Much of the market conversation around agentic AI still focuses on the agent itself, be that the use case, the interface or the promised productivity gains. In banking, that is only part of the story.
The harder question is whether the architecture beneath those systems can support autonomy in a way that is traceable, governable and resilient. Many institutions have demonstrated promising pilots. Far fewer can show, in real time, how an autonomous action can be traced to a data source, a model version, a control point or an accountable owner.
This architectural challenge will separate banks that compound value from AI and those that add complexity at a pace that outstrips their ability to apply the necessary controls. Importantly, this is also a problem that cannot be solved post-deployment. Suitable architecture must be engineered in from the outset.
The AI-enabled bank will be defined less by how many agents it deploys than by whether its architecture can support autonomy safely at scale
Most institutions today sit somewhere between two broad architectural postures.
|
AI as overlay |
AI by design |
|---|---|
|
Here, agents are layered on top of existing systems to accelerate specific processes such as reconciliation, fraud triage or customer servicing. The gains can be real and the time to value fast. But these systems inherit the weaknesses of systems sitting beneath them. Fragmented data, uneven controls and brittle integrations all limit how far autonomy can safely extend. In this model, capability typically scales faster than confidence. |
Here, data flows, controls and workflows are designed with autonomy in mind. Orchestration layers manage hand-offs and policy enforcement. Human checkpoints are designed into decision paths. Here, the question is not simply what can be deployed, but under what conditions intelligent systems can be trusted. |
The distance between these two postures is not primarily a technology gap, it is an architectural one. Closing it requires deliberate sequencing across four layers that will help determine whether agentic capability strengthens resilience or quietly introduces new operational and control risks.
Each of the four layers above addresses risk inside a given system. Yet one of the more important challenges facing institutions sits between systems rather than within them.
As agentic capability begins to span risk, operations, customer servicing and liquidity workflows, interaction effects – so-called ‘emergent behaviours’ – can arise. Systems that function acceptably in isolation may, in combination, generate feedback loops, correlated actions or self-reinforcing behaviours that no individual model would have produced on its own.
Banking institutions therefore need to think beyond model-by-model validation towards scenario testing across agent combinations, cross-agent monitoring for correlated outputs and ‘circuit breakers’ that can pause coordinated activity when unexpected patterns emerge. This remains an emerging discipline for many firms. Yet it is likely to become much more important as autonomous systems move from single use cases to enterprise workflows.
The challenge is not only validating individual models. It is stress-testing what happens when they act together.
Use this diagnostic to locate your institution and identify what the next step requires:
|
Stage |
Model |
Diagnostic signal |
Primary risk |
|---|---|---|---|
|
1. |
AI |
Agents deployed on legacy systems; governance largely point-in-time and review-based |
Underlying fragility inherited from existing systems; explainability weakens as scale grows |
|
2. |
Governed Deployment |
Human-in-the-loop (HITL) checkpoints defined; data lineage partially mapped; compliance and review processes integrated |
Interaction risk between agents remains under-modelled; monitoring is reactive rather than anticipatory |
|
3. |
Architecture-native AI |
Data estate designed for orchestration; controls embedded in workflows; active cross-agent monitoring |
Requires sustained investment, operating-model discipline and organisational change to maintain |
As institutions look to optimise their architectural design approach to autonomy, there are several questions that leaders within these organisations should ask themselves.
Building an AI-enabled bank is not simply a matter of adding a new technology layer. Institutions that treat agentic AI as an overlay may accelerate capability, but they also risk carrying forward fragilities that were otherwise manageable in a low-autonomy world. In contrast, those that build the architecture first are more likely to find that governance becomes an enabler of scale rather than a brake.
The AI-enabled bank will be definedless by how many agents it deploys than by whether its architecture is ready for them.
References
1. Our UK AI Hub provides space for Deloitte’s topic experts to publish their perspectives on the major transformation questions raised by AI adoption in banking and financial services: how institutions modernise their technology estates, redesign operating models, reshape workforces, strengthen governance and scale AI safely and effectively. Regulation is central to that agenda and is a substantial and rapidly evolving topic in its own right. The regulatory implications of AI depend heavily on use case, institution, type of customer or client affected, the jurisdictions involved and the ways in which technology is designed, deployed and controlled. For that reason, this series of article focuses on the transformation themes at hand. For detailed information on regulatory considerations related to AI, we direct readers to our European Centre for Regulatory Strategy (ECRS) for the latest regulatory developments in AI. https://www.deloitte.com/uk/en/blogs/ecrs.html