AI Without Regret: Three Imperatives for Banks to Unlock Real Value


In this column, authors comment on economic and financial topics.


Artificial intelligence (AI) has become a core priority on virtually every strategic agenda, with executive teams and boards actively engaging in discussions around generative AI, agents, and new applications. Yet a gap persists in many organizations between enthusiasm and measurable impact: initiatives generate visibility, but rarely business value.

Studies by MIT, BCG, and Deloitte all point to the same conclusion: the bottleneck is rarely the technology itself, but rather integration, governance, and accountability. In regulated environments such as Swiss banks, an additional layer of complexity arises—every new technology must meet strict requirements for security, traceability, and compliance, not only in pilot phases but in day-to-day operations.

From a Data & Analytics leadership perspective, this tension is evident daily: an AI prototype can be demonstrated quickly. But if the use case is not properly embedded legally and technically—and if operations lack clear guardrails—it remains a flash in the pan.

«A secure AI environment is the price of entry—without guardrails, there is no viable use case.»

Cutting through the AI hype brings three key imperatives into focus—helping decision-makers in regulated organizations make fast, visible progress without compromising security or traceability: enable, embed, and scale.

Enable: Start Securely

In regulated environments, a secure AI setup is the prerequisite. Without clearly defined boundaries, access paths, and controls, there is no viable use case—and no legitimacy to experiment quickly. This is not bureaucracy; it is the condition that allows teams to operate in the first place.

This includes secure, validated connections to models that do not «call out» to unknown endpoints but are fully documented and logged. This means establishing secure, validated model connections that prevent calls to unknown endpoints and ensure full documentation and logging. It also requires clear data governance rules: a living data classification framework and defined policies on which data can be processed in which scenarios. Finally, reusable technical patterns are required—such as retrieval-augmented generation (RAG) for research or extraction—along with simple validation mechanisms, ideally standardized test cases to ensure output stability. 

The goal is not perfection from day one. What matters is a defined starting path: a setup where a team can develop an idea on Monday and shortly thereafter run it within a secure framework—without a marathon of approvals. Such a target architecture can be built within weeks and can reduce time-to-first-use-case to under 90 days.

Embed: Make It Operational

Many banks remain stuck in pilot mode because the transition to production is considered too late—or not at all. A pilot means “it works locally, in a niche.” Production means scalable, resilient, and secure.

This requires operational standards for development, testing, deployment, and monitoring—along with evidence that can be provided when needed. The shift in perspective is clear: AI becomes critical infrastructure. What matters is not the most impressive demo, but a stable and auditable operation.

In practice, this means defined quality and approval gates before deployment into banking operations. Monitoring—including drift and robustness metrics—is not optional but standard where risks warrant it. A lean «evidence kit» must be available for audit and control functions, demonstrating how risks are managed and outcomes monitored. Governance over risk and accountability must be clearly defined—as much as necessary, as little as possible.

«AI is becoming critical infrastructure: approval gates, monitoring, and an evidence kit make impact auditable.»

While this may sound like «more process,» in practice it is the lever that builds trust—internally and externally—and enables the transition from pilot to production in the first place.

Scale: Deliver Impact

The most common misconception in AI programs is confusing activity with impact. «10,000 prompts» is activity. Impact only occurs when a business owner is accountable for concrete performance metrics—and those metrics improve measurably.

«Impact—not activity—matters: scale only what demonstrably creates business value; stop everything else.»

In a Swiss banking context, this translates into tangible outcomes: faster client interactions and compliance case handling, a reduction in inbound calls through AI-supported services, and higher straight-through processing (STP) rates as more transactions are executed without manual intervention.

To avoid turning this into a wish list, discipline is required along two dimensions:

Portfolio focus instead of use-case proliferation: Rather than launching countless initiatives in parallel, organizations need a small, prioritized portfolio with clear business ownership and defined outcome targets—ideally structured along a timeline akin to a product roadmap. Every few weeks, a hard decision must be made: scale or stop. This prevents resources from being tied up in initiatives that look promising but fail to deliver results.

Data craftsmanship over hype: Even in seemingly simple use cases—such as automated document extraction in credit processes—data quality determines success or failure.  Without clear data ownership, service levels for data quality, and stable identifiers, organizations end up with polished demos rather than operational maturity. When this foundation is in place, STP rates increase sustainably. 

What Executives Should Do Now

Organizations that say, «We’re not seeing impact yet,» should resist the reflex to launch more use cases. A more effective approach is to pause briefly and conduct an honest assessment based on a few key questions:

  • Foundation: Is there a defined baseline for secure operations—connectivity, logging, data pipelines, and data security «at rest» and «in motion»?
  • Production readiness: What quality gates, approval processes, metrics, and oversight mechanisms are required to ensure a successful transition into operations?
  • Portfolio & business value: Which use cases have clearly defined outcome targets and a named business owner?

Once these questions are answered, the focus should be clear: enable, embed, scale—with short validation cycles. Well-executed use cases with proven impact will always outperform loosely defined ideas. As the first results materialize, trust grows organically—creating the conditions to scale with greater confidence.


Norman Stürtz heads Data & Analytics at St. Galler Kantonalbank. Previously, he served as Divisional CDO at Credit Suisse (Switzerland) Ltd. and is the founder of Switzerland’s first CDO roundtable.

René-Michel Jost is a transformation leader focused on scaling AI impact. He is also a core member of the MIT-backed business community Gen AI Global.