Banks Are Building a New AI Layer Around Their Legacy Technology

9 September 2026

Artificial intelligence is beginning to reshape the technology architecture of banking, but the transformation may not require banks to replace the decades-old systems at the centre of their operations. Instead, a new technology model is emerging in which trusted legacy platforms remain the systems of record while AI, data and agent layers are built around them to make information easier to understand, access and use. That was one of the central themes of the AI4 2026 panel “Architecting the Future: The AI Tech Stack for Modern Banking,” moderated by technology journalist Naomi Nix, with representatives from Fulton Bank and Deutsche Bank discussing how financial institutions are attempting to capture the productivity benefits of generative and agentic AI without compromising security, customer privacy, regulatory controls or the reliability of their existing banking infrastructure.

One of the more significant conclusions was that legacy technology should not automatically be regarded as something that needs to be replaced. Banking systems that have operated for decades contain enormous amounts of historical information and have been tested through years of transactions, audits and regulatory requirements. Their age can create complexity, but it can also make them highly valuable systems of record. The architectural challenge is therefore increasingly about making those systems understandable and accessible to AI. This creates a new middle layer between traditional banking infrastructure and intelligent applications. Instead of allowing an AI agent to interpret raw databases independently, banks can build semantic, metadata and API layers that explain what information means, where it originates and who is permitted to use it.

The effectiveness of this intermediary layer could become one of the most important elements of banking’s future AI architecture. Financial institutions may ultimately use many of the same underlying models and commercial AI platforms, meaning their competitive differentiation could increasingly come from how effectively they connect those models with proprietary data, internal processes and institutional knowledge. For the moment, however, banks remain cautious about how far AI is allowed to operate independently. Fulton Bank described its current use primarily as internal and assistive, with applications including internal information search, summarisation and software development. Where AI generates code or modifies something that could eventually enter production, responsibility remains with a human employee.

That principle is important because generative AI can produce software considerably faster without guaranteeing that the resulting software is secure or correct. Developers still need to understand what has been generated, examine it for vulnerabilities and take responsibility for what eventually reaches production. Deutsche Bank’s representative described a similar division between AI for technology and AI for the business. On the engineering side, coding assistants can accelerate development and help identify vulnerabilities. On the business side, the priority is increasingly to make AI conclusions traceable back to the underlying information so employees can understand why a recommendation or summary has been produced.

Trust therefore becomes an architectural requirement rather than simply a compliance exercise. An AI application used by a banker cannot operate as an unexplained black box if its conclusions influence important decisions. The system needs to identify the information it used and, where appropriate, connect users back to the underlying source. Client intelligence provides an example of where this architecture could produce considerable value. Investment and corporate bankers traditionally spend significant amounts of time preparing for meetings, assembling market information, previous interactions, internal knowledge and company research. AI could bring those sources together automatically and prepare much of the initial material before the meeting.

The panel described a future in which research that previously contributed to lengthy pitch-book preparation can be assembled dramatically faster. External market information could be combined with internal data about previous conversations, relationships and transactions to give bankers a more complete view of the client before they enter a meeting. The same principle is already changing customer relationship management. Traditionally, bankers have been expected to manually record client conversations in CRM systems, creating an obvious weakness because busy employees do not always complete the process consistently.

Agentic workflows can potentially capture elements of these interactions automatically, organise the information and make previous context available before the next meeting. Rather than asking an employee to remember what was discussed several months earlier or search through CRM notes, an AI-supported system can surface the relevant history and prepare a summary. This has implications beyond simple administrative productivity. Better capture of institutional knowledge can improve continuity when different employees deal with the same organisation, while richer CRM information can provide management with a more accurate picture of client relationships.

Software development is another area where the impact is already measurable. Fulton Bank said approximately 85% of user stories handled by its full-stack development team were receiving some form of AI assistance. Developers had become increasingly comfortable using coding assistants even for relatively small assignments. But the experience also exposed one of the most important limitations of the current AI productivity narrative: producing code faster did not automatically mean that software reached users faster.

Once developers increased their output, other parts of the software delivery process became bottlenecks. User acceptance testing, deployment and the organisation’s ability to absorb changes could not necessarily accelerate at the same rate. In some circumstances, increasing development speed could therefore increase pressure elsewhere in the system and potentially lengthen the complete delivery cycle. This illustrates a broader issue likely to affect companies outside banking as well. AI can optimise an individual stage of a business process without improving the performance of the complete process, meaning organisations need to examine entire workflows rather than simply measuring how much faster employees complete isolated tasks.

The same consideration applies when banks decide whether to build AI technology themselves or purchase it from vendors. Neither approach is likely to dominate completely. The emerging strategy appears to be purchasing widely available infrastructure while developing the elements that provide genuine differentiation internally. Commercial vendors can invest far more heavily in foundation models, orchestration platforms and general-purpose software than most individual banks. Attempting to recreate all of those capabilities internally would rarely make economic sense. Proprietary data structures, entitlement controls, institutional knowledge and business-specific workflows are different because these reflect how an individual bank actually operates.

The result is likely to be a hybrid technology stack. Banks can purchase the underlying platform while building the layers that determine what the AI can access, which actions it can perform and how it interacts with proprietary information. Flexibility will be particularly important because the vendor landscape is changing rapidly. A technology that appears sensible to build internally today could be available commercially within a year, while a vendor selected today may fail to keep pace with competitors. Banks therefore need architectures that allow components to be replaced without rebuilding the entire AI environment.

This modular approach could become even more important as the market shifts from purchasing complete software platforms towards purchasing specialised agents. Instead of licensing a large application containing hundreds of functions, companies could eventually select individual agents for specific activities and connect them with their own systems. Security remains the major constraint on this transition. Financial institutions hold extremely sensitive customer information, making unrestricted access to external AI models unacceptable for many applications.

Fulton Bank said it remains particularly cautious about exposing customer financial information to external large language models and is exploring internally controlled models based on open-weight technology for use cases involving sensitive data. This does not necessarily mean banks will abandon frontier models. Instead, different models could be selected according to the sensitivity and complexity of each task. External systems may be appropriate for some applications, while internally hosted models handle information that institutions are unwilling to send beyond their controlled environments.

Agentic AI adds another security challenge because agents can potentially take actions rather than simply generate text. Traditional access-control principles consequently become even more important. An agent should receive only the permissions required to perform its particular task. The Deutsche Bank discussion described an entitlement model in which access depends on factors including an employee’s role, location, jurisdiction and organisational mandate. A similar concept can be extended to AI agents, with each agent effectively receiving its own identity, permissions and operational boundaries determining which systems and information it can access.

This could become one of the defining components of enterprise AI architecture. As organisations deploy hundreds or eventually thousands of agents, they will need to know not only what employees are authorised to do but also what every autonomous software entity is permitted to see and change. Observability is equally important. Banks need records showing what an agent did, what information it accessed, how it was instructed and which actions it performed. The panel suggested that existing tooling still has room to improve in providing this visibility.

Many AI-related security incidents may also expose existing weaknesses rather than entirely new categories of vulnerability. AI can search systems and combine known weaknesses far faster than humans, increasing the importance of basic cybersecurity disciplines such as permissions, patch management, network segmentation and monitoring. The arrival of more capable AI therefore raises the cost of leaving conventional security problems unresolved.

Determining the return on all this investment remains difficult. Banks can measure whether a process becomes faster, whether employees handle more work or whether customers receive quicker service, but converting those improvements into a precise financial return can be complicated. AI introduces an additional cost variable through computing and token consumption. For the first time, organisations can attach a relatively visible cost to individual units of machine-generated intelligence, making model selection part of financial management. Expensive reasoning models do not need to handle routine tasks that smaller and cheaper models can complete adequately.

Model routing could therefore become another layer of the banking technology stack, automatically selecting the appropriate model according to the task, required accuracy, data sensitivity and cost. Managing AI expenditure may eventually resemble managing cloud infrastructure, with companies continually balancing performance against consumption.

The workforce implications are similarly complex. The panel did not present AI simply as a mechanism for eliminating jobs. Instead, it described changing roles in which employees who previously performed manual activities increasingly learn to create or supervise agents that perform parts of those activities. Routine, highly structured knowledge work is nevertheless exposed. Employees whose roles consist largely of repeating clearly defined processes will need to move towards activities requiring greater judgement, domain knowledge and responsibility as machines become more capable of performing standardised tasks.

Software development illustrates the transition. AI can already generate substantial quantities of code, but experienced engineers remain necessary to determine architecture, examine security, understand dependencies and decide whether the generated software should be deployed. The value of the developer consequently moves away from simply producing lines of code and towards supervising increasingly powerful development systems.

The rise of so-called vibe coding makes that distinction particularly important. AI now allows people with limited programming experience to create functioning prototypes rapidly. This can be extremely useful for product managers and business users who want to demonstrate an idea before requesting significant development funding. Using the same approach for production banking systems is considerably more problematic. Software created without sufficient understanding of its architecture can become difficult to maintain, secure and audit. Both banking representatives therefore drew a distinction between rapid AI-assisted prototyping and production engineering.

That distinction may lead to a new innovation model inside large organisations. Employees throughout the business can use AI to prototype solutions to problems they encounter. Successful prototypes can then be identified by professional technology teams and rebuilt or expanded into controlled enterprise applications.

The longer-term architecture of banking could consequently look very different from the technology estates that institutions operate today. Core banking platforms may remain in place, continuing to provide trusted records and transaction processing, while an increasingly sophisticated intelligence layer develops around them. Above that layer could sit specialised agents responsible for research, customer intelligence, software development, operational workflows and employee assistance. Access and entitlement systems would determine what each agent can see, observability systems would record what it does, and model-routing technology would determine which AI engine should perform each task.

The transformation is therefore less about replacing old banking technology with AI than about connecting the two intelligently. Decades of accumulated data and trusted infrastructure could become an advantage rather than simply technical debt if banks can make that information safely accessible to machines. That may ultimately determine which institutions gain the most from the next phase of financial AI. The foundation models themselves will increasingly be available to everyone. The competitive advantage will lie in the architecture surrounding them: proprietary data, secure access, adaptable systems, institutional knowledge and the ability to turn increasingly powerful AI into reliable banking operations.

Source: CIJ.World Research & Analysis Team

front page info
LATEST NEWS