In the span of five days, four separate financial institutions each put an autonomous AI agent into a system that touches real money. A Singaporean bank let agents draft the credit memos its relationship managers sign off on. A British neobank shipped an assistant that can move a customer’s own money without being asked twice. A crypto exchange opened its trading engine to agents built by outside developers. And two of the world’s largest card networks joined a coalition to decide, before anyone else does, who gets to authorize an agent to spend on a person’s behalf. None of this was coordinated. That it happened in the same week anyway is the story: agentic AI has stopped being a chat interface bolted onto a bank’s website and started being infrastructure that banks, exchanges and card networks build production systems around.
What “Agentic” Actually Means Here
The word gets used loosely enough that it is worth being precise about what changed. A chatbot answers a question. An agent completes a task: it plans a sequence of steps, calls other systems to execute them, and produces an output a human reviews rather than assembles. That distinction is why DBS, Singapore’s largest bank, chose to deploy its newest agentic system not on the customer-facing side of the business but inside the unglamorous, high-stakes work of corporate credit underwriting.
DBS announced on August 19 that it has rolled out an agentic AI system to roughly 1,500 relationship managers and credit risk managers globally, following a 150-person pilot. The system uses specialized agents to handle more than 70 distinct tasks involved in preparing a corporate credit memo, pulling and synthesizing raw financial and market data into what the bank describes as a review-ready first draft. Bankers still sign off on the analysis; the agents do the assembly work that used to consume days of an analyst’s time. “We believe that agentic AI can help to reimagine corporate banking,” said Han Kwee Juan, DBS’s group head of institutional banking, adding that the goal is to “level up the quality of our credit analysis at scale.” DBS expects the system to cut time spent on credit memo preparation by at least 30 percent, freeing relationship managers for client-facing work an agent cannot do.
That is the pattern worth noticing: the highest-value early deployments of agentic AI in banking are not chat widgets. They are agents inserted into a specific, bounded, previously-manual workflow, with a human still required to approve the output before it becomes a decision that touches a client’s balance sheet.
The Same Idea, Pointed at the Customer
Starling Bank took the same architecture and pointed it outward. The UK digital bank has launched what it calls the Starling Assistant, an agentic interface that does not just answer questions about a customer’s spending but acts: setting up savings goals, creating budget categories with automated payday transfers, and walking a customer through account tasks like card ordering or PIN retrieval, all through natural-language prompts rather than menus. It builds on two earlier tools, Spending Intelligence and Scam Intelligence, that already analyze a customer’s transaction history and flag suspicious marketplace activity.
“It’s time to embrace a new era of banking, powered by agentic AI to help people be good with money,” said Harriet Rees, Starling’s group chief information officer. Group chief executive Raman Bhatia was more direct about where the bank thinks this is heading: “Agentic AI is the next step in banking and I’m thrilled customers will benefit from this technology.” The assistant is rolling out first to personal current account holders, with business and joint accounts to follow. Starling has also signaled it intends to ship new capability to the assistant on an ongoing basis rather than as a single release, treating agent skills the way a software company treats features: shipped, measured and iterated, not launched once and left alone.
The distinction between the DBS and Starling deployments is who the agent works for. DBS built an agent that works for the bank, compressing a bankers’s own workflow. Starling built an agent that works for the customer, executing account actions a person used to do by hand. Both are agentic in the technical sense. Only one of them hands a degree of financial control directly to the end user, which is precisely why the third deployment this week matters more than it might first appear.
When the Agent Can Trade
Binance introduced Agent OS on August 20, a developer platform that lets outside AI applications, including general-purpose tools like ChatGPT, Claude Code, Codex and Cursor, connect to the exchange’s market data, wallet infrastructure and trading functions on a user’s behalf. A trader can authorize an agent to view account information and place trades within permissions and limits the trader sets, assign the agent to a dedicated subaccount to wall off funds, and revoke access at any time. Binance built in constraints deliberately: agents cannot withdraw funds to an external address, cannot move money from a user’s main account into the agentic subaccount, and an emergency-stop function can disconnect every connected agent and cancel open positions at once.
“Binance Agent OS addresses the fragmentation developers face when building agentic finance applications across crypto and traditional markets,” said Jeff Li, Binance’s vice president of product, pointing to the platform’s promise of “reliable data, low latency infrastructure, and standardized interfaces.” That framing, infrastructure for other people’s agents to build on, is the real shift Agent OS represents. DBS and Starling built agents themselves, under their own control, for their own workflows. Binance built a platform for agents it did not write and cannot fully audit, trusting its permission system rather than the agent’s own judgment to keep a user’s funds safe. It is the difference between a bank hiring a very fast analyst and a bank handing a stranger a key card with a spending limit on it.
Someone Has to Write the Rules
That trust-a-permission-system-not-an-agent’s-judgment approach is exactly the problem a new industry coalition is trying to get ahead of. Payments infrastructure firm Rain, alongside more than two dozen organizations including Visa and Mastercard, which committed to shared ground rules for agent-driven commerce earlier this month, launched the Agentic Payments Alliance to coordinate how agent authorization, fraud detection and loyalty mechanics get built before every payments company solves them differently and incompatibly. The alliance cites McKinsey projections of $3 trillion to $5 trillion in global agentic commerce by 2030, a market size large enough that whoever sets the authorization standard first effectively sets it for everyone.
“The risk in a moment like this is not that the industry moves too slowly. It’s that innovation outpaces alignment,” said Sherri Haymond, Mastercard’s executive vice president and global head of digital commercialization. Farooq Malik, Rain’s co-founder and chief executive, put the stakes even more plainly: “No single company should get to decide how agents transact on someone’s behalf.” That is a notable admission from two of the industry’s largest players. Card networks that spent decades competing on proprietary rails are, in this one narrow area, choosing to build shared infrastructure first and compete on top of it later, because the alternative, each network building its own incompatible agent-authorization standard, would fragment the very trust layer agentic commerce depends on.
The same logic is showing up beyond payments proper. Stripe’s recent move to acquire an AI token-routing company was a bet that the infrastructure layer underneath agent-to-agent transactions, not just agent-to-merchant ones, will need dedicated plumbing. And embedded finance is already following the same pattern in the other direction, with lenders like Synchrony building financing options directly into AI chat interfaces rather than waiting for a customer to leave the conversation and apply separately.
What It Means for the Finance Leader
Four different institutions arrived at four different points on the same spectrum this week: agent-for-the-bank (DBS), agent-for-the-customer (Starling), agent-for-anyone-who-connects-one (Binance), and agent-authorization-as-shared-infrastructure (the Agentic Payments Alliance). None of them waited for a regulator to define what an AI agent is allowed to do with someone’s money. That is not because the question does not matter; it is because no regulator covered in this publication’s beat has yet issued a binding rule on agent liability, and the institutions moving fastest have concluded that permissioning architecture, not regulatory clarity, is the control that actually exists today.
For a bank, payments firm or fintech evaluating its own agentic AI roadmap, the useful question is not whether to deploy agents. It is where on that same spectrum a given deployment sits, and whether the permission boundaries around it match the stakes of what the agent can actually do. An agent that drafts a credit memo for a human to approve carries a different risk profile than an agent that can move a customer’s money, which carries a different risk profile again than an agent built by a third party that a platform did not write and cannot fully inspect. Treating all three the same, calling each one simply “agentic AI” without distinguishing who the agent acts for and what it can do without a human in the loop, is how a genuinely useful automation ends up carrying the same governance scrutiny as a genuinely risky one, or worse, the other way around.
How to Evaluate an Agent Deployment
Three questions travel well across all four of this week’s announcements, and are worth asking of any vendor pitching an agentic capability: What specific tasks does the agent complete without a human reviewing the output first, and what is the blast radius if it gets one wrong? What are the technical limits on what the agent can move or access, not the policy limits, since a permission that exists only as a setting a user can misconfigure is not a control? And who can revoke the agent’s access, how quickly, and does that revocation actually stop an action already in flight? DBS and Starling can answer those questions today because they built the agents themselves. Any institution connecting to someone else’s agent platform, the way Binance’s Agent OS invites third-party developers to do, needs to be able to answer them about a system it does not control, which is a materially harder problem than deploying an agent in-house, and one this week’s announcements suggest the industry is choosing to solve with permissions and subaccounts rather than waiting for a regulator to solve it first.
Source: DBS Bank

