Major banks are beginning to treat AI agents less like chatbots and more like operational workers. That distinction matters because an assistant produces an answer; an agent may have a login, access internal systems, trigger a workflow or complete an approved transaction.

Reuters reported on July 13 that banks are expanding agentic AI across wealth management, client vetting, trading and treasury. Morgan Stanley is preparing to test client-facing assistants later this summer while retaining human oversight for critical decisions. BNY has described digital workers with login credentials, daily tasks and human managers responsible for quality control.

At UBS, agents analyze internal information and surface actions for advisers; after an adviser decides, the systems can support trading and money transfers. Goldman Sachs, JPMorgan and Citi are also developing agents for functions including transaction accounting, onboarding, treasury and wealth management.

The control boundary is moving

The operational change is not simply better text generation. It is the combination of model capability, system permissions and delegated authority. Once an agent can read member data or initiate an action, traditional controls for workforce identity, vendor access, segregation of duties and incident response become part of AI governance.

A June KPMG banking survey found 51% of respondents were piloting AI agents, while 24% were orchestrating multiple agents across workflows. The same survey identified data readiness, system complexity and human-oversight skills as major deployment challenges.

KPMG also found that only 59% of respondents believed their organizations had the capabilities and governance needed to manage AI risk as use scaled. That gap is especially important for smaller institutions: buying an agent through an established vendor does not transfer responsibility for permissions, member outcomes or operational resilience.

What credit unions should require

Credit unions do not need to copy the largest banks’ scale, but they should borrow the discipline visible in these early deployments. Before allowing an agent to move from recommendations to actions, management should require:

  • A named human owner accountable for training, access approval, performance and shutdown decisions.
  • A separate machine identity with least-privilege access rather than shared employee credentials or broad vendor permissions.
  • Explicit action boundaries defining what the agent may read, draft, recommend, initiate and complete.
  • Complete audit logs showing prompts, data accessed, tools used, approvals, outputs and downstream actions.
  • Human approval gates for member communications, money movement, account changes, adverse decisions and exceptions.
  • A tested kill switch plus vendor commitments for incident notification, investigation support and liability.

Those controls should appear in procurement documents and contracts, not only in an internal AI policy. Credit unions should ask core, digital-banking, contact-center, fraud and workflow vendors whether agents receive persistent identities, how permissions are scoped and who bears responsibility when an agent takes the wrong action.

The bottom line

AI agents are entering financial operations before a single regulatory rulebook has emerged. The durable control principle is familiar: authority should be limited, observable and owned by a person. Credit unions that establish that model now can move faster on useful automation without turning convenience into unmanaged access.