Sebastien Rousseau

CATEGORY

Policy & resilience

DORA, EU AI Act, NIST standards, third-party risk — the supervisory pressure shaping technology decisions.

4 tags

Tags in this category

  • DORA — 59 articles

    Digital Operational Resilience Act — register of information, ICT third-party risk, threat-led penetration testing, and the operational resilience programme banks must run.

  • EU AI Act — 6 articles

    Implementation guidance, supervisory expectations, high-risk system classification, and the conformity-assessment burden the Act puts on banks.

  • NIST — 4 articles

    NIST standards relevant to banking — FIPS 203/204, AI RMF, SP 800/1800 series — and the supervisory adoption patterns around them.

  • Third-party risk — 2 articles

    ICT third-party risk under DORA, EBA outsourcing guidelines, and the supervisory expectation around critical-vendor concentration.

APPLIED AI

從碎裂到斷層:智能體時代裡企業銀行缺席的那套 API 標準

零售銀行早在十年前就有了自己的 API 標準。企業銀行始終沒有——如今 AI 智能體與 Model Context Protocol 已把整合變成一項執行期決策,這道缺口已不再只是麻煩,而成了一條斷層線。一個具體的故障模式、它所逼出的策略抉擇,以及一套企業銀行 API 標準必須強制規定什麼。

INFRASTRUCTURE & CRYPTOGRAPHY

The Agentic AI Index for Banks in 2026: Measuring Autonomy

Agentic AI is operational infrastructure in 2026. This index measures it the way banks measure capital and credit: a six-dimension readiness score across autonomy tiers, the control plane, regulatory evidence, unit economics, organisational readiness, and global regulatory alignment.

APPLIED AI

2026 年銀行智能體 AI 指數:衡量自主性

智能體 AI 在 2026 年已是營運基礎設施。本指數以銀行衡量資本與信用的方式衡量它:橫跨自主性等級、控制平面、法規證據、單位經濟效益、組織準備度與全球法規一致性的六大維度準備度評分。

PAYMENTS & MONEY

開源、FINOS 與雲端原生 CIB 堆疊

Morgan Stanley、JPMorgan 與 Citi 加碼押注 FINOS 與 Linux Foundation。一套 Rust 加零相依的堆疊——noyalib、http-handle、hsh、KyberLib——揭示 2026 年雲端原生 CIB 堆疊在 PSD3、FiDA 與 DORA 之下的真實樣貌。

PAYMENTS & MONEY

持續不停機 CIB:網路復原、備援軌道與量子安全財務管理

企業與投資銀行(CIB)如今將網路復原、跨 RTGS、即時與代幣化網路的 ISO 20022 備援軌道,以及量子安全財務控管,視為單一持續不停機營運模式——這是針對 DORA 第 5、6 條、FHE、QKD 與 PQC 原語,以及 ICT 第三方集中度風險,所給出的董事會級回應。

PAYMENTS & MONEY

2026 年的後量子銀行韌性指數:EO 14409、全球大限與受託的密碼敏捷性

行政命令 EO 14409、ANSSI 嚴格的 2030 年大限與 DORA 第 5 條,已將後量子密碼學從長程技術目標推向現行的監管強制要求。本指數把登記系統、高頻帳本與 SWIFT 通道的安全,轉化為董事會可用的 0–5 級計分卡,使 ML-KEM、ML-DSA 與 SLH-DSA 等原語與受託責任及資產負債表風險對齊。