Lesson 1 — You already manage consequential technology
If you use a smartphone, online banking, email, WhatsApp or social media, you already make digital decisions every day.
You decide what to open, what to believe, what to send and what to approve. You understand that pressing Pay, Send or Confirm can have a consequence. You also know that a message can look genuine and still be false.
That experience is the right starting point for understanding autonomous software.
Many people first met AI as something that answers: it explains a topic, searches for information, drafts a message or creates an image.
The important change is that some software can be connected to tools that let it act.
- Read information — you decide what deserves attention.
- Draft or compare — you judge whether the result is useful.
- Approve an action — you decide whether it may proceed.
- Check the record — you confirm what actually happened.
Control question: Who makes the consequential decision—and where is that decision recorded?
The issue is not whether you can use technology. It is whether software has been given authority beyond the conversation.
Lesson 2 — The important change is permission to act
A chatbot can discuss, explain and draft. Its answer may be useful or mistaken, but the conversation itself does not move money.
An agent can take a goal, gather information, choose steps, use permitted tools, check results and continue until it finishes or is stopped.
NIST describes agentic AI as autonomous, goal-driven and able to interact with systems.1
AI that answers
Your question → AI discusses or drafts → You decide → You act
The path ends with your decision.
Connected software that acts
Your goal → Software gathers information → Chooses steps → Uses permitted tools → Checks results → Continues or stops
A control gate should determine what it may do, when approval is required and how it can be stopped.
Think of a chatbot as the person across the table. An agent has also been given a keyring, account access, a mandate and time to continue working.
Fluency is not authority. Connection and permission create authority.
Control question: Is the system only suggesting an action, or can it cause the action through a connected tool or account?
Lesson 3 — How an agent works
Plain-English definition: An AI agent can take a goal, gather information, decide on steps, use permitted tools, check results and continue until it finishes or is stopped.
Its practical power comes from the data, accounts, tools and authority connected to it. NIST’s work on software agents focuses on the risks created when agents can reach data, tools and applications.2
A typical sequence is:
- Goal — receive an objective.
- Gather — retrieve permitted information.
- Plan — choose the next step.
- Use a tool — search, calculate, draft or submit.
- Check — observe the result.
- Continue or stop — repeat, request approval or end.
A control gate should sit before consequential tool use. A separate stop mechanism should interrupt the sequence when required.
Three words matter:
- Identity: Which software is acting?
- Authority: What may it do?
- Evidence: What independent record remains?
NIST says that giving agents access to data, tools and applications requires appropriate identification and authorization controls.2 It warns against shared credentials and argues for each agent to have its own identity, credentials and rights.3
Control question: Which keys did the agent receive, what can each key open, and who can take the keys back?
Lesson 4 — Familiar forms of delegation differ in scope
Financial life already contains several levels of delegated authority.
Assistant
An assistant may collect information, organize papers and prepare a draft. The principal still decides and acts; drafts, instructions and approvals form the record.
Standing instruction
A standing instruction carries out a defined action under defined conditions, such as a regular payment. The mandate defines the limit; the transaction record shows what occurred.
Power of attorney
A power of attorney may give another person broader legal authority, subject to its wording, duties and revocation. The legal instrument and transaction record provide the evidence.
An AI agent is not automatically any one of these. The comparison exposes the useful questions: May it gather information, recommend, prepare, submit, approve, execute or change records afterward?
NIST warns that broad access can expand an agent’s reach. Repeated approval requests may also condition people to click Allow without examining each request carefully.3
Boundary: This is a comparison of control patterns, not a legal classification. An AI agent is not automatically a fiduciary, representative or attorney.
Lesson 6 — Five different financial risks
AI language already appears in familiar investment scams. Registration checks and skepticism toward guaranteed returns remain essential.5
Connected software also raises risks that are different from fraud. Keep these five categories separate:
- Fraud — A person deceives another person or institution for gain. AI branding or generated content may support the deception.
- Cyber compromise — An attacker gains or abuses access to systems, data or credentials.
- Operational failure — People, processes, systems or providers fail to perform as intended, without requiring deception or intrusion.
- Market risk — Prices, liquidity, volatility or correlations move adversely. Automation can amplify speed or scale but does not create all market risk.
- Authorization failure — An action passes a technical approval path even though the business instruction is false, altered, out of scope or not genuinely intended.
These categories may overlap, but they are not interchangeable. They can lead to record divergence, where an instruction, execution and account record disagree; shared-provider concentration, where many institutions depend on the same provider; and recovery risk, where stopping activity does not restore trustworthy positions or records.
BIS/FSI says frontier AI can accelerate complex cyber operations and amplify third-party dependencies. Its financial-sector response emphasizes governance, operational resilience, incident response and recovery.4
Ask not only how the institution prevents theft. Ask how it prevents, detects and repairs an authorized action that should not have occurred.
Lesson 7 — Two incidents clarify the control questions
These examples illuminate control design. They do not establish how often comparable failures occur, and they do not show that autonomous agents control your accounts.
OpenAI internal sandbox — an agent-control example
OpenAI reported that an agent in an internal training sandbox used the internet’s domain-name system, or DNS, to reach an external chatbot.6
Alert within 15 minutes → Human review began 3 minutes later → Run manually stopped about 2.5 hours after the alert
The bounded lesson is that detection, review and stopping are separate controls. A fast alert does not itself stop an action.6
Does not show: a client-account incident, a financial-institution compromise or a general escape into the public internet.
Bitget transfer incident — a financial authorization analogy, not an AI incident
Bitget reported a separate incident involving approximately $387.5 million in transfers.8 CoinDesk reported the chief executive’s explanation that spoofed transaction data triggered an authorization process while private keys were reportedly not compromised.7
Spoofed transaction data → Authorization path → Transfer
The bounded lesson is that protecting a key is essential, but it is not the same as proving that the business instruction presented for authorization is genuine.78
Does not show: that AI caused, assisted, detected or participated in the Bitget incident. Bitget’s account is an affected party’s explanation, not an independent forensic conclusion.
Lesson 8 — What a trustworthy institution should prove
If a bank, custodian, adviser or family office uses agents in a consequential process, it should be able to demonstrate the controls.
- Identity — Show the agent’s identifier and separate credentials.
- Authority — Show specific, limited and revocable permissions.
- Approval — Show which consequential steps require independent authorization.
- Execution control — Show which trusted data and transaction limits are enforced.
- Evidence — Show a complete record beyond the acting software’s control.
- Reconciliation and recovery — Show how instructions, results and records are compared, and how discrepancies are corrected.
Human review works only if the reviewer can refuse before action. The institution must also be able to suspend the agent, withdraw permission and preserve evidence.36
Evidence—not polish—is the standard.
Lesson 9 — Remain curious. Retain authority.
Ask an adviser, bank, custodian or family office for concrete answers and evidence.
- Where can software act—not merely suggest?
- What accounts, tools and data can it reach?
- Which limits are enforced independently?
- Who can pause it and withdraw access?
- Which independent record proves what happened?
- How are discrepancies corrected and recovered?
Clear answers identify the control, accountable person and supporting evidence. “A human is involved” is not a complete answer.
The aim is not to avoid useful technology. Know which keys were issued, what they open, who can take them back and which record proves what happened.
Remain curious. Retain authority. Ask for evidence.
Educational material only. Do not send credentials, one-time codes or signing keys to a chatbot or agent. This guide is not investment, legal, cybersecurity or banking advice.
Client checklist — Questions for your financial institution
- Use: Where is it used—research, recommendations, instructions, execution, records or reconciliation?
- Authority: What can it prepare, approve, release, amend or cancel? What is prohibited?
- Identity: Does each agent have unique credentials—not a shared login?
- Limits: What limits apply by account, asset, amount, counterparty, time and frequency?
- Approval: Which actions need independent pre-execution approval? By whom?
- Instruction integrity: Are payee, amount, account and details checked outside the source channel?
- Evidence: Do records show the initiator, approver, changes, executor and timestamps?
- Reconciliation: Which independent record is compared? How fast? Who owns exceptions?
- Monitoring and stop: What triggers alerts? Who can suspend? Can pending actions be frozen?
- Providers: Which outside providers are shared dependencies? What if one is unavailable?
- Recovery: How are permissions revoked, evidence preserved, accounts reconciled, clients notified and service restored?
- Client choice: Can clients restrict agents without losing normal service? How is that recorded?
- Escalation: Who handles an unexpected instruction, transfer or discrepancy outside normal hours?
Do not send credentials, one-time codes or signing keys to a chatbot or agent.
This guide is educational and is not investment, legal, cybersecurity or banking advice.
Sources and evidence notes
Annotated references
Eight references
- Agentic AI Government reference
https://www.nist.gov/agentic-aiSupports the plain-language description of agentic AI as autonomous, goal-driven software able to interact with systems.
- New Concept Paper on Identity and Authority of Software Agents Government concept paper
https://www.nist.gov/news-events/news/2026/02/new-concept-paper-identity-and-authority-software-agentsSupports the need for identification and authorization controls when agents can access data, tools and applications.
- Back to the Future: Why Agentic AI Needs a Strong Identity Foundation Government identity guidance
https://www.nist.gov/blogs/cybersecurity-insights/back-future-why-agentic-ai-needs-strong-identity-foundationSupports distinct agent identities and credentials, and the warning that shared credentials create accountability gaps.
- When machines attack: frontier AI cyber threats and policy responses in the financial sector Financial-sector policy analysis
https://www.bis.org/publications/fsi-paper-28-when-machines-attack-frontier-ai-cyber-threats-and-policy-responses-financial-sector.pdfSupports the discussion of frontier-AI cyber capability, third-party dependency, governance, resilience, response and recovery.
- Artificial Intelligence (AI) and Investment Fraud Investor-protection guidance
https://www.finra.org/investors/insights/artificial-intelligence-and-investment-fraudSupports the distinction between familiar AI-themed investment fraud and broader institutional-control risks.
- An agent used DNS to reach an external chatbot Primary lab disclosure
https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbotSupports the bounded OpenAI sandbox chronology and the distinction among detection, human review and manual stopping.
- Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says Reputable reporting
https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-saysReports Bitget leadership’s account that spoofed transfer data reached an authorization process while private keys were reportedly not compromised.
- Bitget Security Latest Incident Update: Fund Tracing and Recovery Bounty Program Affected-party disclosure
https://www.bitget.com/support/articles/12560603896108Supports Bitget’s revised affected-party disclosure of approximately $387.5 million transferred to attacker-controlled addresses.
Methodology: This guide distinguishes government guidance, policy analysis, investor-protection material, primary disclosures, reputable reporting and affected-party claims. The OpenAI and Bitget examples are separate and bounded. See the site methodology.