Knowledge Center
Blog
What Finovate 2026 Revealed About Mobile Banking Security

Key takeaways:
Banking is moving almost entirely onto phones, and user experience is now the main competitive battleground for fintechs.
That shift has outpaced security. Software-only defenses (OTPs, push notifications, app-based checks) are increasingly easy to defeat.
The fix requires the telecom industry and the fintech industry to work together, not in separate lanes.
Hardware-rooted authentication, using the SIM or eSIM already inside every phone, is emerging as the credible answer.
As AI agents start initiating transactions on people's behalf, human-in-the-loop authorization is becoming a requirement, not a nice-to-have.
The mobile banking shift nobody has fully secured for
At Finovate 2026, one theme showed up in almost every conversation. Banking isn't just digital anymore. It's mobile-native.
Fintechs are building entire user journeys, from onboarding to high-value transactions, around the assumption that a customer will do everything from their phone. Some companies are pushing this further than most people expect, handling transactions directly through channels like SMS instead of a traditional app.
The competitive pressure right now is almost entirely about user experience. Fewer taps. Faster approvals. Less friction.
That's a reasonable goal on its own. But it creates a problem that isn't getting nearly enough attention. The more banking activity moves onto a phone, the more that phone becomes the single point of failure.
"Secure with something real": the phrase behind the shift
There's a growing sense of unease underneath the mobile banking boom, and it comes down to identity and security. Phones get lost. SIM cards get swapped. People get tricked into approving things they shouldn't. A phone is just not built to be the last line of defense for someone's money.
Software-based protections like one-time passcodes and push notifications were designed for a threat landscape that no longer exists. Attackers have caught up.
SLC Digital has built its whole positioning around one line: secure with something real.
Real, in this context, means hardware. Not a code that can be intercepted. Not a notification that can be approved by mistake or under duress. A physical, tamper-resistant root of trust that already lives inside the device, the SIM or eSIM sitting in every phone.
It's no longer enough to prove that a password or a code was entered correctly. The industry is moving toward proving that a specific, physical device, tied to a specific person, was present for a specific transaction. That's the bar SLC is trying to push the rest of the industry toward.
The missing bridge: telecom meets fintech
One of the more practical conversations happening across Finovate wasn't about a single product. It was about an entire industry gap.
Fintech and telecom have historically operated in separate lanes. Securing the mobile banking experience requires them to work together.
The telecom industry already has deep, hardware-level infrastructure for identity, built into the SIM and eSIM that sit in every phone on the planet. Fintech and banking have the transactions, the fraud exposure, and the customer relationships. Neither side can solve the mobile security problem alone.
This is where orchestration matters. Bringing mobile network-grade identity infrastructure into the fintech and banking stack isn't a single integration. It's a coordination problem between two industries that haven't historically needed to speak the same language.
Companies positioned as that connective layer, translating hardware-rooted mobile identity into something a bank's fraud and risk systems can actually use, are becoming increasingly relevant as this conversation matures.
AI agents need permission slips too
The other conversation that came up constantly was AI. Every product at Finovate seemed to have an AI angle.
But the more interesting discussion wasn't about building more AI. It was about keeping it in check.
As AI agents start taking real-world actions, checking a balance, moving money, approving a transaction, the question becomes: when should an agent be allowed to act on its own, and when does it need a human to explicitly say yes? This is the human-in-the-loop problem, and it's quickly becoming one of the defining security questions in fintech.
The proposed answer gaining traction is the same hardware-rooted approach used for authenticating people. Use a SIM-based authenticator as the checkpoint for AI-initiated actions.
Instead of trusting an API call or a session token, the system requires a real, physical, human-tied confirmation before an agent can complete a sensitive action. Several conversations at Finovate involved companies actively exploring integrations along these lines. It's becoming a procurement requirement, not a theoretical concern.
SLC Digital isn't an AI solution, and that's the point
Worth being clear about something here, since almost everything else at Finovate had an AI pitch bolted onto it somewhere.
SLC Digital isn't a model. It isn't scoring fraud risk or generating predictions or replacing a human judgment call with a smarter algorithm.
It's infrastructure. A hardware-rooted authentication layer sitting underneath whatever software, AI or otherwise, a bank or fintech is running on top of it. The SIM-based root of trust doesn't care whether the request came from a person tapping approve on their phone or an AI agent trying to move money on someone's behalf. Either way, it needs a real, physical, non-repudiable confirmation before anything moves.
That distinction gets more important as more of the stack turns into AI. Models keep getting smarter. The actual point of failure hasn't changed, proving a real person was there when it mattered.
What this means going forward
Three things are converging at once. Banking is going fully mobile. Mobile is provably hackable at the software layer. AI agents are starting to act on people's behalf without always asking first.
Each of these trends makes the other two riskier.
The direction the industry is heading is clear. Authentication is moving from something you know, a password, and something you're notified about, a push alert, to something real and physical, a hardware-rooted device identity.
Expect more partnerships between telecom infrastructure providers and fintechs. More scrutiny of AI agents that can initiate transactions. And more banks asking vendors a very specific question: can you prove a real device, tied to a real person, was actually there?
SLC Digital is one of the companies building toward that answer.
Its core technology uses the SIM and eSIM already sitting inside a phone as a hardware root of trust, producing a cryptographic proof that a specific device, and the person holding it, authorized a specific action. No app to spoof. No code to intercept. No push notification to approve under pressure.
The company positions itself as the orchestration layer between the mobile network and the bank, turning hardware-level device identity into step-up authentication and transaction assurance that a fintech's existing fraud and risk systems can actually use.


