Agentic AI in Financial Services:
Former UBS and SAP Group CIO
Banks run dozens of AI pilots, but almost no AI agents in production, and the gap is in controls, not models. Former UBS Group CIO Oliver Bussmann outlines the key conditions that must be met before agents can go live.
Agentic AI in financial services faces a hard gap in 2026: banks run dozens of pilots, yet almost no agents reach production because an agent operating within a regulated institution needs identity, permissions, audit trails, and a human accountable for its actions. This discussion explores where agentic AI currently adds genuine value in financial services and what conditions must be met before granting an agent write access to critical systems.
Key Points:
- Why AI agents stall between pilot and production in banks, and why controls rather than model quality decide which agents go live.
- The control stack a regulated institution requires before agents can act includes identity verification, permissions, audit trails, and a human responsible for outcomes.
- Where agentic AI is already delivering results in financial services, and how leaders can tell real deployments from demos.
Watch Episode 925 with Oliver Bussmann live on Friday, July 17, 2026, at 1:00 PM ET on CXOTalk. Subscribe for key takeaways from every episode and advance notice of live shows. Join this interactive discussion and ask your questions!
Agentic AI in financial services faces a deployment challenge: banks run dozens of pilots, yet almost no agents operate in production. The gap is in controls, not model capability: an agent operating within a regulated institution needs identity, permissions, audit trails, and human accountability. In Episode 925, Oliver Bussmann, former Group CIO of UBS, explores where agents add value and the conditions that must be met before granting them write access to critical systems.
Bussmann ran technology for UBS when it was the world's largest wealth manager and led the bank's early blockchain work. Today, he advises financial institutions and boards across Europe and writes a weekly executive briefing on agentic AI in finance. This is his third CXOTalk appearance, after conversations on the CIO role in 2014 and on fintech and blockchain in 2016.
What we will cover:
- Why banks have dozens of AI pilots and almost no agents in production
- The controls an agent needs before it can act in a regulated institution: identity, permissions, audit trails, and a human accountable for what it does
- Why agent deployment is a governance question long before it becomes a technology question
- Where agentic AI is delivering in financial services today
- What conditions must be met before an agent gains write access to critical areas
Watch Episode 925 with Oliver Bussmann live on Friday, July 17, 2026, at 1:00 PM ET on CXOTalk. Subscribe for key takeaways from every episode and advance notice of live shows. Join this interactive discussion and ask your questions!
Episode Participants
Oliver Bussmann advises enterprises, top-tier consultancies, and financial services companies looking to stay ahead of the digital disruption curve. He has held influential CXO roles across industries, including at UBS, SAP, Allianz, Deutsche Bank, and IBM.
Michael Krigsman is a globally recognized analyst, strategic advisor, and industry commentator known for his deep expertise in business transformation, innovation, and AI leadership.
In This Episode
Oliver Bussmann: I'm waiting for an incident in the industry. Hallucination is, or some other issues, then your whole trust and reputation can be gone in a few minutes.
Michael Krigsman: Banks run on trust, but AI agents are not there yet. Oliver Bussmann is the former group CIO of UBS and advises banks across Europe.
The technology works, the controls lag
Oliver Bussmann: Roughly 50% of financial institution already using agents in an environment. I think most of them are proof of concept. I would say most of the banks are exploring agent in the software development. And so I think we are seeing a big change from, I would say, co-pilot work with using agentic AI to autopilot solution with using agent in different function from back office to IT to marketing, et cetera. So it's a big change, especially, I would say, the last couple of months.
Michael Krigsman: So would you say that banks are actually embracing agents, or is it still in practice, or is it still kind of theoretical, you know, it seems like a good idea?
Oliver Bussmann: It's taking time because, you know, I'm also working in the non-regulated business with software companies as board chairs, et cetera, and the adaption of agentic AI is much faster because the financial service industry is a regulated industry. And then every time if you implement a new technology like, you know, a couple of years, software as a service, cloud, or blockchain, you have to adjust your risk method, your control environment, your processes.
That means the regulator is expecting you that you make sure that these new technologies are used in, you know, following the laws, regulation, and policies. And so that means we will see a lot of testing, proof of concept, but huge production cases always takes time to make sure everything is bulletproof.
Michael Krigsman: Are the obstacles technology or compliance and regulatory issues or talent? Mm-hmm.
Oliver Bussmann: The technology is there. I can, you know, working with software companies that are going through the transformation, the change the last, I would say 5 months after, you know, the stock market are, you know, lowering down the valuation of software businesses, there is a really huge change on these businesses to embrace agentic AI, meaning vibe coding or the next generation of software development. And we see a huge change in that non-regulated business from co-piloting and doing software development with 20, 40% productivity gain to factor 2, 4 X more output.
So I would say regulated institutions see this, you know, huge advantages. You know, they're seeing this from a software development perspective, but that requires that, you know, procedures, controls, risk frameworks, policy has to be adjusted. And especially if you work out of Europe, European regulation and laws are much more restricted than the US one, so that puts even more effort for the financial institution. So I would say everybody is working on that. And for me, the best example is that using agent is also from a cybersecurity perspective.
Now, with Mythos being available, you know, you use those kind of agent to scan your entire software libraries and landscapes in a couple of days and try to understand any potential issues. So I would say very selective, I think in certain non-customer facing areas even more, but adoption has to follow first that these kind of control and risk frameworks are in place to make sure that it's safe and in compliant with regulation.
Michael Krigsman: In other words, the technology works. The technology is in place. People have it available, but there needs to be an alignment with the existing compliance and regulatory-
Oliver Bussmann: Yeah
Michael Krigsman: environment, and people are trying to figure out how to make the technology work within that environment.
Oliver Bussmann: Absolutely. Absolutely. The. No, look, I think we have to distinguish 2 things. One is making sure that, you know, in Europe there's the European AI, that you have an inventory of all your AI cases, including agent cases, that depending on the risk classification of the use cases, you have to put more human controls and testing in place. And so that has to be bulletproof. The second topic is also what I see from a non-regulated software environment.
You have to still put some guardrails, making sure that these agents are acting, you know, in the same consistent, traceable, auditable way, that, if you work with the agent that the output is in the same design principles, coding principles, et cetera. So there is a lot of effort also making sure that, you know, these kind of agent produce the expected outcome and so that requires also a lot of governance controls oversight.
Michael Krigsman: Folks, you can ask your questions. If you are watching on LinkedIn, just pop your questions into the chat. If you're watching on Twitter, X, use the hashtag CXOTalk. Take advantage of this opportunity to ask Oliver Bussmann pretty much whatever you want. We have a simple and interesting question on LinkedIn from Vaibhav Mandrawadker, who says, "How are the guardrails being configured?"
Guardrails first, then measure the gains
Oliver Bussmann: If I look from a typical software company perspective, I think the engineering team and head of engineering is, you know, the job description is changing from, you know, actually doing the software coding, et cetera, into defining how these agent are being defined and set up, and also that there's sufficient testing and oversight in place.
So the role of the engineering team is changing rapidly, and their major role is making sure there's high quality, according to these expectation from a compliance security point of view, and making sure that this, almost like the production factory, is producing good quality outcome as expected.
Michael Krigsman: He follows up with a question, another really great one. He says, "What are the course core KPIs that have helped". He asked about UBS, but just banks in general. "What are the core KPIs that help banks after implementing agentic AI?"
Oliver Bussmann: You know, if I look deeper into the software development, 'cause that's something that I would say from agentic AI perspective is the most advanced one, is. And that was a topic also during my time at UBS, how to measure developer productivity, efficiency, code quality. I have to say, there are now tools over the last 10, 13 years in place that measure this kind of productivity, quality, and security of this code, and that's now been adjusted also for the agentic AI environment.
So whatever you do, and it's pretty standard already in financial service, baselining the productivity is absolute necessary. And then you can bulletproof is the way of automation that you have in place, is it really factor 2 or 3 or 4 that everybody is talking about? Is it real? Because that's a proof point that I would say is whatever you can do, measure, and that tool's now in place, do it, and it gives you much more confidence that this is really a game changer.
Michael Krigsman: So have your baseline set up in advance-
Oliver Bussmann: Yeah
Michael Krigsman: so that when you implement agentic AI, you can actually have a point of comparison.
Oliver Bussmann: Yeah, absolutely. You need that.
Michael Krigsman: Give us some examples of some of these baseline measurements.
Oliver Bussmann: The baseline is how many lines of code you develop, their quality KPIs, how the code is being structured, how is this being in line with the coding standards, et cetera. So these kind of KPIs, they're very sophisticated, and these tools that are measuring that, they are working on that kind of KPIs over the last 10 years. So it's, I would say it's pretty standard already. And that's the same now. You have to apply this not only for a human development.
You have to measure also how an agent, a machine is now producing this kind of quality of code.
How regulation shapes what agents may do
Michael Krigsman: And this is from Arsalan Khan, who is a longtime listener. And Oliver, sounds like you remember him from your last appearances on CXOTalk.
Oliver Bussmann: Yeah, it's 10 years already, you know? It's a fantastic journey I would say now. Thank you so much for having me, by the way.
Michael Krigsman: Well, thank you for coming back. And Arsalan Khan says, "Should we deregulate banking for the AI area AI era?" So maybe you can talk about this issue of regulation and the restrictions and what can be relaxed or not relaxed. Mm-hmm.
Oliver Bussmann: If you're a global bank like UBS, you know, with a global operating model, that means you try to utilize as much as possible the same application, the same infrastructure, et cetera, regulation drives fragmentation. So you have to demonstrate that in each jurisdiction that you follow the policies, regulation laws, best practices, et cetera, that makes production and work complex. And what we see right now, if I look from a AI perspective, the European regulation is very restrictive, very risk-based classification, controls. By the way, it's not only for a financial institution.
Also normal corporation has to follow significant fines. And then we see the opposite trend in the US, for example, that assume that, you know, companies will take care about the safety audit, et cetera, and so that's less restricted and the administrative overhead to do that is significant lower. So that's something if you're running a global institution, that is something that you have to take into account.
Michael Krigsman: And this is on LinkedIn from Rafal Szymanowicz, and he says, "Oliver, when giving AI agents write access to core ledgers like SAP S/4HANA, how should boards combat automation bias to keep humans truly in command?"
Oliver Bussmann: If you write into ledgers, I think that has to be tested, has to be traceability, audit logs, et cetera, to make sure if there's an incident, that you can roll back and figure out what happened. And I think there will be also audit agents running. So the audit function going forward is not only that, you know, you bring in topic by topic an audit team and go deeper and see if there's everything computed in the right way.
I think the future is also that your oversight in, you know, in banking called second line of defense or third line of defense, you know, will be part of the production. So that's a good. And audit firms like PwC already and Deloitte, they're bringing their own agent now into auditing the end reporting also.
So you see there's a change that only that, you know, you bring an agent in to produce, also then the controls will be also more automated and so that you can act immediately if there's something is if there's a major deviation point of view.
Michael Krigsman: But to what extent are banks able to be hands-off on their agents and trust that agentic audit report as opposed to require a manual or human review? Because we all know the problem with generative AI and agents is they can make stuff up.
Oliver Bussmann: That's a point that I mentioned before, is the engineering team has to put guardrails into these agents, making sure that the design standards are being followed, certain coding standards, certain testing, each time if you develop a new function that certain test cases are built and going through. So I would say the engineering function is changing to really guardrails, quality assurance, et cetera. Then you have, again, also the other function risk and audit constantly monitoring the environment, and there will be always a supervisor, human supervisor in the loop.
So the discussion going forward will be how much you, you know, how many agent you manage as a department head in the future, in respect to how many people you're managing. So the discussion is already changing, from that perspective that still, as a manager, I need supervision not only about my own people, also for the agent in my working environment.
Michael Krigsman: I know Rivian uses AI agents as part of their financial processes.
Oliver Bussmann: Yeah.
Michael Krigsman: They have very specific points of review, so the human in the loop is very explicitly and very carefully built into the process.
Oliver Bussmann: You have to define exception or topics, workflows that, you know, run into a problem and cannot be fixed through AI. That usually triggers, you know, from a comparable perspective. You can, you know, scan invoices and map them, you know, that's usually 90, 95%. And then AI try to bring it to 100%, but there will still be a percentage or 2 out there that you need human oversight and controls perspective. And I think everybody's now tried to calibrate that.
And so that's something that I would say in the non-regulated industry is easier. In a regulated industry that the regulator usually says, you know, there's a black and white, no? So you. There are rules, and with the agentic AI, you know, there will be a situation that certain rules, because the environment has changed, will apply differently, and that's something the, at least the European regulators are a little bit afraid of that, to move away from a very rules-based workflows to bring other parameters into the workflow that drives a different outcome.
Michael Krigsman: Well, the idea of handing essentially regulation over to the firms themselves-
Oliver Bussmann: Yeah
Michael Krigsman: is potentially problematic for obvious reasons.
Oliver Bussmann: Absolutely. Absolutely.
Michael Krigsman: We have another interesting question, and I encourage you guys, ask your questions. If you're watching on LinkedIn, pop your questions into the chat. If you're watching on Twitter or X, use the hashtag CXOTalk and @mkrigsman me directly as well. And this is from Chris Petersen, and he says, "In the financial realm, is agentic AI built on LLMs and GPTs or embracing other forms of AI to get the transparency and explainability that auditors demand?"
Machine learning and high-risk decisions
Oliver Bussmann: I would say it's not only limited to large language models, agentic, or to. I would say machine learning is still a big portion of a lot of functionality in AML, anti-money laundering, or some analytic capabilities. I would say I would not exclude that. So even I would say the combination with blockchain, everybody knows that I was pretty, I'm still pretty active in the blockchain, DLT community, is a pretty good way because then you have a bulletproof lock of your decisions, that you can't manipulate.
And so I would not exclude any other technology, being part of a much higher level of automation and driving better outcomes. So definitely I would not exclude that.
Michael Krigsman: We have another interesting and short question, a great question from Vaibhav Mandrawadker. And he says, "Is there any specific scenario or use case where agentic AI is not suited to a regulated industry?"
Oliver Bussmann: I would say the regulator, if you ask me, you know, in front, sitting in front of the regulator, everything that could be biased into a credit decision or a security oversight, it means monitoring people on the street, that's something the regulators, let's say from a European perspective, I classify this as a high-risk topic, is something that I would be careful. Because then you have to put in a lot of effort to make sure that there is not misuse of this kind of information or decisions, et cetera.
So I would say I like the classification the way how European governments are looking at these cases, and if they're high-risk cases and these are the most important one, credit decision on consumer, et cetera, that, you know, goes beyond information that is usually available and drives decision, that's something I would be careful. Yeah.
Michael Krigsman: It sounds from what you're saying that the regulators are very concerned about the judgment decisions-
Oliver Bussmann: Yeah
Michael Krigsman: made by a AI as opposed to the AI making mechanical mistakes.
Oliver Bussmann: Yeah. Yeah, absolutely. Because at the end, they are also very keen of, you know, from a European perspective, keen of consumer protection, client protection, et cetera, making sure that these kind of technologies are not driving a disadvantage for consumer from that perspective. So that's something I would also. That angle is maybe not so important in other jurisdiction.
Trust is what a bank cannot lose
Michael Krigsman: I'm halting on this particular point because most technical technology discussions around agentic AI focus on the mechanical aspects, the hallucinations and getting things- making things up.
Oliver Bussmann: Yeah.
Michael Krigsman: Whereas in this instance, you're looking at the higher level-
Oliver Bussmann: Yeah.
Michael Krigsman: set of judgment issues.
Oliver Bussmann: Yeah, yeah.
Michael Krigsman: The real
Oliver Bussmann: It's both. I think the independent how risky AI use case is, the biggest value that, you know, a bank has to take care is trust. So today, if you act as a financial institution, whatever you provide, produce has to be, you know, according to the highest level of trust, because I as a bank customer have to rely on the bank that they're processing all my business in the right way and it's accurate, it's traceable, it's auditable, et cetera.
And if, you know, I'm waiting for an incident in the industry that hallucination is, or some other issues that drives to an incident, then your whole trust and reputation can be gone in a few minutes. Now, you saw that KPMG a couple of weeks ago was under pressure. They put a research report out there and about usage of AI in financial services, and there was a lot of hallucination in there, wrong data and, you know, financial institution had to push back on that.
So that has an impact on trust, on, in confidence can I use this kind of services? Now, so that's something I would say, you know, if you look at big crisis in the bank industry, bank run is based on people, customers are losing trust.
And so that's the worst-case scenario that you as a bank has to be super careful that whatever you do, embracing emerging techniques like AI, making sure is there still that the trusted relationship between you and your customers are still intact and will be not jeopardized, that's just to maximize certain profits, for example.
AI infrastructure and cross-model validation
Michael Krigsman: We have another question now from Arsalan Khan, who's on Twitter, who says, "Are banks creating their own AI infrastructure, buying chips and so forth? Or are they just using Google and others for AI services?"
Oliver Bussmann: It's only one bank, JP Morgan, announced that they are also building their own infrastructure with chip provider than not the typical NVIDIA, et cetera. But that's pretty, I would say it's more an exemption, I think, because you need significant investments, people, going into this hardware topic, and only large bank with, you know, JP Morgan. US banks are usually of, you know, among above $10 billion of budget, IT budget per year. So there is scale, et cetera.
But that's not the normal spend level for normal national banks, so I would say that's more an exception and more tech players with the volume and scale can do that.
Michael Krigsman: This is from Alexander Yin on LinkedIn who says, "What is your confidence level that agents in the same LLM, say Claude, for example, or ChatGPT, would be independent enough to quality control their own work by another agent in the same model? Or do you need to use agents from different companies? Or does it make no difference?"
Oliver Bussmann: If I apply, you know, my experiences, in my day-to-day work life, using different large language models, cross-model validation for super important task is mandatory because it gives you a much higher confidence that whatever you produce is correct and validated, no? The, for again, important outputs is always human checks and reviews is like the important research report that we talk about KPMG is mandatory. In production, yes, absolutely. If you automate more, you use different models or teams that operates a agent in a totally different way, like the auditors or audit firms are doing.
Agents are reshaping technology careers
Michael Krigsman: And this is from Marijan N. who says, "If you need to make a prediction, how will entry-level roles change as agentic AI advances?" So the impact of agentic AI on entry-level jobs.
Oliver Bussmann: I'm tech advisory board member of a non-profit organization that helping over 100,000 students to get the right jobs, et cetera. And we see in the last couple of years that demand for junior software engineers are dropping, you know, the job advertisement are down by 40%. What we are seeing still is that tech companies hiring juniors greater rates in, like I think Salesforce announced that they are still hiring even more than last year.
The difference that what I see is they're looking for graduates with AI background, and they're using this for their new AI project to automate certain business function. I see in high tech firms and also now in banking, this kind of centralized FDE, forward deployed engineer model that goes into business department, understand the breakdowns, the process improvements, and use these kind of agentic AI models to automate this as much as possible.
And so they need the juniors to work on that and then build expertise within the first 3 to 5 years to become a supervisor of this kind of topic. So you can't stop hiring juniors because at the end, someday we need them as a very senior person. On the other side, the work, project work of financial institution and high tech firms in transforming business requires employees with really deep understanding about AI models and the way our AI is working, so that's something I would say is an opportunity.
On the other side, I have to say there is fear out there, if you talk to the younger generation, to my family members, et cetera, they're saying, "You know, I'm studying, and what will be my future job be?" My message is, "Don't be afraid. Be a first mover. Spend time with these models. Apply this to the maximum, and your expertise will be in high demand." The same also for the older generation. So people, you know, at the end of their career or they're saying, "Oh, I don't have to learn that."
It's almost like I'm comparing this like 10 years ago and saying, "I'm not using the iPhone. This is something that maybe is not so important." So that's something I would say is learning is a lifelong experience and must do. And it, so don't be afraid that that gives, open up to more opportunity. But definitely job description are changing, and changing mean now we have different kinds of jobs.
If I look at the software companies that I'm supporting, we have a discussion now what's the role of the CTO, head of engineering, head of product management and sales because work is being shifted from the engine room into more the pre-sales organization. So it's natural that through technology, you know, and we saw this, you know, Michael, we are in the business for so many years, it's changing and, you know, it requires an open mindset and the willingness to learn.
Michael Krigsman: If you're a mid-level programmer, software developer inside a large organization, isn't it undeniably true that your job is going away because AI tools can do software programming, so development fabulously well?
Oliver Bussmann: First of all, there is a need for really good engineers to making sure that these agent are be defined in a professional way and maintained and expanded. That is definitely way. Second topic is what I see is we are moving into, you know, we've been through this from a very standardized SaaS model into more, I would say, AI customized, a custom SaaS model. So your engineer capability will be required in more on-site customer projects to understand the problem and define pro-proms and input for then your agent product factory.
So demand for software engineer then on site with, in your business environment, will be higher. So message is, I think, if I look at studies saying the amount of certain work that's very traditional will come down, will be compressed, but there's more demand for digitalization and customization that we couldn't do because engineering was always the bottleneck, the coding bottleneck, that now is going more to customer facing, understanding the problem, and developing new functionality. Instead of months, we're talking about days now.
That's the game changer that everybody's now trying to figure out how to do that. And this kind of change will lead to more business, and engineers will then be more project driven than working on core software functionality.
Michael Krigsman: Well, there's no doubt that the key here is having an understanding of the technology so that you can manage that technology-
Oliver Bussmann: Yeah.
Michael Krigsman: and most importantly, having a deep understanding of the business and the workflows and what your customers actually care about so that you can create technologies and guide agents to actually solve the most important problems.
Oliver Bussmann: At the end, we will go much deeper in the vertical topic, you know, that you need not only the software also domain expertise to understand problems and fix them. And again, this will open up more opportunities. So I'm personally, I'm not afraid of this kind of change because it leads to more chances to more businesses and like now who has moved my cheese? Now the cheese is moving right now. You have to figure out where it is now. So that's the best way to describe that.
Michael Krigsman: I'm not quite as optimistic as you because of everything you're saying, of course, is accurate, but I also understand, as you do very well, the difficulty that we humans have changing our roles and learning new skills.
Oliver Bussmann: Based on my journey, my learning curve over the last 30. I'm in the business over 35 years to be not afraid to take something new on. So my risk profile is maybe different because I lived in different countries, different companies. I've been through a lot of new innovation cycles, and my learning is if you're the front runner in testing this and utilize that, it's eye-opening, it's fun, it's motivating, and that opens new doors. No?
So if I share with you the way I'm also using the technology in my own business, it's eye-opening. So the productivity gains and work and the quality of work that I'm now working with my companies, with my firms, et cetera, if I compare this with a year ago, has changed so much that now if I look at office productivity, we used to build PowerPoint and reports, et cetera. You know, it's sometimes you question the value of that. That's now possible in a couple of minutes or hours than days now.
And if I look at the amount of quality work that I'm now able to produce. So that's an experience that I would say helps me to increase my confidence that if you do this in the right way, we have the right graduates in there, and the way how you now use, know what technology is best for your different use cases, it's really, it's fun. And so that's something that I want to encourage everybody to don't miss that opportunity.
Risk classification sets the autonomy line
Michael Krigsman: So this is from Mohamed Dasougi, and he says, "What is the impact of autonomous agents with human in the loop?" So maybe just describe that interaction briefly.
Oliver Bussmann: Yeah, the interaction with autonomous is almost like you run a business process almost one hundred percent through those agent working as defined. And human in the loop is, you know, if there's exceptions or critical cases that need still intervention and then also monitoring the overall outcome. Is it in line with defined KPIs, et cetera? So that's, again, the split is between human and agent and the numbers of agent per human, my experience is depending on the criticality of business processes, regulatory requirements, et cetera. But that's something that, you know, will change our day-to-day work.
Michael Krigsman: This is from Yannick Ishimwe, and he says, "What is the real threshold that separates an agent that a bank will trust to advise from one it will trust to execute? And who should own that decision?"
Oliver Bussmann: It really depends on how these use cases been classified as a risk that could lead to wrong outcome impacting customers, impacting businesses. And that drives- this classification drives the level of cross-model validation, human verification, cross checks, et cetera. So that's the logic that I see in my board discussion is, you know, is the governance in place from a inventory, from a risk classification, and is the appropriate, depending on the risk qualification, controls, trust models, human oversight, measurement in place to make sure that there is no deviation?
The consulting model is under pressure
Michael Krigsman: This is from Reza Satari, who says, "What would it take for a regulated bank to accept transformation deliverables, target architectures, fit to standard decisions produced by AI agents rather than an army of consultants? Is that a model risk question, an audit trail question, or a culture question?" And I'll just add the commentary that Reza has just brought the entire consulting industry under a microscope with this.
Oliver Bussmann: It's an ongoing discussion, is, you know, as financial institution are going through their learning of how these agentic AI tools are being used, and then the productivity boost and the quality improvement, if you have the right. Again, if you have the right guardrails in way. So I think the line between external and internal support is shifting. That's the reason why, you know, software companies and consulting firms, like an Accenture, et cetera, they have to change their business model.
So business model means they have to ramp up also the way how the AI tool's being utilized, being implemented, also the training of those consultant, et cetera, because the expectation level now, if you've been through that learning curve on the customer side, the expectation level is much higher, and you do provide services much faster for a reduced cost. You see this already in the legal industry.
Legal industry is now using large language models totally customized for the jurisdiction, so the amount of work to draft new contracts, review them, is coming down. And so the customers are not willing to pay any more $5,000 per day. So. And that changed the whole pricing, valuation, or outcome discussion. So I would say absolutely right.
It really depends on how quickly you can ramp up your expertise and tools, utilize enough tools inside internally, and then you see if somebody else outside is still up to that expectation level, which is much higher than currently.
Michael Krigsman: And of course, the major consulting companies are and have invested billions of dollars in AI training of and tool development because they know their business is shifting rapidly.
Oliver Bussmann: You see consulting firms also, their valuation is down this year, 40 and more percent, no? So I think there is a cross-industry change going on, and that means there will be winners, there will be losers, and the companies that embracing this have a good chance to survive.
Customer agents need verified digital identity
Michael Krigsman: We have another really interesting question from Dr. Alexander Bockelmann, who is the group chief technology officer of Helvetia Baloise Group and has been a guest on CXOTalk,
Oliver Bussmann: and-
Michael Krigsman: Yep, and
Oliver Bussmann: we worked together, so, at Allianz, so yeah, great to hear.
Michael Krigsman: Oh, I didn't realize that. Oh,
Oliver Bussmann: okay. Yeah, yeah, oh.
Michael Krigsman: So it's a small world. And Alexander says, "Oliver, switching to the customer side of the topic, do you think or by when do you think will customers use their digital twin or agentic AI assistant to execute their banking tasks?"
Oliver Bussmann: Yeah.
Michael Krigsman: "And by when will the business model include such things as machine-to-machine banking?"
Oliver Bussmann: If I look at the agent-to-agent use cases, I think the agentic payment topic that Visa and Mastercard working is maybe the first one. And here we have exactly the same topic to making sure that the agent is really Alexander Bockelmann and not somebody else and making sure that this transaction that been initiated are legitimate and not been fake. And that's something everybody's working on that. Do I think we are right now ready for prime time?
I'm not sure because at the end it requires also that there is a digital identity for Alexander that everybody can verify. And I know that the European Commission is working on certain governments on those kind of digital identities, and but that has to be in place that a digital twin is verified that's you and not somebody else. And everybody's working on that. Hopefully this will accelerate because without that verification, it will be hard to do mass volume of transaction for agent-to-agent transactions.
Breaking down financial crime silos
Michael Krigsman: This is from Jörg Mertens, who is a CFO, and he says, "Oliver, from your perspective, which AI-driven business models are emerging in financial crime compliance? For example, shared KYC/AML utilities or compliance as a service. Could these models turn compliance from a cost center into a revenue-generating capability?"
Oliver Bussmann: The compliance models, utility models, now to do KYC, know your clients as a utility, it's a known issue in the industry for the last 10, 15 years. And most of these utility setups failed because there was not enough critical mass sponsoring this kind of development. If we then move on into more decentralized work that, you know, an agent could, you know, reach out to another bank with the right identity to validate this, maybe that's the chance to do that because these kind of centralized utility models is hard to establish.
So overall, I would say if you look at the value chain of financial crime, I think agentic AI will help us because these financial crime categories are in silos. You know, you have a client onboarding, client refresh, transaction monitoring, sanctioning, et cetera.
These are usually specialized application and data silos, and agent, you know, with AI, you can connect them much better to a 360 risk counterpart view, and that's exactly I think the industry is going, is if there's innovation, one trigger that maybe will drive a refresh of a client data point of view. So I would say the technology is really a game changer for the financial crime fraud topic, and we see already companies working on this kind of, embedding this kind of technologies.
Coding is not the bottleneck
Michael Krigsman: And on the subject of technology, Alexander Bockelmann comes back and he says, "The counterargument is coding is not the bottleneck, it is the organizational change required-
Oliver Bussmann: Yeah
Michael Krigsman: for agentic process redesign and adoption."
Oliver Bussmann: Absolutely is spot on because again, if you have set up your right agent, coding is not the problem. It's then you move more to the business analysts and business people in the business department that, you know, has to, you know, you have to train and bring up to speed how to utilize, to analyze processes and breakdowns and able to formulate problems that, you know, leads to software development at the end.
So I would say, as I said, from a software development perspective, we are shifting the focus into understanding the business, business functionality, business analysts, and then also product manager bringing this kind of requirements into the product. So that shift means we will have much more focus on people, front office, business analysts, product manager dealing with the issue instead of, you know, that the engineering team is becoming the bottleneck for these kind of changes.
And that again, it's we are coming back to job definition, allocation of headcounts to this kind of value chain change.
Proving control to regulators and boards
Michael Krigsman: This is from LogiRoot Runtime AI Governance with verifiable, and I can't read the rest because- Okay verifiable audit evidence.
Oliver Bussmann: Yeah.
Michael Krigsman: That's his name. Okay. And LogiRoot Runtime says, "When a regulator or a court asks a bank to prove this agent did exactly what you say it did and prove nobody touched the record, does today's tooling actually clear that bar? Or are we one incident away from learning that having logs and having proof are not the same thing?"
Oliver Bussmann: You know, it's independent of the technology. You know, certain governments say, you know, whatever technology you're using, make sure there's traceability, auditability there, and that you can verify the transaction, and then you can see if there's any misstep from that perspective. You can go to the next level of maturity saying, "You know, I'm using blockchain that nobody can even correct transaction or information past that production time." So I would say that's not a specific agent topic.
I think we always have to prove that, you know, these kind of businesses are falling according to the standards and rules of the local jurisdiction, and you need that evidence in place.
Michael Krigsman: And this is again from Jörg Mertens, and I'm taking this because I like questions from CFOs, and his question is something I was going to be asking you anyways.
Oliver Bussmann: Okay.
Michael Krigsman: And he says, "Oliver, from your perspective as a supervisory board member, how has AI changed the way you exercise oversight?"
Oliver Bussmann: I think the. It has changed. Number one, I think the, if I look at financial institution that I'm. In general, I would say the board agenda focus has shifted the last couple of years into much more operational risk. Operational risk is most of them is using of technology and operations for the day-to-day banking.
And that means, you know, with the new technology, board members, you know, first of all have to be up to speed, you know, what does it mean using AI and what are the risks, the limitation and the way how there's been oversight, et cetera.
And their role is making sure, you know, if I talk to the ECB as my regulator, they're telling me, "Make sure that, you know, for this kind of topic, the existing regulation like the European AI Act, the DORA jurisdiction, how to classify vendors and issues, is being followed for this kind of issue." So, you know, as a supervising board member, what you do is you ask questions, you know, how's the setup, how's the governance?
Or suppose show me evidence that this is in place, that we have the right safeguards in place to utilize this kind of new emerging technology.
AI native banks still need people
Michael Krigsman: This one is from Ricardo Wehrhahn, and he says, "Oliver, in the past, new technology has enabled the creation of digital native banks like Revolut. Do you expect AI native banks to emerge, and how would they look like?"
Oliver Bussmann: Digital native banks are also embracing, like Revolut and other banks, this kind of technology from automating processes also are changing the engagement between customers and the bank. Do I see new software companies calling AI agent software out there and saying, "We have 200 agent"? I see this too. Do I think over time there will be an agent-based bank out there? Yes. But what I learned over the last 35 years is clients love to talk to a person, to human person.
So I don't think that we will have a fully automated agent-based bank out there without any human-to-human interface.
Michael Krigsman: And just the trust issue of do. Are you really going to trust-
Oliver Bussmann: Yeah.
Michael Krigsman: AI agents? I mean, eventually maybe, but we're not there yet. We're not-
Oliver Bussmann: we're nowhere
Michael Krigsman: close.
Oliver Bussmann: And Michael, that's the experience of the last 15 years with these robot advisor. We thought about, you know, everybody is, you know, going online, try to analyze their financial situation, and you get a recommendation, and you execute to reshuffle your $100,000, $150,000 portfolio. That not really. People like to talk to a banker at the end, say, you know, "Is it a good decision?" Then usually you see this kind of execution.
Michael Krigsman: You know, it wasn't too long ago where if you had what appeared to be an error on a bill, for example, from a utility company or whatever, people would say, "Oh, the computer made a mistake."
Oliver Bussmann: Mm-hmm.
Michael Krigsman: We don't say that too much now, but the reality is we don't. We don't trust computers, not when it comes to issues that really matter that seem to be going against what we want.
Oliver Bussmann: Exactly, and that's something I think we always have to think about, the human interface. Now, there will be wealth management, private bankers, advisors still in the loop with the client, but the way this financial advisor will be supported will be much more flexible and customized that today is more standardized and limited.
Michael Krigsman: Important question from Arsalan Khan. Really fast, please. With so much use of AI, what can consumers do to protect themselves from hallucinations?
Oliver Bussmann: From a consumer perspective, my advice is always cross-model checks. So whatever I do, and depending on the criticality, I use different models to verify that, and that's always reducing the risk of any misinformation, et cetera. And then my personal last check too. So don't forget to read important information outcomes that you want to share, making sure that everything is correct.
Agents in production within a year
Michael Krigsman: And the last question, a year from now, are banks running agents in production at scale, or are we still having this conversation about all the obstacles and why we can't do it, and why it's a good idea, and we know it's a good idea, but it's, we can't really do it?
Oliver Bussmann: I'm very optimistic that we'll see a lot of agents across, you know, all function in production with the bank because the upside, the productivity gains and the quality improvements are significant. As I said, the Copilot area is 10, 20, 30% improvement. Here we're talking about one, two, 3x in certain use cases. So if you have a front runner of looking at your competition, and if that institution is achieving that, has huge impact on performance, cost, cost income ratios, et cetera. That's something that the peer pressure will even drive more adoption.
Michael Krigsman: Okay. Oliver Bussmann is the former group CIO of UBS. He was the former CIO of SAP many years ago, which is when I first met Oliver, and he now advises banks across Europe. Oliver, thank you so much for taking your time to be with us today. I'm very grateful to. Everybody, thank you for watching, especially you folks who ask such great questions. Before you go, number one, connect with both Oliver and me on LinkedIn. We love that. And number 2, subscribe to the CXOTalk newsletter. We have just.
I always say this and it's really true, we have extraordinary shows with amazing people coming up, and we want you to join us and participate. Thank you so much, everybody, and I hope you have a great day, and we'll see you next time.

