We are live from Money 20/20 in Riyadh. My next guest — our viewers know him very well — is Ronit Ghose, Co-Chair of the Future of Finance and AI Working Group at the MENA Fintech Association. Joining us here from the show floor in Riyadh for his third year running at this event. Ronit, good to have you again with us.
Thank you for having me.
This is your third year at this event in Riyadh. What has changed the most since the first time you were here?
Two things stand out. This year is obviously bigger — it is a bigger event. Secondly, the mix. There are obviously lots of people from Saudi — Saudi nationals and people working in Saudi. But I feel there are more people from Asia, from India, from the East. That I do not think was the case two years ago. So the mix has changed and the size has changed.
What are the vectors of concern that keep you up at night when it comes to cybersecurity?
We did a great panel yesterday on this topic, and there was a wonderful one-liner which said — the future bad guys, or even the current bad guys, do not break into the bank physically. They log on. So threat actors are logging on, not breaking in physically. That is a different type of risk we have to worry about. And the biggest concerns — AI is going to increase risk, and quantum computing in about five to six years will start becoming relevant. That is going to be a real challenge because all digital data security will be compromised, and it is coming very soon.
How much worse does quantum computing make that threat landscape?
Quantum means we have to change all our cryptography. Think of it as a massive software upgrade — but it is a dynamic, multi-year project, not like Y2K which was a fixed point in time. If you are in a big bank, a big fintech, or a government, you need to start working on it now. SAMA has already issued guidelines about what banks and companies should be doing and thinking about. The US has issued guidelines as well. AI just makes everything smarter and faster — the good guys and the bad guys. It becomes a cat and mouse race between good guys using AI and bad guys using AI.
Is cross-border retail banking a real scalable model or just a plaster over local systems that do not talk to each other?
Traditional banks have become bad at doing retail cross-border. Fintechs by contrast — the likes of Revolut — are actually really good at doing retail cross-border. What do fintechs do differently? One, they focus in on specific products — it could be payments or FX. They start with a niche product and then broaden out. Secondly, they are digitally native. Think of social media apps — they are cross-border. The content might be local but the platforms are international. Fintechs could be like that. The platforms are the same but the content has to be localised.
What is the one AI use case in finance that you think is still underrated?
AI as an individual empowerment tool. I do so much work for my personal life using AI tools that a year or two ago I would have outsourced to other people. It kind of slightly levels the playing field. Big companies still have advantages, big banks still have more resources — but the gap between a small company and a big company gets narrowed. The gap between an incumbent bank and a plucky startup gets narrowed. And that makes life perhaps more interesting. So I think competition is being underestimated, and also how user friendly and user empowering AI is going to be is probably being underestimated.
Any final message for the audience before you head to your panel on cybersecurity?
Cybersecurity — the threat vector is coming online, and that makes it borderless. You are not going to be attacked by some local hoodlum. That person could be sitting behind a computer in North Korea hacking you — it could be anywhere. But also cybersecurity involves all of us. It is not just that banks and fintechs need good technology. We need good best practices as users. All those links we get sent that we know we are not supposed to click on — education has to be done. And it is not so much for young people. The 12-year-old kid knows what to do because they have grown up digitally native. It is for the older population. Banks and governments need to do a lot — maybe even families talking to parents and grandparents — because it is the older people who get compromised and hacked by bad actors.
Good luck with your panel. Thank you so much for being here with us.
Thank you for having me.