Original Research

AI Agents in Banking: New Research Shows Agents Taking Action

Last updated on: Sep 29, 2026

A survey of 520 U.S. finance leaders finds AI agents are already initiating payments, approving payments and tracking transactions—and finance teams plan to give them a larger role in banking. The next challenge for banks is recognizing, authorizing and governing them when they arrive. The research below seeks to understand that gap in readiness.

New Research: AI agents are moving into banking transactions. Are banks ready to receive them?

AI agents are moving quickly from experimentation into everyday finance work. That creates a new challenge for banks. Most banking controls were designed assuming they were engaging with known human users or established system-to-system connections.

That assumption is out of date because customer AI agents are starting to act in workflows.

New OvationCXM research surveyed 520 U.S. finance leaders in organizations ranging from less than $5 million in annual revenue to $1 billion plus. We asked how they use AI agents today, where they expect to expand that use in the next 12 months, how much authority they will give agents over eight different banking tasks, and the controls they want in place to oversee agent action. The findings align with what is being seen on the consumer side of the bank - agentic banking is advancing and must change how financial institutions operate.

In a nutshell, the majority of finance leaders are using AI agents to act in some way in their work, they expect to use them for more significant banking activity, and while they are willing to delegate authority to them across a wide range of tasks, they are unwilling to do so without controls and governance.

For banks, regardless of where agents originate and what activity the finance leaders enable them to do, the institrution is ultimately responsible for what happens in the account. That creates requirements around agent identification, authorization, permissions and controls, and the ability to apply them across teams, systems, partners as it move through the whole transaction. That is not achievable on th client side with a prompt - that is wholly the responsibility of the bank.

Majority of finance leaders are using or piloting AI agents in their work

Nearly 75% of finance leaders are actively using or piloting AI agents in at least one finance workflow today. Specifically, about 30% are using them in multiple workflows, 28% in one or more workflows and 17% are piloting or testing their use. 

This is no longer a discussion about AI agent adoption. It’s now about execution.

When we asked which workflows are leveraging AI agents, finance leaders pointed to financial close as the top answers, followed by tracking transactions, AP invoice processing, AR collections and follow-up, payment approvals and initiating payments and transfers. 

AI agent usages is also expected to grow because 74% said AI agents are important to their finance operations over the next 12 months. A number of the workflows they are targeting to expand require bank interaction, whether it’s to provide information or update accounts or execute money movement. 

AI agents are not coming from one place

One of the most interesting findings was the platforms where AI agents are being used. 

There is no single enterprise platform or channel. Among finance leaders using AI agents for work, general-purpose AI tools lead, but finance leaders also report agent use across productivity tools, spreadsheets, finance applications and banking channels.

ChatGPT leads at 39%, followed by Microsoft Copilot at 36%, Excel/Google Sheets at 32% and Gemini at 28%. By comparison, 13% report agent use through a bank portal and 12% through a direct bank API or integration.

Three of the top six agentic workflows may directly involve the bank

AI agents are not being limited to basic tasks. Three of the six most common agent use cases are workflows that may directly involve the bank: tracking transaction status, approving payments, and initiating payments or transfers. And finance leaders expect agent involvement in banking activity to expand.

Among respondents using or planning to use agents, 28% expect to use them for ACH payments over the next 12 months, 23% for scheduled disbursements and 23% for wire transfers. That doesn't mean AI agents are independently logging into banks and moving money today. Our research did not ask that question.

What it does show is that finance teams are using agents in workflows that increasingly intersect with banking and expect to give them a role in more consequential banking activities. So we wanted to understand something more specific: How far are finance leaders actually willing to let an agent go?

There’s little dropoff in delgated authority between read-, instruct- or transact-level banking tasks 

We asked finance leaders the highest level of authority they would give an AI agent across eight banking activities.

The activities ranged from relatively simple, read-oriented tasks like checking balances and transaction status to more significant activities like initiating payments, moving money between accounts, approving third-party payments or updating banking details.

We expected the level of authority to drop as the tasks became more consequential and complex, but that did not happen. 

Across six of the eight banking activities we surveyed, more than half would allow an agent to at least initiate or advance the activity. That includes 52% for payment, ACH, wire or transfer initiation and 51% for moving money between company accounts or entities. Around 49% of finance leaders would also allow an agent to at least initiate the process to approve or release a third-party payment.

It was surprising that the differentiating factor was not primarily the complexity or significance of the task but the level of controls applied to those tasks.

Finance leaders don’t want to provide unrestricted authority, however. They want bank-side controls on agent activity

Finance leaders are willing to delegate authority to agents, including for transact-level activity. But they generally want boundaries around that authority.

Across the banking activities we surveyed, the prevailing preference was to have human approvals built in before initiating or executing tasks rather than unlimited authority to act automatically, even with preset limits.

Automatic execution was only in the single digits, a clear minority. Even in simple tasks like rrequesting a bank statement, only 17% would let an agent act automatically. This dropped to 9% for approving or releasing a third-party payment.

When we asked what would give finance leaders confidence in agentic banking, their top choices were role-based permissions and limits (39%), the ability to suspend or revoke access (38.1%), real-time status visibility (36.5%), confirmation and audit history (35.6%), and identity and authorization verification (34.4%).

These are typical controls applied to human customers.But finance leaders want them extended to AI agents as well, setting up discussions about the technology stack that will enable these controls.

AI agents are coming through multiple platforms

Banks have spent decades building identity and authorization controls designed to determine who is requesting access, whom they represent and what they are permitted to do. Customer-controlled AI agents add a new layer to that problem.

As finance teams automate more work, banks need a way to determine whether an agent making or initiating a request is known, whom it represents, what authority has been delegated to it and whether the specific action falls within its permissions and limits. Identifying and authorizing the agent at the point of entry is only the beginning.

Those permissions, limits and approvals have to remain in force as the request moves through systems, workflows, teams and partners to execution. Banks need to know not only who is asking, but whether each action is allowed, when human approval is required, when activity should be stopped and what happened at every step. That makes agentic banking more than an access problem; It is becoming an end-to-end governance and orchestration challenge.

If banks can't support agentic workflows, many customers will find a workaround

We also asked finance leaders what they would do if their primary bank couldn't support AI-agent-initiated workflows. About 43% said they would find a workaround to use AI agents, ,with 22% saying the would build their own integrations internally and another 22% saying they would use a third-party platform to enable their use. About one-third would continue with manual processes for now, and 10% would move more of their business to a provider that could support them.

For banks, this creates a hidden risk. While one of the bank's top concerns is losing deposit dollars and customer relationship, this data implies that a customer may not necessaily close an account for the bank to lose primacy in the workflow and the relationship. If customers begin routing agent-activity through their own infrastructure or a third-party platform, the deposit relationship can appear intact even though more and more of the work and the interaction is happening outside the bank where it can't be seen or controlled.

That is why agentic banking must go beyond offering an API or connectivity. That is the starting point, to be sure, but it's only the first step. The strategic question is who will control and orchestrate the work once a customer's agent is involved.

What questions must banks be able to answer

Banks don't need a complete new framework to extend their risk management to customer-owned AI agents. The core issue remain the same - the goal is to ensure authorized users can complete authorized requests. However, as AI agents approach banks, it simply adds a new layer of complexity to an already complex banking journey. Orchestration technology remains the right solution, if it is built to receive and govern Ai agents as well as humans.

Banks need infrastruture that can answer the following questions, at speed and at scale:

  • Who is this? Is it a known, registered AI agent?
  • Who authorized it? For which banking customer is it acting?
  • What is it allowed to do? In which accounts is it allowed to act, in what amounts and how often?
  • Does this request comply with the rules? Does the requested action fall within its authority, permissions and limits?
  • Does a human need to approve it? And yes, who, and how will it be routed?
  • Can we stop it? Is there a kill switch to revoke an AI agent's access immediately or pause it temporarily?
  • What happens next? Which systems, teams or partners need to participate to complete the request and what are the steps?
  • Can we see agent actions in real time? Can we monitor agent activity as it happens?
  • Can we prove it? Is every request, approval, exception, action and decision on record?

Answering the identity questions gets an agent through the front door. The harder work is everything after that, from enforcing permissions, limits and approvals as the request moves across systems, teams and partners, handling exceptions when something doesn't go as planned, and maintaining visibility and an audit trail until the work is complete.

Agentic banking - connectivity plus governance

What is the takeaway to the research? Financial institutions need an operational plan and a control layer that addresses client-owned AI agents that are going to increasingly requesting actions that must be vetted and then a decision made. We recommend a five-step framework.

For banks, enabling AI agent connectivity for customers is only the first step.

1) Banks need to recognize the agent and confirm the identity of the customer it represents.

2) They need to validate its authority to act.

3) Next, they must verify whether it has permission to make this specific request and apply any limits or thresholds.

4) Once the decision is made the bank needs to orchestrate the workflow and monitor the process to ensure the controls are applied at each step along the way.

5) Each action, decision, pause, approval, etc. must be documented and preserved in a detailed and accessible audit trail.

‍

For more resources on agentic banking and governance of AI agents:
Download our latest research report, AI Agents: From Experiment to Execution - no email required.

Download our agentic readiness research report, When AI Agents Become the Customer.