Banks have spent decades strengthening Know Your Customer processes to establish who a customer is, understand the purpose of the relationship and control financial-crime risk. Agentic AI introduces a different question: which machine is acting, on whose authority and within what limits?
At the Global Fintech Fest on 10 September 2026, State Bank of India Chairman C.S. Setty proposed a “Know Your Agent” framework for artificial-intelligence agents participating in financial transactions. He identified identity, authentication, customer consent, transaction limits, audit trails and revocation as necessary components.
The proposal reflects a broader market shift. On the same date, Reuters reported that Visa, Mastercard and Ant International had launched an initiative to develop common standards for identifying and verifying AI agents that can make purchases for users. The framework is intended to help card networks, digital wallets, agent platforms and marketplaces recognise trusted agents while retaining their own approval and risk-management processes.
This matters because agentic AI crosses an important boundary. It moves technology from producing advice to exercising delegated authority.
From recommendation to execution
A conventional analytics model scores a transaction or recommends an action. A generative-AI assistant may summarise a case or draft a customer response. An AI agent can go further: interpret an objective, select a course of action, use tools and execute across connected systems.
In banking, potential applications include customer servicing, payment initiation, fraud investigation, KYC and AML workflows, credit assessment, underwriting, reconciliation and collections. These uses could reduce processing time, improve availability and release employees from repetitive tasks.
They also create a new class of operational risk. An error is no longer confined to an inaccurate output waiting for human review. It can trigger a sequence of actions across accounts, customers, counterparties and systems at machine speed.
The relevant governance unit is therefore not only the model. It is the agent, its delegated mandate and every environment in which it can act.
Why existing AI governance is insufficient
Many AI policies concentrate on model accuracy, bias, privacy, data quality and acceptable use. These remain essential, but autonomy adds different questions.
A model may be accurate in testing yet use an inappropriate tool in production. An agent may have a legitimate identity but excessive permissions. Its initial objective may be valid while its interpretation of that objective is not. A third-party agent may interact with a bank’s systems without clear liability when something fails.
Traditional user-access controls are also an incomplete answer. Human users normally have stable roles, known employment relationships and relatively predictable activity patterns. AI agents can be created quickly, duplicated, connected to several tools and reconfigured as their tasks evolve. Their permissions can therefore drift beyond their original purpose.
Banks need an explicit agent-governance layer that links technical identity to business accountability. This is part of the broader operational-resilience challenge facing financial institutions as technology dependencies extend beyond traditional organisational boundaries.
Five pillars of a Know Your Agent framework
1. Identity: which agent is acting?
Every production agent should have a unique, verifiable identity. The institution should know its model, version, owner, purpose, provider, connected tools and operating environment. Shared or anonymous machine credentials should be prohibited for material activities because they undermine traceability.
An agent register should become as fundamental as a model inventory or application catalogue.
2. Mandate: on whose authority?
An agent should not possess authority merely because it has technical access. Its mandate must be connected to a named customer, employee, executive or approved business process.
Consent should be explicit about the activity being delegated. A customer authorising an agent to compare products has not necessarily authorised it to move money. An employee using an agent for analysis has not automatically delegated approval authority.
3. Limits: what may it do?
Authority should be bounded by data, system, value, time and decision type. Controls might restrict beneficiaries, transaction values, frequency, products or hours of operation. Higher-risk actions should require step-up authentication or human approval.
Segregation of duties is equally important. The same agent should not propose, approve and execute a material transaction without independent control merely because automation makes that architecture convenient.
4. Evidence: what did it decide?
Auditability requires more than a transaction log. Banks need sufficient evidence to reconstruct the instruction received, information accessed, policy applied, tools called, alternatives considered, approval obtained and action executed.
Logs must be protected from alteration and retained according to regulatory, legal and investigative requirements. Without that evidence, accountability becomes an assertion rather than a control.
5. Revocation: how is it stopped?
Every agent needs an immediate and tested method of suspension. Credentials should be time-bound, permissions reviewable and behaviour continuously monitored. The institution should be able to stop a single agent, a class of agents or an entire autonomous workflow without disabling critical services unnecessarily.
Revocation is the operational expression of human control.
Implications for Nigerian and African banks
African financial institutions have strong incentives to adopt agentic AI. High transaction volumes, diverse languages, financial-inclusion opportunities and pressure on operating costs create attractive use cases. AI agents could improve service availability, automate controls and extend digital banking to customers who are more comfortable speaking than navigating complex applications.
The governance architecture should be designed during experimentation, not after deployment. The same principle applies to AI-enabled fraud controls, where identity, intent, transaction context and rapid recovery must operate as an integrated control system. Banks should avoid allowing different functions to create autonomous agents independently through cloud tools, vendor platforms and local pilots. That would reproduce the fragmented access and application estates many institutions are already trying to simplify.
The ecosystem dimension also matters. Payments routinely cross banks, fintechs, processors, telecom operators and merchants. One institution cannot establish trust alone. Shared standards for agent identity, mandates and transaction evidence will ultimately be required, particularly as African payment interoperability expands.
Five actions for executive teams
- Create an enterprise agent register. Record every agent, owner, purpose, model, vendor, data source, system connection and autonomy level.
- Define autonomy tiers. Separate agents that advise, recommend, prepare actions, execute with approval and execute autonomously. Match control intensity to potential impact.
- Redesign delegated-authority rules. Extend existing mandates, approval matrices and segregation-of-duties policies to machine actors.
- Test failure at machine speed. Run scenarios involving erroneous payments, compromised credentials, prompt injection, agent collusion, unavailable providers and cascading actions across systems.
- Report agent risk to executives and the board. Track active agents, high-risk permissions, exceptions, overrides, incidents, unexplained behaviour and time taken to revoke access.
The board question
Agentic AI could create meaningful improvements in productivity, service and inclusion. But the economic value of autonomy depends on trust. Customers, regulators and counterparties must know that a machine actor is identifiable, authorised, constrained and accountable.
If an AI agent executed a harmful action tomorrow, could management demonstrate who authorised it, what it was permitted to do, why it acted and how quickly its authority was withdrawn?
How Trimm Solutions can help
Trimm Solutions helps financial institutions connect AI strategy with process architecture, governance, operational risk and enterprise controls. Our business transformation services help executive teams translate emerging technology into governed operating-model change. We support AI-agent inventories, autonomy and risk classification, delegated-authority design, control diagnostics, operating-model redesign and executive reporting for governed adoption.