Most US banks cannot produce this document.
By the time a human reviews the agent's final output, dozens of autonomous decisions have already executed. Your controls are reviewing ancient history.
Answer five quick yes/no indicators
Signals from the supervisory horizon
"Autonomous AI agents may require novel oversight."
Translation: Ghosts have been confirmed.
Read the Guidance ↗"Generative and agentic AI are not within the scope of this guidance."
Translation: Ghosts are now your problem.
Read the Bulletin ↗"Know Your Agent requirements proposed for financial bots."
Translation: International authorities are also reporting ghost sightings.
Read the IMF Note ↗"First joint statement on frontier AI risks and supervisory expectations."
Translation: The UK has confirmed ghosts crossed the Atlantic.
Read the Statement ↗Identifying internal exposure sectors
Foundational controls for agentic deployments
Every agent in production requires a verifiable, non-human identity — not a shared service account, not a developer's personal token.
Agents operate within defined boundaries. Every external call, every approval chain, every data access is mediated by policy — not trust.
When something happens, you know which agent did it, when, and under what authority. Ambiguity in the audit trail is a regulatory liability.