Financial institutions are now caught between accelerating AI adoption and a converging set of regulatory deadlines across the US and Europe. The EU AI Act‘s August 2, 2026 enforcement date for high-risk AI systems puts credit scoring, behavioral profiling, and customer decision-making directly in scope. At the same time, New York’s cybersecurity regulation is entering its enforcement phase, and DORA is requiring banks to demonstrate operational resilience in ways that go beyond traditional privacy compliance.
In this interview on TFiR, Steve Winterfeld, Advisory CISO at Akamai, breaks down the regulatory landscape shaping financial services security strategy, covering AI governance, API risk, DORA, GDPR, and the gap left by the absence of US federal privacy law.
Guest: Steve Winterfeld, Advisory CISO at Akamai
Show: TFiR
Here is what every CISO, compliance officer, and security architect in financial services needs to know.
Technical Deep Dive
Q: How is AI regulation being shaped in the United States for financial services?
Steve Winterfeld, Advisory CISO at Akamai, explains that US AI regulation is currently fragmented at the state level, with no federal law covering privacy or AI governance in a comprehensive way. Colorado was among the first states to pass an AI law, with its focus on high-impact decisions rather than low-stakes AI interactions. The regulatory intent is to prevent discrimination and ensure correctness in decisions that materially affect consumers, such as bank loan approvals.
“Me talking to AI about what kind of a disk I want to buy is not something that needs to be regulated. But if I were going in to get a bank loan, then that kind of impact is where they want to make sure there’s not discrimination.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is the current status of New York’s cybersecurity regulation for financial institutions?
Winterfeld notes that New York has developed one of the stronger sets of financial cybersecurity laws in the US, and that regulation is now moving into active enforcement. The industry is watching closely to see what cases are brought and what penalties are imposed, which will set precedent for how similar regulations are applied elsewhere.
“New York has one of the better sets of financial laws. Their cybersecurity regulation is moving into the enforcement phase. And so we’re going to start to see what kind of cases and penalties are brought there.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How mature is financial services regulation in Europe compared to the United States?
Winterfeld characterizes Europe as significantly more mature in financial sector regulation. GDPR governs privacy and has already resulted in fines exceeding 6.7 billion euros as of 2025. DORA addresses operational resilience rather than privacy, and both frameworks are now being actively implemented and enforced across the financial sector.
“Europe is a lot more mature in the financial sector. GDPR alone, we’ve had fines exceeding 6.7 billion euros as of 2025.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is the difference between DORA and GDPR for financial services compliance teams?
Winterfeld draws a clear distinction: GDPR is a privacy regulation, while DORA is focused on operational resilience. Financial institutions must treat them as separate compliance workstreams with different requirements, controls, and risk surfaces. Both are enforced in Europe and apply to organizations operating in or serving European financial markets.
“DORA is against resiliency, not privacy. And so we’re seeing those implemented.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What does the EU AI Act require from financial services firms and when does enforcement begin?
The EU AI Act designates certain financial AI applications as high-risk systems, including credit scoring, behavioral profiling, and AI that makes or influences decisions about customers. Winterfeld confirms the deadline for compliance with high-risk system requirements is August 2, 2026. Organizations using AI in these categories must meet the Act’s requirements by that date or face regulatory exposure.
“The EU AI Act has an August 2, 2026 deadline for high risk systems. Credit scoring, behavior profiling, those things where they’re interacting and making decisions around customers.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Are there standalone API security regulations for financial services?
Winterfeld states that dedicated API regulations for financial services do not yet exist in standalone form. API security requirements are currently embedded within broader regulatory frameworks rather than addressed in their own right. Security teams should look inside existing regulations for API-relevant obligations rather than waiting for a dedicated standard to emerge.
“We don’t see as many regulations aimed at APIs right now. There are some embedded within other regulations, but no standalone API regulations really.” — Steve Winterfeld, Advisory CISO, Akamai
Resources & Documentation
- Akamai, security and cloud delivery platform with financial services security solutions referenced throughout this discussion
- EU AI Act, August 2026 high-risk system requirements — official EU regulatory text available at digital-strategy.ec.europa.eu
- GDPR, EU privacy regulation with direct financial penalties for non-compliance — reference at gdpr.eu
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: When it comes to financial services, they’re already one of the most heavily regulated industries. What is emerging on the regulatory front and how is it shaping security strategy? Of course, we can talk about a lot of activities that are going on. Europe, CRA is coming up, a lot of other acts are also coming up here. But in general, what are you seeing when it comes to financial industry, AI, API and improve the security strategy there in this specific sector?
Steve Winterfeld: So, you know, I live in Colorado, Colorado is one of the first states to come up with an AI law. Like most AI laws, the laws are trying to again focus in on what kind of an impact the AI is having. Again, me talking to AI about what kind of a disk I want to buy is not something that needs to be regulated. But if I were going in to get a bank loan, then that kind of impact is where they want to make sure there’s not discrimination. They want to make sure that it’s done correctly. And so within the United States, we don’t have a federal law for privacy or really much around those kind of things. So within this we see the New York has one of the better sets of financial laws. Their cybersecurity regulation is moving into the enforcement phase. And so we’re going to start to see what kind of cases and penalties are brought there. Europe a lot more mature in the financial sector. You’ve got DORA for privacy, Nistu for banking, I’m sorry, GDPR for privacy. And so GDPR alone, we’ve had fines exceeding 6.7 billion euros as of 2025. And Dora is, is against resiliency, not privacy. And so we’re seeing those implemented on the AI side. We see the EU AI act, it is out there now. It has an August 2, 2026 deadline for high risk systems. Again, credit scoring, behavior, profiling, those things where they’re interacting and making decisions around customers. So continued effort around that. We don’t see as many regulations aimed at APIs right now. There are some embedded within other regulations, but no standalone API regulations really.





