SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Indian banks push AI in production, but security bites

Indian banks push AI in production, but security bites

Fri, 4th Sep 2026 (Today)
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

Zeta has published a survey finding that 70% of Indian banks and non-bank lenders surveyed are running artificial intelligence in production. It found that security and data privacy are the main barriers to wider deployment.

The survey covered 40 CXOs across 18 banks and NBFCs, including Chief Information Officers, Chief Technology Officers, Chief Data Officers, Chief Risk Officers, and Chief Operating Officers. It suggests AI has moved beyond pilot projects in Indian banking, but remains concentrated in areas where outputs can be checked within existing controls.

Adoption was strongest in customer service, fraud and risk analytics, document processing, and software testing. The findings suggest banks have had more success deploying AI in bounded, reviewable tasks than in end-to-end workflows or consequential decisions.

The same pattern appeared in responses from operations leaders. Among Chief Operating Officer respondents, 88% identified retail lending as an area where AI is delivering meaningful impact, while 75% cited customer service and 63% pointed to current and savings accounts and back-office operations.

At the same time, the survey found that roughly four in ten Chief Data Officers could not yet identify a high-return use case within their own institution. Most surveyed institutions direct less than 10% of new-project technology spending to AI, indicating that spending remains measured even where deployment spans several functions.

Control over spend

Zeta's data suggests this restraint is linked more to governance and risk than to doubts about the technology itself. Security and data privacy scored 3.89 out of 5 as the leading barrier to broader adoption, while lack of return-on-investment clarity scored 2.0 out of 5, the lowest-rated obstacle listed.

Executive scepticism and employee resistance also ranked below skills and security concerns. The findings point to a sector that sees practical uses for AI but is moving cautiously on systems that would be allowed to act rather than simply assist.

On data readiness, 80% of Chief Information Officers and Chief Technology Officers said their institutions' data environments were mostly ready for AI at scale, but none described them as fully ready. The main constraints were not the existence of data, but whether AI systems could use it easily and safely.

Among those respondents, 61% cited insufficient labelled or training data, 53% pointed to privacy and consent issues, and 46% identified siloed data. Two-thirds said they were already using or piloting AI to improve or enrich their data.

Infrastructure gap

The survey also distinguishes between connected technology estates and infrastructure that can support AI repeatedly. Real-time data platforms and API-first architectures had adoption of 79%, while core modernisation and cloud stood at 64%.

By contrast, advanced analytics and MLOps were reported at 43%. That gap matters because these tools are used to deploy, manage, and monitor AI workloads repeatably rather than as one-off projects.

A similar drop-off appeared in software engineering. Among Chief Information Officers and Chief Technology Officers, 80% said they were using AI in testing and quality assurance and 60% in code generation, but only 40% reported use in code review. The figure fell to 30% each for specifications and documentation, deployment and continuous integration and delivery, and incident detection.

The survey indicates adoption weakens as AI moves closer to actions that change systems or require direct execution. In effect, banks appear more comfortable using AI to produce drafts, suggestions, or test outputs than to carry out tasks with immediate operational consequences.

Governance builds

Risk and governance are also emerging as central themes in the next stage of adoption. At least 60% of Chief Risk Officers identified AI-led credit-risk models, predictive early-warning systems, and real-time fraud decisioning as leading priorities over the next 18 to 24 months.

Around 60% said responsible AI frameworks were under development, but none reported organisation-wide implementation. Only 20% described model-risk management as very mature, suggesting governance remains a work in progress as AI is prepared for more sensitive uses.

The survey also found that AI is changing job design more quickly than headcount. Half of operations leaders said AI-led productivity gains were likely to free up capacity for redeployment into higher-value work, while none expected workforce reductions above 20%.

Skill-building, however, remains uneven. Respondents rated specialist hiring at 3.33 out of 5 and external partners at 3.0 out of 5 as the main ways of building AI expertise, while internal capability development scored just 1.0 out of 5, the lowest reading in the survey.

The findings describe a sector that has moved from experimentation to selective production, but has yet to make deployment routine across institutions. "Indian banks have shown that AI creates value in production. The next challenge is making that success repeatable, and the survey is clear about what stands in the way: not conviction, but control," said Sivaram Kowta, President, Zeta India.

"Banks have connected their core systems. The next step is to make them usable by AI, with banking context and permissions built in, and to put in place the identity, policy, and audit controls that let risk and security leaders say yes with confidence. Banks that build these foundations once will find that the tenth deployment costs a fraction of the first," said Kowta.