
Thales VP Caio Reis says banks have 18-24 months to prepare payment systems for AI-initiated transactions, warning that legacy lift-and-shift cloud migrations preserve technical debt.
Banks are rebuilding payment systems for a future where software, not people, initiates transactions. The shift will force issuers to rethink how they authenticate payments, manage credentials and modernize legacy infrastructure.
Caio Reis, vice president of strategy at Thales, told PYMNTS that AI purchasing sits at the center of several developments often discussed separately: authentication, tokenization and passwordless commerce. Consumers already use generative AI to research products and compare prices. The next step comes when AI moves from advising a shopper to completing a purchase autonomously.
“What is missing now is to be able to pay for yourself autonomously,” Reis said. “Tomorrow, the issuers will have to be ready to accept those payments. Those payments need to be authenticated.”
Payment passkeys, passwordless authentication and tokenization will become part of the infrastructure required to support that model, he said. For issuers, modernization must move beyond a predetermined schedule toward an architecture that can accommodate capabilities whose commercial importance may develop quickly.
Reis said he sees an 18- to 24-month window in which banks need to prepare for what he called “identity commerce,” including the partners and technology needed to support it.
Competition has become another consideration as consumers use FinTechs and neobanks for more of their primary banking relationships. Reis said he is wary of “lift and shift” projects that transfer existing applications to the cloud without changing their underlying architecture. Such migrations may lower hosting expenses. They leave much of the original technical and functional debt intact.
Modernization includes shorter software release cycles, lower operating costs and simpler technologies. Reis contrasted release cycles measured in weeks with legacy environments where software may be released only twice a year.
Changing that architecture creates its own hazards. Reis identified integration complexity as one of the major risks, particularly when banks attempt to connect new technology to a dense collection of existing systems.
Banks should also manage migration risk, Reis said. A complete replacement may be necessary in some circumstances. Other institutions can migrate individual portfolios over several years. Another approach separates the customer-facing experience from the back end, allowing banks to modernize specific use cases while older and newer infrastructure coexist.
The front end can change before every component underneath it has been replaced. Back-end functions can then migrate individually, reducing the operational exposure associated with a single large conversion.
AI purchasing, tokenization and passwordless authentication will add new requirements to payment systems. Banks that carry every legacy product variation, integration and decision process into the new environment may preserve many of the constraints they intended to remove. Reis said the 18-month timeline means issuers need to start simplifying now.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.