I have been thinking about agentic AI a lot lately, and not just from the perspective of how financial institutions might deploy GenAI tools internally to make employees more efficient. I am thinking about what happens when our customers have their own agents and those agents begin interacting with the bank on the customer’s behalf. I believe that will represent a very different proposition. My thinking on this was accelerated by an excellent recent article in The Financial Brand, “The Agentic AI Challenge: Solve for Both Efficiency and Trust,” written by Nicole Volpe. The article summarizes a discussion between James Dotter of MX and Derek White of Primitive regarding how financial institutions should approach agentic AI. Among the most important points they make is that banks need to distinguish between processes where AI can amplify humans and those where allowing an agent to perform an act introduces a very different level of risk. They also identify gateways, guardrails and governance as foundational controls for safely integrating agentic AI into financial services. I think they are spot on in their analysis, but I want to take this discussion one step further. What happens when the AI agent doesn’t belong to the bank? What, were you thinking that if a customer was going to deploy an agent, it would have to be one you provided? Your Customer Is Going to Have Their Own Agents Let’s back up a bit and define what we are talking about. Generative AI (GenAI) generally waits for you to ask it something or at the very least, to initiate an action. Agentic AI can be given a goal, trained on how to achieve that goal and then the agent is empowered to take a series of actions to accomplish that goal. Think about that from the customer’s perspective. Instead of a customer opening your mobile app, examining balances, looking at upcoming bills and deciding whether to move money from savings into checking, the customer might tell an AI agent: “Manage my cash so I don’t overdraft, keep at least $2,000 available in my {bank name} money market account for emergencies and move excess funds elsewhere where I can earn the best safe return.” The agent could monitor the customer’s accounts and make recommendations. Over time, the customer would likely have the confidence to say to the agent: “Just take care of it.” All of a sudden, we’re dealing with something entirely different. The agent was not instructed to maintain a relationship with the current financial institution. Banks have a lot of repeat customers held in place by inertia, who do not have the time to research all of the various account options where their money could be at work. But an agentic agent? It has nothing but time … Or imagine a small business owner telling an agent: “Pay all approved invoices on the optimal date, maintain enough operating cash for the next 30 days and move excess cash into the best yielding insured option available.” Having a digital assistant that can easily handle request like these makes for a very compelling service. In fact, I believe customers are going to fully embrace agentic AI capability. Why wouldn’t they? Our customers don’t want to spend Saturday morning reconciling accounts, comparing rates, reviewing bills or figuring out whether they have enough money sitting in their checking account. If an intelligent agent can do those things safely, customers will happily delegate some (or all) of that work. The advent of agentic AI agents also creates a tremendous opportunity for community banks. I have written for years about the need for community institutions to move from transactions to engagement. AI agents could become an important part of that transition. A bank could provide its own agent that acts initially as an advisor: explaining transactions, identifying unusual spending, suggesting savings strategies, helping a business manage cash flow or walking a customer through financial alternatives. Done correctly, the agent doesn’t replace the community banker. It amplifies the banker. Providing your own AI agent also gives you control over what that AI agent is empowered to do. That point also comes directly through in The Financial Brand article. Dotter describes the goal as expanding the banker’s capacity so the banker can spend more time guiding clients and closing business. That aligns with something I have rigorously advocated regarding AI: the better opportunity is frequently using AI to augment human work rather than simply eliminating people. Said another way, bankers can transition fully from providing information into delivering wisdom. But there is an enormous operational problem lurking underneath all this innovation. Banking Systems Don’t Do “Maybe” This may be the most important issue community bankers need to understand about AI. AI is probabilistic. Banking is deterministic. If you think that sounds like something only the IT people need to worry about, it isn’t. A probabilistic system effectively says, “Based on everything I know, this is probably the correct answer.” A deterministic banking system says, “Your account balance is $4,287.63.” Not approximately $4,287. Not probably $4,287.63. Exactly $4,287.63. As The Financial Brand article points out, Large Language Models and AI agents are probabilistic while the systems banks rely on to operate are deterministic. Dotter put it particularly well by saying, “there are certain things within finance you don’t want to have probabilities around. You don’t want a ‘maybe’ in an account balance.” Exactly so. I have previously written about this very characteristic. GenAI is based on probability rather than concrete absolute facts, meaning its output can sometimes be non-repeatable or simply wrong. That’s manageable when GenAI is drafting a marketing post. It gets considerably more interesting when a GenAI agent is moving $25,000. Banks have spent decades building deterministic systems surrounded by policies, procedures, dual control, transaction limits, authentication, audit trails and defined employee authority. If Mary in Accounting can initiate a wire but cannot approve one, our systems know exactly what Mary can and cannot do. Now a customer named Joe instructs an AI agent to engage with normal banking activities. What exactly is it empowered to do? Our Procedures Weren’t Written for This Suppose a customer gives an AI agent permission to manage cash across several accounts. The agent determines that $20,000 should be transferred from Bank A to Bank B because Bank B currently pays a better rate. Why? The customer authorized the agent to optimize yield. But the customer did not specifically authorize this $20,000 transfer. So, the question is, did the customer authorize the transaction? Maybe. Hmmm, there’s that word again. Now suppose the agent misunderstood one of the customer’s instructions. Or relied on inaccurate information. Or selected the wrong account. Or initiated a payment to a fraudulent recipient. Who is responsible for the loss? Your customer? The AI provider? You? The company providing the interface between the AI and the bank? I am quite sure that current operational procedures, customer agreements and liability structures are not prepared to answer those questions. And community banks should pay particular attention because we have been down a similar road with payments. I have written about Authorized Push Payment fraud and the growing pressure to make banks responsible when customers authorize perfectly functioning payment systems to send money to end points that turn out to be bad actors. Agentic AI could make that liability discussion exponentially more complicated. If the human didn’t click “Send,” but previously told the AI agent it could make payments within certain parameters, does that constitute authorization? That’s not a hypothetical “this could happen years down the road” question. It’s coming. Soon. Start With Advice, Then Carefully Add Authority Does all this mean banks should block AI agents from interacting with their systems? Absolutely not. A better approach is progressive authority. Start with offering an agent that can see and advise but cannot act. Let it analyze cash flow, identify opportunities, explain options and recommend actions. The customer still executes the transaction. Then perhaps allow some limited actions: moving money between owned accounts up to a defined amount, scheduling an already established bill or preparing a transaction that subsequently requires human approval. Only after trust develops should the authority expand. This is consistent with White’s recommendation in The Financial Brand that consumer-facing agents begin in an informational, conversational mode while their permission to act remains limited. When action is eventually permitted, the deterministic banking system must remain the final authority. The probabilistic GenAI agent can recommend. The deterministic system must validate. The agent can determine that a transaction probably makes sense. The bank’s controls determine whether it is actually permitted. That’s the bridge between probabilistic intelligence and deterministic banking. Your Next Customer May Not Be Human Here’s where we get a little crazy. We should begin designing banking services not only for customers using keyboards, browsers and mobile apps but for customer-controlled agents interacting with banking services through secure gateways. That means your future digital banking strategy may need to answer questions nobody was asking three years ago, such as: How does a customer authorize an agent? What information can the agent access? What transactions can it initiate? What dollar limits apply? When must the human step back into the process? Can the customer immediately revoke the agent’s authority? How do we authenticate the agent? How do we maintain an audit trail showing exactly what the customer instructed, what the agent decided and what the bank executed? And perhaps the biggest question: When something goes wrong, who is responsible? These issues belong in conversations with your core provider, digital banking vendor, legal counsel, compliance professionals and board. The discussion needs to begin now, not after customer-controlled agents begin knocking on your digital front door. Agentic AI represents an enormous opportunity for community banks. It can amplify the workforce, provide customers with personalized financial wisdom, improve business cash management and deliver exactly the type of intelligent self-service younger customers increasingly expect. However, we cannot simply bolt a probabilistic brain onto a deterministic banking system and hope everybody gets along. The winners will not be the banks that say no to agentic AI. Nor will they be the banks that turn an AI agent loose with the keys to the vault. Winners will be the institutions that figure out how to let probabilistic intelligence operate inside carefully constructed deterministic boundaries — with gateways, guardrails, governance, human decision points and very clearly defined liability. The customer of the future may still be human, but increasingly, the entity standing at your digital teller window could be that human’s AI agent. Banks need to start thinking now about how they’ll respond when an AI agent asks to make a withdrawal on a customer’s behalf. Author’s Note – ChatGPT was used in researching this article.