Fintech execs unblock AI with shadow AI detection, org shifts

C-level executives in a regulated industry strike a balance between the benefits AI can offer their businesses and the need to guard against its risks.

Two executives at financial services companies used new tools and approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI, while still maintaining security controls.

These approaches ranged from new strategies and data-gathering for monitoring threats to shifts in how teams are organized, but the common theme was to use AI tools safely without falling into the traditional stereotype of security teams as blockers to progress.

"You can throw a 50-foot wall around it and don't let anybody get to it, but then you lose the innovation, and you lose the ability to accelerate by having the right tooling applied to it," said Doug Innocenti, CIO and chief information security officer (CISO) at MoonPay, a cryptocurrency payments firm based in New York.

Avoiding shadow AI, from ChatGPT to agents

After ChatGPT burst onto the scene in late 2022, MoonPay leaders engaged with a stealth AI security startup, Aim Security.

"In the early days of ChatGPT, they didn't have ChatGPT Enterprise or ChatGPT Pro. It was just ChatGPT," Innocenti said. "There was no isolation. Aim not only had a defensive mechanism but also created a secure portal with enterprise-level anonymization and blocking … the features that ChatGPT didn't have."

As ChatGPT gave way to a plethora of generative AI models, Aim Security evolved to scan tools on the network that used internal AI components and assess whether the tool makers used data from those components to train models. Aim Security could also determine which underlying models the tools used and for which other purposes they might use data.

"We were able to perform an independent review on tools and understand which ones we wanted to pick," Innocenti said. "So it was actually both posture management and part of the built-in investigative component we wanted to do."

Aim Security was acquired by Cato Networks in 2025, which renamed the tool Cato AI Security. Innocenti said MoonPay is investigating other secure access service edge (SASE) tools, including Cato's, but hasn't yet purchased any.

Cato has integrated Aim with its SASE products, including its firewall as a service tool, which could potentially act as a higher-level detection point for shadow AI activity than the individual workstation web browsers where MoonPay currently deploys Aim, Innocenti said.

"It's been an ongoing conversation point that I have with my team -- you need AI defense not at the endpoint, but you need it in the transport mechanism, you need it at the network layer," he said.

As the company begins to use AI agents such as Claude Cowork, "Cato AI security provides me with the same depth of support to govern, rather than block, what is being done today," Innocenti said. "It sits in front of Cowork and other components we have and allows me to look for sensitive data that might be pushed into it."

Still, the rapid evolution of agentic AI represents an ongoing challenge, Innocenti said.

If we have to say no, our primary focus becomes, 'How do we get from no to yes?' 'No' is just a temporary stopping point.
Doug Innocenti, CIO and CISO, MoonPay

"What keeps me up at night with agentic AI is that I can go to bed, and something new will emerge by the time I wake up," he said. "I have never done as much research as I have done in the last year and a half."

Still, the guiding principle of enabling employees to take advantage of new AI tech whenever possible remains in place.

"If we have to say no, our primary focus becomes, 'How do we get from no to yes?' 'No' is just a temporary stopping point [but we can find] the right way to do it. It doesn't mean we have to just block it."

'Your employees are both your weakest and strongest link'

MoonPay underwent significant organizational consolidation earlier this year, when Innocenti added the CISO role to his existing CIO position in May. 

"The IT team was the fundamental implementation point of everything that needed to be done from a security perspective, so taking on the responsibility to understand the posture and build the overall policies was just an evolution of what IT already was," Innocenti said.

This consolidation has fostered deeper collaboration between IT and security teams at MoonPay.

"You see IT people talking like security people, and you see security people talking like IT people, and they both want to work together … not looking at it as a rivalry, which you can see happen in some situations, but looking at it as a partnership," Innocenti said.

The way Cato AI Security surfaces potential risks to sensitive data for IT and security teams has also been key for employee training and communication, he said.

"It helps us assist the employee in the right way to use AI tools safely. Now we start seeing people ask questions in our IT tickets that say, 'Hey, I'm thinking about doing this with some data. Is there a better way I can do it?'" Innocenti said. "They understand that it's okay to ask the question.

"In any security stack, your employees are both your weakest and strongest link," he said. "If I can make employees stronger by helping them ask the right questions and pause for a moment, then we've won."

'It's not people being malicious'

At Equals, a London-based payments platform company, 86% of application code is now written by agents, up from 5-10% last year, with the goal of 100%. The use of AI agents has also been valuable to the business, helping the company's legal and customer support teams complete contract reviews and complaint processing more quickly.

However, James Simcox, chief product officer at Equals, is well aware of the risks of unfettered use of AI. Many staff are eager to use AI products they're familiar with at home and might tweak security settings to allow more access if those tools don't perform as expected at work.

"Sometimes people go, 'I'm a senior person trying to implement this tool. … I'll give it admin access to this product, because I have admin access,'" Simcox said. "Then they sort of forget about it, and it makes it into production with access to way more information than it needs. It's not people being malicious. It's people just being like, 'I want to do my job.'"

No humans have been replaced by AI at the company, which is still growing rapidly, reporting double-digit percentage revenue growth over the last year to surpass about £60 billion ($80 billion) in transaction processing volume. Developers have shifted their focus to more strategic technical tasks, while product managers handle smaller, less technical updates. Agentic coding has forced the company to rethink its code review and software release processes, as AI-generated code creates a new bottleneck downstream, Simcox said. The need for human oversight of AI coding agents has led the company to double the size of its human security team this year.

"We've also broken out our system slightly more into some more standardized pieces, so that when you're developing software, you don't necessarily think about the API gateway security layer, for example, because that's handled in a product," Simcox said. "But it's in progress, because the increase in delivery has gone up so much that bottlenecks can appear where you don't expect them to."

New AI threats call for new tools

Attacks look less obviously like a bot just hitting an endpoint, and they look a lot more like a human trying things, which wouldn't necessarily get picked up by a bunch of different tools.
James Simcox, Chief operations and product officer, Equals

While properly organizing and training people to use AI tools was an important component in curbing shadow AI use at Equals, new tools were also called for as AI-assisted cyberattacks grow more sophisticated and numerous, Simcox said.

"Fewer, broader tools are what we've gone for," Simcox said. "Particularly with the rise of AI agents behaving slightly more like humans, attacks look less obviously like a bot just hitting an endpoint, and they look a lot more like a human trying things, which wouldn't necessarily get picked up by a bunch of different tools."

Equals replaced multiple application security monitoring tools with Wiz and added Okta Identity Security Posture Management (ISPM) for staff identity management and authorization, along with Okta's Auth0 for customer identity management and authorization.

"It's very hard for our IT or security team to go around to every single tool in the entire business all day long and go, 'Steve has accidentally given this AI tool admin access to all our customer data. Maybe he shouldn't have done that,'" Simcox said. "That's where Okta ISPM is really useful for us, because it can [see] across all of those different tools, and gives you proactive alerts that say, 'This user is not behaving like they're supposed to, or this user has logged in 14 times in different tools in three seconds.'"

Ideally, every Equals customer would use the company's single sign-on and two-factor authentication with a passkey or hardware security key, Simcox said, but it's not realistic to expect that. Instead, Auth0 has enabled defense-in-depth without imposing overly restrictive login policies on clients.

"We have to account for a really wide range of customers," he said. "We rely a lot on their behavioral ways of doing things, and so we put a bunch of extra data from Auth0 into our platform for login journeys."

The Equals system might let suspicious-looking logins through, but monitors that activity with Auth0 and feeds its information into transaction monitoring systems. If a suspicious login results in a suspicious transaction, Equals might block the transaction.

"We'll try and move the security to the point of the action we care about," Simcox said.

While some of Equals' AI security measures might be useful to IT pros elsewhere, he cautioned that mileage may vary depending on the market those businesses inhabit and their experience developing software.

"The entire delivery product of financial services is software … so as a business, we're quite used to building our own internal tools, because there is no product you can buy off the shelf generally which interacts with our exact banking partners in the way we want to interact with them," Simcox said. "It's quite easy for us to roll more software out to the business."

Beth Pariseau, senior news writer for Informa TechTarget, is an award-winning veteran of IT journalism. Have a tip? Email her or connect on LinkedIn.