Financial institutions across Asia are recalibrating their approach to artificial intelligence, shifting focus from experimentation to resilience, governance and operational trust, as the technology becomes embedded in core systems.
Artificial intelligence is moving deeper into banking operations, but institutions are finding that deploying the technology is the easier part. The harder task is ensuring it behaves predictably under pressure.
At a recent industry discussion with senior banking executives and technology leaders, the attention centred less on innovation and more on control — specifically, how to manage risk as systems grow more complex.
Moderated by Anton Ruddenklau, Head of Financial Services Advisory at KPMG, a global audit and advisory firm. Panelists include Marlon Sorongon, Chief Information Security Officer, Maybank Philippines; Abhijit Dey, Senior Vice President – Product Lead AI and API Banking, Axis Bank; Yan Zhao, Head of Observability for Asia at Splunk, and Sid Govindu, Global GTM Strategist – Observability at Splunk
“There’s been some lessons learned,” said Ruddenklau, pointing to what he described as a growing “zone of disillusionment” around AI outcomes.
Banks, he suggested, are now shifting focus from experimentation to resilience, and whether AI can be trusted to operate reliably at scale. At the same time, banks are modernising their architecture to support AI while protecting core systems.
Customer impact first, technology second
For banks, the starting point is not technology but business impact. “The good question is, if this system fails, what is the impact to our customers?” said Marlon Sorongon of Maybank Philippines.
Rather than prioritising systems based on age, Sorongon argued that institutions should focus on criticality, particularly where outages affect customers, regulatory obligations or revenue channels.
This separation allows banks to introduce AI capabilities while maintaining control over critical infrastructure. It also reflects a broader industry approach: layering new technologies on top of existing systems rather than replacing them outright.
Yet this creates its own complications. Transactions often move between legacy and modern environments, increasing operational complexity and making failures harder to diagnose.
Why resilience is no longer just about uptime
Sid Govindu, Global GTM Strategist for Observability at Splunk, said resilience is no longer defined by uptime alone. “Resilience is no longer just about uptime, but about how quickly you can understand and respond to increasingly complex systems,” he said.
In practice, that complexity is proving difficult to manage. A single transaction can pass through dozens of systems, each generating its own signals.
In one recent outage, Govindu noted that recovery was delayed not by a lack of data, but by an overload of information. Operations teams were forced to work across dozens of disconnected tools, making it difficult to identify the source of the problem quickly. He said engineers can spend more than an hour simply determining where a fault originated before remediation can begin.
Govindu argued that agentic AI could significantly reduce that process. “By using agentic AI, this can be reduced down to several minutes,” he said. However, he cautioned that AI introduces its own challenges, particularly around explainability and oversight. Many AI models still operate as “black boxes”, producing decisions that are difficult to interpret or audit.
“Explainability and oversight are quickly becoming regulatory expectations,” he said. This creates a tension at the centre of AI adoption: faster decision-making, but reduced transparency.
Juggling data fragmentation with regulatory pressure
Underlying these challenges is a persistent structural problem — fragmented data across modern and legacy systems. As Govindu of Splunk explained, “Any transaction will traverse both a modern stack and legacy mainframe systems.” Without a unified view across those environments, AI risks amplifying inconsistencies instead of resolving them.
Yan Zhao of Splunk Asia said open frameworks are emerging as a practical way to bridge this gap because they produce “auditable, vendor-neutral data” that aligns more closely with regulatory expectations. He noted that many banks are adopting hybrid models that combine open standards with proprietary AI tools while avoiding excessive dependence on a single vendor.
At the same time, regulators are taking a more active role in shaping how AI is deployed. Institutions such as the Bank for International Settlements are increasingly focused on whether AI-driven decisions can be traced, explained and audited. For banks, the issue is not only compliance, but also operational clarity and accountability.
Banks draw a hard line on AI accountability
Despite advances in automation, the question of accountability remains unresolved, and firmly human. “In banking, accountability cannot be automated,” Sorongon of Maybank Philippines said. “There must be a clear human ownership.”
Govindu of Splunk echoed the same view, arguing that governance and oversight cannot be outsourced and we must maintain “human in the loop” and rely on human judgement, particularly as AI systems begin making operational recommendations.
As AI systems take on more autonomous functions, banks are becoming increasingly cautious about the risks associated with speed and scale. “Autonomous AI operates at unimaginable speed — that’s powerful, but sometimes it’s also dangerous,” Sorongon explained.
Dey of Axis Bank raised similar concerns around data exposure, especially when external AI models are involved. “How are we ensuring this information will not be reused?” he asked, referring to the risk of sensitive banking data leaking beyond institutional control. As a result, many banks are taking a gradual approach to deployment. “We rather go slow … where a minimum amount of data is getting exposed,” Dey said.
The discussion reflected a broader shift in how banks view AI. Rather than treating it solely as a tool for acceleration, institutions are increasingly approaching it as a system that must be governed, monitored and constrained. As Ruddenklau of KPMG noted, trust remains central to banking: “If the banks are not trusted, there’s no reason to have them.”
AI is expected to play a growing role in banking operations, but speakers agreed that its adoption will depend on whether institutions can demonstrate that systems remain transparent, governable and accountable to human oversight.




