Part 1: What Changes When AI Begins to Act?
Identity sprawl, unpredictable workload patterns, and autonomous systems that can outrun their own guardrails. At Everpure's Accelerate, financial-services infrastructure leaders laid out five areas where agentic AI is forcing a rethink.

What breaks first when agents hit production infrastructure? Something's going to break, and you're not going to know what it was. A very good first step is going back to day one. Integrate observability and traceability in your systems, and also evaluation of outputs.

Agentic AI changes a basic assumption behind banking technology: the user interacting with a system may no longer be human.
An AI agent can interpret a goal, retrieve information, invoke tools, interact with systems, and take action. As financial institutions move these systems closer to production, controls designed around human users and predictable application behavior begin to face a different operating model.
That shift is already underway. According to the Cambridge Centre for Alternative Finance's 2026 Global AI in Financial Services Report, 52% of surveyed financial-services industry respondents are actively adopting agentic AI, including 45% of traditional financial institutions and 57% of fintechs.
The question is therefore no longer simply whether financial institutions can move AI from pilot to production. It is whether the operating environment is ready for AI systems that can act once they get there.
Five areas deserve particular attention: identity and permissions, observability and traceability, execution controls, containment, and resilience and recovery.
One request can become a chain of system activity
Traditional banking applications are built around relatively predictable transaction patterns. Agentic systems introduce a different workload model.
An agent investigating a suspicious transaction, for example, might retrieve customer history, query device information, review prior fraud cases, call external data sources, and invoke multiple internal systems before producing an answer or taking an action.
The important change is the chain of activity. One request may touch APIs, databases, identity systems, payment platforms, fraud systems, risk engines, and other downstream services.
The scale of agent activity is expected to grow rapidly. IDC forecasts 1.15 billion active AI agents across enterprises by 2029, executing 217 billion actions per day. That changes the unit of demand for banking infrastructure. One prompt is no longer one transaction. It can become a chain of autonomous activity across APIs, databases, identity systems, payment platforms, fraud systems, risk engines, and other downstream services.
For infrastructure teams, the question becomes larger than whether the AI environment itself can absorb the load. It is whether autonomous activity can create unexpected pressure elsewhere in the institution.
Five operating assumptions financial institutions need to rethink before scaling agentic AI
If agentic AI changes how systems behave, financial institutions need to look beyond whether the model itself is ready for production. The operating environment around it matters just as much.
In June, a discussion at Everpure's Accelerate summit surfaced five areas where assumptions built around human users and predictable applications begin to look very different when the actor is an autonomous system.
1. Identity and permissions
Agentic AI changes the identity question from simply who or what has access to what an autonomous system could discover and do with the access already available to it.
Financial institutions operate with machine identities, inherited permissions, service accounts, and privileges created for applications and workflows that may have existed for years. An agent introduces a different kind of actor capable of exercising that access across systems.
CyberArk's 2025 identity-security research found that machine identities outnumber human identities 82 to 1 across surveyed organizations, with 42% of those machine identities carrying privileged or sensitive access.
For identity teams, the question becomes: What could an autonomous system discover and do with the access already in the environment?
2. Observability and traceability
Andrea Moccia, VP of AI and Data at Options Technology, brought the discussion back to another basic requirement: institutions need to understand what their agents actually do.
“What breaks first when agents hit production infrastructure? Something's going to break, and you're not going to know what it was,” Moccia said. “A very good first step is going back to day one. Integrate observability and traceability in your systems, and also evaluation of outputs.”
Traditional infrastructure monitoring can tell an organization whether a system is available or performing normally. Agentic observability raises different questions. What data did the agent access? Which identity or service account did it use? Which tools and systems did it invoke? What actions followed? What changed downstream?
In financial services, being able to reconstruct that sequence becomes part of maintaining accountability and operational control. The question for institutions is straightforward: if an agent takes an unexpected action, can you reconstruct exactly what happened?
3. Execution controls
Visibility alone doesn't constrain what an agent can do. When Mike Russo asked whether governance could keep pace as AI systems gained more autonomy, Moccia rejected the premise. “Governance can also be machines,” he said, pointing to policy as code and systems designed to confine agents within defined boundaries.
The distinction matters. Governance cannot exist only as a policy document or a manual review after an action has occurred. Some controls may need to operate inside the execution path itself, constraining what an agent can access, which tools it can invoke, and which actions it is permitted to take.
That doesn't eliminate human oversight. It changes where some controls have to live. For financial institutions, the question becomes: which controls need to operate while the agent is acting, rather than before or after?
4. Containment
An agent doesn't have to be malicious to create an operational problem. It can be acting within legitimate permissions and still generate activity at a speed, scale, or breadth the institution did not anticipate.
As agent activity moves across APIs, databases, identity systems, and other services, the effects may not remain confined to the AI environment itself.
That makes containment an infrastructure question. If an agent begins generating unexpected activity, can its access be constrained? Can downstream systems be protected from unexpected demand? Can the activity be stopped without disrupting unrelated workloads?
For financial institutions, the question is not simply whether an agent will behave unexpectedly. It's how far it can go before something stops it.
5. Resilience and recovery
Richard Galvez brought the discussion back to what happens when AI moves beyond the pilot. The teams that succeed, he argued, take a focused use case all the way to production and pay attention to “all the things that are going to break along the way in your infrastructure.”
That mindset becomes even more important with agentic systems. An autonomous system could create a sequence of legitimate actions across multiple interconnected systems before anyone realizes something has gone wrong.
Resilience therefore needs to account for more than restoring a failed application. Financial institutions need to understand which systems were affected, what data or transactions changed, which actions need to be reversed or remediated, and whether the sequence can be reconstructed well enough to understand what happened.
As institutions give AI systems greater ability to act, they also need confidence that unexpected outcomes can be contained, investigated, and recovered from. The question is: if an agent creates an unexpected chain of actions, can the institution contain it, recover from it, and explain what happened afterward?
The disciplines are familiar. The operating model is not.
Identity and access management are not new. Neither are observability, governance, workload containment, or recovery. Financial institutions have spent decades building controls around these disciplines. What is changing is the actor operating inside that environment.
Agents can discover resources, invoke tools, interact with multiple systems, and pursue objectives with a speed and degree of autonomy that traditional applications and human users were not designed around. The challenge, then, is not to invent an entirely new infrastructure playbook for agentic AI. It's to determine where established controls and operating practices need to change when autonomous systems become another actor operating across the enterprise.
Deploying more agents will not give a bank an advantage if it cannot control what those agents do. The advantage will come from building an environment where they can act, while the institution can see, constrain, and recover from their actions.
Financial institutions will deploy agents. The institutions that move successfully will be the ones that understand what those agents can access, can see what they are doing, can constrain how far they can go, and can recover when something unexpected happens. As banks give AI systems more freedom to act, they need to know what those systems can access, see what they do, and step in when something goes wrong.
And those controls are only part of the production challenge. In Part 2, we look at why so many banking AI projects still stall between the demo and deployment.




