking environments with complex applications and infrastructure.

  • Quicker analysis and reporting: Risk, compliance, operations, and management teams regularly work with large amounts of unstructured information. GenAI can help summarize findings, prepare initial reports, and highlight areas that deserve closer review.

How ManageEngine supports the IT foundations around GenAI in banking  

As banks bring GenAI into more workflows, the surrounding IT environment becomes just as important as the GenAI itself. Identity, access, data protection, security monitoring, and infrastructure reliability all influence how safely these systems can be used.

ManageEngine solutions can support several parts of that foundation:

  • Control access to connected systems: Identity and privileged access controls can help banks manage who has access to sensitive systems, review permissions, strengthen authentication, and place tighter controls around privileged accounts.

  • Improve visibility into security activity: Centralized logging and SIEM give security teams a broader view of authentication events, system changes, suspicious behavior, and other activity across the environment. That visibility becomes useful when investigating incidents involving GenAI-enabled applications or workflows.

  • Protect sensitive financial data: Data security capabilities can help banks monitor access to sensitive information, reduce unnecessary exposure, and strengthen protection around the data employees and applications rely on.

  • Keep supporting systems reliable: Application and infrastructure monitoring can help IT teams track availability and performance across the systems that support GenAI-enabled services and identify issues before they affect customer-facing or internal banking operations.

These capabilities do not replace GenAI governance or model-level controls. They strengthen the IT and security environment around GenAI, giving banks better visibility and control as adoption expands.

Explore ManageEngine solutions for financial services.