Key facts
- Agentic AI introduces end-to-end autonomous processes with faster decisions and complex failure modes.
- Banks should extend existing AI risk management frameworks to cover agent-specific capabilities.
- Disclosure when customers interact with automated agents rather than humans is becoming a regulatory expectation.
- Unique agent IDs, output tagging, and immutable tool-use logs are needed for audit trails.
- Cybersecurity protocols should include controls for invocation limits on external tools and continuous permission checks.
- Defined roles like agent owner, validator, and steward are necessary for agentic AI governance.
Banks are increasingly exposed to new risks as artificial intelligence agents move from experimentation to deployment, according to Deloitte Insights. These agentic AI systems operate with greater independence, making faster decisions and taking autonomous actions, which complicates traditional risk management.
To address these evolving dynamics, banks are advised to adapt and extend their existing AI governance and risk frameworks rather than starting from scratch. Key recommendations include expanding risk taxonomies to include agent-specific capabilities such as tool misuse, action validity, and outcome monitoring. Banks should also maintain agent registries with metadata, risk scores, and controls to manage deployment approvals and permissible actions.
Anticipating regulatory expectations, banks are encouraged to design for disclosure by default. This involves implementing user-facing notices when customers interact with automated agents and maintaining audit-ready records. Transparent and traceable agent identity and logging are crucial, treating agents similarly to human employees with unique IDs, output tagging, and immutable logs to ensure a clear audit trail for every decision.
