When AI Agents Become Bank Employees: Who Is Responsible for Their Decisions?
Artificial intelligence is moving beyond supporting financial professionals to performing tasks on their behalf. As banks introduce autonomous AI agents into their operations, the question is no longer simply whether the technology works. It is whether financial institutions can maintain accountability when software begins making and executing decisions.
AI in banking: from digital assistants to autonomous colleagues
For years, artificial intelligence in banking largely operated within clearly defined boundaries. Algorithms assessed credit applications, identified potentially fraudulent transactions and supported customer service representatives. Even when these systems influenced important decisions, their responsibilities were generally limited to a particular task.
Generative AI expanded these capabilities by allowing employees to interact with technology through natural language. A relationship manager could ask an AI assistant to summarise a client's financial history. A compliance officer could use it to review documentation. A customer service representative could generate a response to a complex inquiry. Agentic AI introduces a different operating model.
Rather than simply responding to individual instructions, an AI agent can pursue a defined objective, determine intermediate steps, interact with multiple systems and execute actions with varying degrees of autonomy.
Consider a corporate banking customer requesting an increase to an existing credit facility.
An AI assistant might summarise the customer's financial statements and prepare a preliminary recommendation. An autonomous agent could potentially go further, retrieving relevant information from internal systems, requesting missing documentation, initiating risk assessments and preparing the application for approval. Depending on its permissions, it might also communicate directly with the customer or initiate downstream processes. The distinction matters because the technology is no longer confined to generating information. It becomes an active participant in the bank's operational processes.
And once AI systems begin performing work previously assigned to employees, familiar questions about responsibility, authority and oversight become considerably more complicated.
A new supervisory challenge for European banking
The growing importance of AI in financial services is attracting increasing attention from central banks and supervisory authorities. In a speech delivered on 18 September 2026, Fernando Restoy, Chair of the Financial Stability Institute at the Bank for International Settlements, examined how artificial intelligence is changing both banking operations and the supervisory frameworks designed to oversee them.
His analysis addressed the use of AI in creditworthiness assessments, fraud detection, compliance and risk management, as well as the limitations of existing model risk management approaches when applied to advanced AI systems.
The underlying supervisory challenge is that frameworks originally developed for relatively transparent statistical models may not adequately capture the behaviour of more complex AI systems.
This topic becomes particularly relevant when an AI agent can independently select tools, retrieve information, and execute multiple actions.
Traditional model validation typically evaluates whether a model performs a defined task accurately and reliably.
For an autonomous agent, that assessment may be insufficient.
The individual outputs of an AI system might appear reasonable while the sequence of actions it undertakes creates an entirely different risk.
An agent responsible for processing customer complaints, for example, might correctly identify the nature of a complaint but retrieve information from an inappropriate customer account, communicate an unapproved resolution or initiate a transaction outside its authorised scope.
The risk is not necessarily an incorrect prediction. It may be an inappropriate action.
Financial institutions therefore need to consider how their existing risk management and internal control frameworks apply to systems that can make operational decisions rather than merely support them.
The accountability problem: Who is responsible when an AI agent acts?
Imagine a bank deploying an AI agent to support payment investigations.
The agent is authorised to retrieve transaction records, communicate with internal teams and prepare customer responses. During an investigation, it incorrectly interprets a transaction record and sends confidential information to an unauthorised recipient.
Who is responsible?
The technology provider developed the underlying model. The bank's IT department integrated it into the existing infrastructure. The business unit defined its operational objectives. A third-party provider may host the system, while the agent itself selected the action that resulted in the disclosure.
From a legal and organisational perspective, however, deploying autonomous technology does not make the institution's existing responsibilities disappear.
The bank must still establish appropriate governance, comply with applicable data protection and financial services requirements, and maintain effective oversight of its operations.
This requires a distinction between technical execution and organisational accountability.
An AI agent may execute an action, but the institution must determine who is authorised to delegate that action, who monitors the agent's performance and who can intervene when its behaviour deviates from the intended process.
In practical terms, every production AI agent should have an identifiable business owner, a defined operational purpose and a documented scope of authority.
These arrangements should be supported by technical controls rather than relying exclusively on written policies.
A system authorised to investigate payment discrepancies, for instance, should not automatically receive permission to initiate unrestricted payments merely because both activities involve the same transaction infrastructure.
The principle is familiar from conventional banking operations: employees receive permissions appropriate to their responsibilities.
AI agents require a comparable approach, adapted to the fact that their behaviour may be less predictable than that of conventional software.
Digital identities and the emergence of machine permissions
One of the less visible consequences of agentic AI is the need to reconsider identity and access management.
Financial institutions have spent decades developing procedures for granting employees access to sensitive systems. These include role-based permissions, segregation of duties, authentication requirements and periodic access reviews.
Autonomous AI agents introduce a new category of operational identity.
An agent might require access to customer relationship management software, transaction databases, internal knowledge repositories and external service providers to complete a single task.
If all these permissions are granted permanently, the institution risks creating an automated user with access far beyond what is necessary for any individual operation.
This creates a particular challenge when agents can invoke other agents or external tools.
An apparently harmless request could initiate a chain of actions involving several systems, each operating under different permissions and security assumptions.
A more controlled architecture would assign permissions according to the agent's specific function, restrict access to necessary data and require additional authorisation before sensitive actions are executed.
For example, an agent might be permitted to prepare a payment instruction but require human approval before the payment is released.
The same distinction could apply to changes in customer data, modifications to credit limits or the disclosure of confidential information.
The important question is not whether an AI agent should have access to banking systems.
It is how the institution can ensure that the agent exercises only the authority necessary to complete its assigned task.
When one compromised agent becomes an operational risk
The security implications extend beyond access management.
On 9 September 2026, the Bank for International Settlements published an analysis of how frontier AI models are changing the cyber threat landscape for financial institutions.
The paper describes how advanced models can support increasingly sophisticated cyber operations, including vulnerability discovery and multi-step attacks. It also identifies potential defensive benefits, such as faster threat detection and incident response.
For financial institutions, the analysis highlights the importance of shorter remediation windows and the amplification of risks through third-party dependencies.
Autonomous agents can introduce additional attack surfaces because they process external information and interact with operational systems.
Consider a customer service agent that retrieves documents from a shared repository.
If an attacker can insert malicious instructions into a document, the agent might interpret those instructions as part of its operational task rather than as untrusted content.
This technique, commonly known as prompt injection, illustrates a fundamental difference between conventional software and language-model-based systems.
The agent must distinguish between information it is supposed to analyse and instructions it is authorised to follow.
A document containing customer information should not be able to redefine the agent's permissions or instruct it to transfer data to an external destination.
Financial institutions therefore need safeguards at several levels, including the validation of external content, restrictions on tool execution, monitoring of agent behaviour and technical separation between data and authoritative instructions.
For sensitive processes, the ability to suspend an agent immediately may be as important as the ability to deploy it.
Human oversight must be designed into the process
The introduction of autonomous AI frequently leads to a familiar assurance: a human will remain in the loop. The statement sounds reassuring, but its practical meaning is often unclear.
Does a human review every action before execution? Does an employee approve only decisions exceeding a particular threshold? Or does the institution rely on retrospective monitoring after the agent has completed its work?
These arrangements provide different levels of control.
A human reviewer who receives hundreds of AI-generated decisions each day may have limited capacity to evaluate them independently. Equally, requiring manual approval for every low-risk administrative task could eliminate much of the efficiency gained through automation.
The appropriate oversight model therefore depends on the nature of the activity, the potential consequences of an error and the agent's degree of autonomy.
For a low-risk internal documentation task, retrospective sampling and monitoring may be proportionate.
For a decision involving a customer's access to credit, sensitive personal information or the movement of funds, more substantial controls may be necessary.
Importantly, human oversight should not be reduced to the presence of an approval button.
The reviewer needs sufficient information to understand what the agent has done, which information it relied upon and why a particular action is being proposed.
Without that context, approval risks becoming a procedural formality rather than a meaningful control.
The challenge of governing systems that change
Traditional banking software is generally developed, tested and released through controlled change management processes. An AI agent may behave differently even when its underlying software has not changed.
Its outputs can vary according to the information it receives, the tools available to it, the context of a particular interaction and changes to the underlying model.
A third-party model provider might also release an update that affects the agent's behaviour.
Consequently, an agent that performed reliably during initial testing may encounter situations in production that were not anticipated during development.
This makes continuous monitoring particularly important.
Financial institutions should be able to reconstruct the sequence of actions undertaken by an agent, identify the systems it accessed and determine whether it operated within its authorised boundaries.
They also need procedures for evaluating changes to models, prompts, connected tools and operational permissions.
A modification that appears minor from a software development perspective may materially alter the risk profile of the overall system.
For example, connecting an existing customer service agent to a payment execution interface changes the nature of its responsibilities even if the underlying AI model remains identical. Governance must therefore address the entire operational system, not simply the model at its centre.
What this means for banks and financial technology providers
The transition towards autonomous AI creates opportunities to redesign processes that have traditionally required substantial manual coordination.
Customer onboarding, payment investigations, regulatory reporting, compliance monitoring and internal knowledge management all contain activities that could benefit from more capable automation.
However, the commercial value of these applications depends on the institution's ability to operate them reliably.
A bank that cannot explain an agent's permissions, reconstruct its actions or suspend its access during an incident may struggle to deploy the technology in sensitive environments.
Technology providers face a related challenge.
Financial institutions will increasingly need to understand not only what an AI solution can achieve, but also how it can be integrated into existing governance, security and operational risk frameworks.
This creates demand for solutions that provide meaningful audit trails, configurable permissions, human approval mechanisms, performance monitoring and clear responsibility boundaries.
The commercial opportunity is not limited to developing more capable AI models.
It also extends to building the infrastructure that allows organisations to use those models responsibly.
The next stage of banking automation
Autonomous AI could change how financial institutions organise work, allocate resources and deliver services.
But the most significant transformation may concern the relationship between technology and organisational responsibility.
Banks are accustomed to managing employees, conventional software and external service providers through established governance structures.
AI agents combine elements of all three.
They perform assigned tasks, operate through technical infrastructure and may depend on models and services supplied by external companies.
The challenge is to develop an operating model that accommodates these characteristics without creating uncertainty about accountability.
The financial institutions that succeed in doing so will be better positioned to introduce autonomous technology into processes where reliability, trust and control are essential.
The next question for banking executives is therefore not simply how many AI agents their organisation can deploy.
It is how much responsibility those agents can safely be given, and whether the institution has the operational infrastructure to remain in control.
FAQs
Who is responsible for decisions made by AI agents in banking?
Financial institutions remain responsible for meeting their applicable legal, regulatory and operational obligations when deploying autonomous AI agents. They must establish clear accountability, appropriate human oversight and effective controls over AI-driven processes.
What are the main risks of agentic AI in financial services?
Key risks include unauthorised actions, inappropriate access to sensitive data, inaccurate decisions, cybersecurity vulnerabilities, third-party dependencies and insufficient human oversight.
How can banks implement effective AI agent governance?
Banks can establish governance frameworks that define agent ownership, access permissions, operational boundaries, risk assessments, human approval requirements, continuous monitoring and incident management procedures.
How do the EU AI Act and DORA affect autonomous AI in banking?
The EU AI Act establishes requirements for AI systems according to their classification and intended use. DORA addresses ICT risk management, operational resilience and third-party technology dependencies. Financial institutions must assess which obligations apply to their specific AI applications.