Concept Blueprint · For Bank Boards & CTOs

Your bank's next interface is not a screen.
It's an agent.

Mobile banking won the last decade by shrinking branches into thumbs. The next decade will be won by banks that delete the thumbs too — and let goal-driven AI agents execute treasury, payments, lending, and disputes on the customer's behalf, inside hard regulatory rails.

This is a working concept for what an agentic bank looks like: the stack, the mandates, the metrics, and the 16-week path from a glossy dashboard to bounded autonomy on real money.

Thesis

Distribution is about to invert.

For thirty years, banks competed on who could put more controls in front of the customer: more screens, more toggles, more fine print. The mobile era polished that surface. It did not change the model.

Agentic AI changes the model. When a customer's agent — embedded in their phone, their accounting tool, their ERP — picks the deposit, routes the payment, and negotiates the loan, the winning bank is the one whose APIs, pricing, and SLAs are most legible to other software, not to other humans.

The bank that still believes its mobile app is the moat will lose primary relationships inside 36 months. Not to a neobank. To a piece of software the customer trusts more than any bank.

Four shifts

What "agentic" actually means inside a bank.

01

Intent, not navigation

Customers state outcomes — 'park EUR 40k for 90 days at best yield, fully insured' — and an agent assembles the product mix. The UI becomes a conversation log and an approval surface, not a tree of menus.

02

Agents on both sides of the glass

Internal agents (KYC, fraud triage, dispute resolution, treasury rebalancing) and customer-facing agents share the same policy graph. No more 'the chatbot says X but the back office does Y'.

03

Auditable autonomy

Every agent action is signed, replayable, and bounded by hard limits (amount, counterparty, jurisdiction, time-of-day). Regulators get a deterministic trace. The bank gets a kill switch per agent, per customer, per minute.

04

Distribution flips

When the customer's agent picks the product, the winning bank is the one whose APIs, pricing, and SLAs are most legible to other agents — not the one with the prettiest mobile app.

Reference stack

Four layers. No magic. Every layer regulator-readable.

L1 — Policy & Limits
The regulator-grade rulebook
Codified risk appetite, AML thresholds, customer mandates, jurisdictional rules. Single source of truth that every agent must call before acting.
L2 — Agent Runtime
Goal → plan → action loop
LLM planner + deterministic tools. Tools are real banking APIs (payments, FX, lending, custody) wrapped with limit checks, idempotency, and dual-control hooks.
L3 — Memory & Mandate
Per-customer agent profile
Long-lived consent: what the agent may do, with what cap, for how long, and what requires human approval. Revocable in one tap, expires by default.
L4 — Telemetry & Replay
Prove what the agent did and why
Every decision is logged as (state, plan, tool call, result, policy version). Disputes, audits, and incident reviews replay the exact trajectory.
Where it pays back first

Six concrete agents your bank could ship this year.

Retail

Cash-flow autopilot

Agent forecasts the customer's next 30 days, moves idle balance to a yield product, pulls it back two days before a bill, and explains every move in plain language.

SME

Treasury-in-a-box

For companies too small to hire a treasurer: agent sweeps cash across currencies, hedges receivables above a threshold, and flags covenant risk before the quarter closes.

Cards

Dispute resolver

Agent ingests the merchant evidence, customer narrative, and scheme rules, drafts the chargeback decision, and routes only the ambiguous 8% to a human analyst.

Lending

Underwriting copilot

Agent pulls accounting data with the SME's consent, runs scenario stress tests, and returns a priced offer in minutes — with the full reasoning chain attached for the credit committee.

Onboarding

KYC orchestrator

One agent coordinates document capture, sanctions screening, UBO discovery, and EDD. Median time-to-account drops from days to minutes; the exception queue is the only thing humans touch.

Ops

Incident commander

When a payment rail degrades, an agent reroutes flows, notifies affected customers with accurate ETAs, and opens the post-mortem doc populated with the actual timeline.

What "shipped" looks like

Four numbers a board can hold the program to.

60–80%

of routine journeys handled end-to-end without a human in the loop

<2 min

median time-to-resolution on the journeys agents own

100%

of agent actions replayable with policy version and signed trace

1 tap

for a customer to revoke or narrow an agent's mandate

Don't do this

Five ways banks already mess this up.

  • ×

    Bolting a chatbot on top of the same broken IVR and calling it 'agentic'.

  • ×

    Letting the LLM 'be creative' with money. Planners propose, deterministic tools dispose.

  • ×

    One mega-agent for everything. Small, scoped agents with narrow tool belts ship and stay safe.

  • ×

    Treating policy as prompt text. Policy lives in a typed, versioned, regulator-readable layer — not in a system message.

  • ×

    Logging the chat transcript and calling it an audit trail. Audit = state + plan + tool calls + policy version + signature.

The 16-week path

From dashboards to bounded autonomy on real money.

Weeks 0–2

Pre-mortem & scoping

Pick two high-volume, low-blast-radius journeys (e.g. card disputes, internal transfers). Map current UI clicks, handoffs, and back-office work. Define the kill-switch and the audit contract before a single agent is built.

Weeks 3–8

Shadow-mode pilot

Agents run in parallel to humans on real traffic but cannot execute. Compare decisions, latency, and reasoning quality. Tune the policy layer until disagreement with humans is explainable, not random.

Weeks 9–16

Bounded autonomy

Agents act on the easy 60–80% with hard limits. Humans handle the long tail. Publish weekly metrics: automation rate, override rate, complaint rate, regulator-grade trace coverage.

Quarter 2+

Customer-facing agents

Open the mandate surface to customers. Start with one product family. Treat the mandate UI as the new core-banking interface — because it is.

Private working session

Have us pressure-test your agentic roadmap.

A 90-minute private working session with your CTO, Chief Risk Officer, and head of digital. We bring the blueprint, the anti-patterns, and the questions your vendors don't want you to ask. You bring the actual constraints.