Near-universal adoption, uncommon scale
The Cambridge Centre for Alternative Finance published its 2026 Global AI in Financial Services Report in partnership with the Inter-American Development Bank, CGAP and the Arab Monetary Fund, drawing on responses from financial institutions, AI vendors and regulatory authorities across 151 jurisdictions. Its central finding is not an adoption number but a diagnosis: an industry in mid-transition, with a significant execution gap between widespread early-stage adoption and genuine strategic change, held back by data quality, legacy infrastructure and talent.
The maturity distribution reported alongside it makes the same point. A large majority of firms are using AI at some level, but only a small share describe their deployment as transformational, a quarter or so are scaling, and the largest single group remains at the piloting stage. Surveys of US banks specifically have found a similar shape: most institutions have pilots defined, a minority have moved proofs of concept into production, and only a very small fraction report a scaled, governed programme.
There is a second finding worth sitting with. The CCAF work concludes that AI is currently being used mainly to improve execution rather than to reconfigure business models, though more mature adopters are roughly twice as likely as less mature ones to be piloting genuinely new AI-powered products. That is a useful corrective to the strategy-deck version of this topic. The realistic near-term return is doing existing work better and cheaper, and institutions that plan for that tend to get it.
None of which is an argument for waiting. It is an argument for being specific. The firms that are getting value are not the ones with the largest ambitions; they are the ones that picked workflows where the conditions for success were already present.
Where AI actually sits, function by function
Adoption is very unevenly distributed across the institution. This is roughly where things stand in 2026, based on published survey work and what shows up in practice, ordered by how established the use is rather than by how much attention it gets.
| Function | What is deployed | Maturity |
|---|---|---|
| Customer support and service | The single most common front-office application, reported by around three quarters of firms, with fintechs ahead of incumbents | Mature. Deflection and handling-time gains are well evidenced, and the failure modes are understood |
| Fraud and financial crime | Detection, anomaly and network analysis, transaction monitoring, alert triage | Mature and among the top stated priorities. Decades of model risk practice already sit behind it |
| Credit risk modelling | Scoring, portfolio analytics, early-warning signals, stress and scenario work | Established, and the most heavily supervised. Explainability constraints shape what is deployable |
| Document and back-office work | Intake, classification, extraction, spreading, reconciliation, exception queues | Fast-growing and where much of the current realised value sits, because the work is high-volume and rules-driven |
| Compliance and regulatory reporting | Obligation tracking, control testing, report preparation, policy question answering | Emerging. Value is real but adoption is slowed by the evidencing burden the outputs have to carry |
| Wealth and advisory | Meeting preparation, client reporting, portfolio commentary, onboarding documentation | Uneven. Legacy systems and suitability obligations slow deployment relative to banking |
| Internal productivity | Assistants, code, search across internal knowledge | Near-universal in exploration, hardest to measure. Widely funded, rarely attributable to a business outcome |
Two patterns come out of that list. The functions with the clearest returns are the ones where the work was already high-volume, rule-governed, and expected to leave an audit trail. The functions where adoption is slowest are the ones where an output has to be defended to a regulator or a customer, which is a constraint on deployment rather than a reason not to bother.
Internal productivity deserves separate mention because it absorbs a great deal of budget and produces the least measurable result. It is not a bad investment, but counting licences is not the same as demonstrating value, and a programme resting mainly on assistant seats will struggle at its first serious review.
Four things that separate the firms getting value
The differences between institutions that scale and institutions that stall are consistent, and none of them is about which model was chosen.
The data was ready, or the use case did not need it to be
Data quality and legacy infrastructure are the constraints named most often in the CCAF findings. The practical response is not a multi-year data programme before anything ships. It is choosing first use cases that work on documents and unstructured inputs as they actually arrive, which sidesteps the warehouse problem rather than waiting for it to be solved.
It layered onto the existing systems
Deployments that require replacing a core, an origination platform or a servicing system rarely survive contact with the budget cycle. The ones that ship read from and write to what is already running. This single choice explains more variation in outcomes than model selection does.
The output can be evidenced
In a regulated institution an output that cannot be traced is an output that has to be re-performed, which erases the saving. Citations to source, retained overrides, and retrievable versions are not compliance overhead; they are what converts review from redoing the work into checking it.
Success was defined as a business number
Model accuracy is a threshold to clear, not a result. The institutions that can defend their programmes measured cycle time, throughput per person, exception rates and rework before they started, and can therefore say what changed. Most cannot, which is why so many programmes are hard to renew.
Agentic systems are the fastest-moving part of this picture and the least settled. Published surveys put roughly two in five financial institutions using or assessing agentic AI, with a much smaller share actually running agents in production. What separates an agent from a model, and what governing one requires, is covered in AI agents for financial services, which is the companion piece to this one.
What is realistic, by institution type
Generic advice is the least useful thing in this category, because the binding constraint differs sharply by segment. What follows is a description of the landscape as of September 2026 and not legal, compliance or supervisory advice.
Large banks
Budget is not the constraint; coordination is. The largest institutions have hundreds of use cases and a small number that matter, and the reported gap between spend and demonstrated return is widest here. The realistic priority is consolidating a sprawling estate onto governed infrastructure, retiring pilots nobody uses, and being able to answer what a given system does and what it changed.
Community banks and credit unions
The constraint is capacity, not appetite. Surveys of this segment show most institutions with pilots and very few with anything scaled, and productivity tooling absorbing most of the attention. The higher-return path is usually a single document-heavy workflow in lending or onboarding, bought rather than built, layered onto the existing core. One workflow that demonstrably works beats a strategy document.
Non-bank lenders and fintechs
Consistently ahead on adoption and on the front office in particular, with fewer legacy constraints and a higher tolerance for change. The risk runs the other way: moving faster than governance, particularly where credit decisions and adverse action reasoning are involved. Speed is an advantage only while the evidence trail keeps up with it.
Wealth and asset managers
Adoption tends to lag banking, with legacy systems and suitability obligations cited as the drag. The strongest near-term cases are preparation rather than advice: meeting preparation, client reporting, onboarding documentation, and extraction from the statement and capital-call paperwork that arrives in volume before every quarter-end.
Equipment finance and specialty lenders
Small ticket, high deal count, and heavy documentation make this segment unusually well suited to document-layer automation, because the cost per file barely moves with deal size. The specific obligations that come with it are set out in equipment finance documentation and compliance automation.
What has not changed
Across every segment and every function, the same boundary holds. Approval, structure, exception decisions, adverse action reasoning, suitability, and regulatory filings stay with named people. The supervisory expectations have not moved even where the technology has, and the revised interagency model risk guidance issued in April 2026 leaves the newest systems explicitly to each institution's own framework rather than prescribing one.
- Citations on every extracted value. A figure in a recommendation should link back to the document and page it came from. Without it, review costs as much as production did.
- Overrides retained with reasons. Prior value, new value, reason, user, timestamp. A correction that vanishes has erased the evidence that anyone reviewed anything.
- Autonomy defined per workflow. Which steps proceed unattended and which do not, set against how reversible the action is rather than against a confidence score alone.
- An inventory that includes what arrived by default. Most institutions can list what they built. Fewer can list the AI features switched on inside software they already licensed.
- Vendor governance treated as your governance. Model versions, change notification, data handling, and whether your customers' documents train anyone's models. The list in SOC 2 Type II for commercial lending AI covers what a security report does not.
Where Uptiq fits
Uptiq works on the part of this picture where the returns are currently most reliable: the preparation layer of regulated workflows. Qore runs domain-trained agents for document intake and classification, extraction and financial spreading, policy and eligibility checks, credit memo drafting and post-close monitoring, across banks, credit unions, non-bank lenders, wealth management firms and equipment finance companies. Every extracted value carries a citation back to its source page, adjustments are surfaced for a person to accept or reject rather than applied silently, and each override is retained with its reason and user. The agents run alongside the existing core, origination and servicing systems through 100+ integrations, which keeps a deployment a workflow change rather than a platform migration.
How to close the gap at your own institution
The pattern that produces a defensible programme is unglamorous and has not changed much in three years.
Audit what is already running before planning anything new
Including capabilities enabled inside purchased software. This usually reframes the conversation from whether to adopt AI to how to govern what is already in production, and it is the first thing an examiner will ask for.
Choose one workflow on evidence, not on volume of complaint
Score candidates on four things: how often the work repeats, whether the rules already exist in writing, whether the output needs an audit trail anyway, and whether a mistake is recoverable. Workflows scoring on all four are where the returns have actually landed.
Buy the layer, build the differentiator
Document processing, extraction and spreading are solved categories where building in-house rarely pays. Reserve internal engineering for whatever is genuinely specific to your institution, which is usually not reading a tax return.
Baseline before, in numbers you would show a board
Elapsed time by stage, touches per file, rework rate, throughput per person. Capture them on a representative sample before anything changes, because reconstructing a baseline afterwards convinces nobody.
Expand along the same file, not into a new function
Once extraction is trusted, the next step is the thing immediately downstream of it, spreading, checking, drafting, monitoring. Each extension reuses the configuration and the governance already built, which is how a second deployment costs less than the first.
The workflow-level detail for lending sits in AI agents for commercial lending workflows, and the review discipline that has to sit over any output is in how to review AI-generated output.
Frequently asked questions
How widely is AI actually used in financial services?
Very widely at some level, and much more narrowly at scale. The Cambridge Centre for Alternative Finance's 2026 global study found a large majority of firms using AI somewhere, but only a small share describing their deployment as transformational, with the largest group still piloting. Surveys of US banks show the same shape. The headline adoption figures in this category are real but describe presence rather than scale.
What are the most common AI use cases in financial services?
Customer support is the most common front-office application, reported by around three quarters of firms in the CCAF study, with fintechs ahead of incumbents. Fraud detection and credit risk modelling lead in risk and compliance. Document-heavy back-office work, intake, extraction and spreading, is where much of the currently realised value sits, because the work is high-volume and the rules already exist.
Why do most AI programmes in financial services fail to scale?
Data quality, legacy infrastructure and talent are the constraints named most often, and none of them is solved by choosing a better model. The practical failure modes are starting with a use case that needs clean structured data nobody has, requiring a system replacement to deploy, producing output that cannot be evidenced and therefore has to be re-performed, and never capturing a baseline so the result cannot be demonstrated.
Is AI changing business models in financial services or just making them cheaper?
Mostly the latter, so far. The CCAF findings describe AI being used primarily to improve execution rather than to reconfigure business models, though more mature adopters are around twice as likely to be piloting genuinely new AI-powered products. Planning for efficiency in the near term and treating new products as a later possibility matches the evidence better than the reverse.
Where should a smaller institution start?
With one document-heavy workflow in lending or onboarding, bought rather than built, layered onto the existing core. Community banks and credit unions consistently show many pilots and little scaled deployment, and most of the attention going to productivity tooling that is hard to measure. A single workflow with a before-and-after number is worth more than a broad programme, and it is what makes the second investment easy to approve.
How is AI in financial services regulated?
Through existing obligations more than through new AI-specific rules in the US. Model risk management, fair lending, adverse action, suitability, and third-party risk all apply already. The interagency model risk guidance was revised in April 2026 and explicitly leaves generative and agentic AI outside its scope, directing institutions to their own risk management. The EU AI Act sets out obligations around logging, documentation and human oversight that are shaping expectations more broadly. How any of it applies to a given institution is a question for its own compliance and legal functions.
Adoption figures are drawn from the Cambridge Centre for Alternative Finance's 2026 Global AI in Financial Services Report and other published survey work, including vendor and advisory surveys of varying methodology and sample; figures are described qualitatively where sources differ. Regulatory descriptions reflect publicly available sources as of September 2026 and may change. Nothing here is legal, compliance, or supervisory advice; how these expectations apply to your institution should be confirmed with your own legal, compliance, and model risk functions.
Start where the evidence says it works
Tell us which document-heavy stage is consuming your team's week and we will run it on the files you actually receive, with every figure cited back to the page it came from.
