An AI agent can find information and use it to decide on further actions. Each permitted tool call makes its permissions and controls more consequential. Before deployment, an institution must establish the task, the changes the system may trigger and who assesses its results.
Agents and other forms of automation
AI agents can handle multistep tasks using tools or APIs. Architecture and permissions limit the steps a system may perform itself. The label alone does not establish whether it only gathers information or can also change business transactions.
| Level | Principle | Typical in GRC | Degree of autonomy |
|---|---|---|---|
| RPA | Deterministic, rule-based replication of human click and form steps | Data transfer, report population, KYC data retrieval | none (rigid, brittle when layouts change) |
| Intelligent process automation | RPA plus ML/OCR/NLP: processes unstructured input, classifies, extracts | Document extraction, alert classification, anomaly detection | low (model decides sub-steps) |
| GenAI assistance | LLM generates text or code on request, without acting on its own | Policy and report drafts, research, summaries | low (a human triggers every step) |
| Agentic AI | LLM plans, calls tools and APIs and executes multi-step action chains itself | End-to-end control testing, autonomous change monitoring, case handling | high (many steps without interim approval) |
The level logic is didactic, not an official standard. Real architectures mix the levels: an agent can call RPA building blocks, and a GenAI assistant can be part of an agentic chain.
Legal classification of the use
Whether an agent can be used depends on its task, data access and permitted actions. Search creates different risks from initiating a payment. Approvals should follow the consequences of an action and be technically enforced; the legal duties depend on the actual use. Where an AI model is used for purposes covered by MaRisk AT 4.3.4, the module’s model requirements apply. The assessment depends on its task and use within the institution. Other duties, including DORA and data protection obligations, may apply independently. AI Act consolidated as at 27 July 2026 FSB: Sound practices for responsible adoption of AI, consultation report BaFin: Rundschreiben 06/2026 (BA), MaRisk
On 10 June 2026, the FSB published a consultation report on responsible AI adoption. It discusses accountability and oversight as design issues for financial entities. These recommendations must be distinguished from directly applicable EU and national legal duties. FSB: Sound practices for responsible adoption of AI, consultation report
Human oversight under the AI Act
Article 14 of the AI Act governs human oversight for covered high-risk systems. It does not impose a blanket duty to approve every agent action manually. Other organisational and control duties may apply independently of that classification. AI Act consolidated as at 27 July 2026 Regulation (EU) 2026/1744 amending the AI Act
For covered high-risk systems, oversight measures must be appropriate to risk and autonomy. Responsible people need sufficient information and effective means of intervention. The application date follows the relevant system category. AI Act consolidated as at 27 July 2026
Annex III point 5(b) covers AI systems evaluating the creditworthiness of natural persons or establishing their credit score. Systems used to detect financial fraud are expressly excluded from that category. Classification follows intended purpose and Article 6, rather than the label chatbot or agent. The amendment to the AI Act under Regulation (EU) 2026/1744 has been in force since 27 July 2026. The relevant obligations for Annex III high-risk systems apply from 2 December 2027; those for Annex I high-risk systems apply from 2 August 2028. AI Act consolidated as at 27 July 2026 Regulation (EU) 2026/1744 amending the AI Act European Commission: AI Omnibus enters into force
Potential GRC tasks
The following tasks are possible design areas. Suitability must be established through domain-reviewed results and the system’s permitted actions. Naming a task does not establish a working deployment.
01Control-test preparation and continuous controls monitoring
The agent pulls evidence from source systems, checks it against the control's target profile and prepares test documentation. The control judgement stays with the second line.
02Regulatory change monitoring and horizon scanning
The agent monitors sources, classifies relevance and drafts gap analyses. Legal interpretation stays with humans.
03Evidence collection and audit preparation
The agent compiles evidence, logs and references and keeps track of processing status, so audits start prepared instead of with a search.
04Alert triage in AML monitoring
The agent pre-prioritises alerts and enriches them with context. No automatic closing and no reporting without human approval.
05Report drafting
The agent drafts report sections from structured sources. Reported figures must never be estimated; every figure needs a traceable origin.
Agentic AI is strong in preparation, research, aggregation and drafting, and risky wherever a regulatorily binding action is triggered: reporting, blocking, rejecting, approving.
Risks of chained actions
An erroneous intermediate step can trigger further actions in a chain. Controls therefore need to account for the consequences of the whole chain. Responsibility and available interventions must be defined before release.
01Accountability
Management responsibility follows from Section 25a KWG and MaRisk AT 3.1. Using a technical system does not remove that organisational responsibility.
02Traceability
Record inputs, tool calls and results so that a relevant action can be assessed with its context.
03Error consequences
Assess which subsequent actions an erroneous intermediate result can trigger and where the chain is stopped.
04Effective oversight
Design approvals and monitoring so that responsible people can actually assess the results.
The FSB consultation report
On 10 June 2026, the FSB published a consultation report on responsible AI adoption. It discusses accountability and oversight as design issues for financial entities. These recommendations must be distinguished from directly applicable EU and national legal duties. FSB: Sound practices for responsible adoption of AI, consultation report
The report provides questions for system design: which actions may an agent trigger, and when is intervention required? This assessment can begin with a limited use case. A supervisory publication does not replace assessment of the actual system. FSB: Sound practices for responsible adoption of AI, consultation report
MaRisk and DORA for the particular use
Where an AI model is used for purposes covered by MaRisk AT 4.3.4, the module’s model requirements apply. The assessment depends on its task and use within the institution. Other duties, including DORA and data protection obligations, may apply independently. Management responsibility follows from Section 25a KWG and MaRisk AT 3.1. Using a technical system does not remove that organisational responsibility. BaFin: Rundschreiben 06/2026 (BA), MaRisk
Under DORA, agents are ICT assets. BaFin's guidance of 18 December 2025 makes this concrete in three ways: AI systems belong in an AI inventory, they run through a controlled AI lifecycle from development to decommissioning, and they are subject to ICT third-party risk management. Since agents are usually connected to LLM APIs and cloud services, ICT third-party risk under DORA Chapter V applies on top.
Define controls before release
Control requirements belong in the system’s task specification. The following criteria can support an initial design review. Their implementation is tested against the intended workflows and failure cases.
01Limit actions
Define what the system may perform itself at each step and which consequences must be prevented.
02Assign approvals
Tie approvals to an action’s consequences and test their technical enforcement.
03Limit tool permissions
Expose only the data and APIs required for the task.
04Trace actions
Document relevant intermediate steps, results and the system version used.
05Assign responsibility
Assign responsibility for deployment and changes; determine legal classification and required validation separately.
- EU AI Act for banks: deadlines, high-risk classification under Annex III and BaFin's role as market-surveillance authority.
- MaRisk (BaFin): module system, AT 4.3.4 and the requirements for models, data quality and validation.
- The DORA regulation at a glance: scope, pillars, ICT risk management and the third-party regime under Chapter V.
- Regulatory roadmap for banks: key dates from 2026 to 2028+ in chronological order with references.
Frequently asked questions on AI agents in banking
Sources & further reading
- Regulation (EU) 2024/1689 (AI Act), EUR-Lexeur-lex.europa.eu
- FSB: consultation report Sound Practices for Responsible Adoption of Artificial Intelligence (10 June 2026)fsb.org
- FSB: full consultation report (PDF)fsb.org
- Bank of England: speech by Sarah Breeden, Agents of change (June 2026)bankofengland.co.uk
- ECB: speech by Frank Elderson (3 June 2026)ecb.europa.eu
- BaFin: statement of 18 December 2025 on the guidance for ICT risks in the use of AIbafin.de
- BaFin: guidance on ICT risks in the use of AI (PDF, German)bafin.de
- BaFin: Circular 06/2026 (BA), MaRisk of 30 June 2026bafin.de
- Regulation (EU) 2022/2554 (DORA), EUR-Lexeur-lex.europa.eu
- Section 25a KWG (organisational requirements), gesetze-im-internet.degesetze-im-internet.de
- AI Act consolidated as at 27 July 2026eur-lex.europa.eu
- Regulation (EU) 2026/1744 amending the AI Acteur-lex.europa.eu
- European Commission: AI Omnibus enters into forcedigital-strategy.ec.europa.eu
An offer from T-NEX GmbH
Discuss the project with T-NEX
Start with a limited workflow, explicit action permissions and a testable outcome. A pilot establishes which steps can be automated and where business decisions or escalation remain necessary.
Management: Andreas Unruh and Christoph Gembruch.
Published by T-NEX GmbH.
