A central bank changes its mind
For years the Bank of England maintained that existing frameworks sufficed for AI risk. That position ended at the ECB's Sintra forum, where Deputy Governor Sarah Breeden said rapid progress in agentic payments and trading has exposed gaps demanding a more sophisticated response - because the frameworks were never built to contemplate autonomous agents, and relying on a human in the loop for every agent action is unlikely to be realistic. The Bank is now reviewing whether rules can cover systems that interpret objectives, select tools, initiate transactions, and adapt across multiple steps - moving the regulatory focus from the quality of a single output to the behaviour of an entire decision-and-action chain.
The specific risks, and the specific remedies
The stability nightmare Breeden sketched is herding: if many agents share similar data, foundation models, and objectives, they may respond identically to the same trigger - selling assets or withdrawing liquidity in unison and amplifying the very stress they are reacting to, especially if their objectives drift from original goals. The Bank is running simulations with the BIS Innovation Hub and the Bundesbank to identify which design elements encourage that correlation. The remedies under consideration read like market infrastructure for the agent era: market-wide circuit breakers or kill switches to halt AI-driven activity in a meltdown, enhanced recovery requirements that could let one bank take over another's basic functions during an outage, and questions about whether key firms need separate failover systems. Cyber is the nearest-term worry - Breeden described a step change in AI cyber capability - and adoption data says none of this is hypothetical: the Cambridge Centre for Alternative Finance finds 81% of financial firms adopting AI and 52% already adopting agentic AI, while the FSB's June consultation proposed 12 sound practices spanning governance, lifecycle risk management, and third-party risk.
Your compliance roadmap just previewed itself
- If you deploy agents in regulated finance, build now what regulators will demand later: a per-agent inventory of ownership, permitted tools and data, action limits, escalation conditions, and complete decision logging. The FSB's 12 practices are a free template - align internal policy to them this year.
- Engineer for the kill switch before it is mandated: every autonomous workflow needs a tested, instant halt-and-rollback path plus non-AI fallback procedures for critical functions. That is good operational resilience regardless of regulation.
- Strategy teams should internalise the herding insight even outside finance: if your agents run on the same models and signals as everyone else's, your diversification is thinner than it looks. Deliberate model and data diversity is becoming a risk control, not just a procurement preference.
- Expect supervision to shift system-wide: stress tests assuming simultaneous multi-firm disruption are coming, and firms that can already demonstrate cross-firm recovery options will find the conversation far cheaper.
