From productivity tools
to operating-model
reinvention.
Generative and agentic AI now sit on top of an IT function that regulators already supervise tightly. The question is no longer whether AI can accelerate a developer or summarize a ticket, but whether IT can redesign its workflows, operating model, and controls — and serve as the safe backbone for the whole enterprise's AI adoption. The evidence from 2024–2026 is that a minority of firms are achieving genuine redesign while most remain in a productivity-tool phase.
Three positions this report defends.
IT functions treating AI as a productivity overlay capture some cost benefit but no durable advantage. The functions pulling ahead redesign the work — and in financial services the regulatory floor is rising fast, with a sector-specific control framework now in force.
IT plays two roles at once.
It is both an adopter of AI inside its own work and the backbone that lets every other function adopt AI safely — supplying the data platforms, identity, model governance, and security controls. A firm whose IT house is not in order cannot govern AI elsewhere.
Reshape, don't replace.
The strongest results — JPMorgan's LLM Suite, Morgan Stanley's AI@MS Assistant, Bank of America's Erica, Citi's developer rollout, Goldman's coding platform — frame AI as augmentation. Klarna's customer-service reversal is the cautionary counter-example.
The regulatory floor moved in 2025–26.
The Treasury/CRI Financial Services AI RMF (230 controls), the NYDFS third-party-provider letter, amended Reg S-P, and SR 11-7 applied to LLMs have redrawn the lines. Most firms have not yet updated their controls to match.
A vanguard, a middle, and a long tail.
Adoption is stratified. A small vanguard of global banks and asset managers has moved beyond pilots to enterprise scale; an expanding middle tier is hardening governance and data; a long tail consumes AI through vendors. The binding constraint everywhere is data quality, not models.
Global institutions with dedicated AI teams and enterprise data infrastructure — JPMorgan, Goldman, Morgan Stanley, BlackRock, Bank of America, Citi — operate in a different category from mid-market firms, which navigate the same transformation with limited governance bandwidth and greater dependence on WealthTech and SaaS vendors. For PE-backed consolidators the integration challenge compounds the adoption challenge: each acquired firm brings different data standards, and AI applied to inconsistent data introduces model risk.
Centrally-led, federated delivery.
The resolution most large institutions are converging on is a centrally-led hub-and-spoke: a central platform and governance core paired with federated delivery inside the lines of business. The center owns the AI platform, foundation-model contracts, the evaluation harness, retrieval and prompt patterns, the model inventory, and the standards; the spokes own use-case selection and business integration.
Fit the model to scale.
For a global bank, a centrally-led platform with federated business AI and an "AI control tower." For a super-regional, a centralized center of excellence. For an RIA or PE-backed consolidator, a lean central AI lead standardizing on a small portfolio of vendor AI, backed by an enterprise acceptable-use policy and an AI inventory.
Shadow AI is an operating-model choice.
Prevention is not merely a policy: the approved-tool pathway has to be genuinely easier to use than the unapproved one, or employees route around it.
Protect the skills that matter.
Let AI absorb basic troubleshooting, password resets, and routine documentation — but actively protect root-cause analysis, compliance interpretation, and knowledge curation from atrophy. 32% of CTOs already report overdependence on AI for decision-making.
Data is the binding constraint.
The structural change is the move from centralized reporting teams to federated data-product squads on a shared platform. Each squad owns a domain — client, portfolio, advisor, custodian, CRM, planning, market, HR, finance, vendor, or operational data — accountable for data contracts, service levels, quality metrics, and lineage. AI multiplies data quality rather than substituting for it: poor data produces confident, well-documented, poorly grounded output at scale.
Bounded autonomy, audited everywhere.
AI's operational value is most concrete in I&O — anomaly detection, capacity forecasting, root-cause analysis, remediation drafting, cloud-cost optimization — and its autonomy risk most acute. The governing principle for autonomous action is blast radius: reversible, low-impact actions are reasonable to automate with logging; anything touching production data, security controls, or customer-facing services requires human approval through documented change management.
Tier-0 self-service · ticket triage · knowledge-article generation. ServiceNow's Now Assist requires a documented reason when a human overrides an AI recommendation — an audit trail supporting regulatory review.
The NYDFS October 2025 third-party-service-provider letter names cloud, AI, and FinTech vendors explicitly: lifecycle due diligence, contractual protections, monitoring, and non-delegation of Part 500 compliance. Consuming vendor-embedded AI concentrates risk rather than transferring it.
AI versus AI.
AI strengthens SOC triage, anomaly detection, and phishing analysis — while attackers weaponize the same tools for deepfakes and business-email compromise. The OWASP LLM Top 10 (prompt injection, excessive agency, training-data and embedding poisoning) defines the new control surface, and NYDFS warns that some multifactor methods are vulnerable to deepfakes, recommending liveness detection and out-of-band verification for payments and approvals.
Human-in-the-loop on suppression.
Automation bias is the risk in SOC triage: a model that suppresses a novel attack is more dangerous than one that floods the queue. Sample and review suppressed alerts.
Out-of-band for money movement.
Deepfake voice and video impersonation of executives is now a live fraud vector; payment and approval flows need verification that does not depend on the channel being spoofed.
Govern non-human identity.
Agents acquire credentials and act. Least privilege, action logging, and approval gates for agentic actions (LLM06 excessive agency) move from nice-to-have to baseline.
From productivity to capacity.
The most important reframing for a wealth-management CTO is to stop optimizing advisor productivity and start increasing advisor capacity — the number of clients an advisor can serve well — because the binding constraint is demographic, not technological. AI's value in wealth is not a cost-optimization story but a capacity story: it decouples revenue growth from advisor headcount.
AI@MS Assistant · Debrief (meeting summaries with consent, written back to CRM) · AskResearchGPT.
LLM Suite · Connect Coach · "Ask David" multiagent investment research (supervisor agent orchestrating structured-data, RAG, and analytics sub-agents, with human-in-the-loop).
UBS Red — two Azure-based domain-specific advisor assistants. Illustrates the shift toward domain-specific language models (DSLMs); Gartner predicts ~50% of WM GenAI models will be domain-specific by end-2027 (Gartner prediction).
The architectural destination is the all-in-one advisor desktop — CRM, onboarding, 360-degree view, planning, portfolio management, order generation, and client communication unified behind one experience. Gartner counts 50+ vendors (Table 14) and predicts 70%+ adoption by 2029 (Gartner prediction). For a CTO the platform choice increasingly determines which AI features advisors get and on whose release cadence — so the vendor's AI roadmap becomes a governance input, and the firm's leverage lies in the integration layer and the data it controls.
Four tiers of AI permission.
A defensible financial-services IT AI policy distinguishes prohibited, senior-approval, enhanced-review, and normal-review use. The full mapping — with the controlling framework for each — is in Table 11 below.
Never permitted
- Concealing material AI use from auditors, regulators, risk, or compliance
- Training external models on confidential or source-code data without an executed prohibition
- Agents changing firewall, identity, network, or permission config without approved change management
- Deepfake / synthetic-identity tools in access, approvals, payments, or client instructions
- AI making final credit, employment, investment, or client-treatment decisions without human sign-off
CTO / CISO / CDO / CCO / legal / risk
- Agents provisioning privileged access
- AI-generated code to production without secure review, dependency scanning, and testing
- AI-generated audit evidence, exam responses, or policy attestations
- AI changing client-facing content without compliance review
- AI-generated vendor-risk conclusions used as a final assessment
Technology / security review
- RAG over sensitive client, portfolio, cyber, HR, or source-code data
- Agentic workflows touching production data or external APIs
- Customer data in evaluations or fine-tuning
- Unapproved public AI tools (default prohibited; approved enterprise tooling required)
Allowed with standard QA
- Productivity copilots within approved data domains
- Code completion in approved IDEs with secure review enforced
- Knowledge retrieval over approved internal bases
- Meeting summarization with client consent and CRM logging (the Morgan Stanley pattern)
The floor rose in 2025–26.
No single "AI law" governs financial-services IT; instead a stack of existing and new authorities applies. The full mapping to IT implications is in Table 10. The headline shift is a sector-specific control framework and a sharpened third-party-risk posture.
Five levels. Most firms sit at 2–3.
The diagnostic companion to the use-case map. The leaders profiled in the case studies operate at Level 4; only the largest approach Level 5 in selected domains.
A 12-to-24-month plan.
Four phases from foundation to operating-model and resilience — sequenced so governance and data precede agentic scale.
What CTOs should do differently now.
Stop benchmarking AI adoption by tool count or pilot count. Start benchmarking by the question the evidence converges on: how much of the IT function's work has been redesigned around AI, and can the firm show — to an examiner — who or what made each consequential change and on what authority?
By 2027, the difference between IT functions that thrived through the AI transition and those that did not will not be model access — every firm will have the same frontier models, the same clouds, and many of the same vendors.
The difference will be (1) how decisively the operating model moved to product-and-platform with centrally-led governance and federated delivery; (2) whether data quality, model risk, vendor risk, and the red lines were built in upstream rather than bolted on; and (3) whether IT became — or refused to become — the safe backbone for the enterprise's AI adoption, not merely an adopter of its own tools.
In wealth specifically, the winning CTOs treat AI not as a cost-optimization story for the CFO but as a capacity story: the way a stable or shrinking advisor base serves more clients well, against a ~100,000-advisor shortfall that technology alone cannot close.
The full evidence, on demand.
Every analytical table from the underlying research is below as a click-to-expand data view. The AI use-case map is open by default — it is the single most useful artifact for prioritization. The other thirteen are closed to keep the briefing scannable; open one, several, or all at once.