Innovation to Regulatory Compliance: How Swedish Banks Ensure Data Privacy and Security in AI Adoption
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesis
Abstract [en]
Problematization: The rapid adoption of Artificial Intelligence (AI) in banking raises challenges for data privacy and security. While existing literature acknowledges the tension between AI innovation and regulatory compliance, there is limited empirical research on how Swedish banks balance this under GDPR and the AI Act. This thesis fills that gap by investigating how Swedish banks manage implementation of AI, while ensuring data privacy, security, and regulatory compliance.
Purpose: The thesis aims to explore how Swedish banks manage data privacy, security and regulatory compliance in the context of implementation of AI. It identifies the practices applied for AI adoption while meeting legal obligations and offers country-specific insights into the dynamics between AI and regulatory requirements in the Swedish banking sector.
Method: This thesis adopts an exploratory, qualitative method grounded in interpretivism and an inductive approach, to identify themes and patterns from gathered data. Data was collected through semi-structured interviews with AI and IT experts representing large Swedish banks. Secondary sources, such as bank reports and regulatory publications supported the analysis. Thematic coding and triangulation were applied to ensure trustworthiness.
Main results: Swedish banks ensure data privacy and security in AI implementation by treating regulatory compliance as a proactive and strategic priority. Through structured processes, technical safeguards, and continuous oversight, banks embed risk management and data governance into operations. Key mechanisms such as DPIAs, DPOs, and ethical frameworks, enhance transparency and stakeholder assurance. Successful AI adoption requires alignment between innovation with early integration of ethical and legal considerations.
Place, publisher, year, edition, pages
2025. , p. 74
Keywords [en]
“AI Act”, “AI Act Banking”, “AI disclosure”, “AI in banking”, “AI in Swedish Banking”, “AI and data privacy and security”, “Cybersecurity in banking”, “Data privacy in banking”, “Data privacy loss”, “Data Privacy and Security Sweden”, “Ethical and privacy considerations in banking”, “Ethics of data protection”, “Fintech in banking”, “GDPR”, “GDPR in banking”, “GDPR in AI”, “Machine learning and AI”, “Stakeholder theory”, “Stakeholders in banking”, “Stakeholder theory banking”, “Swedish Banking System”, “The right to privacy”.
National Category
Business Administration
Identifiers
URN: urn:nbn:se:hj:diva-68485OAI: oai:DiVA.org:hj-68485DiVA, id: diva2:1969153
Subject / course
JIBS, Business Administration
Supervisors
Examiners
2025-06-252025-06-132025-10-13Bibliographically approved