Banks ship untested code as AI outpaces their testing

TL;DR:

  • 64% of financial services organisations admit releasing untested software into production, according to Tricentis’s 2026 Quality Transformation Report.
  • Most now describe this as a conscious trade-off, driven by leadership pressure for speed and the sheer volume of AI-generated code — not accidental quality slips.
  • Nearly two-thirds estimate poor software quality costs them more than £372,000 a year, with almost one in five putting losses above £744,000.

The report, based on a survey of around 2,500 executives and engineers across six countries, captures a governance gap opening inside banks. AI now writes code faster than testing capacity can keep up, and rather than slow delivery, many firms are simply accepting more risk. Seven in ten financial organisations have embedded AI in software delivery, and 80% say they trust AI agents to make release decisions — yet only 40% feel prepared to govern those agents at scale.

A boardroom-shaped problem

The consequences reach well past bugs. More than a quarter of financial respondents said poor quality would most likely surface as a security breach or compliance failure — acute in a sector where software underpins payments, trading and financial-crime controls. Andrew Power, head of UKI at Tricentis, argued the challenge has shifted: “The challenge is no longer simply deploying AI; it is governing AI at the speed it is being deployed. Just as cybersecurity became a board-level priority over the past decade, AI governance is becoming a strategic concern.”

A telling disconnect underpins the risk: 81% of chief executives express high confidence in AI-driven delivery, against just 56% of the QA and DevOps professionals doing the work. Only 38% of financial firms say executives and developers even agree on what “release-ready” means.

Looking forward

The regulatory direction runs the other way. Under the EU’s Digital Operational Resilience Act, and echoed in the Bank of England’s resilience framework and FCA supervisory work, firms must increasingly prove continuous testing and control over automated systems. That reframes testing itself — no longer just defect-hunting, but the evidence base for demonstrating resilience. The advantage, Tricentis argues, will not go to whoever ships code fastest, but to whoever can still prove every release can be trusted.