Central banks are beginning to reconsider how financial institutions should control artificial intelligence systems capable of acting without continuous human approval.

The most explicit warning came from Sarah Breeden, the Bank of England’s Deputy Governor for Financial Stability, during the European Central Bank Forum on Central Banking in Sintra on 30 June 2026.

Breeden argued that financial regulation was largely designed for institutions in which people remain responsible for making or approving consequential decisions. Agentic AI changes that assumption because an autonomous system can plan a sequence of actions, interact with external systems and execute decisions at machine speed.

The Bank of England expects such agents eventually to transact for consumers, devise and implement trading strategies and identify combinations of cyber vulnerabilities across complex technology environments. Existing technology-neutral rules may continue to apply, but regulators are questioning whether those rules provide enough visibility, control and accountability when decisions are made autonomously and at scale.

Among the options now being discussed are AI-specific market simulations, stronger recovery requirements, controls embedded in an agent’s objectives and circuit breakers or “kill switches” capable of limiting or stopping activity when autonomous systems behave unexpectedly. These are not yet new regulatory obligations. They are indications of the direction in which financial supervision may develop.

The transition from AI assistance to AI action

Financial institutions have used machine learning for years in areas such as fraud detection, risk modelling, claims processing, customer service and credit assessment.

Generative AI expanded those applications by producing text, code, analysis and recommendations. Agentic AI introduces a more consequential capability: the system can decide what steps are necessary to reach an objective and then perform those steps through connected applications and financial infrastructure. The difference is important. An AI assistant may recommend a portfolio adjustment to an investment manager. An AI agent may analyse the market, select assets, place orders, monitor the result and modify its strategy without requesting separate human approval for every transaction.

A conventional banking chatbot may explain how to make a payment. An agent could identify the product a customer needs, select a merchant, authorise a purchase and initiate the payment.

The Bank of England believes the financial system may therefore become more autonomous much faster than existing supervisory processes were designed to accommodate. Breeden also warned that the pace at which AI systems can complete longer software tasks has accelerated and that recent advances in discovering cyber vulnerabilities demonstrate how quickly capabilities can change.

Adoption is already substantial. More than 75% of UK financial-services firms reportedly use AI in some form, while the European Central Bank says more than 85% of the significant banks under European banking supervision use AI. The European Banking Authority has also reported that approximately 40% of surveyed EU banks are already using general-purpose AI, although many higher-risk applications remain in testing or controlled deployment.

Most current applications are not fully autonomous. The regulatory concern is that the infrastructure, models and organisational experience being built today could allow institutions to move rapidly from AI-supported work to AI-executed decisions.

Why human oversight may no longer be sufficient

Many organisations describe a “human in the loop” as their principal safeguard for AI. That approach is valuable when a system produces a limited number of recommendations that a qualified person can realistically review. It becomes less credible when an agent performs thousands of actions, responds to markets in milliseconds or coordinates several applications across payments, trading, compliance and customer-service systems.

A nominal approval step does not provide meaningful control when the reviewer lacks time, information or authority to challenge the system.
Breeden therefore suggested that more sophisticated governance and accountability mechanisms may be required. The question is no longer only whether a bank has assigned a human owner to an AI model. Regulators also need to know whether the institution and the wider market can observe what autonomous agents are doing and contain their behaviour before it produces systemic consequences. This represents a transition from model governance to action governance.

Traditional model-risk management examines whether a model is accurate, explainable, appropriately validated and used for its intended purpose. Agentic governance must additionally determine what the system is permitted to do, which resources it may access, how much money or data it may control, when it must stop and who can override it.

Autonomous trading could create a new form of market herding

Trading is one of the clearest areas of concern. Financial markets already contain extensive automation. The new risk is not automation itself, but the possibility that many institutions will use similar foundation models, data sources, prompts or agent architectures.

If several agents interpret the same event in a similar way, they may buy or sell simultaneously. During normal conditions this could appear efficient. During stress it could amplify volatility, reduce liquidity and accelerate a market correction before human decision-makers understand what is happening.

The risk could be greater if an agent’s behaviour drifts from its original objective or if several agents learn that similar strategies produce short-term advantages.

Research published by the ECB in May 2026 demonstrated that different AI architectures can create materially different stability outcomes. In its simulations, reinforcement-learning systems displayed strong coordination but could produce extreme redemption behaviour comparable to a bank run. Large language model systems were less coordinated but behaved more heterogeneously and unpredictably. The research suggests that the architecture through which an AI system makes decisions may itself become a financial-stability factor.

Central banks have started building tools to study this behaviour. The BIS Innovation Hub, the Bank of England and the Deutsche Bundesbank launched Project Logos in June. The project will place large-language-model agents in a simulated market as portfolio managers and compare their decisions with those of traditional rules-based systems. Researchers will examine how agents interpret information, allocate capital and respond to constraints, including the conditions under which their decisions become correlated.

This work could eventually support AI-specific stress testing. Instead of testing only whether an individual institution’s model produces acceptable results, authorities could simulate how many autonomous agents interact during a market shock.

Breeden said such simulations could help determine whether safeguards similar to market circuit breakers are needed. These might restrict or stop trading if faulty or misaligned AI systems begin creating disorderly conditions.

The term “kill switch” should not be interpreted as a simple power button attached to every AI model. Depending on the use case, it could mean suspending an agent, revoking its credentials, blocking transactions, reducing its permitted exposure, isolating it from external systems or activating a market-wide control.

The difficult part is not merely creating the switch. It is deciding who may activate it, what evidence is required, how quickly it operates and how essential services continue after the agent is stopped.

Agentic payments raise unresolved questions about consent and liability

Payments create a different set of problems. Today, AI systems generally recommend products while the customer completes the final transaction. Future agents may receive broader authority to shop, subscribe, negotiate or make recurring payments for their users.
This creates practical questions that existing payment controls do not fully answer.

A customer may authorise an agent to “book an appropriate business trip”, but that instruction does not clearly define acceptable airlines, hotels, dates, cancellation conditions or spending limits. The customer may also expect the agent to adapt when circumstances change.
Financial institutions will need ways to translate broad human intentions into enforceable transaction permissions.

Regulators must also determine how disputes are handled when an agent purchases the wrong product, exceeds an expected budget, falls victim to fraud or performs an action the customer did not anticipate.

Responsibility could be distributed among the customer, the bank, the payment provider, the merchant, the AI developer and the organisation operating the agent. A conventional authentication record may show that the agent possessed valid credentials without proving that the customer intended the specific transaction.

The Bank of England has identified secure consent, authorisation for multiple transactions, dispute resolution, liability and interoperability as central questions for agentic payments. It is also working with industry on the next generation of UK retail-payment infrastructure, while HM Treasury intends to consult on how payment-services regulation should adapt to transactions conducted by AI agents.

The interoperability problem is strategically important. Technology companies, banks, payment networks and merchants may each develop their own mechanisms for agents to communicate. Without common standards, the market could fragment into closed ecosystems in which an agent works only with selected platforms and service providers.

Cyber risk is the most immediate concern

Autonomous trading and payments may develop progressively. AI-enabled cyber risk is already changing. The Bank of England, the Financial Conduct Authority and HM Treasury warned in May that frontier AI models can perform some cybersecurity tasks faster, more widely and at lower cost than skilled practitioners.

Used defensively, these systems can identify vulnerabilities and help organisations remediate them. Used maliciously, they can reduce the expertise, time and cost required to discover and exploit weaknesses.

The ECB has described this as a structural change in the economics of cyber risk. Advanced models may identify vulnerabilities at scale, combine several minor weaknesses into a serious attack and reverse-engineer security patches more quickly. That can shorten the interval between publication of a fix and exploitation of the underlying vulnerability.

This creates systemic rather than merely institutional risk.

Banks depend on shared cloud providers, telecommunications networks, payment infrastructure, software libraries, electricity and other critical services. An AI-enabled attack against a common dependency could disrupt several financial institutions at the same time.

The Bank of England is therefore considering whether individual recovery plans remain sufficient. Breeden raised the possibility of stronger failover arrangements, rebuilding critical systems from clean infrastructure or enabling one institution to temporarily provide basic functions for another during a severe disruption. She cited Ukraine’s Power Banking programme as an example of coordinated continuity across financial institutions during wartime disruption.

This changes the meaning of resilience. The goal is no longer only to prevent a successful attack. Financial institutions may need to demonstrate that essential services can continue when several firms or shared providers become unavailable simultaneously.

Regulators are moving, but there is no single global rulebook

The regulatory response remains fragmented and largely exploratory. The Financial Stability Board published a consultation in June containing 12 proposed sound practices for responsible AI adoption. They cover organisation-wide governance, management of the AI lifecycle and controls for cyber, technology and third-party risk.

The FSB is directing the practices particularly toward boards and senior management. However, it explicitly states that the consultation is not an international regulatory standard and does not impose a prescriptive approach. The consultation remains open until 22 July 2026.

In the United States, banking supervisors are already asking institutions during examinations to explain where they use AI, which data the systems can access, how third-party providers are controlled and whether shutdown mechanisms and contingency plans exist.

US regulators are nevertheless continuing to rely mainly on existing model-risk, third-party, consumer-protection and governance frameworks rather than issuing a dedicated set of agentic-AI rules.

The UK Parliament’s Treasury Committee previously called for AI-specific financial stress testing. In response, the Bank of England confirmed plans to investigate the effect of correlated behaviour among AI trading agents, work that is now reflected in Project Logos.

The European Union already has several relevant frameworks. The AI Act classifies certain financial applications, including systems used to assess the creditworthiness of natural persons and some life and health insurance pricing systems, as high-risk. DORA establishes operational-resilience requirements for financial entities and provides mechanisms such as threat-led penetration testing.

Those rules provide important controls, but they do not by themselves answer every question raised by autonomous trading agents or broad consumer payment mandates. Agentic finance cuts across AI governance, cybersecurity, payment law, market supervision, operational resilience, consumer protection and third-party risk.

No single existing framework covers all those dimensions.

What financial institutions should prepare now

Financial institutions should not interpret the absence of final agentic-AI regulation as permission to wait. The direction of supervisory attention is already visible. Organisations need a reliable inventory of AI use cases that distinguishes systems producing information from systems capable of executing actions. A chatbot that summarises a policy does not create the same risk as an agent that changes a customer record, initiates a payment, modifies code or places a trade.

Each agent should have a defined operational boundary. This includes the systems it can access, data it can retrieve, transactions it can perform and financial or operational exposure it can create. Permissions should be technically enforced rather than recorded only in policies. Agents should use separate identities, restricted credentials and clearly defined transaction limits. Their authority should not automatically expand merely because a connected user or application has wider privileges.

Institutions also need complete activity records. It should be possible to reconstruct which information the agent received, what reasoning or policy path it followed, which tools it invoked and which actions it performed. Emergency controls must be tested under realistic conditions. Suspending an agent should not make critical banking or payment services unavailable. Organisations need a degraded operating mode, manual or alternative processes and clearly assigned authority for containment.

Third-party arrangements deserve particular attention. Many institutions will not build the underlying models themselves. They may depend on an AI provider, cloud platform, orchestration layer, data supplier and several software components for one business service.

Boards should know whether the institution can replace a critical provider, preserve necessary records, revoke external access and continue operating when the vendor’s system is compromised or withdrawn. These concerns are already appearing in both FSB recommendations and supervisory examinations.

Finally, testing must extend beyond the individual model. Institutions should simulate interactions between several agents, shared service failures, abnormal market conditions, manipulated data, compromised credentials and situations in which an agent remains technically functional while pursuing an inappropriate objective.

From responsible AI to controllable autonomy

The emerging central-bank position is not that autonomous AI should be prohibited from finance. AI agents could improve efficiency, increase competition, reduce transaction costs and provide services that react more quickly to customer and market needs. Central banks are also exploring how AI can improve their own monitoring, scenario analysis and supervision.

The issue is whether institutions can remain accountable for actions that occur too quickly and at too great a scale for conventional human oversight.

For the first stage of financial AI adoption, regulators focused on fairness, model accuracy, explainability and data governance. The next stage will focus on authority. Who authorised the agent? What was it allowed to do? How was that authority enforced? Could its behaviour be observed across the market? Who could stop it? And what would continue operating after it was stopped?

Central banks have not yet produced final answers. But their experiments, consultations and public warnings show that autonomous AI is moving from an innovation topic to a financial stability and operational resilience issue.

Financial institutions that begin answering those questions before regulation is finalised will be better prepared for both supervisory scrutiny and the operational reality of agentic finance.