(23) Autonomy Should Be Earned Like a Credit Limit
Start at zero
An autonomous financial agent should begin with no execution authority and earn larger limits only through verified performance inside a stable workflow. Sygnum Bank used that conservative starting point in May 2026. Its agent planned multi-step on-chain transactions, reviewed smart contracts and flagged risks, but the client approved and signed every action from a self-custodial wallet. The agent could recommend movement without possessing the authority to move anything.
That arrangement makes sense for a first live deployment. It cannot be the permanent design for high-volume finance. Visa reported in September that most agentic-commerce deployments still retain a human in the loop, while its US survey found only 23% of respondents trusted generative AI to handle payments. Trust has to accumulate before authority does.
The credit-limit analogy is useful because a limit is provisional. An institution can raise it after observing low error, exception, override and policy-breach rates across a defined volume of work. Deterioration should cut it. Observed evidence should determine the amount.
Authority belongs to the workflow
The agent is too broad a unit for this decision. A limit should attach to a specific operating envelope: model version, data, tools, transaction type, counterparties, payment rail and control policy. An agent that has processed recurring supplier invoices reliably has not earned authority to open a credit line, trade an unfamiliar asset or pay a new wallet.
US banking regulators' April 2026 model-risk guidance offers a useful analogy with an important caveat. It explicitly excludes generative and agentic AI from scope. For the models it does cover, risk depends on purpose, exposure and use; validation normally precedes first use; performance is monitored against defined thresholds; and incomplete validation can require tighter limits. Applying that logic to agents is an inference, but a practical one. A changed model, tool, data source or transaction rail changes the system that produced the evidence. The affected authority should fall until the changed workflow is tested again.
This extends the AI maturity gap as an operating-model problem. Reusable governance is valuable because it shortens the path to the next controlled deployment. It should never make yesterday's evidence transferable to a materially different action.
Put the limit outside the model
An agent cannot be allowed to grant its own promotion. The IMF's April 2026 architecture places probabilistic intent upstream of deterministic authorization and settlement. Google's AP2 specification implements the same separation: its trusted approval surface must be non-agentic, validation must use deterministic code, and autonomous payments operate under previously signed constraints. The IMF also describes wallet controls for spending, velocity, counterparties and approval workflows.
Those controls make autonomous execution technically possible, while promotion requires a separate evidence test. An August security analysis of AP2 found that valid mandate signatures can preserve transaction data after signing while manipulated messages and tool calls corrupt the context that produced the mandate. A separate August paper on authority-inference separation reached a compatible conclusion: a financial proposal should receive temporary authority only after an independent control plane checks identity, mandate, policy and transaction semantics.
Successful settlement is therefore a weak promotion metric. The evidence should include adversarial tests, blocked attempts, human overrides, near misses, reconciliation outcomes and the completeness of the decision record. A clean audit trail of easy transactions cannot support a higher ceiling against attacks the system has never faced.
The human loop should shrink
The strongest objection is that moving money is too consequential for earned autonomy: a person should approve every transaction. Sygnum's pilot shows that model can deliver useful agentic planning while preserving human custody and consent. It remains a defensible boundary for novel, irreversible or high-impact actions.
Universal approval becomes weaker as volume rises. Fundi Tshazibana, speaking as head of South Africa's Prudential Authority in May, asked whether humans in the loop would catch problems or merely satisfy regulators. Bank of England roundtable participants made the same concern operational: agentic risk management needs more emphasis on testing, monitoring and outcome guardrails because traditional validation and a generic human checkpoint will not scale.
Humans should retain policy design, accountability and exception judgment. Routine actions can earn bounded execution authority; a new counterparty, expanded purpose, irreversible rail or material system change should restore approval. Before the first live transaction, the institution should define the evidence needed to raise a limit, the events that cut it and the changes that reset it. If it cannot state what an agent must prove before receiving the next pound of authority, it has authorised a pilot without building an operating model.
Sources
Regulation and institutional practice
-
Federal Reserve, FDIC and OCC, "Supervisory Guidance on Model Risk Management" https://www.federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf
-
Bank of England, "Summary of AI roundtables - February 2026" https://www.bankofengland.co.uk/minutes/2026/february/summary-of-ai-roundtables-feb-2026
-
Fundi Tshazibana, "Regulation and Supervision of the Financial Sector in the Age of Artificial Intelligence" https://www.bis.org/speeches/20260520-regulation-and-supervision-financial-sector-age-artificial-intelligence
-
Sygnum Bank, "Sygnum Completes First Live AI-Agent Driven Digital Asset Transactions by a Regulated Swiss Bank" https://www.sygnum.com/news/sygnum-completes-first-live-ai-agent-driven-digital-asset-transactions-by-a-regulated-swiss-bank/
-
Jack Forestell, "Your AI Just Bought You a Couch. Are You Okay with That?" https://corporate.visa.com/en/sites/visa-perspectives/innovation/visa-trust-index-trust-powers-agentic-commerce.html
Architecture and security
-
Sonja Davidovic and Hervé Tourpe, "How Agentic AI Will Reshape Payments" https://www.imf.org/-/media/files/publications/imf-notes/2026/english/insea2026004.pdf
-
Google Agentic Commerce, "Agent Payments Protocol (AP2) Specification" https://github.com/google-agentic-commerce/AP2/blob/main/docs/ap2/specification.md
-
Avital Aviv, Parth A. Gandh, Ron Bitton and Asaf Shabtai, "Beyond the Mandate: A Systematic Security Analysis of the Agent Payments Protocol (AP2)" https://arxiv.org/abs/2608.23858
-
Hui Gong, Michail Samawi and Francesca Medda, "Authority-Inference Separation in Agentic Finance: First-Line Control, Blockchain Enforcement, and Replayable Assurance" https://arxiv.org/abs/2608.30519