Executives discuss the importance of keeping up with agentic AI governance

Why Agentic AI Governance is Falling Behind Adoption in Financial Services

Financial firms are integrating AI agents into their business workflows, and agentic AI governance must keep pace. Gartner’s 2026 Hype Cycle for Agentic AI advises leaders to assess the maturity of AI-agent technologies carefully and focus on applications that can deliver scalable business value. At the same time, Gartner has predicted that more than 40% of agentic AI projects will be canceled by the end of 2027. The causes are rising costs, unclear business value, or inadequate risk controls. 

That combination should get the attention of executives at investment firms, hedge funds, private equity firms, asset managers, and fintechs. Leaders at these companies must consider whether their teams can successfully supervise an agent. With access, it will be able to make decisions that affect clients, capital, or regulated activity.

A pilot may work well with limited data, a small user group, and close human review. Once a firm connects an agent to production, leadership must have clear agentic AI governance in place. Only then can they gain clear answers about ownership, data access, retained evidence, and accountability.

Agentic AI changes the nature of deployment

Financial firms have used artificial intelligence for fraud detection, portfolio analytics, credit decisions, market surveillance, and operational forecasting. Generative AI has given them tools for research, summarization, document review, coding, and client communication drafts.

Agentic AI extends those capabilities by allowing a system to retrieve information and select next steps. It can even use connected tools and complete a sequence of tasks toward a defined objective. For example, it may prepare an exception report, review documents against a policy, or route work to a human reviewer.

Agent accountability becomes the central question

That added capacity raises the burden of AI governance. Firms need to know what systems an agent can access, what authority it has, what actions it took, and who is accountable for its work. McKinsey describes the shift as a move beyond model accuracy toward agent accountability for system actions. McKinsey recommends that firms define an agent’s scope, maintain an inventory of deployed systems, and assign accountable owners.

In financial services, agents may support investment research, operations, client service, or compliance work. Those uses can save skilled employees time, but they also bring agents closer to sensitive information and decisions that affect clients, capital, or regulated activity. Human review, system permissions, and retained records therefore matter as much as the quality of the underlying model.

Adoption is rising ahead of clear standards

The market pressure behind agentic AI is real. A global 2026 survey by McKinsey found that 40% of respondents from companies with annual revenue above $1 billion reported scaling AI agents, up from 27% the year before. Financial firms are exploring these tools to support research, service, operating processes, and risk work without expanding headcount at the same rate.

Formal rules and internal governance practices are still developing. Different regulators have taken different positions, which complicates planning for firms with cross-border operations, global clients, or vendors operating across jurisdictions.

Regulators are moving at different speeds

In the United States, the Federal Reserve, the Office of the Comptroller of the Currency, and the Federal Deposit Insurance Corporation updated model risk management guidance in April 2026. The guidance excludes generative AI and agentic AI from its formal scope. However, existing expectations around operational risk, cybersecurity, third-party oversight, fair lending, recordkeeping, and supervision still apply.

The exclusion shows that U.S. banking regulators have not yet issued a dedicated model-risk standard for these systems.

Treasury’s Financial Services AI Risk Management Framework

Treasury has taken a more sector-specific step. It released a Financial Services AI Risk Management Framework to help institutions assess AI use cases. It also helps them incorporate agent accountability, transparency, and operational resilience into deployment decisions.

FINRA’s 2026 Regulatory Oversight Report

FINRA has also made clear that its rules remain technology-neutral. Its 2026 Regulatory Oversight Report includes generative AI as a topic and states that FINRA rules and securities laws still apply when firms use GenAI or similar technologies in the course of business. Member firms cannot treat the use of an agent as separate from their existing supervisory duties. 

The EU AI Act

The European Union has taken a more prescriptive route. The EU AI Act classifies certain financial-services applications, including credit scoring and insurance risk pricing, as high-risk uses of AI. Those classifications carry obligations tied to risk management, documentation, and human oversight. The implementation schedule has also changed. Compliance obligations for high-risk AI systems have been delayed to December 2027. The delay reflects the challenge of translating broad policy into standards institutions can apply consistently.

Singapore’s Safeguards for Agentic Finance at Runtime

Singapore has moved further on agentic AI. In July 2026, the Monetary Authority of Singapore published its Safeguards for Agentic Finance at Runtime paper with financial institutions and fintechs, then stated in August that its proposed AI risk management guidelines would cover agentic AI. The guidelines call for board and senior-management oversight and risk controls across the AI lifecycle. 

Financial firms operating across jurisdictions may face different levels of regulatory specificity. Each still needs to show that its use of AI fits within existing duties to protect data, maintain records, supervise activity, and manage operational risk.

A pilot is not an operating capability

A contained pilot can show whether employees adopt a tool and whether its output meets an initial standard. It offers only a partial view of what the firm will need to manage in production.

During a pilot, a small group may review most outputs, the agent may have access to selected documents, and a sponsor may resolve exceptions informally. Production use expands the number of users, connected data sources, and business processes affected by the system. The need for consistent oversight grows with that scope.

Financial leaders should distinguish between an agent that demonstrates technical promise and one the organization can operate responsibly at scale. The relevant test is whether the firm can identify the system, explain its purpose, trace its activity, and intervene when it operates outside approved boundaries.

Consider an agent that prepares a morning summary of research notes, market data, and portfolio commentary for an investment team. During a pilot, analysts may review each summary, spot errors quickly, and report issues directly to the project team.

The governance requirements change when the agent gains access to more data sources, distributes output more broadly, or becomes part of a formal research process. Leaders then need to decide what records to retain, what information should remain outside the agent’s reach, how corrections are documented, and where human review remains necessary before the material informs an investment recommendation.

A hypothetical: An operations agent moves into production

Consider a private equity firm that pilots an agent to prepare weekly operating summaries for a portfolio company. The agent pulls information from approved internal reports, identifies changes in selected operating metrics, and drafts a briefing for the operating partner. During the pilot, a small group reviews every briefing before it is circulated. The agent has access only to a defined reporting folder.

The firm may later want to connect the agent to additional finance, customer, or operational systems. It could prepare reports faster and identify exceptions for review. That expansion could make the output more useful, but it also changes the firm’s responsibilities. Leadership would need to decide which data the agent may access, who verifies its conclusions, how inaccurate output is corrected, and whether the system’s activity is recorded for later review.

The agent may perform the same core task in both settings. The need for agentic AI governance changes because the agent’s access, audience, and influence have expanded. This is the point at which many firms discover that a successful pilot has not yet established an operating model for broader deployment.

Questions that leadership should be able to answer about agentic AI governance

Executive teams do not need to become specialists in model architecture. Before a pilot becomes a wider deployment, however, they need clear answers to questions about ownership, authority, oversight, and evidence.

  • Which business processes use agentic AI, including capabilities embedded in third-party software?
  • Who owns each use case after limited testing ends, and what data and systems can the agent access?
  • What decisions can the agent influence or actions can it take without additional approval?
  • When must a person review the agent’s work before it affects a client, transaction, control, or regulated process?
  • What records show the agent’s activity and support an investigation into unexpected or unauthorized behavior?
  • How would the firm explain the agent’s role to a regulator, allocator, client, auditor, or board member?

These questions apply to internally built systems and vendor products alike. A firm may have strong policies for internally developed models while lacking a complete view of AI capabilities in cloud services, research platforms, customer-service software, security tools, or workflow applications. Vendor due diligence should clarify an agent’s limits of autonomy, data use, available audit evidence, and the division of responsibility between vendor and customer. 

The answers will vary according to use case. An agent that helps an internal team locate policy documents may warrant lighter review than an agent that drafts communications based on client information or assists with a process that affects capital allocation. Oversight should reflect what the agent can access, influence, and do.

Agentic AI Governance supports more useful deployment

Agentic AI can reduce manual work across complex financial-services processes. The question for leadership teams is whether their organizations can deploy these systems where they add value while retaining appropriate oversight.

The firms best positioned to do so already have useful capabilities in place: defined ownership for material technology use cases, third-party risk review, escalation procedures, cybersecurity controls, business continuity planning, and recordkeeping. Those disciplines can guide agentic AI governance while formal rules continue to develop.

The immediate priority is to establish where agents are being introduced, who owns them, what data and systems they can use, what evidence the firm retains, and where human review is required. With that information, leadership can decide which use cases should move forward, which require further controls, and which are not ready for production.

Option One Technologies helps financial firms assess the infrastructure, cybersecurity, cloud, and operating requirements that support modern AI deployments. A structured assessment can help organizations determine where existing capabilities support responsible agentic AI use and where additional planning is required.