Banks have stopped asking whether they have AI: now they ask how much autonomy to give it

-

Until recently, the question in banks’ technology committees was binary: do we have AI or not? That question aged fast. Bank of America has already rolled out artificial intelligence tools for its more than 200,000 employees, who generate over 400,000 prompts a day. JPMorgan is working with close to 1,000 use cases, from fraud and risk management to document processing and other bank operations. And at Citigroup, according to CEO Jane Fraser, nearly nine out of ten employees already use the organization’s AI tools.

Success created a new problem. While artificial intelligence was limited to answering questions, the main risk was that it would get something wrong. Once it starts acting, the nature of the risk changes: it can get something wrong and execute the mistake.

That difference was laid bare on August 7, when OpenAI revealed that preliminary evaluations of Astra showed cybersecurity capabilities so advanced that the company could no longer rule out the model reaching its “Critical” warning threshold.

That level doesn’t simply describe an AI that knows a lot about information security. It covers systems capable, under certain conditions, of discovering vulnerabilities, developing exploits, and carrying out sophisticated attacks with a degree of autonomy that drastically reduces the need for human intervention.

The episode put a concrete case behind a concern the International Monetary Fund had raised weeks earlier. In its report Artificial Intelligence and Cybersecurity in the Financial Sector, published on June 29, the IMF raised a particularly uncomfortable paradox for banking: the same capabilities that allow AI to be used to detect a vulnerability before an attacker does can also be used to find and exploit it.

And the risk doesn’t end at one institution. Banking depends on cloud, software, infrastructure, and model providers that are often shared. In a system this interconnected, a common vulnerability can turn a single incident into a simultaneous problem for multiple institutions.

The problem, then, is no longer just what the machine knows how to do. It’s who gave it permission to do it. For a bank, talking about autonomy means deciding what data an AI can query, what systems it can modify, what operations it can execute, under what limits, and what happens when its behavior strays from what’s expected.

Giving autonomy doesn’t mean losing control. “A bank has to determine what the AI can do. With what information, with what scope, and how to stop it if it crosses predefined boundaries. If any of those answers isn’t clear, it isn’t ready yet to delegate the decision to it,” says Julián Colombo, CEO of N5.

At N5, that discussion isn’t abstract. It’s part of the thinking behind the design of Singular, the company’s banking artificial intelligence, built to operate under a supervised autonomy model.

The same logic runs through the products in the by N5 family, designed to step in on specific tasks rather than being handed, from day one, unrestricted control over entire processes.

Because autonomy isn’t a binary condition. An organization can give a system permission to read but not to write; to recommend but not to execute; to operate up to a certain amount; to act only within certain workflows; or to keep going only while certain conditions stay within defined limits.

In a sense, that’s also the answer to the risk the IMF describes. If an increasingly capable AI widens the potential blast radius of an error or an attack, the solution isn’t to give up that capability. It’s to design the radius within which it can be used. Audit it. Limit it. Explain it. And, when necessary, stop it.

Share this article

Recent posts

Popular categories