
Only 21% of banks have mature governance for autonomous AI agents. The gap between adoption and oversight is widening, creating regulatory and operational risk, warns Zafin's CTO.
The pattern of ungoverned technology deployments spreading through banks before governance catches up is repeating itself. This time it is artificial intelligence agents, not software tools, and the stakes are higher because agents do not just introduce another technology. They introduce another participant in how work gets done.
Shahir Daya, chief technology officer and head of Zafin AIOS, described the phenomenon as Shadow AI. A team can deploy an agent in hours without anyone taking a broader view of how it fits into the bank's operating model, he wrote in a recent analysis. The gap between how fast agents are adopted and how well they are governed is where the real risk sits.
Only 21% of organizations have a mature governance model for autonomous AI agents, according to Deloitte research cited by Daya. That number is low, and the gap is widening, he said. The reason has less to do with urgency than with architecture.
Banks were built for a workflow where humans initiated work, executed it, reviewed it, and documented it across systems. Authority was clear because a person sat at every decision point. Agents create a different operating model. People define intent and set the boundaries of authorized work. Agents execute within those boundaries, accessing systems, routing models, and moving tasks. The evidence of that execution should be captured as it happens, not assembled afterward. Most banks have not built the architecture to make that end-to-end chain traceable from intent to governed outcome, Daya said.
The result is a set of problems that compound quickly. Agents are typically governed by the teams that built them. Lending has its own view of what its agents are authorized to do. Compliance has another. Operations has a third. Ask a bank today what data a given agent can access, what decisions it can make without human authority in the loop, or what it has cost the institution over the past quarter, and the honest answer in most cases is that nobody has a complete picture, Daya said. That is not because the teams involved are negligent. The operating model is not designed to surface that information across organizational lines.
The gaps show up most visibly under pressure: an audit finding, a regulatory inquiry, a risk committee asking for a decision trail. At that point, the bank is not answering a compliance question. It is reconstructing evidence that should have been built into the work path from the start, Daya said. Many banks can describe what an agent did. Fewer can demonstrate why it acted, what it was authorized to do, and whether a person with that authority reviewed the outcome when policy required it. The distinction between recording that work happened and proving it happened within governed parameters is what regulators will increasingly draw, he said.
The instinct when you see this pattern is to slow the deployment down. That is the wrong move, Daya said. Banks getting the most value from agents are not the cautious ones. They are the ones that built governance into the architecture before scaling, treating it as the operating foundation that makes agent programs expandable rather than the friction that eventually stops them.
What that requires is a control plane that spans all agent deployments regardless of which team built them: where authority sits, what data can be accessed, when human sign-off is required, and what proof is generated as work moves from intent to outcome. That is the operating infrastructure that makes it possible for a risk committee or a regulator to see the full picture, and for the institution to expand what is working with confidence, Daya said.
Banks have demonstrated they can move fast on pilots. Successful agent deployments across lending, operations, and compliance are now common. The harder question is whether those programs stay siloed at the team level or whether the institution can see across all of them, govern the portfolio under a single authority model, and build on what is working at scale, he said.
Shadow IT took most institutions the better part of a decade to bring under real governance. Part of that was technology. Most of it was that institutions failed to recognize it as an operating model problem. Every year without governance architecture accumulates governance debt: decisions made without traceable rationale, agents operating without registered authority, costs growing without a complete picture. Banks that recognize the pattern early and build the architecture to match will not just be more defensible. They will move faster, because agents operating inside a governed architecture can be expanded with confidence in ways that ungoverned ones cannot, Daya said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.