September 10, 2026

AI Agents in banking. From automated answers to executed operations

How AI Agents execute the banking operations customers request most, within the rules of the sector, and turn customer care into a revenue center

In banking customer care, the distinction that matters is no longer between those who have adopted conversational AI and those who have not, but between the virtual assistant that explains procedures and the AI Agents that execute them directly on the bank's systems, with permissions defined for every operation and a record kept of every action.

The difference shows in any ordinary operational case, such as a payment declined due to an anti-fraud block outside business hours. The informational assistant explains what an anti-fraud block is and invites the customer to call the dedicated number. The operational Agents verify the customer's identity, show them the suspicious transaction, collect their confirmation through in-app authentication and remove the block within the same conversation. The assistant has automated an explanation; the Agents have automated the work.

In banking, this distinction weighs more than in any other industry, for two reasons that compound. The first is that customer requests are almost always operational, and an answer that defers to further action leaves the need exactly where it was. The second is that every action takes place in an industry where permissions, authorizations and traceability are a regulatory obligation, not an organizational choice. The right question for a bank today is not whether to adopt AI Agents in customer care. It is how far to let them operate, on which processes, and under what governance.

Why the moment is now

The quality of the conversation is no longer the differentiator. Language models have brought the understanding and generation of language to a level the customer takes for granted. Today, the difference is played out on the depth of execution, that is, on how many operations the Agents actually complete, on which systems, and with what guarantees.

Customer expectations, meanwhile, have grown. Operational assistance in real time, at any hour, is now the standard customers are used to, and they expect it from their bank as well. The economics of the contact center, however, have stayed the same. Automating answers alone shifts the cost without absorbing it, because an informed customer still has to act and, failing that, calls back. Automating operations absorbs the cost and frees people for the conversations where judgment produces value.

From cost center to revenue center

The banking contact center was born to contain costs. It becomes a revenue center when service interactions turn into commercial opportunities, handled with the same rigor as a banking operation.

AI Agents pick up signals of interest within assistance conversations, qualify the lead, check consents and trigger the next step without leaving the channel, whether that is an appointment with the most suitable advisor, synchronized with the calendar and the CRM, or the guided start of an application. Every step leaves a trace, and that same trace feeds both the commercial side and the control side.

The enabling condition is integration. Agents connected to the CRM, the core banking system, ticketing and booking systems turn a signal into an action. A disconnected assistant turns it into a reminder for someone else.

Inbound that executes. Cards, KYC, complaints

High-volume inbound requests are the ground where the difference between answering and acting shows first.

Cards and payments

Blocking and unblocking, reissuing, disputing a charge. The Agents verify the customer's identity with the factors set out in the bank's policy, execute the operation or prepare it for whoever must decide on it, and confirm the outcome within the conversation. The after-hours anti-fraud block is not the exception; it is the typical case. And it is the operation with the best ratio between the value the customer perceives and the effort required of the system.

Customer records and KYC

Data updates and document renewals are periodic obligations with predictable volumes. The Agents collect the documents, run the formal checks, update the systems in standard cases and hand over to people the cases that require an assessment. Compliance gains twice over, in the completeness of the collection and in the timeliness of the fulfillment.

Complaints

The Agents gather the elements required by regulation, categorize the case, route it to the right team and inform the customer of timelines and references. The decision on the merits remains with people. The preparation of the case, which today absorbs a significant share of the teams' time, becomes automatic.

In all three cases, the same principle applies. Reversible, low-risk actions proceed autonomously; actions with concrete effects require the customer's confirmation; high-impact or regulated ones are decided by a person. It is the bank that sets this classification, not the technology provider, and the classification evolves with the data.

Outbound that accelerates. Leads, qualification, continuing value

On the commercial side, the dominant variable is time. A lead contacted back within minutes converts at a markedly higher rate than one called back hours later, and the gap widens with the value of the product. No team can guarantee immediate follow-up on every lead, at every hour. AI Agents can, and it is a structural advantage, not the result of an organizational effort.

Qualification is where execution becomes visible. The Agents contact the lead back on the channel the request came from, including voice, gather the necessary information, apply the eligibility rules defined by the bank and screen out the cases that fall outside the target. Once the lead is qualified, they book the appointment with the most suitable advisor, directly in their calendar, with the data already recorded in the CRM. The advisor arrives at the conversation with the context already complete, not starting from zero.

The same mechanism works on the existing portfolio. An abandoned quote receives a follow-up before it goes cold. A newly activated recurring deposit, or an approaching deadline, becomes a relevant contact opportunity, managed within the customer's consents and with the handover to an advisor always one step away. Upselling stops being a mass campaign and becomes a conversation at the right moment, prepared by the machine and closed, when it matters, by a person.

Human in the lead. Governing Agents in a regulated industry

The governance of AI Agents in banking has a precise name, human in the lead. The person leads, the Agents work. The bank establishes in advance what the Agents execute autonomously, what requires the customer's confirmation and what reaches a person. The relationship manager decides on the cases that matter, with the context gathered by the Agents in front of them, not an empty ticket, and concentrates their time where judgment changes the outcome.

This arrangement does not rest on internal memos; it rests on technical means. Every Agent operates with its own credentials and granular permissions for every single operation, according to the principle of least privilege, so that what the Agents can do coincides exactly with what the bank has decided. And every action leaves a record linking it to the conversation that generated it, with the data consulted, the outcome and any handovers to a person. It is the first document a control function asks for, and it already exists.

The regulatory framework makes this arrangement necessary, not optional.

DORA, the European regulation on digital operational resilience, has applied since January 2025 and requires banks to be able to reconstruct the behavior of their information systems and to govern the risk of critical providers, AI Agents included.

The AI Act classifies the creditworthiness assessment of natural persons as high-risk and requires effective human oversight for these systems, meaning the concrete ability to understand the system, correct it and stop it. The obligations on high-risk systems, after the postponement decided by the European legislator in July 2026, will apply from December 2027, but a governance framework cannot be improvised in the months before a deadline. Building it on the human in the lead principle means meeting these requirements by design, because rules decided by people and enforced through permissions can be documented and verified, while the spontaneous behavior of a model cannot.

From pilot to roll-out

The journey does not require a multi-year program. It requires a pilot built as a test, not as a demo. Three or four high-volume operations, autonomy levels defined with compliance and security before release, KPIs set at the start and measured from the first week. A pilot designed this way produces two results, the business case for extension and the trust of the control functions. In banking, the second is worth as much as the first.

The extension then follows the data. Operations that prove reliable move up in autonomy, new ones enter at the most controlled level, and the value curve grows with the depth of execution.

For twenty years, the banking contact center was the place where costs were contained. With AI Agents executing within the rules the bank already owns, it becomes the place where the customer relationship produces measurable revenue. The banks that have made this shift did not automate answers. They automated the work.

FAQ

What distinguishes an operational AI Agent from a traditional banking chatbot?

A chatbot answers within predefined flows and stops when the request steps outside them. An operational AI Agent verifies the customer's identity and executes real operations on the bank's systems, from blocking a card to opening a case, with permissions defined for every operation, authorizations compliant with regulation and complete traceability. The former automates part of the conversation, the latter automates the process.

How does a customer authorize a transaction in a conversation with an AI Agent?

Not with a simple confirmation message. For remote payments, European regulation requires strong customer authentication with dynamic linking, that is, an approval, typically in the bank's app, cryptographically bound to the amount and the beneficiary of that specific operation. The conversation captures the intention and prepares the operation; strong authentication authorizes it. For euro credit transfers, since 9 October 2025, this is complemented by verification of payee, which alerts the customer to any mismatch between the beneficiary's name and IBAN before execution.

Are AI Agents compatible with the compliance requirements of the banking industry?

Yes, if they are designed according to the principle of compliance by design. This requires dedicated credentials with granular permissions for every operation, human decisions on high-impact cases with the file already prepared by the Agent, end-to-end traceability consistent with DORA, and specific safeguards for the use cases the AI Act classifies as high-risk, such as creditworthiness assessment. The general principle is simple. What the Agents can do is decided by the bank, and every action remains verifiable by the control functions.

Non crederci sulla parola
This is some text inside of a div block. This is some text inside of a div block. This is some text inside of a div block. This is some text inside of a div block.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.