Technology

Agentic AI in financial systems

Agentic AI in financial systems covers systems that pursue a goal, plan or sequence actions, use tools or external services, observe results and adapt with bounded autonomy. The public evidence supports a financial-resilience technology profile, not a documented statecraft operation. As at 29 July 2026, no public source cited here identifies a confirmed state-directed agentic attack on a regulated financial system.

Definition and current use

Agentic AI is not a synonym for machine learning, generative AI, a chatbot or a fixed trading algorithm. A useful operational threshold requires goal-directed action across several steps, connected tools and some capacity to revise a plan after observing results. The deployment record should identify the operator, production status, permissions, transaction limits and level of human control.

The Bank of England and Financial Conduct Authority's 2024 survey found that 75 per cent of respondent firms already used AI, but only 2 per cent of reported use cases involved fully autonomous decision-making. This shows broad AI adoption and limited reported full autonomy in that sample. It does not establish unrestricted financial agents moving funds or trading across venues.

Resilience significance

The Financial Stability Board's November 2024 report concerns AI broadly. It identifies third-party concentration, market correlation, cyber risk, model risk and governance weaknesses that could affect financial stability. These findings establish the risk environment, not the occurrence of every agentic scenario.

An agent with excessive tool permissions could increase the speed or reach of a model error, compromised data feed or cyber intrusion. Common models, cloud providers and data sources may also create correlated exposure. Prompt injection, hallucination, vendor outage, fraud and cyber compromise nevertheless remain operational, criminal or prudential events unless an attributable state operator and strategic purpose are established.

Claims that agents will necessarily produce herding or machine-speed runs remain hypotheses requiring deployment and market evidence. The same technology may support fraud detection, compliance, research, supervision and operational resilience.

Governance and control points

Effective control extends beyond placing a human in the loop. It includes action authority, transaction limits, segregation of duties, tool and model change controls, monitoring, audit logs, independent validation, escalation, rollback and recovery. Supervisory expectations vary by jurisdiction and use case.

United States model-risk guidance changed on 17 April 2026, when the Federal Reserve, Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation issued SR 26-2 and superseded SR 11-7. The EU AI Act, the Digital Operational Resilience Act and sectoral financial law overlap but do different work. DORA governs ICT operational resilience and third-party risk, not AI safety as a complete field. The EU AI Act has phased application dates and should not be described as fully applicable in one undifferentiated block.

This record remains in the context sequence. Promotion requires a documented public authority or state-linked operator, strategic objective and financial transmission mechanism.

See also

Algorithmic and high-frequency trading systems · AI-enabled market manipulation · Central bank and market-infrastructure resilience technology · Reflexive control in financial markets

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Agentic AI in financial systems.' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/agentic-ai-in-financial-systems/.

Suggest an edit