An AI assistant may summarize information for a person. An AI agent can go further by choosing steps, calling systems or initiating an action within assigned permissions. That additional capability makes clear boundaries essential.

01

Start with a defined task and owner

A bank identifies the specific outcome the agent may pursue, the systems and data it may use, and the accountable business owner. A narrow role such as gathering documents presents different risks from changing an account, moving money or communicating a decision to a customer.

The use case is assessed under applicable technology, model, information-security, privacy, compliance and third-party frameworks. Calling software an agent does not remove the bank’s responsibility for the process it performs.

02

Identity and authority are separate questions

Systems need a reliable way to recognize which agent is making a request and who operates or authorized it. They also need to confirm that the identified agent may perform this particular action for this user, account and moment.

Credentials should be limited to the minimum access needed rather than reusing broad human or service accounts. Short-lived permissions and explicit purpose can reduce the harm if a credential or instruction is misused.

03

Limits constrain what the agent can do

Controls may restrict transaction amount, destination, frequency, product, data field, operating time or sequence of actions. Higher-risk activity can require fresh customer confirmation or approval by an authorized employee.

A human approval step is useful only when the reviewer receives enough context and has time and authority to challenge the recommendation. Repeatedly approving opaque actions can create the appearance of oversight without meaningful control.

04

The action and its intent must be recorded

An audit trail links the user or operator, agent identity, granted permission, relevant inputs, proposed action, approval and final result. This helps the bank investigate errors, disputes and attempts to manipulate the agent.

Sensitive reasoning data should not be retained without purpose. Logging needs to support accountability while following privacy, security and record-retention requirements.

05

Monitoring includes the ability to stop

Teams monitor unusual destinations, repeated failures, unexpected tool use, attempts to exceed limits and changes in outcomes. Tested suspension procedures should be able to revoke credentials, pause actions and route work to a person when risk rises.

Banks also reassess permissions as the agent, connected systems and customer behavior change. A safe boundary at launch may become too broad after new capabilities or integrations are added.

Sources

Read the primary material

Banking Explained prioritizes regulators, official publications and first-party announcements.