AI Governance Institute
← News
Research2026-10-08

Risk-Based Framework for Bank AI Agent Authority Sets a Governance Benchmark

What happened

The Asian Banker published How much authority should banks give AI agents?, a practical framework for financial institutions evaluating AI agent deployments. The article outlines five evaluation dimensions: the nature of the use case and expected business value. It also covers which external services the agent can reach, how human oversight is embedded, and what deployment controls are in place. It recommends that banks assign agents to authority tiers, starting with read-only or advisory tasks before granting the ability to initiate transactions or communicate externally. Mandatory human intervention points must be defined before production release, not added afterward. The framework also requires testing evidence, meaning documented proof that agents behaved within bounds during pre-production trials, as a gate for go-live approval. Regulators including the Bank for International Settlements have signaled that existing model risk frameworks do not fully address agentic systems. Supervisors aligned with the Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) share this view. That gap is explored in SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight.

Why it matters

  • ·Regulators are applying model risk management standards to AI agents, and banks that cannot show how agent authority was set, tested, and documented face supervisory criticism. The Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) now frames agent governance as part of model risk. Gaps in authority calibration are audit findings, not just design choices.
  • ·Agents that can initiate payments, approve credit, or communicate with customers on behalf of the bank create direct liability for actions taken outside sanctioned scope. Firms without a documented authority tier and human intervention policy have no defensible position when an agent exceeds its intended boundaries. Enforcement bodies are already investigating rogue agent incidents in the financial sector.
  • ·The framework's requirement for pre-production testing evidence sets a practical audit bar that many institutions are not yet meeting. Banks using off-the-shelf agentic tools from third-party vendors may find that vendor-supplied documentation does not satisfy this standard, creating a gap in third-party AI risk programs.

Governance controls affected

What to do now

  • ☐Map every AI agent currently in production or in testing to a list of actions it can take without a human approving each step, including sending messages, initiating payments, updating records, or contacting external services.
  • ☐For each agent, define in writing which actions require a human to approve before the agent proceeds, and confirm that this gate is enforced in the system, not just described in policy documentation.
  • ☐Require pre-production testing evidence as a condition for go-live: ask engineering or the vendor to produce records showing the agent stayed within its defined authority boundaries during testing, and treat the absence of such records as a deployment blocker.
  • ☐Review your third-party AI vendor contracts to confirm vendors are obligated to disclose when an agent update changes what the agent can do autonomously, and that your team re-approves authority scope after any such change.
  • ☐Bring the authority tier framework to your model risk committee or AI governance committee as a standing agenda item, and document the rationale for each tier assignment in a format that could be shared with a regulator or internal auditor.

What to watch next

Banks should monitor whether the Monetary Authority of Singapore formalizes agent authority controls in the MAS Guidelines on Artificial Intelligence Risk Management. Those guidelines remain proposed. The consultation could incorporate tier-based authority requirements as it progresses. Supervisory expectations from the BIS and from US bank regulators enforcing SR 26-2 are likely to converge on documentation standards similar to those in this framework. Institutions that build these records now will be better positioned when examiners ask for them. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services already names containment and human oversight as baseline controls. Additional jurisdiction-specific rules are emerging across APAC, Europe, and North America.

Related Coverage

Corporate Policy2026-10-02

ICE Agentic Software Factory Bans Self-Approval and Permission Escalation by Design

U.S. Immigration and Customs Enforcement (ICE) issued a request for information (RFI) seeking vendor support for an agentic software factory built on its existing STELLA platform. The design assigns planning, coding, testing, and review tasks to AI agents operating across three governance layers. Notably, the architecture explicitly prohibits any agent from expanding its own permissions or approving its own production releases.

Research2026-10-07

MCP Threat Guide Turns Six Attack Classes Into Enterprise Controls

The Agentics published the Enterprise MCP Guide 2026 on October 5, cataloging six attack classes targeting the protocol layer that connects AI agents to enterprise tools. The guide recommends per-agent tool allowlists, verified identity binding for each agent, centralized gateways, and mandatory human approval before any destructive or irreversible action. Organizations running AI agents connected to real business systems should treat this taxonomy as an immediate control gap assessment tool.

Enforcement2026-09-28

FTC Chair Warns AI Agent Deployments Face Liability for Harm and Nondisclosure

FTC Chair Andrew Ferguson stated the agency will enforce consumer protection laws against companies that fail to disclose AI agent use or whose agents cause consumer harm. The remarks signal that the FTC views AI agents as company conduct, not independent actors, making deploying enterprises directly accountable. No new rule was announced, but the enforcement signal applies under existing FTC authority.