It is 2:14 in the morning. A payments reconciliation agent at a large bank starts pulling customer account records it has never touched before. Within seconds, a runtime control flags the behavior, the agent is quarantined, and a kill switch severs its access to every downstream tool.
The control worked. Now comes the hard part. By 8:00 AM the Chief Risk Officer, the CISO, internal audit and, eventually, an examiner will all ask the same question: why? Why did the agent do what it did, why was it stopped, and can you prove it?
For AI leaders in financial services, stopping a bad agent is table stakes. Explaining the stop, with evidence that holds up to a regulator, is the real test. That is what agent explainability means in 2026.
The concern is no longer theoretical. Supervisors on both sides of the Atlantic, and the people who run the largest banks, are naming agent explainability as a gap when considering releasing autonomous fleets of agents to production environments.
FINRA put it in writing. Its 2026 Annual Regulatory Oversight Report lists auditability as a core AI agent risk:
"Multi-step reasoning or complex chains of agent actions may be difficult to reconstruct, complicating auditability."
The same report flags "autonomy and scope creep," where agents "may take actions that exceed the user's actual or intended scope or authority," and urges firms to track agent actions and decisions and to establish guardrails that constrain agent behavior.
The Bank of England is talking about kill switches. Speaking at the ECB Forum on Central Banking on June 30, 2026, Deputy Governor Sarah Breeden said:
"Our frameworks were not built to contemplate autonomous agents, and relying on a human in the loop for all agent actions is unlikely to be realistic."
She raised circuit breakers and kill switches as possible safeguards, and warned that agents whose "objectives drift from original goals" could amplify volatility in stress.
US bank model risk guidance left agents out. When the Federal Reserve, OCC and FDIC issued SR 26-2 on April 17, 2026, replacing SR 11-7, the guidance expressly omitted generative and agentic AI from its scope, calling them "novel and rapidly evolving" and promising a future request for information. That is not a pass. As DefenseStorm notes, banks must still govern agents under their existing risk programs, which means building the evidence themselves.
Bank leaders feel the same pressure. Former Goldman Sachs CEO Lloyd Blankfein told a16z in May 2026 that the danger of AI agents is "not because it's smarter than us... but because we don't have the ability to test whether it's right or not," adding that a single piece of software "could go out and do 70,000 transactions." At JPMorgan Chase, consumer bank CIO Gill Haus described the current posture plainly: "We don't let it loose in that sense. We have a human in the middle."
The survey data shows how wide the gap is:
| Finding | Source |
|---|---|
| Only 18% of banking leaders are confident they could pass an independent audit of their AI controls | Grant Thornton 2026 AI Impact Survey (banking subset, directional) |
| 44% of senior finance leaders are only somewhat confident they could explain AI agent actions to auditors or regulators | Avalara, July 2026 |
| 23% say accountability for a significant AI error would be unclear or nonexistent | Avalara, July 2026 |
| 76% lack dedicated in house expertise to understand how their AI agents function | Avalara, July 2026 |
| Only 7% prioritize governance over deployment speed | Avalara, July 2026 |
And the clock is running in Europe. Under the EU AI Act omnibus agreement, high risk systems such as credit scoring must comply by December 2, 2027, bringing logging, transparency and human oversight obligations with them.
Don't wait for the 2:14 AM quarantine to find out whether you can explain it.
An evaluation license lets your team run Prediction Guard inside your own infrastructure, so you can register an agent, trace a run, trigger an Intervention and review the Evidence bundle with your own data and your own reviewers before you commit.
Request an Evaluation License →For a traditional model, explainability meant answering why a score came out the way it did. Agents plan, call tools, move data and take actions across systems. So explainability now has to answer three questions, each with evidence.
If any of those answers begins with "we think" or "the logs suggest," the institution does not have explainability. It has a story. Examiners, auditors and boards want a record.
Two capabilities turn a 2:14 AM quarantine into a clean answer by 8:00 AM: agent identity registration and agent tracing. Identity tells you who the agent is and what it was allowed to do. Tracing tells you what it actually did. The gap between the two is the finding.
agent investigation flow · identity and trace meet at the runtime control
The runtime control sits between what the agent may do and what it did; every Intervention it triggers feeds the Evidence bundle reviewers read.
Every agent is registered before it ever runs, like a new employee getting a badge. The registration records its owner, business purpose, the models it may use, the tools and data it is entitled to, and the runtime controls that apply to it. In our example, the reconciliation agent was registered by the payments operations team with read access to transaction ledgers only. Customer account records were never in scope.
Without that registration, investigators cannot tell an agent acting outside its authority from one acting as designed. FINRA's concern about agents that "exceed the user's actual or intended scope or authority" is only answerable if the intended scope was written down first.
Agent tracing captures every step of the run as a linked chain: the prompt and context the agent received, each reasoning step, each tool call with its inputs and outputs, and each data access. This is exactly the "complex chain of agent actions" FINRA says is hard to reconstruct. With tracing, nothing needs reconstructing. The chain is already there.
Replaying the trace, investigators see the agent received a reconciliation task, hit a mismatch, and then called a customer lookup tool to "resolve the discrepancy." That tool call was the first step outside its registered entitlements.
The trace shows the moment Agent Behavior Controls compared the tool call against the agent's registered identity and flagged it. The Intervention log records which policy fired, the quarantine that followed, and the kill switch that revoked the agent's credentials and tool access. It also records what was prevented: 1,400 queued lookups that never executed.
The investigation closes with an Evidence bundle drawn from Immutable Audit Logs: the agent's registration, the full trace, the control decision, the intervention timeline and the remediation. That bundle is what goes to the CRO, internal audit and, if needed, the examiner. It answers all three questions with records, not recollection.
The root cause in our example turns out to be a newly added tool in a shared tool library that no one had scoped to the agent's role. The fix is a registration change and a Component Input/Output Control on that tool, not a rewrite of the agent.
If your team cannot answer yes to each of these today, the first quarantine will expose it.
Notice what is missing from that list: a human approving every step. As Breeden said, that is "unlikely to be realistic" at scale. Explainability is what lets institutions move past human in the middle without losing accountability.
Don't wait for the 2:14 AM quarantine to find out whether you can explain it.
An evaluation license lets your team run Prediction Guard inside your own infrastructure, so you can register an agent, trace a run, trigger an Intervention and review the Evidence bundle with your own data and your own reviewers before you commit.
Request an Evaluation License →Prediction Guard is a sovereign AI control plane built for exactly this moment. It gives regulated institutions operational control of their agents, running inside their own environment so sensitive data and audit records never leave their boundary.
Stopping a rogue agent is the easy part. Explaining it is what earns the right to deploy the next one. Talk to our team to see an agent investigation end to end.
Don't wait for the 2:14 AM quarantine to find out whether you can explain it.
An evaluation license lets your team run Prediction Guard inside your own infrastructure, so you can register an agent, trace a run, trigger an Intervention and review the Evidence bundle with your own data and your own reviewers before you commit.
Request an Evaluation License →