Mal7
Insights
AI regulationJuly 8, 20269 min read

The Financial Stability Board has reclassified your AI agents as employees

The world's main financial regulator wants banks to manage AI agents the way they manage employees. The deadline to respond is 22 July

By Mustafa Khider

Executive summary

  • On 10 June, the Financial Stability Board moved autonomous AI agents into a synthetic-employee frame by recommending HR-style controls for agents in finance
  • The adoption signal is already live: 52% of financial-sector respondents are using agentic AI, with 23% in production and 29% in pilot
  • The control burden shifts inside the bank: authorisation thresholds, escalation, kill switches, tool permissions, audit trails and named accountable owners now need to be explicit

So what

Banks should inventory every deployed or pilot agent now, because supervisors will ask who hired it, what it can do, and who can stop it

The regulatory shift is not theoretical. The FSB consultation puts autonomous systems under a synthetic-employee lens while a majority of surveyed financial institutions are already using agentic AI.

10 June

FSB consultation issued

The date the FSB issued its consultation report on sound practices for AI in finance

22 July

response deadline

The date by which comments are open on the FSB consultation

12

sound practices

The report covers governance, lifecycle, data hygiene, cyber and third-party risk

01 Reclassification

A small shift in language creates a large shift in liability

On 10 June, the Financial Stability Board, the international body that coordinates financial regulation across the G20, issued a consultation report on sound practices for AI in finance. Most of it reads as expected. Twelve practices covering governance, lifecycle, data hygiene, cyber and third-party risk, with comments open until 22 July. The board members who signed off will be familiar to anyone who has tracked the Basel and FSB workstreams over the last five years. One sentence, sitting inside the section on autonomous systems, resets the legal category of agentic AI inside financial services. The FSB recommends that firms adapt their human resources controls to treat autonomous AI agents as synthetic employees.

It is a small shift in language. It is a very large shift in liability.

Liability shift

It is a small shift in language. It is a very large shift in liability

02 Adoption signal

Most of the regulated market is already running the thing now being reclassified

The figure that frames the urgency sits in the same report, drawn from survey work by the Cambridge Centre for Alternative Finance, a research unit at Cambridge Judge Business School that tracks digital finance adoption. 52% of financial sector respondents are already using agentic AI. 23% in production. 29% in pilot. Most of the regulated market is now running what the FSB has just characterised as colleagues with login credentials and transaction authority, brought in under software contracts rather than employment terms.

This lands first on the chief risk officer and chief information officer at a regional bank. Their names sit on the model risk policy and the third-party risk register. Those documents are about to feel undersized. The window to act ahead of the supervisor is the next two budget cycles. After that, the supervisors do the writing for you.

Adoption signal

Agentic AI is already inside the regulated perimeter.

The Cambridge Centre for Alternative Finance survey data turns the FSB language from future policy into immediate operating risk.

using agentic AI

52%

Financial-sector respondents already using agentic AI

in production

23%

Agentic AI already running in production environments

in pilot

29%

Agentic AI currently moving through pilot-stage use

03 Software reading

The conventional reading treats the agent as another software supplier

The conventional reading inside most banks treats agentic AI as a deeper version of the existing software supply chain. The agent calls APIs, the technical connection points other software uses to talk to the bank, and schedules tasks. On an architecture diagram, it looks like an unusually well-integrated workflow tool. So it gets the workflow-tool treatment. Model risk reviews the model. Enterprise architecture reviews the integration. Third-party risk reads the vendor's SOC 2 report. The vendor accepts an SLA and a slice of indemnity. The whole thing slots into the controls the bank already runs. There is real value in that continuity. The controls are mature, the audit functions know how to read them, and the supervisors are familiar with the rhythm of model risk committee reporting. The argument has logic on its side. It is the most efficient way to scale a new capability without breaking what already works. Proponents would add, fairly, that bolting on a parallel HR-shaped track for AI creates duplication and shadow oversight, and the right move is to deepen the model risk regime rather than invent a second one. The institutions that hold this view have been right before. The same logic carried them through cloud, robotic process automation, and the first generation of machine learning models. Each time, the existing controls absorbed the new technology and the bank kept moving without inventing a parallel oversight regime.

Control frame

The same agent looks different depending on which control system has to answer for it.

Workflow-tool frame

The existing controls absorb the agent

01Model risk reviews the model
02Enterprise architecture reviews the integration
03Third-party risk reads the vendor's SOC 2 report
04The vendor accepts an SLA and a slice of indemnity

Synthetic-employee frame

The questions reach inside the bank

01Who authorised it
02On what threshold
03With what oversight
04Who acted when the limit was breached

04 Employee line

The line moves when the first material agent error arrives

The argument holds until the first material agent error. Then the seams show. When a vendor's product fails, the supervisor talks to the vendor. When an employee acts outside policy, the supervisor talks to the bank that hired the employee. The FSB has now told the global financial system that autonomous agents sit on the bank's side of that line. The questions reach inside. Who authorised it. On what threshold. With what oversight. Who acted when the limit was breached. Those are HR-shaped questions. They sit naturally inside the synthetic-employee frame and uncomfortably anywhere else.

05 Policy as code

Agentic systems collapse the partition between strategy and build

The harder consequence is for delivery. The dominant consulting model in regional banking is built on a partition between strategy and build. One firm designs the governance and hands over a policy document. Another firm or an offshore unit writes the code. A control framework sits between them and is meant to make them line up. Agentic systems collapse that partition, because the policy is the code. The authorisation thresholds, the escalation paths, the kill switches, the tool permissions, the boundary between a human approving each agent action and a human only supervising the flow more loosely, all of these live as configuration inside the agent. They cannot be designed in one document and built by a different team six months later. A policy document can say that any trade above five million dirhams requires explicit human sign-off. The agent does not read the policy document. The configuration does, and the configuration was written by someone two steps downstream of the policy author, working from a one-line acceptance criterion in a Jira ticket. The intent does not survive the handover from partner to senior associate to offshore developer. By the time the agent ships, the threshold has become a default, and the default is wrong.

Policy as code

The controls live where the agent acts.

01

Authorisation thresholds

The line where an agent can act and where explicit human sign-off is required

02

Escalation paths

The route from agent exception to accountable response inside the bank

03

Kill switches

The operational off-switch and the person authorised to use it

04

Tool permissions

The systems an agent can read from, write to and trigger

05

Human in/on the loop

The boundary between approving each action and supervising the flow

06

Audit evidence

The log a supervisor can read after an agent has acted

06 Response window

Supervisory expectations will follow agent velocity, not delivery timelines

The seat-based pricing model makes the problem worse. The economics reward extended timelines and high headcount, neither of which match the velocity the FSB has now demanded. Parallel UK supervisory work has warned that AI-enabled cyber threats compress remediation windows from weeks to hours. A bank that has bought its agentic governance from a firm pricing by the consultant-month does not have the response architecture that horizon requires. Supervisors will calibrate their expectations to that velocity, not to the bank's preferred timeline. A bank that responds to model misbehaviour in weeks has already lost the conversation. The lean, founder-led model gets this right by accident of structure. The senior practitioners who read the FSB consultation also write the code that enforces it, and they stay long enough to walk the supervisor through the audit log.

Delivery pressure

The response window has moved from programme rhythm to agent rhythm.

5m

dirham trade threshold

The example approval threshold used to show how policy intent can become configuration

2

budget cycles

The window to act ahead of the supervisor

2026

operating build year

The year banks need to build the rare pairing of accountable ownership and technical literacy

07 Inventory work

The work in the next two quarters is narrower than the market will suggest

The work in the next two quarters is narrower than the consulting market will suggest. Start with an inventory. Every agent currently deployed or in pilot, the systems it touches, the actions it can take, the threshold at which a human is in the loop and at which a human is on the loop, and the audit trail it produces. The inventory should include the agent's tool permissions, the systems it can read from, the systems it can write to, the maximum value of action it can take without escalation, and the response time of the escalation chain. Each entry should be testable. A name and a phone number is not an escalation path; a name with response-time obligations and a documented back-up is. The inventory will be uncomfortable. It will surface agents commissioned by business lines outside the model risk regime, and agents whose threshold logic exists only inside a prompt nobody owns. Then the HR-shaped policy. What each agent is permitted to do, who in the bank is the named accountable owner, what triggers escalation, what the off-switch is, and who in the building has the authority to use it. Only then does the engineering work begin. The named owner needs the authority to challenge the agent's design before it ships, and the technical literacy to understand what they are being shown. The named accountable owner has to attend the model risk committee. That is the practical test. If the role exists only inside an org chart and not inside the room where decisions are made, the agent has no human owner the supervisor can find. That pairing is rare inside banks, and rarer inside the firms that sell to them. Building it is the work of 2026.

Agent inventory

Each deployed or pilot agent needs a testable control entry

The inventory is not a list of tools. It is the operating record a supervisor can use to find ownership, authority and evidence

01

Systems touched

The systems each agent reads from, writes to or triggers

02

Actions allowed

The operational actions an agent can take without additional approval

03

Human-in-loop threshold

The point at which a human must approve each agent action

04

Human-on-loop threshold

The point at which a human supervises the flow more loosely

05

Maximum value without escalation

The largest value of action an agent can take before escalation is required

06

Escalation response time

The response obligation, documented back-up and route for exceptions

07

Off-switch authority

Who in the building has the authority to stop the agent

08

Named accountable owner

The owner who can attend model risk committee and answer for the agent

08 Close

When the first synthetic employee misbehaves, the bank that fires it cleanly will still have to explain who hired it

The boards that get the hiring paperwork right this year will spend next year supervising. The boards that do not will spend it explaining

About the author

Mustafa Khider is a co-founder of Mal7, focused on enterprise AI and automation for financial institutions, FinTechs and regulators moving AI into production.

Agentic AI control readiness

Build the synthetic-employee register before the supervisor asks for it

Mal7 helps financial institutions turn agentic AI governance into named ownership, policy-as-code controls and audit evidence that can survive production