Agentic AI in regulated lending: Where to draw the line

Lenders are moving into an environment where AI can reason, plan, adapt, and take action with increasingly little human direction. That creates an obvious tension for regulated financial institutions: move too cautiously and miss the value, or move too quickly and struggle to explain what happened when an examiner asks.
So where should financial providers draw the line?
That question came up during LoanPro’s 2026 Salt Flats Summit on stage with Mariah Miller, Head of AI Innovation and Frontier Engineering, AWS Generative AI Innovation Center; Amanda Lester, Principal Worldwide Agentic AI Go-To-Market Specialist, AWS; and Colin Terry, Chief Product Officer at LoanPro.
Their discussion gives lenders a way to think about the line: autonomy can expand, but only when lenders can define the boundaries, monitor what happens, and intervene when the stakes require it.

Key Takeaways
- The cost of accessing AI intelligence has fallen dramatically, making more lending use cases economically viable.
- As intelligence becomes more available, judgment about where and how AI should act becomes more important.
- Reversibility is a practical way to decide where agents can act autonomously and where humans need to stay involved.
- Human review can create its own operational risk when people are asked to approve every AI decision.
- Regulators are increasingly focused on whether institutions can explain, monitor, constrain, and reverse AI-driven actions.
- The strongest controls live outside the agent itself, giving the institution a stable layer of permissions and policies that the agent cannot rewrite.
Intelligence is getting cheaper. Judgment is getting more valuable.
The cost of intelligence has dropped roughly 2,000 times over the past 5 years. According to Miller, “that means you can now access PhD level intelligence for three cents for a million tokens. That's like having a four hundred dollar an hour consultant work for you for about a dollar. And with that dropping price of intelligence, suddenly a lot more possibilities open up for your organization, for your company.”
That shift changes what’s possible for agentic lending. When intelligence was expensive, organizations had to be selective about where they applied it. As the cost of accessing models falls, more tasks become economically viable. Now, a lender can bring proprietary data and institutional context to AI systems and use them across more workflows.
The resulting advantage, however, does not come from simply having access to the same underlying intelligence as everyone else.
“Intelligence itself becomes a commodity, and it's no longer scarce,” Miller said. “But what is scarce and what becomes scarce is judgment.”
For lenders, that judgment starts with deciding where an agent should be allowed to reason and act, what information it can access, what actions it can take, and when another control needs to intervene.
That is a different operating model from traditional software, where organizations could design a process around predictable inputs and outputs. Agentic systems introduce a degree of non-determinism by design. They can reason through a goal and determine how to accomplish it rather than following one fixed sequence of steps.
The challenge is to preserve determinism where it matters most: in the rules surrounding the agent.
Give agents room to reason, then define the boundaries
Agentic AI is useful precisely because it can make decisions within a broader objective. It can break a goal into smaller tasks, use available tools and data, adapt its approach, and escalate when it reaches a situation it cannot resolve confidently.
“This new age and frontier of agentic AI is not the future,” Lester said. “This is actually happening now across every single industry segment and size of company around the world.”
Agents will become part of the technology stack for regulated lenders. So, the question becomes how much authority should they have?
AWS's approach is to separate the non-deterministic part of the system from the deterministic controls around it. The agent can determine how to accomplish its objective. The organization determines the rules governing what AI can access and what it is allowed to do.
For example, an agent might be able to analyze borrower information, research an account, identify a potential issue, summarize a case, or recommend the next action. The system surrounding that agent can determine whether it has permission to update an account, initiate a transaction, modify a loan, communicate with a borrower, or take another consequential action.
Most importantly, those permissions should not depend on the agent deciding for itself what the rules mean.
“It’s also important to leverage a rule system that lives outside of the agent itself so it can’t convince itself to sort of get around the rules,” Miller said.
That external layer matters in regulated lending because models, prompts, and agent behavior can change. The permissions governing consequential actions need to remain stable even when the system doing the work is dynamic.
One-way door vs. two-way door decisions
One of the biggest takeaways from the discussion was the distinction between one-way and two-way door decisions.
Miller notes that two-way doors are ones you can walk through and walk back should something go wrong. But, one-way door decisions are those that you walk through and it's done.
This idea of reversible actions (i.e., two-way doors) gives lenders a more useful way to think about human oversight than simply asking whether a human should be “in the loop.”
Some use cases may require a human to approve every action. Others may work better with an agent that can act independently within clearly defined permissions, with humans involved when the system encounters uncertainty or reaches a defined risk threshold.
The appropriate level of autonomy depends on the use case, the institution's risk appetite, and the applicable regulatory requirements.

It also can change over time. Miller described agents as being able to “earn” greater autonomy by consistently operating within defined risk limits. The important point is that increased autonomy comes from demonstrated performance inside a defined framework, not from simply giving the agent broader access.
The key is to make that decision deliberately.
Understanding where human review can become its own risk
While putting a human in front of every AI decision sounds like the safest possible approach, it can create a different problem.
If an agent generates hundreds of recommendations and a human is expected to approve every one, the reviewer eventually becomes a bottleneck. More importantly, the quality of review can deteriorate when people are asked to repeatedly evaluate large volumes of routine decisions.
Miller described this as a “peanut butter spread” approach to approvals: human attention gets distributed thinly across everything instead of concentrated where it provides the most value.
A better approach is to identify the decisions that genuinely require human judgment. An agent can handle routine work within its authorized permissions while surfacing exceptions, uncertainty, unusual inputs, or decisions that cross a defined threshold. The human then spends time where human judgment adds the most value.
That turns human oversight from constant approval into targeted intervention.
It also gives the institution a clearer AI governance framework. A lender can explain which decisions are automated, which require approval, what triggers escalation, and how the organization responds when something falls outside the expected parameters.
State examiners also want operational visibility
The regulatory conversation around AI is also moving toward operational visibility.
During the Salt Flats discussion, Terry highlighted the newly published Conference of State Banker Supervisors (CSBS) AI supervisory framework.
The framework gives state examiners a way to assess AI use and risk at state-chartered banks and state-licensed nonbank financial institutions.
One section Terry called out focuses on AI systems that can take action with limited human direction. It directs examiners to review how institutions define permitted actions, human checkpoints, system logging, reversibility, and the ability to restrict or halt the system.
“As I read it, the thing that was interesting to me is it's less about controlling your AI usage and more about making sure you know how you're using AI,” said Terry.
For instance, a vendor’s controls do not eliminate the institution’s responsibility to understand the system operating in its environment. If an examiner asks how an AI system works, the lender needs to be able to explain its permitted actions, human checkpoints, logging, reversibility, and ability to restrict or halt the system.
That makes governance part of the product architecture rather than an exercise that happens after deployment.
Soft rules, hard permissions
This is where the AWS framework and the regulatory discussion converge.
AI agents in banking need enough flexibility to reason through a problem. The institution needs a separate control layer that determines what the agent is allowed to do.
That layer can include permissions, least-privilege access, external rules, human checkpoints, monitoring, logging, audit trails, and mechanisms for restricting or stopping the system. Each serves a different purpose, but together they create something an agent cannot simply redefine for itself.
Visibility is just as important as control.
“If you don't know what agents exist within your organization or what jobs they're working on or who built it, what version they're on, how can you address problems and ensure that those agents are driving the right performance?” Lester said.
Institutions need a current view of the systems operating across the organization, who owns them, what they are authorized to do, and how their performance is being monitored.
The same principle applies to changes over time. Agentic systems are non-deterministic by nature, and changes to models or surrounding systems can affect how an agent achieves its objective. Continuous monitoring and optimization therefore become part of operating the system, rather than something reserved for periodic reviews.
Where to start when lenders can’t risk anything
For lenders still figuring out where agentic AI belongs, the answer does not have to begin with the most consequential decisions.
Start with a business problem. Then determine how much autonomy the problem can support. Lester described several agentic use cases already operating at scale, including conversational agents, coding and security workflows, and broader workflow automation.
Research and information gathering can happen with relatively limited risk when the resulting action remains with a human. Agents can then move into recommendation workflows, where they propose actions and humans approve them. More autonomous execution can follow when the action is reversible, the permissions are constrained, and the institution has the monitoring and controls required to intervene.
That creates a path toward greater autonomy without requiring the organization to make one giant leap. It also gives teams something valuable as they build: evidence.
Each use case can demonstrate what the agent does well, where it needs guardrails, what types of exceptions require escalation, and how the organization monitors performance. Those lessons can inform the next deployment and, eventually, support greater autonomy.
Have questions? Checkout our FAQ:
What is agentic AI in lending?
Agentic AI refers to AI systems that can independently plan and execute multi-step tasks to achieve a defined goal, without needing a human to guide every step. Given an objective, an agentic system breaks it into subtasks, sequences the right actions, executes across tools and systems, and self-corrects when something goes sideways.
Should lenders keep a human in the loop for every AI decision?
Not necessarily. The appropriate level of human involvement depends on the risk, reversibility, business objective, and regulatory requirements associated with the use case. Human review can be concentrated around consequential or uncertain decisions while lower-risk, reversible work can operate with greater autonomy.
Is the new CSBS Artificial Intelligence Supervisory Framework mandatory?
The CSBS Artificial Intelligence Supervisory Framework is a supervisory tool for state regulators, not a standalone regulation. CSBS says each state financial regulatory agency will determine the extent to which it incorporates the framework into its supervisory program.
Institutions can use the framework to assess their own AI governance and prepare for the types of questions examiners may ask about AI use, accountability, controls, and oversight.
Who does the CSBS AI Supervisory Framework apply to?
The CSBS AI Supervisory Framework is designed to support state examiners assessing AI use and risks at state-chartered banks and state-licensed nonbank financial institutions.
How it is used can vary by state and institution. The framework is intended to help examiners consider factors including an institution’s size, complexity, risk profile, and use of AI when evaluating governance and controls
What is an AI inventory?
An AI inventory is a documented view of the AI applications an organization uses, along with enough information to understand what each application does, who owns it, how it is being used, and what controls apply to it.
What controls should lenders have around agentic AI?
Key controls may include defined permissions, least-privilege access, external rules, human checkpoints, monitoring, logging, audit trails, reversibility, and the ability to restrict or halt an agent.
How can lenders get started with agentic AI?
Start with a specific business problem and measurable outcome. Then determine what level of autonomy the workflow can support, beginning with use cases where actions are reversible and the institution can monitor performance and intervene when necessary. As the organization gains experience, it can expand autonomy within clearly defined boundaries.




