Businessman using video conferencing screen

How governed intelligence can scale agentic banking

The next banking advantage won’t come from isolated AI use cases, but from embedding governed intelligence in core processes and decisions.


In brief:
  • AI in banking is moving from isolated pilots to redesigning end-to-end processes, where value comes from embedding intelligence into core operations.
  • The focus is on governed intelligence, using orchestrated, seasoned agents within clear controls, accountability and human oversight.
  • Winning banks will redesign work, build strong data and governance foundations, and prove AI-driven decisions are measurable, controlled and trusted.

    Co-author of the article: Dr. Kostis Chlouverakis

    Artificial intelligence (AI) is changing industries by moving beyond standalone tools and becoming embedded into the work itself. In banking, that means AI is moving from experimentation at the edge of the organization to the redesign of processes that create value: onboarding, lending, servicing, fraud, financial crime, collections, treasury, finance, risk, compliance and relationship management.

    Many banks have already learned a hard lesson. Individual AI use cases can help, but they rarely change enterprise economics on their own. A local AI assistant, workflow automation or proof of concept may improve one team's productivity, but return on investment (ROI) is hard to measure, scale and sustain if the surrounding process remains unchanged. EY banking research points to the same gap: The challenge is to move beyond pilots and turn experimentation into scaled performance, with business ownership, ROI discipline, governance and workforce adoption designed into the operating model.1,2

    Ready to move from AI pilots to measurable business value?

    Connect with our team to explore how governed intelligence can help scale AI with confidence across your organisation.

    The next phase focuses on a different set of questions: which processes should be redesigned, which decisions can be safely assisted or automated, which controls need to become executable, and which delivery model allows AI to become part of how the bank runs.

    A 2024 joint survey of AI in UK financial services by the Bank of England and the Financial Conduct Authority found that 75% of firms were already using AI, with a further 10% planning to use it within three years. Foundation models represented 17% of reported AI use cases. Yet fully autonomous decision-making represented only 2%, while 55% involved some degree of automated decision-making.3 The lesson is clear: Adoption is accelerating, but autonomy remains bounded.

    Across markets, supervisory expectations are converging around the same design challenge. Banks can innovate with AI, but accountability, explainability, privacy, fair outcomes, operational resilience and human oversight must be designed into the operating model. BIS analysis frames AI risk as an extension of familiar financial sector risks. NIST's AI Risk Management Framework and Generative AI Profile add a practical risk management lens, while ISO/IEC 42001 provides a management system approach for governing AI risks and opportunities.4, 5, 6

     

    The winning banks will set themselves apart by moving beyond pilots, large model estates and bold automation slogans to redesigning work, orchestrating seasoned agents safely, choosing delivery models that fit their scale and maturity, and proving that AI-assisted decisions are controlled, measurable and can be trusted.
     

    1. From use cases to process economics

    The use case era was necessary. It helped banks learn where AI works, where data is weak, where controls need to adapt and where colleagues will actually use new tools. But it also created fragmentation such as scattered pilots, duplicated platforms, inconsistent governance, and unclear ownership and benefits that are hard to connect to the bank's economics.

     

    Use cases remain useful, but value compounds when AI is applied systematically to whole processes. At a use case level, returns can be hard to show; in banking, the real unit of value is usually the process or journey: onboarding a client, approving a loan, resolving a dispute, investigating an alert, servicing a vulnerable customer, preparing a credit review or managing a collections path. The 2025 EY banking AI research makes a similar point: 52% of banks had piloted agentic AI but only 16% had fully deployed use cases.1

     

    This changes the business case. Banks should measure AI against process outcomes such as cycle time, cost to serve, rework, error rates, control effectiveness, straight-through processing, case backlog, false positives, capacity release, customer experience, colleague adoption and risk outcomes.

    AI creates value when it changes the shape of work: embedding intelligence into the process, not placing a tool beside the process.
     

    2. Agentify the process, not the whole bank at once

    Agentic AI is an important development in banking and also one of the easiest to overstate. The credible banking model is a governed network of seasoned mini agents that support defined steps within a process, instead of one mega agent running the entire process.

     

    In this article, to agentify a process means redesigning it so that bounded, seasoned AI agents can assist or execute specific tasks under an orchestration layer. That layer coordinates handoffs, permissions, tool access, policy rules, escalation points, human approvals, monitoring and evidence capture.

     

    A client onboarding journey, for example, could include a document collection agent, identity verification agent, adverse media agent, policy interpretation agent, exception triage agent, relationship manager AI assistant and quality assurance agent. None owns the whole process. The orchestration layer makes them work together within the bank's controls.

     

    The same pattern applies across lending, fraud, disputes, financial crime and servicing. Mini agents can retrieve evidence, extract information, interpret policies, draft communications, prepare analyst summaries, route exceptions and trigger human review where risk is material.

     

    This is controlled autonomy, not unchecked autonomy. Rather than outsourcing accountability to an AI system, the bank decomposes work into governed components and decides, by process step, what can be suggested, executed, escalated, blocked or approved by a human.

     

    3. The intelligence architecture banks need

    The future AI-enabled bank should be understood as a layered operating capability that connects process design, trusted data, knowledge, orchestration, network intelligence, simulation and governance evidence — moving beyond a collection of pilots, AI assistants or vendor tools.

     

    Capability and what it enables in banking

    This architecture separates common intelligence foundations from delivery choices. A bank may operate an AI factory, a federated platform, embedded domain teams or a hybrid model. In all cases, the core requirements remain: trusted data, grounded knowledge, bounded action, simulation and evidence.

    Banks do not need to build every capability at once. They need to stop treating AI as a series of experiments and start treating it as a managed operating capability.

    4. Delivery model: one size will not fit all

    The choice of delivery model will reflect the bank's history and maturity, its current operating model and, critically, its culture. A banking AI factory is a powerful concept, but it should not be presented as the only answer. It is a delivery model and often a useful one. For some banks, especially smaller or less mature institutions, a central AI factory can create focus, scarce skill leverage, consistent governance and a repeatable path from idea to production.2, 7

     

    For larger or more complex banks, however, AI capability may not sit only in one place. It may need to be dispersed into businesses, functions, regions and process ownership structures. Process owners need to understand the delivery model, the data dependencies, the controls, the value case and the operational changes required to make AI work in the real process.

     

    The practical design principle is simple: Centralize what must be consistent and embed what must be close to the work. The 2026 EY banking AI strategy work frames this as balancing reusable core platforms and standards with business-led innovation and clear decision rights.2

    Model

    Where it fits best

    What to watch

    Central AI factory

    Smaller or mid-sized banks; early maturity; consolidation of effort across silos; scarce experienced talent; need for standardized delivery

    Can become a bottleneck if every use case depends on one central team

    Hub-and-spoke

    Central standards and platforms with delivery capacity in business lines or regions

    Requires clear decision rights between the hub, spokes, risk, technology and business owners

    Embedded process teams

    Value depends on redesigning specific journeys such as onboarding, lending or servicing

    Can fragment controls unless common platforms, patterns and assurance are enforced

    Platform product model

    Mature engineering and reusable AI, data, orchestration, monitoring and evidence services

    Requires product ownership, funding discipline and adoption by process teams

    Partner-augmented model

    Speed, seasoned skills or vendor ecosystems while building internal capability

    Needs strong third-party risk management, IP clarity, data controls and exit plans

    The AI factory therefore remains important, but it should be described as one operating pattern rather than the operating model. The choice of model may change over time as the organization's maturity and needs evolve. In a large universal bank, the future is more likely to be a governed network of common platforms, reusable components, embedded process teams and central assurance. Global capability centers can also become part of this model where banks need talent scale, engineering depth and governance capacity to industrialize AI across the enterprise.2, 7

    This is where the human operating model becomes the multiplier. The EY workforce perspective for banking frames the future as tech powered and people driven.8 The real operating model question is how humans and agents will share the work, not simply whether AI can do it. In banking, this means redesigning roles, controls, decision rights and escalation paths around AI-enabled processes. Process owners must understand the technology, while monitoring how work changes, where judgement remains human, how colleagues build trust in AI outputs and how benefits are captured. The next frontier is therefore not autonomous banking; it is human-agent banking by design.

    5. From AI assistants to bounded agents

    The immediate role of generative AI (GenAI) in banking remains as a grounded knowledge and workflow layer. Banks run on policies, procedures, product manuals, credit files, legal opinions, compliance guidance, call transcripts, audit findings and operational playbooks. GenAI can make this institutional knowledge searchable, conversational and actionable.

    But banking GenAI cannot rely on generic prompting alone. It needs role-based access control, approved sources, retrieval testing, hallucination evaluation, data leakage controls, prompt governance and escalation paths. These controls are consistent with emerging GenAI security guidance on risks such as prompt injection, supply chain vulnerabilities, sensitive information disclosure and excessive agency, especially where agents can call tools or act across systems.9 The future knowledge layer will be a portfolio of grounded, seasoned and monitored services embedded into workflows, not a single giant chatbot.

    A practical autonomy ladder helps separate ambition from hype:

    Level

    Role of AI

    Banking examples

    Level 1: AI assistant

    Suggests, drafts and summarizes

    Policy Q&A, relationship manager support, call summaries

    Level 2: Workflow assistant

    Executes low-risk tasks with approval

    Document collection, case routing, data checks

    Level 3: Bounded agent

    Executes within pre-approved limits

    KYC triage, dispute preparation, card replacement

    Level 4: Supervised orchestrator

    Coordinates multiple agents and systems

    Onboarding, collections, fraud case management

    Level 5: Autonomous decisioning

    Makes material decisions independently

    Rare, tightly controlled and regulator sensitive

    Serious banking investment should generally be placed around Levels 2 to 4. These are the high-value zones where AI can reduce friction, improve consistency and compress cycle times while maintaining human accountability.

    6. Context-aware banking, not surveillance banking

    A process-led AI agenda should improve efficiency while also strengthening customer relevance, advice, protection and trust. AI in banking is often described as hyper-personalization: the ability to offer the right product, message or action to the right customer at the right time. That remains important, but it is no longer enough.

    The next evolution is multi-context banking. Experiences can adapt to who the customer is as well as where, when and why they engage. A customer's financial context, channel, intent, life event, vulnerability indicators, liquidity position, risk appetite and macroeconomic environment may all influence the advice, warning, product or next best action they receive.

    The commercial upside is significant: more timely advice, better vulnerability support, more relevant small-business cashflow alerts and stronger relationship manager prompts. But this must be governed carefully. Multi-context personalization can cross into intrusive surveillance if consent, transparency, data minimization and vulnerability safeguards are not clear. The responsible ambition is context-aware banking, not surveillance banking. That will require a clear bargain with customers about how their data is used safely, transparently and with appropriate safeguards.

    7. Truth, networks and synthetic rehearsal

    Agentic AI creates a hidden dependency: the bank's data architecture. A model may be powerful, but if it operates on stale batch data, incomplete customer records, disconnected product systems, inconsistent consent flags or fragmented fraud signals, it can make the wrong recommendation with confidence.

    This is why banks need a real-time banking truth layer: a governed, current and permissioned view of customer identity, account holdings, transactions, channel interactions, fraud and scam signals, credit and risk status, consent, complaints, vulnerability flags, operational case status and regulatory restrictions. Without it, agents act on assumptions. With it, they act on a verified view of the bank.

    Many banking risks are also network risks. A borrower is connected to suppliers, sectors and payment flows. A fraudster is connected to devices, IP addresses, merchants, mule accounts and counterparties. Graph intelligence shifts the lens from isolated scoring to structural intelligence, supporting AML network detection, sanctions evasion mapping, beneficial ownership risk, fraud ring detection and supply chain contagion.

    A related opportunity is privacy-preserving and consortium AI. Fraud, scams and mule networks do not stop at one institution, but raw customer data cannot simply be pooled across banks. Federated learning, differential privacy, secure multiparty computation, homomorphic encryption and confidential computing may allow institutions to learn across boundaries while reducing data exposure. Recent federated learning research for cross-institution financial fraud detection illustrates both the promise and the privacy, integrity and governance tradeoffs.10 The hard part will be governance: common definitions, liability, validation, security protocols, incentives and supervisory comfort.

    Synthetic data should also be reframed as rehearsal, not just privacy protection. A synthetic bank is a controlled digital twin of banking activity where new products, credit strategies, fraud controls, servicing journeys, pricing policies, collections approaches and agentic workflows can be tested before deployment. Industry momentum around synthetic data, including Nvidia’s reported acquisition of Gretel and broader investment in synthetic data generation, shows how synthetic data is becoming a mainstream AI development, training and privacy-preserving experimentation capability.11 Banks should treat synthetic data as a governed rehearsal environment where quality, privacy and validation still need to be managed carefully, rather than simply as “fake data”.12 It helps banks test rare scenarios, tail risks, vulnerable-customer journeys, fairness outcomes and operational edge cases before real customers are exposed. The strategic question becomes: Can we safely test the future before it happens?

    Explore what's next for AI in banking

    AI success depends on more than technology alone. Talk to our professionals about building the governance, operating model and capabilities needed to scale AI responsibly and effectively.

    8. Governance-as-code and the AI decision flight recorder

    As AI becomes embedded in banking decisions, institutions will need to prove what happened, why it happened, what data was used, which model or prompt was active, which sources were retrieved, which policy constraints were applied, whether a human approved the action and how the output was monitored after deployment.

    This points toward an AI decision flight recorder or AI control ledger. It should capture use case risk tier, model version, prompt version, tool calls, retrieved sources, input data lineage, decision path, confidence and uncertainty signals, human approval or override, policy constraints, monitoring results, issues, remediation and audit evidence.

    Governance-as-code takes this further by embedding policy rules, approval gates, validation metrics, monitoring thresholds and evidence capture directly into AI workflows. In a bank, responsible AI needs to move from committees, principles and documents into executable controls, especially when mini agents are acting across systems, handoffs and customer journeys. The EY Responsible AI Pulse similarly links real-time monitoring and oversight with stronger returns and fewer risks, reinforcing the need to make governance operational rather than retrospective.13

    This aligns with the movement toward formal AI management systems. ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an artificial intelligence management system.6 For banks, the implication is clear: Responsible AI must be auditable by design, not reconstructed after the fact. A bank cannot simply say an AI system is governed. It must be able to prove it.

    9. Frontier signals without distraction

    One reason AI strategies become confusing is that they mix near-term delivery, emerging capabilities and frontier research into one agenda. Banks need all three, but they should manage them differently. The near-term agenda is grounded GenAI, workflow assistants, trusted data, delivery model design, human oversight and resilience-ready controls. The next agenda is bounded agents, orchestration layers, graph intelligence, synthetic bank environments, privacy-preserving collaboration and decision evidence. Frontier topics should be monitored with discipline, not allowed to distract from execution.

    Post-quantum cryptography is a good example. NIST released its first three finalized post-quantum encryption standards in 2024.14 For banks, this is a resilience planning issue, not a speculative AI use case. Other signals, such as tokenization-enabled programmable finance, quantum enhancement and sustainable AI, should be evaluated through the same lens: Prepare for capabilities that could change resilience, trust, cost or competitive advantage, without overstating production maturity.

    10. Six moves for banks now

    The practical agenda is to build an operating model that allows AI to scale with value and control, instead of chasing every new AI concept. Six moves that matter to banks are as follows:

    1. Map AI to process value pools: Identify the journeys where AI can change process economics, not just local productivity. Measure cycle time, cost to serve, risk outcomes, control effectiveness, customer experience and capacity release.
    2. Define the autonomy and orchestration policy: Decide which process steps can be assisted, automated, bounded, orchestrated or must remain human led. Make permissions, escalation points and human approvals explicit by product, customer, risk and regulatory materiality.
    3. Choose the right delivery model: Use a central AI factory where consistency and scarce skills matter, hub-and-spoke where scale is needed, embedded process teams where transformation must be close to the work, and platform models where reusable services can be consumed across the bank.
    4. Build reusable intelligence foundations: Invest in grounded knowledge, the real-time truth layer, orchestration tooling, model and prompt registries, synthetic simulation, monitoring and evidence capture so every process team is not rebuilding the same capabilities.
    5. Rehearse, monitor and prove: Test AI-enabled processes in synthetic environments, track benefits against process outcomes, and use governance-as-code plus an AI decision flight recorder to evidence what happened, why it happened, who approved it and how it was monitored.
    6. Establish protection and adequate resilience: Recent concerns around Anthropic's Claude Mythos Preview and Project Glasswing highlight why banks will need dynamic, real-time monitoring of agent behavior, prompt and tool activity, third-party dependencies and emerging software vulnerabilities.9, 15, 16 The EY Responsible AI Pulse and EY/IIF bank risk work reinforce that real-time oversight, controls, operational resilience and advanced risk capabilities need to evolve as AI moves into core processes.13, 17 As agents become embedded in banking processes, resilience, vulnerability management, access controls and incident response must evolve with them. Preserving customer trust will become table stakes.

    These six moves reveal whether a bank is experimenting with AI or redesigning how banking work gets done.

    Conclusion: governed intelligence as an operating model

    The next phase of AI in banking will depend less on any single model, vendor or use case, and more on a bank's ability to embed governed intelligence into the processes, controls and decisions that run the institution.

    That operating model must do four things well. It must understand through grounded GenAI, structured data intelligence, graph models and contextual personalization. It must act through mini agents and workflow orchestration within policy-defined limits. It must test through synthetic data and simulation of rare, risky or future states. And it must prove through governance-as-code, human oversight, monitoring and an AI decision flight recorder.

    This is the real transition: from AI as a tool to AI as an operating capability. The future AI bank will be more adaptive, more contextual, more explainable, more simulated, more network aware and more governed.

    The future will belong to banks with a structured operating model for governed intelligence, not those with more models.
     


    FAQ about AI transformation, governance and agentic banking

    Summary

    Artificial intelligence is moving from isolated pilots to becoming embedded in how banks operate. Real value comes from redesigning end-to-end processes — such as onboarding, lending and fraud — not from standalone use cases. The focus is shifting to governed intelligence, where AI supports or automates decisions within clear controls, oversight and accountability. Banks need an operating model that combines trusted data, orchestration of seasoned agents and strong governance. Success will depend on redesigning work, choosing the right delivery model and proving outcomes — facilitating AI-driven decisions are measurable, controlled and trusted across the organization.

    About this article