Alex Ford, CRO, Encompass. Alex drives global business growth, working with customers and industry partners to transform KYC with CDI.
Sibos 2026, held in Miami from September 28 to October 1, is Swift’s flagship conference and opens with a keynote from Citi chair and CEO Jane Fraser. Her leadership of Citi’s multiyear digital transformation captures the event’s theme of digital finance for AI-driven economies.
AI is reshaping the financial ecosystem. Fraser told the South China Morning Post in an interview (paywall) that banks, in her view, are now running two AI races simultaneously. The first is to capture productivity and revenue gains, while the other is to defend against AI-enabled threats.
What deserves more attention than either race is a quieter shift underway. Increasingly, AI systems are initiating and executing actions, payments, approvals and negotiations on an institution’s behalf. Identity frameworks, in finance and far beyond it, were built to answer one question: Who is this person or company? They weren’t built to answer a second, now-urgent question: Who authorized this AI to act, and within what limits?
Healthcare is running into the same wall: Many hospitals are piloting AI agents that can schedule procedures and order tests on a clinician’s behalf, and the same gap shows up there—a system built to verify which doctor is logged in has no equivalent way to verify which actions an AI was actually authorized to take for them.
A Governance Problem, Not A Technology Problem
It’s tempting to treat this as a model capability issue. It’s more accurately a data, authorization and accountability problem, and it’s already on regulators’ desks.
The U.K.’s Financial Conduct Authority published its review into AI and retail financial services, led by executive director Sheldon Mills, in July 2026. Mills was direct about where responsibility sits as firms pilot increasingly autonomous systems: “You need a human on the hook for what they’re doing.”
The review’s own finding reinforces the point: Accountability for an AI-driven action stays with a named senior manager under the FCA’s Senior Managers and Certification Regime, not with the AI system or its provider.
That principle generalizes well beyond U.K. retail banking. Any organization giving AI agents room to act, in any industry, needs a clear, verifiable chain from action back to an accountable human. Most identity and governance systems in place today can’t produce that chain on demand.
Three Layers, Not One
Reimagining corporate identity for an AI-driven economy means separating it into three distinct layers, where most organizations have only really built the first:
1. Entity Identity: Knowing who a company or institution is. Decades of know your customer (KYC), vendor verification and entity data infrastructure have been built to solve this layer.
2. Human Accountability: Knowing which named individual is accountable for a specific AI-driven action or decision. This sounds straightforward until an organization tries to document it for every AI use case currently running inside the business.
3. Delegated Authority: What, specifically, an AI agent is authorized to do on a person’s or entity’s behalf and where that authority stops. This one’s receiving the least attention.
Agentic AI is already negotiating terms, approving transactions and initiating payments in pilots across banking, procurement and supply chains. In most cases, the boundary of what the agent may do exists as an assumption rather than a documented, enforced limit.
Interoperability Making This Urgent
Sibos is pairing AI with two other themes this year: interoperability and resilience. That pairing matters more than it first appears.
Bank of England Deputy Governor Sarah Breeden made a related point from the systemic-risk side at the European Central Bank’s forum in Sintra in June 2026. Existing, technology-agnostic regulatory frameworks, in her assessment, weren’t designed with autonomous agents in mind, prompting the bank to explore market-wide safeguards such as circuit breakers. An April 2026 University of Cambridge survey found that 52% of responding finance firms had already deployed agentic AI in some capacity, well ahead of the governance built to contain it.
As AI agents increasingly act across institutional and national borders, one organization’s internal authorization record isn’t enough. A counterparty, regulator, or partner system needs a way to verify an agent’s delegated authority in real time rather than trust that the sending institution has it under control internally. Identity, in this sense, stops being a purely internal control and becomes something that must be portable and verifiable across an entire ecosystem.
What Technology Leaders Should Do Now
Four steps are worth taking before scaling agentic AI further, regardless of industry:
1. Map every point where an AI agent currently has any ability to initiate action, however limited. Most organizations underestimate this number.
2. For each, document the named individual accountable—the individual, not the team.
3. Define the explicit boundary of that agent’s authority and confirm how it’s enforced technically, not just described in policy.
4. Test whether the full chain (entity, accountable human, agent authority) can be produced on demand for a regulator, auditor or counterparty asking the question cold.
Gaps in that chain should be treated as governance debt. Like technical debt, it compounds quietly and becomes far more expensive to unwind once agentic AI is operating at scale than it is to address now.
The Competitive Case
Although this can be a compliance argument, it’s mainly a competitive argument. Organizations that solve agent identity and delegated authority now will be positioned to scale agentic AI with genuine confidence in front of regulators, partners and their own boards.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


