TechNewsReel
Live

Fintechs Pivot to 'Govern, Don't Block' Strategy to Combat Shadow AI

MoonPay and Equals are restructuring IT and security roles to enable AI-driven development while securing sensitive financial data.

TechNewsReel Newsroom · August 14, 2026

Fintech executives are abandoning traditional restrictive security postures in favor of active governance to manage the rise of unauthorized AI tools. By shifting from blocking to enabling, firms are attempting to harness productivity gains without compromising regulatory compliance.

To manage this transition, MoonPay has implemented a "govern, don't block" approach to AI adoption. The company utilized Aim Security—now Cato AI Security—to detect "shadow AI," the use of unauthorized AI tools by employees. This system allows MoonPay to provide a secure portal featuring enterprise-level anonymization, ensuring that sensitive data remains protected even as staff experiment with new tools. Doug Innocenti, who serves as both CIO and CISO at MoonPay, notes that "no" is merely a temporary stopping point, stating, "If we have to say no, our primary focus becomes, 'How do we get from no to yes?'"

The Rise of Shadow AI

The surge in generative and agentic AI has created a systemic challenge across the financial sector. Employees frequently bypass security protocols to use AI tools that increase their individual productivity, creating significant risks of data leakage. In a highly regulated environment, this "shadow AI" creates a tension between the need for rapid innovation and the necessity of strict data integrity. Innocenti highlights this duality, observing that in any security stack, employees act as both the "weakest and strongest link."

Structural Shifts for Scale

To address these bottlenecks, fintechs are restructuring their organizational hierarchies to merge IT and security functions. MoonPay consolidated the CIO and CISO roles under Innocenti to ensure that security is integrated into the deployment process rather than acting as a final hurdle.

This structural shift is critical as firms move toward agentic AI—systems capable of acting autonomously. At Equals, the impact of AI-driven development is already evident: 86% of the company's application code is now written by AI agents, a massive increase from the 5-10% reported last year. To support this trajectory toward 100% AI-written code, Equals utilizes Wiz and Okta Identity Security Posture Management (ISPM) to maintain visibility and control over identity and security configurations.

The Path Forward

The industry is now watching whether these consolidated governance models can scale alongside the increasing autonomy of AI agents. While the shift toward merging IT and security roles helps reduce friction, the primary challenge remains the integrity of financial transaction systems. The success of these strategies will depend on whether detection tools and identity management can keep pace with the speed of AI-generated code and autonomous workflows.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.