Agentic AI in Banking: What It Can Already Do Without Asking You
Agentic AI in banking has moved from pilot to production. What UK and global banks now let software do on its own, who authorises it, and what recourse you have when it gets it wrong.
The software stopped asking a while ago#
Most people meet their bank's artificial intelligence at the worst possible moment. A card declines at the till. A transfer to a builder sits in limbo. An application comes back refused in eleven seconds, which is not long enough for a person to have read it.
None of that is new, and none of it is agentic. It is scoring and rules, running fast.
The next step is new. In December 2025 the Financial Conduct Authority's chief data officer, Jessica Rusu, told Reuters she expected the first consumer-facing agentic AI applications to reach the UK market in early 2026, and that the technology brought a new category of risk for retail customers. Her phrasing was careful: "Everyone recognises that agentic AI introduces new risks, primarily because of ... the ability for something to be done at pace" (Reuters, 17 December 2025).
That was nine months ago. The rails have been built since.
What "agentic" actually means, in plain terms#
An ordinary AI model answers. You ask, it replies, and nothing happens in the world.
An agentic system takes a goal instead of a single instruction, breaks it into steps of its own choosing, and is wired into tools that can act: a payments API, a customer record, a savings product. The International Monetary Fund's April 2026 note on agentic payments describes such systems as able to "interpret objectives, break them into tasks, and interact with digital services with limited human input" (Davidovic and Tourpe, IMF Note 2026/004).
The phrase doing the heavy lifting is "limited human input". Autonomy is a dial, not a switch. A model that drafts a letter for a human to sign sits at one end, a model that moves your money at the other, and most bank deployments sit awkwardly in between.
One more distinction matters, because regulators keep returning to it. Language models are probabilistic: given the same input twice they may not produce the same output. Payment systems are deterministic. A payment either settled or it did not, and the record has to say which. The IMF treats that mismatch as the central design problem rather than a teething issue.
What is already running without a prompt from you#
The last full survey of the UK industry, published by the Bank of England and the FCA in November 2024, found 75% of financial firms already using AI, with another 10% planning to within three years. Of the use cases reported, 55% involved some degree of automation, 24% were semi-autonomous with human oversight reserved for critical decisions, and 2% made fully autonomous decisions with no human in the loop. The three most common applications were internal process optimisation at 41% of respondents, cybersecurity at 37% and fraud detection at 33% (Bank of England and FCA, Artificial intelligence in UK financial services 2024).
Two per cent sounds trivial until you notice where it sits. Nobody rings you before a suspicious card transaction is blocked, because the blocking has to happen in the time it takes a terminal to respond.
That machinery works. UK Finance reported that the industry stopped £1.68 billion of unauthorised fraud in 2025, against £703.4 million that got through, across 3.81 million cases (UK Finance, Annual Fraud Report 2026). The same report shows authorised push payment losses rising 19% to £576.4 million, with banks reimbursing £354.3 million, or 61% of what victims lost. Detection is a balance, and the errors fall on customers both ways: a blocked payment that was fine, or a scam payment that sailed through.
Banks are extending that autonomy into servicing. NatWest has been testing agentic systems to investigate and analyse complaints. Lloyds has piloted software that helps staff assist customers with money management, and its chief data and analytics officer, Ranil Boteju, has said savings could one day be moved automatically into a tax-free ISA if customers agree beforehand. Starling has been building tools that let customers set predictive spending caps and have standing orders configured for them (Reuters, December 2025).
Note the conditional in the Lloyds example. "If customers agree beforehand" is the whole ballgame.
The card networks quietly rebuilt the rails for machines#
While banks piloted, the payment networks rewrote the plumbing.
Visa introduced its Trusted Agent Protocol in October 2025 and said in December that hundreds of agent-initiated transactions had been completed, with more than 100 partners involved and pilots planned for Asia Pacific and Europe in early 2026. It also cited research finding that 47% of US shoppers already use AI tools for shopping tasks (Visa, December 2025).
Mastercard went live at scale first. On 24 March 2026 it announced completed end-to-end agentic transactions across Latin America and the Caribbean with 17 institutions including Santander, Banco Itaú and Bancolombia, covering everyday purchases on debit and credit cards. The mechanism is an "agentic token", a payment credential held by the agent carrying cryptographic data that lets the card issuer see a machine is transacting. Mastercard says every transaction required full cardholder consent, used biometric passkeys, and produced a tamper-resistant record of exactly what the cardholder authorised (Mastercard, 24 March 2026).
Stripe and OpenAI took a third route, launching Instant Checkout and the open Agentic Commerce Protocol on 29 September 2025. Their answer is a shared payment token scoped to one merchant and one cart total, so the agent triggers a payment without ever holding your card details (Stripe).
Britain's version is arriving through open banking rather than cards. On 2 June 2026 the FCA welcomed the launch of the UK Payments Initiative, an industry-led scheme for commercial variable recurring payments, which let a trusted third party pull varying amounts from your account under a mandate you set. The FCA expects to consult on a long-term regulatory framework by the end of 2026 (FCA, 2 June 2026). A mandate with limits is exactly what an agent needs to spend on your behalf.
Where the money actually gets authorised#
The IMF note is useful because it refuses to treat "agentic payments" as one thing. It splits a payment into three layers: intent, authorisation and settlement.
Intent is working out what you want. Comparing tariffs, finding the cheapest way to send money to Lagos, noticing a current account balance that should be earning something. Agents are good at this layer, and the least can go irreversibly wrong in it.
Authorisation is the consent step, proving you agreed. Every scheme described above is an attempt to solve this one, whether by tokens, passkeys or scoped mandates.
Settlement is the movement of money, and it is final. Here the IMF flags its main risks: weak traceability when a decision cannot be reconstructed, systemic effects if many agents react to the same signal at once, a wider attack surface, unresolved legal accountability, and complications for anti-money-laundering compliance. Its conclusion is not a technology verdict. Outcomes, the authors write, "will depend on institutional design and governance as much as technology".
Who answers when it goes wrong#
Nobody has settled that, but the shape of the answer is visible.
The FCA has not written agentic rules. It is applying the ones it has, principally the Consumer Duty and the senior managers regime, which means a named executive is accountable for what the software does. Alongside that it runs AI Live Testing. The second cohort, announced in April 2026, comprises Aereve, Coadjute, Barclays, Experian, GoCardless, Lloyds Banking Group's Scottish Widows, UBS and Palindrome, testing agentic payments, anti-money-laundering detection, know-your-customer checks and credit score insights for consumers. Testing runs to the end of 2026, with an evaluation report due in the first quarter of 2027 (FCA, April 2026).
Internationally, the Financial Stability Board put out a consultation on 10 June 2026 proposing 12 sound practices for AI governance, and asked whether they cope with "emerging and new complex forms of AI, such as GenAI and agentic AI" (FSB). That question mark is the honest state of play.
Your own legal position shifted this year too, and not obviously in your favour. The Data (Use and Access) Act 2025 widened the lawful bases on which firms can make significant decisions about you by automated means, including legitimate interests, while keeping safeguards and excluding special category data. All its data protection provisions came into force on 19 June 2026 (Information Commissioner's Office).
A systemic worry sits behind the consumer one. Tao Zhang of the Bank for International Settlements told the Asian Financial Forum in January 2026 that "the widespread use of similar AI models, data or decision rules can lead institutions to respond to shocks in similar ways, increasing correlations in behaviour" (BIS, 26 January 2026). The Bank of England's July 2026 Financial Stability Report adds the capability point: frontier models now complete software tasks that would take a human expert 16 hours, with a 50% success rate, and the AI Security Institute found the newest models able to carry out multi-stage attacks on vulnerable systems with little human input (Bank of England). Agents that act fast can be attacked fast.
Where autonomy sits today#
| What happens | How autonomous it is now | Who authorises it | Your practical recourse |
|---|---|---|---|
| Card or payment blocked as suspected fraud | Fully automatic, in milliseconds | The bank's own model | Confirm identity, then complain; unauthorised fraud losses are largely reimbursed |
| Transaction monitoring and AML alerts | Automatic detection, human review before most actions | The bank, under statutory duties | Limited during an investigation; complaint and Ombudsman afterwards |
| Credit or affordability decision | Automated scoring, wider lawful bases since June 2026 | The lender | Ask for the reasons and human review under the DUAA safeguards |
| Complaint triage and servicing chat | Piloted agentic investigation at NatWest and others | The bank | Standard complaints process, then the Financial Ombudsman Service |
| Moving savings into a better product | Not autonomous, requires prior agreement (Lloyds pilot) | You, in advance | Withdraw consent; check the mandate terms |
| Agent buying something for you | Live in pilots via agentic tokens and shared payment tokens | You, at set-up and per transaction | Card protections plus the scheme's authorisation record |
| Recurring payments under a mandate | Scheme launched June 2026 in the UK | You, when granting the mandate | Revoke the mandate through your bank |
Sources: Bank of England and FCA (2024); UK Finance (2026); Reuters (2025); Mastercard (2026); Stripe (2025); FCA (2026); ICO (2026).
Key takeaways#
- Autonomy is not arriving, it is already here in narrow places. Fraud blocking has always run without asking you, and 2% of UK financial AI use cases were already fully autonomous when the Bank of England last counted.
- The interesting shift is from deciding to spending. Visa, Mastercard, Stripe and the UK's new commercial VRP scheme have all built ways for software to move money under a mandate.
- Consent has become a design problem. Agentic tokens, passkeys and scoped payment tokens exist because "the customer agreed" needs to survive a dispute months later.
- Nobody has finished writing the rules. The FCA is testing rather than legislating, the FSB is still asking whether its own guidance covers agentic AI, and the IMF says governance will matter as much as the technology.
- Your best chance to control any of it comes at set-up. The limits you place on a mandate before an agent starts spending are worth more than any complaint you make once it has.
Frequently asked questions#
Can my bank's AI move my money without me agreeing first?
Not in normal circumstances. It can block, freeze or refuse without asking, and it can act on standing instructions you have already given. Every agentic payment scheme now in the market is built around prior customer authorisation.
Is agentic AI in banking regulated in the UK?
Not by a dedicated rulebook. The FCA is applying existing rules, chiefly the Consumer Duty and senior managers regime, and is running live tests with eight firms until the end of 2026.
If an AI agent buys the wrong thing, who pays?
That depends on the scheme, the merchant and whether the authorisation record shows what you agreed to. The IMF lists legal accountability as an unresolved risk. Anyone offering you an agent that spends should be able to say in writing who bears the loss.
How do I find out why an automated decision went against me?
Ask the firm directly. Significant automated decisions still carry safeguards under UK data protection law, and complaints that go nowhere can be taken to the Financial Ombudsman Service.
Does an AI agent get to see my full card details?
Under the main schemes, no. Stripe's shared payment token is scoped to a single merchant and cart total, and Mastercard's agentic tokens are designed so the issuer can tell an agent is transacting.
Should small businesses let agents pay suppliers?
That is a judgement about controls rather than technology. The questions worth answering first are what the spending limit is, who reviews it, and how quickly a mandate can be revoked.
Is any of this investment or financial advice?
No. This article describes published data and official statements. Decisions about your own money should involve a regulated adviser who knows your circumstances.
Glossary#
Agentic AI Software that takes a goal, plans its own steps, and uses tools to act with limited human input.
Agentic token A payment credential issued to an AI agent that lets the card issuer see that a machine is transacting on a customer's behalf.
Shared payment token A one-off payment permission scoped to a single merchant and cart total, so the agent never holds the card number.
Authorisation layer The step in a payment where consent is proved, as distinct from working out what the customer wants and from moving the money.
Deterministic system One that produces the same result from the same input every time. Payment settlement has to work this way.
Probabilistic model One whose output can vary between runs on identical input. Most modern AI models are of this type.
Variable recurring payment (VRP) An open banking permission allowing a provider to take differing amounts from your account under limits you set.
Consumer Duty The FCA rule requiring firms to deliver good outcomes for retail customers, which applies to AI-driven services as much as any other.
Authorised push payment (APP) fraud A scam in which the victim is tricked into authorising the payment themselves.
References#
- Reuters, Agentic AI race by British banks raises new risks for regulator, 17 December 2025 (syndicated copy).
- Sonja Davidovic and Hervé Tourpe, How Agentic AI Will Reshape Payments, IMF Note 2026/004, 24 April 2026.
- Bank of England and Financial Conduct Authority, Artificial intelligence in UK financial services 2024, 21 November 2024.
- UK Finance, Annual Fraud Report 2026, June 2026, covering calendar year 2025.
- Visa, Visa and Partners Complete Secure AI Transactions, December 2025.
- Mastercard, Mastercard advances agentic payments in Latin America and the Caribbean with live transactions completed across the region, 24 March 2026.
- Stripe, Stripe powers Instant Checkout in ChatGPT and releases the Agentic Commerce Protocol, 29 September 2025.
- Financial Conduct Authority, Open banking takes next step forward with launch of UK Payments Initiative scheme, 2 June 2026.
- Financial Conduct Authority, FCA announces second cohort for AI Live Testing, April 2026.
- Financial Stability Board, Sound Practices for Responsible Adoption of Artificial Intelligence: consultation report, 10 June 2026.
- Financial Stability Board, Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector, 10 October 2025.
- Information Commissioner's Office, The Data (Use and Access) Act 2025: what does it mean for organisations?, in force 19 June 2026.
- Tao Zhang, Bank for International Settlements, The financial stability implications of artificial intelligence and digital finance, Asian Financial Forum, 26 January 2026.
- Bank of England, Financial Stability Report, July 2026.