AI agents in banking · Lifecycle

Eight gates between an idea
and an agent in production.

Last updated Sep 6, 2026 · Updated as regulators move

An AI agent in a bank passes eight gates, and each gate is a question with evidence attached. The order matters: tiering comes before design because the tier decides which rulebook applies; vendor onboarding comes before validation because most agents are bought, not built; and the last stage loops back to the second, because a vendor model update, a new use, a new rule or an incident each re-opens the tiering question. The documents behind each gate are the ones examiners cite.

The eight-stage lifecycle of an AI agent, with a gate before every stage01Intake02Risk tiering03Design04Build andonboard05Validate andtest06Approve anddeploy07Operate andmonitor08Change,incident andretirementRE-ASSESS · VENDOR UPDATE · NEW USE · NEW RULE · INCIDENT◇ GATE QUESTION■ SIGN-OFF: ACCOUNTABLE OWNER + SECOND LINE
Figure 2 · The lifecycle. Each diamond is a gate question the stage must answer before the next begins; the return arrow is the re-assessment loop that vendor updates, new uses, new rules and incidents all trigger.
01

Intake

What will the agent do, for whom, and what could go wrong?

EVIDENCE AT THE GATE

  • Use-case statement naming the process, the users and the affected customers
  • The actions the agent will be allowed to take, listed
  • Initial harm analysis

DOCUMENTS

02

Risk tiering

Which tier, which autonomy level, which rulebook?

EVIDENCE AT THE GATE

  • Materiality rating
  • Autonomy level (0–4) proposed and approved
  • Regulatory classification: model-risk scope, EU high-risk, consequential decision, consumer-facing

DOCUMENTS

  • FSB AI sound practices consultation (June 2026) · FSBSound Practice 5: materiality and risk assessment before selection.
  • SR 26-2 · Federal ReserveMateriality drives the intensity of validation and monitoring; generative/agentic out of scope.
  • Regulation (EU) 2024/1689 · EU AI ActAnnex III classification decides whether the full high-risk regime applies.
  • SB 26-189 · Colorado AI Act'Covered ADMT' — material influence over a consequential decision — triggers notice and review duties.
03

Design

What is the permission envelope and where does a human sit?

EVIDENCE AT THE GATE

  • Identity and entitlements specified
  • Tool allow-list, limits and approval points
  • Data scope and lineage plan
  • Oversight design: thresholds, reviewers, recourse

DOCUMENTS

04

Build and onboard

Do we know what we are buying, and can we leave?

EVIDENCE AT THE GATE

  • Vendor due diligence and contract terms (data use, audit, incident notification, exit)
  • Secure development evidence; human review of AI-generated code
  • Component inventory including models, retrieval stores and tools

DOCUMENTS

05

Validate and test

Does it do what we approved, and what happens when attacked?

EVIDENCE AT THE GATE

  • Evaluation results against the approval metrics
  • Adversarial and red-team testing (prompt injection, poisoning, specification gaming)
  • Independent validation for any in-scope model the agent calls

DOCUMENTS

  • SR 26-2 · Federal ReserveIndependent validation with outcomes analysis and effective challenge for in-scope models.
  • NIST AI 100-2e2025 (Adversarial ML) · NISTAdversarial machine-learning taxonomy for attack-oriented testing.
  • PRA SS1/23 · UK (BoE / PRA / FCA)Independent validation principle, including vendor models.
  • FCA FS25/5 · UK (BoE / PRA / FCA)Supervised live testing as a path to production for AI in UK financial services.
06

Approve and deploy

Who signs, and is the oversight actually configured?

EVIDENCE AT THE GATE

  • Sign-off by the accountable owner and the second line
  • Staged rollout with rollback
  • Oversight thresholds, reviewers and kill switch verified in production

DOCUMENTS

07

Operate and monitor

Is it still doing what we approved?

EVIDENCE AT THE GATE

  • Traces retained; drift and performance dashboards against approval metrics
  • Security alerting for anomalous behaviour
  • Oversight metrics: override rate, escalations, time-to-human

DOCUMENTS

08

Change, incident and retirement

What changed, what broke, and when do we re-assess?

EVIDENCE AT THE GATE

  • Re-assessment triggers: vendor model update, new use, new rule, incident
  • Incident playbook with regulatory notification paths
  • Exit executed per plan; entitlements revoked; data handled per retention

DOCUMENTS

Know which gate just moved

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →