From Copilots to Colleagues

Financial institutions spent the first generative-AI wave worrying about chatbots hallucinating. The next challenge is more unsettling: what happens when AI acts on its mistakes? Banks, insurers and fintechs are moving towards agentic systems that can plan, decide and execute tasks, from detecting fraud to initiating payments. Indeed, the FCA is already live-testing agentic payment applications. This autonomy challenges controls designed around humans or predictable software. In the EU, the AI Act operates alongside DORA, while Britain’s FCA favours existing frameworks, including Consumer Duty and SM&CR. How, then, do humans govern machines operating at machine speed?

What Agentic AI Really Means for Financial Services

Traditional automation follows rules. Generative AI creates content or recommendations. However, agentic AI crosses a more consequential boundary where it can interpret an objective, plan several steps, use external tools and act with limited human intervention. The Bank of England describes such systems as capable of carrying out multi-step tasks at machine speed.

Consider cash management. A generative tool might recommend where surplus funds could earn more. An agent could analyse balances, compare products, transfer money and monitor whether its decision remains appropriate. The governance question therefore becomes not simply what model is being used, but how large its autonomy envelope” is. What can it access, decide, spend, change or communicate without permission?

This is already moving beyond theory. The FCA’s 2026 AI Live Testing cohort includes agentic payments alongside investment support, AML detection and KYC applications. Its Supercharged Sandbox is also exploring safer agent-led payments and commerce. Financial institutions may consequently need something new in the form of an agent inventory, recording each agent’s purpose, permissions, tools, limits and accountable owner.

Who Is Accountable When the Agent Makes the Decision?

If an autonomous agent makes 5,000 decisions overnight, what does “human oversight” actually mean? Governance must distinguish between humans in the loop, approving actions, on the loop, supervising and intervening, and effectively out of the loop, where agents operate within preset boundaries.

Simply inserting a person into the process is no guarantee of control. Faced with hundreds of machine-generated decisions, a manager can quickly become a rubber stamp. Meaningful intervention requires understanding the agent, receiving useful warnings and possessing genuine authority to stop or reverse actions. The EU AI Act reflects this principle for high-risk systems, requiring effective human oversight and the capacity to override, reverse or interrupt operation.

Britain takes a different route. The FCA relies on existing frameworks including the Senior Managers and Certification Regime (SM&CR) and Consumer Duty, rather than new AI-specific rules. Encouragingly, 84% of UK financial firms already report an accountable person for their AI framework. Agentic AI should push this further. Every significant agent needs a named human owner, explicit authority boundaries and an effective emergency kill switch.

The New Frontier of Agentic AI Risk

An AI agent with credentials, API access, databases and payment authority is no longer merely clever software. It starts to resemble a privileged digital employee, except one capable of acting at machine speed. That creates a new attack surface. Prompt injection could manipulate an agent into revealing data or using a connected tool improperly, while stolen credentials, excessive permissions or compromised third-party services could turn autonomy into autonomous fraud.

This makes machine identity governance a board-level issue. If a bank deploys thousands of agents, each may need an authenticated identity, permissions, transaction limits and audit trail. In effect, an agent needs the digital equivalent of an employee badge, job description and delegated authority schedule.

DORA provides part of the governance architecture, requiring EU financial entities to manage ICT risk and assess third-party and concentration dependencies. More ominously, the EBA warned in June 2026 that frontier AI models have greatly enhanced capabilities to discover and exploit software vulnerabilities. Agentic finance therefore demands more than model controls. Institutions must govern what each machine is authorised to touch, trust and do.

Can Autonomous Finance Remain Fair, Explainable and Trustworthy?

Imagine your personal AI agent negotiating a mortgage with your bank’s AI agent. Which machine is protecting your interests, and who answers when the outcome causes harm? As agents enter lending, insurance, investments, debt management and payments, familiar conduct risks acquire an autonomous dimension. Hyper-personalisation could improve financial choices, but it could also become manipulation, particularly for vulnerable customers.

This is approaching quickly. The FCA’s July 2026 Mills Review found that one fifth of consumers, equivalent to 11 million UK adults, are likely to use AI capable of acting autonomously within pre-set goals. That creates a new challenge where firms may increasingly serve not customers directly, but AI intermediaries representing them.

Transparency therefore matters. Since 2 August 2026, Article 50 of the EU AI Act requires, subject to specified exceptions, people to be informed when they are interacting directly with AI. Yet disclosure alone cannot guarantee fairness. Financial institutions will need understandable explanations, accessible human escalation and mechanisms for challenging autonomous outcomes. The deceptively simple governance test is can a customer appeal against an agent?

Governing the Machine Economy

Tomorrow’s financial system may involve not one AI agent, but networks of them, potentially customer agents negotiating with bank, merchant, payment, compliance and market agents. Governance then becomes less about controlling models and more about managing interactions between autonomous systems owned by different organisations.

Agent-to-agent payments illustrate the challenge. A purchasing agent might select a product, instruct a payment agent and trigger fraud and compliance agents within seconds. One faulty instruction could cascade across the network before supervisors know it happened. The UK’s Financial Services AI Adoption Plan recognises this frontier, making “agentic payments readiness” a priority and calling for a trust framework covering liability and consumer protection.

This demands machine-speed governance with continuous monitoring, real-time controls and automated escalation capable of matching autonomy. Concentration risk also matters when many institutions depend upon the same AI or cloud providers. The EU can draw on the AI Act and DORA, while the FCA is experimenting through AI Live Testing and its Supercharged Sandbox, including safer agent-led payments. Tomorrow’s question is bigger: are regulators governing AI systems today, when they may soon need to govern AI economies?

The Winners Will Govern Autonomy, Not Just Artificial Intelligence

The winners in agentic finance will not necessarily deploy the most agents. They will know precisely how much freedom to give them, and when to take it back. Governance must therefore evolve from model governance to agent governance, access control to machine identity, human approval to meaningful intervention, and periodic monitoring to continuous assurance. The UK’s 2026 Financial Services AI Adoption Plan already proposes “Know Your Agent” protocols for autonomous payments, signalling how quickly governance is changing. Boards should now ask not simply, “Where are we using AI?” but “Where have we delegated authority to AI, how far does that authority extend, and how quickly can we reclaim it?”

And what about you…?

  • If an AI agent made a damaging financial decision tomorrow, could you identify exactly which human was accountable for its actions?
  • What limits should your organisation place on what AI agents can access, decide, communicate, purchase or transact without human approval?