THE SIGNAL IN ONE SENTENCE
State Bank of India's chairman wants banks to verify AI agents before those systems can move money or make decisions. His proposed checks would identify the agent, confirm the customer approved it, limit what it can do, record every action, and let the bank revoke access.
01
WHAT ACTUALLY CHANGED
On September 10, State Bank of India chairman C S Setty used a familiar banking phrase to name a new problem. Banks have spent decades building Know Your Customer checks for people. As AI systems begin to recommend and eventually execute financial actions, he said banks will also need to know the agent acting inside the transaction.
Setty outlined the proposal at Global Fintech Fest 2026. His Know Your Agent framework would cover an agent's identity, authentication, customer consent, transaction limits, audit trails, and revocation. Those pieces turn a vague promise that an agent is trusted into a control system that can answer six useful questions: what is it, who approved it, how did it authenticate, what may it do, what did it do, and how can it be stopped?
The shift from advice to execution is the hinge. A chatbot that suggests a transfer can be wrong once and wait for a person. An agent with permissions can initiate a chain of actions across accounts and institutions at machine speed. Setty warned that autonomy can spread a single error to customers, counterparties, and financial firms before the usual human review catches up.
He described possible uses across fraud detection, customer identification, anti-money-laundering work, loan appraisal, underwriting, reconciliation, service, and complaint handling. He said SBI already uses AI in areas including customer service, pre-approved personal loans, credit assessment, cash-flow lending, fraud detection, anti-money-laundering monitoring, and early-warning systems. The speech did not say that autonomous agents currently control all of those processes.
Setty also put the Indian deployment problem on the table. He said advanced AI needs affordable models and computing infrastructure if it is going to operate at national scale. For financial inclusion, he pointed to voice-based conversational banking in Indian languages for people who are more comfortable speaking than typing. Access, in other words, is not only permission. It is also language, price, interface, and whether the system works outside the easiest customer segment.
02
WHY THIS MATTERS
An AI agent is not a customer, employee, or ordinary piece of software. It can act for a person while being built by one company, hosted by another, connected through a third, and updated after the customer approved it. A bank therefore needs an identity for the running agent and its owner, version, permissions, and current risk status, not just a friendly product name.
Consent needs to be specific enough to survive contact with money. "Help with my finances" is not permission to empty an account, open credit, trade an asset, or share records. A workable system would bind consent to named accounts, allowed actions, spending ceilings, time windows, counterparties, and escalation rules. The customer should be able to inspect and withdraw that consent without hunting through twelve menus and a prayer.
Transaction limits make mistakes containable. Banks already use payment caps, velocity checks, cooling-off periods, and extra approval for risky activity. Agent permissions can borrow the same logic. A software assistant might pay a recurring electricity bill automatically, require confirmation for a new recipient, and be blocked entirely from borrowing or changing account ownership.
An audit trail is the difference between an explanation and a shrug. Banks will need records of the agent's identity, instructions, tools, data access, intermediate decisions, approvals, and resulting transactions. Those records must be useful to customers, investigators, and courts, not merely an ocean of technical logs that only the vendor can read.
The final control is revocation. Customers and banks need a kill switch that actually closes tokens, sessions, delegated permissions, and queued actions across connected systems. Setty's proposal is not a finished standard, but it identifies the right unit of trust. If software can act like an authorized participant, it should face participant-grade identity, limits, monitoring, and consequences.
03
WHERE IT COULD HELP
- Issue a verifiable identity to every bank-connected agent and software version
- Bind customer consent to specific accounts, actions, limits, recipients, and time periods
- Require step-up human approval for unusual, irreversible, or high-value transactions
- Preserve an intelligible audit trail from instruction through final transaction
- Revoke every token, session, delegated permission, and pending action from one control
KEEP A HAND ON THE WHEEL
Know Your Agent is a proposal from SBI chairman C S Setty, not an enacted Reserve Bank of India rule, a technical standard, or a deployed national system. The speech did not specify who would issue agent identities, how credentials would work across institutions, which actions require human approval, how liability would be divided among customers, banks, model providers, and agent developers, or how customers could challenge an automated decision. The available reporting does not establish performance, security, adoption dates, costs, or independent tests. Current SBI uses of AI should not be read as proof that autonomous agents already execute each listed banking function.
04
TERMS WORTH KEEPING
SOURCES AND VERIFICATION STATUS
This article was written from the materials below. Product claims and dates were checked against those sources on September 10, 2026.
PUBLICATION RECEIPT: Revision 1. Published September 10, 2026.
THE PUBLICATION ENGINE
WANT A SIGNAL OF YOUR OWN?
We build source-grounded publications, private briefings, and editorial systems for organizations with something useful to say.
WORK WITH US