There's a conversation happening in boardrooms across every major bank and financial institution right now. It's not about whether AI will change operations. That question was settled two years ago. The conversation today is: how fast, which roles first, and what do we do with the people whose jobs are going away.
I've been close enough to the infrastructure of financial institutions — building payment systems, BI platforms, and fraud engines — to watch this shift happen in real time. And the pattern I'm seeing is consistent: AI agents are not coming for the creative, judgment-heavy roles first. They're coming for the BAU — the business-as-usual work that keeps the lights on, consumes enormous headcount, and adds no competitive differentiation.
That's a more important observation than it sounds. BAU work is the backbone of operations at most financial institutions. Understanding exactly which parts are vulnerable — and which aren't — is the difference between a well-managed transition and an expensive, chaotic one.
What we mean by BAU — and why it's the prime target
BAU in banking covers an enormous surface area. It includes everything that has to happen every day, every week, every month to keep the institution running — not to grow it, not to improve it, just to maintain it. Think: transaction reconciliation, regulatory reporting, AML alert review, KYC refresh cycles, exception handling queues, IT incident triage, trade settlement checks, interbank communication, and the hundred smaller processes that live in spreadsheets and email inboxes because no one ever got around to automating them properly.
These tasks share a common profile that makes them ideal for AI agent replacement:
- They are rule-bound or pattern-driven — the decision logic is knowable, even if complex
- They are high-volume and repetitive — the same type of task runs thousands of times a day
- They have clear inputs and outputs — a document in, a decision out; a data feed in, a report out
- They are well-documented — compliance requirements mean there are usually written procedures
- They are measurable — you can tell objectively whether the agent did the job correctly
This is exactly the profile that agentic AI systems are built for. Not general intelligence. Not creativity. Bounded, well-defined, high-volume work where speed and consistency beat human throughput.
Where AI agents are already doing BAU work
1. Transaction reconciliation and exception management
Reconciliation has been a candidate for automation for thirty years. The reason it's still done manually at most mid-sized institutions is that the exceptions— the mismatches that don't resolve automatically — require judgment that traditional rule engines couldn't provide.
AI agents change this equation. A modern reconciliation agent doesn't just match records — it classifies exceptions by likely cause, fetches supporting documentation from connected systems, proposes a resolution, and routes only the genuinely ambiguous cases to a human. What used to require a team of five working an exceptions queue can now be handled by one person reviewing agent-generated resolution proposals.
The banks deploying this well are seeing reconciliation cycle times collapse from days to hours, with error rates dropping because the agent doesn't have Monday morning attention issues.
2. AML alert review and false positive triage
Anti-money laundering compliance is one of the most expensive BAU functions in banking. A large institution might generate tens of thousands of AML alerts per day from its transaction monitoring system. Industry benchmarks suggest that 95% or more of those alerts are false positives. Human analysts spend the majority of their time dismissing alerts that any experienced compliance officer would dismiss in seconds.
This is a solved problem for AI agents. An agent trained on historical alert dispositions can triage the obvious false positives automatically — documenting its reasoning for the audit trail — and surface only the alerts that warrant human review. The humans shift from alert-dismissal work to actual investigation work. Compliance quality goes up while headcount requirements go down.
The regulatory question that used to make institutions nervous — “can we use AI for AML decisions?” — has been substantially answered. Regulators across the UK, EU, and US have published guidance explicitly permitting AI-assisted AML triage provided the human-in-the-loop and audit trail requirements are met. The technology is no longer ahead of the regulation here.
3. Regulatory reporting
Regulatory reporting is one of the most resource-intensive BAU functions at any bank. A mid-sized institution might file hundreds of regulatory reports per year across multiple jurisdictions — each one requiring data extraction, transformation, validation, and submission with strict deadlines.
AI agents are replacing the human effort in all four stages. An agent can monitor source data feeds, detect when required data is available, run validation checks against regulatory schemas, generate the report, flag anomalies for human review, and submit — all without a human touching the process unless something unexpected happens.
The institutions I've seen deploy this well have not eliminated their regulatory reporting teams. They've redeployed them. Instead of running the process, the team's job becomes owning the agent — monitoring its performance, handling the exceptions it escalates, improving the validation rules, and managing the regulatory relationship. It's a better use of experienced compliance professionals.
4. IT operations and incident management
Banking IT operations is classic BAU territory: monitoring dashboards, alert triage, runbook execution, ticket routing, incident documentation. The vast majority of IT incidents at a large bank are variations of a small number of known patterns — a database connection pool exhausting, a batch job timing out, a certificate expiring.
An AI agent with access to monitoring systems, runbooks, and historical incident data can handle the entire lifecycle of a known incident pattern: detect, diagnose, execute the remediation runbook, verify resolution, and close the ticket — potentially without waking anyone up at 3am. The humans focus on the novel incidents that don't match known patterns, which are the ones that actually require engineering judgment.
I've implemented infrastructure monitoring and automation for financial clients that operates exactly this way. The on-call load drops dramatically. The incidents that do escalate to humans are genuinely interesting problems, not the third recurrence of the same batch job timeout this month.
5. KYC periodic review and customer due diligence refresh
Every financial institution is required to periodically refresh customer due diligence — checking that the information on file still matches the customer's current profile, risk classification, and any adverse media or sanctions list changes. For large retail banks, this means millions of reviews per year.
AI agents can handle the routine cases end-to-end: pull the customer record, check against updated sanctions lists, screen for adverse media, assess whether the risk profile has changed, update the record, and document the review — all automatically. A human reviews only cases where a meaningful change has been detected.
The compliance quality improvement here is often better than the cost saving. Manual KYC refresh cycles, done under time pressure, produce inconsistent quality. An agent is consistent by design.
What AI agents cannot replace (yet)
Being honest about the limits is just as important as understanding the capabilities.
Relationship management
Corporate banking relationships, particularly at the senior level, still require humans. A relationship manager who knows a CFO personally, who understands the strategic context of a financing request, who can navigate a difficult renegotiation — that judgment is not coming from an agent in 2026. The agents handle the prep work: pulling account history, generating briefing documents, flagging relationship risks. The human does the meeting.
Novel regulatory interpretation
When a new regulation is published, somebody has to read it, interpret it, assess its impact on the bank's specific business model, and decide what to change. This requires legal expertise, institutional knowledge, and judgment about regulatory intent that current AI systems cannot reliably provide. Agents can help — summarising the regulation, identifying potentially affected processes — but the interpretation decision stays with humans.
Crisis management and novel risk events
When something genuinely unprecedented happens — a market structure break, a counterparty failure, a systemic liquidity event — the BAU playbook is useless and agents trained on BAU patterns will not help. These situations require experienced humans making judgment calls under uncertainty. This is precisely when you need your senior people freed from BAU work, which is another reason to automate the routine.
The organisational question nobody wants to answer
The technology discussion is relatively straightforward. The harder conversation is about people.
Banks that deploy AI agents for BAU work are not, in most cases, proportionally growing their headcount elsewhere to absorb the displaced capacity. Some redeployment happens. Some roles genuinely go away. The institutions handling this best are the ones being transparent about it early — giving people time to retrain, identifying which human skills complement rather than compete with agents, and building internal paths to the new roles.
The roles that hold value in an agent-augmented bank look different from today's BAU roles:
- Agent owners — people who understand the process deeply enough to specify, monitor, and improve an agent's behaviour
- Exception handlers — experienced professionals who handle the cases agents escalate, which are by definition the hard ones
- Process designers — people who can redesign end-to-end workflows around agent capabilities rather than human ones
- Relationship and judgment roles — the senior, context-dependent work that agents genuinely cannot do
The institutions that are going to get this wrong are the ones treating agent deployment as a headcount reduction exercise first and an operational improvement second. The ones getting it right are treating it as a chance to redeploy smart people to higher-value work while eliminating the grinding, repetitive operations that no one actually wants to do.
How to actually deploy this — the infrastructure reality
There's a gap between the boardroom conversation about AI agents and what it actually takes to deploy one in a regulated financial institution. Having built the underlying infrastructure for several of these systems, here's what that gap looks like in practice.
Data access and integration
An agent is only as useful as the data it can access. Most large banks have decades of technical debt in their data layer — core banking systems that predate the internet, data siloed by business unit, APIs that were never built because the processes they would serve were always done manually. Before you can deploy an agent that automates reconciliation, you need to solve the data integration problem. That often means building API layers over legacy systems, which is engineering work that needs to happen before the AI work.
Audit trails and explainability
Every action an agent takes in a regulated environment needs to be logged, explainable, and attributable. This isn't optional — it's the baseline requirement for regulatory acceptance. Building the audit infrastructure is not glamorous, but it's what makes the difference between a proof of concept and a production system.
Escalation design
The most important design decision in any BAU agent deployment is the escalation boundary — what the agent handles autonomously versus what it routes to a human, and how it hands off. Get this wrong and you end up with either agents that escalate everything (useless) or agents that make autonomous decisions they shouldn't (dangerous). The escalation logic usually takes longer to design than the core agent functionality.
Change management
The people whose BAU work is being automated are often the subject matter experts you need to build the agent correctly. Getting them involved in the design — treating them as agents of the change rather than subjects of it — produces better agents and more manageable transitions.
Where to start if you haven't yet
If your institution hasn't begun deploying AI agents for BAU work, you're not behind — yet. But the window to make this transition at your own pace is closing. The institutions that move first gain compounding advantages: lower operational costs, better compliance quality, and talent redeployed to differentiated work.
- 1Identify your highest-volume BAU processes and rank them by the share of work that is rule-bound versus judgment-dependent. The top of that list is where you start.
- 2Assess your data infrastructure honestly. Can an agent actually access the data it needs? If not, what's the shortest path to making that possible?
- 3Start with a contained pilot — one process, one team, a measurable outcome. Don't start with the most complex or politically sensitive process. Start with one where success is easy to demonstrate.
- 4Design the human role first. Before you build the agent, define what the human in this process does after automation. If you can't answer that question, the deployment will fail organisationally even if it succeeds technically.
- 5Measure rigorously. Define what success looks like before you deploy — cycle time, error rate, cost per transaction, staff hours freed. You'll need this data to justify the next deployment.
The agentic AI wave is not coming for the interesting work first. It's coming for the grinding, repetitive, high-volume operations that consume the majority of operational headcount at most financial institutions. For the people doing that work, that's a disruption. For the institutions, it's an opportunity to redirect human intelligence to where it actually matters.
The question is not whether this happens. It already is. The question is whether you're the one driving it or reacting to it.