惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
Last Week in AI
Last Week in AI
Blog — PlanetScale
Blog — PlanetScale
V
Visual Studio Blog
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
博客园 - Franky
IT之家
IT之家
博客园 - 叶小钗
Engineering at Meta
Engineering at Meta
The GitHub Blog
The GitHub Blog
雷峰网
雷峰网
腾讯CDC
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
人人都是产品经理
人人都是产品经理
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
博客园_首页
G
Google Developers Blog

PYMNTS.com

Treasury Calls for Programmable Financial Enforcement Across Crypto DeepSeek Seeks $20 Billion Valuation as Tech Giants Weigh Investment Google Accelerates Agentic AI Shift With New Enterprise Platform OpenAI Begins Briefing Governments on Cybersecurity Capabilities DeFi Security Suffers New Blow With $3 Million Volo Exploit Uninvited Users Access Anthropic’s Mythos AI Model Block and Uber Expand Partnership Across Several Global Markets OpenAI Pledges $1.5 Billion to PE Enterprise AI Project Podcast: Inside the $9 Billion DeFi Hack That’s Shaking Crypto’s Foundations Synchrony CFO Flags Momentum in Spending and Credit Banks Risk Slowing the Emerging Middle Market Firms Driving Growth Paysafe Expands Digital Wallet Availability Across 18 European Markets Bad Data Can Break Good AI in Payments 50% More Digital Shopping Days Put Parents at the Center of Retail’s Shift 65% Call Insurance Essential. Why Most Spending Isn’t So Clear-Cut Amazon Recasts Marketplace Fraud as a Broader Trust Problem Capital One’s Q1 Shifts Attention From Spending to Strategy Lawmakers Question JetBlue About Surveillance Pricing Allegations Small Businesses Stop Chasing Amazon on Delivery Speed Google Embeds AI Into Chrome for 3.5 Billion Users Adobe Plans Outcome-Based Pricing for New AI Product Suite UnitedHealth Spends $1.5 Billion on AI and Wants Double Back MiCA Forces Crypto Firms to Get Licensed or Get Out Prediction Market Kalshi Targets Crypto Perpetuals New York Sues Coinbase and Gemini Over Prediction Markets Amazon and Anthropic Deepen Ties With Investment and Hardware Pact Agentic B2B Is Here. Are Your Contracts and Invoices Ready? Apple Hardware Leader John Ternus to Succeed CEO Tim Cook The Web Is Gaslighting AI Agents and Nobody Can Tell OCC Enters the Interchange Fight and Raises the Stakes
Data Mobility Across the API Economy Is Rewriting Bank Se...
PYMNTS · 2026-05-13 · via PYMNTS.com

 | 

data security, banking

Highlights

Banks face growing data governance risks as APIs, AI tools and FinTech integrations move sensitive information far beyond traditional banking perimeters.

A recent SEC filing showed how an unauthorized AI application exposed material customer data, underscoring the security challenges created by interconnected banking systems.

Financial institutions are replacing perimeter-based security with continuous monitoring, identity controls and AI-powered cybersecurity to manage constant data movement.

In the age of application programming interfaces (APIs) and artificial intelligence (AI), data governance is becoming harder for banks than perimeter defense.

After all, the infrastructure powering vital advances like instant payments and personalized financial services is also creating sprawling new security risks as banks connect to AI tools, FinTech solutions and third-party APIs for the thousands of financial software integrations on offer in today’s landscape. Information that once lived inside monolithic core banking systems now flows continuously across interconnected software layers designed for speed, personalization and real-time decision making.

A recent disclosure filed with the U.S. Securities and Exchange Commission (SEC) this month by U.S. commercial bank Community Bank illustrates the growing challenge of data sprawl for banks, particularly smaller and mid-size lenders looking to stand up digital innovation in order to compete with larger peers. The bank, a wholly owned subsidiary of CB Financial Services, voluntarily disclosed that an amount of sensitive customer information determined to be “material” had been exposed through an unauthorized AI application used within its environment.

The filing underscored an uncomfortable reality facing the industry: the modern banking perimeter is no longer clearly defined. The issue is not simply that banks are adopting more technology. It is that the architecture of modern banking increasingly depends on constant data mobility.

Read more: The End of the Artisanal Hack: How AI Industrialized Cybercrime 

Why Banks Are Losing Sight of Their Data

For decades, banks operated on a relatively simple security premise: protect the perimeter, secure the core and tightly control access to customer data. Sensitive information largely stayed within institution-owned systems, moving slowly through carefully managed channels and governed by rigid internal protocols. That model no longer exists.

Advertisement: Scroll to Continue

Open banking frameworks, embedded finance partnerships and real-time payments have accelerated API adoption across the industry. Financial institutions now routinely integrate with FinTech providers for everything from fraud prevention and lending to customer onboarding and treasury management. At the same time, generative AI tools are rapidly becoming embedded inside employee workflows, customer service operations and internal analytics platforms.

Each integration creates value. Each integration also creates another potential exposure point. The challenge of defending, and even just governing, these exposure points is particularly acute for mid-sized and regional banks operating with leaner compliance and cybersecurity resources than the largest national institutions.

For example, across the credit union (CU) landscape, PYMNTS Intelligence research found that fraud now occurs across the full CU member life cycle, from account opening and onboarding to authentication and transaction activity. CUs must now defend every interaction point rather than a single stage, and 77% of CUs have experienced unauthorized network access in the past year.

The same technologies driving operational efficiency and customer personalization also increase organizational exposure. AI systems require data access to generate value. APIs require connectivity to function effectively. Modern banking infrastructure is inherently designed for openness and interoperability.

See also: The Enterprise Security Stack Is Moving to the Edge

The End of the Closed-Core Era

The real question is whether banks can establish governance models sophisticated enough to match the complexity of the ecosystems they now depend on. What has changed is the scale, speed and opacity of modern data movement. As customer data becomes increasingly distributed across external systems, governance itself is emerging as a competitive differentiator.

Rather than attempting to seal off every endpoint, many smaller institutions are shifting toward continuous monitoring models built around identity management, behavioral analytics and real-time visibility into data movement. Increasingly, the focus is less about defending a fixed perimeter and more about understanding how information flows across interconnected systems.

Data in the report “Embedding Security: Designing Fraud Risk Out of Business Transactions,” a March PYMNTS Intelligence Business Payments Tracker Series report in collaboration with WEX, reveals that nearly a quarter of banking CEOs (24%) are prioritizing AI investments for cybersecurity.

The broader banking landscape is also hoping that a rising security and data governance tide can lift all boats. PYMNTS covered Tuesday (May 12) how JPMorganChase is making nearly $14 million in philanthropic investments to support seven organizations that are combating fraud and scams through consumer awareness and real-time prevention.

Ultimately, the institutions succeeding in this transition are generally not those attempting to halt technological change. They are the ones redesigning governance around the assumption that data mobility is now permanent. Because in the API economy, the most important security question is no longer whether data leaves the bank. It is whether the bank still knows where the data went.