AI as the Operating Layer: What It Takes to Run AI Inside Regulated Fintech
Maxim Ivanchenko explains the controls, audit trails, vendor oversight and governance regulated firms need as AI moves into the operating layer.
Read More →Revolut is using ChatGPT to strengthen its paid plans. Chime is cutting jobs as it reorganises around AI. BaFin is preparing to examine how financial institutions use the technology. The bigger story is no longer what AI can add to a fintech app, but what it is beginning to change underneath it.
AI is moving beyond customer-facing features and beginning to reshape how fintech companies distribute products, organise their teams and meet regulatory expectations.
For the past two years, most financial companies have talked about artificial intelligence as a visible improvement to the product or an efficiency tool for the people working behind it. The examples were usually familiar and fairly contained: a chatbot answering customer questions, a budgeting tool making sense of spending patterns, a compliance system prioritising suspicious activity more effectively, or an employee using AI to get through routine administrative work more quickly.
The developments of the past week were more revealing because they placed AI in three very different parts of the financial-services business. Revolut added ChatGPT Go to the benefits included in its paid plans, using AI as another reason for customers to remain within its subscription ecosystem. Chime, by contrast, linked the technology to a reduction of roughly 10% of its workforce and to a broader shift towards smaller teams and a flatter organisation. In Germany, BaFin set out how the use of AI by banks, insurers and other regulated firms is moving more clearly into the supervisory perimeter. (Revolut; Reuters; BaFin)
These announcements were not connected, nor do they describe the same use of the technology, but taken together they point to a shift that is easy to overlook when every AI story is treated as another product launch. Artificial intelligence is beginning to influence how fintech companies attract and retain customers, how they structure their organisations and where regulators expect responsibility to sit when automated systems begin to shape financial outcomes.
The chatbot is becoming the least interesting part.
Revolut’s partnership with OpenAI may look like the least complicated of this week’s three developments, but it says something important about where competition in consumer fintech is heading. The company is offering ChatGPT Go to millions of eligible customers, with the length of access determined by the Revolut plan they hold, thereby adding a recognisable consumer AI product to an increasingly broad package of paid benefits. (Revolut)
This is not an attempt to place ChatGPT inside the financial infrastructure itself. It will not maintain account balances, settle transactions, replace the core ledger or make compliance decisions. The strategic logic is more familiar: Revolut is using another company’s product to make its own subscription more valuable and, ideally, less likely to be cancelled.
That matters because the original digital-banking proposition has become much easier to imitate. The first generation of challengers won customers by making recognisably financial activities less cumbersome: cards were easier to control, foreign exchange was cheaper, onboarding was faster and fees were clearer. Those improvements were once distinctive enough to persuade customers to try an alternative to their existing bank. Today, however, instant notifications, virtual cards, spending categories and a reasonably smooth mobile journey are no longer unusual. They are the minimum expected from any serious financial app.
The next phase of competition is therefore less about one outstanding banking feature and more about the overall value of the relationship. Leading platforms are assembling bundles in which payments and accounts sit alongside travel benefits, insurance, subscriptions and services that may have little direct connection to finance. No single element has to justify the price on its own; the bundle only needs to feel sufficiently useful that cancelling it would mean giving up too much at once.
ChatGPT fits this model particularly well because customers already understand what it is and attach a value to it. Revolut does not need to educate users about a small proprietary AI feature or convince them that it might be useful. It can place a familiar product inside its paid plans and use the demand around that product to reinforce the appeal of the wider subscription.
In that sense, the real asset being monetised is not AI but distribution. Revolut already has the customer relationship, the payment method and a prominent place on the customer’s phone. That gives it the ability to become a channel through which users obtain services that extend well beyond banking.
The model is commercially attractive, although it adds a layer of operational complexity that is largely invisible from the customer’s side. Eligibility has to be linked correctly to the customer’s plan, while upgrades, downgrades and cancellations must be reflected across two separate services. Promotional periods, billing arrangements, failed activations and support responsibilities all need to be coordinated, and when something goes wrong the customer is unlikely to care which company technically owns the broken part of the journey.
What appears in the app as one additional benefit is, behind the scenes, another commercial relationship, entitlement process, support obligation and external dependency. As these subscription bundles grow, the quality of the product will depend less on how much the fintech has built itself and more on how effectively it can assemble, govern and operate an ecosystem of services without making the underlying complexity visible to the customer.
Chime’s announcement takes the discussion in a more consequential direction because it is not about adding another benefit to the customer proposition, but about changing the organisation itself. The US fintech said it would cut roughly 10% of its workforce, affecting close to 150 employees, with chief executive Chris Britt arguing that AI was making it possible to operate with smaller teams, fewer layers of management and faster execution, while also changing the mix of skills the company needs. (Reuters)
For years, companies have described AI productivity in relatively reassuring terms. Employees would receive better tools, repetitive tasks would be automated and people would be freed to focus on work requiring more judgement. Chime’s decision moves beyond that narrative. The question is no longer simply whether the existing workforce can become more productive, but whether the company can be redesigned around the assumption that fewer people will be needed to do the work at all.
For a fintech, the appeal is easy to understand. Digital financial businesses are expected to grow quickly without inheriting the cost base of a traditional bank. They need to support more customers, transactions and products while proving that scale will eventually improve margins. If AI allows a company to reduce management layers, shrink operational teams and move faster, it appears to offer exactly the kind of operating leverage investors have been asking for.
The harder part is determining what has genuinely become unnecessary. Financial operations contain a great deal of work that can look inefficient when reduced to a list of tasks: reviewing similar alerts, checking documents, investigating exceptions or reconciling differences between systems. Much of this can and should be automated, and the strongest institutions have been doing so for years. Yet not every apparent inefficiency is a flaw in the process.
An experienced analyst may notice that an otherwise ordinary transaction is unusual for a particular customer. An operations specialist may recognise that a recurring discrepancy points to a specific integration issue. A compliance employee may understand why a technically valid document still does not make sense in the wider context of an application. This kind of knowledge is often spread across individuals and teams rather than captured neatly in procedures or workflow diagrams.
That creates the central risk in Chime’s approach. A company may remove manual work and discover later that it also removed the people who understood the exceptions. AI may support a leaner organisation, but that organisation still needs enough expertise to recognise when the automated process is wrong, especially because the most serious failures rarely begin with the standard case. They emerge from unusual combinations of customer behaviour, incomplete data and system errors that were never anticipated when the workflow was designed.
For that reason, AI productivity cannot be measured only by the number of tasks automated or roles eliminated. A more meaningful test is whether decisions are still being challenged, whether unusual cases reach the right people and whether the organisation retains enough knowledge to recover when the technology behaves in ways no one expected.
Smaller teams can be faster. They can also leave less room for error.
BaFin’s position shifts the discussion from commercial opportunity to accountability. The German regulator has said that it will monitor the use of AI by banks, insurers and other financial firms, particularly where these systems are embedded in the delivery of regulated services, while also working through how that oversight will fit within its responsibilities under the European AI Act. (BaFin)
The significance of this is not that artificial intelligence has suddenly entered a regulated environment. Financial institutions were already expected to manage operational risk, data quality, outsourcing, consumer protection and automated decision-making, regardless of whether a particular system was described as innovative. What is changing is that AI is now being treated more explicitly as a distinct source of risk, with its own questions around governance, explainability and control.
Once a model begins to influence how a customer is treated, how a transaction is assessed or how a regulated decision is reached, the institution must understand far more than the software’s intended function. It needs to know which data the system relied on, whether that data was suitable for the decision, how the model was tested, who approved its use and how errors are identified. Where the consequences are material, there must also be a clear route for human review.
The most important point is that the institution remains responsible for the outcome, even where the technology itself is supplied and operated through a chain of third parties. A bank may buy software from one vendor, which incorporates a model developed by another, draws information from several internal systems and passes its output to an outsourced operations team. An employee may then use that recommendation as part of the final decision.
No single participant controls the entire process, but the regulated institution still stands behind the result.
That is why AI governance cannot be separated from vendor oversight, data governance, access controls and operational design. Assessing the model in isolation is not enough; the institution must understand how it behaves within the actual workflow in which it is used, including how data enters the process, how outputs are acted upon and where responsibility changes hands. A reputable provider may reduce some risks, but it cannot assume responsibility for the institution’s customers, its regulatory obligations or the consequences of deploying the system poorly.
AI may accelerate the decision. It does not remove the need to explain it.
The conversational assistant is likely to remain the most visible expression of AI in financial services because it is immediately understandable to customers and easy for institutions to demonstrate. A user asks why a payment is still pending, where an unfamiliar charge came from or what happened to a transfer, and the system turns the available information into a clear answer.
Used well, that can be genuinely helpful. The danger is that a fluent response can make the application appear to understand the customer’s entire financial relationship when, in reality, the relevant information is scattered across several systems that do not always agree with one another.
A fintech rarely operates from a single, complete source of truth. The core banking platform may hold the account balance and primary transaction record, while card activity comes from a processor, bank transfers pass through another provider and compliance restrictions sit in a separate system. Details of a previous complaint, manual review or unusual customer request may exist only in the support platform. An AI assistant can draw from some or all of these sources and present the result as one coherent explanation, but the quality of that explanation depends entirely on the quality, completeness and authority of the underlying data.
This is where fluency becomes a risk rather than merely a benefit. A conventional system that cannot find the relevant information may return an error or force the customer to contact support. An AI system may instead work with the incomplete context available to it and produce an answer that sounds entirely plausible. As the language becomes more natural and confident, it becomes harder for either the customer or an employee to notice that an important part of the picture is missing.
For that reason, the adoption of AI makes strong infrastructure more important, not less. A reliable financial assistant needs to know which system contains the authoritative record, whether the information is current and what the customer is permitted to see or do. It must work with accurate customer and transaction data, respect account restrictions and permissions, and record any action it initiates in a way that can later be traced and reviewed. In some cases, the action should also be reversible.
The challenge, therefore, is not simply to connect an AI model to as much data as possible. It is to ensure that the system understands that not all data is equally reliable, current or relevant. That distinction may be easy to overlook in a polished demonstration, but it becomes unavoidable once the assistant is dealing with real balances, blocked payments and regulated customer journeys.
An elegant interface can make fragmented infrastructure appear coherent without actually resolving the fragmentation underneath. That may look like progress until the assistant explains the wrong balance, gives an incorrect reason for a blocked transfer or suggests an action the customer is not authorised to take. At that point, the customer does not see an experimental model working with imperfect data. They see their financial provider getting something important wrong.
Most fintech companies will eventually arrive at a similar set of visible AI capabilities. Their apps will summarise transactions, categorise spending, explain documents and answer routine questions, but access to capable models is becoming too widespread for a generic assistant to remain distinctive for very long.
The more durable advantage will come from what happens deeper inside the business, where AI is applied to complete workflows rather than isolated tasks. In onboarding, for example, extracting information from an identity document is useful, but the real value lies in comparing that information with the application, spotting inconsistencies, assessing which findings actually matter and presenting the case to an employee with the relevant evidence already organised.
Transaction monitoring raises the same issue. A model may identify patterns that static rules miss, but a more sophisticated alert is only valuable if an investigator can understand why it was generated, inspect the underlying activity and record a decision that can later be defended. Without those supporting steps, better detection may simply produce a more complicated backlog.
Customer support makes the distinction especially clear. A basic assistant can answer a general question. A deeply integrated system can securely identify the customer, inspect the relevant account and transaction data, explain what happened and carry out a controlled action within clearly defined limits. The first is an additional feature; the second changes how the service is actually operated.
That kind of redesign is difficult because it crosses system boundaries and redistributes responsibility between people and technology. It depends on reliable records, precise permissions and an audit trail that remains useful after the interaction has ended. It is also far harder for competitors to copy, because the advantage lies not in the model itself but in the operating processes built around it.
The visible AI interaction is only one layer. Reliable use depends on permissions, operational workflows, core records and clear human accountability.
Revolut, Chime and BaFin are all responding to the same technology, but from very different positions. Revolut sees AI as a distribution tool: because it already owns a large and active customer relationship, it can use a high-profile service such as ChatGPT to make its paid plans more attractive. Chime is looking for operating leverage, betting that smaller teams supported by AI can move faster and improve margins. BaFin, meanwhile, is focused on accountability and on whether financial institutions can still understand, govern and explain the systems on which they increasingly depend.
Each of those objectives makes sense in isolation. The difficulty lies in pursuing them at the same time without weakening the business elsewhere. A fintech can broaden its subscription bundle, but every new partner creates another dependency to manage. It can reduce headcount, but may also lose employees who understood the exceptions, workarounds and informal controls on which daily operations quietly relied. It can automate more decisions, but then needs stronger processes for review, escalation and explanation.
The danger is that companies optimise what is easiest to count. Subscription growth is visible, headcount savings can be reported and faster decision times can be demonstrated. It is much harder to measure whether the organisation has become more fragile, whether important knowledge has disappeared or whether customers are receiving confident answers based on incomplete information.
Those weaknesses rarely show up in the standard case. They tend to remain hidden until an unusual customer, a failed integration or an unexpected model output exposes them.
Access to advanced AI models is no longer the difficult part. Fintech companies can now add conversational tools to an application, embed AI into an employee workflow or automate parts of an existing process without building the underlying technology themselves. The harder work begins when they have to decide where the system’s authority should end.
That means defining which information the model can access, which decisions it may make independently, what must be recorded and when human review is mandatory. It also means preparing for the most difficult case: an output that is convincing, useful in many situations and still wrong when it matters.
The organisational consequences are just as important. Some manual processes may genuinely disappear, while others will need to be redesigned around a different division of responsibility between people and software. Companies must also consider who will retain enough practical knowledge to challenge the system once the employees who previously performed the work are no longer there.
These questions reveal far more about a fintech than the quality of its chatbot. They show whether the company’s data is reliable, whether its systems are properly integrated, whether accountability is clear and whether the organisation can recognise and correct its own mistakes.
This week, AI was used to make a subscription more attractive, support a leaner organisational model and define a new area of regulatory scrutiny. That is why fintech’s AI race is no longer primarily about visible features. The next advantage will belong to companies that can use the technology effectively without losing sight of the institution, controls and people that must still stand behind it.
Customers will see the intelligence. They will still expect the financial provider to stand behind every answer.
This article does not constitute legal advice. It reflects the operational perspective of a team that has helped launch and support more than 100 regulated financial businesses.