Can AI fill the cyber-expert deficit in banking?
I will tell it as it is reaching me these weeks. After it was reported that Spanish banking needs 15,000 cybersecurity experts who do not exist, the million-dollar question has landed in every management committee I know: could artificial intelligence not fill that gap? The short answer is no. AI in banking cybersecurity under DORA is the combination the sector is trying to solve with automation, but the reality is that AI can absorb repetitive tasks, speed up detection and multiply the productivity of existing teams. The structural deficit, however, it does not solve: it displaces it. It transforms it. And in the short term, it makes it worse. Anyone who tells a board otherwise is going to get a surprise when the first serious DORA audit arrives.
The easy promise being sold at every keynote
The commercial argument has been circulating for months through keynotes, white papers and demos: if we cannot find analysts, let’s deploy models. If there is no SOC team, let’s automate with SOAR. If penetration tests are costly, let’s leave them to an autonomous agent. The narrative is seductive because it has a true part: AI in banking cybersecurity under DORA has advanced more in two years than traditional cybersecurity in a decade. XDR platforms with deep learning models, autonomous incident response agents, assistants that draft compliance reports in seconds. All that exists and works.
The problem begins when someone translates that to “then we don’t need to hire”. That translation is wrong because of a combination of three factors: regulatory, technical and market. If you have read my previous analysis of the shortage of 15,000 cyber experts in banking, you already have the context of the problem. Here I focus on why AI is not the answer many want to hear.
AI in banking cybersecurity under DORA: what does work today
It would be unfair and technically incorrect to minimise the real capabilities. Modern defensive AI delivers measurable value on five fronts:
- Mass triage of SIEM alerts. A traditional SOC handles thousands of alerts a day; AI filters out up to 80% of the noise and prioritises those that deserve human attention.
- Real-time event correlation. Models that detect lateral patterns a human analyst would take hours to connect.
- Generation of draft notifications and reports. An agent can prepare the first version of an incident report in minutes.
- Preliminary vulnerability analysis. Scanning, prioritisation and initial documentation of findings.
- Detection of known fraud patterns. Models trained on transactional data that identify anomalies before they escalate.
All this is real, is in production in European entities and frees up teams’ time. The question is not whether AI adds value — it does. The question is whether that value is enough not to hire anyone. And there the answer changes radically. AI in banking cybersecurity under DORA delivers real operational value, but it is not equivalent to covering the structural deficit. Where it truly amplifies the team is in tasks like modernising COBOL with AI, speeding up the understanding and migration of banking legacy without replacing human judgement.
The real limits of AI in banking cybersecurity under DORA
DORA, NIS2 and the EU AI Act establish a perimeter that AI in banking cybersecurity under DORA cannot cross by regulatory design. There are decisions an automated system cannot legally take, not because of a technical limitation, but because the regulation requires nominated human responsibility.
Nominated legal responsibility
The DORA Regulation requires the ICT risk management function to operate under the responsibility of the management body. An AI cannot be responsible in a legal sense. It cannot appear before the Bank of Spain, it cannot sign the quarterly reporting, it cannot assume administrative or criminal consequences. The AI Act, in its Article 14, reinforces this architecture: AI systems in high-risk sectors — and banking is one — require significant human oversight. That “significant human” has a name, a surname and an employment contract.
Classification of major incidents
DORA requires major incidents to be notified to the supervisor within four hours. Classifying an incident as major or not is not a deterministic calculation: it involves judgement about reputational impact, the number of customers affected, the criticality of the service that is down and propagation to third parties. An AI can offer an estimate; a human signs the notification. If that signature is missing, the penalty is indeed deterministic.
Negotiation with critical ICT providers
Renegotiating the contract of a cloud provider that serves a financial entity is not something delegated to an autonomous agent. It requires audit-right clauses, an exit plan, measurable KPIs and incident notification obligations. That process is carried out by a human team of IT, legal and procurement over months. AI can analyse clauses, it cannot commit the entity before a court.
Coordination of TLPT tests
The advanced threat-led penetration tests that DORA requires every three years from significant entities involve coordination with the supervisor, certified external red teams and controlled communication within the entity itself. It is an end-to-end human programme. No autonomous agent manages it today.
The AI, cybersecurity, banking and DORA paradox: more demand for talent, not less
However, here is the point systematically ignored in vendor presentations. Deploying AI in security introduces new risks that someone has to govern. The (ISC)² Workforce Study 2024 documented that the introduction of AI into SOCs has not reduced headcounts: it has shifted demand towards more expensive and scarcer profiles. AI security engineers, MLSecOps specialists, AI governance officers. Roles that did not exist three years ago and that the market still does not produce at the speed European regulation demands.
ENISA has also warned about the new attack surface that defensive AI opens up: training-data poisoning, prompt injection attacks against autonomous agents in regulated environments, model evasion. Defending these layers requires deep knowledge of both disciplines — security and AI — and that intersection is still rare in the market. Every bank that deploys an autonomous agent needs someone able to audit it, validate it and respond when something fails. And when that system makes a decision affecting a customer, the entity has to be able to explain it. Black-box models do not pass a DORA audit.
Asymmetry: AI democratises the attack faster than the defence
Anthropic’s Project Glasswing experiment, which I documented in my analysis of Claude Mythos in cybersecurity, showed that current models —according to (ISC)²’s own research— can detect and exploit vulnerabilities with effectiveness comparable to experienced human teams. The operational consequence is brutal: an attacker with an autonomous agent can launch campaigns on an industrial scale with a fraction of the personnel they needed before. Meanwhile, the defence still requires human teams to govern the AI, validate its decisions and answer to the regulator.
The asymmetry that punishes regulated banking
The asymmetry works against the defender. Attackers can afford models without governance, without auditing and without legal responsibility; regulated entities cannot. Each layer of defensive AI requires an additional layer of human governance. Each deployment automates operational tasks and simultaneously raises the bar for the talent needed to maintain it. The deficit does not close: it shifts upwards. That is the real equation of AI in banking cybersecurity under DORA.
Shadow AI: how it worsens the AI in banking cybersecurity under DORA challenge
In addition, there is an aggravating factor almost no one is quantifying yet: shadow AI within the entities themselves. Banking employees using ChatGPT, Copilot or generative assistants without corporate governance. Each of those uses opens a regulatory risk — leakage of personal data under the GDPR, breach of AI literacy under Article 4 of the AI Act, exposure of confidential information — and multiplies the work of the compliance teams. AI is not freeing up professionals: it is creating new fronts that require senior profiles with judgement to govern them.
AI in banking cybersecurity under DORA architecture: human + AI with clear roles
Consequently, the right question is not whether AI replaces the human, but which architecture combines both without falling into the trap of apparent compliance. What I am seeing work in entities that are managing the transition well is a three-layer architecture. AI absorbs the repetitive, high-volume work — triage, correlation, drafts. Mid-level analysts take on the cases that require context and operational judgement. Senior leadership — Project Manager, CISO, DORA lead — governs the whole system, validates the critical decisions and signs the reporting to the regulator.
The result: deficit shifted to senior profiles
That architecture does not reduce the talent deficit: it reduces the pressure on junior profiles and shifts demand towards senior profiles with regulatory vision. Which is exactly the profile the market cannot find.
AI does not save the bank: it forces it to make better hiring decisions
The Spanish financial sector is going to deploy defensive AI massively over the next three years. That will not close the structural deficit: it will transform it into a deficit of more qualified and more expensive profiles. The entities that understand in time the real role of AI in banking cybersecurity under DORA will invest at once in platforms and in senior talent with regulatory judgement. Those waiting for AI to “solve the problem on its own” will find themselves in 2027 with a DORA penalty and a board asking why no one signed the notification in time.
How to face the deficit with judgement: programme management
If your entity is at this decision point, we can talk. I work as an AI/Cybersecurity Project Manager with 30 years of experience in regulated sectors, specialising in DORA, NIS2, the EU AI Act and the GDPR, hybrid (Almería) or 100% remote. You can write to me from the contact page.
Frequently asked questions about AI in banking cybersecurity under DORA
No. AI absorbs repetitive tasks (SIEM triage, correlation, report drafts) but cannot assume legal responsibility, classify major DORA incidents or sign reporting to the supervisor. It reduces pressure on junior profiles and increases demand for senior talent with judgement in AI, cybersecurity, banking and DORA.
DORA requires the ICT risk management function to operate under the responsibility of the management body. Combined with Article 14 of the AI Act, AI systems in banking require significant human oversight with a nominated responsible person.
Because it introduces new risks (data poisoning, prompt injection, model evasion) that someone must govern. It creates new profiles —AI security engineer, MLSecOps, AI governance— that the market still does not produce at the speed regulation requires.
It is the ungoverned use of generative AI tools by employees (ChatGPT, Copilot). It generates data-leak risks under the GDPR and breaches of Article 4 of the AI Act, multiplying the work of the compliance teams and worsening the structural deficit.
A three-layer architecture: AI absorbs high-volume repetitive work, mid-level analysts handle cases with context and operational judgement, and a senior Project Manager / CISO governs, validates critical decisions and signs the reporting to the regulator.
Related reading
- Previous article in the cluster: DORA and the 15,000 cyber experts missing from banking
- On offensive AI: Claude Mythos: when AI surpasses hackers
- On the risk of shadow AI: Shadow AI in the company: how to govern it
- Regulatory framework: DORA Regulation: digital operational resilience
Sources: reports published by Spanish economic media in May 2026 on the shortage of 15,000 cybersecurity experts in banking. (ISC)² Cybersecurity Workforce Study 2025. ENISA Threat Landscape 2024. Regulation (EU) 2022/2554 (DORA). Regulation (EU) 2024/1689 (AI Act).
Do you have to apply this under DORA, NIS2 or ENS? Tell me about it.
Book 20 minutes