10 June
FSB consultation issued
The date the FSB issued its consultation report on sound practices for AI in finance
The world's main financial regulator wants banks to manage AI agents the way they manage employees. The deadline to respond is 22 July
By Mustafa Khider
Executive summary
So what
Banks should inventory every deployed or pilot agent now, because supervisors will ask who hired it, what it can do, and who can stop it
The regulatory shift is not theoretical. The FSB consultation puts autonomous systems under a synthetic-employee lens while a majority of surveyed financial institutions are already using agentic AI.
10 June
The date the FSB issued its consultation report on sound practices for AI in finance
22 July
The date by which comments are open on the FSB consultation
12
The report covers governance, lifecycle, data hygiene, cyber and third-party risk
01 Reclassification
On 10 June, the Financial Stability Board, the international body that coordinates financial regulation across the G20, issued a consultation report on sound practices for AI in finance. Most of it reads as expected. Twelve practices covering governance, lifecycle, data hygiene, cyber and third-party risk, with comments open until 22 July. The board members who signed off will be familiar to anyone who has tracked the Basel and FSB workstreams over the last five years. One sentence, sitting inside the section on autonomous systems, resets the legal category of agentic AI inside financial services. The FSB recommends that firms adapt their human resources controls to treat autonomous AI agents as synthetic employees.
It is a small shift in language. It is a very large shift in liability.
Liability shift
It is a small shift in language. It is a very large shift in liability
02 Adoption signal
The figure that frames the urgency sits in the same report, drawn from survey work by the Cambridge Centre for Alternative Finance, a research unit at Cambridge Judge Business School that tracks digital finance adoption. 52% of financial sector respondents are already using agentic AI. 23% in production. 29% in pilot. Most of the regulated market is now running what the FSB has just characterised as colleagues with login credentials and transaction authority, brought in under software contracts rather than employment terms.
This lands first on the chief risk officer and chief information officer at a regional bank. Their names sit on the model risk policy and the third-party risk register. Those documents are about to feel undersized. The window to act ahead of the supervisor is the next two budget cycles. After that, the supervisors do the writing for you.
Adoption signal
The Cambridge Centre for Alternative Finance survey data turns the FSB language from future policy into immediate operating risk.
using agentic AI
52%
Financial-sector respondents already using agentic AI
in production
23%
Agentic AI already running in production environments
in pilot
29%
Agentic AI currently moving through pilot-stage use
03 Software reading
The conventional reading inside most banks treats agentic AI as a deeper version of the existing software supply chain. The agent calls APIs, the technical connection points other software uses to talk to the bank, and schedules tasks. On an architecture diagram, it looks like an unusually well-integrated workflow tool. So it gets the workflow-tool treatment. Model risk reviews the model. Enterprise architecture reviews the integration. Third-party risk reads the vendor's SOC 2 report. The vendor accepts an SLA and a slice of indemnity. The whole thing slots into the controls the bank already runs. There is real value in that continuity. The controls are mature, the audit functions know how to read them, and the supervisors are familiar with the rhythm of model risk committee reporting. The argument has logic on its side. It is the most efficient way to scale a new capability without breaking what already works. Proponents would add, fairly, that bolting on a parallel HR-shaped track for AI creates duplication and shadow oversight, and the right move is to deepen the model risk regime rather than invent a second one. The institutions that hold this view have been right before. The same logic carried them through cloud, robotic process automation, and the first generation of machine learning models. Each time, the existing controls absorbed the new technology and the bank kept moving without inventing a parallel oversight regime.
Control frame
Workflow-tool frame
Synthetic-employee frame
04 Employee line
The argument holds until the first material agent error. Then the seams show. When a vendor's product fails, the supervisor talks to the vendor. When an employee acts outside policy, the supervisor talks to the bank that hired the employee. The FSB has now told the global financial system that autonomous agents sit on the bank's side of that line. The questions reach inside. Who authorised it. On what threshold. With what oversight. Who acted when the limit was breached. Those are HR-shaped questions. They sit naturally inside the synthetic-employee frame and uncomfortably anywhere else.
05 Policy as code
The harder consequence is for delivery. The dominant consulting model in regional banking is built on a partition between strategy and build. One firm designs the governance and hands over a policy document. Another firm or an offshore unit writes the code. A control framework sits between them and is meant to make them line up. Agentic systems collapse that partition, because the policy is the code. The authorisation thresholds, the escalation paths, the kill switches, the tool permissions, the boundary between a human approving each agent action and a human only supervising the flow more loosely, all of these live as configuration inside the agent. They cannot be designed in one document and built by a different team six months later. A policy document can say that any trade above five million dirhams requires explicit human sign-off. The agent does not read the policy document. The configuration does, and the configuration was written by someone two steps downstream of the policy author, working from a one-line acceptance criterion in a Jira ticket. The intent does not survive the handover from partner to senior associate to offshore developer. By the time the agent ships, the threshold has become a default, and the default is wrong.
Policy as code
The line where an agent can act and where explicit human sign-off is required
The route from agent exception to accountable response inside the bank
The operational off-switch and the person authorised to use it
The systems an agent can read from, write to and trigger
The boundary between approving each action and supervising the flow
The log a supervisor can read after an agent has acted
06 Response window
The seat-based pricing model makes the problem worse. The economics reward extended timelines and high headcount, neither of which match the velocity the FSB has now demanded. Parallel UK supervisory work has warned that AI-enabled cyber threats compress remediation windows from weeks to hours. A bank that has bought its agentic governance from a firm pricing by the consultant-month does not have the response architecture that horizon requires. Supervisors will calibrate their expectations to that velocity, not to the bank's preferred timeline. A bank that responds to model misbehaviour in weeks has already lost the conversation. The lean, founder-led model gets this right by accident of structure. The senior practitioners who read the FSB consultation also write the code that enforces it, and they stay long enough to walk the supervisor through the audit log.
Delivery pressure
5m
The example approval threshold used to show how policy intent can become configuration
2
The window to act ahead of the supervisor
2026
The year banks need to build the rare pairing of accountable ownership and technical literacy
07 Inventory work
The work in the next two quarters is narrower than the consulting market will suggest. Start with an inventory. Every agent currently deployed or in pilot, the systems it touches, the actions it can take, the threshold at which a human is in the loop and at which a human is on the loop, and the audit trail it produces. The inventory should include the agent's tool permissions, the systems it can read from, the systems it can write to, the maximum value of action it can take without escalation, and the response time of the escalation chain. Each entry should be testable. A name and a phone number is not an escalation path; a name with response-time obligations and a documented back-up is. The inventory will be uncomfortable. It will surface agents commissioned by business lines outside the model risk regime, and agents whose threshold logic exists only inside a prompt nobody owns. Then the HR-shaped policy. What each agent is permitted to do, who in the bank is the named accountable owner, what triggers escalation, what the off-switch is, and who in the building has the authority to use it. Only then does the engineering work begin. The named owner needs the authority to challenge the agent's design before it ships, and the technical literacy to understand what they are being shown. The named accountable owner has to attend the model risk committee. That is the practical test. If the role exists only inside an org chart and not inside the room where decisions are made, the agent has no human owner the supervisor can find. That pairing is rare inside banks, and rarer inside the firms that sell to them. Building it is the work of 2026.
Agent inventory
The inventory is not a list of tools. It is the operating record a supervisor can use to find ownership, authority and evidence
The systems each agent reads from, writes to or triggers
The operational actions an agent can take without additional approval
The point at which a human must approve each agent action
The point at which a human supervises the flow more loosely
The largest value of action an agent can take before escalation is required
The response obligation, documented back-up and route for exceptions
Who in the building has the authority to stop the agent
The owner who can attend model risk committee and answer for the agent
08 Close
When the first synthetic employee misbehaves, the bank that fires it cleanly will still have to explain who hired it
The boards that get the hiring paperwork right this year will spend next year supervising. The boards that do not will spend it explaining
Mustafa Khider is a co-founder of Mal7, focused on enterprise AI and automation for financial institutions, FinTechs and regulators moving AI into production.
Agentic AI control readiness
Mal7 helps financial institutions turn agentic AI governance into named ownership, policy-as-code controls and audit evidence that can survive production