What Stands Between Agents and the Decision Layer
By 2026 you can assemble a credible investment research team almost entirely out of software. A fundamental-analysis agent reads the filings. A sentiment agent scans news and earnings calls. A pair of agents argues the bull and bear case while a risk-controller checks the conclusion against the firm’s limits. The architecture is real, and it is spreading fast. Then you reach the step where someone clicks “execute,” and the workflow stops cold. The button stays under a human hand. The most revealing question in capital markets right now is why.
The first article in this series argued that agentic AI has already arrived in operations, where mistakes are cheap and reversible. The front office is where it stalls. The reason is not that the models are too dim; they are often plenty capable. The reason is that no institution has settled what it must answer for when an agent acts on its own. Institutional design is the binding constraint, not model capability.
The Four Walls Between Agents and the Decision Layer

Start with a question a supervisor can now reasonably ask. Writing in American Banker, Lisa Matthews posed it directly: could a bank name the single human accountable for the ongoing performance of every AI agent running in its critical processes, the individual, not the committee, without first making a phone call?4 Most could not. That matters because when an autonomous agent makes a call that loses money or breaks a rule, responsibility has to land on a specific person. The supervisory architecture of finance was built around named humans with defined mandates. Agentic systems blur that picture. Outcomes emerge from the interplay of models, data, and tools, and no single decision-maker owns the result. Generative-AI-related lawsuits in the United States grew almost tenfold between 2021 and 2025, and standard insurance policies leave real coverage gaps.4 Liability stopped being theoretical a while ago.
The rulebook has not kept pace. In April 2026 the Federal Reserve and the OCC retired SR 11-7, their long-standing model-risk guidance, and replaced it with a revised version that states plainly that generative and agentic AI sit outside its scope.4 Read that twice. The central model-risk framework for US banks declines to cover the fastest-moving model risk in the building. Regulators are not asleep; the SEC and European authorities are actively drafting. But the EU AI Act assigns obligations according to an agent’s risk level and intended use, and a great deal of finance lands in the higher tiers.2 Firms are left supervising probabilistic systems with tools designed for deterministic ones. The IMF puts it plainly: periodic model review does not work for adaptive agents. The job calls for real-time monitoring, complete audit trails, and the ability to step in the moment behavior drifts.3
A third wall gets less attention and deserves more. Agents are valuable in rough proportion to how much they can see, and information barriers exist precisely to stop certain people, and now certain systems, from seeing everything. An agent that ingests research, client order flow, and market data across a firm is powerful and, handled carelessly, a compliance incident waiting to happen. The same appetite for context that makes an agent good at synthesis makes it hazardous around material non-public information and the walls that separate advisory from execution. Building an agent capable enough to be worth deploying and constrained enough to stay compliant is genuinely hard. The difficulty lives entirely in permissions and architecture.
The last wall is the one that keeps regulators up at night. If many firms run similar agents, trained on similar data, reacting to similar signals, they may move the same way at the same instant. That is herding and amplification at machine speed, a crowded trade with no human finger on the pause button. Set that against market infrastructure built to process deterministic, legally certain instructions, and the mismatch looks structural.3 One firm’s agent misfiring is a risk-management problem. Ten thousand agents misfiring in unison is a financial-stability problem.
The front office is not bolted shut. But the real work is governance architecture, and the useful patterns are already taking shape. The IMF and others describe a recognizable toolkit: mandate-based authorization that fixes exactly what an agent may and may not do; architectural separation of the agent that decides from the system that executes; agent identity and audit trails so every action is attributable to a source; and tiered human-in-the-loop controls scaled to the stakes of the decision.3 The early adopters already run a version of this. Some investment banks let agents optimize client portfolios while a human oversight committee validates the consequential moves and sets the risk limits.5 The agent proposes. The human, for now, disposes.
Emerging Governance Architecture for Front-Office Agents:

Early adopters already run versions of this—letting agents propose optimizations while a human oversight committee validates the consequential moves and decides whether to proceed.
Here is the signal I would pay attention to. On Gartner’s 2026 maturity curve, governance, security, and cost-control capabilities for agentic AI are surfacing early, ahead of mass deployment and ahead of any public failure.1 The market is telling you something. Governance is the enabling layer for this technology, and the firms that treat it that way will move first.
My counsel to a client cuts against both camps. To the enthusiasts: do not rush an agent to the execution button to earn a press release. A single visible incident will set your whole program back years and hand the narrative to your most cautious regulator. To the skeptics: do not wait for regulatory clarity before you build. By the time the successor to SR 11-7 actually addresses agentic AI, the firms that put up the scaffolding early will own the capability and you will be licensing it. Sequence autonomy by reversibility and blast radius. Let agents act freely where an error is cheap and instantly undone, and gate them hard where it is not. Treat the governance architecture as a moat, because it is the one part a competitor cannot replicate over a weekend.
Sequencing Agent Autonomy: Reversibility vs. Blast Radius

The capability gap between today’s agents and a genuinely autonomous trader will keep narrowing, probably faster than the rulebook moves. The gap that decides winners will sit somewhere else entirely: between the firms that used the operational wave to build real accountability, supervision, and control and the firms that merely bought software. When the walls at the trading desk finally come down, and some of them will, the firms that walk through first will be the ones that spent these years earning the right to be trusted with the decision. That trust is the product. The model is the tool.
Works Cited
1. Gartner, Hype Cycle for Agentic AI, 2026. Governance, security, and cost profiles emerging before mass deployment.
2. Hogan Lovells, Agentic AI in Financial Services: Regulatory and Legal Considerations, 2025. EU AI Act obligations by risk level and third-party agent liability.
3. International Monetary Fund, How Agentic AI Will Reshape Payments (IMF Notes 2026/004), 2026. Supervisory mechanisms, real-time monitoring, audit trails, and correlated-behavior risk.
4. American Banker, Regulators’ Guidance on Model Risk Leaves Many Questions Unanswered, 2026. SR 26-2 scope exclusion, accountability gap, and AI-related litigation growth.
5. Outscale, Agentic AI Finance: Opportunities, Risks, and Regulatory Frameworks, 2026. Investment bank oversight-committee model for agent-assisted portfolio optimization.
Robert Adams
Senior Manager | Financial Services








