logo

How much authority should banks give AI agents?

Add The Asian Banker on Google
Discover more trusted banking and financial services insights by adding The Asian Banker as a preferred source on Google.
How much authority should banks give AI agents?
  • 158

Lee Wan Sie, Cluster Director of AI Governance and Safety at Singapore’s IMDA says agentic AI brings greater autonomy because systems can act, not just generate information. Institutions, including banks must define the limits of that authority and how it is governed.

Generative artificial intelligence (AI) has largely raised questions about what a system produces. Agentic AI adds another dimension on what the system is authorised to do. A banking agent could collect information from several systems, update a customer record or prepare a payment instruction as it works towards an objective. Governance therefore shifts from evaluating AI-generated output to determining the authority given to systems that can act.

Lee Wan Sie, Cluster Director of AI Governance and Safety at Singapore’s Infocomm Media Development Authority (IMDA), said agentic systems differ from generative AI because "the agents can take action" and operate with "a lot more autonomy." Unlike generative AI, they can interact with systems inside and outside an organisation, extending governance beyond model outputs to the authority exercised through connected systems.

IMDA launched its Model AI Governance Framework for Agentic AI in January 2026 and updated it in May following industry feedback. The voluntary framework complements existing laws by providing risk-based guidance on governing agentic AI, including interactions with other agents, external services, human oversight and deployment controls.

An agent's operating limits define the systems, data and actions it may access, together with conditions requiring it to stop, seek approval or escalate. Banks therefore need to determine where an agent’s authority begins and ends, and whether the controls remain appropriate for each use case, guided by the risk-based approach set out in IMDA’s framework.

Delegated authority becomes the first control decision

As agents take on more tasks, Lee said banks must ensure humans remain responsible for overseeing them. “You must still make sure that the human at the end is accountable,” she said. For banks, that involves deciding what an agent may access, decide and execute without further approval.

A bank might allow an agent to prepare a payment instruction while reserving execution or higher-risk transactions for human approval. Such limits can separate the actions an agent performs independently from those requiring intervention.

Lee said organisations should start with the use case, estimate the value it could create and weigh that against the risks and controls required. Lower-risk internal activities may justify greater autonomy than deployments involving external systems or sensitive customer information. IMDA's framework therefore advocates calibrating controls to individual use cases rather than applying the same level of oversight across all deployments.

AI Verify provides one way to assess whether those controls are working as intended. Lee said the testing framework and software toolkit, launched by the AI Verify Foundation, a subsidiary of IMDA, enables organisations to evaluate systems against identified risks, governance principles and internal policies, providing evidence to support deployment decisions.

Testing does not automatically justify deployment. Lee said regulated institutions may still decide that tasks requiring a high degree of certainty should remain outside an agent’s mandate because the institution remains responsible for the financial and reputational consequences.

Human oversight shifts towards exceptions

Once an agent is allowed to act independently, another question is when human review is required. Lee said meaningful oversight does not require a person to approve every action, particularly when agents operate at scale. “It is not so much about a human in the loop, but human oversight.”

Human intervention can instead focus on decisions and exceptions. Lee cautioned that cognitive offloading and automation bias could leave employees less able to exercise judgement when intervention becomes necessary, raising the question of whether they remain equipped to challenge or override an agent.

Thresholds offer one way to trigger human intervention. Lee gave the example of an organisation allowing an agent to automatically approve low-value transactions while requiring human approval above a defined threshold. She cautioned that thresholds alone may not be enough, as large numbers of smaller transactions could create significant aggregate exposure. Organisations may therefore also need to monitor transaction volumes and patterns over time and flag unexpected behaviour for review.

Evidence becomes critical when agents act at scale

Where human oversight does not involve reviewing every action individually, records of what an agent did become particularly important after an error, disputed transaction or unexpected event. Banks may need to reconstruct why an agent acted, what authority it exercised, which controls applied and what ultimately happened. The process resembles establishing who initiated, approved and executed a banking transaction, except some participants may now be software agents.

Lee said no universal specification yet defines exactly what organisations should record for agentic systems, but highlighted traceability, monitoring and logging as essential. Existing frameworks recommend different approaches, leaving institutions to determine what evidence is appropriate for each deployment.

For example, the European Union’s (EU) AI Act requires high-risk AI systems to support automatic recording of events. The United States (US) National Institute of Standards and Technology's (NIST) AI Risk Management Framework Playbook identifies logging as one mechanism supporting auditability and the investigation of system errors. Neither framework prescribes a universal audit trail, leaving banks to determine the records needed to satisfy their legal, operational and governance requirements.

Automation can weaken the bank's fallback

Greater reliance on agents also raises business continuity questions. “What is your business continuity plan when the AI doesn’t function well?” she asked. She also raised the possibility of a service provider withdrawing access, saying organisations should consider what backup arrangements would be available in such circumstances.

Lee cited an example of an organisation where an outage forced employees to resume manual reconciliation, raising the question of whether they still retained the skills to do so. Sustained automation can erode manual capabilities, meaning banks may need to have both trained staff and alternative systems to support critical processes when automated workflows become unavailable.

The risk becomes greater where agents support critical banking processes. Banks may therefore need contingency arrangements if an agent, model, provider or supporting service becomes unavailable, with recovery plans reflecting the importance of the process and its dependencies.

External providers push control beyond the bank

Lee also noted that agents increasingly interact with other agents and external services, extending governance beyond a single AI system.

A bank can define the authority of its own agent without necessarily controlling every component on which it depends. The system might rely on a model supplied by one company, infrastructure supplied by another and external tools or services supplied by others.  Governance therefore extends beyond the bank's own technology and processes.

Lee described AI as “a complex ecosystem, supply chain” requiring “some kind of shared responsibility." She compared the challenge with cloud computing, where providers and enterprise customers have gradually established clearer divisions of responsibility. A similar allocation across the AI supply chain has yet to emerge.

Lee also stressed that outsourcing does not remove accountability. “If your agents end up being malicious to somebody else’s system, the responsibility remains on the organisation,” she said. Providers may assume operational responsibilities, but banks remain accountable for how their agents are deployed and the authority they are given.

Singapore is building governance in layers

Lee said existing law remains the baseline of Singapore's approach, with organisations subject to the same legal obligations whether they use AI or not. Rather than creating a separate governance regime, Singapore uses different instruments for different aspects of AI governance.

Beyond existing law, the Monetary Authority of Singapore focuses on governance across the AI lifecycle and safeguards for agentic finance, while IMDA's Model AI Governance Framework provides broader guidance on risk, accountability and technical controls. AI Verify complements these by providing a way to test whether those controls work as intended.

These instruments create a layered governance approach in which legal obligations establish the baseline, governance frameworks guide implementation and testing provides evidence that controls are operating as intended.

Cross-border regulation changes the conditions for control

The control problem extends beyond Singapore because jurisdictions use different approaches to govern similar AI risks. The EU’s AI Act creates binding, risk-based requirements, while the US NIST AI Risk Management Framework remains voluntary. South Korea and Vietnam have also introduced statutory AI laws, meaning banks may encounter legal requirements in one market and voluntary guidance in another when deploying similar systems.

Asia itself contains several regulatory models. Japan has adopted legislation focused on promoting AI while addressing governance through national policy, India relies on principle-based AI governance guidelines, and ASEAN continues to promote voluntary regional guidance. Regional banks therefore cannot assume that compliance with one framework satisfies the legal requirements of another jurisdiction.

Lee said jurisdictions often pursue similar governance outcomes, such as transparency, testing and risk assessment, even where legal requirements differ. Banks can therefore apply common internal principles for delegated authority and human oversight while adapting documentation and controls to local regulatory requirements.

The same distinction applies to evidence and accountability. Banks may establish common expectations for logging, testing, escalation and provider management across their operations, while individual jurisdictions determine whether those practices are voluntary, required by law or subject to specific regulatory thresholds. Institutions therefore must distinguish controls that manage underlying agentic risks from obligations imposed by each legal regime.

Regional banks need controls that travel across markets

Lee said complete regulatory uniformity is unrealistic because jurisdictions will continue to develop AI governance according to domestic needs. Governments are using different combinations of legislation, voluntary frameworks, standards and testing to address overlapping concerns. Regional institutions therefore need internal controls that operate across regulatory systems that may never converge fully.

Singapore has pursued interoperability with regulatory counterparts. Lee said Singapore has worked to make AI Verify interoperable with the US NIST AI Risk Management Framework, helping organisations identify where the frameworks use different terms for similar concepts and where substantive differences remain.

Lee said such crosswalks can make implementation easier for organisations operating across markets. Regional banks can maintain common approaches to authority, human oversight, testing, traceability and provider management while adapting them to local requirements. Jurisdiction-specific rules can then determine where additional restrictions, evidence or documentation are needed.

The challenge becomes more pronounced when banks deploy agents across jurisdictions using different legal and regulatory approaches. A common control architecture could define what an agent may access or execute, when human intervention is required and what evidence the bank retains, while local requirements determine where those controls must be adapted. Such an approach allows banks to govern delegated authority consistently without assuming that compliance in one jurisdiction establishes compliance in another.

Banks will have to govern authority as it evolves

Lee’s final advice was that organisations’ AI implementations “cannot be static.” As models become more capable and patterns of use change, organisations need to adapt their deployments accordingly. Even where a system's purpose remains unchanged, shifts in capability or usage can alter its risk profile.

The same principle applies to delegated authority. Improvements in an agent’s capability or changes in its usage may require banks to reassess permissions, controls, testing and accountability. Institutions may then choose to increase autonomy, tighten boundaries or keep certain activities outside an agent's mandate according to the risks involved.

The question is therefore not only how much authority an agent receives at deployment, but whether that authority remains appropriate as the system evolves.

Chat with us WhatsApp