As financial institutions increasingly delegate decision-making to AI agents, establishing clear authority boundaries and revocation mechanisms becomes crucial to prevent risks and ensure compliance in automated payments.
As banks push artificial intelligence from advice towards action, one issue is becoming central: who actually has the right to let a machine act in the first place. The question is no longer just whether an AI system is secure or whether it can reach a payments interface. It is whether it has been properly given delegated authority to do a specific task for a specific party, under specific limits, at a specific moment. NIST has said its 2026 work on AI agents is aimed at identity, authorisation, auditing and non-repudiation, while the IMF has warned that payment systems will have to handle the gap between an agent’s flexible behaviour and the rigid rules of settlement.
That distinction matters because technical access is not the same as permission. An AI agent may be able to reach a payment rail, use a token or trigger an automated workflow, yet still lack the mandate to move funds beyond a threshold, pay a new counterparty or act outside a stated purpose. NIST’s concept paper on software and AI agent identity says the goal is to reduce the risks of giving agents access to data, tools and applications without the right controls.
The practical test is whether the institution can define the boundaries of that authority clearly enough for it to be enforced. In banking terms, that means setting the scope of actions an agent may take, the value limits that apply, the counterparties it may deal with, the duration of the mandate and the circumstances under which it must escalate to a human. The IMF said its framework for agentic payments separates intent, authorisation and settlement precisely because those steps are no longer guaranteed to line up cleanly once an autonomous system is involved.
Just as important, authority cannot be treated as permanent. A payment that is acceptable in one context can become risky in another if a beneficiary changes, a security signal shifts or a credential is compromised. The IMF has pointed to concerns around traceability, opacity, cybersecurity and legal uncertainty, all of which make it harder to rely on a one-time approval as proof that later actions remain valid. In that setting, banks need revocation mechanisms that can narrow limits, pause actions or terminate a delegated mandate quickly.
The problem becomes more complex when agents begin to work through other agents. A customer-facing assistant might hand a task to a specialist payments agent, which in turn calls another service for checks, conversion or fulfilment. If authority is allowed to travel too far down that chain, there is a risk of privilege escalation, where a narrow instruction expands into a much broader financial power. The World Economic Forum has argued that trusted adoption of AI agents depends on making authorisation and scaling explicit at the deployment level, not just at the model level.
Payments make this issue urgent because they are consequential and often difficult to reverse. The IMF has said agentic AI could shift activity from human-triggered payments towards agent-mediated decisions, increasing the need for machine-readable identity, interoperable controls and clear liability rules. That is why evidence matters as much as authorisation itself: banks may need to preserve not only the transaction record, but also the policy version, mandate, limit, context and approval state that justified the action when it was taken.
In that sense, the next layer of banking control is becoming clear. Model governance asks whether an AI system is suitable for use. Access control asks whether it can reach a system. Delegated authority asks whether it was entitled to act at all. As agentic banking develops, institutions will need to answer that question precisely, or risk allowing autonomy without a proper chain of permission.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





