Agentic banking starts with governance

Dan Kim
VP, Product Partnerships, Ecosystem & Developer Experience

Can agents safely execute financial work? The answer goes beyond just telling them what to do.
When people say “agentic”, they’re almost always talking about commerce: an agent finds a product, checks out, and pays in one click. That conversation is moving fast, but I see more finance leaders asking a harder question, one that has nothing to do with shopping.
What happens when the agent has to run the finance function on its own? That means agents paying suppliers on time across a dozen currencies, managing currency exposure, closing the books, and keeping every action inside controls a board would recognise. To do that, agents need to understand which entity owns the money, which account should fund a payment, which rail should carry it, and what needs to happen when a transaction fails. We call this agentic banking.
We recently made the case that businesses that can execute financial work at agentic speed will be ahead of the curve. Agentic speed only becomes an advantage when it’s governed. Governance is another layer of control that protects the accuracy and accountability that finance requires.
Finance proves whether agents can be trusted elsewhere
Across business functions, finance tests autonomous execution most rigorously because precision is paramount. A wrong payment causes real financial loss. A bad treasury call affects liquidity. A compliance failure creates regulatory exposure. An error touches a supplier, an employee, or a customer.
With agents, finance teams no longer wait to collect revenue in one currency, convert it into another, pay a supplier through a local rail, and reconcile the result against the right entity and ledger. Agents perform those steps while everyone in that time zone sleeps. Every step still must be correct and leave a record for an auditor, regulator, or CFO.
If agents execute financial work safely, continuously, and within controls, leadership can trust them across the business. Controls that make a payment or liquidity decision trustworthy clear the ground for agents to execute work in other functions.
What agents can do today and where they stop
We wrote earlier about why software agents stop when a workflow requires a payment. Now, finance teams need to decide how much authority to give an agent and which controls make that transaction safe.
Today, agents can already read invoices, reconcile transactions, flag anomalies, forecast cash flow, and build a case for a payment before a person looks at it.
What agents don't do yet is move money themselves. A person still approves anything that leaves the account, regardless of how routine the payment is or how many times the agent has gotten it right before.
The goal is for agents to execute that work directly while people keep oversight exactly where it matters most. Getting there means moving from broad, human-level access to something narrower and enforceable. This is a governance decision every business will eventually face.
Enforce agent boundaries through infrastructure, not prompts
To let agents execute financial work confidently, businesses need controls in place, like approvals, permissions, and audit trails.
Autonomous execution requires three things:
First, grant authority to agents by specifying what they can move, in which currencies, and to which recipients.
Second, set limits on transaction amounts and establish an approval chain.
Third, enforce those limits through underlying infrastructure rather than prompts.
A prompt is not a financial control. You can tell an agent not to overspend, but only infrastructure can actually enforce a card limit, approval threshold, beneficiary restriction, or entity-level permission.
Telling and enforcing aren’t the same. People set the objectives, authority, limits, and escalation rules. Agents review information, prepare actions, and complete low-risk work within those boundaries. People approve sensitive or high-risk decisions, with no exceptions for an agent’s track record. We check every action against policy before execution and log every outcome for audit.
Let’s take purchasing as an example. If you let multiple agents buy on your behalf using a shared business card or unrestricted API key, you won't be able to tell which agent made which purchase. But if you issue each agent its own virtual card for specific tasks, you can control all the parameters of that transaction, including budget limits, permitted currencies, merchant category codes, and time windows. Every transaction then carries a record connecting it back to the agent, the task, and the policy behind it, so accountability doesn't depend on a person's memory.
Why agentic money movement depends on regulated accounts and rails
Whether you're a startup that collects revenue in two or twenty currencies, an agent moving money still depends on regulated infrastructure: accounts that safeguard funds, permissions that enforce policy, networks that move money across borders, and ledgers that record every action.
Airwallex built that infrastructure so finance teams can give agents access to accounts, balances, and global payout rails with transaction-level controls.
Through AgentOS, teams can let agents query cash flow and balances, draft invoices, or provision cards inside tools like Claude, Cursor, or Codex, while keeping high-risk actions like transfers and FX subject to human approval.
That balance of authority and control is how businesses move safely from automated reporting to continuous, autonomous execution.
The material presented here is for informational purposes only and does not constitute legal, regulatory, taxation, or investment advice. Readers should engage their own advisors or counsel for advice unique to their circumstances.

Dan Kim
VP, Product Partnerships, Ecosystem & Developer Experience
Dan Kim is VP, Product Partnerships, Ecosystem & Developer Experience at Airwallex, where he works at the intersection of global financial infrastructure, developer platforms, and agentic finance. A builder and operator, he previously spent five years at Coinbase and co-authored x402, an internet-native payments standard for APIs, apps, and AI agents. His work focuses on what happens after an agent decides to act: how identity, permissions, payments, and financial execution come together in the real world.


