Your Bank’s AI Agent May Need a Permission Slip

AI-agents-banks-permission-slip

Financial regulators and banks have spent years catching artificial intelligence agent mistakes after the fact, tracing errors and assigning blame once the money has already moved.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Singapore’s central bank wants to get there first. The Monetary Authority of Singapore is asking banks to check an agent’s identity, permissions and risk limits before it executes a payment or trade, not after.

    MAS published the approach in a July 3 white paper called “Safeguards for Agentic Finance at Runtime,” or SAFR, developed with eight financial and payments companies, including Ant International, Circle, HSBC, JPMorganChase, Manulife, Mastercard, OCBC and Visa.

    The architecture runs on four components, including an identity layer confirming what an agent is and what it is authorized to do, a repository of the specific rules that apply to it, an engine that checks each proposed action against those rules, and an audit log that records every decision. Every action resolves to one of four outcomes. It executes automatically, proceeds while flagged for review, pauses for a human to approve, or gets denied outright, according to the paper.

    MAS confirmed in an Aug. 5 written parliamentary reply that agentic AI falls within the scope of its broader AI risk management guidelines. Those guidelines are being finalized under a principles-based approach rather than fixed technical rules.

    SAFR itself does not constitute binding regulatory guidance, the white paper said.

    Other Regulators Are Building Their Own Version of This Model

    Singapore is not alone in facing this problem, although it has moved further toward a concrete technical answer than most peers.

    The United Kingdom’s Financial Conduct Authority, the country’s main regulator for banks, insurers and payments firms, has taken a more cautious approach so far. In a June 24 speech, CEO Nikhil Rathi said legislation “will never keep up” with AI and that the regulator must shift toward “stewardship,” intervening on judgment rather than waiting for detailed rules in every case.

    “In some areas, we will still need detailed rules,” Rathi said. “But in others, traditional rule-making simply won’t work anymore.”

    More than 80% of U.K. financial services firms are already using or adopting AI, Rathi said in his June remarks. The FCA is separately exploring whether agentic AI could act as a “first responder” to speed up its own market monitoring.

    Hong Kong has no centralized framework governing AI in financial services, relying instead on voluntary governance frameworks, according to law firm Mayer Brown.

    The European Union’s supervisory authorities have called only for “enhanced governance” of frontier AI models used in finance, Mondaq reported Friday (Aug. 7), a general statement rather than an operational framework comparable to MAS’ runtime checkpoints.

    U.S. financial institutions are approaching the same problem from the industry side rather than waiting for a regulator to define it.

    Fiserv launched an operating system called agentOS in May, built to let banks deploy and govern AI agents across core banking, payments and servicing workflows from a single environment, with kill switches, human-in-the-loop controls and audit trails built in. Six banks helped build it, two institutions are running it in beta, and OpenAI and AWS joined as collaborators.

    The instinct behind the build mirrors what MAS is proposing. Check an agent’s authority before it acts, not after.

    The volume of decisions AI agents can generate is starting to outpace what compliance teams can review manually. Financial executives feel that strain already, as 47% cited overlapping regulatory requirements as a top operational challenge, and 46% reported increasing sophistication in fraud schemes, according to the PYMNTS Intelligence report “2025 State of Fraud and Financial Crime in the United States.”

    For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.