Charles Kerrigan
Partner

Charles Kerrigan is a subject matter expert in AI and digital assets. He has a corporate finance background in London and New York, since 2015 working extensively in AI and digital assets for specialist firms, financial institutions, and investors.

He has worked in AI since 2012 and has undertaken AI implementation and regulatory work for numerous banks and fintechs, including global training and implementation programmes. He is the editor and lead author of Artificial Intelligence: Law and Regulation (1st and 2nd editions), and other specialist texts in AI. He has a teaching affiliation in the Computer Science dept at UCL.

Charlie sits on financial regulator and trade body boards and on the advisory boards of fintech and deep tech firms. He is a Partner at international law firm CMS. He is a co-founder of Dogberry, an AI diligence platform that converts fragmented technical, legal and commercial evidence into a scored and auditable assessment of AI companies.

Erica Stanford
Advisor

Erica Stanford is an AI, risk and emerging technology specialist at the international law firm CMS, where she advises, in a non-legal capacity, on the strategy, risk and governance dimensions of artificial intelligence, and sits on the firm’s AI committee. Her work focuses on how AI systems and autonomous agents are reshaping trust, liability and the future of fraud, from AI-enabled financial crime and malicious models to the ethics and regulation of AI in practice.

She has completed an MSc in Data and Artificial Intelligence Ethics at the University of Edinburgh and an MSc in Applied Data Analytics at BPP and has studied artificial intelligence at the University of Oxford’s Saïd Business School.

Erica writes and speaks internationally on AI-enabled fraud, autonomous AI and liability, AI governance and the future of financial crime. Her published work on AI includes chapters on misinformation and AI in legal technology in Artificial Intelligence Law and Regulation (Edward Elgar), and on ethical AI and UK AI law across the 2024 and 2026 editions of AI, Machine Learning & Big Data (Global Legal Insights).

She is training to cross Antarctica in 2027–28 as part of the Polar Dogs Antarctica Expedition (polardogs.uk).

AI IN UK FINANCIAL SERVICES: ISSUES FOR H2 2026: AGENTIC AI

Introduction

The most talked about aspect of AI in financial services now is agentic AI, widely heralded as a likely and useful near future for financial firms and markets. AI systems and of AI acting autonomously via AI agents gather information from fragmented systems, investigate fraud alerts, prepare compliance reports, identify missing documents, help customers compare products, build platforms and carry out routine actions within agreed limits, often at a fraction of the financial and time cost of their human equivalents.

For UK financial-services firms agentic AI presents mixed questions of a technological and operational nature, as well as governance and authorisation issues about what happens legally when a firm gives an AI system authority to act.

An AI model that summarises a policy or drafts a customer response may make a mistake, but a human can ordinarily check the output and decide what happens next. An AI agent that can access accounts, contact customers, change records, submit an application or initiate a payment can turn the same mistake into a legally significant act before anybody has had an opportunity to intervene.

The distinction is between human producing information and exercising delegated authority. An AI system may have no legal personality and no regulatory responsibilities of its own, but its actions may alter the rights, interests and financial position of customers. Somebody must remain legally responsible for those consequences. In most cases that responsibility will continue to rest with the regulated firm, its senior management and, depending upon the circumstances, other persons involved in supplying or operating the system.

Avoiding agentic AI altogether is not an realistic answer because it reduces cost, improves administrative processes and allow firms to innovate. Criminals use increasingly capable AI tools so financial institutions themselves need AI systems to detect and defend against AI-enabled fraud and cybercrime.

Legal Questions

The core legal issues relate to how far authority can lawfully and responsibly (I use “responsibly” here as a catch all for the expectations of financial regulators) be delegated, which leads to what safeguards must accompany that delegation and who bears responsibility when the system exceeds its authority or causes harm.

The UK is unusual in Europe because financial-services firms do not presently operate under a single, comprehensive AI statute or bespoke FCA AI rulebook. The FCA has instead deliberately continued to apply its existing principles- and outcomes-based regulatory framework to AI. Consumer protection, senior-management accountability, data protection, equality law, operational resilience, outsourcing, financial-crime and other existing obligations apply according to what an agent actually does.

The central principle for firms can be simply stated: an AI system should receive no more autonomy, data, permissions, reach or persistence than its task requires; each unit of delegated authority should be legally and operationally justified.

What Makes AI Agentic?

There is no settled definition of agentic AI. The term is variously applied to chatbots, automated workflows and systems able to plan and act with little supervision.

A working definition for financial services is a goal-directed AI system that can autonomously select or plan steps, use tools or external systems, retain relevant information and take actions with some independence from continuous human instruction.

An easy way to explain what this is about is by thinking about the difference between surfacing information and making a recommendation. A chatbot may explain the terms of a mortgage without much problem (as long as it obtains data only from the true source) but recommending between different mortgage products, or even further, altering an account pose more complex questions for law and regulation.

Here is a simple cascade of agency from easiest to hardest to deploy:

  1. retrieve and analyse information
  2. recommend an action
  3. prepare an action for human approval
  4. execute an action following human approval
  5. execute defined actions independently within predetermined limits
  6. plan and perform a sequence of actions with limited human involvement.

In legal terms the cascade describes levels of delegated authority. The further the system moves from analysis towards independent action, the more it triggers requirements for governance architecture combining legal responsibility, authorisation, oversight, auditability, and redress.

The FCA’s Mills Review describes a corresponding evolution in the human role from operator to collaborator, consultant, approver and (in the most autonomous cases) observer.

Why Agentic AI Changes the Legal Risk

An agent may go wrong in any number of ways, including misunderstanding its instructions, inventing a fact, relying upon inaccurate information, using the wrong tool, and pursuing its goal in an unexpected way. It may be manipulated by instructions embedded in emails, webpages or documents.

Not everything is predictable so , to build governance systems, I approach the scope using checklists of legal questions, for example this simplified series:

  • What decision or action is the system permitted to take?
  • Whose legal or financial interests can that action affect?
  • What information can the system access?
  • How far can the consequences travel before a human can intervene?
  • Can the action subsequently be explained, stopped, reversed and remedied?

A highly capable research model confined to read-only material may therefore create less legal risk than a less sophisticated system authorised to communicate with customers or transfer money.

The Firm Remains Responsible

The most important legal principle is that delegation to AI does not amount to delegation of legal responsibility. A regulated firm cannot (currently) answer a complaint, regulatory investigation or claim only by saying that “the AI made the decision”. Where a firm chooses to deploy the system as part of the way in which it conducts regulated business, the system becomes part of the firm’s arrangements for carrying out that business. The consequences of this require an understanding of the firm’s existing governance and control systems.

First, the firm must identify who is accountable for the decision to deploy the system and for the activities it performs.

Then, the authority given to the system must be consistent with the firm’s regulatory obligations and systems of control.

Then, the firm must be able to explain and reconstruct sufficiently important actions even where the agent selected its own intermediate steps.

Note that using a third-party model, cloud service or agent platform does not in itself transfer the firm’s regulatory responsibilities to the supplier. The Senior Managers and Certification Regime is based on the principle that delegation is an ordinary feature of large financial institutions, but appropriate delegation relies on effective oversight.

Agentic AI is best thought of as creating a new form of delegation problem: authority is being delegated not merely down an organisational hierarchy but into a technical system capable of making further choices about how a task should be completed.

Therefore, a firm’s governance should identify the responsible business owner and senior manager and define:

  • the system’s purpose
  • what decisions it may make
  • what actions it may take
  • actions it may never take
  • financial or customer limits
  • required human approvals
  • escalation requirements
  • monitoring and testing
  • supplier dependencies
  • incident and redress procedures
  • the circumstances in which its authority must be suspended or withdrawn.

Each of these points can be relatively easily dealt with as part of an implementation project that is well scoped and planned. In my experience, the hard parts relate to the long-standing hard parts of delivering projects inside large bureaucratic organisations, namely managing communications and incentives.

Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 changed the UK’s rules on solely automated significant decision-making. The previous framework generally restricted decisions based solely on automated processing that produced legal or similarly significant effects unless specified conditions applied. The DUAA regime permits solely automated significant decisions in a wider range of circumstances, subject to safeguards and restrictions where special-category personal data is involved. The safeguards include rights concerning information about the decision; the ability to make representations; human intervention; and the ability to contest the decision.

It is obvious how this is significant for deployment of agentic systems. Specifically, several autonomous steps precede final decisions so firms need to be able to establish the chain of processing and reasoning (in an auditable manner) where a significant decision is based solely on automated processing occurring in layers.

What Counts as Human Involvement?

This is likely to become one of the contested legal issues surrounding financial-services agents. Humans in the loop may not be sufficient if in fact the human:

  • lacks sufficient information to understand the agent’s reasoning
  • has insufficient time to investigate the agent’s work
  • review too many recommendations to exercise independent judgement
  • lacks practical authority to overturn the agent
  • in fact routinely accepts machine recommendations

Human roles are an architecture and a practical issue to be solved to ensure that it can be shown to a regulator that the role design is such that the human can genuinely understand, challenge and alter the proposed decision. For example, if the human is presented only with the final proposed action without the chain of choices and reasoning that produced it, or the human is shown a million decisions a second, nether will be sufficient to satisfy a need for human oversight.

Consumer Duty and Autonomous Customer Outcomes

For retail financial-services firms, the Consumer Duty, requiring that firms deliver good outcomes for retail customers (including in relation to products and services, price and value, and consumer understanding and support), is the challenge of the age. Agentic AI does not change the obligations but it may in time bring a much needed solution to the current challenge of meeting such a tough and overarching test.

Even where an AI agent does not make the decision it can still exercise significant influence over the customer journey. For example, an agent could:

  • recommend a product
  • determine what information is presented to a customer
  • alter the order or prominence of the options displayed
  • decide when further information or evidence is required
  • identify a customer as presenting a potential fraud risk
  • determine how a complaint or support request is triaged or routed
  • initiate communications or actions affecting an account.

Each of these functions can materially affect customer outcomes. Foreseeable harm is the underlying legal principle and where a firm knows, or ought reasonably to know, that an autonomous system is capable of producing a particular category of error, it may not be sufficient to rely on high aggregate accuracy if the consequences of that error are serious and reasonably preventable. Firms should therefore test not both accuracy and what happens when there is a failure. This should include consideration of the severity and reversibility of resulting harm, whether errors are detectable, and whether appropriate safeguards operate before harm reaches the customer.

Testing should also consider outcomes for vulnerable customers and for groups that may interact differently with automated systems, including where communication style, accessibility needs or other characteristics affect how an agent interprets or responds to a customer. If an agent can materially affect a customer’s interests, firms should preserve an effective route to human support, review and redress. The human intervention should be practically accessible and capable of correcting the consequences of an automated action, in other words merely a formal escalation mechanism is not sufficient.

Equality and Discrimination

The Equality Act 2010 may apply where a firm’s use of an AI system results in unlawful discrimination. An agent may discriminate without using an expressly protected characteristic because apparently neutral variables, inferred information or patterns in historical data may act as proxies or produce disproportionately adverse outcomes for particular groups. AI’s capabilities are now so extraordinary that they are far more able to infer characteristics than a human actor. Further, agentic systems add the further difficulty that discriminatory effects may emerge from a sequence of decisions rather than a single model output.

An agent deciding what information to request and how to interpret missing information can easily build a chain of logic that roots a decision in a protected characteristic of a (potential) customer). Building guardrails that include explainability of steps in decisions, plus testing to examine the behaviour and outcomes of the complete system, are a developing field within the AI trust and safety communities that have the most expertise in model and system bias.

Contract, Authority and the Acts of the Agent

Where a firm equips an AI agent with credentials, access to its systems and authority to communicate or transact, disputes may arise over whether actions taken by that system bind the firm. These are private-law questions, usually grounded in contract in relation to customers and tort in relation to third parties. The existing tests defining scope of services and responsibility, exclusions, harms and foreseeability are in general good enough to deal with the work of architecting and testing relevant points.

Firms should therefore define technically and contractually what authority the system has with reference to the level of visibility that external counterparties may have of internal prompt instructions or internal limits placed upon an agent. Controls governing authority consequently need to be reflected in credentials, permissions, transaction limits and contractual arrangements.

Beyond this, the new area of agent-to-agent transactions requires us to look at questions of identification, authentication, authority and attribution from both sides, although this allows us to take a consistent and system-level approach to the issues.

Liability When the Agent Gets It Wrong

This is one of the most interesting questions because there is no single legal answer to a question framed as “who is liable for an AI agent?” Liability depends upon the nature of the relationship between the parties and on how harms relate to legal duties.

The board categories are:

– regulatory responsibility

– contractual liability

– negligence or other civil liability

– strict liability for breach of a statutory offence

– data-protection liability

– discrimination

– financial-ombudsman redress

– responsibility under payments or sector-specific rules

– breaches of fiduciary duties.

Take the example of an agent that incorrectly freezing a customer’s account.

The legal analysis does not involve much about the underlying model although we would look at whether the failure caused or contributed to by the model, data, system integration, or the firm’s permissions? It relates mainly to conventional questions such as:

  • Was the firm entitled to take the action?
  • Was the information relied upon accurate?
  • Was the action proportionate?
  • Was the correct process (including any escalation) followed?
  • Could the customer challenge it?
  • How quickly was the action be corrected?
  • Were foreseeable customer consequences considered?
  • What compensation or other redress is appropriate?

The most significant legal element of running agentic systems in this context is that they must be designed to ensure legal standards in matters of causation and evidence are met. A failure must be traced to the component, instruction, data source, tool call, or delegated permission that produced the harmful result.

Data, Training and Provenance

In AI it is often legal questions around data that are most important and prevalent. In the broadest terms we are concerned with: data used to train or adapt the AI model; and operational data accessible while the agent performs its task.

Training data may introduce inaccuracies, bias and legal issues concerning provenance.

Operational data may include customer records, prompts, retrieved documents, tool outputs and agent memory.

Training data is a central question for model developers. For users of models, which is most financial firms, the system is pre-trained. The EU AI Act and other similar regulations, however, raise questions of how much fine-tuning by a user turns that user into a developer and therefore subject to more onerous rules.

Since operational data is usually held and managed at the model user level (the financial firm) our task requires aligning data protection concepts with automated system operations. These will be familr categories:

  • lawful basis
  • purpose limitation
  • minimisation
  • accuracy
  • security
  • retention
  • international processing
  • confidentiality
  • access by suppliers.

For agentic systems issues such as data minimisation become questions of design and permissions, that is we avoid a system misusing information by ensuring it can not, as a technical matter, access it. Access can be limited to the particular customer, purpose, task and period for which it is required without giving up too much accuracy or functionality. This approach supports explainability, which is a key requirement for most financial regulators currently.

Among the AI specific assets that are generated, firms are usually required to negotiate with model developers on ownership of prompts and evaluations in large system build outs.

Third-Party Providers and Outsourcing

Dependence upon a small number of model, cloud and data providers creates concentration and operational risk which is now a concern for financial regulators. The same concern arises in relation to any autonomous system with the added issue of the contractual allocation problem arising from the fact that one supplier may provide the model, another supplier the orchestration layer, another the cloud infrastructure and the regulated firm the customer data, permissions and business rules.

When building these systems, the design must ensure there is a record of the answers to questions that are asked when something goes wrong. For example:

  • who can change the model
  • whether model changes occur without prior approval
  • what performance and security assurances are given
  • where information is processed
  • which subcontractors are involved
  • what incident information will be provided
  • whether logs are available
  • whether the firm can test the system
  • how quickly access can be terminated
  • how the firm can migrate or operate manually if the supplier fails.

Facing these suppliers there is often a back-to-back issue where a contractual disclaimer from an AI supplier cannot be relied on by the regulated firm which retains its obligations owed to its customers or regulator. All financial regulators now call out this type of point within their policing of operational-resilience requirements and outsourcing and third-party risk expectations.

Transparency, Evidence and Auditability

Transparency has at least three legal and regulatory functions. First, customers may need to understand when AI is materially involved and how they can obtain human review or challenge an outcome. Secondly, those responsible within the firm need enough information to supervise the system. Thirdly, the firm needs evidence capable of reconstructing legally significant events after they occur.

If an agent freezes an account as in our example above the firm must be capable of establishing:

  • which version of the model was operating
  • the relevant instructions
  • what information was available
  • which tools and systems were accessed
  • what steps the agent took
  • which permissions applied
  • whether a human intervened
  • what final action occurred
  • whether it was later corrected.

Some industry regulators will trade off explainability for performance but financial regulators are not in this camp. They want firms to be able to show why an action was taken relating to customers individually. This does not require reconstructing internal mathematical operations of models in all cases but it does require an intelligible account of the process from information through decisions and actions to outcomes to be easily available.

Governance: A Legal Framework for Delegated Authority

Let’s build a simple system to take account of what we have covered.

Effective governance begins with a comprehensive inventory of AI agents (and models and systems).

Each distinct agentic system should have system level constraints:

  • a defined purpose
  • a named business owner
  • an accountable senior manager where appropriate
  • an authority and materiality classification
  • permitted and prohibited actions
  • specified data access
  • validation requirements
  • monitoring
  • escalation
  • redress arrangements
  • decommissioning arrangements;

together with technical identifications and permissions

  • model
  • prompt
  • data
  • tool
  • permissions

Each of these is an update to an existing internal policy, with versions being tracked and recorded since a change to any of these may change how we define the the system being governed.

Before giving an agent a particular power, the firm should ask:

  1. Why does the system need to perform this action rather than merely recommend it?
  2. What legal or financial consequence can the action produce?
  3. What is the maximum credible harm from a single error?
  4. What is the maximum harm if the error is repeated at machine scale?
  5. Which legal duties are engaged?
  6. Can a human realistically supervise the action?
  7. Can the action be stopped or reversed?
  8. What evidence will remain afterwards?
  9. What remedy is available to the affected customer?
  10. What evidence justifies granting this degree of autonomy?

Here is a delegation ladder based on one we use in practice:

Level 1 — Read

Agent can retrieve defined information / cannot alter systems or communicate externally

Level 2 — Analyse

Agent can analyse and summarise information / cannot determine or implement an outcome.

Level 3 — Recommend

Agent can recommend an action / cannot take a decision.

Level 4 — Prepare

Agent can prepare communications, transactions or system changes / cannot execute them without approval.

Level 5 — Execute Within Defined Limits

Agent can perform specified actions independently / cannot redefine its technical limits.

Level 6 — Autonomous Planning and Execution

Agent can determine a sequence of steps and execute them with limited human involvement.

Mitigating Legal and Operational Risk

Risk mitigation focuses on limiting what an agent can do when it is mistaken or manipulated.

Core controls include:

  • read-only access during initial deployment
  • unique and short-lived credentials
  • access confined to a particular task
  • limits upon relevant customers and accounts
  • approved tools and destinations
  • transaction-value limits
  • rate limits
  • restrictions upon external communications
  • anomaly detection
  • circuit breakers
  • a reliable means of stopping the system.

These restrictions have to exist outside the model itself. This is a critical distinction to understand for people whose understanding of AI is based on generative AI. Telling an AI agent in a prompt that it “must not” exceed £10,000 or, disclose customer information is not equivalent to technically preventing it from doing so.

Testing has its own cascade. We consider an agent tested when it has survived extensive simulation on:

  • ordinary cases
  • unusual cases
  • malicious inputs
  • prompt-injection attempts
  • vulnerable customers
  • protected groups
  • tool failures
  • stale or inaccurate information
  • model updates
  • supplier failures
  • errors accumulating across a sequence of actions.

Humans constantly make mistakes so we are not trying to say that agents must be perfect. What we are trying to do is make predictable errors are prevented controlled, avoiding legally significant problems.

Conclusion

Agentic AI has a distinctive legal significance that it can turn a model output into conduct. We therefore work on the question of what authority are we prepared to delegate to a system, on what evidence, and subject to what legal and technical constraints.

An AI agent does not become the bearer of a firm’s regulatory obligations and firms must continue to identify accountable people, but now with sufficient expertise to be able to be responsible for these powerful new systems.

Firms already run thousands of AI tools and are deploying agents first at human scale but then at digital scale. This is beyond human supervision. So the answer is good design, architecture, governance, and ethics. Those things will remain human tasks for some time.