My Advice to Banks on AI: Anna Nicolis of Sepanta

Anna Nicolis, Head of Strategic Operations at Sepanta, shares practical advice for bank executives on AI strategy, governance, and where banks are getting it wrong.

My Advice to Banks on AI: Anna Nicolis of Sepanta

Anna Nicolis, Head of Strategic Operations at Sepanta, brings a systems-thinking approach to enterprise AI, combining advisory work on regulatory positioning with hands-on product implementation. With a Master's in AI Ethics & Society from Cambridge and experience across financial services, compliance, and retail, she helps firms build governed AI systems that actually deliver measurable value.

My questions are in bold - over to you Anna:


Can you give us an introduction to you and an overview of your organisation?

I work at Sepanta, an operating system for enterprises. We build and run governed AI systems that scale, and we do it across environments as different as financial services, compliance, retail, consumer goods and supply chain. My role has two sides. One is advisory, where I help firms understand their regulatory and operational position to build the AI ROI business case. The other is product implementation.

The range of what we offer is quite broad. Finspector reviews and monitors financial promotions at scale. NuStream turns real shelf data into demand signals across large retail networks. Both run on the Sepanta platform, with the same governance and orchestration underneath.

Our CEO, Omid Paskeresesht, holds us all to one expectation: think in systems. I treat a model as one component inside a workflow, a control environment and a set of human decisions, and I judge it as part of that whole. That habit, thinking in systems and asking first principles questions, is what drew me to a Master's in AI Ethics & Society at Cambridge, which I'd matriculated in 2021, before AI became mainstream.

If you were advising a bank CEO today, what would you say is the single biggest mistake they're making with data and AI?

Treating activity as a result. A board gets shown a list of live AI initiatives and reads it as value delivered. It is not, and the evidence is now hard to argue with. MIT's 2025 study found that 95% of enterprise generative AI pilots produced no measurable effect on the bottom line; only 5% created real value. Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, on unclear business value, rising cost and weak controls.

The firms in that successful minority did not adopt AI for its own sake. They picked a specific cost to remove, a delay to close or a control gap to fix and used AI where it was the right tool. The trouble starts when the technology becomes the objective rather than the method, because that's the moment you commit money with no defined outcome to justify it.

What's one AI or data capability banks should prioritise in the next 12-18 months, and why?

I'd get the data and controls into a state that are actually fit for AI to use. A model deployed on a fragmented or poorly governed data estate won't survive production, whatever it does in testing.

Once that foundation is there, I'd focus on bounded automation in functions where regulation already demands rigour: surveillance, controls monitoring, financial promotions. The outcome is measurable, the risk is contained and the manual cost is high. Finspector does exactly this, monitoring financial promotions at scale, and I can show its value to a finance function and a regulator alike. Start here and the return is visible early, while the failure modes are ones the firm already knows how to manage.

Where do you see banks overestimating AI, and where are they underestimating it?

There's certainly a tendency to overestimate autonomy. A model that tests well gets assumed ready for production, when the two are very different, and that gap is where a lot of the failed spend goes. The caution is warranted: only about one in five leaders say they trust AI agents with financial transactions. An agent that can call APIs and move money is a new category of operational risk, and in most firms no one has been made its owner. The three lines of defence model banks rely on wasn't built for systems that act on their own initiative. The FCA's Mills Review, its July 2026 report on the long term impact of AI on retail financial services, makes the same point from the regulator's side: it recommends actively monitoring the transition to autonomous models rather than assuming firms will manage it on their own.

What I think they underestimate is the narrow, repeatable work: a well scoped task done consistently at volume, continuous monitoring, or freeing analysts from reconciliation to do work that needs judgement. It rarely gets attention, but it delivers steady, compounding value inside processes that used to lose time and carry avoidable risk.

What does "good" actually look like when AI and data are working well inside a bank?

Good is when you see faster decisions, earlier detection of errors and a control environment a regulator finds credible. A clear ROI on your AI investment. Underneath that, the discipline is exact. Give every system a defined owner and a clear purpose, and hold it to two things at once: a goal, which sets what it should achieve, and a constitution, which sets what it must never do regardless of efficiency. A firm in that position can say at any moment what each system is for, who's accountable when it fails, and where human judgement is built in by design.

Run this way, governance maturity becomes a commercial advantage rather than a cost, because the firms that can evidence the reliability of their systems are the ones that can move at pace.

What's the hardest AI or data decision bank executives are avoiding right now, and why?

Deferring accountability for AI end to end: who answers for the whole path, from the business outcome, through the technology, to the controls around it. Individual pilots have owners; that wider responsibility usually does not. Technology understands what the systems can do but not the firm's risk appetite. Risk and the business understand appetite but can't always examine what the model is actually doing. Each side assumes the other has it, and the gap between them is where failed projects and unmanaged exposures collect.

And this gets deferred because it's genuinely hard. It needs accountability that cuts across existing reporting lines, and it asks someone to answer for a technology few executives fully understand.

Someone has to hold both sides at once, the organisation's real position and a realistic view of what the technology can do, and until that role exists the firm isn't really governing its AI. Here's the test I'd put to any board: if an AI system failed tomorrow, who would be accountable for it?


Thank you Anna! You can connect with Anna on her LinkedIn Profile and find out more about the company at sepanta.io.