← Back to blog

Agentic AI in BFSI: when the model stops asking permission

Generative AI drafts. Agentic AI acts. The shift from a model that suggests a reply to a system that opens accounts, moves money, files disputes and emails customers without a human in each loop is the defining governance challenge of 2026 — and most BFSI risk frameworks were not written for it.

Sakthi Thangavelu·Co-founder, AramGRC·June 4, 2026·9 min read

Every existing control assumes a human checkpoint. A drafting assistant produces text a person reviews and sends. But an agent can chain dozens of tool calls — query a database, score a customer, approve a limit, trigger a transfer — in seconds, with no natural pause for review.

The same shadow-AI dynamics already straining institutions (two-thirds of staff using AI, fewer than one in five firms with a policy) become exponentially riskier when the tool can take consequential actions, not just generate words. Regulators have seen it coming.

RBI's FREE-AI framework centres human oversight, accountability and explainability — principles that get harder, not easier, when decisions are autonomous and multi-step.

The CBUAE's 2026 guidance explicitly preserves effective human oversight and consumer opt-out for high-impact automated decisions.

DIFC's proposed amendments introduce the idea of Autonomous Systems Officers — a named human accountable for autonomous processing. The regulatory message across India and the Gulf is consistent: autonomy does not dilute accountability; it concentrates it.

Governing an agent requires controls that drafting tools never needed: scoped permissions (what tools and accounts can the agent touch, and up to what value?); hard action limits with mandatory human approval above a threshold; a complete, immutable audit trail of every step the agent took and why; pre-deployment red-teaming for prompt injection and goal misalignment; and a kill switch with a tested rollback.

Treat each agent as you would a junior employee with system access — onboarded, permissioned, supervised and logged. The institutions that win the agentic era will be the ones that can prove, after the fact, exactly what their agents did.

Agentic AIBFSIGovernanceModel Risk
WhatsApp