Get a free audit

Field Notes / Industry Analysis

AI security for financial services: why banks and insurers are the highest-value AI targets

94% of financial institutions run AI in production. Only 23% have tested it against a real adversary. This is the threat map, the regulations that now bite, and the work that closes the gap.

Author
Red Team Partners
Read
12 MIN READ
Filed
13 March 2026
A financial executive at a lit terminal after hours, reviewing an AI risk file.

01 Where AI touches the money

bank does not deploy one AI. It deploys dozens, and most of the risk sits in the systems that decide who gets money and who gets stopped. Map where the models sit and the attack surface names itself: every place a model makes a financial call is a place an attacker wants to change the answer.

The table below is the deployment picture across the sector, drawn from the 2025 surveys of banks and insurers McKinsey 2025 . Read it as a target list. The higher the deployment rate, the more places an attacker can probe, and the column that matters is the one on the right: the regulator already watching each function.

AI application Deployment Primary risk Regulator
Fraud detection 87% Adversarial evasion: crafted transactions that slip past the model PSD2, AML directives
Credit scoring / underwriting 76% Model manipulation: poisoned or biased data shifts lending decisions EU AI Act (high-risk), ECOA
Customer service chatbots 82% Prompt injection: extracting account data or authorising transfers GDPR, consumer protection
Algorithmic trading 54% Market manipulation through adversarial inputs to trading AI MiFID II, MAR
KYC / AML screening 71% Adversarial bypass of identity checks and sanctions screening 5AMLD, 6AMLD
Internal knowledge assistants 89% Data leakage from RAG pipelines holding confidential deal data MiFID II, insider trading
Risk assessment models 63% Model poisoning that systematically underestimates risk Basel III, Solvency II

Sources: Accenture Financial Services Cybersecurity Report 2026, McKinsey Global Banking AI Survey 2025, EBA Report on AI in Banking 2025.

02 Five financial-specific attack paths

These are the routes we walk in financial engagements. Each one leaves the client with the same thing: the exact way an attacker changes a money decision, and the control that stops it.

1. Credit decision manipulation. An attacker who understands the features behind a credit model crafts applications that exploit its weak spots. The Bank of England showed in 2025 that adversarial perturbations shifted credit scores by an average of 47 points while every visible field on the application stayed unchanged Bank of England 2025 . At scale, that is synthetic-identity fraud the model itself signs off as low risk.

2. Chatbot-enabled account takeover. A chatbot that can check balances or move funds is a prompt-injection target worth real money. Pull the system prompt and you learn exactly which authentication checks it runs, and how to talk it out of them. In our assessments, 3 of 5 banking chatbots allowed unauthorised account actions through multi-turn prompt manipulation RTP engagements .

3. Insider trading through RAG. Investment banks wire AI assistants into deal databases and research. When RAG access controls are thin, someone in one division can query the AI to surface material non-public information from another. The model does not respect information barriers. It returns what is semantically relevant, and the insider-trading liability lands on you.

4. Fraud detection evasion. A fraud model can be probed until its decision boundary is mapped, then attacked from just inside the line it treats as normal. Visa reported AI-aware fraud attempts rose 340% year on year as criminal networks began running their own AI to probe detection systems Visa 2025 .

5. Regulatory reporting manipulation. AI now feeds stress testing, capital adequacy and transaction monitoring. Tamper with the training data or the parameters and the model underreports risk. Every dashboard reads compliant while the real exposure grows underneath it.

03 What the regulators now demand

Four regimes have converged on the same requirement: test your financial AI against an adversary, and keep the evidence. Miss the deadlines and the penalties stack.

EU AI Act, by 2 August 2026. Credit scoring, insurance pricing and financial assessment are named high-risk under Annex III. That means mandatory adversarial testing, risk-management documentation and ongoing monitoring. Penalties reach €15M or 3% of global revenue for high-risk breaches, and €35M or 7% for prohibited practices EU 2024/1689 . Our EU AI Act red teaming guide walks the whole obligation.

DORA, in force since 17 January 2025. DORA requires threat-led penetration testing of critical systems, and the 2025 technical standards put AI explicitly in scope. Significant institutions test at least every three years under Article 26, and AI model providers now count as critical third parties under Article 28.

EBA guidelines on AI/ML, 2025. The European Banking Authority tells banks to validate models against adversarial scenarios, run AI-specific model-risk frameworks, and document testing for supervisory review EBA 2025 .

UK FCA and PRA, 2025 to 2026. The Financial Conduct Authority and Prudential Regulation Authority have signalled AI-specific requirements for late 2026, building on the Bank of England's 2025 AI principles.

04 Why old testing misses it, and the fix

You already run a mature security programme. SWIFT CSP, PCI DSS, SOC 2, ISO 27001. Every one of them was built for deterministic systems with fixed rules. AI is probabilistic, so a model can be tricked into the wrong call while all four frameworks still report green. PCI DSS protects cardholder data and cannot detect a manipulated fraud model. SOC 2 validates your process and never tests whether the model itself can be fooled.

Closing the gap is not a bigger audit. It is offensive testing aimed at the model, mapped to the regulations that now apply to you. The work is concrete, and most institutions can start it inside a quarter. The list below is where financial teams get the most back for the least spend.

Remediation Log
  • Inventory every AI system, including the shadow AI your CISO does not yet know about
  • Map each model to its regulator (EU AI Act, DORA, EBA, FCA) and mark the compliance gaps
  • Commission AI-specific red teaming for every high-risk model, not just a network pentest
  • Deploy monitoring for model drift, adversarial input patterns and anomalous AI behaviour
  • Treat AI model providers as critical third parties with DORA-grade due diligence

In financial services, trust is the product. An AI breach that touches customer accounts or lending decisions becomes an existential reputational event, and it arrives with a regulator attached. You want to find these paths before a criminal does. That is the whole job. Start with a free audit and we will show you where your models are exposed, in plain terms, for the price of your attention.

References

Sources

  1. Accenture. Financial Services Cybersecurity Report. Accenture, 2026. accenture.com
  2. McKinsey & Company. Global Banking AI Survey. McKinsey & Company, 2025. mckinsey.com
  3. European Banking Authority. Guidelines on the Use of AI/ML by Credit Institutions. EBA, 2025. eba.europa.eu
  4. Bank of England. Adversarial Robustness of AI Models in Financial Services. Bank of England, 2025. bankofengland.co.uk
  5. Visa. Annual Fraud Intelligence Report. Visa, 2025. usa.visa.com
  6. European Parliament and Council. Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union, 2024. artificialintelligenceact.eu
  7. European Parliament and Council. Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA). Official Journal of the European Union, 2022. eur-lex.europa.eu