The Bank of England is reviewing whether existing financial regulations can adequately cover the rapid deployment of agentic AI — autonomous systems that can make decisions and execute tasks without direct human instruction — in payments, trading, cybersecurity, and operational functions.

Deputy Governor Sarah Breeden delivered the stark assessment at the European Central Bank Forum on central banking in Portugal, warning that current frameworks "were not built to contemplate autonomous agents" operating across critical financial infrastructure.

"Relying on human oversight for every action by these systems is unlikely to be practical," Breeden said, as she outlined the central bank's concerns about the gap between technological capability and regulatory preparedness.

Agentic AI differs fundamentally from traditional automated trading systems. While conventional algorithms follow pre-programmed rules, agentic systems can pursue objectives, chain together sequences of actions at machine speed, and adapt their approach based on changing conditions — all with significantly less direct human supervision.

A 2026 Cambridge Centre for Alternative Finance report cited by Breeden found that 81% of surveyed financial services firms are adopting AI at some level, with 52% already actively deploying agentic AI. Most current use remains concentrated in internal functions — process automation, data visualization, software engineering, and knowledge management — but use in trading is expanding.

Breeden described cyber resilience as one of the Bank of England's closest financial stability concerns around agentic AI. She noted that the technology has undergone a "step change" in cyber capability and that supervisors need to look at systemic risks rather than only individual firm-level exposures.

The same tools that strengthen cyber defenses when used by security teams could, in the hands of malicious actors, increase the chance of attacks that harm financial stability. The International Monetary Fund has separately warned that AI-enabled cyber risk should be treated as a financial stability issue, as attacks can scale quickly and spread across sectors that share digital infrastructure.

The Bank of England is considering stronger recovery requirements for core systems, including arrangements that would allow one bank to take over another's basic functions during an outage. On the market-wide level, regulators are examining guardrails including circuit breakers and kill switches designed to limit or stop trading across markets if faulty AI models contribute to severe disruption.

The Financial Stability Board earlier in June proposed 12 sound practices for responsible AI adoption by financial institutions. Breeden's remarks mark a significant escalation in tone, shifting from the Bank of England's earlier position that existing rules were sufficient. The review now underway is expected to shape both firm-level controls and market-wide safeguards as agentic AI becomes embedded in the financial system.