Articles

Sygnum’s Thomas Frei Says AI Agents Should Inform, Not Act, on Material Transactions

“The agent should make people faster and better informed, not become the party that acts,” believes Thomas Frei, Head of AI and Data Analytics at Sygnum. In which context does it apply: reveals PaySpace Magazine interview.

Sygnum's Thomas Frei Says AI Agents Should Inform, Not Act, on Material Transactions

In this interview, Sygnum’s Head of AI and Data Analytics, Thomas Frei, discusses where human oversight of AI agents should remain non-negotiable. Frei says a human should approve anything material or irreversible, particularly on-chain transactions that cannot be unwound. He argues human-in-the-loop is not a control the bank would relax until AI agents build a performance record that justifies it — a principle drawn from Sygnum’s May 2026 pilot, in which the bank ran what it describes as the first live AI-agent-driven digital-asset transactions by a regulated Swiss institution.

  1. Within Hong Kong’s GenA.I. Sandbox++, Know Your Agent framework is a centerpiece. It links an AI agent to a verified person or business. Is it really enough for a banking institution to start processing payments coming from AI agents? What additional information (if any) does a bank need before it can safely allow an agent to initiate payments?

Knowing the person or business behind an agent is necessary, but that part is not new: it is the standard identification a bank already performs on its customers. An agent is not a legal person and has no identity of its own; it always acts for a natural or legal person, and that person stays the account holder and the party we identify. What a bank genuinely needs on top is the authorisation layer: a clear, risk-graded mandate from the customer setting out what their agent may do, up to what value and with which counterparties, plus a human approval step for anything material. Identifying the customer is the easy part. Defining and enforcing the mandate is the real work. 

  1. When Sygnum executed digital asset transactions through an AI agent, you didn’t give the agent its own wallet or transaction authority. Why did you choose this model? How does Know Your Agent framework offered by Hong Kong regulators differ from the one Sygnum tested?

By design, our agent had no wallet, no keys and no authority of its own. In our May 2026 pilot, the first live AI-agent-driven digital-asset transactions by a regulated Swiss bank, the agent interpreted the instruction, prepared the steps and surfaced the risks, but the client kept the keys and signed every transaction. The agent proposes; the client executes and stays accountable. That is the important difference. A framework built around giving the agent its own identity or credential treats the agent as the actor. In our model the agent is never the actor: the customer is identified in the normal way, the customer approves, and the agent simply does the work in between. 

  1. You have compared agent authorisation with a traditional power of attorney. What can the financial industry learn from the way powers of attorney define and limit a person’s authority, and where does the analogy break down when the “representative” is software?

Power of attorney is the right mental model, and it is already solved in law. The customer grants the agent a defined authority, caps it, keeps it revocable, and stays responsible for how it is used. Banks will most likely operationalise exactly that through their terms and conditions. Finance can borrow it directly: a scoped, revocable, auditable mandate rather than open-ended power. Where it differs from a human attorney is that software exercises no judgement and bears no responsibility, and it can act faster or be manipulated in ways a person would not, so the mandate has to be tighter, machine-enforced, and paired with a human check on anything irreversible. 

  1. At what point should a human be required to approve an AI agent’s transaction? Should this depend on transaction value, counterparty risk, asset type, destination or the agent’s previous behaviour?

The factors you list should all feed a risk grade: value, counterparty risk, asset type, destination and the agent’s track record. The honest line today is that a human should approve anything material or irreversible. For a bank moving client assets, and especially on-chain where a transaction cannot be unwound, human-in-the-loop is not a control we would relax until there is a performance record that justifies it. The agent should make people faster and better informed, not become the party that acts. 

  1. In regulated sandboxes, all institutions may be interconnected within the national payment ecosystem or by other links. What happens when an AI agent needs to make a payment across borders to a bank or payment provider that may not recognise the credential used to identify that agent?

This is less of a new problem than it first looks. A payment does not come from an agent; it comes from the account of a natural or legal person. When it arrives, the receiving institution runs its compliance on that person, using identification standards that have been in place for years. The agent does not need a portable cross-border credential of its own, because it is not the payer and is not a legal person. The genuinely new work sits on the sending side: making sure the agent acted within the mandate its customer set, and that the customer behind it is properly identified. Identity stays where it always was, with the person. 

  1. Who should ultimately be liable when an authorised AI agent makes a transaction that technically falls within its permissions but causes financial loss? Should responsibility sit with the customer, the bank, the agent developer or another party?

The clearest principle is that responsibility sits with the customer who authorised the agent. The customer grants the agent its power of attorney, so they are accountable for what it does within that authority, and banks will most likely make this explicit in their terms and conditions, agreed in advance rather than argued after a loss. The wider legal framework around AI agents is still developing, and I would be cautious of anyone claiming it is fully settled, but the starting point is not mysterious: the person who gave the mandate stands behind it. 

  1. Given intensifying talks of most advanced AI agents “overstepping” their boundaries, do you believe verifiable credentials schemes can work without revealing unnecessary information about the underlying person or business? What extra precautions do providers need to take to protect sensitive data?

A bank accepting a payment must always know the underlying person or business in full. That is non-negotiable, and no bank would accept a payment “from an agent,” because an agent is not a person. So minimum disclosure does not mean hiding the customer from their own bank. Where verifiable credentials earn their place is further along the chain: proving to other counterparties that an agent is authorised to do a specific thing, without exposing the principal’s full identity or unnecessary personal data to everyone it touches. The precaution for providers is not to create new stores of sensitive data in the process: verify against the customer you already know, keep any credential scoped and short-lived, and never let convenience pull more personal information into the flow than the check requires. 

  1. Looking at Sygnum’s experience so far, what would you consider the minimum safeguards a bank should have in place before allowing AI agents to execute financial transactions at scale?

From our experience: the agent holds no standing authority and no keys; the underlying customer is always identified and stays accountable; every material or irreversible action needs explicit human approval; the agent runs on a defined, risk-graded mandate with least-privilege, scoped credentials; everything it proposes and everything a human approves is logged so the full chain can be reconstructed; and the blast radius is contained by design, so an error or compromise stays contained rather than becoming a loss. Scale should follow evidence that these controls hold, not replace them. 

Nina Bobro

Nina Bobro

2223 Posts

https://payspacemagazine.com/author/nb/

Nina is passionate about financial technologies and environmental issues, reporting on the industry news and the most exciting projects that build their offerings around the intersection of fintech and sustainability.