Artificial intelligence has had a place in finance for years. Banks, insurers, asset managers and fintech firms already use AI for fraud checks, customer service, risk analysis and document review. But a new phase is now taking shape.
AI agents can do more than answer a question or prepare a report. They can take a goal, find the needed data, use software tools, make a plan and carry out several steps on their own. This gives financial firms a new way to automate work across research, compliance, treasury, payments and other areas.
The shift is important because finance deals with money, private data and strict rules. An AI system that gives a poor answer can cause a problem. An AI agent that has permission to act can turn that problem into a real transaction.
That is why the key issue in 2026 is not only how smart an AI agent can become. It is also how much power the agent should have, what limits should apply, and how a firm can stop or review its actions.
From AI Assistant to AI Agent
A normal AI assistant mainly responds to a person. An agent can take a larger task and carry out several steps with less direct human input.
For example, a finance worker may ask an agent to review a group of companies. The agent can collect financial data, check company records, compare results, prepare a summary and place the findings in a report.
The same idea can apply to a treasury team. An agent could check cash levels, review expected payments, spot a possible cash gap, assess permitted funding choices and prepare a transfer for approval.
This difference matters. The AI is no longer just a source of information. It becomes part of the work process.
Google Cloud now offers Gemini Enterprise for Financial Services, with a Financial Research agent, more than 50 financial skills and links to major financial data sources. The company says its system can support tasks such as market analysis, KYC research and portfolio risk work. Its Financial Research agent also provides confidence scores, methods, data snapshots and source citations for audit use.
Anthropic has also released ten agent templates for finance. These cover tasks such as pitchbook creation, KYC file checks and month-end close. Its finance platform also connects with data providers such as Moody’s, FactSet, PitchBook, LSEG and others.
These moves show that agents are moving closer to real financial work.
Where Finance Can Use AI Agents
Financial firms have many processes that suit agent-based automation.
Research is one clear example. Analysts often spend hours on reports, filings, market data and company documents. An agent can collect this material and create a first research view much faster.
Compliance is another area. KYC teams must review large amounts of customer material. An agent can sort documents, find missing details and flag cases that need more attention.
The same model can help with anti-money-laundering work. An agent can collect transaction details, compare them with known risk patterns and prepare evidence for an investigator.
Back-office finance also has strong potential. Month-end close, reconciliation, invoice checks and report preparation contain many repeat steps. An agent can handle routine work while a finance professional deals with unusual cases.
Treasury may become one of the most important areas. A treasury agent could monitor cash across many accounts, review expected payments and identify a need for a transfer. With strict limits, it could prepare or execute a transaction without a person handling every step.
KPMG’s 2026 Global AI in Finance survey found that active AI use across the finance function had more than doubled in two years. The research covered 1,013 senior finance leaders across 13 sectors and 20 countries. KPMG also found a gap between firms that gain value from AI at scale and firms that continue to invest without the same level of business impact.
The Main Problem Is Control
The biggest concern with financial agents is not simply a wrong answer.
A chatbot may give an incorrect answer that a person can correct. An agent may have access to a bank account, payment system or internal database. If it makes the wrong choice, the result can affect real money.
This creates a new form of risk.
A person may tell an agent to manage a payment process. The agent then sees a request, checks available data, chooses a payment path and sends the transaction. If its authority is too broad, one mistake can have a direct financial effect.
There is also the risk of a chain reaction. One agent may pass its result to another agent. That second agent may use the result to make another decision. Several small errors can then form one large problem.
For this reason, financial institutions need controls at the point where an agent takes action, not only after the task is complete.
The Rise of Runtime Controls
One of the most important developments in 2026 is the focus on runtime safeguards.
In July 2026, the Monetary Authority of Singapore and industry partners published the SAFR framework, or Safeguards for Agentic Finance at Runtime. The framework focuses on real-time controls that keep AI agents within set mandates, policies and risk limits.
The idea is simple.
Before an agent performs an important action, the system should check whether that action is allowed.
For example, a treasury agent may have permission to make payments below $100,000. If it creates a $250,000 payment, a control system can block the action or send it to a person for approval.
This approach is different from a system where people review the agent only after the transaction has taken place.
The Bank for International Settlements has also highlighted SAFR. In a September 2026 speech, the BIS said runtime safeguards should cover an agent’s identity and authority, checks on actions before execution and a clear audit record.
This points toward a new model for financial AI: give the agent freedom inside a clearly defined boundary.
Give Each Agent a Clear Identity
A financial agent should not simply use a worker’s account and permissions.
It should have its own identity.
A bank could, for example, give a treasury agent permission to read cash balances, create a payment and execute payments below a fixed value. The same agent could have no right to add a new beneficiary or change account details.
This creates a clear record of what the agent did.
It also follows a basic security idea: give a system only the access it needs.
Such controls become even more important when one company has dozens or hundreds of agents. Without clear identities and permissions, it can become difficult to know which system took an action and whether that action was allowed.
Human Control Will Change
The phrase “human in the loop” can sound simple, but it may not work for every financial task.
If a person must approve every small action, the speed benefit of an agent disappears.
A better model can divide work by risk.
An agent could handle low-risk tasks on its own. Medium-risk tasks could require review. High-risk actions could require direct approval from an authorised employee.
This does not remove human control. It moves human attention toward the decisions that need it most.
For example, an agent could automatically reconcile routine payments. A payment that breaks a policy limit could then go to a finance manager.
The person does not need to watch every routine action. The system instead sends attention to the exceptions.
Audit Records Become Essential
Financial institutions already need strong records for many decisions. Agent-based systems make this need even greater.
A useful audit record should show what the agent saw, what tools it used, what decision it made, which rules it checked and what action followed.
It should also show who had authority over the agent.
Google’s Financial Research agent, for example, includes data snapshots, confidence scores, methods and source citations. These features can help firms understand how a result came about and provide evidence for later review.
This matters because a simple final answer is not enough when an AI system has a role in a regulated process.
A bank may need to explain not just what happened, but why it happened.
Regulators Are Paying Close Attention
Regulators and global financial bodies now treat AI as both a technology issue and a financial stability issue.
In June 2026, the Financial Stability Board released a consultation on sound practices for responsible AI use. Its framework contains 12 practices that cover organisation-wide governance and different stages of AI development and use. The FSB said the final report is due in October 2026.
The concern goes beyond one bank.
If many financial firms rely on similar AI models, data sources or technology providers, their systems could react in similar ways during a period of market stress. This could create risks that are larger than the problems inside one institution.
The Cambridge Centre for Alternative Finance also released its 2026 Global AI in Financial Services Report with support from groups such as the BIS, IMF and World Economic Forum. The report looks at AI use, impact and risk across financial services and includes views from financial firms, technology providers, regulators and users.
Banks Are Building Stronger AI Boundaries
Recent bank activity also shows that security controls are becoming part of AI deployment.
JPMorgan, for example, has expanded its use of Anthropic’s Claude while also adding stronger limits and a separate environment called Devspace. Recent reports say the bank has placed a $2,000 monthly Claude spending limit on selected employees and is using Devspace as an isolated environment for safer AI use. Around 8,000 of its 65,000 technology workers have Claude licences, while fewer than 2,000 are part of the Devspace rollout.
This example is useful because it shows that AI scale and AI control have to grow together.
More access does not simply mean more productivity. It also means more need for permission rules, isolation, monitoring and cost controls.
The Future of Finance May Be Bounded Autonomy
The next stage of financial AI may not be full autonomy.
It may be bounded autonomy.
Under this model, a person sets the goal and the limits. The agent then carries out the work inside those limits. A separate policy layer checks important actions. High-risk cases go to a person. Every major step has an audit record.
This structure can allow finance teams to gain speed without giving an AI system unlimited authority.
It also changes how firms should think about AI projects. The question is no longer only, “Can this model do the task?”
A better question is, “Can this task be given to an agent with clear limits, reliable data, strong controls and a clear path back to a person?”
That question will matter across banking, insurance, asset management, payments and corporate finance.
What Comes Next
AI agents are now moving from simple assistance toward real work inside financial systems. Research, compliance, treasury, payments, reconciliation and other processes can all benefit from this change.
But the value of an agent will depend on more than model quality.
It will depend on the quality of its data, the tools it can use, the permissions it receives and the controls around each action.
The most important change may therefore be less about smarter AI and more about safer delegation.
Finance has always worked through rules, limits and accountability. AI agents now have to fit into that structure.
The likely path is clear: agents will receive more responsibility, but that responsibility will come with stronger identity controls, policy checks, audit records, human escalation and emergency stop mechanisms.
The goal is not to remove people from finance. It is to let software handle more routine work while people retain authority over the decisions that carry the greatest risk.
That balance — more automation without the loss of control — may define the next phase of AI in financial services.
Also Read – How to Research a VC Before Taking Their Money