The card warm-up looks like a person’s day. A US$4 purchase at a Singapore coffee chain. An EZ-Link top-up. A small digital subscription. None of it trips a fraud rule, and none of it is meant to. By 3 AM, the same card has moved nearly US$50,000 through three e-wallets across two jurisdictions. The cardholder slept through it.
Every large bank in Southeast Asia now runs on software that makes real decisions, often with no person in the loop. Agents approve credit, decline transactions, assemble money-laundering profiles and, increasingly, move funds. Most went live in the past two years, and the results have been good enough that the pace of adoption is unlikely to slow. However, if you ask the people running these institutions what a given agent does, where it sits, and who owns it, the answers are often worryingly vague, given the immense access these agents possess.
This is simply the next stage of a fast and largely successful roll-out, the point where deployment has to be matched by governance. Boards and regulators have understandably spent the past year focused on AI pointed at the bank from the outside. The opportunity many are still getting to is the AI that the bank has already brought on board.
The new regulatory standard for AI
In early May, the Monetary Authority of Singapore brought together the chief executives of the country’s largest banks to discuss AI-enabled cyber risk. The Senior Minister of State for Digital Development was direct: fully autonomous agents running attacks end-to-end are a question of when, not if. In early June, GovTech followed with an AI Agent Registry to log and monitor autonomous assistants. The message underneath is one that technology leaders should consider. Regulators now treat an autonomous agent as an actor in the system, with an identity that must be recorded and monitored.
Few banks can do that for their own agents yet because internal deployment has moved faster than the register of what exists. Copilots, retrieval systems wired into core data, and automation that reaches into payments have mostly been stood up by capable teams under pressure to ship, and some of it has been stood up quietly, outside the security function’s line of sight. Shadow agents are now common in large banks rather than exceptional. Prompt an internal assistant correctly, and it will recite the credit policy it was trained on. Most of this capability did not exist 18 months ago, so the work of mapping it is genuinely new.
When traditional controls fail
Several of the controls institutions still rely on are also nearing the end of their useful lives. Selfie liveness, SMS one-time passwords, and quarterly model refreshes were designed for a slower adversary. Synthetic faces now pass many commercial liveness checks in seconds, and the tools to make them are easy to find. SIM-swapping has turned the OTP into a step that attackers route around. And a risk model retrained four times a year will, by design, sit behind systems that adapt continuously, since every block it issues also tells whoever is probing it where the boundary sits. None of this is a failure of the original controls so much as a sign of how quickly the ground has moved.
External capabilities are advancing just as quickly. Frontier models that can locate and chain software vulnerabilities at an expert level have already drawn close attention from regulators in Singapore and Frankfurt. The point is simply that the same class of technology a bank is deploying internally is also available to the people testing its defences, which is all the more reason to know your own agents well.
A three-step governance framework
For the technology leaders who own this, the work is concrete and achievable. Three shifts matter more than the rest, and each one makes it easier to keep deploying.
Treat agents as identities. Every agent should have a named human owner, a written scope, an audit trail, and a kill switch, registered the way the bank registers an employee or a service account. An agent operating outside that framework is not a productivity gain. It is an unmanaged account with privileged access, and it should be found and brought inside the perimeter or switched off.
Move verification from the front door to the whole session. Selfie liveness answers a question that attackers solved years ago. The useful question is behavioural and continuous: Does the intent expressed across a session match the account it claims, at every step instead of only at login? That shift also happens to be where much of the region’s fraud signal now resides.
Match the cadence of defence to the cadence of attack. A quarterly retraining cycle is an operations decision when the systems on the other side adapt in real time. Continuous evaluation, monitoring for drift and adversarial behaviour, and the ability to roll back quickly belong in the same tier as any other critical production system.
None of this argues for slowing deployment. The region’s financial inclusion gap is wide, and the productivity case for these systems is real. It argues for managing them properly. The MAS FEAT principles — covering fairness, ethics, accountability, and transparency — remain the right frame, and putting the conversation in front of chief executives rather than only their technology deputies was the right instinct. But principles only bind if someone can answer basic operational questions about each agent in production.
Those questions are not too out there. Who owns this agent? What is it allowed to do? How would we know if it failed, and could we tell a failure apart from an attack? Can we turn it off without taking down something we need? Outperforming a human predecessor on a single metric, the benchmark many of these deployments were sold on, says nothing about any of them.
Singapore’s response to the external threat has shown that governance works best when regulators, institutions and technologists move together. The agentic AI already making credit, fraud and compliance decisions deserves the same coordination, and the banks that get there first will be the ones that can keep scaling these systems with confidence. The goal is to clearly say what each of them is doing and to keep the option of stepping in.



