Everyone bought the same model
When BBVA puts ChatGPT on 120,000 desks and JPMorgan on 200,000, the frontier model stops being a differentiator. It becomes electricity.
In the space of a year the frontier model went from scarce to ambient. BBVA rolled ChatGPT Enterprise to almost all of its ~120,000 employees; JPMorgan's LLM Suite reached the order of 200,000; DBS attributes around S$1bn of 2025 economic value to AI across 430+ use cases. When every competitor has the same models on every desk, the model is no longer where the advantage lives, it is the new baseline, available to anyone with a contract.
This is the banking expression of the Reset: capability has been commoditised. The interesting question is no longer which model a bank uses, but whether the bank can feed it, and that turns out to be a far harder problem than buying a licence.
The bottleneck is underneath
Ask any bank's AI leaders where their programme stalls, and the answer is the same: the data. Not the model.
The WEF and Accenture's 2026 AI Playbook for Financial Services found that data analytics is the sector's number-one AI focus area, at 68% adoption, ahead of GenAI and agentic AI. The reason is blunt: agents and copilots can only act on data that is unified, governed, and real-time, and most banks' customer, transaction, and risk data is fragmented across decades-old cores. ING has been explicit that it is rewriting core systems because, without that groundwork, even the best AI projects end up as “cosmetic patches on 30-year-old logic.”
This is why the leaders treat the data foundation, domain-owned data products, federated governance, a unified view of customer and risk, as the actual programme, and the model as a detail. Whoever eliminates the silos first earns the ability to build at fintech speed; everyone else runs pilots that never reach production. The chart's lesson is the whole thesis: the value has moved from the model layer to the layer beneath it.
Share of banking leaders citing each as a primary AI focus area; the model layer is not the constraint, the data foundation is. Source: WEF/Accenture AI Playbook for Financial Services 2026.
And the EU made that foundation a sovereign one
In Europe a second shift compounds the first: where and under whose jurisdiction that data foundation runs is now a regulated, board-level decision.
DORA has been in force since January 2025, demanding documented cloud-exit strategies and control over critical ICT third parties; the EU AI Act's high-risk obligations land on 2 August 2026; and FiDA will turn open finance into permissioned, API-served data products. Stacked together, they make the architecture question, residency, exit, auditability, jurisdiction, unavoidable. And residency is not the same as sovereignty: data sitting in a Frankfurt region of a US-headquartered provider remains reachable under the US CLOUD Act, which Standard Contractual Clauses cannot cure.
Europe's largest banks have read the signal. A syndicate including BNP Paribas, Crédit Agricole and HSBC backed Mistral with €830m of debt financing specifically for self-hosted, EU-data-residency, CLOUD-Act-free deployments. The message is unambiguous: the data foundation that matters is not just integrated and governed, in Europe, it must be sovereign, or it is a liability waiting for an audit.
“Every bank can buy the same model. None can buy your data, which is exactly why the integrated, governed, sovereign data foundation is the only advantage left to build.”
Build the foundation before you buy the agent
Four moves to make the data foundation, not the model, your bank's actual AI strategy.
Stop measuring AI maturity by model access and start measuring it by data readiness: can you produce a unified, governed view of a customer and a risk position in real time? Most banks cannot, and that gap is the real roadmap.
Build the foundation as domain-owned data products with federated governance, on infrastructure whose residency, exit, and jurisdiction you can prove, so the same architecture that satisfies DORA and the AI Act is the one that powers your agents.
Place the sensitive, high-volume workloads, AML, KYC, credit decisioning, on sovereign inference first, where their auditability is straightforward, and keep the frontier to the non-personal edge. Then treat every new AI use case as a data-and-placement decision, not a model decision. The bank that builds the foundation owns its AI; the one that keeps buying models rents a capability it cannot feed.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.