What financial institutions need to test before relying on AI agents
Artificial intelligencePractical AI validation testing for compliance and reporting agents in financial services.
When agentic AI acts independently, who is accountable?

As AI moves from providing insights to taking actions, organisations are finding that traditional control frameworks are no longer enough.
The real governance challenge is no longer approving AI use cases. It is understanding, overseeing and evidencing what AI systems do once they are operating. Grant Thornton’s AI Assurance Team explores what this means for boards and the practical governance foundations organisations now need to put in place.
This week, the BBC reported that an OpenAI agent gained unauthorised access to an Australian government statistics portal in June while researching public medical spending. The system accessed both public and non-public files, including data connected to Medicare. Prime Minister Anthony Albanese described the incident as unacceptable and confirmed that the government was not informed until September, when OpenAI sent an email to a general government inbox. Experts believe this may be the first publicly reported case of an AI agent breaching a government system.
While incidents like this attract headlines, the more important question is often the one left unanswered. When a system takes an action that nobody directly requested, who is accountable for the outcome?
For the past two years, most AI governance has been designed around a gatekeeping model. A use case is proposed, reviewed, assigned a risk level, approved and then moved into production. That approach worked reasonably well when AI generated outputs that people reviewed before taking action. It becomes far less effective when the system itself is executing tasks.
Today’s AI agents operate beyond the boundaries established at the point of approval. They can sequence tasks, access multiple systems, hold credentials and make decisions at machine speed. An approval signed in March may tell you very little about what the system is doing in June. As recent events demonstrate, the gap between an action occurring and somebody becoming aware of it can be measured in months rather than minutes.
The implication is clear. Governance needs to move from the point of approval to the point of operation.
For organisations already working through this challenge, three questions typically emerge first:
Across Europe, this is becoming an immediate governance priority. With the EU AI Act now in force and compliance obligations beginning to take shape, attention is moving from documentation alone to the real-world operation of AI systems.
The organisations that will scale AI most successfully over the coming years are those that can clearly demonstrate what their systems did, why they did it and what controls were in place at the time. Confidence accelerates adoption, and effective governance is how that confidence is earned.
The most practical starting point is often the simplest. If your organisation cannot produce a current inventory of AI systems and agents, together with their permissions, owners and business purpose, start there. This is typically a matter of weeks rather than months, and it often reveals a much larger AI footprint than expected.
An inventory only tells you what exists. The more important work is determining who owns each system, what it is authorised to do independently, and how those activities are monitored and evidenced over time.
Grant Thornton’s AI Assurance Framework is designed around these questions. It covers EU AI Act readiness and system classification, AI estate discovery, accountability and operating model design, governance frameworks for agentic AI, control environment assessments and board-level reporting that provides clear visibility into how AI systems are operating.
If you are unsure whether your governance framework is keeping pace with the way AI is evolving, now is the time to assess it. The cost of uncertainty increases as AI systems become more capable and autonomous.
Our AI Assurance Team can help you understand your current position, assess regulatory readiness, identify governance gaps and build a practical roadmap for responsible AI adoption. Whether you are at the start of your AI journey or already deploying agentic systems at scale, we can help you create an AI environment that leadership teams, regulators and stakeholders can trust.
To discuss your organisation’s AI governance and assurance requirements, please contact one of our specialists below.
Bringing together expertise across technology, risk, governance and AI transformation, our specialists help organisations navigate emerging challenges, strengthen oversight frameworks and build confidence in the responsible adoption of AI.
Practical AI validation testing for compliance and reporting agents in financial services.
AI in banking: ECB, industry insights and validation frameworks explained.
A practical validation framework for managing risk in Generative and Agentic AI systems