← Industries
Sector thesis · Financial district · dawn

Banking.

Acquire, personalise, and retain, on customer data that stays sovereign.

The terrain

In retail and wealth banking, the contest is for the customer relationship: acquiring the right clients, personalising every interaction, and keeping them from switching. That runs on transaction and behavioural data, the most revealing signal a person emits, so the marketing and personalisation stack is exactly the one that cannot cross an extraterritorial border.

Where the risk sits
  • R01Personalisation drifting into automated decisions under GDPR Art. 22 and consumer-duty rules
  • R02First-party consent and lawful basis for cross-sell on transaction data
  • R03Customer and behavioural data crossing extraterritorial jurisdictions (DORA third-party risk)
Forces reshaping banking

What's actually
reshaping the sector.

01 · Personalisation is the growth engine

DBS runs hyper-personalised nudges to customers and relationship managers as an always-on system, not a campaign, and the nudges to relationship managers alone drove a 16% lift in client engagement. That is the bar your customers are being taught to expect.

DBS Bank
02 · The revenue is in the relationship

McKinsey finds banks that centralise customer-value-based personalisation earn 5 to 15% higher revenue from campaigns, and shift the metric from products sold to retention and advocacy.

McKinsey
03 · It runs on a sovereign data platform

BBVA completed the global rollout of its ADA data-and-AI platform specifically to power generative-AI personalised customer services. The lesson: the personalisation is only as good, and as sovereign, as the data foundation beneath it.

BBVA
04 · Sovereignty is now regulated

DORA (live since Jan 2025) + EU AI Act high-risk (2 Aug 2026) + FiDA make where your customer AI runs a board-level decision. Europe's largest banks have read it that way: they are already funding sovereign, CLOUD-Act-free alternatives for themselves.

Retail Banker Int’l
Position

In banking, the customer relationship, not the core ledger, is where AI and sovereignty compound: personalisation runs on data too revealing to hand to a third-country model.

The business case

Win the customer on data a competitor can never see.

Retail and wealth banking growth is a personalisation problem now: acquiring the right customers, guiding the next best action, and keeping them from switching. Every one of those runs on transaction and behavioural data, the most revealing signal a person emits. A bank that lets that signal leave its perimeter has given away the one edge a rival cannot buy.

Personalise onboarding, cross-sell, and relationship management on sovereign, first-party data and you lift revenue and retention on the campaigns where a few points compound, without a transfer or consumer-duty problem. Run them on an opaque US API and you have handed a competitor the one signal that was yours alone.

We build the sovereign customer-data and personalisation stack: first-party acquisition, next-best-action, and RM copilots decisioned on EU compute, with frontier speed reserved for non-personal creative. In banking, the relationship is the franchise; sovereignty is how you keep it growing.

Workload placement

Where each AI workload
should live.

WorkloadPlacementRationale
Acquisition & onboarding personalisationSovereignBuilt on first-party customer data; belongs on EU compute.
Next-best-action & cross-sellSovereignDecisioned on transaction history that must not leave the perimeter.
Relationship-manager copilotsSovereignClient PII and portfolio context; long retention.
Marketing creative & campaign copyFrontierNon-personal, fast iteration.
The first engagement

What is yours to encode,
and what you are renting by accident.

Before any platform decision, one question settles the rest: how much of what your organisation knows can be written down precisely enough for a machine to act on it, and who ends up owning that writing. We run a short engagement to answer it, and it produces working artefacts rather than a report.

01
What know-how can be encoded?

Two artefacts come out of this. An operating ontology, the nouns: the entities, relationships, and states your business actually runs on, described once and precisely. And agentic skills, the verbs: the procedures, thresholds, and judgments your best people apply, written down, versioned, and testable instead of retold.

02
How much of the stack comes in-house?

A placement map addressed to the CTO or CIO office: what runs on your compute, what is bought, what is rented, who holds the keys, and what each costs. One test cuts through most of the debate. If a supplier vanished on a Friday, what stops working on Monday, and how long would it take you to replace it?

03
Which models should be yours?

Where an open-weight model fine-tuned or adapted on your own corpus beats a frontier call, where a small purpose-built model for one narrow task beats both, and where the frontier still earns its fee. Geographic sovereignty falls out of that answer rather than having to be argued for on its own.

What we would look for in banking
  • Credit and eligibility policy: the criteria, the exceptions, and who may grant them
  • Suitability and consumer-duty language, with the reasoning a regulator would ask for
  • Complaint handling: what counts as detriment, and the remedy ladder that follows
  • The relationship manager's playbook: which signal triggers which conversation
  • Fraud and financial-crime triage rules that today live in analysts' instincts
Models of your own

Transaction narratives are a corpus nobody else holds. A small open-weight model fine-tuned on your own decisioned cases beats a frontier call on classification, at a fraction of the cost, and never leaves the perimeter.

What you get back
  • +A register of encodable know-how, ranked by value and by how fast it decays
  • +A draft operating ontology in an open format, not inside a vendor's platform
  • +Two or three working skills, built and evaluated on your real work, not demonstrated on a slide
  • +A bring-it-in-house plan the CTO or CIO office can actually staff
  • +A model strategy: open weights, fine-tuning, purpose-built small models, and where the frontier stays
  • +An evaluation harness that shows it works, and keeps showing it after we leave

This is a CTO and CIO office engagement, not a procurement exercise. Your own people have to end up running it, because the moment the encoding is delegated, the thing being encoded quietly stops being yours.

Palantir calls this layer an ontology, and the idea is right: a governed model of your objects, links, and actions that agents can act on. It lives inside their platform. 8090 will design, build, host, and maintain the software around it for you. Both are serious, and both leave the same question open. At the end of it, who owns the layer that holds your judgment? We build the same artefacts in open formats, on compute you control, and hand your CTO the keys.

The stack we deploy

The customer stack,
inside the bank.

The same four layers we ship in legal, instantiated for a bank. Here the application layer is built with you rather than bought off a shelf, and it belongs to you when the engagement ends.

01 · Application layer
Decisioning and relationship apps

A first-party identity and consent spine, a next-best-action console the marketing team can operate without a data scientist in the room, and a relationship-manager workspace grounded in the client's own portfolio and correspondence.

02 · Knowledge & skills
Product rules and house positions, encoded

Eligibility criteria, suitability and consumer-duty language, complaint handling, and tone of voice, written once as versioned skills the agents load, reviewable by compliance, rather than buried in prompts nobody can audit.

03 · AI operating layer
The harness

Routing by sensitivity: anything decisioned on transaction or behavioural data stays on sovereign compute by architecture, non-personal creative work goes to the frontier under zero-retention terms, and every call is logged against the customer record.

04 · Hardware & hosting
Where it runs

In your own data centre, on an isolated instance we operate on sovereign infrastructure, or on dedicated AI hardware inside the bank's perimeter for the models that score transaction data.

The application layer here is built for you, not bought. The pattern is the one we already ship, as a product, in legal.

How you run it

Four postures.
One codebase.

The same software in every posture, so a team can start hosted and end up air-gapped without a migration project. You move along the ladder when you decide to, not when a contract renews.

01 · We host it, briefly
Pilot

Your stack stood up on our infrastructure in days and pointed at real work, so it is judged on your matters rather than on a demo. The pilot fee credits against the hardware when you migrate.

Teams that want proof before capital expenditure.

02 · One computer in your building
Self-hosted

The open-source cores installed on a machine you own, by a script anyone can read first. No account with us, no telemetry, no phone-home. Code flows one way, from us to you, and only when you ask for it.

Small teams, and anyone who wants to inspect the source before trusting it.

03 · We operate, you hold the keys
Managed

An isolated instance per client on sovereign infrastructure, European by default, run, patched, and monitored by us, with the security and backup credentials in your hands rather than ours.

Organisations without an infrastructure team to spare.

04 · Your own hardware, air-gappable
Appliance

Dedicated AI hardware inside your building, with the applications and the open-weight models you choose installed and tested before it ships. It runs with the network unplugged, and it keeps working whatever happens to us.

In banking the appliance usually sits beside the analytics estate, scoring the data that is too revealing to send anywhere.

Work that cannot leave the building, ever.

Around it
  • +Deployment and hardening, on your machines or ours
  • +Knowledge encoding: your playbooks and positions compiled into installable skills
  • +Model selection, tuning, and an evaluation harness built on your own work
  • +Remote maintenance and monitoring at a published monthly rate
  • +Updates as ordered, readable migrations, always after an encrypted backup
  • +Backup, restore, and continuity drills you can actually rehearse
  • +Enablement for the people who use it daily, not only for IT
  • +Governance evidence: routing logs, audit trail, and an attestation pack
What we can never do
  • Reach into your instance or see your work
  • Revoke your software or disable a licence remotely
  • Force an update on you

Not promises. Consequences of the architecture: your keys and your data are generated on your machine and stay there, and nothing calls home.

Sector brief

Get the full
banking
placement map.

We send a sector-specific brief with workload-by-workload placement guidance and a reference architecture for sovereign deployment.

Request this research

Banking placement map