Skip to main content
← Back to Radar
AI & ML

AI Agents Are Starting to Move Money — and Banks Aren't Ready

Most financial firms now run AI agents, and most of those agents have some autonomy — but fraud and identity controls were designed for humans.

What Happened

Industry data discussed around American Banker's June 2026 Digital Banking conference points to a striking gap: roughly 62% of financial services firms have deployed AI agents, and 93% of those firms have granted their agents some level of autonomy. A large majority of organizations expect agents to directly facilitate payments, yet about two-thirds admit that authorizing legitimate agent activity will require technology they do not have today.

Early product answers are appearing. Robinhood's agentic accounts, for example, ring-fence agent activity in a separate account, enforce hard spending limits, and give the customer a one-tap kill switch — while placing the residual risk explicitly on the user.

Why It Matters

Bank fraud and identity stacks are built on human signals: device fingerprints, behavioural biometrics, typing cadence, session patterns. An AI agent transacting with a customer's own credentials looks legitimate to all of them. The two questions the industry has not answered are structural — how does a bank verify that an agent is actually authorized to act, and who absorbs the loss when an authorized agent does the wrong thing?

Banking & Fintech Implications

Banks need an agent-aware control plane: scoped, revocable mandates that define what an agent may do; cryptographic attribution so agent traffic is distinguishable from human traffic; hard limits and kill switches as first-class product features; and liability allocation written into terms before volume arrives. Fraud models must be retrained on agent behaviour rather than treating it as an anomaly.

My Take

Treat agents as a new client class, not a new fraud pattern. The banks that win this transition will issue explicit machine mandates — the way corporate banking has handled delegated authority for decades — instead of retrofitting human KYC onto software. Start with low-limit, revocable delegation and full audit trails; expand scope only as attribution matures.

Agentic AIPaymentsFraudIdentity