Financial Services: DORA-Ready AI on Encrypted Data
Train fraud, KYC, and risk models on encrypted customer data. DORA Article 9(2) is in force. Zero plaintext exposure, no re-architecture.
Encryption at rest and in transit was never the hard part
DORA Article 9(2) has required financial entities to protect data “at rest, in use, or in transit” since it took effect in January 2025. Most institutions already have at-rest and in-transit covered — that part was solved a decade ago. The part nobody solved is data in use: the moment a model, a query, or an analyst actually touches the record. That gap is exactly where fraud models, KYC pipelines, and cross-border risk scoring have been stuck behind legal review.
The number that changes the conversation
BlindML trained a Naive Bayes model on 1,000,000 encrypted records — six features, one target — in 50 seconds, with each record scoring in roughly 8 milliseconds. Fully homomorphic encryption, the approach most institutions evaluate first, takes 4 to 24 hours for comparable workloads and isn’t NIST-approved or FIPS-certified. Blind Insight runs on FIPS-compliant AES-GCM-256 at every layer — the standard your auditors already expect — and the server that stores and indexes your records can’t decrypt them, because the keys never reach it.
That’s zero trust enforced by cryptography, not policy. Centralized key custody — the model every other vendor backs into — breaks the trust assumption. Blind Insight doesn’t have your keys.
I put Blind Insight on the roadmap because it’s the first time I’ve seen query performance on encrypted data that’s actually usable in production. The approach is spot-on.
— Patrick McKinney, VP, Security and IT, Invisible Technologies
What’s actually on the table
42% of companies abandoned most of their AI initiatives in 2025, up from 17% in 2024, according to S&P Global Market Intelligence. Ask financial services firms why they haven’t formally adopted AI tools, and 60% point to the same thing — cybersecurity or privacy concerns around the tool itself, per ACA Group’s 2025 AI Benchmarking Report. That’s not a model problem. It’s a data-access problem, and it’s the reason the catch-22 persists: mobilize the data and you’re carrying breach and compliance risk; lock it away and the value it could have created stays unrealized.
Where this shows up
The same architecture runs identically across every plan:
- Fraud and AML models trained on encrypted transaction data. Train directly on production records with BlindML — no six-month pseudonymization negotiation between data science, legal, and security first.
- Cross-border fraud signal sharing — the use case banks ask about most: flagging a suspicious account in one jurisdiction without sending customer data across it. Swift’s 2025 cross-border fraud pilot with 13 banks found the collaborative model roughly doubled real-time fraud-detection accuracy over any single institution working alone, in trials run on synthetic transaction data. Encrypted, cross-institution collaboration is already a tested category, not a hypothetical.
- Investigator questions in plain language through Blind(L)LM™: an AML analyst asks how many flagged accounts cleared a threshold in a jurisdiction last quarter and gets an aggregate answer. The model never sees a record, and neither do we.
Why this stayed unsolved
Every other approach makes you trade value for privacy. FHE is mathematically sound and operationally unusable — we’ve written about why. Tokenization drops the fields your fraud signal actually needs. Secure enclaves depend on hardware that keeps failing: an October 2025 disclosure, TEE.fail, extracted attestation keys from fully patched Intel and AMD chips using an interposer that cost under $1,000. Blind Insight is a proxy architecture, not a hardware bet — the underlying cipher can swap to meet a local mandate without a re-architecture. See the full comparison and benchmarks. For the full DORA Article 9(2) and GDPR Art. 32 walkthrough, read how Blind Insight maps to both. And when the RTS lets you fall back to a segregated environment instead of encrypting data in use, that fallback has its own compounding cost.
From demo to production in weeks. Book a demo and we’ll walk the DORA Article 9(2) mapping against your schema, then start in the sandbox — nothing to deploy, synthetic data in your shape, live in 72 hours. Or try it on your own schema today.