Penomic ResearchAgent governance · October 2026

Govern the agent through the institution's decision rights

In 2026 AI agents moved from answering questions to taking actions inside banks, insurers and asset managers, and supervisors said their frameworks do not yet cover them. The control that works is not a prompt but the institution's own decision rights, evidence rules and escalation cases, encoded as a governed layer.

By Jared D. Yerian and Jennifer Kilian · 17 minute read

Download the PDF

In 2025 the question inside most financial institutions was what a language model could be allowed to say. In 2026 it became what an agent could be allowed to do. The agents now in production reconcile trades, open accounts, update fraud rules and move items through a workflow, calling the same systems a member of staff would. That changes the governance problem. A wrong answer can be reviewed. A wrong action has already happened.

Among the 50 banks in the Evident AI Index, the share of newly announced AI use cases that were agentic rose from 15 percent in the fourth quarter of 2025 to 31 percent in the first quarter of 2026 (Exhibit 1).1 In the second quarter the same banks announced 93 new use cases, 45 percent more than in the first, and six of them announced their first agent.6 KPMG's second-quarter pulse of 204 US banking leaders found 39 percent deploying AI agents and 51 percent piloting them.2 In the Cambridge Centre for Alternative Finance's global survey of 628 institutions, vendors and regulators, 52 percent of industry respondents were piloting or beyond on agentic AI, against 28 percent of the regulators who supervise them.3 Among 728 EU securities firms surveyed by ESMA, 141 production use cases, 17 percent of the total, were already agentic, and 27 percent of those ran with medium or high autonomy.4 In February Goldman Sachs confirmed it was building agents with Anthropic for trade and transaction accounting, client due diligence and onboarding.5 By the second quarter BNP Paribas had announced agentic know-your-customer and Danske Bank end-to-end credit automation.6

Exhibit 1

The supervisors have been candid that their frameworks do not yet cover this. The revised US model risk guidance, SR 26-2, states in its third footnote that generative and agentic AI "are not within the scope of this guidance."7 The Financial Stability Board wrote in June that "an AI agent can take hundreds of intermediate steps in pursuit of its goals" and that real-time human monitoring of those steps is impractical at scale.11 Singapore's new guidelines defer agentic AI to a 2027 consultation.12 Our argument is that the control that works in this gap is not a better prompt but the institution's own decision rights, evidence rules and escalation cases, made explicit and encoded as a governed layer that every agent action must pass through.

Continue reading

Read the full paper and get the PDF

The rest of “Govern the agent through the institution's decision rights”, every exhibit and the full source notes. We will also email you the PDF. One form unlocks all Penomic Research.

We use your details to send the paper and, if you ask, future research. See our privacy policy.

About the authors

Jared D. Yerian

Jared D. Yerian, CFA, CIRA, CDBV, Senior Board Advisor, Penomic. Former Partner at McKinsey & Company, where he was one of five founders of the global Recovery & Transformation Services practice, and later Senior Partner and Co-Lead of Transformation at Oliver Wyman. He has served in CFO, CRO and board advisory roles on complex financial and operational transformations, restructurings and M&A. LinkedIn

Jennifer Kilian

Jennifer Kilian, Senior Board Advisor, Penomic. Former Partner at McKinsey & Company and Co-Founder and CEO of Cognition Capital. A transformation executive working where AI, digital product and experience-led growth meet, advising CXOs and boards. LinkedIn

Private architecture briefing

Institutions building an institutional knowledge layer can request a confidential briefing with the authors.

Request a briefing

More from Penomic Research

Flagship paper

The institutional intelligence gap

Financial institutions have wired AI into their data. Value stalls because the firm's definitions, policy, precedent and judgment were never made machine-usable.

AI adoption

Why AI pilots stall after the demo

2026 surveys, bank disclosures and agent benchmarks show that AI pilots stall because the institution's definitions, precedent and decision rights were never written down and governed.

Data and definitions

One number, five definitions

2026 supervisory findings and enterprise benchmarks show why governed definitions, with owners and effective dates, now return more than any model choice in financial AI.