Financial Services Industry Shifts from AI Adoption to Governance as Autonomous Systems Proliferate, Cloud Security Alliance Survey Finds
As AI systems gain ground in financial sector, limited visibility raises flags about governance and risk management
A new survey from the Cloud Security Alliance (CSA), the world’s leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, found that the financial services sector has moved beyond debating whether to adopt Artificial Intelligence (AI), and is now grappling with how to govern it effectively before autonomy outstrips control.
Also Read: AiThority Interview with Matej Bukovinski, Chief Technology Officer at Nutrient
“In an industry built on trust, the institutions that succeed will be the ones that can balance innovation with accountability and prove they can maintain control as AI systems take on more decision-making responsibility.” -Troy Leach
Commissioned by Anjuna, a leader in Confidential Computing and Autonomous Software Runtime Governance, the State of Cloud and AI for Financial Service 2026 report found that while 62% of organizations have already deployed AI agents, many still lack critical visibility into AI-related risk. Even as 20% of respondents reported experiencing known AI-security incidents, another 21% were unsure whether such incidents had occurred, underscoring how limited visibility may hamper organizations’ ability to investigate, and ultimately mitigate, future AI-related incidents.
“The results of this year’s survey show an industry speeding toward autonomous AI-driven operations while also recognizing that visibility, identity governance, and real-time security controls must mature just as quickly,” said Troy Leach, Chief Strategy Officer, Cloud Security Alliance, and a lead author of the paper. “In an industry built on trust, the institutions that succeed will be the ones that can balance innovation with accountability and prove they can maintain control as AI systems take on more decision-making responsibility.”
The survey’s findings revealed seven defining trends, and highlighted a growing urgency across the industry to establish stronger AI governance frameworks that allow financial institutions to balance innovation with security, governance, and compliance.
- AI is in production. Only 27% of organizations reported no AI agent usage. Over one-third (35%) are actively implementing AI in production, with an additional 9% reporting that they are at the stage of advanced adoption. Nearly half (49%) stated they were in the process of exploring or launching pilot programs.
- AI agents are mainstream (and gaining autonomy). Customer service (63%), cybersecurity operations (47%), back-office operations (44%), and fraud detection (41%) were among the top-ranked use cases. As to how much autonomy these agents have, a large majority (93%) of those using agents have granted them some form of autonomy.
- Agentic finance is on the horizon. An overwhelming majority of respondents believe AI agents will initiate and execute payments on behalf of consumers. Even as 85% said they anticipate autonomous AI payments, the majority (65%) believe that doing so will mandate a new authorization model.
- AI risk is a data problem. Sensitive data leakage through AI interactions (61%) is the top AI security concern, far exceeding worries about model attacks or adversarial techniques.
- Cloud adoption — universal with a twist. This year’s report further confirmed the findings of the 2023 State of Financial Services in Cloud in that cloud services are now embedded across financial services organizations — 98.3% reported using some form of cloud services, with a third (33%) reporting that they rely primarily or fully on cloud-based architectures.
- Senior leadership support is key. Senior leadership’s understanding of the importance of cloud security in mitigating business risk has paved the way for their support of AI deployment. Ninety-one percent of respondents indicated they have moderate to strong support from executive leadership.
- Misconfiguration and third-party risk remain top cloud risks. Risks tied to human error completed came in as the top three security concerns — third-party risk (55%), misconfiguration (52%), human error (27%) — indicating a greater confidence in security tools and supporting technology.
“The financial services industry is entering a new phase of AI adoption where AI is not just a competitive advantage, but table stakes. The only way to deploy AI at scale, especially in the financial services industry, is by deploying it responsibly,” said Ayal Yogev, CEO and co-founder of Anjuna. “Organizations clearly recognize the opportunity AI presents, yet many are still developing the visibility and governance needed to manage these systems at scale. As AI agents become more autonomous and begin handling sensitive transactions and data, security, policy enforcement, and accountability can’t be secondary considerations . They must be embedded into the foundation of every AI initiative.”
The survey was conducted online from January 15 to March 1, 2026, and is based on 340 responses from professionals involved in cloud computing, AI, cybersecurity, compliance, and risk management within financial services organizations worldwide. Respondents were recruited through CSA’s membership network, the Financial Services Working Group, partner organizations, and industry events.
Also Read: AI systems – Interoperable AI systems: Connecting models across platforms
[To share your insights with us, please write to psen@itechseries.com]
Comments are closed.