Agentic AI in Banking: Six Weeks After the EU AI Act

Six weeks after the 2 August EU AI Act deadline for high-risk systems, a different sort of email is landing on bank innovation desks. It is not the flood of vendor pitches that dominated July. It is a short internal note from Risk or Model Validation asking, in a tone somewhere between weary and clinical, whether that agentic AI fraud pilot is now a regulated high-risk system, and if so, who is accountable for it. Meanwhile, in the United States, the joint Federal Reserve, OCC and FDIC update to model risk management, SR 26-2, did the opposite of what many expected: it explicitly excluded generative and agentic AI, punting the question. Two continents, two supervisory postures, one problem. A bank innovation office that spent H1 building a business case for agentic AI is now being asked to say, on paper, how the thing is actually governed.
The problem this creates inside a financial institution
Inside a European bank, this is harder than the LinkedIn headlines suggest. Three years of pilots have produced a small stack of live use cases: financial-crime triage, regulatory-change screening, controls monitoring, some customer-service assistants. Each has a different tooling stack, a different data path, and a different vendor. Add the 2 August deadline and the picture inverts overnight. Where the innovation team used to argue for more experimentation, it now argues for consolidation. Where the model risk team used to see a pipeline of new work, it now sees a backlog it did not size correctly. And where Procurement used to accept a vendor's own AI governance claims at face value, it now has to prove those claims are true to an auditor.
The complication is not the deadline itself. It is the vendor market's response to it. Every AI provider now positions itself as EU AI Act ready. Some are. Most are not, at least not in the sense the Act intends: a conformity assessment, technical documentation, post-market monitoring, and a functioning human override. Filtering signal from noise at that level of technical claim is not a Procurement job. It is a joint innovation, model risk and compliance job, and few banks have designed a process for it. In practice this means the same three-page vendor brief circulates for weeks between teams, none of whom feel authorised to decide.
Common approaches and their trade-offs
Three responses are visible across European institutions right now.
The first is retrenchment. Freeze new AI initiatives. Focus on the pilots already in production, harden their governance, and defer new deployments until the OCC and the Federal Reserve issue the guidance SR 26-2 signals is coming, and until the European Banking Authority publishes its supervisory expectations. The trade-off is time: competitors that keep moving will pull ahead on operational learning, even if their governance is thinner. This is common at the largest universal banks, where a delay of two quarters is measured against political and prudential exposure rather than commercial upside.
The second is fragmented delegation. Let each business line make its own choices, run its own vendor selection, and manage its own model risk file, coordinated loosely by a central AI office. The trade-off here is that the innovation office ends up as a scorekeeper rather than a decision-maker, and Procurement inherits a portfolio of vendors it did not choose. This is common at mid-sized institutions with strong divisional autonomy, and it usually shows up in the audit findings a year later.
The third response is what most vendors would prefer: pick a strategic AI platform partner, commit to their governance stack, and outsource the interpretive work. The trade-off is concentration risk and lock-in at exactly the moment supervisors are becoming more sensitive to third-party AI risk under DORA. It also assumes the partner's understanding of the Act is correct, which is a bet, not a fact.
None of these responses is wrong. All of them share the same weakness: they optimise for internal simplicity rather than for the buyer's actual question, which is: what are comparable institutions in comparable markets actually doing right now, and why?
A smarter route
The banks moving fastest, and quietly, are running a different pattern. They are not defaulting to any one of the three responses above. They are staging small, structured decisions, each informed by peer signal, before touching the vendor market at all.
That process has three moving parts.
First, a horizon scan that is disciplined about what has changed in the last six weeks, not the last six months. FIS shipping an Anthropic-powered Financial Crimes Agent into live pilots at BMO and Amalgamated Bank tells you something specific. So does the Wolters Kluwer survey showing 44 per cent of finance teams expecting to use agentic AI in 2026, sharply up on the prior year. So does the fact that SR 26-2 explicitly excluded generative and agentic AI from its scope. These are signals, not stories, and each one shifts the risk calculus in a different direction.
Second, a peer view. Not a vendor's peer story, an actual peer view. What has a Nordic universal bank, a Benelux systemic bank, a Southern European retail bank, and a UK challenger done differently on the same use case? Where are the divergences, and are they explained by regulator posture, by IT stack, or by risk appetite? Almost none of that is on a public webinar. Very little of it is safe to ask a vendor. Most of it lives inside two dozen heads across the industry, in institutions that would compare notes readily if a legitimate format existed.
Third, a curated vendor shortlist that is filtered against those two inputs before Procurement or Legal see it. That is the step where most banks lose weeks. The vendor inbox does not respect deadlines and it does not respect the shape of an internal review.
This is where an external, curated format earns its place. A Discovery Innovation Meeting format collapses steps two and three into a working session with three or four screened innovators and a small internal group, with the peer conversation running in parallel. A Peer Forum or Roundtable adds the missing peer signal directly, on the record, from institutions the innovation office would otherwise have no legitimate way to compare notes with. And a longer editorial format such as Finance X Magazine sits alongside the two as the discovery layer, where senior teams can stay exposed to what other markets are treating as material without having to schedule another call. None of this replaces internal model risk work. It sequences it. The result is a smaller shortlist, better questions for Procurement, and a governance conversation that starts with peer-tested assumptions rather than vendor slides.
Why this matters right now
The specific moment matters. Between now and the end of the year, three things will happen. The European Banking Authority will start clarifying its supervisory expectations on agentic AI, and early bilateral guidance is already being exchanged with the largest institutions. The US regulators will begin publishing the generative and agentic AI guidance that SR 26-2 signalled. And a large tranche of the vendor market will attempt to migrate its GenAI copilot positioning into agentic AI platform positioning, which is a different technical claim with different governance implications, and it will not always be honest about the difference.
An innovation office that enters that four-month window without a peer view is going to spend Q4 reactive: sitting through demos, forwarding vendor decks to Model Risk, and negotiating scope with Procurement. An innovation office that enters it with a peer view, a horizon read, and a shortlist filtered against both spends Q4 on the actual work: sequencing pilots, tightening governance, and moving one or two use cases from pilot to production with a defensible file the auditor will accept.
The delta is not intelligence, it is preparation. And preparation, at senior level, is the single hardest thing to protect under delivery pressure.
Closing thought
The uncomfortable truth about agentic AI in banking, six weeks after the deadline, is that the regulatory picture is more permissive than the internal picture. The Act is now live. SR 26-2 is now live. Neither has stopped the largest institutions from moving. What has stopped many mid-sized European banks from moving is the internal cost of assembling a defensible peer view before the next steering committee. If your innovation office is running a Q4 review this month, the useful question is not which vendor to shortlist. It is: what would we need to know about three comparable banks in three other markets before we shortlist anything, and what is the cheapest way to find that out this quarter? The answer is rarely another vendor call.



