Skip to content
Agentic AI in Banking and Payments: What's Real in 2026
Business & Startups42 min read

Agentic AI in Banking and Payments: What's Real in 2026

Scult Team
42 min read

Banks are moving from AI chatbots to autonomous agents handling fraud, compliance, and credit workflows in 2026, with regulation now the main brake on adoption.

Agentic AI in Banking and Payments: What's Real in 2026

Direct answer: Agentic AI in banking means software that can plan and carry out multi-step financial tasks — flagging fraud, running KYC checks, assembling a credit file — with limited human intervention, rather than just answering questions. It matters right now because the infrastructure to run these agents at scale, from Fiserv's agentOS to FIS's Anthropic-powered financial-crimes agent, is shipping in 2026, and bank executives increasingly believe the biggest obstacle left is not the technology but the regulatory and legal framework around it.

What's Actually Happening

For years, "AI in banking" mostly meant a chatbot that could answer a balance question or a machine-learning model quietly scoring fraud risk in the background. What's changing in 2026 is the shift toward agentic AI: systems that don't just respond to a single query but can plan and execute a sequence of steps toward a goal, checking their own work, calling other systems, and only pausing for a human when something falls outside their defined authority.

The infrastructure for this shift is now shipping, not just being discussed at conferences. Fiserv has launched agentOS, which it describes as an operating system for deploying AI agents across banking workflows, with wide availability expected by August 2026. Read literally, that's a significant claim: an "operating system" implies a common layer that different banks and different agent vendors can build on top of, rather than every institution stitching together its own bespoke agent stack from scratch. If it delivers on that promise, agentOS could do for agentic banking AI something similar to what core banking platforms did for basic account management — turn a custom integration problem into a configuration problem.

At the same time, FIS has partnered with Anthropic to bring agentic AI to banking, and notably chose to start with a financial-crimes agent rather than a customer-facing chatbot or a marketing tool, with general availability planned for the second half of 2026. That sequencing choice is itself informative: financial crime and fraud detection is a domain where banks already have data, established metrics for what "good" looks like, and a clear internal owner for the outcome. It's a sensible first wedge for agentic AI precisely because success and failure are measurable, unlike more diffuse use cases like general customer service.

The research backing this shift is coming from multiple directions. The IMF published a dedicated research note in April 2026 examining how agentic AI will reshape payments, treating this as a systemic question worth central-bank-adjacent attention rather than a vendor talking point. Trade press like Banking Dive has been tracking bank ambitions to scale agentic AI deployments through 2026, and industry surveys tied to Accenture-style research are now quantifying executive sentiment rather than just anecdote: 57% of banking executives expect AI agents to be fully embedded in risk, compliance, audit, and fraud detection within three years, and 56% expect the same for credit assessment, loan processing, and KYC. Those numbers describe boards and executive committees that have already decided this is coming, not vendors "hoping" it will land.

It's worth sitting with how quickly the framing has changed. As recently as 2023 and 2024, most banking-AI coverage was still about generative AI chatbots handling customer questions, or machine-learning models quietly scoring credit risk in the background — useful, but bounded, single-purpose tools. The 2026 wave is a different kind of announcement: a named operating system for running agents across workflows, a major processor partnering with a frontier AI lab specifically on financial crime, and a multilateral institution like the IMF publishing dedicated research on the systemic implications. That's the vocabulary of infrastructure, not experimentation, and it's a meaningful signal that the industry believes this wave is durable rather than a passing hype cycle.

It also matters that this shift is happening inside institutions that are, by design, conservative about new technology. Banks don't typically move fast on unproven systems — they move fast when the risk-adjusted case for a technology becomes clear enough that not moving looks like the bigger risk. The fact that agentic AI is arriving through core infrastructure vendors like Fiserv and FIS, rather than purely through standalone AI startups pitching banks directly, is itself telling: it suggests the technology has cleared enough of a bar that the incumbents banks already trust with their core systems are willing to build and stake their reputation on it.

Why It's Trending Now

Three separate pressures are converging on banks at the same time, which explains why 2026 specifically — rather than 2023, when generative AI chatbots first went mainstream in banking — is turning into the agentic-AI inflection point.

The first is operational cost pressure that hasn't gone away just because interest rates or the macro cycle changed. Compliance, KYC, fraud investigation, and credit-file assembly are all labor-intensive, rules-heavy, document-heavy workflows — exactly the kind of work that large language models paired with structured tool access are good at accelerating, provided the outputs are checked. Every large bank has a backlog of this work sitting somewhere, and agentic AI is the first technology in a decade that plausibly attacks the backlog directly rather than just making the existing team's dashboard nicer.

The second is that the underlying model and tooling capability crossed a threshold. Earlier generations of banking AI were mostly classification models: score this transaction, flag this document, predict this default probability. Agentic systems add planning and tool use on top of that — the ability to decide which checks to run, in what order, and to call out to case-management systems, document stores, and sanctions-screening tools along the way. That's a materially different capability than a single-purpose fraud score, and it only became commercially viable to deploy at scale recently.

The third is vendor infrastructure catching up to the ambition. A bank's compliance and technology teams might have wanted agentic workflows two years ago, but building the orchestration layer, audit trail, and permissioning model in-house was a multi-year undertaking most banks weren't going to fund on spec. agentOS and the FIS-Anthropic partnership are exactly the kind of platform investment that removes that barrier — banks can now buy the plumbing instead of building it, which collapses years of internal build time into a procurement and integration decision.

There's a fourth, quieter factor too: competitive anxiety. Once one major processor announces something as ambitious as an "operating system for agentic AI in banking," every competing vendor and every bank evaluating vendors has to take a position on it — either matching the move, differentiating against it, or explaining to their own board why they're waiting. That dynamic tends to compress adoption timelines industry-wide once a credible first mover appears, because the cost of being seen as the laggard starts to outweigh the comfort of moving cautiously. It's a pattern familiar from earlier waves of banking technology, from online banking to mobile check deposit to real-time payments — the first credible large-scale mover usually triggers a broader race, not just its own rollout.

Who This Affects — The Business Stakes

The functions named most consistently in this wave — risk, compliance, audit, fraud detection, credit assessment, loan processing, and KYC — are not peripheral cost centers. They sit directly on top of a bank's regulatory exposure and its ability to grow the loan book responsibly. That's the real business stake here: this isn't primarily a customer-experience play, it's an attempt to make the most expensive, most regulated, most people-intensive parts of banking operations faster and more consistent without sacrificing the audit trail regulators require.

For bank executives, the stakes show up in a fairly direct calculation. Every KYC onboarding delay is a customer who might walk to a competitor with faster onboarding. Every fraud investigation that takes a human analyst two days instead of two hours is a window where a bad actor has more time to move funds. Every manual step in credit assessment is a data point about where the bank's cost-to-serve is out of line with digital-only challengers who never built the manual process in the first place. Agentic AI, done well, directly compresses each of those timelines.

For compliance and risk teams specifically, the stakes cut both ways. Done right, agentic AI gives them faster, more consistent case handling and a system that never gets tired on the two-hundredth alert of the day. Done poorly — deployed without proper guardrails, audit logging, or human review on high-stakes decisions — it introduces a new category of operational risk: an autonomous system making judgment calls in a domain where regulators expect a documented, explainable rationale for every decision. That tension is precisely why the surveys cited above show high executive confidence in the destination (57% and 56% embedding rates within three years) alongside caution about the path to get there.

For fintechs and smaller banks, the stakes are different again. Platforms like agentOS and the FIS-Anthropic partnership are, in effect, trying to make agentic capability available to institutions that could never have built a frontier AI research team internally. That's a genuine leveling force — a mid-sized regional bank buying into a shared agentic-AI platform can plausibly deploy fraud and compliance agents on a timeline that would have been unthinkable if the alternative were hiring an in-house ML team from scratch.

For competing technology vendors, the stakes are about not being left out of the platform layer. Once a bank standardizes its agentic workflows on a system like agentOS, switching away from it later carries real integration cost — which means the current wave of announcements isn't just about winning this year's deals, it's about winning the default platform position for the next decade of banking-AI spend. That's a large part of why the moves being made right now by Fiserv and FIS are being watched so closely by every other core-banking and payments vendor.

And for customers — the group least likely to be in the room for any of these vendor decisions — the stakes are mostly about speed and consistency they'll experience without necessarily knowing why: faster KYC onboarding, quicker resolution when a legitimate transaction gets mistakenly flagged as fraud, and potentially fewer inconsistent outcomes between two customers with similar circumstances, since an agent applying a consistent policy is less prone to the day-to-day variability that comes from different human analysts handling similar cases differently.

How Agentic AI Actually Works Inside a Bank

It's worth being concrete about what an "agent" is actually doing inside a financial-crimes or KYC workflow, because the term gets used loosely enough to blur real capability with marketing.

A financial-crimes agent, in the FIS-Anthropic sense, is generally a system that can take a flagged transaction or account, pull the relevant supporting data (transaction history, counterparty information, prior alerts, sanctions-list matches), reason across that evidence against a defined policy, and produce either a disposition with supporting rationale or an escalation to a human investigator with a summary of what it found and why it couldn't resolve the case itself. The meaningful difference from a traditional rules engine is that the agent can handle cases that don't fit a pre-written rule cleanly — it can read a free-text transaction memo, cross-reference an unusual entity name against public records style data, and produce a judgment call with reasoning attached, rather than simply firing a rule or not firing it.

A KYC agent works similarly: instead of a human analyst manually pulling a new customer's identity documents, cross-checking them against sanctions and PEP (politically exposed persons) lists, verifying address and beneficial-ownership information, and writing up a summary for approval, the agent assembles that file itself, flags any gaps or inconsistencies, and hands a human a decision-ready package rather than a blank task. The human's job shifts from "do the legwork" to "review the judgment," which is a materially different — and typically faster — task.

Crucially, in every credible deployment described in this wave, these agents operate inside defined permission boundaries and with logging that captures what data they touched and what reasoning they applied — because a bank cannot pass a regulatory exam with "the AI decided" as the entire audit trail. That constraint is not a limitation bolted on reluctantly; it is the actual design requirement that separates a production-grade banking agent from a generic AI demo.

The permissioning layer deserves particular attention because it's where most of the real engineering effort in a platform like agentOS likely goes, even though it's the least visible part to anyone outside the implementation team. An agent needs to be told, explicitly, what systems it's allowed to query, what actions it's allowed to take unilaterally versus propose for approval, and what dollar or risk thresholds automatically trigger escalation regardless of how confident the agent is in its own judgment. Get that layer wrong — too permissive — and a single mistaken agent decision can compound across thousands of cases before anyone notices. Get it too restrictive, and the agent adds so little autonomy that it barely improves on the manual process it was meant to replace. Calibrating that boundary correctly, function by function, is arguably the actual hard problem in agentic banking AI, more so than the underlying language-model capability itself.

Where the Real Risk Sits

None of this is worth discussing honestly without naming where it can go wrong, because the same properties that make agentic AI valuable — planning across multiple steps, reasoning over unstructured information, acting with some independence — are exactly what makes it a different category of risk than the rules engines and scoring models banks are used to governing.

The first risk is opacity. A traditional fraud rule either fires or doesn't, and an auditor can trace exactly why. An agent's reasoning across several steps of evidence-gathering and judgment is harder to reconstruct after the fact unless the system was specifically built to log its own reasoning in a form a human or regulator can actually review. This is precisely why detailed logging has become a non-negotiable design requirement in every credible deployment described in this wave, rather than an afterthought — without it, a bank has no defensible answer when a regulator asks "why did the system decide this."

The second risk is manipulation. An agent that reads and reasons over inputs — a transaction memo, a submitted document, a customer message — can potentially be steered by someone who understands how to craft those inputs to produce a favorable but wrong outcome, in a way that's conceptually different from trying to trick a fixed rule. Banks deploying these systems are treating this as seriously as they treat any other fraud vector, which is part of why human review checkpoints remain in place on higher-value or higher-risk decisions even as agents take on more of the initial analysis.

The third risk is concentration. As more banks build on shared platforms like agentOS, a flaw or blind spot in that shared platform doesn't stay contained to one institution — it potentially propagates across every bank that adopted it. This is a familiar pattern from other shared financial infrastructure (core banking platforms, card networks, clearing systems), but it's worth naming explicitly here because agentic AI platforms are new enough that the shared-infrastructure risk hasn't yet been tested by a real large-scale incident the way older financial infrastructure has.

The fourth risk, and arguably the most consequential for how fast this wave moves, is the liability gap referenced earlier: when an autonomous system contributes to a bad outcome, and legal frameworks haven't fully settled who bears responsibility, both banks and regulators have an incentive to move carefully rather than aggressively — which is a reasonable, healthy brake on a technology this consequential, even though it frustrates the pace some vendors would prefer.

The Global Picture

The clearest, most concrete reporting on agentic AI in banking so far is concentrated in the US. Fiserv's agentOS launch and the FIS-Anthropic financial-crimes partnership are both US-headquartered vendor initiatives aimed initially at the US banking market, and the 57%/56% executive-sentiment figures come from surveys of banking leadership tied to that same wave of US-centric reporting.

For the UK, UAE and Dubai, Australia, Germany, and Europe/France, public reporting specific to those regions on agentic AI in banking is thin so far in this research pass — which doesn't mean nothing is happening there, only that the vendor announcements and executive surveys driving this specific news cycle haven't yet produced region-specific figures the way they have for the US. Given how globally distributed major banking-technology vendors are, and how quickly platform launches like agentOS tend to expand beyond their initial market, it would be reasonable to expect UK and EU banks — which already operate under some of the world's most detailed AI and financial-services regulation — to be closely watching the US rollout as a live test case before committing to their own timelines.

China is a distinct case worth naming honestly: this specific research pass turned up no agentic-AI-in-banking reporting for China comparable to the US coverage, and drawing conclusions about Chinese bank adoption from a gap in Western trade press would be speculation rather than reporting. What can be said is that China's financial-technology sector has historically moved fast on automation once a use case proves commercially valuable elsewhere, so a lack of current coverage should not be read as a lack of interest.

There's a useful lesson in this uneven global picture for any institution outside the US watching from the sidelines: the absence of a splashy regional announcement doesn't mean the underlying pressures — cost of manual compliance work, competitive urgency around onboarding speed, the same fraud and financial-crime exposure every bank carries — are any less real outside the US. If anything, regions with historically stricter data-protection and financial-services regulation, like the UK and the EU, may simply be taking longer to reach the point of a public vendor announcement precisely because the compliance groundwork required before a bank there can deploy an autonomous agent is more involved than in the US market where this wave's first concrete moves have landed. A slower public rollout is not necessarily evidence of less interest — it can just as easily reflect a more front-loaded regulatory review process.

What This Means Going Forward — How to Respond

For a bank or fintech leadership team evaluating this wave, the mistake worth avoiding is not "moving too slowly" or "moving too fast" — it's picking the wrong first use case. The pattern in this wave is consistent: successful early agentic-AI deployments in finance start with a function that has clear, measurable outcomes (fraud caught, cases closed, false positives reduced) and an existing human-review structure the agent can slot into, rather than starting with a fully autonomous, customer-facing use case where mistakes are visible and reputationally costly.

That argues for a specific rollout order: start with internal, reviewable workflows (fraud triage, KYC file assembly, compliance case summarization) where a human remains the final decision-maker and the agent's job is to compress the time between "case opened" and "case decision-ready." Only after that pattern is proven — with a real audit trail, real error-rate data, and a real understanding of where the agent's judgment breaks down — does it make sense to extend agentic AI toward higher-autonomy or customer-facing use cases.

For institutions without a large in-house AI engineering function, the practical path is increasingly to build on top of platforms designed for this purpose rather than assembling the orchestration, permissioning, and audit-logging layer from scratch — the same logic that makes custom software development projects succeed when they're scoped around a well-defined workflow instead of an open-ended "add AI to everything" mandate. That's true whether the institution is a bank of meaningful scale deciding whether to build on a platform like agentOS or a smaller fintech deciding whether agentic capability is even worth pursuing before its core product has fully matured — in both cases, the discipline of scoping a single, measurable workflow first is what separates a deployment that survives its first audit from one that becomes a cautionary tale cited in the next round of industry commentary. A team that already understands how to design AI agents and automation around clear approval boundaries and audit requirements will typically get a financial-crimes or KYC agent to a defensible, regulator-ready state faster than a team retrofitting governance onto a system built for speed alone. Institutions weighing this build-versus-platform decision often benefit from a structured custom software development discovery process before committing engineering time, precisely because the cost of a wrong architectural choice in a regulated workflow is far higher than in a typical consumer app — a mistaken assumption about permissioning or audit logging discovered after launch is dramatically more expensive to unwind in banking than in most other software categories, given how tightly those systems are tied to regulatory exam cycles and customer trust.

The regulatory dimension deserves equal weight in any response plan. Given that both the IMF and industry commentary now describe the main barrier to agentic AI in payments as regulatory and legal rather than technological, the institutions that move fastest and most safely won't necessarily be the ones with the best model — they'll be the ones that built compliance, explainability, and human-review checkpoints into the system from day one rather than trying to bolt governance on after a pilot succeeds technically but fails an audit.

A useful internal exercise before committing budget to an agentic-AI initiative is to walk through a short set of readiness questions with both the technology and compliance teams in the room together, rather than sequencing one after the other: Does this workflow already have a clear, measurable definition of a good outcome? Is there an existing human-review structure the agent can slot into rather than one that has to be invented from scratch? What's the maximum-consequence single error the agent could make, and does the proposed permission and escalation design actually bound that consequence? Who, specifically, owns the audit log and the responsibility for reviewing it on an ongoing basis, not just at launch? Institutions that can answer all four clearly before writing code tend to have a much smoother path to a defensible production deployment than those that start with the AI capability and try to retrofit the governance answers afterward.

It's also worth resisting the temptation to treat this as a single, bank-wide initiative rather than a portfolio of individually justified deployments. The functions leading this wave — fraud, compliance, KYC, credit assessment — succeeded as starting points precisely because each one was scoped narrowly enough to have its own clear metric of success. A bank that tries to launch "an agentic AI transformation" as one large program, rather than a sequence of well-scoped deployments each proven on its own merits, risks recreating the same problems that sank many earlier generations of ambitious, loosely-scoped digital-transformation initiatives — high visibility, unclear ownership, and no crisp definition of what success actually looks like until well after the budget is spent.

None of this means moving slowly for its own sake. The competitive dynamics described earlier are real, and an institution that waits for every open question to be resolved before acting risks ceding the platform-level relationships — with vendors like Fiserv and FIS, and with the emerging norms around governance and audit — to competitors who moved first. The more accurate framing is: move decisively, but scope narrowly, govern deliberately, and treat the compliance and audit design as inseparable from the technical build rather than a separate track that catches up later.

Questions People Are Actually Asking About Agentic AI in Banking

In agentic AI payments, what's real, what's still a pilot, and what's hype?

The honest 2026 answer sits in the middle. What's real: agentic systems doing internal, reviewable work — fraud-alert triage, KYC file assembly, compliance case summarization — where a human makes the final call and the agent's contribution is measurable in time saved and cases cleared. What's still pilot-stage: agents handling more of the judgment themselves with lighter human review, and early agent-to-agent payment coordination between institutions. What's still mostly hype: fully autonomous agents independently initiating and settling payments end-to-end with no human checkpoint, or agents negotiating financial products unsupervised. The gap between vendor announcements like agentOS and FIS's Anthropic partnership and what's actually running in production at scale is real, but it's narrowing fast — 2026 is the year the "real" column got noticeably longer than it was in 2024 or 2025.

What is "agentic AI" and how is it different from a chatbot or basic automation?

A chatbot answers questions in a conversation; basic automation executes a fixed, pre-programmed sequence of steps. Agentic AI sits between and beyond both: it's given a goal (say, "resolve this fraud alert") and some tools it's allowed to use (pulling transaction data, checking sanctions lists, escalating to a human), and it plans its own sequence of steps to reach that goal, adapting as it goes rather than following a rigid script. The key differences are autonomy over the how — the agent decides which checks to run and in what order — and the ability to handle cases that don't match a pre-written rule exactly. A chatbot that answers "what's my balance?" isn't agentic. A system that reads a flagged transaction, gathers supporting evidence on its own, and produces a documented disposition is.

What is Fiserv's agentOS and what does it let banks do?

agentOS is Fiserv's operating system for deploying AI agents across banking workflows — a shared platform layer meant to let banks run agentic AI without each institution building its own orchestration, permissioning, and integration stack from scratch. In practical terms, it's the infrastructure that lets a bank plug agents into existing core banking, fraud, and compliance systems in a governed way, rather than treating every agent deployment as a bespoke engineering project. The "operating system" framing is deliberate: Fiserv is positioning it as common ground that different agent use cases and potentially different agent providers can run on top of, which matters most to banks that don't have the in-house resources to build that governance layer themselves.

When is Fiserv's agentOS expected to be widely available?

Fiserv has targeted wide availability for agentOS by August 2026. That timeline puts the platform's broad rollout squarely in the second half of 2026, alongside other major agentic-banking milestones like FIS's Anthropic-powered financial-crimes agent — which is part of why 2026, rather than an earlier or later year, is being treated as the inflection point for agentic AI reaching real scale in banking rather than staying confined to pilots.

What is FIS doing with Anthropic in banking, and which use case did they start with?

FIS has partnered with Anthropic to bring agentic AI capabilities into banking, and chose to begin with a financial-crimes AI agent rather than a customer-facing or marketing-oriented use case. That sequencing is a signal in itself: financial crime detection is a domain with clear, auditable outcomes and an existing human-review structure (investigators, case managers) that an agent can slot into, which makes it a lower-risk, higher-clarity starting point than something like autonomous customer service. It's also a domain banks already invest heavily in staffing, so time saved translates fairly directly into either cost reduction or reallocated analyst capacity toward harder cases.

When is the FIS-Anthropic financial-crimes AI agent expected to reach general availability?

General availability for the FIS-Anthropic financial-crimes agent is planned for the second half of 2026 (H2 2026). That places it on a similar timeline to Fiserv's agentOS wide-availability target, reinforcing that the second half of 2026 is when agentic AI in banking is expected to move from limited pilots toward broader production deployment across multiple major vendors at once, rather than one vendor moving alone.

What percentage of banking executives expect AI agents to be fully embedded in fraud detection within three years?

Fifty-seven percent of banking executives surveyed expect AI agents to be fully embedded in risk, compliance, audit, and fraud detection within three years. That figure describes a majority of bank leadership already planning around agentic AI as a near-term operational reality in these functions specifically, rather than a distant possibility — which lines up with why fraud and financial-crime use cases are the ones vendors like FIS chose to lead with.

What percentage expect broad adoption in credit assessment and loan processing?

Fifty-six percent of banking executives expect broad adoption of AI agents in credit assessment, loan processing, and KYC within three years — nearly matching the 57% figure for risk, compliance, audit, and fraud detection. Together, these two numbers suggest bank leadership sees roughly the same three-year adoption horizon across both the "catch bad actors" side of the business (fraud, financial crime) and the "onboard and assess good customers" side (credit, KYC), rather than expecting one to lag the other significantly.

Can an AI agent actually initiate a payment on a person's behalf?

Technically, yes — an agent with the right permissions and tool access can initiate a payment instruction. Whether that's happening at meaningful scale in 2026 is a different question, and the honest answer is: mostly not yet, and where it exists it's typically bounded by strict limits (pre-approved payees, capped amounts, or a human confirmation step before funds actually move). The pattern across this wave of banking-AI deployment is that agents are trusted first with the preparation work around a payment — verification, compliance checks, fraud screening — while the final authorization step stays human or is governed by tightly scoped, pre-agreed rules rather than open-ended agent discretion.

What does "agent-mediated" payment mean compared to a human-initiated payment?

A human-initiated payment is one where a person directly decides to send money and triggers the transaction, even if software executes the mechanics. An agent-mediated payment is one where an AI agent, acting on a person's or business's standing instructions or goals, decides when and how to execute a payment as part of a broader task — for example, an agent managing a business's accounts payable that decides which invoices to pay and when, within budget and approval rules it's been given. The distinction matters for liability, dispute resolution, and regulation: who is accountable when an agent — not a person in the moment — makes the specific decision to move money is exactly the kind of open legal question regulators are still working through.

How could agentic AI orchestrate an entire cross-border payment, from initiation to compliance checks?

In principle, an agent could take a cross-border payment request and handle the full chain: verifying payer and payee details, running sanctions and AML screening, selecting the routing and FX conversion, generating the compliant message format, and monitoring settlement — escalating to a human only where something doesn't clear automatically. This is closer to the pilot-and-hype end of the spectrum than the "real today" end: individual pieces (compliance screening, message formatting) are further along than fully autonomous end-to-end orchestration, largely because cross-border payments touch multiple jurisdictions' regulatory regimes simultaneously, which is exactly the kind of legal complexity that industry commentary points to as the current brake on full agentic autonomy in payments.

What is the biggest barrier to adoption of agentic AI in payments — technology or regulation?

Both the IMF's research and broader industry commentary converge on the same answer: regulation and legal frameworks, not the underlying technology, are now the main barrier. The core AI capability to plan and execute multi-step financial tasks has arrived faster than the legal clarity around questions like liability for agent errors, required human-review thresholds, and cross-border regulatory consistency. That's a meaningful shift from a few years ago, when "the model isn't good enough yet" was still a legitimate objection — in 2026, the more common blocker is "we're not yet sure who's liable, or what the compliant guardrails need to look like."

What does "human-in-the-loop" mean in the context of agentic AI banking systems?

Human-in-the-loop means the AI agent does the analysis, gathers evidence, and proposes a decision or action, but a person reviews and approves it — especially for higher-stakes or lower-confidence cases — before it's finalized. It's the design pattern underpinning almost every credible agentic-banking deployment described in 2026 coverage: the agent compresses the time-to-decision-ready-case, while a human retains final authority, particularly on financial-crime dispositions, credit decisions, and anything with direct customer or regulatory impact. It's less about distrust of the AI and more about matching oversight to the actual stakes of a given decision.

Will agentic AI systems be allowed to make final credit decisions without human review?

Not broadly, at least not yet and not without significant guardrails — the current trajectory described across this research is toward AI agents handling more of the assembly and analysis work in credit assessment (pulling financial data, checking documentation completeness, flagging risk factors) while a human or a tightly governed automated policy makes the final call, particularly on adverse decisions that carry legal disclosure obligations. Full autonomous credit decisioning without any human or rules-based checkpoint sits closer to the hype end of the spectrum than to what's shipping in 2026.

How are banks using AI agents in know-your-customer (KYC) processes?

Banks are using AI agents to assemble KYC files automatically — pulling submitted identity documents, cross-checking them against sanctions and politically-exposed-persons lists, verifying address and beneficial-ownership details, and flagging any gaps or inconsistencies — so that a human reviewer receives a decision-ready package rather than a blank onboarding case. This is one of the clearest "real, not hype" use cases in this wave precisely because KYC has well-defined data requirements and an existing compliance-review structure the agent slots directly into, and because faster onboarding has an obvious, measurable business benefit in reduced customer drop-off.

What risks does agentic AI introduce into fraud detection and financial-crimes compliance?

The core risk is that an autonomous system making judgment calls in a heavily regulated domain needs a documented, explainable rationale for every decision — and if the audit trail, logging, or explainability isn't built in from the start, a bank can end up with a system that works well operationally but fails a regulatory exam. Other real risks include over-reliance on the agent for edge cases it wasn't designed to handle well, false confidence in agent outputs that weren't actually reviewed carefully, and the possibility that an agent's own reasoning process becomes a new attack surface if bad actors learn to craft inputs designed to mislead it.

Who is liable if an AI agent makes an erroneous or fraudulent payment?

This is precisely the kind of open legal question that both the IMF and industry commentary point to as the current brake on faster agentic-AI adoption in payments — liability frameworks haven't fully caught up to autonomous agent decision-making. In practice, banks deploying these systems today are managing that uncertainty by keeping humans in the loop on higher-stakes decisions and maintaining detailed audit logs of what the agent did and why, so that if something goes wrong there's a clear record to establish what happened — even though the broader legal question of where liability ultimately sits between bank, vendor, and customer is still being worked out.

How is agentic AI different from the robo-advisors already used in wealth management?

Robo-advisors are largely rules-based or model-driven portfolio allocation tools operating within a narrow, pre-defined scope — rebalance a portfolio according to a risk profile, for example. Agentic AI is broader and more dynamic: it can plan multi-step tasks across different systems, reason about unstructured information (like a flagged transaction's free-text memo or inconsistent KYC documents), and adapt its approach case by case rather than following one fixed allocation logic. Robo-advisors were an early, narrow precursor to what agentic AI is now attempting across a much wider set of banking functions — fraud, compliance, credit, and customer service — with more autonomy over process, not just outcome.

Can an AI agent negotiate a loan or financial product on a customer's behalf?

Not in any way that's currently well-established or widely deployed in 2026 — this sits toward the hype end of the spectrum described in this wave of coverage. The nearer-term, more grounded version of agentic AI in lending is an agent that assembles and analyzes a credit file faster, flags what's missing, and surfaces options for a human loan officer or the customer to choose between — not one that autonomously negotiates terms. Product negotiation involves regulatory disclosure requirements and often genuine human judgment about a customer's specific circumstances that current agentic systems aren't positioned to fully own without oversight.

What guardrails are banks putting in place before deploying AI agents at scale?

The consistent pattern across this wave is: defined permission boundaries (what data and systems the agent can touch), detailed audit logging (what it did and why, for every action), human review checkpoints calibrated to stakes (higher-value or lower-confidence cases route to a person), and starting deployments in internal, reviewable workflows before extending toward higher-autonomy or customer-facing use cases. None of this is optional overhead bolted on after the fact — for the deployments described as credible in 2026 coverage, it's treated as the actual design requirement that separates a production-ready banking agent from a general-purpose AI demo.

How do regulators view autonomous AI agents making financial decisions?

Cautiously, and the IMF's dedicated 2026 research note on agentic AI reshaping payments is itself a signal of that caution — when an institution like the IMF publishes focused research on a technology trend, it's typically because policymakers see systemic questions worth getting ahead of, not because the trend is already fully understood and settled. Industry commentary consistently frames regulatory and legal clarity, not model capability, as the current bottleneck, which suggests regulators are still working through core questions — acceptable autonomy levels, liability, required explainability — rather than having settled on a clear framework banks can simply build to.

What does the IMF's 2026 research say about agentic AI reshaping payments?

The IMF's April 2026 research note, part of its IMF Notes series, examines how agentic AI is expected to reshape payments — treating it as a matter significant enough for focused macro-financial research rather than leaving it purely to vendor announcements and trade press. Its existence underscores that agentic AI in payments is being taken seriously at a systemic level, addressing questions like how autonomous payment-related decision-making could affect financial stability, oversight, and cross-border coordination as adoption scales, alongside the operational questions banks themselves are focused on.

How might agent-to-agent payments work?

Agent-to-agent payments describe a scenario where an AI agent representing one party transacts directly with an AI agent representing another party — for example, a procurement agent negotiating and paying a supplier's billing agent — without a human initiating each individual transaction. This remains firmly in pilot-and-emerging territory in 2026 rather than mainstream production use: the coordination, authentication, and trust mechanisms needed for two autonomous systems from different organizations to transact safely are still being worked out, which is part of why blockchain-based and other verifiable-identity protocols are drawing attention as a possible foundation for this kind of exchange.

What blockchain-based protocols are emerging for agent-to-agent payments?

Blockchain and distributed-ledger approaches are being explored as a foundation for agent-to-agent payments because they offer a way to verify identity, authorization, and transaction finality between two autonomous systems that don't inherently trust each other and may belong to different organizations — properties that traditional payment rails weren't originally designed to provide at the agent level. This remains an emerging, early-stage area rather than a settled standard; specific protocol names and adoption figures weren't part of the grounded research behind this piece, so it's fairer to describe the direction of exploration than to claim any particular protocol has become dominant.

Is agentic AI in banking mostly still in pilot stage, or already in production in 2026?

It's genuinely both, split by function. Internal, reviewable workflows — fraud-alert triage, KYC file assembly, financial-crimes case support — are moving from pilot into real production in 2026, reinforced by the fact that major vendors like Fiserv (agentOS) and FIS (with Anthropic) are targeting broad or general availability within this same year. Higher-autonomy or customer-facing use cases, and anything involving autonomous payment initiation or agent-to-agent transactions, are still substantially in pilot or earlier stages. The honest framing for 2026 is "moving decisively from pilot to production in specific, well-bounded functions," not "fully arrived across banking."

How are banks measuring return on investment from agentic AI deployments?

The functions getting agentic AI first — fraud detection, compliance, KYC, credit assessment — all have pre-existing, well-understood metrics: cases cleared per analyst, time-to-decision, false-positive rates, onboarding drop-off, cost per KYC file. That's part of why these functions were chosen as starting points rather than more diffuse use cases like general customer engagement — a bank can measure agentic AI's ROI against a baseline it already tracks, rather than needing to invent a new success metric from scratch. Executive confidence reflected in the 57%/56% adoption-expectation figures likely reflects that measurability as much as it reflects raw enthusiasm for the technology itself.

What happens if an AI agent is manipulated or hacked to authorize fraudulent transfers?

This is one of the more serious risks named in this wave of coverage, and it's a genuinely new category of exposure: an agent's reasoning process becomes an attack surface in a way a traditional rules engine's rigid logic generally isn't. It's a core reason banks are keeping human review checkpoints on higher-value transactions and maintaining detailed logging of an agent's reasoning and actions — so that manipulation attempts are more likely to be caught either by the review step itself or, after the fact, by an audit trail detailed enough to reconstruct what happened and close the gap the manipulation exploited.

How does agentic AI affect the jobs of compliance and risk-management staff at banks?

The pattern in this wave points toward role change rather than wholesale replacement, at least for now: agents take over the repetitive assembly and first-pass analysis work (pulling documents, cross-checking lists, drafting case summaries), while human staff shift toward reviewing agent-prepared cases, handling the genuinely ambiguous ones the agent escalates, and overseeing the guardrails and audit processes that keep the system accountable. That's a different day-to-day job than doing the legwork manually, and it likely means fewer people are needed to handle the same case volume over time — but the research behind this piece doesn't support a specific job-loss figure, so it's more accurate to describe the shift in the nature of the work than to project headcount numbers.

Which financial-services functions are banks prioritizing for agentic AI first?

Risk, compliance, audit, fraud detection, credit assessment, loan processing, and KYC are the functions named most consistently across this wave — and not by accident. They share three traits: high labor intensity, well-defined success metrics, and an existing human-review structure the agent can slot into without requiring a new governance model built from scratch. FIS's decision to begin its Anthropic partnership specifically with a financial-crimes agent, rather than a customer-facing use case, is a direct example of this prioritization logic in action.

Do consumers know when they are interacting with an AI agent instead of a human bank employee?

This specific research pass didn't surface concrete data on consumer awareness or disclosure practices, so it would be inaccurate to state a figure here. What can be said generally is that as agentic AI moves deeper into customer-facing functions — which, per this wave's evidence, is happening more slowly and cautiously than in internal functions like fraud and compliance — questions about disclosure, consent, and consumer understanding become more pressing, and are likely to intersect directly with the same regulatory and legal frameworks that industry commentary already flags as the current bottleneck on faster agentic-AI adoption in payments overall.

What legal and regulatory constraints are slowing agentic AI adoption despite the technology being ready?

The clearest constraints named across this research are unresolved questions of liability (who's accountable when an autonomous agent's decision goes wrong), the required level of human review for different classes of financial decision, and explainability standards sufficient to satisfy regulators used to reviewing human-made or rules-based decisions rather than AI-agent reasoning. The IMF's decision to dedicate 2026 research specifically to this question, and the consistent framing across industry commentary that regulation — not capability — is now the limiting factor, both point to the same conclusion: the legal scaffolding hasn't caught up to what the technology can already do.

How is Accenture's research characterizing bank readiness for agentic AI in 2026?

The Accenture-linked survey data cited in this wave shows a banking-executive population that is confident about the destination — 57% expecting full embedding in risk, compliance, audit, and fraud detection within three years, and 56% expecting the same in credit assessment, loan processing, and KYC — which reads as high strategic conviction about where agentic AI is headed in the near term. That's a meaningfully different signal than executives merely being curious about a new technology; it describes leadership already planning budgets, staffing, and technology roadmaps around a three-year adoption horizon.

Can agentic AI systems be audited the same way traditional banking software is audited?

Not identically, and that gap is part of why regulation is described as the current bottleneck rather than technology. Traditional banking software follows deterministic rules that are relatively straightforward to trace and audit — this input produced this output because of this specific rule. Agentic AI systems reason across evidence in ways that are less mechanically traceable, which is exactly why detailed logging of what data an agent accessed and what rationale it produced has become a standard design requirement rather than a nice-to-have. Banks and regulators are actively working out what an adequate audit standard for agentic systems looks like, rather than simply applying the old standard unchanged.

What data-privacy issues arise when AI agents access a customer's full financial history to act on their behalf?

Giving an agent broad access to a customer's financial history to do its job well — assembling a KYC file, assessing credit risk — inherently expands the amount of sensitive data flowing through a system that also needs to be permissioned, logged, and secured against misuse or breach. This is a genuine tension: the more data an agent can see, the better its judgment tends to be, but also the larger the potential blast radius if that access is compromised or exceeds what's actually needed for the task. Institutions taking this seriously typically pair agent deployments with the same rigor they'd apply to any security and compliance review of a new system with access to regulated customer data.

How might agentic AI change customer service in retail banking?

Based on this wave's evidence, customer-facing agentic AI is moving more cautiously than internal functions like fraud and compliance — which makes sense, since customer-facing mistakes are immediately visible and reputationally costly in a way an internal case-triage error isn't. The more likely near-term pattern is agents supporting human customer-service staff by preparing account context, summarizing a customer's history, and drafting responses for review, rather than fully autonomous customer-facing agents making unsupervised decisions about a customer's account. Full autonomy in this specific function looks closer to a multi-year trajectory than a 2026 reality.

Are there real-world cases of agentic AI already causing errors or losses in financial services?

This research pass didn't surface specific documented cases of agentic-AI-caused errors or losses in banking, so it wouldn't be accurate to cite one. That absence shouldn't be read as proof that no such incidents exist — reporting on AI failures in regulated industries often lags the deployments themselves, and this is still a young enough part of the adoption curve that comprehensive incident reporting hasn't caught up. It's a reasonable part of why banks are moving carefully, with human review checkpoints on higher-stakes decisions, rather than treating early success in pilots as proof the risk of errors has been eliminated.

How does agentic AI adoption in banking differ between the US and other regions?

Based on the reporting available in this research pass, the US is where the concrete, named developments are concentrated — Fiserv's agentOS, the FIS-Anthropic partnership, and the executive-sentiment survey data all trace back to US-centric coverage. Public reporting specific to the UK, UAE/Dubai, Australia, Germany, and Europe/France on agentic AI in banking specifically is thin so far in this pass, and the same is true for China. That doesn't mean adoption elsewhere isn't happening — global banking-technology vendors typically expand platforms like agentOS well beyond their launch market — but the documented 2026 story right now is substantially a US story.

What skills do bank employees need to develop to work alongside AI agents?

The clearest implication from this wave is that reviewing and validating AI-agent output becomes a core skill, distinct from doing the underlying task manually — a compliance analyst reviewing an agent-assembled case file needs to know how to spot where the agent's reasoning might be wrong or incomplete, which is a different skill than compiling the file from scratch. Beyond that, familiarity with how these systems are governed (permission boundaries, escalation triggers, audit requirements) is likely to matter more for staff working near agentic systems, even if they're not the ones building or maintaining the AI itself.

Will agentic AI reduce the number of jobs in banking operations and compliance?

The research behind this piece doesn't include a specific job-loss projection, so any exact figure would be invented rather than grounded. What the evidence does support is a change in the nature of work in these functions — agents taking over repetitive assembly and first-pass analysis, humans shifting toward review, escalation handling, and governance oversight — which plausibly means fewer people are needed to process the same volume of cases over time, consistent with how automation has generally played out in banking operations historically. Whether that nets out to fewer total roles, redeployed roles, or roles absorbing higher case volumes likely varies significantly by institution and function, and isn't something this specific research base can responsibly quantify.

Want results like this?

Keep reading