September 17, 2026 By Yodaplus
Regulatory change is forcing BFSI institutions to fold AI governance directly into their existing technology roadmaps, rather than treating it as a separate compliance project running alongside the real work. More than 85% of banks under European banking supervision already use AI, according to a February 2026 ECB Banking Supervision speech, and from August 2, 2026, most of the remaining provisions of the EU AI Act take effect, including the framework governing high-risk systems. For institutions that size, AI stopped being an isolated innovation initiative months ago. It’s now part of the same conversation as cybersecurity and operational resilience.
That shift changes what a technology roadmap actually needs to include, not just what compliance teams need to track.

For a while, EU AI Act obligations felt like something to prepare for eventually. That framing is now out of date. Most tier-1 banks already have at least one high-risk AI system in production, covering things like credit scoring and biometric identification, and those systems now need to meet certification requirements with very little runway left.
The practical effect on a roadmap is straightforward: any project involving artificial intelligence in banking now needs a compliance classification step built in from the design phase, not bolted on before launch. Waiting until a system is close to production to ask “does this count as high-risk” is no longer a viable sequence.
The EU’s Digital Operational Resilience Act has quietly moved past its early rollout period. Core requirements, covering ICT risk management, incident reporting, and resilience testing, have been in force for well over a year, and regulators are now auditing against them rather than simply checking whether institutions have a plan.
This matters for technology roadmaps because DORA and the AI Act aren’t separate tracks anymore. Institutions are expected to align their AI strategy with their existing DORA operational resilience framework, meaning any new agentic AI platform or AI agents deployment has to fit inside the same governance structure already built for ICT risk.
The clearest shift in 2026 is that AI governance has stopped being its own workstream. It’s being absorbed into the same strategic conversation that already covers cybersecurity, third-party risk, and operational resilience. A bank’s management body is now expected to hold an AI strategy that’s consistently embedded in its wider business and resilience strategy, not a standalone AI policy sitting off to the side.
For technology teams, this means an enterprise AI solution can’t just prove it works. It has to prove it fits within existing risk reporting, incident response, and third-party oversight structures that were originally built for very different kinds of technology.
In practice, three things now show up earlier in project planning than they used to. Roadmaps need a documented compute and data volume plan, since AI systems demand resource planning most standard IT projects never required. They need traceability built in from day one, since regulators expect institutions to explain how an AI system reached a decision, not just that it reached the right one. And they need human oversight checkpoints designed into the workflow itself, particularly for anything touching credit decisions or customer risk profiles.
None of this is about slowing AI adoption down. It’s about making sure the roadmap accounts for governance costs upfront instead of discovering them mid-project, which is exactly where budgets and timelines used to blow up before this became standard practice.
Not every AI use case carries the same regulatory weight. Credit scoring is explicitly named as high-risk under the AI Act, while fraud detection is specifically carved out of that same category, a distinction worth getting right before scoping any project. Biometric identification and risk pricing in insurance carry similar high-risk classification.
This means a technology roadmap increasingly needs a triage step early on: is this specific AI agents deployment touching a classified high-risk use case, and if so, what documentation, testing, and oversight does that trigger before a single line of code gets written.
None of this is a reason to pull back on AI automation broadly. Institutions are still finding real value in reconciliation automation, payment automation, and intelligent document processing, precisely because these use cases tend to sit outside the highest-risk categories while still delivering measurable efficiency gains.
The institutions handling this well aren’t avoiding AI process automation. They’re sequencing it deliberately, tackling lower-risk, high-volume workflows first while building the governance muscle needed for the higher-stakes use cases like credit decisioning and investment research that carry more regulatory weight.
Expect regulatory expectations to keep tightening rather than settling, with high-risk obligations continuing to phase in through 2027 and beyond. Institutions treating governance as a design requirement rather than a compliance afterthought are likely to move faster on AI in banking overall, since they won’t be redesigning systems mid-project to meet requirements they should have planned for at the start.
Regulatory change in 2026 hasn’t slowed BFSI’s technology roadmaps down. It’s changed what has to be on them from day one, folding AI governance, traceability, and human oversight into the same planning process that already covers cybersecurity and operational resilience.
Yodaplus builds enterprise AI solutions with this reality designed in from the start. Our approach to AI agents, intelligent document processing, and AI process automation includes the governance-first architecture regulators now expect, so institutions can move on AI in banking without redesigning systems mid-project to catch up with requirements they should have planned for from the beginning.
From August 2, 2026, most of the remaining provisions of the EU AI Act take effect, including transparency requirements and the framework governing high-risk AI systems, giving institutions with systems already in production very little runway to certify compliance.
DORA’s core requirements are already in an audit phase rather than preparation, and institutions are expected to align any new AI initiative with their existing DORA operational resilience framework rather than treating AI governance as a separate track.
Credit scoring, biometric identification, and risk pricing in insurance are explicitly classified as high-risk, while fraud detection is specifically carved out of that same category, making early classification important before scoping any project.
Not necessarily. Many institutions continue investing in lower-risk, high-volume automation like reconciliation and payment automation, while sequencing governance-heavy work for higher-stakes use cases like credit decisioning.
Teams now need to build compliance classification, traceability, and human oversight checkpoints into a project’s design phase, rather than adding them just before launch, since retrofitting governance late in a project tends to cause the biggest delays and cost overruns