Europe’s Digital Banking: Slowed by Complex Rules
European banks have a clear opportunity to modernize services with artificial intelligence and cloud computing, but uptake remains limited. Fragmented regulatory regimes, overlapping reporting duties, and uneven national interpretations create compliance overheads that raise costs and slow rollout of AI-driven products such as fraud detection, credit scoring, and automated customer servicing.
Overcoming Regulatory Friction
Boosting Cloud and AI Investment
Simpler rules and fiscal incentives would encourage banks to commit to scalable cloud platforms and to fund production-ready AI. Public procurement partnerships and shared infrastructure initiatives can help build a European cloud ecosystem that reduces vendor lock-in and supports model training at scale. Clear, proportionate guidance on model validation and third-party risk will shorten procurement cycles and cut deployment risk.
Building Coordinated Cyber Resilience
Financial services face evolving threats, including AI-assisted attacks. A single EU reporting channel for major cyber incidents and harmonised incident thresholds would reduce duplicative filings and speed cross-border response. Common playbooks, regular table-top exercises, and shared threat intelligence would make banks more resilient while keeping regulatory burden predictable.
Harmonising AI and Data Legislation
The interaction of the AI Act, DORA, GDPR and national rules creates legal uncertainty, especially for models trained on sensitive data or operating as common foundational services. Treating common models as high-risk without aligned guidance raises operational costs. A risk-based, proportionate approach to data processing, clearer rules on lawful bases for model training, and coordinated supervisory expectations will lower compliance friction and enable safer innovation.
The Path to a Competitive Digital Future
Simpler, consistently implemented rules would let European banks deploy AI at scale, cut operational costs, and compete globally. Policymakers and industry should prioritise harmonisation, joint infrastructure investment, and aligned incident reporting so that regulation supports secure, efficient digital banking rather than fragmenting it.



