Image related to The delegation question: What financial institutions must decide before AI acts

The delegation question: What financial institutions must decide before AI acts

Since AI became a key fixture in their operations, most financial institutions have been attempting to answer the key question of whether it can be used responsibly.  

To address it, model risk frameworks, fairness testing and explainability standards have been introduced, giving institutions increasingly established ways of governing AI. Agentic AI, however, introduces some thornier issues. 

What decisions and actions are institutions prepared to delegate to AI agents? Under what conditions are they willing to do so? And how do they remain accountable if an agent gets something wrong? 

The distinction between decisions and actions is not one of semantics. Governance for AI that produces an output looks markedly different from governance for AI that takes an action. 

Consider the spectrum institutions are already moving along: a system that assists a human, one that recommends a course of action, one that makes a decision and one that acts autonomously on that decision. 

Each step changes what governance has to supply. Assistance requires quality control, recommendation means calibrated trust in the model's judgement and decision-making demands clear decision rights and defined boundaries. 

Action requires all of that in addition to real-time escalation, an evidentiary trail and a credible answer to who is accountable when the system moves faster than anyone can review it. 

Financial crime compliance illustrates this shift clearly. While screening and AML systems have long assisted analysts by surfacing alerts, it is now not uncommon for AI to recommend dispositions and resolve defined categories of alerts, or support downstream investigative workflows. 

Judgement call

As systems move from informing decisions towards executing them, fairness and explainability remain important. But another concern becomes harder to avoid, which is how much judgement the institution has deliberately decided to hand over. 

Regulatory frameworks are beginning to reflect this shift, even if the delegation question itself remains unsettled. Singapore's proposed Guidelines on AI Risk Management explicitly address AI Agents, proposing that governance should scale with an application's materiality and the autonomy granted to it, rather than applying uniform controls everywhere. [1

The same risk-based thinking is visible elsewhere. The EU AI Act applies stronger obligations to defined high-risk uses, [2] while the Financial Stability Board’s 2026 consultation proposes proportionate AI governance based on the risks and materiality of individual use cases, while also considering emerging forms such as Agentic AI. [3]  

Together, they point towards a broader principle, which is that as AI gains greater authority to decide and act, governance should scale with the consequences. 

None of this should be read as an argument for tighter control everywhere. Governance that treats a low-stakes internal automation with the same rigour as an autonomous action affecting a customer or a regulatory filing will slow adoption without reducing risk where it matters. 

The more useful question is not how much oversight AI needs in general, but which specific decisions warrant which specific controls – and who at the institution is prepared to own that answer. 

That is the decision now facing senior leaders across risk, compliance and technology; not whether AI can be trusted, but which decisions they are willing to trust it with, and the evidence they will need to defend that choice in the future.

About the author

This thought leadership article was written with our partners SilentEight. SilentEight are a leading provider of AI agents built for financial institutions to assit with financial crime compliance.

SilentEight logo