Banks need to rethink identity governance for AI agents
By Jasie FonAs AI moves from assisting to acting autonomously, they need to be governed the way banks govern a user with access.
When the Monetary Authority of Singapore (MAS) published Safeguards for Agentic Finance at Runtime (SAFR) last July, developed with banks and fintechs through the BuildFin.ai initiative, it made explicit something risk teams have been circling around for a while.
As artificial intelligence (AI) agents move from assisting employees to acting autonomously in payments, lending, fraud management, and customer servicing, they need to be governed the way banks govern any user with elevated access, not as software components that behave predictably once configured.
That distinction sounds academic until an agent is actually initiating transactions, and by the time institutions notice the gap in their controls, the agent is usually already in production making decisions.
MAS is careful to note that SAFR is industry guidance, not a supervisory requirement. Even so, its core recommendation is unusually concrete. It calls on institutions to verify and record an agent's intended action before it initiates a payment, approves a loan, executes a trade, or files a regulatory report, rather than reviewing what happened after the fact.
That is a meaningful shift from how most institutions currently operate, where an agent is provisioned once with a broad set of permissions and then largely left to operate within them.
For banks already deploying agentic AI across payments, lending, fraud management, and customer servicing, the operational specificity of that recommendation matters more than the paper's voluntary status, because it points directly at a control that is usually missing.
Asia's regulators are converging on the same principle
Singapore is not alone in reaching this conclusion.
Earlier this year, Hong Kong's Privacy Commissioner for Personal Data urged organisations deploying agentic AI to adopt stronger governance and limit agents to the minimum access rights needed for each task, a clear signal that regulators across the region are paying closer attention to how autonomous systems access sensitive information.
China's National Information Security Standardisation Technical Committee released draft guidance covering the deployment, operation and retirement of AI agents across their lifecycle, taking a broader, more structural view of the same underlying risk.
MAS has essentially translated that shared concern, that autonomous systems require tighter and more granular control than conventional software, into practical guidance for financial services specifically.
For banks operating across these markets, that consistency is worth paying attention to. Supervisory expectations may not develop at the same pace in every jurisdiction, and none of these three papers carries the same legal weight, but the underlying principle is now appearing often enough, and independently enough, that it is reasonable to plan around it rather than wait for a single regulator to make it binding.
Static permissions were not built for actors like this
Bank access models were designed around two kinds of users.
Employees are governed through role-based access, approval workflows, segregation of duties and periodic review. Machine identities such as service accounts and APIs are granted fixed permissions because, historically, once deployed, they kept performing the same narrow thing every time.
AI agents fit neither category comfortably. They act without continuous human involvement, which rules out the employee model, but they can also chain tasks together, retrieve data, and reach systems that were never anticipated when access was first granted, which breaks the machine-identity model too.
An agent reviewing loan documentation, for example, may pull customer records, trigger verification checks and interact with payment or treasury systems in the course of a single task, moving across systems, at machine speed, in ways no static permission set was designed to anticipate.
Accountability moves from IT into identity governance
When an agent submits a wrong payment instruction, approves a transaction that should have been escalated, or makes a decision with financial or regulatory consequences, banks will be asked who is accountable for it. Is that the engineers who built the agent, the business line running it day to day, or the executives who signed off on putting it into production?
Conventional audit trails, built to explain human decisions, or fixed system behaviour do not easily reconstruct how an agent evaluated information, called different tools, interacted with multiple banking systems, and arrived at a decision within seconds.
That is not a hypothetical problem. It has direct implications for fraud investigations, customer disputes, and regulatory examinations, where supervisors will expect institutions to show what the agent was authorised to do, what it actually did, and where those two diverged.
The gap sits squarely with CISOs and identity teams, not model risk or data science functions, because the question is not whether the model is accurate, it is whether this actor was authorised to take this specific action, right now, within this specific scope. That is an identity and access question dressed up as an AI question.
The advantage goes to banks that move first
For many institutions, this is an extension of controls they already run for privileged human users and administrators, applied to a new category of actor, rather than an entirely new discipline. It means access scoped to a defined task, permissions that expire when the task is done, and continuous logging of every privileged action across an agent's lifecycle.
What has changed is the timeline. With MAS, Hong Kong's PCPD and China's TC260 all pointing in the same direction within months of each other, banks that build these controls now, while expectations are still guidance rather than rule, will spend far less time retrofitting once supervisors formalise them.
The institutions that benefit most will not be the ones that wait for a single mandatory regulation to emerge. They will be the ones already extending identity governance to autonomous actors, which will leave them free to expand agentic AI across payments, lending, and customer servicing without governance becoming the limiting factor.