H

HSBC

HSBC achieves 5x faster vulnerability patching by deploying AI coding assistants to 31,000 engineers

Curated & reviewed by Peter Korpak, Founder & Chief Analyst, 100SignalsHow we verify
5x fasterVulnerability Patching Speed
31,000+Engineers with AI Coding Assistants

Vendor-reported figures — source: kingy.ai

HSBC
Metric Before After Impact
Vulnerability Patching Speed baseline 5x faster 5x improvement in security responsiveness
Engineers with AI Coding Assistants 31,000+ One of largest enterprise AI coding deployments in financial services
Applications Decommissioned (2025) 1,165 36% of four-year rationalization target in one year
Annualized Simplification Savings $1 billion $1.2 billion Exceeded original target by $200M

The Challenge

HSBC operated a technology estate of over 9,000 applications accumulated across decades of global expansion — a legacy footprint that created compounding security and operational risk. In financial services, regulatory requirements demand rapid vulnerability remediation; manual patching cycles across thousands of disparate systems created meaningful attack-surface exposure and slowed engineering throughput. Engineers spent significant capacity on maintenance rather than higher-value development, while technical debt accumulated faster than it could be retired. With roughly 3,000 applications classified as non-strategic, the sheer maintenance burden constrained the bank's ability to modernize. The status quo carried direct costs: extended remediation windows, rising compliance risk, and reduced capacity to deliver new capabilities to customers.

The Solution

HSBC deployed AI-powered coding assistants — built on large language models and generative AI — to more than 31,000 engineers across its global technology organization, part of a broader transformation initiative that CEO Georges Elhedery identified at the bank's Q4 2025 earnings call as its single largest technology investment. Rather than a narrow pilot, HSBC pursued enterprise-wide deployment, granting 85% of its total workforce access to generative AI tools. For engineering teams specifically, the assistants were integrated into existing development workflows, providing real-time code suggestions, automated vulnerability detection, and AI-assisted patching. This deployment ran in parallel with an aggressive application rationalization program — decommissioning 1,165 non-strategic applications in 2025 alone — ensuring that AI productivity gains compounded as the legacy estate shrank and maintenance overhead declined.

Results

The headline outcome was a 5x improvement in vulnerability patching speed, a step-change in security responsiveness for a bank managing thousands of production applications. The program reached 31,000+ engineers globally, making it one of the largest enterprise AI coding deployments in financial services. Broader AI adoption metrics include:

  • 600+ AI use cases active across the organization as of early 2026
  • 1,000+ relationship managers equipped with a Wealth AI platform for personalized client insights
  • 50%+ of CRM engagement now supported by Banker Assist AI tools
  • 1,165 applications decommissioned in 2025 — 36% of a four-year rationalization target completed in a single year

The bank also delivered $1.2 billion in annualized simplification savings in 2025, exceeding its original $1 billion target.

Key Takeaways

  • AI coding assistants deliver multiplicative — not incremental — productivity gains when deployed at enterprise scale; a 5x improvement in patching speed reflects a structural change, not a marginal one.
  • Enterprise-wide AI adoption (85% of workforce) requires explicit leadership mandate and deliberate enablement investment, not just tool access.
  • Application rationalization and AI deployment are mutually reinforcing: retiring legacy systems reduces maintenance burden and frees engineering capacity for AI-assisted development.
  • Pairing generative AI with end-to-end process redesign — rather than bolting it onto existing workflows — is what drives structural efficiency gains.
  • Vulnerability remediation speed is a strong early proof-of-value metric for AI coding programs in regulated industries.

Share:

Details

Industry
Retail
Company Size
Enterprise
Company
HSBC
Quality
Curated
Last verified
Jul 28, 2026

Source

kingy.ai

Have a similar implementation?

Share your customer's AI results and link it to your vendor profile.

Submit a case study →