When AI can move money, Banks face a new governance challenge

By Gemma Rolfe Agentic Commerce
views

Artificial intelligence is already embedded across European banking. More than 85 per cent of banks supervised by European authorities now use AI, according to the European Central Bank. The next challenge, however, is considerably more complicated: what happens when those systems are given authority to act?

Envato Licenced

When AI Moves Money, Banks Face a New Challenge

For payments, the distinction is particularly important.

An AI system that identifies a suspicious transaction and alerts a fraud investigator is fundamentally different from an autonomous agent capable of stopping the payment, contacting the customer and triggering actions elsewhere within a bank.

The underlying intelligence may be identical. What has changed is the authority delegated to the machine.

From Model Risk to Machine Authority

Banks have spent decades developing governance around models, employees and payment systems. Models are validated; traders operate within limits; payment instructions above defined thresholds require additional approval.

Agentic AI introduces these disciplines to a new category of decision-maker.

Traditional model governance asks whether technology is accurate, explainable and performing as intended. Agentic systems require another question: even when the AI works correctly, what should it be allowed to do?

This concept of “machine authority” could become increasingly important as AI progresses from providing information to executing actions within financial infrastructure.

A treasury agent preparing a payment instruction, for example, creates very different exposure from one authorised to release £10mn autonomously.

Banks Need Limits for AI Agents

The principle is familiar from human governance. High-performing employees are not automatically given unlimited authority because their previous decisions proved correct.

AI should operate under similar constraints.

Banks will increasingly need explicit limits covering what decisions agents can make, which systems and data they can access, what actions they can execute and how much financial exposure they can create.

There is also the question of delegation. An AI agent capable of invoking another agent or downstream workflow could create chains of machine actions whose combined authority exceeds that originally intended.

The EBA has already warned that AI introduces operational, cyber, data, conduct, legal and third-party risks, while the ECB argues that AI resilience needs attention at management-body level.

Autonomy Is a Risk Decision

This becomes particularly important as banks move towards graduated autonomy.

An AI agent might initially observe transactions, then recommend actions, subsequently act with human approval and eventually operate independently.

Strong historical performance can justify considering greater autonomy. It cannot grant that autonomy automatically.

Increasing an agent’s permissions should instead resemble raising a delegated financial or operational risk limit: evidence must be considered alongside potential exposure, controls and accountability.

Circuit breakers, transaction thresholds, independent monitoring and the ability to withdraw permissions rapidly will become essential.

Keeping Risk Appetite in the Loop

This also moves the debate beyond the familiar concept of keeping a “human in the loop”.

Requiring manual approval for every low-risk machine action would undermine much of the economic value of agentic AI. Removing humans indiscriminately creates the opposite danger.

The more useful principle is keeping the bank’s risk appetite in the loop.

As AI gains the ability to block transactions, release payments and move money, boards will ultimately need to know not merely where AI is deployed, but how much authority has been delegated to it.

The banks that can answer that question may also be those best positioned to embrace greater automation.

The objective should not be to prevent machines acquiring autonomy. It should be to make that autonomy measurable, controllable and governable.

Comments

Post comment

No comments found for this post