The next identity problem in banking may not involve identifying a person at all. As AI agents begin shopping, comparing financial products, managing subscriptions, moving money and carrying out instructions on behalf of customers, banks will increasingly encounter transactions where the account holder is human but the entity actually interacting with the financial system is software. That creates a new challenge for an industry built around establishing exactly who is on the other side of a transaction. If an AI agent can independently initiate financial activity, knowing the customer may no longer be enough. Banks may also need to know which agent is acting, who authorised it, what it has permission to do and whether its behaviour remains within the boundaries established by the customer.
From Know Your Customer to Know Your Agent
Know Your Customer frameworks are based on a relatively clear relationship. A bank establishes the identity of an individual or business, assesses the associated risk and determines what that customer is permitted to do. AI agents complicate that relationship because the customer could increasingly delegate financial decisions to software rather than personally initiating every transaction.
Imagine a customer authorising an AI assistant to manage household bills, search for cheaper insurance, renew subscriptions, move surplus cash into savings and purchase travel within an agreed budget. The customer remains the account holder, but potentially hundreds of individual decisions could be initiated by software without the customer opening a banking application or approving every action individually.
For banks, the question therefore extends beyond whether the customer is legitimate. They may need to establish which AI agent is acting, which customer authorised it, what permissions were granted, whether those permissions remain valid and whether the transaction being attempted falls within that mandate. It begins to resemble a new layer of financial identity: Know Your Agent.
This does not necessarily require another regulatory acronym or a replacement for KYC. Instead, it could mean extending existing identity and authentication architecture to recognise delegated machine activity as a distinct part of the financial relationship.
An AI Agent Cannot Simply Inherit Unlimited Trust
The simplest technical approach might be to treat an authenticated AI agent as an extension of the customer. Once permission has been granted, the agent could operate using the customer’s existing privileges. But giving software unrestricted access to financial accounts would create significant security and governance risks, particularly as agents become capable of operating continuously and making decisions at machine speed.
Human banking behaviour has natural limitations. People sleep, hesitate, reconsider decisions and typically make a relatively small number of financial transactions during a given period. Autonomous software has none of those constraints. An AI agent could potentially evaluate hundreds of options, communicate with multiple providers and execute financial instructions continuously. If its credentials were compromised, its instructions manipulated or its underlying behaviour altered, the same speed and automation that make agents useful could accelerate financial losses.
Banks will therefore need to separate identity from authority more clearly. Establishing that an AI agent belongs to a legitimate customer will not necessarily mean that the agent should inherit every privilege available to that customer. The financial institution will also need to understand exactly what that particular agent has been authorised to do.
Financial Permissions Could Become Much More Granular
Today’s digital banking permissions are often relatively broad. Once customers successfully authenticate themselves, they can usually access most functions associated with their accounts, although additional authentication may be required for higher-risk transactions. Agentic banking could require something considerably more granular, effectively turning financial authority into a programmable set of permissions.
A customer might allow an AI agent to pay household bills up to a defined amount, purchase airline tickets within a specific budget, move surplus cash between approved accounts or renew subscriptions below an agreed threshold. Another agent might be permitted to compare mortgages or investment products but prevented from opening them. Transactions above a certain value could automatically require human approval before completion.
The important distinction is that autonomy does not have to be binary. An AI agent does not need either complete access or no access at all. Banks could create permission structures defining precisely where autonomous action is allowed, how much money can be moved, which counterparties can receive funds and when human intervention remains mandatory. In effect, customers would be creating financial mandates for machines.
Authentication Will Need to Identify Who, or What, Is Acting
Banks have spent years improving their ability to determine whether someone attempting a transaction is genuinely the customer. Device intelligence, behavioural analytics, passwords, biometrics, passkeys and multifactor authentication all contribute to that decision. Agentic transactions introduce another question: is the transaction being initiated directly by the customer, by an authorised AI agent acting for the customer or by something pretending to be one?
This distinction could become increasingly important for fraud detection because legitimate machine behaviour may look very different from legitimate human behaviour. An authorised agent could operate at unusual hours, interact through APIs rather than a banking interface and execute actions much faster than any individual. Traditional behavioural models might interpret perfectly legitimate automated activity as suspicious, while attackers could simultaneously attempt to imitate trusted agents.
Banks may therefore need identity frameworks capable of recognising authorised machines as distinct participants rather than disguising their activity as human behaviour. That could allow financial institutions to apply different authentication, transaction monitoring and risk controls depending on whether the actor is a person, an authorised agent or an unknown automated system.
Every AI Agent May Eventually Need Its Own Financial Identity
One possible outcome is that trusted AI agents eventually acquire persistent identities within financial ecosystems. A bank could know that a transaction originated from a particular customer through a particular authorised agent operating under a defined permission set. That identity could contain information about the agent’s provider, authentication status, delegated authority, transaction limits and the period for which its permissions remain valid.
This would also make access easier to control and revoke. If a customer stopped using an AI service, the bank could terminate that agent’s authority without changing the customer’s own banking credentials or disrupting other services. Customers could potentially authorise several different agents, each responsible for a particular area of their financial lives and each operating under different restrictions.
That separation may become increasingly important as financial accounts connect with a growing ecosystem of applications, wallets, platforms and autonomous services. Banks will need visibility into this network because a single customer could eventually have multiple machines capable of interacting with their money.
Fraud Controls Will Have to Understand Intent
The security challenge becomes more complicated because criminals will also use increasingly autonomous technology. Generative AI has already made impersonation, social engineering and synthetic content easier to scale, while more capable agents could automate additional stages of fraudulent activity. Banks cannot respond simply by treating machine-generated financial behaviour as suspicious because legitimate customers will increasingly be using machines as well.
The challenge will instead be distinguishing authorised automation from malicious automation, which could push fraud detection further toward understanding the context and intent behind a transaction. If a customer has instructed an authorised agent to find and purchase the cheapest flight to Singapore below a defined price, a corresponding transaction could be legitimate even if it occurs instantly and without the customer opening the bank’s application. A large transfer to an unrelated account outside the agent’s mandate would present an entirely different risk profile.
The customer’s original permission could therefore become an important fraud signal. Instead of analysing only what happened, banks may increasingly need to compare each autonomous action against what the agent was originally authorised to do.
Banks Could Become the Trust Layer for Agentic Commerce
There is also a strategic opportunity for financial institutions. Much of the discussion around AI agents focuses on whether technology platforms will weaken the direct relationship between banks and customers. If consumers increasingly manage their financial lives through external AI assistants, they may interact less frequently with bank applications and websites. The interface could shift away from the bank even while the underlying financial infrastructure remains essential.
Money still needs to move securely. Identity must still be established, transactions authenticated and financial risk managed. Banks could therefore position themselves as the infrastructure determining which agents are trusted and what those agents are permitted to do. Instead of simply processing a payment requested by an AI system, the bank could verify the customer, authenticate the agent, validate its authority, apply transaction controls and maintain the audit trail connecting the machine’s action to the customer’s original consent.
That role could become increasingly valuable as autonomous participants multiply across digital commerce. Customers may not always see the bank when an AI assistant books a trip, renews an insurance policy or manages a subscription, but the agent could still depend on the bank to validate its authority before money moves.
Consent Will Need to Become Visible Again
One of the biggest design challenges will be ensuring customers genuinely understand what they have authorised. Digital services have conditioned consumers to accept lengthy terms, permissions and privacy notices with limited scrutiny. That model becomes considerably more dangerous when granting permission allows software to independently spend or transfer money.
Banks may need to make consent much more visible and manageable. Customers should be able to see which AI agents have access to their accounts, what each agent is allowed to do, how much it can transact, which accounts it can access and when its authority expires. Revoking or temporarily suspending an agent should be straightforward, while significant changes to permissions may require fresh authentication.
A future mobile banking dashboard could therefore include something unfamiliar today: a list of authorised AI agents sitting alongside cards, registered devices and connected accounts. Managing machines could eventually become a routine part of managing money.
The Bank Account Is Becoming a Programmable Environment
Agentic banking represents something larger than another digital banking channel. Mobile banking allowed customers to access accounts through smartphones, while open banking enabled approved third parties to access financial data and initiate certain services with customer consent. AI agents could introduce another stage in that evolution by allowing software to continuously make financial decisions within boundaries established by the customer.
The account would gradually shift from being a place where customers manually initiate every action to an environment where people establish financial rules and authorised systems execute them. That creates new possibilities for convenience and automation, but it also makes identity, permissioning and governance far more important.
Banks preparing for this transition will therefore need more than sophisticated AI models. They will need identity architecture capable of answering a deceptively simple question whenever a machine attempts to move money: who authorised this agent to act, and exactly what did they authorise it to do?
What it means for the industry
- Digital identity will expand beyond people and businesses. Banks will increasingly need mechanisms for recognising and authenticating AI agents interacting with financial systems on behalf of customers.
- Authentication and authorisation will become more distinct. Establishing who owns an agent will not be enough; banks must also determine exactly what that agent is permitted to do.
- Granular consent could become a competitive banking capability. Customers may expect configurable controls around spending, transfers, counterparties, duration and human approval.
- Fraud models will need to distinguish legitimate machine behaviour from malicious automation. Transaction speed or non-human behaviour alone will become less useful as indicators of suspicious activity.
- Banks have an opportunity to become the trust infrastructure behind agentic commerce. Even where AI platforms control the customer interface, banks can retain a critical role in identity, permissioning and transaction assurance.
- Managing AI agents could become part of everyday digital banking. Customers may eventually control authorised agents in much the same way they currently manage cards, devices and connected applications.

