Agentic AI In Finance, Explained: What An AI Agent Actually Is, What It Can Do, And What It Should Never Be Allowed To Touch
Agentic AI is the most used and least understood phrase in financial services right now. EY found 78% of wealth and asset management firms already exploring it and just 7% actually deploying it - a gap that says less about appetite than about confusion. This is the plain-English explainer we wish existed: what separates an agent from a chatbot, why the distinction decides your entire risk picture, the five-rung autonomy ladder every serious deployment uses, where agents are genuinely earning their place in finance today, and the three questions to ask any vendor before you believe a word of the demo. No code, no hype, no acronyms left undefined.
AlchmAI Editorial14 min read
78% / 7%
Wealth and asset management firms exploring agentic AI versus those that have actually deployed it, per EY's survey
55%
Of asset managers with AI integrated into at least one investment process, with 91% planning to increase use within 12 months (Mercer)
40%
Of enterprise applications Gartner expects to embed task-specific AI agents by late 2026
95%
Of firms that have not yet implemented any cross-system integration for AI - the single biggest reason pilots stall
There is a particular meeting that happens in financial services firms at the moment, and it goes badly in a predictable way. Someone has seen a demo. In the demo, an AI was asked a question, went away, looked things up across several systems, did some reasoning, and came back with an answer and a recommended action. It was genuinely impressive. The meeting is about whether to buy it, and within ten minutes the conversation has split into people who think this changes everything and people who think it is a chatbot with better marketing, and neither group can articulate why they believe that, because nobody in the room shares a definition of what they just watched.
The numbers suggest this meeting is happening almost everywhere. EY's wealth and asset management survey found 78% of firms already exploring agentic AI and just 7% actually deploying it. Mercer's 2026 survey of asset managers found 55% with AI integrated into at least one investment process and 91% planning to increase use within a year. Enormous interest; very little in production. The usual explanation is caution, and caution is certainly part of it. But having sat in a lot of these meetings, we think the bigger problem is definitional. Firms are not slow to deploy agents because they have weighed the risk and decided against. They are slow because they cannot tell which of the things they have been shown is actually an agent, and therefore cannot tell which risk framework applies. This is our attempt to fix that, in plain English.
What Makes Something An Agent
Strip away the marketing and there is one distinction that matters. A chatbot or copilot answers. An agent acts. Everything else - reasoning, memory, planning, orchestration - is implementation detail that varies by vendor. The question that determines your entire risk picture is whether the system can cause something to happen in the world without a human doing it.
Concretely, an agent has three things a copilot does not:
- 01Tools. The ability to call other systems - read a database, query market data, send an email, create a ticket, submit an order. Tools are what convert language into consequence. A system with no tools cannot do anything, however clever its answer.
- 02A loop. It can take an action, observe the result, and decide what to do next, repeatedly, without being re-prompted. This is what lets it handle a task rather than a question - and it is also why agents fail in unfamiliar ways, because a small error early can compound across a dozen steps.
- 03A goal rather than an instruction. You give it an objective - reconcile these accounts, assemble this client pack, investigate this alert - and it determines the steps. That is the source of the value and the source of the anxiety, in exactly equal measure.
The Autonomy Ladder
Every serious agentic deployment we have built or reviewed uses some version of the same five-rung ladder. The value of writing it down is that it converts an argument about whether agents are safe into a specific decision about which rung a given workflow sits on - which is a question a risk committee can actually answer.
- 01Read-only. The agent can look things up across your systems and produce a briefing. It has no tools that change anything. Almost every firm should be here already; the risk is comparable to a search engine and the productivity gain is immediate.
- 02Draft and propose. It prepares the thing - the email, the order, the report, the client pack - and a human sends it. The crucial detail is that the human approves the specific artefact, not a general instruction to proceed.
- 03Bounded execution. It can act without asking, but only inside a hard envelope set outside the agent: these counterparties, up to this value, these hours, these transaction types. Anything outside the envelope is refused by a separate system that the agent cannot argue with.
- 04Supervised autonomy. It runs continuously inside the envelope with a human watching a live feed rather than approving each action, with anything unusual pausing the agent automatically.
- 05Full autonomy. Nobody is watching in real time. In financial services this is appropriate for genuinely non-consequential internal work and essentially nothing else. Any vendor proposing it for anything touching money, clients or regulated decisions is telling you they have not been through a controls review.
Where Agents Are Genuinely Working In Finance Today
Setting aside what is possible in principle, here is where we actually see agents earning their keep in financial institutions right now. The pattern is consistent: agents do well where the environment is well instrumented, the task is tightly scoped, and success is checkable by a machine or by a human in seconds.
- Research and briefing assembly. Pulling together filings, news, positions, prior correspondence and internal research into one reviewed brief before a human decides. Read-only, immediately useful, no regulatory drama.
- Client onboarding and KYC coordination. Chasing documents, validating completeness, flagging inconsistencies. The judgement stays human; the coordination does not need to be.
- Reconciliation and break investigation. High volume, rules-heavy, chronically under-staffed, and the answer is verifiable. This is the most under-rated agentic use case in the industry and the one we most often recommend firms start with.
- Alert triage in compliance and fraud. The agent does not decide what is an alert - the deterministic rules still do that - it ranks the queue and explains its reasoning, so analysts spend their time on the alerts that deserve it.
- Internal policy and knowledge answering. Answering the same question about a procedure with a citation to the source, which is both more useful and more auditable than the shared drive it replaces.
- Suitability and reporting drafts in wealth management. Draft-and-propose, always. The productivity gain is large precisely because the review is fast when the evidence is presented well.
What is not on that list, notably, is picking investments. The public evidence that general-purpose AI models can generate returns autonomously remains thin, and the firms with the best AI capability are conspicuously using it on the operational layer rather than the alpha layer. That is not timidity; it is where the measurable money currently is.
Why 95% Of Pilots Never Become Systems
The most useful statistic in EY's research is not the 78% or the 7%. It is that 95% of firms have not implemented any cross-system integration for AI. That single fact explains most of the pilot-to-production gap, and it is worth understanding why, because it determines where your money should go.
An agent's usefulness is almost entirely a function of what it can reach. An agent with access to one system is a better interface to that system. An agent that can reach your CRM, your custody data, your document store and your market data can answer questions no individual system can. The demo you saw was impressive because the demo environment had everything connected. Your environment does not, and connecting it is unglamorous integration work that nobody budgeted for because the proposal was about AI.
“Firms consistently under-budget the integration and over-budget the intelligence. The model is the cheapest part of an agentic system and the only part anyone puts in the business case.”
There is a positive version of this, though, and it is the reason we still recommend starting. The integration work is reusable. Connecting your document store properly serves the agent you build this year and every one you build after it. Firms that treat the first agentic project as an integration project with an agent on top end up with an asset; firms that treat it as an AI project end up with a demo and a renewal decision.
Three Questions To Ask Any Vendor
- 01Where does the permission boundary live, and can you show me the code or configuration that enforces it? You are looking for an answer that names a system other than the model. 'The agent is instructed not to' is a failing answer.
- 02What happens when it is wrong - and can you show me a real example? Every honest team has examples. A vendor with no failure stories has either not run in production or is not going to tell you about it, and both should affect your decision.
- 03What does it write to the audit trail, per action? For every step, you want the inputs it saw, the tool it called, the decision, the model version and who approved it. If you cannot reconstruct a decision six months later, you cannot defend it to a regulator, a client or your own risk function.
The Bottom Line
Agentic AI is neither the revolution the demos imply nor the rebranded chatbot the sceptics claim. It is a genuinely new capability - software that can pursue a goal across your systems rather than answer a question about them - wrapped in more hype than any technology since the cloud. The distinction that matters is simply whether the thing can act, because that determines which controls you need. Put autonomy in the tool layer rather than the prompt, start on the reconciliation-shaped work where success is checkable, budget for integration rather than intelligence, and insist on an audit trail you could show a regulator. Do those four things and you will be in the 7% that deployed rather than the 78% that explored, which on current evidence is a considerably better place to be. That is the work we do as an agentic AI and automation agency in London, and the firms getting value from it are not the ones with the cleverest models - they are the ones who were clear about what they were building.
References & Further Reading
- EY - GenAI in Wealth & Asset Management Survey. ey.com/en_us/insights/wealth-asset-management/gen-ai-in-wealth-asset-management-survey
- Mercer - Moving beyond the AI pitch: asset managers' use of AI. mercer.com/insights/investments/market-outlook-and-trends/asset-managers-use-of-ai
- Deloitte - The agentic AI productivity wave is heading for wealth management. deloitte.com/us/en/insights/industry/financial-services/financial-services-industry-predictions/2026/agentic-ai-wealth-management-productivity.html
- Neurons Lab - Agentic AI in financial services: a research roundup for 2026. neurons-lab.com/articles/agentic-ai-in-financial-services-2026
- FinTech Global - AI in wealth management: closing the implementation gap. fintech.global/2026/04/17/ai-in-wealth-management-closing-the-implementation-gap
- Fidelity - Wealth management trends for 2026: six questions driven by a wave of change. clearingcustody.fidelity.com/insights/topics/running-your-business/wealth-management-trends-for-2026
- Sourcegraph - Context engineering: a practical guide for AI agents (2026). sourcegraph.com/blog/context-engineering
AlchmAI Editorial
Research and analysis, London
The AlchmAI team writes about the markets, technology and regulation we work with every day. We build trading platforms, real-time charts and AI analysis tools for brokers, prop firms and fintech teams from our office in Mayfair, London. Every article lists its sources. Nothing we publish is investment advice.
This article is general information and commentary. It is not investment advice or a recommendation to buy or sell any investment. Important information