Skip to Content
  • Article
  • Open Access

10 August 2026

43 Pages

Artificial Intelligence Governance and Organizational Readiness in Banking: Evidence from Albania

,
and
Faculty of Economy, University of Tirana, 1001 Tirana, Albania
*
Author to whom correspondence should be addressed.

Abstract

Artificial intelligence (AI) is increasingly transforming banking, yet responsible adoption depends not only on technical deployment but also on organizational readiness, governance capacity, monitoring practices, and the capacity to scale AI responsibly. This study examines AI adoption, governance readiness, maturity, perceived benefits, adoption barriers, and scaling intention in the Albanian banking system. Based on a cross-sectional survey of 85 professionals from 15 institutions, including all 12 banks operating in Albania and 3 additional financial institutions, the study applies the Technology–Organization–Environment framework together with principles of responsible AI governance. The analysis uses reliability and validity diagnostics, common-method diagnostics, robust OLS regressions, institution-clustered inference, bootstrap confidence intervals, PLS-SEM robustness analysis, and sensitivity checks. The findings show that AI adoption is visible but uneven: more than half of respondents reported active or pilot AI use, while integration, monitoring, and benefit measurement remain less developed. Data and Technology Readiness and Environmental/Regulatory Pressure were positively associated with Capability-Governance Readiness, which was positively associated with Perceived Benefits. Perceived Benefits were positively associated with Intention to Invest in or Scale AI, whereas Adoption Barriers showed no statistically significant association with scaling intention. The study provides exploratory evidence from a small banking system, indicating that responsible AI development requires the alignment of technological foundations, organizational capability, governance structures, monitoring routines, responsible-use orientation, and benefit-measurement practices.

1. Introduction

Artificial intelligence (AI) is becoming increasingly embedded in banking activities, including fraud detection, anti-money-laundering monitoring, credit-risk assessment, customer-service automation, document processing, cybersecurity, and internal decision support. Its growing use reflects the potential of AI to improve operational efficiency, analytical capacity, risk management, and service delivery. At the same time, it introduces challenges related to data quality, model risk, explainability, cybersecurity, accountability, and dependence on third-party technology providers (Basel Committee on Banking Supervision, 2024; Financial Stability Board, 2024, 2025). These developments shift attention from the adoption of individual AI applications to the broader institutional conditions required to integrate, monitor, evaluate, and scale them responsibly.
Banking provides a particularly relevant context for examining these conditions. Banks rely on data-intensive processes and use analytical systems in activities that may directly affect customers, institutional risk, and financial stability. AI applications in areas such as credit assessment, fraud detection, transaction monitoring, and regulatory compliance are therefore closely connected with prudential supervision, data protection, model governance, operational resilience, consumer protection, and human oversight (Basel Committee on Banking Supervision, 2024; European Banking Authority, 2025). The value of AI in banking consequently depends not only on technical performance, but also on whether banks possess the organizational capabilities, governance arrangements, and monitoring practices needed to manage its risks and sustain its use.
The relevance of these conditions is increasing as banks expand their use of advanced analytics, generative AI, and externally provided AI solutions while supervisory expectations continue to evolve. When technological adoption develops more rapidly than internal governance capacity, gaps may emerge in accountability, model validation, data protection, explainability, and third-party oversight. Such challenges may be more pronounced in smaller banking systems, where specialized expertise, technological resources, and implementation capacity can be unevenly distributed across institutions. Understanding the relationship between technological readiness, governance capability, responsible AI practices, and scaling intention is therefore relevant to both banks and supervisory authorities (European Banking Authority, 2025; Financial Stability Board, 2024, 2025).
Although research on AI in banking has expanded, existing studies have frequently examined specific applications, general adoption determinants, customer acceptance, digital transformation, operational benefits, or individual dimensions of AI-related risk (Eskandarany, 2024; Lazo & Ebardo, 2023; Singh et al., 2025). These contributions provide important evidence on the drivers and consequences of AI use but offer a more limited understanding of how technological readiness, organizational and governance capability, environmental and regulatory pressure, responsible AI orientation, perceived benefits, adoption barriers, and scaling intention are related within a single empirical framework. Empirical evidence on these relationships remains particularly limited for small or emerging banking systems (Ajili Ben Youssef et al., 2025; Singh et al., 2025; Vuković et al., 2025).
Albania provides a relevant setting in which to examine this research problem. Its financial system is bank-dominated, and the banking sector comprises 12 licensed banks operating under the supervision of the Bank of Albania (Bank of Albania, 2026a, 2026b). The sector is undergoing digital transformation through the expansion of digital banking channels, process automation, data-driven services, and emerging AI-supported solutions. Evidence from the Albanian banking-sector digitalization survey indicates that banks are pursuing digital transformation at different levels of implementation and organizational development (Bank of Albania, 2026b). At the same time, Albanian banks operate within a regulatory environment increasingly influenced by European and international expectations concerning data governance, cybersecurity, outsourcing, operational resilience, transparency, and accountability. These conditions make Albania an informative setting for examining whether the growing use of AI is accompanied by the technological readiness, organizational capability, governance structures, and responsible-use practices required for its institutional integration and further scaling.
This study addresses this gap by examining AI adoption as a readiness and maturity phenomenon in the Albanian banking system. The empirical analysis is based on 85 valid responses collected from experienced professionals across 15 institutions, covering all 12 banks operating in Albania and three additional financial institutions, two of which are fintech institutions. The analysis focuses on the relationships between Data and Technology Readiness, Environmental/Regulatory Pressure, Capability–Governance Readiness, Responsible AI Orientation, Perceived Benefits, Adoption Barriers, and Intention to Invest in or Scale AI. The study develops and tests a parsimonious conceptual model linking these technological, organizational, governance, environmental, and strategic dimensions. It also constructs a descriptive AI Maturity Index that combines adoption and integration, technological readiness, capability–governance readiness, and responsible AI orientation. The focus is therefore not only on the presence of AI applications, but also on the organizational and governance capacity required to integrate, monitor, and scale AI responsibly.
The study contributes to the literature in three main ways. First, it provides empirical evidence on AI readiness and governance within the banking system of a small European economy, a context that remains underrepresented in AI banking research (Singh et al., 2025; Vuković et al., 2025). By covering all banks operating in Albania, the study offers a broad institutional view of how AI adoption, governance readiness, monitoring, and scaling capacity are developing in an institutionally concentrated banking system. Second, it shifts the focus from AI adoption as a binary deployment question toward AI maturity, governance capability, and readiness to scale. This distinction recognizes that the presence of AI applications does not necessarily imply their integration into organizational processes or the existence of adequate monitoring and governance arrangements. Third, it connects the TOE-based adoption framework, institutional pressure, and responsible AI governance within a single empirical model (DiMaggio & Powell, 1983; Fundira & Mbohwa, 2025; International Organization for Standardization, 2023; Tabassi, 2023; Tornatzky et al., 1990). In this way, the study contributes to administrative and organizational research on responsible digital transformation in regulated institutions, where AI adoption requires the alignment of technological, organizational, governance, and responsible-use dimensions. It extends existing AI adoption research by examining how these dimensions are associated with perceived benefits and scaling intention within a small and institutionally concentrated banking system.
The results show that AI adoption in the Albanian banking context is visible but uneven. AI use is present, but integration, monitoring, and benefit measurement remain less developed. The AI Maturity Index indicates a banking system in transition, with substantial variation across respondents and institutions. The regression results support the positive associations of Data and Technology Readiness and Environmental/Regulatory Pressure with Capability–Governance Readiness, the positive association between Capability–Governance Readiness and Perceived Benefits, and the positive association between Perceived Benefits and Intention to Invest in or Scale AI. Adoption Barriers showed no statistically significant association with scaling intention. Overall, the findings indicate that the next stage of AI development in Albanian banking depends not only on expanding AI use cases, but also on strengthening governance readiness, monitoring practices, benefit measurement, and responsible scaling capacity.

2. Theoretical Background and Hypotheses Development

2.1. Study Background: Banking, AI Governance, and Organizational Readiness in Albania

Albania has a bank-dominated financial system in which commercial banks play a central role in financial intermediation, payment services, and the transmission of monetary and regulatory policy. At the time of the study, 12 licensed banks operated under the supervision of the Bank of Albania (Bank of Albania, 2026a). Although relatively small in international terms, the banking system includes institutions with different ownership structures, organizational capacities, technological infrastructures, and levels of digital development. This heterogeneity provides an appropriate setting for examining AI readiness and governance within an institutionally concentrated banking system.
Digital transformation has become increasingly visible in Albanian banking through the expansion of online and mobile services, process automation, digital payment infrastructure, and data-intensive approaches to customer service, risk management, and operational decision-making. The Bank of Albania’s banking-sector digitalization survey indicates that this transformation is progressing at different levels of implementation and organizational development across the sector (Bank of Albania, 2026b). AI-supported applications are emerging within this process, particularly in customer interaction, automation, data analysis, and internal operational support. However, the presence of individual applications does not necessarily imply that AI has been integrated into core processes or supported by mature governance, monitoring, and performance-measurement arrangements.
AI governance in Albanian banking develops within a regulatory environment shaped by domestic supervision and wider European and international standards. The Bank of Albania is responsible for the licensing, regulation, and supervision of banks and for supporting the stability and effective functioning of the financial system. AI-related developments therefore interact with established requirements concerning data governance, cybersecurity, operational resilience, outsourcing, model risk, consumer protection, and internal control. The European Banking Authority (2025) similarly emphasizes that AI applications involving creditworthiness and credit scoring must be considered alongside existing banking, data-protection, risk-management, and consumer-protection requirements. The Basel Committee on Banking Supervision (2024) identifies AI, machine learning, cloud computing, and third-party technology provision as interconnected dimensions of financial digitalization with implications for operational resilience and supervisory capacity.
These developments create opportunities for greater efficiency, fraud detection, customer service, compliance monitoring, and analytical decision-making, but they also place demands on data quality, infrastructure, expertise, governance, model monitoring, and third-party oversight. Smaller banking systems may face particular constraints in accessing specialized skills, modernizing legacy systems, developing dedicated governance arrangements, and independently assessing externally provided solutions. Readiness consequently extends beyond access to technology. It includes the capacity to select appropriate use cases, allocate resources, establish accountability, monitor performance and risk, and integrate AI into organizational processes.
Responsible AI adds a further dimension to this capacity. Principles such as transparency, explainability, fairness, privacy, accountability, human oversight, and auditability must be translated into operational practices. The NIST AI Risk Management Framework and ISO/IEC 42001 provide general principles and management-system requirements for trustworthy and accountable AI (International Organization for Standardization, 2023; Tabassi, 2023). Their application in banking depends on how institutions connect these principles with existing risk-management, compliance, audit, data-governance, and model-validation structures. The Albanian setting therefore supports an examination of AI adoption as a process of organizational readiness, governance, integration, and maturity rather than as a binary distinction between adoption and non-adoption.

2.2. AI Governance and Organizational Readiness Across Industries

Research across industries shows that effective AI adoption depends on a combination of technological, organizational, and institutional conditions. Jöhnk et al. (2021) identify strategic alignment, resources, knowledge, organizational culture, and data capabilities as central elements of AI readiness. Based on a systematic review of 52 studies, Ali and Khan (2025) similarly highlight IT infrastructure, top-management support, resource availability, organizational capabilities, compatibility, data quality, and financial capacity. These findings establish readiness as a multidimensional concept, although much of the literature concentrates on conditions preceding adoption and gives less attention to governance after AI enters organizational use.
Evidence from manufacturing and supply-chain management emphasizes the integration of AI with existing technologies, workflows, and operational capabilities. Shahzadi et al. (2024) find that infrastructure, data availability, managerial support, workforce competencies, environmental pressure, and implementation barriers shape AI adoption in supply chains. This research demonstrates that technological potential produces organizational value only when supported by compatible processes and internal capabilities. Its principal focus, however, remains operational performance, resilience, and process optimization, while accountability, explainability, and governance of automated decisions receive less systematic attention.
Research in hospitality also shows that readiness and intention do not necessarily result in effective implementation. In a study of 1821 licensed accommodation providers in Albania, Godolja et al. (2025) identify distinct adopter profiles and find that innovation readiness is associated with broader AI and smart-technology adoption. Competitive pressure strengthens perceived usefulness, but the translation of intention into actual use varies across adopter groups. The findings indicate that positive attitudes toward AI may coexist with financial, organizational, and infrastructural constraints. Although hospitality differs from banking in regulatory intensity and risk exposure, this evidence illustrates how interest in AI can develop more rapidly than the capabilities required for systematic integration.
Public-sector research gives greater attention to legitimacy, transparency, institutional accountability, and compliance with formal rules. de Almeida and dos Santos Júnior (2025) show that AI governance in public organizations depends on translating ethical principles and regulatory guidance into training, defined responsibilities, internal procedures, and oversight practices. Formal standards or organizational commitments alone do not ensure effective governance; responsible AI principles become operational when embedded in decision-making, system development, procurement, monitoring, and use.
Healthcare provides a closely regulated setting in which AI may influence diagnosis, treatment, resource allocation, and patient safety. Based on a systematic review of governance frameworks, Hussein et al. (2026) identify interrelated domains covering organizational structure, problem formulation, product evaluation, model development, deployment, integration, monitoring, and maintenance. Their maturity-based approach also indicates that comprehensive governance frameworks can place substantial demands on organizations with limited resources, drawing attention to differences in institutional capacity to apply general standards.
Across these sectors, reliable data, compatible infrastructure, appropriate resources, leadership support, specialized expertise, defined accountability, validation, and continuous monitoring emerge as recurring conditions. The literature also distinguishes implementation capacity from governance: readiness concerns whether an organization can adopt and integrate AI, while governance concerns how its development and use are directed, monitored, and held accountable. These insights provide a useful foundation for banking research, but their transfer requires attention to the sector’s combination of commercial objectives, prudential supervision, financial-stability considerations, consumer protection, model-risk management, anti-money-laundering obligations, and third-party dependence.

2.3. AI Adoption and Governance in Banking

AI applications in banking include fraud detection, anti-money-laundering monitoring, credit-risk assessment, customer-service automation, document processing, cybersecurity, marketing analytics, and internal decision support. These applications can improve efficiency, analytical accuracy, service responsiveness, and risk identification, but their organizational value depends on data quality, compatibility with existing systems, and the capacity to monitor performance and manage risk (Lazo & Ebardo, 2023; Singh et al., 2025).
The banking literature has developed along several related streams. Adoption studies emphasize data availability, infrastructure, managerial support, employee expertise, implementation resources, and perceived usefulness (Ajili Ben Youssef et al., 2025; Rahman et al., 2021). Outcome-oriented research examines efficiency, forecasting accuracy, risk management, and financial performance (Alassuli et al., 2026; Baffour Gyau et al., 2024). Governance research focuses on explainability, algorithmic bias, data protection, cybersecurity, accountability, and model oversight (Eskandarany, 2024; Fundira & Mbohwa, 2025; Vuković et al., 2025). Although these streams establish AI adoption as both a technological and organizational process, they often examine its antecedents, benefits, and governance implications separately.
Systematic reviews confirm this fragmentation. Singh et al. (2025), based on 157 studies, identify themes relating to customer service, customer readiness, financial inclusion, regulation, explainability, applications, and adoption barriers. Vuković et al. (2025) similarly show that AI integration in financial services is shaped by technological development, institutional requirements, and regulatory challenges. These reviews document the breadth of the field but also indicate that evidence remains organized primarily around specific applications or individual dimensions of adoption. Fewer studies examine technological readiness, organizational capability, governance, regulatory pressure, perceived benefits, barriers, and scaling intention within the same empirical framework.
Governance is particularly important because AI may influence credit access, fraud classification, customer profiling, compliance monitoring, and risk assessment. Weak arrangements can create problems involving data quality, model instability, explainability, discriminatory outcomes, cybersecurity, and unclear accountability. Third-party models, cloud services, and generative AI may introduce additional dependencies and reduce direct institutional control. Financial Stability Board (2024, 2025) identifies third-party concentration, cyber risk, model risk, data quality, and governance weaknesses as potential vulnerabilities, while the Basel Committee on Banking Supervision (2024) emphasizes the implications of digitalization for operational resilience, outsourcing, and supervision. The European Banking Authority (2025) further highlights the interaction between AI-specific requirements and existing banking and payments regulation.
Evidence from Albania reflects similar opportunities and constraints. Earlier research identifies potential applications in fraud detection, credit-risk assessment, cybersecurity, customer service, and automation, alongside challenges related to data quality, legacy-system integration, transparency, expertise, and regulatory alignment (Godolja & Domi, 2024). However, this evidence primarily maps applications and perceived barriers. It provides a more limited account of how technological foundations, organizational capability, governance readiness, responsible-use orientation, environmental pressure, perceived benefits, and scaling intention are connected. A broader institutional approach is therefore needed to understand how AI moves from isolated use cases toward integrated and responsibly governed banking practice.

2.4. Technology–Organization–Environment Framework and Institutional Pressure

The Technology–Organization–Environment (TOE) framework provides the principal organizational-level foundation for this study. It explains technology adoption through three interrelated contexts: the characteristics of the technology available to the organization, its internal organizational conditions, and its external environment (Tornatzky et al., 1990). By moving beyond individual acceptance, TOE accommodates technological infrastructure, organizational resources, managerial capability, regulation, competition, and external support within the same analytical perspective (Awa et al., 2017; Baker, 2012).
In AI research, the technological context commonly includes data quality, infrastructure, compatibility, integration complexity, and security. The organizational context covers managerial support, resources, expertise, training, strategic alignment, and implementation capability. The environmental context includes regulatory requirements, competition, customer expectations, and vendor support. Cross-industry reviews confirm the relevance of these dimensions, although their importance varies by sector and stage of implementation (Ali & Khan, 2025; Shahzadi et al., 2024).
In the present study, Data and Technology Readiness represents the technological context by capturing data quality, data-governance processes, infrastructure, and integration conditions. Capability–Governance Readiness represents the organizational context by combining implementation resources with governance capacity. Environmental/Regulatory Pressure captures the external context through regulatory and supervisory expectations, market competition, and customer demand. This operationalization retains the three-part structure of TOE while adapting it to AI adoption in banking.
TOE does not fully explain why institutions facing similar technological opportunities respond differently to regulatory, professional, and legitimacy pressures. Institutional theory complements the framework through coercive, mimetic, and normative mechanisms (DiMaggio & Powell, 1983). In banking, regulation and supervision create coercive pressure, competitive uncertainty can generate mimetic responses, and professional standards shape normative expectations. These forces may encourage institutions to strengthen internal capability, governance, transparency, accountability, and oversight (Basel Committee on Banking Supervision, 2024; European Banking Authority, 2025; Financial Stability Board, 2024, 2025).
Together, TOE and institutional theory explain the technological, organizational, and environmental conditions associated with implementation and how external expectations may influence internal readiness. Neither framework, however, provides a detailed account of the principles and practices required for responsible AI. Responsible AI governance is therefore incorporated as a complementary perspective, enabling the model to distinguish organizational capacity from the responsible-use orientation guiding its application.

2.5. Responsible AI Governance and Capability-Governance Readiness

AI governance comprises the structures, responsibilities, processes, and controls through which organizations direct, monitor, and account for AI development and use. International frameworks treat it as an organizational management issue rather than solely a technical property. The NIST AI Risk Management Framework identifies validity, reliability, safety, resilience, transparency, explainability, privacy, fairness, and accountability as interrelated characteristics of trustworthy AI (Tabassi, 2023). ISO/IEC 42001:2023 similarly connects policy, leadership, risk assessment, operational controls, performance evaluation, and continuous improvement (International Organization for Standardization, 2023).
In banking, AI governance should be integrated with existing systems of risk management, internal control, compliance, audit, model validation, and prudential supervision. This is especially important when banks use externally developed models, cloud services, generative AI tools, or vendor-provided applications. Responsibility remains with the institution even when development or operation is partly external, increasing the importance of documentation, third-party assessment, monitoring, and clear accountability (Basel Committee on Banking Supervision, 2024; Financial Stability Board, 2024, 2025).
Capability–Governance Readiness represents the organizational capacity to implement and oversee AI. It combines skills and resources with an AI strategy, assigned responsibilities, formal approval procedures, model validation and monitoring, standardized documentation, and cross-functional oversight. Banks may have access to relevant technologies but remain unable to use them systematically if they lack expertise, dedicated resources, coordinated decision-making, or formal governance processes (Ajili Ben Youssef et al., 2025; Eskandarany, 2024; Rahman et al., 2021).
Responsible AI Orientation captures the extent to which transparency, explainability, fairness, privacy, accountability, human oversight, auditability, and preparedness for AI-related incidents guide institutional practice. It is reflected in reported safeguards and control practices rather than only in stated ethical preferences. Capability–Governance Readiness therefore concerns whether an institution has the structures and resources to implement and oversee AI, whereas Responsible AI Orientation concerns the principles and safeguards guiding that capacity.
The constructs are related but not interchangeable. An institution may possess staff, resources, formal responsibilities, and monitoring procedures without consistently emphasizing fairness, privacy, explainability, or human oversight. Conversely, it may support responsible-use principles while lacking the capability to operationalize them. Their distinction allows the analysis to examine whether organizational capacity and responsible-use orientation have separate associations with Perceived Benefits.

2.6. Perceived Benefits, Adoption Barriers, and AI Maturity

Perceived Benefits refer to the operational and strategic value that organizational decision-makers associate with AI. In banking, these expectations include greater efficiency, improved fraud detection, stronger risk analysis, more responsive customer service, faster processing, improved compliance monitoring, and better decision support (Lazo & Ebardo, 2023; Rahman et al., 2021; Singh et al., 2025). They should be distinguished from objectively measured outcomes, particularly where institutions have limited evidence on realized changes in cost, productivity, risk, or service quality.
Readiness and governance may shape perceived value by enabling banks to identify feasible use cases, allocate resources, coordinate implementation, and monitor performance. Formal responsibilities, approval procedures, validation requirements, and risk controls can reduce uncertainty surrounding implementation. Perceived Benefits may therefore depend not only on AI’s technical potential but also on whether an institution can implement and oversee it reliably (Ajili Ben Youssef et al., 2025; Eskandarany, 2024).
Adoption Barriers include cost, shortages of expertise, limited data quality and accessibility, legacy-system integration, regulatory uncertainty, ethical and reputational concerns, cybersecurity, and dependence on external providers (Lazo & Ebardo, 2023; Singh et al., 2025; Vuković et al., 2025). These conditions can constrain implementation or scaling by increasing complexity, uncertainty, and risk. However, institutions with greater exposure to AI may also become more aware of implementation difficulties. Perceived barriers may therefore coexist with positive assessments of AI value and intentions to expand its use.
Intention to Invest in or Scale AI captures plans to increase investment, extend AI to core processes, and strengthen related governance and audit arrangements. It is a forward-looking organizational position and should not be interpreted as evidence that future implementation will necessarily occur. Scaling requires more than adding applications; it involves extending AI across functions while maintaining data quality, system compatibility, oversight, and risk control.
AI maturity describes the progression from isolated experimentation toward integration supported by appropriate technological foundations, organizational capability, governance, monitoring, and responsible-use practices. In this study, it is represented descriptively through an AI Maturity Index combining Adoption and Integration, Data and Technology Readiness, Capability–Governance Readiness, and Responsible AI Orientation. The index summarizes complementary dimensions of institutional development rather than defining a causal or universal maturity model. Its construction follows general principles for composite indicators, including theoretical justification, transparent normalization, and sensitivity analysis of the weighting structure (Diamantopoulos & Winklhofer, 2001; Nardo et al., 2005). Detailed procedures are reported in the Materials and Methods and Supplementary Materials.
Perceived Benefits, Adoption Barriers, scaling intention, and AI maturity consequently represent distinct aspects of institutional engagement with AI: expected value, implementation constraints, future orientation, and current organizational development. Maintaining these distinctions avoids treating adoption, performance, constraints, and future investment as equivalent manifestations of the same construct.

2.7. Research Gap and Hypotheses Development

The literature identifies technological readiness, organizational capability, environmental pressure, governance, responsible-use practices, perceived value, and implementation barriers as relevant to AI adoption. However, these dimensions are often examined separately. Organizational-adoption studies emphasize technological and institutional antecedents, responsible AI research focuses on ethics and accountability, and banking studies frequently address specific applications, outcomes, or regulatory concerns. As a result, limited evidence is available on how these dimensions relate within a single institutional framework, particularly in small banking systems (Lazo & Ebardo, 2023; Singh et al., 2025; Vuković et al., 2025).
The present framework addresses this gap through six hypothesized associations. The two paths to Perceived Benefits are formulated as H3a and H3b to distinguish organizational and governance capacity from responsible-use orientation.
Data and technology provide the operational foundation for AI implementation. Reliable data, formal data-governance processes, scalable infrastructure, and system compatibility support model development, validation, monitoring, and organizational integration. Within TOE, these conditions reduce implementation uncertainty and enable organizations to develop the capabilities required to manage new technologies (Baker, 2012; Tornatzky et al., 1990). AI-readiness research likewise identifies data quality, infrastructure, compatibility, and technical capability as central to implementation (Ali & Khan, 2025; Jöhnk et al., 2021). Accordingly:
H1. 
Data and Technology Readiness is positively associated with Capability–Governance Readiness.
Banks also respond to regulatory, competitive, and customer-related pressures. Supervisory expectations can encourage clearer governance responsibilities, stronger monitoring, better documentation, and more formal risk-management practices. Competition may stimulate investment in AI capabilities, while customer expectations can increase the organizational importance of automated and personalized services. Institutional theory explains these influences through coercive, mimetic, and normative pressures (DiMaggio & Powell, 1983). Empirical banking studies similarly associate environmental and regulatory conditions with AI adoption and organizational readiness (Ajili Ben Youssef et al., 2025; Rahman et al., 2021). Accordingly:
H2. 
Environmental/Regulatory Pressure is positively associated with Capability–Governance Readiness.
Banks with stronger implementation and governance arrangements are better positioned to identify feasible use cases, coordinate resources, monitor performance, and control operational risk. These capabilities can strengthen perceptions of AI’s contribution to efficiency, fraud detection, risk management, customer service, and decision quality (Baffour Gyau et al., 2024; Eskandarany, 2024; Rahman et al., 2021). Accordingly:
H3a. 
Capability–Governance Readiness is positively associated with Perceived Benefits, after accounting for Responsible AI Orientation.
Responsible AI Orientation may contribute to Perceived Benefits through transparency, explainability, fairness, privacy, accountability, human oversight, and risk awareness. These safeguards can strengthen confidence in the reliability and acceptability of AI-supported processes, particularly where applications affect high-impact decisions and regulated activities. Their contribution is conceptually distinct from the resources and structures captured by Capability–Governance Readiness (Fundira & Mbohwa, 2025; Tabassi, 2023; Vuković et al., 2025). Accordingly:
H3b. 
Responsible AI Orientation is positively associated with Perceived Benefits, after accounting for Capability–Governance Readiness.
Organizations are more likely to expand AI when decision-makers expect meaningful operational or strategic value. Perceived improvements in efficiency, risk management, fraud detection, customer service, compliance, and analytical decision-making can strengthen support for further investment and wider integration. Banking studies similarly associate perceived advantages with stronger adoption intentions (Ajili Ben Youssef et al., 2025; Rahman et al., 2021). Accordingly:
H4. 
Perceived Benefits are positively associated with Intention to Invest in or Scale AI.
Implementation costs, limited expertise, data problems, legacy-system integration, regulatory uncertainty, ethical and reputational concerns, cybersecurity, and third-party dependence can reduce the feasibility of further expansion (Lazo & Ebardo, 2023; Singh et al., 2025; Vuković et al., 2025). Although experience may increase awareness of these difficulties, the theoretical expectation is that stronger perceived constraints reduce willingness or organizational capacity to scale AI. Accordingly:
H5. 
Adoption Barriers are negatively associated with Intention to Invest in or Scale AI.
The hypotheses describe a framework in which technological readiness and environmental pressure are associated with Capability–Governance Readiness; Capability–Governance Readiness and Responsible AI Orientation are associated with Perceived Benefits; and Perceived Benefits and Adoption Barriers are associated with scaling intention (Figure 1). Because the empirical analysis uses cross-sectional survey data, the hypotheses concern associations rather than causal effects.
Figure 1. Conceptual model of AI adoption, governance readiness, perceived benefits, and scaling intention.

3. Materials and Methods

3.1. Research Design and Data Collection

This study used a cross-sectional survey design to examine artificial intelligence adoption, governance readiness, AI maturity, perceived benefits, adoption barriers, and intention to invest in or scale AI in the Albanian banking system. The study focuses on perceived organizational conditions that may support or limit responsible AI adoption. These conditions include technological readiness, environmental and regulatory pressure, governance capability, responsible AI orientation, perceived value, and future scaling intention.
The unit of observation was the individual survey response. However, the main phenomenon examined in the study is organizational in nature, since AI readiness and governance are shaped by institutional capabilities, processes, and structures. For this reason, the responses are interpreted as informed professional perceptions of organizational conditions. They should not be understood as official institutional statements or as independently audited organization-level measures. Rather, they provide relevant assessments from professionals working primarily in banks, complemented by a small number of respondents from institutions connected to the wider financial-technology environment.
A survey design was considered appropriate because several important aspects of AI adoption are not directly observable from public financial data. These include governance readiness, perceived implementation barriers, monitoring practices, use-case experience, benefit measurement, and future intention to scale AI. The study therefore examines associations among the main constructs rather than causal effects. Accordingly, the empirical results are interpreted as cross-sectional associations (Podsakoff et al., 2024; Hair et al., 2019).
Data were collected through a structured questionnaire administered between 5 April and 5 May 2026. The survey targeted professionals in roles relevant to AI adoption, governance, technology, risk, compliance, and organizational decision-making in Albanian banking and a small number of related financial institutions. Respondents included professionals in business and management roles, IT, digital, data and analytics roles, compliance and AML-related roles, and other functions related to banking operations, technology adoption, governance, risk, compliance, data, analytics, or organizational decision-making. These roles were considered appropriate for assessing perceived organizational readiness and AI governance conditions. The final analytical sample consisted of 85 valid responses. Respondent and institutional characteristics, including professional role, sector experience, institution size, AI adoption status, implementation model, integration level, monitoring practice, and investment horizon, are reported with the descriptive results in Section 4.1. Personal demographic characteristics such as age and gender were not collected because they were not required by the research questions and could increase the risk of indirect identification within a small institutional setting.
The institutional pool included 15 institutions: all 12 banks operating in Albania at the time of data collection and three additional financial institutions, two of which were fintech institutions. The inclusion of all 12 banks provides broad institutional coverage of the Albanian banking system. The three additional institutions provide complementary contextual perspectives on financial technology and AI implementation but do not alter the study’s primary focus on banking. At the same time, because the banking system is relatively small, careful anonymization was required to reduce the risk of indirect institutional identification.
The sample size should be interpreted in relation to the size and structure of the banking system under study. Although the number of individual responses is modest, the coverage of institutions is broad. The study is therefore positioned as an exploratory banking-system-level analysis of perceived AI readiness and governance conditions, rather than as a basis for institution-level ranking or highly detailed subgroup comparisons.
Because more than one respondent could come from the same institution, responses may partly reflect shared institutional contexts. This issue is considered in the empirical strategy through institution-clustered inference and sensitivity analyses. The findings are therefore interpreted as associations among informed professional perceptions, with appropriate caution regarding within-institution dependence.
The questionnaire collected information on respondent role, banking system experience, institution size, AI adoption status, AI use cases, implementation model, integration level, monitoring practices, governance-unit status, benefit measurability, perceived benefits, adoption barriers, environmental and regulatory pressure, responsible AI orientation, and intention to invest in or scale AI. It also included multi-select and open-text questions to support descriptive analysis of AI use cases, adoption barriers, and performance-measurement practices. The questionnaire–construct linkage is reported in Appendix Table A1 and described in Section 3.2. The complete questionnaire, including the original Albanian item wording, item codes, response options, Likert-scale format, and routing instructions, is provided in Supplementary File Q1. The original questionnaire used the broader term “financial institution” because the sampling frame included banks and three related financial institutions. The study nevertheless retains banking as its primary theoretical and analytical focus.

3.2. Measures and Construct Operationalization

The questionnaire included multi-item constructs measured on a five-point Likert-type scale. It was developed as a literature-informed and context-adapted instrument, rather than through the direct adoption of one pre-existing validated scale. This approach was appropriate because the study combines dimensions that are usually examined separately, including technology readiness, organizational readiness, institutional pressure, AI governance, responsible AI orientation, perceived benefits, adoption barriers, and scaling intention. Accordingly, the instrument should be understood as a context-adapted survey instrument designed for this study, with its measurement properties evaluated for the present sample rather than as a universally validated psychometric scale.
The development of the questionnaire followed three steps. First, the main constructs were defined from the theoretical framework and mapped to questionnaire blocks. Second, the item wording was adapted to the banking context, with attention to AI use cases, data and system readiness, governance arrangements, monitoring practices, benefit measurement, regulatory pressure, and responsible AI principles. Third, the questionnaire was reviewed before data collection to assess content validity, clarity, and sector relevance. This review involved academic experts and banking-sector professionals. Their feedback was used to refine item wording, improve construct alignment, and ensure that the questions were understandable for respondents working in banking and related professional settings. No separate formal psychometric scale-development study was conducted; therefore, the measurement diagnostics reported below are interpreted as scale-quality checks for the present dataset. Appendix Table A1 reports the questionnaire-construct linkage, theoretical/source basis, and analytical treatment.
Construct scores were calculated as the arithmetic mean of the corresponding items. This approach was used to obtain transparent and directly interpretable composite scores for the theoretical constructs. Their suitability was assessed using conceptual correspondence, internal consistency, composite reliability, convergent validity, item loadings, and discriminant-validity diagnostics, as described in Section 3.5. The construct-level results are reported in Section 4.4, while item-level PLS-SEM loadings and weights are provided in Supplementary Materials Table S19. For descriptive comparability and maturity-index construction, construct scores were transformed to a 0–100 scale using the following linear transformation:
X_100 = (X − 1)/4 × 100
where  X is the original construct score on the 1–5 scale. Under this transformation, a score of 1 corresponds to 0, a score of 3 corresponds to 50, and a score of 5 corresponds to 100. The transformation does not change the relative ordering of responses.
The main constructs were operationalized as follows. Data and Technology Readiness, measured through DTR1–DTR4, captured the perceived availability of data, technology infrastructure, system readiness, and technical foundations for AI adoption. Skills and Resources Readiness, measured through SR1–SR3, captured the perceived availability of skills, resources, training, and implementation capacity. AI Governance Readiness, measured through AGR1–AGR6, captured governance arrangements, oversight capacity, accountability, monitoring, and readiness to manage AI-related processes. In the main empirical model, Skills and Resources Readiness and AI Governance Readiness were combined into Capability–Governance Readiness, because responsible AI adoption in banking requires both implementation capability and governance capacity. The two dimensions were also retained separately in supplementary diagnostics and analyses.
Responsible AI Orientation, measured through RAI1–RAI6, captured attention to fairness, transparency, accountability, ethical use, human oversight, privacy, explainability, and AI-related risk awareness. It was retained as a separate construct because it reflects the normative orientation guiding AI use, whereas Capability–Governance Readiness reflects perceived capacity to implement, coordinate, monitor, and govern AI systems.
Perceived Benefits, measured through PB1–PB6, captured the perceived organizational value of AI, including efficiency, decision support, analytics, customer service, risk management, and operational performance. Adoption Barriers, measured through AB1–AB7, captured perceived obstacles related to implementation cost, expertise and capability gaps, data quality and accessibility, integration with existing systems, regulatory and compliance uncertainty, ethical, transparency and reputational risk, and dependence on third-party vendors. Environmental/Regulatory Pressure, measured through ERP1–ERP3, captured perceived external pressure from regulation, supervision, competition, market expectations, and broader institutional developments. Intention to Invest/Scale, measured through INT1–INT3, captured perceived willingness or strategic intention to expand AI investment or scale AI use.
AGR7, PB7, and INT4 were analyzed separately because they measure specific organizational characteristics rather than the multi-item constructs represented by the corresponding scales. AGR7 indicates whether a dedicated AI, data, or analytics unit exists or is under development; PB7 indicates the extent to which AI-related benefits are measured using KPIs; and INT4 identifies the expected investment horizon. Accordingly, AGR7 was not included in AI Governance Readiness, PB7 was not included in Perceived Benefits, and INT4 was not included in Intention to Invest/Scale. This analytical treatment was specified by the questionnaire design and construct definitions and does not reflect item invalidity. All indicators specified for the seven multi-item constructs: DTR1–DTR4; SR1–SR3 and AGR1–AGR6 for CGR; RAI1–RAI6; PB1–PB6; AB1–AB7; ERP1–ERP3; and INT1–INT3, were retained in their respective composite scores. Open-text responses were coded thematically and reported only in aggregated form.

3.3. Use-Case, Barrier, and Maturity Measures

Multi-select responses on AI use cases and top-three adoption barriers were separated into individual entries and recoded into harmonized English-language categories. AI use cases were summarized using counts, percentages of all valid respondents, and percentages among respondents reporting active or pilot AI use. These results were used to describe the functional areas in which AI was already being applied or tested, rather than to estimate causal relationships.
The use-case categories included generative AI, robotic process automation, customer service and chatbots, fraud, AML and transaction monitoring, cybersecurity, document processing and OCR/NLP, marketing and sales analytics, decision analytics and forecasting, credit scoring and risk analytics, offer personalization, user assistant functions, software development or testing, and other internal processes. The categories were harmonized to reflect common AI applications in banking, while preserving the meaning of the original survey responses.
Adoption barriers were summarized using descriptive mention counts and percentages of respondents. The categories included skills and capability gaps, regulatory or compliance uncertainty, total cost or budget constraints, integration with existing systems, ethical, transparency or reputational risk, data quality or accessibility, and third-party or vendor risk. Although respondents were asked to select three barriers, diagnostic checks showed that 80 of the 85 respondents selected exactly three, 3 selected fewer than three, 2 selected more than three, and no responses were missing for this item. The barrier results are therefore interpreted as descriptive mention counts rather than mutually exclusive proportions. This interpretation is important because the barrier categories indicate the relative salience of perceived constraints, not exclusive respondent groups.
An AI Maturity Index was constructed as an exploratory descriptive measure rather than as a statistically validated latent construct. The index combined four dimensions: adoption and integration, Data and Technology Readiness, Capability–Governance Readiness, and Responsible AI Orientation.
AMI = 0.30(AI Adoption/Integration) + 0.30(DTR) + 0.25(CGR) + 0.15(RAI)
Since no established weighting scheme exists for AI maturity in the Albanian banking context, the weights were specified conceptually and should be interpreted as a transparent scoring rule rather than as empirically estimated parameters. The index was developed as a composite indicator intended to summarize multiple theoretically relevant dimensions of AI maturity. This approach is consistent with composite-indicator construction, where conceptually assigned weights are appropriate when the objective is descriptive profiling rather than latent-factor estimation (Nardo et al., 2005; Diamantopoulos & Winklhofer, 2001; Saltelli, 2025).
Adoption/integration and Data and Technology Readiness were each assigned a weight of 0.30 to reflect the importance of both actual implementation and technological foundations. Capability–Governance Readiness was assigned a weight of 0.25 because organizational capability and governance are central to responsible scaling. Responsible AI Orientation was assigned a weight of 0.15 because it is included as an important maturity dimension, while the main empirical model examines its distinct association with Perceived Benefits through H3b. The weighting scheme therefore reflects the study’s view of AI maturity as a combination of implementation depth, technological foundations, governance capability, and responsible-use orientation.
The AMI was not intended as a latent construct or as an empirically derived factor score. Therefore, PCA or factor-based weighting was not applied, because such approaches would produce a sample-dependent empirical score driven by the covariance structure of this particular dataset. This was considered less appropriate for the exploratory and context-specific purpose of the study, where conceptual interpretability and transparency were prioritized over statistical optimization of weights. This approach is consistent with formative or composite measurement logic, in which indicators define the construct rather than reflect a single underlying latent factor (Diamantopoulos & Winklhofer, 2001).
To evaluate the robustness of the descriptive interpretation, an additional equal-weighted AMI specification was calculated as a sensitivity check, assigning a weight of 0.25 to each dimension. This sensitivity check was used to assess whether the descriptive maturity profile depended strongly on the selected conceptual weights.
The index was used only for descriptive profiling and maturity-tier classification, not for hypothesis testing or causal inference.

3.4. Data Cleaning and Quality Diagnostics

Data were imported from a CSV file, and variable names were standardized before analysis. Direct identifiers were removed from analysis-facing and manuscript-facing files. Institution names were replaced with anonymized institution codes. Private lookup files linking anonymized codes to original institution names were excluded from the public submission package. These procedures reduced the risk of direct or indirect identification before analysis.
Case-level missingness was assessed across the primary Likert-scale items. A pre-specified exclusion threshold was applied: responses with more than 20% missing values across the primary Likert-scale items would be excluded from the analytical dataset. No response exceeded this threshold; therefore, no cases were excluded on the basis of primary Likert-scale missingness, and the final analytical sample remained 85 valid responses.
For retained cases, remaining item-level missing values in Likert-scale items were imputed using the item median. This procedure was used to preserve the analytical sample in a modest-sample setting while limiting the influence of missing item responses on construct-score calculation. Missingness in non-scale and conditional items, such as benefit measurability, was assessed separately and reported descriptively (Little & Rubin, 2019; Hair et al., 2019). Median imputation was applied only to Likert-scale items used in construct scoring and was not used to replace missing values in open-text, categorical, or conditional descriptive variables.
Response-quality diagnostics were conducted to identify potential straight-lining. A response was flagged when the standard deviation across Likert-scale items was below 0.20 or when the respondent used two or fewer distinct Likert response values. Six responses were flagged as potential straight-lining cases. These responses were retained in the main analysis because uniform response patterns may reflect genuine perceptions in some survey contexts rather than careless responding. A sensitivity analysis was therefore conducted after excluding the flagged cases. This approach allowed the main analysis to preserve the full valid sample while testing whether the results were sensitive to potentially low-variation response patterns.
Branch-logic and skip-logic diagnostics were also conducted. The branch-logic check assessed whether respondents who reported no current AI use, no adoption plan, or uncertainty nevertheless provided AI-detail responses that were inconsistent with questionnaire routing. No branch inconsistencies were identified. The skip-logic check showed that all active or pilot AI users completed the relevant AI-detail questions and that respondents expected to skip those items did not provide inconsistent responses. Conditional missingness was assessed for the benefit-measurability item. Missingness was similar among active or pilot AI users and non-users, indicating that missingness in this item should be interpreted as a conditional descriptive feature rather than as a general data-quality problem. Overall, the diagnostic checks supported the suitability of the cleaned dataset for the descriptive, regression, PLS-SEM, and sensitivity analyses.
The complete workflow: from data import, anonymization, missing-data treatment, and response-quality checks to construct-score calculation, model estimation, and sensitivity analysis, is documented in the R script provided with the Supplementary Materials. Outputs from the missingness, response-quality, branch-logic, and skip-logic checks are reported in Supplementary Materials Tables S1–S4. Tables S5–S33 and Figures S1–S5 provide the corresponding descriptive profiles, measurement diagnostics, regression and PLS-SEM outputs, AI Maturity Index results, sensitivity and subgroup analyses, and aggregated qualitative outputs.

3.5. Measurement and Common-Method Diagnostics

Measurement quality was assessed using Cronbach’s alpha, standardized alpha, ordinal alpha, composite reliability, average variance extracted (AVE), item loadings, HTMT ratios, and Fornell–Larcker diagnostics. Cronbach’s alpha and standardized alpha were used to assess the internal consistency of multi-item scales (Cronbach, 1951). Ordinal alpha was calculated as a sensitivity measure that accounts for the ordered categorical form of the five-point Likert responses. Composite reliability and average variance extracted were used to assess convergent validity, using 0.70 and 0.50, respectively, as interpretive reference values (Hair et al., 2019). Item loadings were examined together with the conceptual relevance of each indicator and the composite reliability and AVE of its construct, rather than used as an automatic item-deletion criterion. The Fornell–Larcker criterion was used as one diagnostic for discriminant validity (Fornell & Larcker, 1981). HTMT ratios were also reported because the heterotrait–monotrait ratio is considered a sensitive criterion for assessing discriminant validity (Henseler et al., 2015). HTMT values were evaluated using 0.85 as a conservative reference and 0.90 as a more permissive reference for conceptually related constructs.
These diagnostics were used to evaluate the measurement quality of the multi-item constructs and their suitability for use as composite scores in the empirical models. They were not intended to present a fully confirmatory measurement model. This distinction is important because the main regression analysis used averaged construct scores, while PLS-SEM was added as a supplementary robustness analysis to assess whether the main relationships remained consistent under a latent-composite modelling approach. The measurement results therefore describe the performance of the instrument in the present sample rather than establish the validity of a general-purpose psychometric scale. Construct-level results are presented in Section 4.4.
The diagnostics were interpreted cautiously because the study used a modest cross-sectional sample. Particular attention was given to the empirical proximity between Capability–Governance Readiness and Responsible AI Orientation. These constructs are theoretically related because both concern AI governance, but they are conceptually distinct. Capability–Governance Readiness captures perceived organizational capacity to implement, coordinate, monitor, and govern AI systems, whereas Responsible AI Orientation captures the extent to which AI use is guided by fairness, transparency, accountability, privacy, explainability, and human oversight. Their empirical distinctiveness was assessed using both HTMT and Fornell–Larcker diagnostics, while their conceptual distinction was maintained in the theoretical model.
Because the study relied on cross-sectional self-reported survey data, common-method bias could not be ruled out. This concern is well established in organizational survey research, particularly when predictor and outcome variables are collected from the same respondent at the same time (Podsakoff et al., 2003, 2024). Two diagnostic checks were applied. First, Harman’s single-factor test was used to assess whether one factor accounted for the majority of variance across the Likert-scale items. Second, full-collinearity VIF diagnostics were calculated. These diagnostics were interpreted conservatively: they can indicate whether a single dominant common factor is likely, but they cannot prove that common-method variance is absent. Therefore, the results are interpreted as cross-sectional associations based on informed professional perceptions, not as causal estimates.

3.6. Regression, PLS-SEM, and Sensitivity Analyses

The main empirical model was estimated using ordinary least squares regression. A parsimonious specification was adopted because the sample size was modest and the study had an exploratory banking-system-level purpose. OLS regression was applied to construct-level composite scores rather than to individual questionnaire items or latent variables. This choice was appropriate because the objective was to test theoretically specified associations among composite constructs in a transparent and interpretable way. The OLS models were therefore treated as the main hypothesis-testing approach, while additional analyses were used to assess the stability of the findings.
Three main equations were estimated:
CGR_i = β_0 + β_1 DTR_i + β_2 ERP_i + ε_i,
PB_i = β_0 + β_1 CGR_i + β_2 RAI_i + ε_i,
INT_i = β_0 + β_1 PB_i + β_2 AB_i + ε_i.
In these equations, i denotes the individual survey response. CGR_i denotes Capability–Governance Readiness, DTR_i denotes Data and Technology Readiness, ERP_i denotes Environmental/Regulatory Pressure, PB_i denotes Perceived Benefits, RAI_i denotes Responsible AI Orientation, INT_i denotes Intention to Invest/Scale, AB_i denotes Adoption Barriers, and ε_i denotes the regression disturbance term. In the first equation, the coefficients of DTR and ERP correspond to H1 and H2. In the second equation, the coefficients of CGR and RAI correspond to H3a and H3b, respectively, and estimate their distinct associations with PB while controlling for one another. In the third equation, the coefficients of PB and AB correspond to H4 and H5.
Inference was based on coefficient direction, HC3 robust standard errors, institution-clustered p-values, and bootstrap confidence intervals. HC3 heteroskedasticity-consistent standard errors were used because they are commonly recommended in smaller samples and in settings where heteroskedasticity cannot be ruled out (MacKinnon & White, 1985). Bootstrap confidence intervals were used as an additional robustness check for coefficient uncertainty, following the logic of bootstrap inference for estimating sampling variability under uncertain distributional assumptions (Efron, 1979; Cameron & Miller, 2015).
Institution-clustered p-values were also reported because multiple respondents came from the same institution, which may create within-institution dependence. The clustered results were used to examine whether statistical inference remained stable after accounting for shared institutional context among respondents. The main regression models used 5000 bootstrap resamples, while sensitivity models used 1000 bootstrap resamples. Hypotheses were classified as supported only when the coefficient direction was consistent with the theoretical expectation and the HC3, institution-clustered, and bootstrap results were consistent in indicating an association distinguishable from zero. A coefficient in the expected direction was not classified as supported when the corresponding confidence interval included zero or the robust inference did not indicate statistical support.
As a supplementary robustness analysis, the conceptual model was also estimated using Partial Least Squares Structural Equation Modelling (PLS-SEM). This analysis was included because the study uses multi-item constructs and because PLS-SEM allows the measurement and structural components of the model to be examined within one latent-composite framework. The PLS-SEM model used item-level reflective measurement blocks for Data and Technology Readiness, Environmental/Regulatory Pressure, Capability–Governance Readiness, Responsible AI Orientation, Perceived Benefits, Adoption Barriers, and Intention to Invest/Scale.
The PLS-SEM analysis was interpreted as a robustness check, not as a replacement for the main OLS analysis. The purpose was to assess whether the direction and support of the hypothesized relationships remained stable when the model was estimated using item-level measurement blocks. Path coefficients, bootstrap confidence intervals, construct reliability, average variance extracted, outer loadings, and explained variance were examined and compared with the OLS results. The CGR → PB and RAI → PB paths were reported as H3a and H3b, respectively, in accordance with the specified hypothesis structure.
A disaggregated PLS-SEM model was also estimated as a supplementary analysis. In this model, Skills and Resources Readiness and AI Governance Readiness were reported separately rather than combined into Capability–Governance Readiness. This additional model was used to assess whether the combined CGR construct masked important differences between implementation capability and governance readiness. The disaggregated model was interpreted as a supplementary diagnostic analysis and not as a replacement for the main conceptual model.
Several sensitivity analyses were conducted. First, equal-institution weighting was applied to account for unequal numbers of respondents across institutions. Second, a leave-one-institution-out analysis was conducted by removing one institution at a time and re-estimating the main models (Cameron & Miller, 2015; MacKinnon, 2026). Third, a straight-lining exclusion analysis was conducted by removing responses flagged for potential straight-lining. Fourth, an equal-weighted AI Maturity Index specification was calculated to assess whether the descriptive maturity profile depended strongly on the selected conceptual weights. These analyses were used to evaluate the sensitivity of the findings to respondent concentration across institutions, the influence of individual institutions, potentially low-variation response patterns, and the conceptual AMI weighting scheme. They were not treated as alternative causal specifications.
Overall, the empirical strategy combined OLS estimation, clustered and bootstrap inference, PLS-SEM robustness analysis, and sensitivity checks. This approach allowed the study to assess the consistency of the hypothesized associations across alternative inferential and measurement specifications, while retaining an explicitly non-causal interpretation appropriate to the exploratory, cross-sectional, and perception-based nature of the study.

3.7. Ethical Considerations, Confidentiality, and Reproducibility

The study was conducted within the framework of doctoral research. Participation in the survey was voluntary, and respondents were informed about the purpose of the study and the confidential treatment of their responses. Completion of the questionnaire was treated as informed consent.
The data were processed in anonymized form, and the findings were reported at an aggregated level. Direct identifiers were removed before analysis, and institution names were replaced with anonymized codes. Because the Albanian banking system is small, additional confidentiality safeguards were applied to reduce the risk of indirect institutional identification. Private lookup files, institution-name mappings, and verbatim open-text responses were excluded from manuscript-facing and public materials. Open-text responses were used only for aggregated thematic interpretation.
All analyses were conducted in R. The analysis workflow produced the cleaned and anonymized analysis-ready dataset, construct scores, measurement diagnostics, common-method diagnostics, regression outputs, PLS-SEM robustness outputs, use-case and barrier tables, maturity-index outputs, subgroup profiles, sensitivity analyses, and figures. The reproducibility package excludes private lookup files and verbatim open-text responses. The R version and package versions used to reproduce the analyses are reported in Supplementary File R1. This approach supports transparency while maintaining confidentiality in a small banking system where institutional identification may be possible from detailed contextual information.

3.8. Generative AI Disclosure

Generative AI tools were used only to support language refinement during manuscript preparation. They were not used to generate the dataset, conduct the statistical analysis, interpret the empirical results, or replace author judgment. The authors reviewed and validated the final manuscript content and remain fully responsible for all analyses, interpretations, conclusions, and the integrity of the work, in line with guidance on transparent and responsible use of generative AI in academic writing (Porsdam Mann et al., 2024).

4. Results

4.1. Analytical Sample and Data-Quality Diagnostics

The final analytical sample consisted of 85 valid responses from professionals working primarily in the Albanian banking system, supplemented by respondents from three related financial institutions. The institutional pool covered 15 institutions, including all 12 banks operating in Albania and three additional financial institutions, two of which are fintech institutions. This coverage provides a broad institutional view of the Albanian banking context while maintaining confidentiality through anonymized institution codes.
The respondent profile indicates substantial professional experience in banking and related financial services. Most respondents reported 16 or more years of professional experience, representing 63.5% of the sample. In terms of functional role, 54.1% were from business or management positions, 41.2% from IT, digital, data, or analytics roles, 3.5% from compliance or AML-related roles, and 1.2% from other or mixed roles. Institution-size representation included small, large, and medium institutions, with small institutions accounting for 42.4% of responses, large institutions for 35.3%, and medium institutions for 22.4%.
The same table also reports the descriptive AI adoption profile. A total of 27.1% of respondents reported active AI use in production, while 28.2% reported pilot or limited AI use. Taken together, 55.3% of respondents indicated either active or pilot AI use. Another 28.2% reported that AI was not currently used but was planned. These results suggest that AI adoption is already visible in the sector, although many institutions remain at the pilot, planning, or early implementation stage. The sample and adoption profile is reported in Table 1.
Table 1. Sample profile and AI adoption status.
Data-quality diagnostics showed that no response exceeded the pre-specified threshold of more than 20% missing values across the primary Likert-scale items. Six responses were flagged as potential straight-lining cases. These responses were retained in the main analysis and assessed separately using sensitivity analysis. Branch-logic and skip-logic diagnostics did not indicate inconsistencies. Overall, the data-quality checks supported the use of the cleaned dataset for the descriptive and empirical analyses. The detailed diagnostic outputs are reported in the Supplementary Materials (Tables S1–S4).

4.2. AI Adoption, Implementation, Integration, and Monitoring

AI adoption is visible in the Albanian banking system, but it remains uneven in terms of implementation depth, integration, monitoring, and governance structures. As shown in Table 1, more than half of respondents reported either active or pilot AI use, while a further group reported planned future adoption. This pattern suggests that AI is no longer only a distant prospect for the sector, but its institutional embedding is still developing.
Implementation patterns show that 38.8% of respondents reported in-house implementation, 15.3% reported vendor or third-party implementation, and 1.2% reported use of a GenAI assistant or Copilot-type tool. The remaining 44.7% were classified as not applicable because they did not report current AI deployment (Table 1). The relatively high share of in-house implementation may indicate that some institutions are building internal AI-related capacity, while the presence of vendor-based implementation also highlights the relevance of third-party dependency and oversight.
Integration and monitoring appear less developed than initial adoption. Partial integration was reported by 24.7% of respondents, while 22.4% reported pilot or proof-of-concept integration. Only 4.7% reported broad integration and 3.5% full or end-to-end integration. Regular monitoring was reported by 17.6% of respondents, while 10.6% reported ad hoc monitoring, 11.8% reported no structured monitoring, and 15.3% were unsure (Table 1). These results indicate that AI experimentation and early use are more common than broad integration or systematic monitoring. This distinction is important because responsible AI adoption requires not only deployment, but also integration into organizational processes and continued performance oversight.
Governance structures are emerging, but not yet universal. A dedicated AI, data, or analytics unit was reported by 40.0% of respondents, while 36.5% indicated that such a unit was in development. A further 23.5% reported that no such unit existed (Supplementary Materials Table S5). Benefit measurability was also mixed: 35.3% reported that AI benefits were measured with KPIs, 28.2% reported partial or moderate measurement, 15.3% reported no systematic measurement, and 21.2% did not answer this item (Supplementary Materials Table S6). Taken together, these findings suggest that the sector is moving toward more structured AI governance, but monitoring routines and benefit-measurement practices are not yet consistently institutionalized.

4.3. AI Use Cases and Adoption Barriers

The most frequently reported AI use case was generative AI, mentioned by 30 respondents, corresponding to 35.3% of the full sample and 63.8% of active or pilot AI users. This was followed by RPA or process automation, reported by 25.9% of all respondents and 46.8% of active or pilot AI users. Customer service and chatbot applications, fraud, AML and transaction monitoring, cybersecurity, and document processing/OCR/NLP were also among the most frequently reported use cases. Overall, the reported use cases show that AI adoption is concentrated mainly in operational automation, customer-facing support, risk and compliance monitoring, cybersecurity, document processing, and generative AI support functions. The main use-case categories are reported in Table 2.
Table 2. Main reported AI use.
The top-three barrier question shows that the most frequently mentioned barrier was the skills or capability gap, selected by 57.6% of respondents. Regulatory or compliance uncertainty followed at 45.9%, while total cost or budget constraints were reported by 44.7%. Integration with existing systems was also a major constraint, reported by 43.5%. Ethical, transparency, or reputational risk was selected by 40.0%, while data quality/accessibility and third-party/vendor risk were each selected by 32.9%. The pattern of barriers suggests that AI adoption is constrained by a combination of internal capability limitations, regulatory uncertainty, implementation cost, legacy-system integration, and governance-related risks. These results are reported in Table 3 and visualized in Supplementary Materials Figure S1.
Table 3. Main reported AI adoption barriers.
The barrier-integrity check showed that 80 of the 85 respondents selected exactly three barriers, 3 selected fewer than three, 2 selected more than three, and no responses were missing for this item (Supplementary Materials Table S7). The barrier results are therefore interpreted as descriptive mention counts rather than mutually exclusive response shares. This means that the percentages indicate how often each barrier was mentioned among all respondents, not the share of respondents belonging to separate barrier groups.

4.4. Measurement Diagnostics

Cronbach’s alpha ranged from 0.775 for Environmental/Regulatory Pressure to 0.941 for Perceived Benefits, while ordinal alpha ranged from 0.823 to 0.963 for the same constructs. Capability–Governance Readiness showed high internal consistency under both measures, with Cronbach’s alpha of 0.937 and ordinal alpha of 0.951. The consistency of the results across conventional and ordinal reliability estimates supports the internal consistency of the multi-item constructs. These statistics are interpreted as scale-quality diagnostics supporting the use of composite construct scores rather than as evidence of a fully confirmatory measurement model. The reliability results are reported in Table 4, and full construct descriptives are provided in Supplementary Materials Table S8.
Table 4. Measurement reliability diagnostics.
Composite reliability values were above the conventional 0.70 threshold for all constructs, and average variance extracted values were above 0.50. Together, these diagnostics support the use of the construct scores in the subsequent regression analyses. These convergent-validity diagnostics are reported in Table 5.
Table 5. Composite reliability and convergent-validity diagnostics.
Discriminant-validity diagnostics were generally acceptable. The Fornell–Larcker criterion was met for all constructs. The HTMT diagnostics showed one value slightly above the strict 0.85 threshold: Capability–Governance Readiness and Responsible AI Orientation had an HTMT value of 0.855. This value remained below the more lenient 0.90 threshold and is theoretically understandable, given the conceptual proximity between governance readiness and responsible AI orientation. This result is therefore interpreted as a discriminant-validity caveat, not as evidence that the two constructs should be collapsed. Conceptually, Capability–Governance Readiness captures the institutional capacity to implement, coordinate, monitor, and govern AI systems, whereas Responsible AI Orientation captures the responsible-use orientation that guides AI deployment, including transparency, fairness, accountability, privacy, human oversight, explainability, and risk awareness. This empirical proximity is taken into account when interpreting the results involving Responsible AI Orientation. The HTMT matrix is reported in Appendix Table A2, the HTMT diagnostic flags in Appendix Table A3, the Fornell–Larcker matrix in Appendix Table A4, and the Fornell–Larcker diagnostics in Appendix Table A5.
Common-method diagnostics were interpreted cautiously because the study relies on cross-sectional self-reported survey data. Harman’s single-factor test indicated that the first factor explained 41.61% of the variance, below the 50% benchmark. The maximum full-collinearity VIF was 4.839. Several full-collinearity VIF values exceeded the conservative 3.3 threshold, although all remained below 5.0. These diagnostics suggest that no single dominant factor fully explains the covariance structure, but they do not eliminate the possibility of common-method effects. Therefore, common-method bias cannot be ruled out. These results are reported in Supplementary Materials Tables S9 and S10.

4.5. AI Maturity Index

The AI Maturity Index indicates a sector in transition. The mean AMI score was 49.047, with a median of 47.521 and a standard deviation of 22.535. Scores ranged from 2.625 to 92.375, showing substantial variation across respondents and institutions. The adoption and integration component had a mean of 34.833, lower than the mean values for Data and Technology Readiness, Capability–Governance Readiness, and Responsible AI Orientation. This pattern indicates that reported technological readiness, capability–governance readiness, and responsible AI orientation are, on average, more developed than operational adoption and integration. The AMI summary is reported in Table 6, and the distribution is shown in Figure 2.
Table 6. AI Maturity Index summary.
Figure 2. Distribution of the AI Maturity Index.
As discussed in Section 3.3, the AMI was designed as a descriptive composite indicator rather than as a latent statistical construct. Accordingly, the results are interpreted as exploratory maturity profiles that summarize variation across respondents and institutions. They should not be interpreted as causal evidence or as independently audited institution-level maturity scores.
The maturity-tier distribution shows that 40.0% of respondents fall into the low-maturity category, 38.8% into the moderate-maturity category, and 21.2% into the high-maturity category (Appendix Table A6). The scaling-readiness gap also points to uneven development: 60.0% of respondents showed broad alignment between maturity and intention, 31.8% reported scaling ambition above current maturity, and 8.2% reported maturity above scaling ambition (Appendix Table A7). This distribution suggests that, for a substantial minority of respondents, future scaling intention is higher than the current maturity profile captured by the AMI. Additional maturity-related subgroup profiles are reported by institution size, respondent role, and investment horizon in Appendix Table A8, Table A9 and Table A10. Related figures are retained in the Supplementary Materials (Supplementary Materials Figures S2–S5).
As a robustness check, an alternative equal-weighted AMI specification was also examined. The overall descriptive interpretation remained broadly consistent, with similar maturity-tier patterns and subgroup tendencies. The equal-weighted AMI had a mean of 49.450 and a median of 48.819, and it was highly correlated with the main AMI specification (Spearman correlation = 0.995), supporting the stability of the descriptive interpretation (Supplementary Materials Tables S11 and S12). This indicates that the descriptive maturity profile is not materially altered when equal weights are assigned to the four AMI dimensions.

4.6. Main Hypothesis Tests

The regression results support four of the six hypothesized relationships. Data and Technology Readiness was positively associated with Capability–Governance Readiness, supporting H1. Environmental/Regulatory Pressure was also positively associated with Capability–Governance Readiness, supporting H2. Capability–Governance Readiness was positively associated with Perceived Benefits, supporting H3a. Responsible AI Orientation was positively, but not statistically significantly, associated with Perceived Benefits; therefore, H3b was not supported. Perceived Benefits were positively associated with Intention to Invest/Scale, supporting H4 (Table 7). Taken together, these results are consistent with the conceptual model: technological readiness and environmental pressure are associated with capability–governance readiness, capability–governance readiness is associated with perceived benefits, and perceived benefits are associated with future investment or scaling intention.
Table 7. Main Hypothesis Results.
Adoption Barriers were not negatively associated with Intention to Invest/Scale. The estimated coefficient was positive rather than negative and was not statistically significant. Since the Adoption Barriers scale was coded so that higher scores indicate stronger perceived barriers, this finding is interpreted as non-support for H5 rather than as a reverse-coding issue. This result should therefore be interpreted cautiously: the data do not support the expected negative relationship between perceived barriers and scaling intention. One possible interpretation is that, in an early-stage adoption context, respondents with greater exposure to AI implementation may also be more aware of implementation barriers. This interpretation remains exploratory and should not be read as evidence that barriers increase scaling intention.
The H3b path from Responsible AI Orientation to Perceived Benefits was positive but not statistically significant after accounting for Capability–Governance Readiness. The coefficient was 0.1437, with HC3 p = 0.2710, cluster p = 0.3373, and a bootstrap 95% CI of [−0.1151, 0.3761]. Thus, Responsible AI Orientation had the expected positive direction, but the analysis does not provide sufficient evidence that it adds a unique association with Perceived Benefits once Capability–Governance Readiness is included in the model (Supplementary Materials Table S13). This finding should be interpreted alongside the measurement diagnostics, which showed conceptual and empirical proximity between governance readiness and responsible AI orientation. Full regression outputs and model diagnostics are provided in the Supplementary Materials Tables S14 and S15. Construct-level Spearman correlations are reported in Appendix Table A11 and Table A12.

4.7. PLS-SEM Robustness and Sensitivity Analyses

As a robustness check, the conceptual model was also estimated using PLS-SEM. The PLS-SEM results were broadly consistent with the main OLS findings. Data and Technology Readiness was positively associated with Capability–Governance Readiness, and Environmental/Regulatory Pressure was also positively associated with Capability–Governance Readiness. Capability–Governance Readiness was positively associated with Perceived Benefits, and Perceived Benefits was positively associated with Intention to Invest/Scale. The path from Adoption Barriers to Intention to Invest/Scale was positive but not supported, consistent with the OLS finding for H5. The H3b path from Responsible AI Orientation was also positive but not supported. These results are reported in Table 8.
Table 8. PLS-SEM robustness results.
The PLS-SEM model explained a substantial share of variance in Capability–Governance Readiness, with R2 = 0.695. The explained variance was more moderate for Perceived Benefits, with R2 = 0.336, and Intention to Invest/Scale, with R2 = 0.337. These results support the stability of the main pattern of associations under a latent-composite modelling approach, while the interpretation remains exploratory and cross-sectional. PLS-SEM construct-quality diagnostics, detailed path coefficients, explained-variance statistics, outer loadings and weights, and unidimensionality diagnostics are reported in Supplementary Materials Tables S16–S20.
A disaggregated PLS-SEM model was also examined to assess whether separating Skills and Resources Readiness from AI Governance Readiness materially changed the interpretation of the organizational readiness structure. This model was used as a supplementary diagnostic analysis, not as a replacement for the main conceptual model. The disaggregated PLS-SEM results are reported in Supplementary Materials Tables S21–S24.
Sensitivity analyses generally supported the stability of the main findings. Excluding the six responses flagged for potential straight-lining did not change the direction or inferential interpretation of the hypothesized relationships. The H3b coefficient remained positive but statistically unsupported, while the H5 coefficient remained positive rather than negative (Supplementary Materials Table S25).
The leave-one-institution-out analysis also showed stable coefficient directions across all six hypothesized relationships. The H3b estimate remained positive across the 15 re-estimated models, ranging from 0.0330 to 0.1963, but remained statistically unsupported. The H5 coefficient also remained positive in all leave-one-institution-out models, indicating that the non-support of H5 was not driven by a single institution (Supplementary Materials Table S26).
Under equal-institution weighting, H1, H3a, and H4 remained supported. H2 remained positive but was no longer statistically significant (estimate = 0.2817; weighted HC3 p = 0.0886). H3b also remained positive but unsupported (estimate = 0.1862; weighted HC3 p = 0.2187), while H5 remained unsupported because its coefficient was positive rather than negative. These results indicate that the main interpretation is generally stable, although the statistical support for H2 is sensitive to institutional weighting (Supplementary Materials Table S27).
Subgroup analysis showed no statistically significant difference in AMI by institution size or respondent role. The Kruskal–Wallis test for institution size was not significant, with p = 0.160, and the test for respondent role was also not significant, with p = 0.624. AMI differed significantly by investment horizon, with p = 0.0159, but this result should be interpreted as exploratory because investment horizon was used as a descriptive subgroup variable rather than as a main predictor (Supplementary Materials Tables S28–S30).
The alternative equal-weighted AMI specification also supported the descriptive stability of the maturity profile. As reported in Section 4.5, the equal-weighted AMI produced a similar mean and median and was highly correlated with the main AMI specification. This indicates that the descriptive maturity profile is not materially altered when equal weights are assigned to the four AMI dimensions.

4.8. Qualitative Thematic Results

Open-text responses were coded thematically and reported without verbatim text in the public outputs. The purpose of this analysis was descriptive and supplementary: the open-text responses were used to contextualize the survey findings, not to develop a separate qualitative model. For highest-value AI use cases, the most frequent theme was efficiency and automation, representing 43.4% of coded responses. Customer experience, document processing/OCR/NLP, and risk, fraud, AML, or monitoring also appeared as relevant themes but were less frequently mentioned (Supplementary Materials Table S31).
For the main AI adoption barrier, data governance and data quality accounted for 24.1% of coded responses, while skills and capability gaps accounted for 22.2% and cost, budget, or investment constraints for 13.0%. These open-text themes are broadly consistent with the structured barrier results reported in Section 4.3, where skills, regulatory uncertainty, cost, system integration, and data-related issues were among the most frequently reported constraints. The residual “Other” category remained sizeable, accounting for 24.1% of main-barrier responses, 22.6% of highest-value use-case responses, and 26.7% of KPI or performance-indicator responses (Supplementary Materials Table S32). This category was retained to avoid over-coding heterogeneous responses into categories that did not fully capture their meaning. The non-verbatim qualitative coding output is provided in the Supplementary Materials (Supplementary Materials Table S33).

5. Discussion

5.1. Interpretation of the Main Findings

This study examined AI adoption, governance readiness, maturity, perceived benefits, adoption barriers, and scaling intention in the Albanian banking system. The findings show that AI adoption is already visible, but its maturity remains uneven. The main implication is that AI use appears to be advancing before full organizational embedding has been achieved. Adoption has not yet fully translated into consistent integration, structured monitoring, and systematic benefit measurement.
This pattern supports the central argument of the study: AI adoption in the Albanian banking system should be assessed not only through the presence of AI tools, but also through the technological, organizational, and governance conditions that allow AI to be integrated, monitored, evaluated, and scaled responsibly. This is particularly relevant in smaller and institutionally concentrated banking systems, where AI implementation may develop under tighter capacity, regulatory-alignment, and confidentiality constraints. The institutional coverage of the study, including all operating banks in Albania and three additional financial institutions, provides a broad perspective on the Albanian banking system. At the same time, the findings should be read as informed professional perceptions of organizational conditions, not as audited institution-level assessments.
The AI Maturity Index reinforces this interpretation. Its component structure indicates that readiness-related foundations are more developed than operational adoption and integration. This does not imply that institutions have completed the transition toward mature AI adoption. Rather, it suggests that technological, organizational, and responsible-use foundations are emerging before AI becomes fully embedded in operational processes, monitoring routines, and measurable performance systems.

5.2. Readiness Through the Technology–Organization–Environment Perspective

The results provide empirical support for the Technology–Organization–Environment framework in the context of AI adoption in the Albanian banking system. Data and Technology Readiness was positively associated with Capability–Governance Readiness, indicating that stronger data availability, technical infrastructure, system readiness, and digital foundations are linked with stronger perceived organizational and governance capacity. This is consistent with the TOE perspective, where technological readiness and organizational capability are interconnected dimensions of technology adoption rather than separate stages (Tornatzky et al., 1990; Baker, 2012; Awa et al., 2017).
In the case of AI, this relationship is particularly important because governance capacity is shaped by the systems, data, expertise, and implementation processes that institutions are able to monitor and control. Where data are fragmented, systems are weakly integrated, or technical expertise is limited, governance may remain formal or procedural rather than operational. Conversely, stronger data and technology foundations can support governance arrangements that are connected to actual AI use cases, implementation processes, monitoring routines, and risk controls.
Environmental/Regulatory Pressure was also positively associated with Capability–Governance Readiness in the main respondent-level model. This finding is consistent with institutional theory, according to which organizations respond to coercive, normative, and legitimacy pressures within their institutional environment (DiMaggio & Powell, 1983). In financial services, regulation is not merely a constraint; it can also create incentives for internal governance capacity, risk-management procedures, documentation practices, and monitoring routines. This interpretation is aligned with the emphasis placed by the Basel Committee and the Financial Stability Board on digitalisation, operational resilience, third-party dependency, model risk, data quality, and supervisory capacity (Basel Committee on Banking Supervision, 2024; Financial Stability Board, 2024, 2025). These pressures are particularly relevant to the Albanian banking system because domestic AI adoption is developing in a context increasingly shaped by European and international expectations.
At the same time, the sensitivity analysis showed that the ERP–CGR relationship became weaker under equal-institution weighting. This qualifies, rather than reverses, the main finding. Environmental and regulatory pressure appears relevant in the respondent-level analysis, while its association with capability–governance readiness may differ across institutions depending on their size, maturity, exposure to AI, or representation in the sample.

5.3. Capability–Governance Readiness, Benefits, and Scaling

Capability–Governance Readiness was positively associated with Perceived Benefits. Substantively, this suggests that AI-related value is more likely to be perceived where implementation capability and governance capacity are stronger. This does not imply that governance alone generates benefits. Rather, it indicates that organizational readiness and governance capacity can help institutions identify appropriate use cases, coordinate implementation, monitor outcomes, and recognize potential value from AI adoption.
This finding supports the conceptual decision to combine implementation capability and governance capacity into the Capability–Governance Readiness construct. In banking, AI adoption cannot be reduced to technical deployment. AI systems may affect fraud detection, compliance monitoring, credit-risk analytics, customer interaction, document processing, cybersecurity, and internal decision support. These applications require not only tools and data, but also human expertise, governance mechanisms, monitoring procedures, accountability structures, and risk-management capacity.
The finding is also consistent with responsible AI governance frameworks. The NIST AI Risk Management Framework and ISO/IEC 42001:2023 emphasize that trustworthy AI depends on risk management, accountability, transparency, lifecycle governance, documentation, and continuous improvement (International Organization for Standardization, 2023; Tabassi, 2023). From this perspective, governance readiness is not only a safeguard against AI-related risk; it is also part of the organizational capacity needed to implement AI coherently, monitor its use, and evaluate its value.
Perceived Benefits showed a strong positive association with Intention to Invest/Scale. This finding indicates that future AI scaling is closely connected to whether institutions perceive AI as useful for concrete organizational objectives, including efficiency, customer service, analytics, compliance support, risk management, automation, and decision-making.
This result has direct managerial relevance. AI scaling is unlikely to depend only on technological availability or regulatory pressure. Institutions also need credible internal evidence that AI creates relevant organizational value in areas that matter for operations, risk management, customer service, compliance, and strategic decision-making. Strengthening benefit-measurement practices is therefore important for prioritizing AI use cases, evaluating implementation outcomes, justifying investment, and distinguishing high-value applications from experimental or low-impact initiatives.
The positive association between Perceived Benefits and Intention to Invest/Scale also helps explain why AI scaling ambition may persist even when barriers are recognized. In early-stage adoption contexts, perceived benefits and perceived barriers may coexist. Institutions may continue to view AI as strategically important while also acknowledging unresolved challenges related to skills, governance, integration, data quality, regulation, cybersecurity, and vendor dependency.

5.4. Adoption Barriers and the Non-Supported H5

The hypothesis that Adoption Barriers would be negatively associated with Intention to Invest/Scale was not supported. The coefficient was positive and statistically non-significant. Since the Adoption Barriers scale was coded so that higher values indicate stronger perceived barriers, this result is not a reverse-coding issue. The appropriate interpretation is that the data do not support the expected negative relationship between perceived barriers and scaling intention.
One possible interpretation is that barrier awareness may be higher among respondents with greater exposure to AI implementation. Institutions that are experimenting with or actively using AI are more likely to encounter practical implementation challenges, including skills shortages, regulatory uncertainty, integration problems, data-quality limitations, explainability concerns, cybersecurity risks, and third-party dependencies. By contrast, institutions with limited AI activity may report fewer barriers because they have not yet faced these challenges directly.
This interpretation should remain cautious. The result does not show that barriers increase scaling intention. Rather, it suggests that in an early-stage adoption context, perceived barriers may reflect implementation exposure as well as constraint. Barriers may therefore coexist with scaling intention when institutions consider AI strategically important but still face unresolved organizational, technical, regulatory, and governance challenges.
This interpretation is consistent with the descriptive findings, where skills gaps, regulatory uncertainty, cost, integration, ethical and transparency risks, data quality, and vendor risk were all frequently reported. These barriers correspond closely to the vulnerabilities emphasized by international supervisory bodies, particularly those related to governance, third-party dependency, model risk, cyber risk, operational resilience, and data quality (Basel Committee on Banking Supervision, 2024; Financial Stability Board, 2024, 2025). The non-supported H5 therefore adds nuance to the findings: barriers are clearly present in the sector, but their relationship with scaling intention is not simply negative in the current cross-sectional data.

5.5. Responsible AI Orientation and Governance Maturity

Responsible AI Orientation was included as a maturity dimension and as a hypothesized predictor of Perceived Benefits. The H3b path was positive but not statistically significant after accounting for Capability–Governance Readiness. This indicates that Responsible AI Orientation did not add a distinct association with Perceived Benefits in the main regression specification once broader capability–governance readiness was included.
This result is consistent with the way responsible AI is positioned in the conceptual model. Responsible AI Orientation captures the normative principles that guide AI use, including fairness, transparency, accountability, privacy, explainability, human oversight, and risk awareness. Capability–Governance Readiness captures the organizational capacity to implement, coordinate, monitor, and govern AI systems. The two constructs are therefore conceptually related, but they do not represent the same dimension.
This interpretation is supported by the discriminant-validity diagnostics, where the relationship between Capability–Governance Readiness and Responsible AI Orientation required cautious interpretation. The empirical proximity between the two constructs suggests that, in this sector, responsible AI principles are closely connected to broader governance readiness. This is plausible in banking, where responsible AI depends on governance structures, monitoring capacity, accountability mechanisms, documentation, risk assessment, and human oversight.
The practical implication is that responsible AI should be embedded in governance routines rather than treated as a separate ethical statement. For banks, this means connecting responsible AI principles to model review, data governance, vendor oversight, explainability practices, human-in-the-loop procedures, performance monitoring, and internal audit.
Accordingly, Responsible AI Orientation remains relevant as part of the maturity profile, even though it was not supported as a separate unique predictor of Perceived Benefits in the main regression model. Its role in the study is therefore best understood as a responsible-use dimension of AI maturity and governance, rather than as an independent driver of perceived benefits.

5.6. Theoretical Contributions

The study makes three theoretical contributions. First, it extends the application of the TOE framework to AI adoption in a small, highly regulated European banking system. The findings show that technological readiness, organizational capability, and environmental pressure remain useful for examining AI readiness in banking. The contribution is not only that these TOE dimensions are relevant, but that their meaning changes in the context of AI. In AI adoption, the organizational dimension cannot be limited to managerial support, resources, or general readiness. It must also include the capacity to govern, monitor, document, and control AI systems.
Second, the study advances Capability–Governance Readiness as a theoretically useful construct for AI adoption research. This construct integrates implementation capacity with governance capacity and reflects the conditions under which banks can move from experimentation to responsible scaling. By combining skills, resources, governance arrangements, oversight, accountability, and monitoring capacity, the construct captures an organizational capability that is particularly relevant for AI in banking. In this sense, the study refines the organizational component of the TOE framework by showing that, in banking, organizational readiness is closely connected to governance readiness, oversight, accountability, and risk-management capability.
Third, the study contributes a maturity-based perspective. The AI Maturity Index provides a structured descriptive view of AI adoption that goes beyond simple adoption status. By combining adoption and integration, data and technology readiness, capability–governance readiness, and responsible AI orientation, the index captures the multidimensional nature of AI maturity. This contribution is conceptual and descriptive rather than causal: it provides a way to distinguish initial AI use from deeper institutional embedding, monitoring, governance, and responsible scaling capacity.
This maturity perspective is theoretically relevant because it distinguishes between the presence of AI tools and the institutional capacity to integrate, monitor, evaluate, and scale them responsibly. It is consistent with previous conceptual work arguing that AI adoption in the Albanian banking system should be understood as a socio-technical transformation involving data foundations, application domains, governance mechanisms, and organizational readiness (Domi & Godolja, 2026). The present study extends this prior conceptual work by providing primary empirical evidence on how these dimensions appear together in the readiness and maturity profile of the Albanian banking system
Overall, the study contributes to administrative and organizational research by positioning AI adoption as a governance and maturity process rather than as a binary technology-adoption outcome. This framing is especially relevant for small and emerging banking systems, where the key challenge may not be whether AI is present, but whether institutions have the organizational, technological, and governance capacity to integrate and scale it responsibly.

5.7. Practical and Policy Implications

The findings suggest that AI scaling in the Albanian banking system should be approached as a staged maturity process. Institutions should assess whether their data infrastructure, system integration, skills, governance arrangements, monitoring practices, and benefit-measurement mechanisms are sufficient to support responsible scaling. This assessment should be linked to specific AI use cases rather than treated as a general digital-readiness exercise. Pilot projects should not be treated as evidence of maturity unless they are accompanied by governance, monitoring, accountability, and measurable value.
For managers, the most immediate priority is capability building. Skills and capability gaps were the most frequently reported barriers, indicating the need for staff training, cross-functional collaboration, data literacy, model-risk awareness, and governance competence. AI adoption should involve not only IT and data teams, but also business, compliance, risk, legal, audit, and senior management functions. A practical step is to establish cross-functional AI governance groups that review use-case selection, data availability, model-risk exposure, operational impact, customer impact, and benefit measurement before AI systems are scaled.
For risk, compliance, and governance functions, the results highlight the need to integrate AI into existing risk-management frameworks. AI governance should address model risk, data quality, explainability, cybersecurity, third-party dependency, human oversight, and accountability. Institutions should maintain an internal inventory of AI use cases, document the purpose and owner of each system, define monitoring responsibilities, and specify when human review is required. These areas are consistent with the priorities emphasized by the Basel Committee, the FSB, NIST, ISO/IEC 42001:2023, and the EBA’s work on AI-related regulatory implications in banking and payments.
Benefit measurement is another practical priority. Institutions should define measurable objectives before moving from pilot use to broader implementation. Depending on the use case, these objectives may include processing time, error reduction, fraud-detection effectiveness, customer-service response time, compliance workload reduction, document-processing efficiency, or risk-monitoring accuracy. This would help institutions distinguish between experimental AI use and applications that generate observable organizational value.
For policymakers and supervisors, the findings suggest that regulatory clarity can support responsible AI readiness. In smaller banking systems, system-wide guidance, shared terminology, reporting templates, supervisory dialogue, and capacity-building initiatives may help institutions interpret evolving international expectations and translate them into practical governance processes. Supervisory guidance could focus on AI-use-case inventories, minimum documentation requirements, third-party and outsourcing risk, human oversight, model monitoring, data governance, and incident-reporting expectations. Such guidance would be especially useful where institutions differ in size, technical capacity, and AI maturity.
Finally, the findings suggest that responsible AI scaling should be treated as a banking-system capacity-building issue. Training initiatives, supervisory workshops, and shared good-practice examples could help smaller institutions understand how to operationalize responsible AI principles without treating governance as a purely formal compliance requirement.

5.8. Limitations and Future Research

This study has several limitations. First, the cross-sectional design means that the results should be interpreted as associations rather than causal effects. The analysis identifies patterns among perceived readiness, governance, benefits, barriers, and scaling intention at one point in time; it does not establish temporal ordering or causal change. Future longitudinal research could examine how AI readiness develops over time and whether improvements in governance capacity, monitoring routines, and benefit measurement are followed by deeper integration or stronger scaling outcomes.
Second, the unit of observation is the individual survey response, although respondents provided informed organizational perceptions. This interpretation is supported by the respondent profile: most respondents had long experience in the banking system, and the sample was concentrated in business and management, IT, digital, data and analytics, risk, compliance, audit, operations, and related decision-support functions. These roles are directly relevant to AI adoption, governance, monitoring, and scaling in banking. The institutional pool is broad and includes all banks operating in Albania, but the number of responses per institution differs. Accordingly, the findings should be interpreted as banking-system-level evidence based on experienced professional perceptions, not as formal institution-level measurement. Equal-institution weighting and leave-one-institution-out analyses were used to assess the stability of the main patterns, but they do not replace research designs based on matched institution-level data, repeated observations, or within-institution case evidence. Future studies could combine survey evidence with institutional AI inventories, governance documents, supervisory information, interviews, or case studies to examine how AI readiness is organized within specific institutions.
Third, the study relies on self-reported measures. Common-method diagnostics did not suggest that a single factor dominated the data, but common-method bias cannot be ruled out. This limitation is relevant because predictor and outcome variables were collected from the same respondents in the same survey instrument. The experience and functional relevance of the respondents improve the interpretive value of the survey evidence, but they do not eliminate the possibility of common-method effects. Future research could reduce this concern by combining multiple data sources, such as managerial surveys, technical deployment indicators, audit or compliance records, performance metrics, and supervisory or regulatory data.
Fourth, the sample size is modest, which is expected in a small national banking system but limits the complexity of the empirical model. For this reason, the model was intentionally parsimonious and the measurement diagnostics were interpreted cautiously. The results are therefore best understood as exploratory evidence from a small and concentrated banking system based on informed professional perceptions, rather than as population-wide statistical generalization. Future studies with larger cross-country samples could test more complex models, compare institutional subgroups, and examine whether the relationships observed in this study differ across regulatory environments, market structures, or levels of digital maturity.
Future research could examine how AI maturity evolves over time and whether improvements in readiness lead to deeper integration and measurable benefits. Comparative studies across Western Balkan or other small European banking systems would help assess whether the observed difference between readiness-related foundations and operational integration is specific to Albania or reflects broader regional dynamics. Future work could also combine survey data with interviews, institutional case studies, supervisory analysis, or technical indicators of AI deployment. More detailed research is especially needed on how banking systems measure AI benefits, govern third-party and generative AI tools, manage model risk, and align responsible AI practices with evolving European and international regulatory expectations.

6. Conclusions

This study examined AI adoption, governance readiness, maturity, perceived benefits, adoption barriers, and scaling intention in the Albanian banking system. Based on 85 responses from professionals across 15 institutions, including all 12 banks operating in Albania and three additional financial institutions, the study provides exploratory banking-system-level evidence on how AI readiness and governance are developing in a small and institutionally concentrated banking system. The evidence should be interpreted as informed professional perceptions of organizational conditions, not as audited institution-level measurement or causal evidence.
The findings indicate that AI adoption is visible in the sector, but maturity remains uneven. Initial use and experimentation are more advanced than full operational integration, systematic monitoring, and benefit measurement. This distinction is important because responsible AI adoption in banking requires more than the presence of AI tools. It requires data readiness, implementation capability, governance structures, monitoring routines, accountability mechanisms, and clear evidence of organizational value.
The empirical results support the relevance of technological, organizational, and environmental conditions for AI readiness. Data and Technology Readiness and Environmental/Regulatory Pressure were positively associated with Capability–Governance Readiness. Capability–Governance Readiness was positively associated with Perceived Benefits, and Perceived Benefits were positively associated with Intention to Invest/Scale. These associations are consistent with the study’s conceptual model and show that AI scaling is linked to the alignment of technological foundations, organizational capability, governance capacity, and perceived value.
The non-supported relationship between Adoption Barriers and Intention to Invest/Scale adds an important nuance. Adoption Barriers were not negatively associated with scaling intention in the main model. This does not mean that barriers are unimportant. Rather, it suggests that in an early-stage adoption context, perceived barriers may coexist with AI engagement and scaling ambition. Institutions that are already exposed to AI implementation may be more aware of skills gaps, integration difficulties, regulatory uncertainty, data-quality limitations, cybersecurity risks, and third-party dependencies. The relationship between barriers and scaling intention is therefore more complex than a simple negative association in the present cross-sectional data.
The study contributes to AI adoption and governance research in three ways. First, it provides empirical evidence from a small European banking system, a context that remains less represented in AI banking research. Second, it extends the readiness perspective by emphasizing Capability–Governance Readiness as a central organizational condition for responsible AI adoption in banking. Third, it applies a maturity perspective that distinguishes initial AI use from deeper institutional embedding, monitoring, governance, and responsible scaling capacity. Responsible AI Orientation complements this maturity perspective by emphasizing that AI development should be guided by fairness, transparency, accountability, privacy, explainability, human oversight, and risk awareness.
For practice, the findings indicate that banking systems should approach AI scaling as a staged maturity process. Priorities include strengthening data infrastructure, system integration, staff capability, cross-functional governance, model and vendor oversight, monitoring routines, and benefit-measurement practices. For supervisors and policymakers, the results point to the value of clear and practical guidance on AI governance, documentation, transparency, accountability, outsourcing, data governance, and risk management. Such guidance is especially relevant in smaller banking systems, where institutions may differ in technical capacity, governance maturity, and exposure to AI-related risks.
The study has limitations that define the scope of interpretation. The design is cross-sectional, the data are self-reported, the sample size is modest, and the unit of observation is the individual survey response. Although the respondents were experienced professionals in relevant banking, management, technology, data, compliance, risk, and decision-support roles, the findings remain perception-based and should not be interpreted as formal institutional assessments. Future research could use longitudinal, institution-level, comparative, or mixed-method designs to examine how AI maturity develops over time. Cross-country studies across Western Balkan or other small European banking systems would also help assess whether similar maturity patterns appear in comparable regulatory and institutional contexts.
Overall, the next stage of AI development in the Albanian banking system is likely to depend less on adoption alone and more on the capacity to govern, monitor, measure, and scale AI responsibly. Although the study is situated in Albania, its findings may also be relevant for other small and emerging banking systems facing similar challenges related to data readiness, specialized expertise, regulatory alignment, third-party dependency, and responsible AI governance.

Supplementary Materials

The following supporting information can be downloaded at https://www.mdpi.com/article/10.3390/admsci16080385/s1. Figure S1: Top-three AI adoption barriers; Figure S2: AI Maturity Index tiers; Figure S3: AI Maturity Index by institution size; Figure S4: AI Maturity Index by respondent role; Figure S5: AI Maturity Index by investment horizon; Table S1: Missingness by case; Table S2: Response-quality diagnostics; Table S3: Branch-logic summary; Table S4: Skip-logic detail summary; Table S5: Governance-unit profile; Table S6: Benefit-measurability profile; Table S7: Top-three barrier integrity check; Table S8: Construct descriptives; Table S9: Harman single-factor test; Table S10: Full-collinearity VIF diagnostics; Table S11: Equal-weighted AMI tiers; Table S12: Equal-weighted AMI summary; Table S13: Detailed Hypothesis Test for Responsible AI Orientation and Perceived Benefits; Table S14: Main regression results; Table S15: Main regression diagnostics; Table S16. PLS-SEM main construct quality; Table S17. detailed PLS-SEM main path coefficients; Table S18. PLS-SEM main explained variance R2; Table S19. PLS-SEM main outer loadings and weights; Table S20. PLS-SEM main unidimensionality; Table S21. disaggregated PLS-SEM hypothesis summary; Table S22. disaggregated PLS-SEM construct quality; Table S23. disaggregated PLS-SEM explained variance R2; Table S24. disaggregated PLS-SEM outer loadings and weights; Table S25: Straight-lining exclusion sensitivity analysis; Table S26: Leave-one-institution-out sensitivity analysis; Table S27: Equal-institution weighted hypothesis summary; Table S28: Institution-size Kruskal–Wallis test; Table S29: Respondent-role Kruskal–Wallis test; Table S30: Investment-horizon Kruskal–Wallis test; Table S31: Qualitative theme summary; Table S32: Qualitative “Other” category audit; Table S33: Non-verbatim qualitative theme codes; R Script: Reproducible empirical analysis script; File Q1. Original Albanian-language questionnaire; File R1: R session information and package versions.

Author Contributions

Conceptualization, L.D. and M.G.; methodology, M.G. and L.D.; formal analysis, M.G.; validation, L.D.; original draft preparation, L.D. and M.G.; supervision, M.G. and K.S. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Ethical review and approval were waived for this study due to its voluntary, anonymous, non-interventional survey design and minimal risk to participants. The study was conducted within the approved doctoral research framework “Aplikimi i Inteligjencës Artificiale në Industrinë Bankare në Shqipëri: Zhvillimet Aktuale dhe Perspektivat e Ardhshme” at the University of Tirana, Faculty of Economy.

Data Availability Statement

The data supporting the findings of this study are available from the corresponding author upon reasonable request owing to privacy restrictions.

Acknowledgments

The authors would like to thank all survey participants for their valuable time, insights, and professional contributions to this study. Special appreciation is extended to the professionals working in the key departments of banks operating in Albania and the financial institutions included in the study, whose informed perspectives and sectoral expertise made this research possible.

Conflicts of Interest

The authors declare no conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
ABAdoption Barriers
AIArtificial Intelligence
AMIAI Maturity Index
AMLAnti-Money Laundering
APIApplication Programming Interface
AVEAverage Variance Extracted
BCBSBasel Committee on Banking Supervision
CGRCapability–Governance Readiness
CIConfidence Interval
DTRData and Technology Readiness
EBAEuropean Banking Authority
ERPEnvironmental/Regulatory Pressure
FSBFinancial Stability Board
HC3Heteroskedasticity-Consistent Standard Error, type 3
HTMTHeterotrait–Monotrait Ratio
INTIntention to Invest/Scale
ISO/IECInternational Organization for Standardization/International Electrotechnical Commission
KPIKey Performance Indicator
MLMachine Learning
NISTNational Institute of Standards and Technology
NLPNatural Language Processing
OCROptical Character Recognition
OLSOrdinary Least Squares
PBPerceived Benefits
PCAPrincipal Component Analysis
RAIResponsible AI Orientation
RPARobotic Process Automation
SDStandard Deviation
SEStandard Error
SRSkills and Resources Readiness
TOETechnology–Organization–Environment
VIFVariance Inflation Factor

Appendix A

Table A1. Questionnaire blocks, construct linkage, and analytical treatment.
Table A2. HTMT Matrix.
Table A3. HTMT Diagnostic Flags.
Table A4. Fornell–Larcker Matrix.
Table A5. Fornell–Larcker Diagnostics.
Table A6. AMI Tiers.
Table A7. Scaling Readiness Gap Profile.
Table A8. AMI by Bank Size.
Table A9. AMI by Respondent Role.
Table A10. AMI by Investment Horizon.
Table A11. Spearman Correlation Matrix_r.
Table A12. Spearman Correlation Matrix_p.

References

  1. Ajili Ben Youssef, W., Bouebdallah, N., & Long, H. (2025). Factors influencing generative artificial intelligence adoption in Vietnam’s banking sector: An empirical study. Financial Innovation, 11(1), 119. [Google Scholar] [CrossRef] [Scilit]
  2. Alassuli, A., Eltweri, A., Thuneibat, N. S., Al-Hajaya, K., & Ismail, S. M. (2026). Artificial intelligence applications and financial forecasting accuracy in banking platforms: Evidence from Jordan. Administrative Sciences, 16(3), 122. [Google Scholar] [CrossRef] [Scilit]
  3. Ali, W., & Khan, A. Z. (2025). Factors influencing readiness for artificial intelligence: A systematic literature review. Data Science and Management, 8(2), 224–236. [Google Scholar] [CrossRef] [Scilit]
  4. Awa, H. O., Ojiabo, O. U., & Orokor, L. E. (2017). Integrated technology-organization-environment (T-O-E) taxonomies for technology adoption. Journal of Enterprise Information Management, 30(6), 893–921. [Google Scholar] [CrossRef] [Scilit]
  5. Baffour Gyau, E., Appiah, M., Gyamfi, B. A., Achie, T., & Naeem, M. A. (2024). Transforming banking: Examining the role of AI technology innovation in boosting banks financial performance. International Review of Financial Analysis, 96, 103700. [Google Scholar] [CrossRef] [Scilit]
  6. Baker, J. (2012). The Technology–Organization–Environment framework. In Y. K. Dwivedi, M. R. Wade, & S. L. Schneberger (Eds.), Information systems theory. Integrated series in information systems (Vol. 28, pp. 231–245). Springer. [Google Scholar] [CrossRef] [Scilit]
  7. Bank of Albania. (2026a). Banks. Available online: https://www.bankofalbania.org/Supervision/Licensed_institutions/Banks/ (accessed on 14 May 2026).
  8. Bank of Albania. (2026b). Digital transformation of the Albanian banking system: The results of the Albanian banking sector digitalization survey 2024. Available online: https://www.bankofalbania.org/Publications/Research/Research_Papers/Digital_transformation_of_the_Albanian_banking_system_The_results_of_the_Albanian_banking_sector_digitalization_survey_2024.html (accessed on 31 July 2026).
  9. Basel Committee on Banking Supervision (Ed.). (2024). Digitalisation of finance. Bank for International Settlements. [Google Scholar]
  10. Cameron, A. C., & Miller, D. L. (2015). A Practitioner’s guide to cluster-robust inference. Journal of Human Resources, 50(2), 317–372. [Google Scholar] [CrossRef] [Scilit]
  11. Cronbach, L. J. (1951). Coefficient alpha and the internal structure of tests. Psychometrika, 16(3), 297–334. [Google Scholar] [CrossRef] [Scilit]
  12. de Almeida, P. G. R., & dos Santos Júnior, C. D. (2025). Artificial intelligence governance: Understanding how public organizations implement it. Government Information Quarterly, 42(1), 102003. [Google Scholar] [CrossRef] [Scilit]
  13. Diamantopoulos, A., & Winklhofer, H. M. (2001). Index construction with formative indicators: An alternative to scale development. Journal of Marketing Research, 38(2), 269–277. [Google Scholar] [CrossRef] [Scilit]
  14. DiMaggio, P. J., & Powell, W. W. (1983). The iron cage revisited: Institutional isomorphism and collective rationality in organizational fields. American Sociological Review, 48(2), 147–160. [Google Scholar] [CrossRef] [Scilit]
  15. Domi, L., & Godolja, M. (2026). Designing responsible AI adoption in banking: A multi-layer conceptual framework. All Sciences Academy. [Google Scholar]
  16. Efron, B. (1979). Bootstrap methods: Another look at the jackknife. The Annals of Statistics, 7(1), 1–26. [Google Scholar] [CrossRef] [Scilit]
  17. Eskandarany, A. (2024). Adoption of artificial intelligence and machine learning in banking systems: A qualitative survey of board of directors. Frontiers in Artificial Intelligence, 7, 1440051. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  18. European Banking Authority. (2025). AI act: Implications for the EU banking and payments sector. Available online: https://www.eba.europa.eu/sites/default/files/2025-11/d8b999ce-a1d9-4964-9606-971bbc2aaf89/AI%20Act%20implications%20for%20the%20EU%20banking%20sector.pdf (accessed on 14 May 2026).
  19. Financial Stability Board. (2024). The financial stability implications of artificial intelligence. Report to the G20. Financial Stability Board. Available online: https://www.fsb.org/2024/11/the-financial-stability-implications-of-artificial-intelligence/ (accessed on 4 May 2026).
  20. Financial Stability Board. (2025). Monitoring adoption of artificial intelligence and related vulnerabilities in the financial sector. Financial Stability Board. Available online: https://www.fsb.org/2025/10/monitoring-adoption-of-artificial-intelligence-and-related-vulnerabilities-in-the-financial-sector/ (accessed on 3 May 2026).
  21. Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation models with unobservable variables and measurement error. Journal of Marketing Research, 18(1), 39–50. [Google Scholar] [CrossRef] [Scilit]
  22. Fundira, M., & Mbohwa, C. (2025). AI ethics in banking services: A systematic and bibliometric review of regulatory and consumer perspectives. Discover Artificial Intelligence, 5(1), 319. [Google Scholar] [CrossRef] [Scilit]
  23. Godolja, M., & Domi, L. (2024). AI applications in banking risk management: Exploring key trends and barriers. In Proceedings book—AI 2024. Academy of Sciences of Albania. [Google Scholar]
  24. Godolja, M., Tavanxhiu, T., & Sevrani, K. (2025). Strategic readiness for AI and smart technology adoption in emerging hospitality markets: A Tri-Lens assessment of barriers, benefits, and segments in Albania. Tourism and Hospitality, 6(4), 187. [Google Scholar] [CrossRef] [Scilit]
  25. Hair, J. F., Black, W. C., Babin, B. J., & Anderson, R. E. (2019). Multivariate data analysis. Cengage. [Google Scholar]
  26. Henseler, J., Ringle, C. M., & Sarstedt, M. (2015). A new criterion for assessing discriminant validity in variance-based structural equation modeling. Journal of the Academy of Marketing Science, 43(1), 115–135. [Google Scholar] [CrossRef] [Scilit]
  27. Hussein, R., Zink, A., Ramadan, B., Howard, F. M., Hightower, M., Shah, S., & Beaulieu-Jones, B. K. (2026). Advancing healthcare AI governance through a comprehensive maturity model based on systematic review. npj Digital Medicine, 9(1), 236. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  28. International Organization for Standardization. (2023). “Information technology—Artificial intelligence—Management system” (ISO/IEC 42001:2023). ISO. Available online: https://www.iso.org/standard/42001 (accessed on 14 May 2026).
  29. Jöhnk, J., Weißert, M., & Wyrtki, K. (2021). Ready or not, AI comes—An interview study of organizational AI readiness factors. Business & Information Systems Engineering, 63(1), 5–20. [Google Scholar] [CrossRef] [Scilit]
  30. Lazo, M., & Ebardo, R. (2023). Artificial intelligence adoption in the banking industry: Current state and future prospect. Journal of Innovation Management, 11(3), 54–74. [Google Scholar] [CrossRef] [Scilit]
  31. Little, R., & Rubin, D. (2019). Statistical analysis with missing data, third edition (1st ed.). Wiley Series in Probability and Statistics. Wiley. [Google Scholar] [CrossRef] [Scilit]
  32. MacKinnon, J. G. (2026). When can we trust cluster-robust inference? arXiv, arXiv:2604.02000. [Google Scholar] [CrossRef] [Scilit]
  33. MacKinnon, J. G., & White, H. (1985). Some heteroskedasticity-consistent covariance matrix estimators with improved finite sample properties. Journal of Econometrics, 29(3), 305–325. [Google Scholar] [CrossRef] [Scilit]
  34. Nardo, M., Saisana, M., Saltelli, A., Tarantola, S., Hoffmann, A., & Giovannini, E. (2005). Handbook on constructing composite indicators: Methodology and user guide. OECD Statistics Working Papers, 2005(3), 108. [Google Scholar] [CrossRef]
  35. Podsakoff, P. M., MacKenzie, S. B., Lee, J.-Y., & Podsakoff, N. P. (2003). Common method biases in behavioral research: A critical review of the literature and recommended remedies. Journal of Applied Psychology, 88(5), 879–903. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  36. Podsakoff, P. M., Podsakoff, N. P., Williams, L. J., Huang, C., & Yang, J. (2024). Common method bias: It’s bad, it’s complex, it’s widespread, and it’s not easy to fix. Annual Review of Organizational Psychology and Organizational Behavior, 11(2024), 17–61. [Google Scholar] [CrossRef] [Scilit]
  37. Porsdam Mann, S., Vazirani, A. A., Aboy, M., Earp, B. D., Minssen, T., Cohen, I. G., & Savulescu, J. (2024). Guidelines for ethical use and acknowledgement of large language models in academic writing. Nature Machine Intelligence, 6(11), 1272–1274. [Google Scholar] [CrossRef] [Scilit]
  38. Rahman, M., Ming, T. H., Baigh, T. A., & Sarker, M. (2021). Adoption of artificial intelligence in banking services: An empirical analysis. International Journal of Emerging Markets, 18(10), 4270–4300. [Google Scholar] [CrossRef] [Scilit]
  39. Saltelli, A. (2025). Models and the common good. Environmental Modelling & Software, 188, 106430. [Google Scholar] [CrossRef] [Scilit]
  40. Shahzadi, G., Jia, F., Chen, L., & John, A. (2024). AI adoption in supply chain management: A systematic literature review. Journal of Manufacturing Technology Management, 35(6), 1125–1150. [Google Scholar] [CrossRef] [Scilit]
  41. Singh, R. K., Mishra, R., Kumar, S., & Bag, S. (2025). Applications of artificial intelligence for optimizing banking and financial operations: A systematic literature review and future research agenda. Journal of Economic Surveys, 39(5), 2284–2302. [Google Scholar] [CrossRef] [Scilit]
  42. Tabassi, E. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). National Institute of Standards and Technology (U.S.). [CrossRef] [Scilit]
  43. Tornatzky, L. G., Fleischer, M., & Chakrabarti, A. K. (1990). The processes of technological innovation. Lexington Books. [Google Scholar]
  44. Vuković, D. B., Dekpo-Adza, S., & Matović, S. (2025). AI integration in financial services: A systematic review of trends and regulatory challenges. Humanities and Social Sciences Communications, 12(1), 562. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.