
Why Financial Services Must Learn to Defend at the Speed of AI
Lessons from the Main Panel Discussion at the Hi2AI Security Edition, Toronto
Artificial intelligence is moving rapidly from experimentation into everyday business. In Financial services, it is beginning to influence productivity, Fraud management, payments, Security, customer experience and operational decision-making. But as AI becomes more capable, the Security question is changing. The issue is no longer simply whether an AI model is accurate, reliable or secure. It is increasingly about what happens when AI can access information, interact with enterprise Systems and perform actions on behalf of an Organization.
That was the central tension explored during the Executive Panel discussion at Financial Technology Frontiers (FTF)’s Hi2AI Security Edition in Toronto on 22 September 2026. Under the theme “AI, Trust & The New Security Frontier”. The Panel was moderated by Babu Nair, Founder of FTF.

The session brought together practitioners from Cybersecurity, Banking, technology, payments and Security architecture to examine how Financial Institutions can embrace increasingly capable AI without losing control.
The discussion produced no single technology answer. Instead, it surfaced a set of questions that Executive teams will increasingly have to answer. Further, the discussion did not treat AI as either a technology miracle or a Security problem. Instead, it explored a more difficult question: “How can Financial Institutions capture the benefits of AI while building the resilience, controls and Trust needed when both defenders and attackers have access to increasingly capable AI?”
AI Is Moving Faster Than Security Can Adapt
The first challenge is the speed of change. AI capabilities are advancing at extraordinary pace, while threat actors have access to many of the same capabilities.
Amyn Sarif, Field CISO and Director Business Development at Sopra Steria North America, captured the dilemma early in the discussion: “When used for good, it’s great. But we also must remember there’s a flip side of it: Threat Actors also have access to using AI.”
The point is not simply that attackers are using AI. It is that the technology itself is evolving faster than many traditional Security approaches were designed to handle. That creates an uncomfortable situation for Security leaders. The technology they are trying to secure may be changing while the Organization is still establishing policies, controls, testing processes and Governance around it. The implication is significant. Security cannot remain a point-in-time exercise that happens after technology has been deployed. It must become continuous. For Executives, the question therefore shifts from “Are we secure?” to “Can our Security capability evolve as quickly as the technology and threats around us?”.
That is a fundamentally different leadership challenge.
The Productivity Opportunity Needs to Be Measured Honestly
The conversation also challenged some of the assumptions surrounding AI productivity.
For many employees, AI is still primarily an advanced search, assistance or content-generation capability. The bigger transformation begins when AI starts performing activities rather than simply answering questions. But that is also where the productivity calculation becomes more complicated. If an AI System completes a task in a fraction of the time, the Organization has not necessarily achieved an equivalent productivity gain. Someone may still need to validate the result. Another employee may need to correct it. Additional controls may be required before the output can enter a business process.
The discussion therefore pointed towards a more meaningful Executive measure of AI productivity. The question should not simply be: “How much time does AI save?” It should be: “How much useful work can the Organization complete safely, accurately and economically with AI?”.
That distinction will become increasingly important as Financial Institutions move from pilots into production. The panel discussion also highlighted the hidden cost of AI adoption. Headline productivity gains can look very different once the time spent reviewing, correcting and securing AI-generated work is included. This is particularly relevant to Boards and Executives evaluating AI investments. The business case cannot be separated from the cost of Governance, Security and human oversight.
AI Versus AI Is Not a Race to Spend More
One of the most compelling themes from the discussion was the idea of AI versus AI.
It would be tempting to assume that Organizations need to deploy increasingly powerful AI simply to keep pace with increasingly sophisticated attackers. The panel challenged that thinking. Phillip Solakov, Security Principal at Microsoft, put it directly: “We must be smarter than that. Ultimately, I think that the AI versus AI concepts really can be reduced backwards to traditional Security defense.”
Phillip’s argument was that Organizations cannot simply try to outspend adversaries in AI. Traditional Security foundations remain essential: Identity, Governance, Data Security, Privileged Access and Zero Trust. But AI can fundamentally increase the capacity of the defender. As Phillip explained, “We can scale ourselves via AI, but we don’t have to fight in the traditional AI-versus-AI race. That’s the wrong way to look at it.”
AI can help Security teams analyse large volumes of information, identify suspicious behaviour, support threat hunting, investigate incidents and accelerate remediation. Instead of simply adding more people to deal with an expanding threat landscape, Organizations may be able to use AI to multiply the effectiveness of existing teams. The opportunity, therefore, is not AI instead of Security. It is AI strengthening Security.
The Real Shift Happens When AI Starts Acting
The conversation became more consequential when the panel moved from AI as an Assistant to AI as an Actor. An AI System that provides information presents one level of Risk. An AI System that can access applications, retrieve information, initiate transactions or perform tasks presents another. The distinction is fundamental. An Organization would not normally give a new employee unrestricted access to every System, Database and business process. The same principle needs to apply when an AI Agent enters the enterprise environment. Organizations therefore need to know:
- What information can the Agent access?
- Which Systems can it interact with?
- What actions can it perform?
- What approvals are required?
- How is its behaviour monitored?
- What happens when it behaves unexpectedly?
- Can it be isolated or stopped immediately?
This was captured particularly well by Manmeet Sachar, Head of Enterprise Platforms and Security Architecture at OpenText: “Every project that gets built out in AI should be treated like an employee.”
The point extends beyond the analogy. Manmeet’s argument was that an AI Agent should be treated as a new employee would be treated: with defined Policies, Frameworks, Controls and Access based on what it needs to perform its role. This provides a useful Executive framework for thinking about AI Governance. An AI Agent is not simply another application. It increasingly has Identity, Authority, Access and the ability to act.
Containment May Become as Important as Prevention
The faster an AI System can act, the less time an Organization must intervene after something goes wrong. That makes containment a critical part of AI Security. The panel repeatedly returned to the need for controlled environments, bounded Agents, monitoring and a mechanism to stop an AI System when its behaviour moves outside expected parameters. As Dharshan Shanthamuthy, Founder and CEO of SISA, put it: “In case an Agent goes wrong, you need to be able to contain that blast radius. You need to be able to turn it off”.
This is an important change in mindset. Organizations cannot assume that an AI System will never make a mistake, be manipulated or behave unexpectedly. The more realistic objective is to ensure that when something does go wrong, the failure remains contained. That means visibility into what the AI is doing, continuous observation of its behaviour, clear access boundaries and a rapid mechanism for intervention.
Fraud Detection Needs to Become More Connected
Another important perspective emerged around Fraud management.
Financial Institutions already operate multiple Fraud and Risk Systems. Different models may examine transactions, identities, behavioural patterns or other signals. The challenge is that these Systems can operate independently. Moy Ghulati, a senior Banker and Security Practitioner, argued for greater orchestration across these layers. His observation was that the future could involve: “Unified orchestration across layers.”
Moy went on to describe the possibility of proactively correlating anomalies between different Fraud layers. A suspicious transaction, for example, could be examined alongside Identity and behavioural information to determine whether a broader pattern exists. This changes the question from: “How good is each individual Fraud model?” to “How effectively can the Organization connect the signals generated across all of them?”. For Banks, this could become one of the most valuable applications of AI: not simply creating another model but creating a more intelligent layer of orchestration across existing capabilities. The objective is to identify a potential problem earlier, before it progresses through multiple levels of attack or Fraud.
Payments Will Put AI Trust to the Test
The payments environment provides an especially powerful illustration of the Trust challenge.
Dharshan brought a payments perspective to the discussion, highlighting Agent-based commerce, Fraud Management and the growing need for secure and compliant AI adoption. He noted the potential of AI to transform payments and described how AI could help consumers make decisions and execute activities more efficiently. At the same time, he stressed that Security and Compliance must remain embedded in the model. As AI becomes more directly involved in payment journeys, the consequences of an incorrect or manipulated decision become much more immediate. A customer may never know which AI System influenced a particular decision. What the customer experiences is whether a payment is approved, blocked, delayed or flagged. That makes boundaries essential. AI Agents operating in payments cannot have unrestricted freedom to access Data, Systems or external resources. Their objectives, permissions and actions need to be clearly bounded.
As AI moves from recommending an action to initiating one, Trust becomes an operational requirement, not simply a Governance principle.
Security, Compliance and Privacy Cannot Operate in Silos
Another clear message from the discussion was that Security, Compliance and Privacy cannot continue to be treated as separate technology exercises.
Financial Institutions operate within complex regulatory environments, handle highly sensitive information and depend on extensive technology ecosystems. Every significant AI deployment therefore must work across three dimensions.
- Security must protect the environment.
- Compliance must ensure that the Organization operates within applicable requirements.
- Privacy must govern how information is accessed and used.
Dharshan emphasised this integrated approach in discussing the evolution of Security platforms. His perspective was that Organizations need technology and processes that bring Security, Compliance and Privacy together rather than creating more disconnected tools. For Executives, this is as much an operating-model issue as a technology issue. The objective should be to make these disciplines work together around the same AI capability rather than allowing each function to create its own controls, tools and processes.
Legacy Technology Cannot Be Ignored
Financial Institutions are not introducing AI into clean, newly built environments.
They are introducing it into large estates of legacy applications, infrastructure and interconnected Systems. That makes containment particularly important. If an AI Agent has access to one System, that access should not automatically create a pathway into everything else. Controlled Access, Compartmentalisation, Least Privilege and the ability to stop an Agent therefore become practical safeguards. This is particularly relevant to Banking because AI will increasingly have to coexist with technology environments built over many years. The objective should be straightforward: An unexpected AI action should remain a contained incident, not become an enterprise-wide event.
The Bank’s Security Does Not Stop at the Bank
The discussion also returned to a familiar but increasingly important problem: Third-Party and Supply-Chain Risk. A Financial Institution may have highly mature internal Security controls while remaining exposed through a technology supplier, service provider or other external partner. Dharshan framed the concern particularly clearly: “It is not the end company that’s getting attacked. It is the supply chain that’s causing the attack, that’s putting the company at Risk”.
He argued that the Security expectations applied to suppliers and third parties need to move closer to those expected within the Financial Institution itself. As AI becomes embedded across platforms, applications and outsourced services, that dependency becomes even more significant. The AI ecosystem itself therefore needs to become part of the Security conversation.
The Future May Be Industry-Specific
The discussion also pointed towards an important development in the AI Security market.
Rather than one generic AI Security solution being sufficient for every Organization, there is likely to be increasing demand for industry-specific capabilities. Phillip described a future in which highly specialised, industry-focused Agents and services address the Security, Compliance, Privacy and operational requirements of individual sectors. In his words, “The actual industry and vertical-specific use cases will be very, very important to the companies who are consuming these products”.
Phillip suggested that marketplaces could eventually contain pre-built Agents and services designed for specific industries and Security environments. For Financial services, this could mean AI Security solutions designed specifically around Banking, payments, insurance, wealth management and capital markets rather than generic enterprise use cases. That is an important opportunity for fintech and Cybersecurity innovators.
From AI Adoption to AI Accountability
The most important conclusion from the panel was perhaps the simplest. The question is no longer merely whether Organizations can use AI safely. It is whether they can remain accountable for what AI does. That requires visibility, Identity, clearly defined Authority, continuous monitoring and containment. More importantly, it requires a tight integration between Security and Fraud functions, and extending Security expectations across the wider ecosystem.
The panel discussion ultimately moved the conversation from AI adoption to AI accountability. Financial Institutions that benefit most from AI will not necessarily be those deploying the largest number of AI tools. They are more likely to be the Organizations that understand where intelligence should be allowed to act, where it must be constrained, and how quickly the Institution can intervene when something goes wrong. That is where Trust becomes part of the technology architecture. And that may well be the real Security frontier for AI in Financial services.
Trust Is the Real End Game
The closing discussion returned to a simple truth: Financial services run on Trust. Customers are willing to share their money, Identity and Data because they believe Institutions will protect them. AI changes the scale and speed at which that Trust can be tested. It can improve Fraud detection, strengthen Security operations and accelerate response. It can also introduce new identities, new attack surfaces, new dependencies and new forms of unintended behaviour.
The panel pointed towards a Security model that is continuous, Identity-aware, bounded, observable and increasingly intelligent. The objective is not to eliminate AI Risk. It is to build the capability to understand, control and respond to AI-driven Risk as it evolves.
The central message from the conversation was clear: the Financial services industry does not need to choose between innovation and Security. It needs to build Security into the way innovation is designed, deployed and governed.
AI may accelerate the pace of change. The responsibility to protect Trust remains with the Institutions that deploy it.
“When Trust is lost, everything is lost.”

Acknowledgements
Financial Technology Frontiers (FTF) acknowledges the thoughtful contributions of the panel participants and the wider Hi2AI community whose perspectives shaped the conversation.
The Executive Panel brought together leaders from Cybersecurity, Banking, technology, payments and Security Architecture, with contributions from the following leaders.
- Dharshan Shanthamuthy, Founder and CEO, SISA.
- Phillip Solakov, Security Principal, Microsoft.
- Amyn Sarif, Field CISO and Director Business Development, Sopra Steria North America.
- Manmeet Sachar, Head of Enterprise Platforms and Security Architecture, OpenText.
- Moy Ghulati, Banking Cybersecurity Leader (in personal capacity).
- Babu Nair, Founder of Financial Technology Frontiers.
FTF thanks its Partners for enabling the Hi2AI Security Edition, and making it a grand success:
- Hosting Partner: ICICI Bank Canada, ably led by Himadar Maddipatla, President And CEO.
- Knowledge Partner: SISA, ably led by Dharshan Shanthamuthy, CEO. Click here to watch the immersive conversations of Dharshan Shanthamuthy, with Babu Nair, Founder of Financial Technology Frontiers.
- Community Partner: QGBS Canada, ably led by Sanjoy Chakraborty, Founder & CEO.

