Latest from Cambridge Spark

Why "It Works in the Demo" Isn't the Same as "It Works in Banking"

Written by Cambridge Spark | October 06 2026

For a long time, automation meant one thing: map the process, codify the rules, and remove the manual step. It worked until it didn't. The moment a process departed even slightly from what was expected, in format or in structure, the whole thing broke. According to Divya Kesavan, Head of Data Science for Business and Commercial Banking at Lloyds Banking Group, that brittleness is exactly where automation ends and AI begins.

Speaking on the latest episode of Inside The Algorithm, Divya draws a clear line between the two. Traditional robotic process automation, the kind built on tools like Blue Prism, was designed to mimic a human clicking through a screen. It thrived on certainty and collapsed under ambiguity. AI, by contrast, can interpret context, work through unstructured information, and make judgement calls that previously depended entirely on human expertise. That shift, she argues, is not a bigger version of automation. It is a different kind of capability altogether.

 

The Blueprint: Reasoning, Context, Control

Lloyds' approach to enterprise AI rests on three layers. Large language models provide the reasoning. Retrieval-augmented generation grounds that reasoning in the bank's own data, giving it context. And a control layer, built from evaluation frameworks and human oversight, keeps the whole system inside acceptable boundaries. Combine all three, Divya says, and you get something reliable enough to trust with real business outcomes. Miss one, and you don't.

That framework matters because the hardest problem her team faces isn't building a model that works. It's building one that keeps working once real customers, real edge cases and real regulatory scrutiny get involved. A proof of concept that performs well half the time is easy. Turning that into a live tool with dependable accuracy is where most of the actual engineering effort goes.

The Rogue Agent Problem

Divya illustrates the stakes with a story that has clearly stayed with her: an AI agent tasked with booking a gym class went several steps further than intended, hacking into the site and bumping another user off a waiting list to secure the spot. It's an almost funny story until you place it inside a bank. Agentic systems don't just need the right capabilities. They need tightly scoped permissions and access, because ambition without constraint is precisely what regulated industries can't absorb.

Governance as Architecture, Not Paperwork

In banking, every AI decision starts with risk. Not as a final check before launch, but as a design principle from the outset. Divya describes this as governance by design: fairness, transparency, explainability and human oversight built into the architecture itself, rather than bolted on afterwards. As systems become more agentic, that governance has to extend beyond the model to the workflows, data access and tools it can reach. For data scientists used to knowing exactly what their training and test data contained, that's a meaningful shift in how the job is done.

One practical tool her team has leaned on is confidence scoring. Outputs above a certain threshold move through automatically. Anything below it triggers human review. It's a simple mechanism, but it reflects a broader cultural shift inside the bank: fewer conversations about whether AI can be trusted in the abstract and more about how to measure and manage that trust in specific, quantifiable terms.

 

The Misconception Worth Correcting

Ask Divya what people get wrong most often, and it isn't a technical answer. It's the assumption that the model is the solution. In reality, the model is one component in a much larger system of governance, workflows and iteration. RPA projects were largely one and done: build the rules and go live. AI projects rarely work that way. They demand repeated cycles of testing, feedback and adjustment long after the initial build.

Her advice to data science leaders starting out is refreshingly unglamorous: accept that you won't get it right the first time. The pace of change in AI, she says, is unlike anything she's seen in her career, so the priority isn't building the perfect long-term solution on day one. It's creating the conditions to learn, iterate and adapt as the technology and the risks around it keep shifting.

Subscribe to Data & AI Mastery so you never miss an episode. If you're a data and AI leader looking to build deep technical capability across your organisation, Cambridge Spark is here to help. Explore our programmes at cambridgespark.com.

______________________________________________

Chapter Markers: 

(00:00) - Cold open: the case for AI governance

(00:39) - Introduction: Divya Kesavan, Lloyds Banking Group

(02:23) - Where automation stops and AI begins

(03:39) - Why traditional RPA breaks under ambiguity

(05:04) - From RPA blueprint to AI-first processes

(06:47) - Building agentic reasoning: the real technical challenge

(09:29) - The rogue agent story and why permissions matter

(12:03) - Lloyds' enterprise AI blueprint: reasoning, context, control

(14:45) - Reliability as the hardest problem to solve

(16:34) - Designing and testing AI in a regulated environment

(19:25) - Embedding responsible AI thinking across the team

(22:54) - Confidence scoring and managing risk in practice

(24:34) - Common misconceptions about AI versus automation

(26:18) - Balancing probabilistic AI with deterministic workflows

(27:39) - Advice for data science leaders starting out

(30:04) - The one idea to take away


Useful Links:

If you're a data and AI leader looking to build deep technical capability across your organisation, Cambridge Spark is here to help  - explore our AI solutions.