Financial services firms are increasingly recognising the benefits of AI, machine learning and open-source software (OSS), but security concerns and legacy systems are hindering progress.
According to the 2024 State of Open Source in Financial Services report, created in conjunction with the Fintech Open Source Foundation (FINOS), the Linux Foundation, and Scott Logic, 84% of Financial Services businesses agree that OSS delivers substantial business value.
Early adopters in financial services have primarily focused on using genAI for chatbots and customer service applications, according to the report.
For instance, BloombergGPT and BondGPT are specialised models tailored for finance-specific tasks, such as accessing market data and bond-related information. Additionally, Goldman Sachs has launched a GenAI tool for code generation, underscoring the technology’s potential for boosting internal developer productivity – a key area where 37% of respondents anticipate genAI having the biggest impact.
Other areas expected to benefit from genAI include new or enhanced client-facing services (33%) and business process automation (26%). Despite the promising potential of these use cases, many financial institutions have initially limited their focus to internal applications to minimise risks associated with genAI’s broader implementation.
Cloud and Open Source
Cloud technology continues to be a major priority in financial services, with roughly 30% of survey participants ranking it among their top three priorities.
The shift to cloud-based solutions helps firms modernise operations by enabling real-time analytics, AI-driven customer service, and other innovations. Notably, cloud computing allows financial institutions to reduce upfront costs and streamline data storage, while open-source software can further enhance agility by avoiding vendor lock-in.
However, cloud adoption also brings new challenges, particularly in compliance and cybersecurity. Regulatory requirements for cloud financial services are evolving, with governments emphasizing the need for robust data protection measures.
The 2023 establishment of the Common Cloud Controls initiative by FINOS – a collaborative project initially proposed by Citi – aims to standardise cloud compliance controls across major service providers, reducing the risks associated with cloud concentration.
Cybersecurity: A Growing Concern
With nearly one-fifth of all cyber-incidents affecting financial firms, cybersecurity is a top priority for the industry.
JPMorgan Chase alone reported handling 45 billion cyber-events daily, investing $15 billion (£11.5bn) annually in technology and employing 62,000 technologists, many focused on cybersecurity.
Regulatory measures are ramping up to address the rising threats, such as the EU’s Cyber Resilience Act and the U.S. Securities and Exchange Commission’s recent amendments to Regulation S-P.
Open-source software is increasingly seen as a viable solution to improve security standards across financial services, according to the report.
According to survey data, 47% of participants believe that improving secure software development practices would significantly benefit open-source adoption.
Additionally, 46% agree that using Software Bill of Materials (SBOMs) could enhance trust in open-source components.
Yet, only 12% of organisations currently include SBOM development as part of their open-source contribution processes, highlighting a gap between awareness and action.
Recommended reading
- 98% of Firms Eye GenAI for Cloud App Modernisation
- NCSC Issues Guidance for Securing Cloud-Hosted SCADA Systems
- Cloud Complexity and AI are Too Much for Traditional Security
As Colin Eberhardt, CTO at Scott Logic and a co-author of the report, explained, this, combined with the issue of legacy systems, needs to be addressed if firms are able to reap the real benefits of OSS, AI and ML:
“It’s clear that the Financial Services industry can benefit from innovative technology such as Open-Source Software, AI and Machine Learning and it is certainly encouraging to see this increasingly recognised by leaders in the sector. However, given the highly regulated nature of Financial Services and the understandable concerns around data security, many firms aren’t yet reaping the rewards.
“A careful approach to ensure any new tools are compliant with industry regulations and standards is certainly needed. However, one critical point that is also hindering businesses in the sector from truly benefitting from the potential of OSS and other tools is the issue of legacy IT systems which simply can’t accommodate the changes required.
“Replacing these tech stacks is a monumental job for many, particularly those firms that have had systems in place for decades. It will require brave and bold leadership, but it is, without doubt, a necessity.”





