FinAgentHub
← Archive
Issue No. 0056 min read

Bounded autonomy: why less than full autonomy is the safer bet

The number behind why almost nobody's letting agents run unsupervised — and why that's not a compromise.

Last week was a calculator — how much to hand over, by category. This week zooms out: why "bounded" isn't a temporary compromise on the way to full autonomy. For most tasks, it's the actual destination.

This week in the agent economy

  • A US banking group told Congress that consumers, not banks, may bear liability for their AI agent's mistakes. The question turns on existing electronic-transfer law that was never written with agents in mind. What it means for you: "bounded" isn't just a safety preference — it may be the only thing standing between you and being on the hook for a transaction you didn't personally make.
  • The UK's financial regulator opened a consultation asking whether agentic AI should be allowed to analyze, initiate, approve, and execute payments — and what authentication and liability rules need to change. What it means for you: the rules for all of this are still being actively written, in more than one country. What's "safe" today is a moving target, not a settled answer.

The deep dive: why less autonomy is more

Here's a number worth sitting with: a joint Bank of England and FCA survey found 75% of financial firms are already using AI. Only 2% of those use cases involve fully autonomous decision-making. Just over half involve some automated decision-making, but most of that stays constrained or supervised.

That's not an industry dragging its feet. These are the institutions with the most resources, the most incentive, and the most experience managing risk at scale — and they've landed overwhelmingly on bounded, supervised autonomy as the actual strategy, not a stepping stone to something bigger. Forrester has gone further, predicting that an agentic AI deployment will cause a publicly disclosed data breach sometime in 2026. The firms staying bounded aren't behind. They're reading the room correctly.

Two ways "human oversight" quietly fails

Adding a human reviewer doesn't automatically make a system safe — it just moves the risk. Two failure modes worth knowing:

Automation bias: after enough correct runs, the human reviewing an agent's work starts rubber-stamping instead of actually checking. The review step still exists; it's stopped doing anything.

Exception overload: if the boundary is too wide, the agent escalates too often, and a human facing dozens of daily approvals starts approving on speed instead of judgment.

The fix for both is the same: keep the bounded task narrow enough that review is still real. A limit you can actually think about each time beats a wider one you've stopped reading.

— FinAgentHub

This web version has the subscriber-only Tool Corner and Reader Question sections removed. Subscribers get those in the original email, two weeks before this page goes up.

Get the next issue two weeks early.