Francesco Di Costanzo

(27) The AI Maturity Gap Is an Operating-Model Gap

Applied AI & Agent Systems
  • Enterprise AI
  • AI governance
  • Operating models
  • Leadership

Download presentation (PDF)

Adoption is broad; material scale is not

Financial services does not have an AI awareness problem. In the Bank of England and Financial Conduct Authority's 2024 survey of 118 firms, 75 percent were already using AI and another 10 percent planned to do so within three years. Yet 62 percent of reported use cases were rated low materiality and only 16 percent high materiality. Foundation models were even more concentrated at the edge: 71 percent of those use cases were low materiality. The distance between adoption and materiality is the maturity gap.

That gap is often described as a shortage of models, data scientists or regulatory clarity. Those constraints are real, but the evidence points to a more specific cause. A pilot can be created by a small technical team using a bounded dataset and a cooperative group of users. Production requires a named business owner, integration with live systems, reliable data access, testing, monitoring, security, legal approval, model-risk judgement, training and an economic measure that survives scrutiny. A firm can buy the technology for the first task. It has to organise itself for the second.

The thesis is testable. Among institutions with broadly comparable access to models and capital, those with business-owned workflows, reusable technical services and proportionate controls should move more valuable use cases into production faster than those organised around disconnected experiments. If those features do not predict deployment speed, reuse or measurable value, then the operating-model explanation is wrong. For now, supervisory surveys, industry studies and the disclosures of leading banks all point in the same direction.

Leaders build a path to production

The clearest disclosures from AI-mature banks describe a production system rather than a catalogue of demonstrations. DBS says its ADA data and analytics platform supports more than 2,000 models across over 430 use cases. It reports that code deployment is 25 percent faster, model deployment takes seven to ten weeks, and data and AI initiatives delivered about SGD 1 billion of economic value in 2025. Its generative-AI framework supplies reusable components, governance guardrails and workflow capabilities. The significant number is not the model count. It is the shortening and standardisation of the route from idea to monitored service.

JPMorgan's Commercial & Investment Bank presents the same architecture from the business side. More than 65,000 employees use its internal LLM platform, while AI-assisted transaction screening has more than doubled review volume and halved manual operator checks. Each business has an AI strategy aligned with an end-to-end client journey, supported by a common data estate. Goldman Sachs made the organisational implication explicit in its 2025 annual report: its One Goldman Sachs 3.0 operating model starts with six front-to-back workstreams, including onboarding, regulatory reporting, lending and enterprise risk, rather than a list of generic AI tools.

These examples are self-reported and come from large institutions able to spend heavily. They should not be read as controlled evidence that a particular structure causes returns. They do show what leaders choose to make visible: common platforms, workflow ownership, deployment cadence, data foundations and measurable operating outcomes. Their unit of transformation is the process, not the model.

Business ownership changes the unit of work

The typical pilot asks whether a model can perform a task. A production programme asks whether a business process can deliver a better outcome after roles, decisions, controls and systems have changed. That distinction extends the argument in Why AI Adoption Depends on Management: executive sponsorship is too weak unless a business leader owns the workflow, its budget, its risks and the realised benefit.

This changes portfolio selection. A central AI team may rank ideas by technical feasibility or novelty. A business owner must rank them against customer outcomes, control failures, capacity constraints and other uses of capital. The relevant backlog is therefore not “chatbots, copilots and agents.” It is onboarding time, fraud losses, false positives, credit-decision quality, adviser capacity and software-release reliability. AI becomes one component of a redesigned service.

Organisation still matters. McKinsey's 2024 review of 16 large financial institutions found that about 70 percent of those with highly centralised generative-AI models had put use cases into production, compared with about 30 percent of fully decentralised institutions. The sample is small and the finding is correlational, but the mechanism is plausible: scarce expertise, architecture choices, vendor decisions and risk standards are easier to reuse when coordinated. Full centralisation has its own failure mode, because a remote AI team can optimise a prototype while missing the work. The durable design is usually central standards and shared services, with prioritisation, adoption and value owned by the business. As capability matures, execution can become more federated without fragmenting the foundation.

Data maturity is bounded, not universal

“Fix the data first” sounds responsible and often becomes an indefinite postponement. No large financial institution will finish cleaning every historical system before using AI. The practical requirement is narrower: for a chosen workflow, the firm needs authoritative sources, defined owners, usable lineage, access rules, quality thresholds and a process for correcting errors. Data maturity is the ability to make those conditions true repeatedly, not the achievement of universal cleanliness.

The starting position remains weak. Almost a decade after the Basel Committee issued its principles for risk-data aggregation and reporting, its 2023 assessment found only two of 31 global systemically important banks fully compliant with all principles. Its 2026 report still identified fragmented responsibilities, organisational resistance and insufficient senior attention. The BIS has since linked wider use of generative AI to the same structural defects: fragmented stacks, inconsistent definitions, data silos and unclear accountability. ECB Banking Supervision found promising practices such as “golden” sources, central model records and joint Chief Data and AI Officers, but said only a few banks in its workshop sample effectively applied data-management standards adapted to AI.

The non-obvious point is that many data-quality problems are decision-rights problems in disguise. Two functions preserve conflicting customer definitions because nobody can impose one. A critical field remains incomplete because no owner bears the downstream cost. An access request takes weeks because risk appetite has not been translated into rules. Architecture matters, but architecture cannot settle authority. This is why the same institution can have excellent data in payments and unusable data in a neighbouring process.

AI leaders build governed data products around valuable domains, then make them reusable through shared interfaces. That approach supports the control point described in Where the Agent Layer Captures Value: value sits in the governed connection between models and proprietary systems. The faster route to scale is not a heroic enterprise clean-up. It is a sequence of owned domains whose data contracts become part of the production platform.

Governance should manufacture reusable evidence

Governance blocks scale when every proposal enters a bespoke committee process, each control function asks for different evidence, and the production team discovers requirements near the end. That operating model turns caution into a queue. It also creates a false choice between speed and safety, because rushed exceptions and abandoned pilots are both signs of a weak control system.

Mature governance begins earlier and repeats itself. The institution inventories uses, assigns materiality and autonomy tiers, defines approved architectures, records data provenance, specifies human intervention, tests performance against business and conduct outcomes, and monitors drift, incidents and override rates after release. Higher-risk uses receive deeper challenge; low-risk internal assistance should not face the same path as automated credit decisions. A model card or impact assessment becomes useful when its fields feed approval and monitoring, not when it exists as a document detached from operations.

The regulatory direction supports this design. The PRA's model-risk principles require proportionate implementation and clear senior accountability. In the Bank of England's 2026 industry roundtables, several firms described that framework as a practical support for responsible adoption. The same discussions exposed the constraint: second-line caution can delay pipelines because specialist skills are scarce and compliance evidence is hard to assemble. Participants argued that traditional validation cannot simply be multiplied across generative and agentic systems; more emphasis must fall on outcome testing, monitoring and guardrails.

Governance becomes an enabler when it converts policy into reusable production assets: risk tiers, test suites, approved retrieval patterns, supplier clauses, logging standards, escalation routes and control evidence generated by the delivery pipeline. This does not relax oversight. It makes effective challenge faster and more consistent. The best measure of governance maturity is not the number of committees or policies. It is whether the next team can satisfy the same standard with less reinvention.

Investment should follow the bottleneck

The visible AI budget is usually model licences, cloud capacity and specialist hiring. Those are necessary inputs, but they are poor first moves when the bottleneck is workflow ownership or data access. More capacity merely allows the institution to produce more pilots that cannot cross the same boundary.

The investment sequence should start with a small number of economically important workflows and a baseline for their current performance. It should then fund persistent teams that join business, product, engineering, data, security, legal and risk expertise. Shared services come next: identity and access, model routing, retrieval, evaluation, observability, audit records and cost measurement. Domain data products and modern integration patterns reduce dependence on brittle point-to-point connections. Training should be role-specific and tied to changed decisions, not counted through attendance at general AI courses.

Leading-bank disclosures reflect this mix. Deutsche Bank pairs shared AI services and broad workforce access with platform modernisation and the retirement of legacy applications. ING describes a private-cloud foundation, a common delivery pipeline and reusable services. Commonwealth Bank reports a cloud data estate, more than 2,000 real-time machine-learning models and extensive use of coding assistants. These programmes differ, but each combines infrastructure with operating change rather than treating infrastructure as the strategy.

The capital-allocation rule is simple: fund the constraint that prevents a valuable workflow from reaching controlled production. In one domain that may be source-data quality; in another, an unresolved policy decision, a missing API, insufficient evaluation capacity or weak user adoption. Portfolio governance should move money when the constraint changes. This is the same general lesson as Strategy Fails When the Operating System Contradicts It: stated priority matters only when authority, resources and measures reinforce it.

The strongest objection is partly right

Large banks possess advantages that an operating model cannot create quickly: proprietary data, engineering depth, bargaining power with suppliers and the capital to modernise old estates. Regulation also fragments deployment across jurisdictions, while model behaviour still limits high-stakes automation. The Bank of England's survey found model safety and insufficient skills among the largest non-regulatory constraints. Its later roundtables recorded cross-border data rules, supplier negotiations and third-party substitution as practical barriers. In some cases, staying in pilot mode is the correct risk decision.

There is also selection bias in the evidence. Leading institutions publish successes more readily than failures. Consultancy maturity surveys often rely on executive responses, use different definitions of “scale,” and do not randomly assign operating models. Centralised firms may reach production because they were more capable before centralising. The thesis therefore concerns the mechanism most consistent with the record, not a universal causal estimate.

Yet the objection does not overturn the pattern. The largest institutions also have the most complicated legacy estates, regulatory obligations and organisational boundaries. Model access has spread quickly, but material deployment has not converged. Academic field studies help explain why: AI raises performance inside well-defined, instrumented tasks, while changes that cross team boundaries require coordination and work redesign. Technical readiness determines which tasks are possible. The operating model determines whether a possible task becomes a dependable business capability.

Maturity compounds through reuse

Pilot mode treats each use case as a fresh project. A new team finds data, negotiates access, chooses a vendor, interprets policy, creates tests and argues for adoption. Even a successful prototype leaves little institutional residue. The next project pays the same fixed costs.

AI maturity appears when those costs become shared assets. One deployment adds a data contract, an evaluation case, a monitoring pattern, a supplier term, a trained product owner and a clearer risk precedent. The marginal cost and time of the next deployment decline. Learning compounds because the institution retains it in platforms, controls and roles rather than in a presentation about the pilot.

This suggests a better management scorecard. Count the time from approved use case to controlled production, the share of components reused, the proportion of benefits measured against a baseline, active adoption in the target workflow, control exceptions, incident resolution and post-release model performance. Model counts and employee licences are useful capacity measures, but they say little about maturity on their own.

The firms stuck in pilot mode do not necessarily lack ambition, data or technical talent. They lack an institutional path that connects those assets to a business outcome under real operating constraints. Closing the maturity gap means building that path once, measuring it, and improving it with every deployment. The competitive advantage is not any single AI system. It is the organisation's falling cost of turning uncertain technology into controlled, repeatable value.

Sources

Supervisory Evidence and Governance Frameworks

  1. Bank of England and Financial Conduct Authority, "Artificial intelligence in UK financial services - 2024" https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024

  2. Bank of England and Financial Conduct Authority, "Machine learning in UK financial services" https://www.bankofengland.co.uk/report/2022/machine-learning-in-uk-financial-services

  3. Bank of England and Financial Conduct Authority, "The AI Public-Private Forum: Final report" https://www.bankofengland.co.uk/research/fintech/ai-public-private-forum%C2%A0

  4. Bank of England and Financial Conduct Authority, "FS2/23 - Artificial Intelligence and Machine Learning" https://www.bankofengland.co.uk/prudential-regulation/publication/2023/october/artificial-intelligence-and-machine-learning

  5. Prudential Regulation Authority, "SS1/23 - Model risk management principles for banks" https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss

  6. Bank of England, "Summary of AI roundtables - February 2026" https://www.bankofengland.co.uk/minutes/2026/february/summary-of-ai-roundtables-feb-2026

  7. Financial Stability Board, "The Financial Stability Implications of Artificial Intelligence" https://www.fsb.org/2024/11/the-financial-stability-implications-of-artificial-intelligence/

  8. Financial Stability Board, "Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector" https://www.fsb.org/2025/10/monitoring-adoption-of-artificial-intelligence-and-related-vulnerabilities-in-the-financial-sector/

  9. Financial Stability Board, "Sound Practices for Responsible Adoption of Artificial Intelligence: Consultation report" https://www.fsb.org/2026/06/sound-practices-for-responsible-adoption-of-artificial-intelligence-ai-consultation-report/

  10. Bank for International Settlements Financial Stability Institute, "In data we trust? Emerging policy and supervisory approaches to AI data use in financial services" https://www.bis.org/publications/fsi-insight-73-data-we-trust-emerging-policy-and-supervisory-approaches-ai-data-use-financial-services

  11. Basel Committee on Banking Supervision, "Implementation of the Principles for effective risk data aggregation and risk reporting" https://www.bis.org/publications/implementation-principles-effective-risk-data-aggregation-and-risk-reporting-bcbs-239-principles

  12. Basel Committee on Banking Supervision, "Progress in adopting the Principles for effective risk data aggregation and risk reporting" https://www.bis.org/publications/202311-implementation-reports-progress-adopting-principles-effective-risk-data-aggregation-and-risk-reporting

  13. European Central Bank, "Annual Report on supervisory activities 2025" https://www.bankingsupervision.europa.eu/press/other-publications/annual-report/html/ssm.ar2025~6ee989dc7e.en.html

  14. European Central Bank Banking Supervision, "AI's impact on banking: use cases for credit scoring and fraud detection" https://www.bankingsupervision.europa.eu/press/supervisory-newsletters/newsletter/2025/html/ssm.nl251120_1.en.html

  15. European Central Bank Banking Supervision, "Supervisory priorities 2026-28" https://www.bankingsupervision.europa.eu/framework/priorities/pdf/ssm.supervisory_priorities202511.en.pdf

  16. European Banking Authority, "AI Act: implications for the EU banking and payments sector" https://eba.europa.eu/sites/default/files/2025-11/d8b999ce-a1d9-4964-9606-971bbc2aaf89/AI%20Act%20implications%20for%20the%20EU%20banking%20sector.pdf

  17. European Banking Authority, "Special topic - Artificial intelligence" https://www.eba.europa.eu/publications-and-media/publications/special-topic-artificial-intelligence

  18. OECD, "Regulatory approaches to Artificial Intelligence in finance" https://www.oecd.org/en/publications/regulatory-approaches-to-artificial-intelligence-in-finance_f1498c02-en.html

  19. Office of the Superintendent of Financial Institutions, "Financial Industry Forum on Artificial Intelligence: A Canadian Perspective on Responsible AI" https://www.osfi-bsif.gc.ca/en/about-osfi/reports-publications/financial-industry-forum-artificial-intelligence-canadian-perspective-responsible-ai

  20. UK Parliament Treasury Committee, "Artificial intelligence in financial services" https://publications.parliament.uk/pa/cm5901/cmselect/cmtreasy/684/report.html

  21. HM Treasury, "Financial Services AI Adoption Plan" https://www.gov.uk/government/publications/ai-adoption-plan-financial-services/financial-services-ai-adoption-plan

  22. Financial Conduct Authority, "AI Sprint summary" https://www.fca.org.uk/publications/techsprints/ai-sprint-summary

  23. European Parliament and Council, "Regulation (EU) 2024/1689 - Artificial Intelligence Act" https://eur-lex.europa.eu/eli/reg/2024/1689/oj?locale=en

  24. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework" https://www.nist.gov/itl/ai-risk-management-framework

  25. Board of Governors of the Federal Reserve System, "Supervisory guidance on model risk management" https://www.federalreserve.gov/frrs/guidance/supervisory-guidance-on-model-risk-management.htm

Operating Models, Investment and Industry Studies

  1. McKinsey & Company, "The State of AI: Global Survey 2025" https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai

  2. McKinsey & Company, "Scaling gen AI in banking: Choosing the best operating model" https://www.mckinsey.com/industries/financial-services/our-insights/scaling-gen-ai-in-banking-choosing-the-best-operating-model

  3. McKinsey & Company, "Platform operating model for the AI bank of the future" https://www.mckinsey.com/industries/financial-services/our-insights/platform-operating-model-for-the-ai-bank-of-the-future

  4. McKinsey & Company, "Extracting value from AI in banking: Rewiring the enterprise" https://www.mckinsey.com/industries/financial-services/our-insights/extracting-value-from-ai-in-banking-rewiring-the-enterprise

  5. McKinsey & Company, "Evolving model risk management in the age of AI" https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/evolving-model-risk-management-in-the-age-of-ai

  6. Boston Consulting Group, "Are You Generating Value from AI? The Widening Gap" https://www.bcg.com/publications/2025/are-you-generating-value-from-ai-the-widening-gap

  7. Deloitte, "The State of AI in the Enterprise - 2026" https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html

  8. Deloitte, "From AI pilots to production: getting the tech right" https://www.deloitte.com/content/dam/assets-zone2/nl/en/docs/industries/financial-services/2026/deloitte-c-suite-guide-from-ai-pilots-to-production.pdf

  9. EY and Institute of International Finance, "Banks race to adapt as traditional risks rebound and new threats accelerate" https://www.ey.com/en_gl/newsroom/2026/02/banks-race-to-adapt-as-traditional-risks-rebound-and-new-threats-accelerate-ey-and-iif-survey-shows

  10. KPMG, "AI adoption growing rapidly in financial services, but execution remains the key challenge" https://kpmg.com/dp/en/media/press-releases/2026/08/ai-adoption-in-financial-services.html

  11. KPMG, "AI Quarterly Pulse Survey" https://kpmg.com/us/en/articles/2025/ai-quarterly-pulse-survey.html

  12. Evident, "Evident AI Index for Banks 2025" https://evidentinsights.com/ai-index/

  13. Accenture, "Banking in the Age of AI" https://www.accenture.com/content/dam/accenture/final/accenture-com/document-2/Accenture-Age-AI-Banking-New-Reality.pdf

Research on Work, Productivity and Project Failure

  1. RAND, "The Root Causes of Failure for Artificial Intelligence Projects and How They Can Succeed" https://www.rand.org/pubs/research_reports/RRA2680-1.html

  2. Brynjolfsson, Li and Raymond, "Generative AI at Work" https://academic.oup.com/qje/article/140/2/889/7990658

  3. Dell'Acqua et al., "Navigating the Jagged Technological Frontier" https://aiinstitute.hbs.edu/navigating-the-jagged-technological-frontier/

  4. Dillon, Jaffe, Immorlica and Stanton, "Shifting Work Patterns with Generative AI" https://www.nber.org/papers/w33795

  5. Brynjolfsson, Rock and Syverson, "The Productivity J-Curve" https://www.aeaweb.org/articles?id=10.1257/mac.20180386

Disclosures from Financial Institutions

  1. DBS Group, "CIO statement - Annual Report 2025" https://www.dbs.com/annualreports/2025/cio-statement.html

  2. JPMorgan Chase, "Annual Report 2025" https://www.jpmorganchase.com/content/dam/jpmc/jpmorgan-chase-and-co/investor-relations/documents/annualreport-2025.pdf

  3. JPMorgan Chase Commercial & Investment Bank, "Letter to Shareholders - Annual Report 2025" https://www.jpmorganchase.com/ir/annual-report/2025/ar-ceo-letter-petno-rohrbaugh

  4. Goldman Sachs, "Annual Report 2025" https://www.goldmansachs.com/investor-relations/financials/current/annual-reports/2025-annual-report

  5. Deutsche Bank, "Annual Report 2025" https://investor-relations.db.com/files/documents/other-presentations-and-events/2025/Annual-Report-2025.pdf?language_id=1

  6. ING Bank, "Annual Report 2025" https://ing.com/binaries/content/assets/documents/annual-reports/2025-ing-bank-nv-annual-report.pdf

  7. Commonwealth Bank of Australia, "Annual Report 2025" https://www.commbank.com.au/content/dam/commbank-assets/investors/docs/results/fy25/2025-annual-report.pdf