A large coin with a dollar symbol next to a small
AI

PYMNTS: Stablecoins and AI are forcing enterprises to reprice cyber budgets

The analysis argues wallet keys and transaction signing are becoming treasury controls as quantum shortens encryption lifespans.

By Elliot Marsh5 min read

Enterprises are being pushed to reallocate cybersecurity budgets as AI compresses fraud timelines, quantum computing shortens the expected lifespan of encryption, and stablecoins turn credential compromise into direct treasury risk. A Sept. 9, 2026 analysis frames the shift as a capital-allocation problem where some existing security spend is becoming “redundant, inadequate or mispriced.”

The clean separation between “cyber incident” and “treasury loss” gets harder to maintain once a company starts moving value over stablecoin rails or tokenized deposits. In conventional enterprise payments, compromising an employee identity and stealing corporate cash are usually different steps, with payment approvals, fraud controls, and intermediaries acting as speed bumps before settlement.

The PYMNTS analysis argues that blockchain-based finance compresses that path. As firms use stablecoins, tokenized deposits, and blockchain infrastructure, cryptographic credentials can directly control financial assets. That shifts the control surface from perimeter security toward wallet governance, meaning private keys, wallet permissions, and transaction-signing policies start to look like treasury infrastructure, not just IT tooling.

That mechanism also drags identity and financial-crime controls into the same budget line. The piece frames digital assets as merging cybersecurity with KYC/KYB, meaning Know Your Customer and Know Your Business checks used to verify individuals and companies, because compromised credentials, synthetic identities, and scams can become balance-sheet events. The operational response it calls out is concrete: stronger KYC/KYB, wallet screening, transaction monitoring, and transaction controls that constrain how value can move once access is obtained.

AI and Quantum Reprice the Security Stack’s Time Horizon

The analysis puts AI, quantum computing, and blockchain finance in the same bucket for a specific reason. It says they attack three assumptions the modern security stack was built on: AI undermines the economics of human-centered detection and response, quantum undermines cryptography’s expected lifespan, and digital money blurs the line between cybersecurity infrastructure and financial infrastructure.

On AI, the argument is about speed and marginal cost. The piece describes AI as industrializing phishing, impersonation, and fraud while compressing attack timelines, which pushes spend toward automated detection, identity verification, and faster response. It also claims AI lowers the marginal cost of producing attacks and lowers the marginal cost of investigating them, creating an arms race “measured in time rather than head count.”

That budgeting lens shows up in how the piece frames ROI for agentic AI, meaning systems that can take actions autonomously or semi-autonomously. “If you’re going to experiment with agentic AI or any type of AI solutions, you want to focus on two things. One is the area where you’re most likely to have success. And two, is there going to be a good return on that investment?” said WEX Chief Digital Officer Karen Stroup.

Quantum is positioned differently: not as an active breach vector today, but as a depreciation schedule on existing controls. The analysis says quantum risk puts an “expiration date” on today’s encryption, requiring cryptographic inventories, post-quantum migration planning, and “crypto-agility,” meaning the ability to swap cryptographic algorithms across systems without rebuilding everything. “The time to start thinking about migrating to quantum-resistant methods of encryption is now,” said Professor Scott Aaronson, who recently joined StarkWare as scientific adviser, in a February conversation hosted by PYMNTS CEO Karen Webster.

The work the piece calls out is operational and unglamorous: inventory cryptography across applications, certificates, APIs, hardware, software libraries, and third-party systems, then classify data by “confidentiality horizon,” test replacement algorithms, and pressure vendors for migration paths. It frames this as technology debt, and warns the biggest eventual bill may land on enterprises that do not know where their cryptography lives.

Where Enterprise Spend Is Tilting: Identity, Connectivity, Automation

The near-term spend signals in the analysis point to identity and workflow plumbing, not just new point solutions. A PYMNTS Intelligence report titled “Payment Protection: Why Firms Still Aren’t Real-Time Ready,” referenced as published in August, found 65% of firms plan to adopt or expand identity verification and KYC automation within the next 12 months.

Two other categories tied for the next slot: secure bank connectivity at 59% and AI-based fraud detection at 59%. Reconciliation automation was the highest-cited item at 70%, which matters because reconciliation is where enterprises prove what moved, when, and under whose authority, the same questions that become acute when stablecoin settlement is fast and hard to reverse.

For stablecoin and tokenized-deposit adoption, that mix implies where friction will concentrate. If enterprises are budgeting for identity verification, secure connectivity, fraud detection, and reconciliation automation, then stablecoin rails that cannot plug into those controls cleanly will carry a higher internal risk premium.

The forward signal to track is whether stablecoin or tokenized-deposit pilots start shipping with explicit wallet governance requirements, including multi-signature or permissioned approvals, transaction policies, and monitoring. The other tell is vendor and bank roadmaps for post-quantum migration and crypto-agility features like cryptographic inventories and algorithm swap capability that enterprises can adopt without a full rebuild. The PYMNTS Intelligence percentages are also a live indicator: if the 65% identity/KYC automation and 59% AI fraud detection figures climb over the next 12 months, it suggests enterprises expect verification and automation to carry more of the fraud load as timelines compress.

My Take: The Next Adoption Bottleneck Is Operational Control, Not Chain Throughput

The part that decides this isn’t whether stablecoin settlement is fast. It’s whether enterprises can make wallet keys, permissions, and transaction signing behave like treasury controls with approvals, segregation of duties, and monitoring that survives an identity compromise.

The threshold that matters is when stablecoin and tokenized-deposit deployments start specifying those controls as non-negotiable requirements, alongside KYC/KYB automation and transaction screening, rather than treating them as optional “security add-ons.” If that holds, the repricing becomes structural: stablecoin rails win or lose on operational control surfaces that constrain value movement under attack, not on-chain throughput.

Sources