Financial institutions are moving closer to using AI agents to execute business processes, but the biggest holdback to adoption is no longer whether the technology is capable enough. It is whether banks can prove that autonomous systems can be trusted, controlled and audited.
In conversation with iTNews Asia, Michael Heinrich, CEO of 0G Labs, outlined the challenges financial institutions face as they move from AI assistants and pilots towards autonomous agents that can make decisions and execute tasks with limited human intervention.
“The gap is not capability, it is evidence. Executives are not waiting for a smarter model. They are waiting to be able to prove exactly what an agent did and why,” Heinrich said.
For banks, that means every action taken by an AI agent needs to generate evidence that can withstand scrutiny from compliance teams, auditors and regulators.
Heinrich said an effective audit record needs to be complete, tamper-evident and reproducible. It should capture not only successful actions but also blocked and failed attempts, while allowing a decision to be replayed using the same inputs, model version and policy set.
“Banks distrust anything they can’t audit,” he said. This makes trust less about reaching a point where a model is considered sufficiently intelligent and more about creating a framework around it.
“Trust is not a line the model crosses on its own. There is no moment where a model gets smart enough that you hand it the keys,” he added.
Instead, autonomy is likely to be introduced workflow by workflow, starting with low-risk and reversible decisions before moving towards processes with greater consequences.
Model may not be the biggest differentiator
As enterprises evaluate agentic AI, Heinrich believes organisations are still emphasising on model selection. “The model is the most commoditised part of this whole stack,” he said.
The bigger challenge is building the infrastructure around the model including memory, orchestration, identity, permissions, logging and enforcement.
“A brilliant model with no memory and no accountability is not an asset, it is a liability,” he explained.
This also changes the order in which enterprises should approach AI deployments. Rather than selecting a model first and addressing governance later, Heinrich said institutions should establish their governance architecture upfront, allowing models to become interchangeable components within a controlled system.
The infrastructure gap could hold back agentic AI
Moving from one AI agent working under close human supervision to fleets of autonomous agents introduces another challenge of managing state and activity at scale.
He identified durable memory, portable identity for each agent and scalable audit trails as key requirements for moving beyond individual pilots.
The issue becomes particularly important in financial services, where thousands of automated decisions could be happening simultaneously and where organisations need to understand what happened across an entire workflow.
Traditional governance models are also being challenged because they were designed around human actors who can be trained, reviewed and held accountable.
AI agents can act at machine speed and operate at a scale that makes retrospective review insufficient. “The shift is from governance as paper policy checked quarterly to governance as code that runs inline, at the moment of the decision,” Heinrich said.
That means existing controls such as least privilege, segregation of duties and approval processes need to be translated into mechanisms that operate during execution.
For example, agents should have their own scoped and expiring credentials rather than inherit a human employee's permissions. Irreversible actions could require a second approval before execution, while the system performing an action should be separated from the system recording it.
Heinrich also highlighted the need for controls that prevent agents from repeating actions, such as issuing the same credit or processing the same transaction more than once.
Shadow AI adds another layer of risk
The move towards autonomous AI is also taking place alongside the growth of unapproved AI use within organisations.
Heinrich said employees are already using consumer AI tools with customer information and building their own agents outside formal enterprise controls.
Rather than relying solely on bans, organisations should provide sanctioned AI routes that are easier and more effective than unapproved alternatives.
“Ban it and it moves somewhere you cannot see. Give people a better path and it comes back inside the perimeter, where it can be audited,” Heinrich said.
The biggest gains may come from the back office
While customer-facing AI continues to attract attention, Heinrich expects some of the earliest meaningful gains from autonomous agents to emerge in less visible banking operations.
Reconciliation, compliance review, fraud and AML triage, settlement and payment exception handling are among the areas he sees as particularly suited to agentic AI. “The unglamorous work is where autonomy pays first, and it pays quietly,” he said.
He also identified transaction reconciliation, first-line fraud and AML triage, routine credit pre-checks and regulatory report assembly as potential candidates for end-to-end automation.
Measuring AI by work completed
The shift towards autonomous workflows will also require banks to rethink how they measure AI success.
Instead of relying primarily on chatbot metrics such as customer satisfaction or deflection rates, boards should examine autonomy rates, error and reversal rates, time to detect and correct problems, auditability, blocked actions and the cost of completing a task compared with the human baseline.
“The north star is work completed, not conversations handled,” Heinrich said.
The same principle applies to ROI. Heinrich argued that organisations should move away from measuring how much faster employees become with AI and instead measure the cost of work completed autonomously.
Trusted deployment could become the competitive edge
As AI models become increasingly accessible, Heinrich believes competitive differentiation for banks will come from proprietary data and the infrastructure needed to deploy AI safely in regulated environments.
This could make the ability to clear new AI workflows through compliance quickly a competitive advantage, rather than simply the availability of a more capable model.
For bank leaders, Heinrich's argument is that agentic AI should not be approached primarily as a model procurement decision.
“They are asking ‘which vendor, which model’ when they should be asking ‘do we have identity for our agents, durable memory, verifiable execution, and controls that run inline,’” he said.
Heinrich added that organisations also need to build data quality and governance alongside autonomy rather than treating them as separate prerequisites. “Autonomy on top of bad data and weak governance just automates your mistakes at machine speed,” he said.
For enterprises moving into the next stage of AI adoption, the path to autonomy will depend on whether organisations can build the controls, identity, memory and evidence needed to let those models act.
“In this domain, trust is not the tax you pay for autonomy. It is the thing that makes autonomy possible at all,” said Heinrich.




