Skip to main content

AI in Banking Presentations: Use Cases, Risks, and Governance

Where AI helps in bank presentation workflows, where it must not go, and the governance a supervised institution needs: source authority, access, DORA and human release.

Maximilian BetzPublished 26 August 202613 min read

Evidence base

Sources behind this article

This article supports its claims with 5 sources. Key sources include:

All 5 sources and access dates

Banks can use AI in presentation workflows where five conditions hold: approved inputs, access that mirrors existing entitlements, authoritative data sources, bounded generation, and a named human who releases the file. Where any of those is missing, the material is too consequential and the supervisory expectation too clear.

That is the short answer. The longer one is more interesting, because banking presentations are not one workflow. A branch network update and a supervisory submission share a file format and nothing else.

Let me split them properly.

The four categories of bank presentation

Treating these the same is the root of most governance failures I see in financial services.

CategoryExamplesPrimary riskControl weight
Regulatory and supervisorySubmissions, supervisory dialogue, board risk reportingAccuracy, traceability, regulatory consequenceHighest
Management and financial reportingMonthly and quarterly reporting, forecasts, committee packsReconciliation, version integrity, restatement riskHigh
Client facingPitch material, product presentations, advisory decksSuitability, marketing rules, permitted claims, confidentialityHigh, and different
Internal communicationTown halls, project updates, trainingOrdinary confidentialityModerate

The mistake is applying one policy across all four. Do that and you either strangle the internal town hall or, far worse, treat a supervisory pack with the care of a town hall.

Where AI genuinely helps

I want to be concrete, because generic enthusiasm has not served banks well here.

Recurring management reporting. A monthly pack rebuilt from the approved workbook. Stable scope, authoritative source, reconcilable output. This is the highest value automation in a bank because the work is high volume, repetitive and currently consumes senior analyst time that could go into analysis.

Native chart and table construction. From a controlled table into real chart objects with underlying data. Verifiable, because you can check the chart against the source. Enormously better than the current practice of pasting images that nobody can correct.

Retrieval of approved slides, disclaimers and product wording. The mandatory language, the risk warnings, the standard product descriptions. Retrieved from records rather than copied from last quarter's deck, which is how outdated disclaimers survive for years.

Brand and format enforcement. Deterministic, observable, and it removes work that adds no judgement.

Pre delivery quality checks. Number reconciliation across slides, unit and currency consistency, missing sources, stale data warnings, unlabelled charts, accessibility. Read only, immediate value, catches exactly the errors that embarrass a bank in front of a committee.

Translation and localisation of approved material. With protected regulatory wording locked and market specific text retrieved rather than translated. In a multi entity bank this is a serious saving and a serious risk if done carelessly.

Document review at scale. Reading policy sets, contracts or regulatory texts for specific questions, with citations to the source document and page.

Where it must not go

Material regulatory interpretation. Whether a requirement applies, and how, is a judgement with supervisory consequence. Drafting support around a decision that a qualified person has made is fine. Making the decision is not.

Credit, risk and suitability decisions. These involve individuals and outcomes with real consequences, and they attract their own regulatory expectations. A presentation tool has no business anywhere near them.

Unreconciled figures in a regulatory submission. Every number that leaves the bank in a supervisory context must be traceable to an authoritative source and reconciled. No exceptions, and no "the system generated it" as an explanation.

Price sensitive conclusions and inside information. Where information barriers and market abuse controls apply, the workflow has to respect them at least as strictly as any other system. If your AI tool can retrieve across an information barrier, you have built a control failure.

Anything with no definable correct output. If nobody can describe what right looks like, you cannot test it, cannot review it, and should not automate it.

Source authority is the load bearing control

In a banking context this matters more than anywhere else, so it deserves its own treatment.

Every material figure in a bank presentation should carry an authoritative source. Not "the finance team sent it." A specific system, report or controlled workbook, with the period, the units, the currency, the scenario, the owner and the refresh date attached to the value.

Then three rules:

One source per figure. When the same number exists in two systems, decide which one is authoritative for presentation purposes and record that decision. Two sources of truth means two versions in circulation within a quarter.

The system flags what it cannot source. A generative system that fills an unsourced gap with a plausible figure has created a reconciliation failure that looks like finished work. This is the most dangerous single behaviour in the category and it must be designed out rather than caught in review.

Reconciliation is automated where possible. Totals, cross slide consistency, appendix against summary. Humans are unreliable at this and it is perfectly machine checkable.

Access, entitlements and information barriers

A bank already has a carefully constructed entitlement model. The presentation workflow has to inherit it, not sit beside it.

Concretely: retrieval and writes should respect tenant, workspace, role and document level permissions, and the AI features should run with the permissions of the invoking user rather than a service identity. Where information barriers exist between advisory and markets, or between deal teams, the workflow must honour them.

Then test it, which is the part that gets skipped. Create a deliberately restricted user, ask for content across the barrier, and confirm the system reports nothing found rather than helpfully summarising. Run that test through every surface: the main interface, search, export and any API. In my experience the main UI enforces entitlements correctly and a retrieval index or export path does not.

DORA in practice

DORA has applied since 17 January 2025. For in scope financial entities it makes ICT risk management and ICT third party risk management a central concern, and BaFin has issued supervisory statements to support implementation, including guidance aimed at smaller and less complex entities.

What this means for a presentation tool, practically: if it processes bank data, it is an ICT service and it belongs inside your existing framework. That means the contractual arrangements, inclusion in your register of information where the arrangement is in scope, concentration analysis, testing, incident handling and a documented exit plan.

What it does not mean: there is no "DORA compliant" label a vendor can hold up. DORA regulates the financial entity, not the software. A vendor can support your compliance by providing the contractual terms, evidence and information you need. They cannot provide the compliance itself, and any vendor claiming otherwise has told you something useful about their rigour.

The EU AI Act position as of 2026

Precision matters here because the timeline moved and a lot of internal guidance is now out of date.

The AI literacy obligation under Article 4 has applied to deployers of any AI system since 2 February 2025. A bank rolling out a slide drafting assistant is a deployer.

Transparency obligations under Article 50 have applied since 2 August 2026.

Obligations for Annex III high risk systems were deferred to 2 December 2027 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. Systems embedded in products under Annex I follow on 2 August 2028.

A presentation drafting tool is usually not a high risk system. Reach that conclusion through a documented assessment of your use rather than an assumption, particularly where output feeds anything touching creditworthiness or employment, where the Annex III categories become directly relevant.

The governance model

Checklist
  • Presentation categories defined, with a control level assigned to each.
  • Data classification mapped to which tools may process which levels.
  • Authoritative source recorded for every material figure, with period and refresh date.
  • Retrieval and writes inherit existing entitlements, tested through every surface.
  • Information barriers enforced by the system, not by user discipline.
  • Generation prohibitions written down: no unsourced figures, no altered regulatory wording, no invented client references.
  • Native editable output, so reviewers inspect the real artifact.
  • Named human approver for every externally visible and every supervisory deck.
  • Audit trail covering source set, changes, validation results, reviewer and release.
  • ICT third party arrangements documented, including register entry, testing and exit.
  • AI literacy training for everyone who reviews or releases generated material.
  • Incident route connected to the existing process, including near miss reporting.

Where to start

One recurring reporting workflow. Not the board pack, and not the pitch material. Something monthly, internal, with an approved source and a known correct answer.

Run it on non sensitive or synthetic data first. Test the failure cases deliberately: an entitlement boundary, a figure that cannot be sourced, a conflicting instruction, an attempt to alter a disclaimer, a file someone edited by hand between runs. Record the failures with the same care as the successes, because a pilot report containing only successes is a sales document.

Measure review effort alongside drafting speed. The pattern to watch is generation getting faster while review gets longer. In a bank that pattern is not a productivity gain, it is risk moving to a more expensive and more tired person.

Then have risk, compliance, data protection, information security and the business owner evaluate the evidence together, including what went wrong. Expand one workflow at a time.

Where offgen fits

offgen keeps PowerPoint as the working artifact, which matters in banking because committee review, annotation and last minute correction all happen in the file. Retrieval runs inside existing entitlements. Output is native and editable with source references intact. Lockable elements protect disclaimers and regulatory wording so they cannot be quietly paraphrased.

Our security overview, trust center and data processing agreement provide the material for ICT third party assessment. More on the sector view is on our banking page.

The test I would apply: can you show a supervisor what went into a deck, what the system did, what changed, who checked it and who released it? If yes, you have a governable workflow. If no, the answer is not more model quality.

Frequently asked questions

Can banks use AI to build presentations?

Yes, where the workflow is built on approved inputs, access control that mirrors existing entitlements, authoritative data sources, bounded generation, native editable output and a named human approver. The strength of each control should scale with the sensitivity and consequence of the material.

Which banking presentation tasks are safest to automate first?

Recurring management reporting from an approved workbook, native chart building from a controlled table, brand and format enforcement, retrieval of approved slides and disclaimers, and pre delivery quality checks. All have a definable correct output that can be reconciled against a source.

What must not be automated in a bank presentation workflow?

Material regulatory interpretation, credit or risk decisions, any figure that becomes a regulatory submission without reconciliation, price sensitive conclusions, and anything touching inside information without the controls that framework demands. Automate production, keep the judgement and the accountability.

How does DORA affect AI presentation software in a bank?

DORA has applied since 17 January 2025 and makes ICT risk management and ICT third party risk a central concern for in scope financial entities. A presentation tool that processes bank data is an ICT service, so it belongs in your contractual arrangements, register of information where applicable, concentration analysis, testing and exit planning. There is no DORA compliant label for a product.

Does the EU AI Act apply to AI presentation tools in banking?

It depends on the system and your role. The AI literacy duty under Article 4 has applied to deployers since 2 February 2025 and transparency duties under Article 50 since 2 August 2026. Annex III high risk obligations were deferred to 2 December 2027 by Regulation (EU) 2026/1744. A slide drafting assistant is usually not high risk, but the classification must be assessed for your actual use.

How do you keep numbers in a bank deck reconcilable?

Give every material figure an authoritative source with period, units, currency, scenario, owner and refresh date. Build charts as native objects from the controlled table so the values can be checked. Require the system to flag any figure it cannot source rather than presenting a plausible one.

Sources

  1. 01Regulation (EU) 2022/2554 on digital operational resilience (DORA) EUR-Lex, 2022-12-14. Accessed 26 August 2026.
  2. 02DORA overview BaFin. Accessed 26 August 2026.
  3. 03Regulation (EU) 2016/679 (General Data Protection Regulation) EUR-Lex, 2016-04-27. Accessed 26 August 2026.
  4. 04Regulation (EU) 2026/1744 (Digital Omnibus on AI) EUR-Lex, 2026-07-24. Accessed 26 August 2026.
  5. 05Banking industry solutions offgen. Accessed 26 August 2026.

Related articles

Maximilian Betz

About the author

Maximilian Betz

Co-Founder and CEO, MD

Max writes about management consulting, enterprise adoption, data protection, and the operating controls required for AI in regulated organisations.