Banks Rely on Autonomous Artificial Intelligence Without Safety Plans
New York, Wednesday, 30 September 2026.
Despite 72% of financial institutions adopting high-autonomy AI, 81% operate without incident management procedures, exposing the global financial system to critical operational risks.
Widespread Adoption Versus Governance Gaps
On September 29, 2026, Parker & Lawrence Research published findings indicating that 72% of surveyed financial institutions utilize high-autonomy artificial intelligence in risk and compliance domains [1]. Despite this high adoption rate, 81% of those institutions operate without established AI incident-management procedures [1]. Based on the 216 firms reported using high-autonomy AI, this percentage suggests approximately 174.96 institutions lack critical safety protocols [1]. The research surveyed 300 senior risk and compliance professionals across markets including the US, UK, France, Australia, Singapore, and the UAE [1].
Further analysis reveals that 89.7% of institutions have fewer than 50% of the 13 assessed AI governance and control capabilities in place [1]. The average firm reported possessing only 4 of these 13 capabilities, highlighting a significant deficit in operational readiness [1]. Additionally, 70.4% of firms lack pre-deployment review and approval processes, while 65.3% do not maintain an AI inventory or use-case register [1]. These gaps expose the global financial system to critical operational risks and challenge regulatory oversight mechanisms [1].
Identity and Access Management Challenges
Compounding the governance issue, AI agents are increasingly acting as privileged identities within enterprise systems [2]. As of September 29, 2026, industry experts note that AI agents can act independently at machine speed, creating new identity and privilege risks [2]. Melissa Carvalho, Vice President of Global Security Identity and Access Management at Royal Bank of Canada, stated that organizations must redefine how privilege and access are managed for these autonomous accounts [2]. The core challenge lies in governing identities that can execute actions without direct human intervention [2].
Organizations face difficulties in discovering shadow agents and prioritizing controls based on the potential blast radius of a compromise [2]. Continuous monitoring, runtime authorization, and rapid containment are becoming essential as agents gain autonomy [2]. Firms relying solely on general employee access to foundation models report the fewest controls, averaging fewer than 3 of the 13 assessed capabilities [1]. This reliance increases the vulnerability of sensitive financial data and infrastructure [1].
Regulatory Landscape and Future Risks
Regulatory bodies such as NIST are turning their attention to AI agent identity and authorization requirements [2]. Financial institutions need to know which agents exist, who owns them, and whether they should be authorized to take specific actions at specific moments [2]. While high-deployment firms demonstrate greater adoption of AI policies compared to low-deployment firms, the security uplift does not proportionally match their increased intensity of AI use [1]. Currently, 65.6% of reported AI activity is at the production stage or beyond, and 58.4% involves AI taking action rather than just providing recommendations [1].
The published research report includes benchmarking data on AI spend, realized ROI, and deployment depth across six markets [1]. Michael Lawrence, Co-founder of Parker & Lawrence Research, noted that adoption is moving faster than preparedness [1]. As the financial sector integrates more autonomous systems, the disparity between deployment intensity and control maturity remains a primary concern for systemic stability [1]. Addressing these governance gaps is critical to maintaining trust and security in the global economic framework [1][2].