Let's be honest: nobody reads 81 use cases. I wouldn't either.
A few weeks ago I wrote that we were 21 banking use cases in, and counting. The counting part turned out to be an understatement. So we sat down, went through every floor of the bank, added what regulators, customers and our own delivery teams kept bringing up, and turned it into a public playbook: 81 jobs AI can take over inside a bank. For every job: where the AI fits, what the evidence says, and what a strict bank has to govern.
But the number isn't the point. Writing it all down taught me two things I didn't expect. Banks aren't buying use cases anymore. They're becoming something else. And what decides which banks get there isn't the model, the budget or even the talent. It's governance.
Banking has done this before. In the branch era, people did every task and software just recorded it. Then came the neo banks. Great app, slick onboarding, and behind the glass? Largely the same manual work. Ever waited four days for a "digital" bank to review one document? Then you know how thin that glass is.
The next move is different, because it changes the work itself. In the AI bank the jobs run on governed AI, not just the screens. Servicing, fraud triage, KYC review, reconciliation, audit prep: all on the same platform, with a human on every decision that matters. Not a bank with a chatbot bolted on. A bank where people supervise, decide and handle the edges.
The neo bank changed how a bank looks. The AI bank changes what a bank is.
And no, this isn't five years out. Look at the leaders. In May 2026 CommBank resolved about 84.6 percent of its self service messaging interactions end to end, according to Microsoft. DBS has gen AI virtual assistants serving more than 10 million customers, plus a real time assistant for its customer service officers. At Morgan Stanley, advisors search the firm's own research with an AI assistant, and access to documents jumped from 20 percent to 80 percent according to OpenAI's case study. McKinsey's estimate of $200 to 340 billion a year sounds abstract. Spread it over 81 concrete jobs and it suddenly doesn't.
Here's what surprised me when we sorted all 81 jobs by floor.

The front office, where every AI conversation starts, holds 14 jobs. The biggest floor is the one nobody demos: the middle office, with 24. Fraud scoring, AML triage, mule network detection, sanctions, perpetual KYC, SAR drafting. Add the specialized businesses (corporate, trade, wealth) and the bank behind the bank (IT, HR, audit, the model inventory itself), and about four out of five jobs sit outside the front office. Most of them in places your customers will never see.
Which makes sense, if you think about it. An interface upgrade stays in the front. A work upgrade spreads through the whole building.
One example. SAR drafting: an alert survives triage, the AI builds the case file, writes the narrative and attaches the evidence. The investigator reads it, edits it and owns the filing. The AI does the hours, the human does the judgment, and the audit trail records both. Do that 24 times and you have a floor. Do it 81 times and you have a bank.
This is the part I care about most. Honestly, it's why I wrote this post.
Every job in the playbook has a "what to govern" section. Write 81 of those in a row and you notice something: it's the same four rules every time, just wearing different clothes.

Guardrails: answer only from approved sources, check identity before anything sensitive, refuse what you're not licensed to do. A model inventory: every model has an owner, a purpose, data lineage and a risk tier, and shadow AI gets found instead of tolerated. Human in the loop: the AI drafts, scores and recommends, and a named person owns the decision. The onboarding approval, the sanctions hit, the credit limit, the account freeze. An audit trail: every automated action logged, explainable and replayable when a model changes.
Did we invent any of this? No. Supervisors are writing it down. APRA's CPS 230 has been in force since July 2025 and covers critical operations and material service providers, AI or not. MAS consulted on AI risk management guidelines that expect up to date AI inventories and human oversight. OJK published AI governance guidance for Indonesian banks in April 2025. And the EU AI Act requires deployers of high risk systems to assign human oversight, keep the logs and cooperate with the authorities. Paul wrote a readiness checklist for that one. Short version: the rules are on paper now, and they only get more specific.
After five years of working for banks, here's what I see. More and more use cases are moving toward AI, and the appetite is real: adoption is high. But getting something into production still takes a long time. A big part of that sits with central banks and regulators. They need to understand what is happening before anything can move, and to be fair, they want to. It's just that they turn like an oil tanker.
Regulators want AI in banking. But a regulator turns like an oil tanker.
You can't push a tanker. What you can do is make it very easy to see where you're going. That's what good governance does: the clearer you can show a supervisor what the AI does, who decides and what gets logged, the sooner the tanker starts turning.
So the question isn't whether you meet that bar. It's how many times you want to build it. Fifty jobs as fifty vendor projects? That's fifty security reviews, fifty ways of logging, fifty guardrail sets drifting apart, and an AI estate nobody can explain to a supervisor. Good luck with that meeting.
On one governed platform you set up the four rules once and every job inherits them, from the voice assistant to the fraud triage. In our experience that's the difference between a risk review that takes a quarter and one that takes a meeting, because the review only has to look at what's actually new. It's also why we carry ISO 42001 next to ISO 27001, SOC 2 Type II and PCI DSS: the AI management system is certified once, and every use case lands inside it. And it's why we built a control tower for agentic operations. When agents do the work, oversight is a feature, not a committee.
My favorite use case in the whole catalog is the last one: the model inventory itself, run as an AI job. Agents find the models in use, read their cards and approvals, flag what's unregistered and build the evidence pack when the supervisor calls. The platform governing itself. When we demo that one, the compliance team leans in further than the innovation team. After enough of these projects I've learned that's the most reliable sign a project will make it to production.
Nobody switches on 81 jobs at once. Please don't try. The advice from the 21 use case post still stands, now over five floors. One job from the front office, because visible wins buy patience. One from the middle office, because that's where you want to learn governance early. And one from the back office, because it pays for the other two. Measure, share the numbers internally, and let the second wave ride on what the first wave already paid for.
A pile of pilots and an AI bank both start with three use cases. So what's the difference? On a governed foundation, use case four inherits the guardrails, the inventory entry, the oversight model and the audit trail from the first three. Every new job lands faster and safer than the last. Fifty use cases stop being fifty projects and become one capability. That's how the AI bank gets built, quarter by quarter. And it's why the banks that start with governance pull away from the ones still trying to get pilot number seven past risk.
The playbook is public: 81 jobs, five floors, every "what to govern" spelled out. Want to go through your own longlist? I'm happy to map it on a whiteboard together: which jobs fit your bank, in which order, and what governance looks like when it comes first.