Key facts
- AI agents are increasingly capable of acting on behalf of consumers, posing new challenges for mortgage servicers.
- Existing authentication processes, designed for human interaction, are insufficient for AI agents.
- A key concern is that AI agents can degrade in performance over time without notice, unlike human representatives.
- Three distinct questions arise: disclosure (AI must identify itself), authentication (is the agent authorized?), and ongoing fitness (is the agent still capable?).
- Servicers are advised to default to caution, routing suspected AI interactions to live representatives and establishing clear policies for agent evaluation.
- The industry lacks robust mechanisms to authenticate customer-authorized AI agents and monitor their ongoing fitness.
The mortgage servicing industry is facing a significant challenge as artificial intelligence agents become increasingly capable of acting on behalf of consumers, a development that current authentication and oversight frameworks are not equipped to handle.
While it is not yet common for a customer's AI agent to initiate calls or act on their behalf in mortgage servicing, the infrastructure for this is rapidly developing. An IMF staff note highlighted that agentic AI is already influencing payment decisions, and a 2026 Cloud Security Alliance survey indicated that 85% of financial services respondents anticipate AI agents initiating payments for consumers. This trend necessitates proactive policy development to set standards rather than react to issues after they arise.
The author, Anwar Ali, SVP, Head of Product Management at BSI Financial Services, draws on personal experience with a customer-facing AI system that degraded in quality unnoticed. This led to the realization that if an organization's own AI can worsen without detection, confidence in external AI agents representing customers is even lower.
Existing authentication methods, which rely on verifying human identity through personal information, are insufficient when the caller might be an AI. Unlike human representatives, AI agents can silently degrade in performance over time, a risk not addressed by current human-centric verification protocols. This necessitates a new framework that goes beyond simple authentication.
Ali proposes splitting the concept of "AI agent trust" into three distinct questions: disclosure, authentication, and ongoing fitness. Disclosure requires AI agents to clearly identify themselves as non-human. Authentication ensures the agent is specifically authorized by the customer, a capability that payment networks like Visa and Mastercard are beginning to build but is not yet available for loan servicing. The overlooked question of ongoing fitness addresses whether the agent, even if initially authorized, remains capable of representing the customer's interests, a concern highlighted by the risk of 'model drift'.
The asymmetry in accountability between servicers' own AI systems and customers' external AI agents is another key issue. Servicers have direct oversight and legal responsibility for their systems, whereas consumers typically do not have the same level of governance or accountability for their agents. This distinction is crucial, especially when AI agents are involved in mission-critical tasks like negotiating loan modifications.
While documented instances of customer AI agents negotiating loan modifications are not yet prevalent, adjacent developments in banking and payment networks, along with regulatory discussions, point towards this future. A Forrester survey indicated that only about 24% of US online adults trust an agent to act on their behalf for routine purchases, and regulations like PSD2 in the EU require explicit human authorization for payment orders.
Ali suggests that until reliable methods for authenticating and monitoring AI agents emerge, servicers should exercise caution. This includes routing suspected AI interactions to live representatives and establishing clear policies for identifying, authenticating, and evaluating these agents to ensure they remain capable of acting in the borrower's best interest. These policies should be integrated into AI, IT, or customer care governance structures as a practical bridge to developing industry-wide standards.
