The Agentic Enterprise, Sector by Sector: Banking, Telecommunications, Retail

By NATARAJA Team

The agentic enterprise did not arrive as a strategy. It arrived as a series of local decisions: a credit team automated pre-screening, a network operations centre let the optimiser act on its own recommendations, a merchandising team gave the pricing engine write access. Nobody declared a transformation. The enterprise became agentic one workflow at a time, which is exactly why most boards cannot say today how many systems act autonomously on their behalf.

We have written about what an agent cannot carry, which is accountability, and about the governance framework that contains agentic risk in general. This piece is about something the general treatments cannot show: the risk does not concentrate in the same place in every industry. Where your agents can hurt you depends on what your industry sells, and so does the regulation already standing behind you. Three sectors carry most of the early exposure, and they happen to be the three where autonomous action meets other people's money, other people's connectivity, and other people's buying decisions.

Two questions travel across all three, and they come from our Executive Guarantees Brief on the Sovereign Decision: what commitments can this system create, and what institutional exposure can those commitments generate? Keep them in hand; each sector answers them differently.

Banking and financial services: the decisions were already regulated

Banking is the sector where agentic AI meets the most developed supervisory machinery, because the decisions agents are taking over were regulated before agents existed. Credit decisioning, transaction monitoring, treasury execution, claims and collections: every one of these already sits under model risk management, fair-lending duties, and conduct supervision.

That creates a paradox worth stating plainly. Banks are simultaneously the best-prepared sector, because governance muscle exists, and the most exposed, because the muscle was built for the wrong question. Model risk management asks whether the model is sound: validated, monitored, explained. An agent introduces the question that regime was never designed to answer: was the action it took authorised? A perfectly validated model inside an agent that exceeded its authority produces a clean model-risk file and an incident. We covered the regime mapping in detail in agentic AI risk: the PRA's model risk principles, MAS FEAT, and the EU AI Act's high-risk regime all govern the model; none of them, natively, governs the delegation.

Where the risk concentrates: credit and affordability decisions, which the EU AI Act classifies high-risk with fixed conformity deadlines already covered in our deadline analysis; and machine-speed execution, where the treasury case from our Executive Authority Brief on AI incidents is the standing caution: a system trading correctly within an authority designed for continuous execution, while conditions exceeded everything the design anticipated.

One sector-specific severity deserves naming, from our Guarantees Brief on Graceful Fall: most failures are operational, but confidence collapse is existential, and banking is the industry where that sentence is literal. A bank does not need its agents to lose money to be destroyed by them; it needs depositors and counterparties to stop believing the bank controls its own systems. The governance objective in banking is therefore not preventing every agent error. It is being able to demonstrate, quickly and credibly, that authority was bounded and the error was contained.

Govern first: the credit decision (because the regulator will ask) and any agent with execution authority against markets or payments (because the clock there is measured in seconds). The architecture for the first is laid out in our banking-specific piece, authority architecture for agentic banking.

Telecommunications: the network is the agent's body

Telcos took a different door into the agentic enterprise. The first autonomous systems were not customer-facing; they were network-facing: traffic optimisation, self-healing, capacity allocation, energy management. Letting the optimiser act on its own recommendations was an efficiency decision made years ago, and it quietly created some of the most autonomous infrastructure in any industry.

The risk shape follows. A banking agent that fails affects accounts; a network agent that fails affects everything running on the network, including emergency services, payment rails, and every other company's agents. Telecommunications is where agentic failure has the widest blast radius per decision, which is why the EU AI Act lists safety components of critical infrastructure among its high-risk categories, and why the sector's regulatory floor is converging from two directions at once: AI rules on one side, network resilience regimes on the other.

The second concentration is customer operations, and it is closer to the retail pattern than telcos tend to assume. Retention agents that construct offers, plan-change agents that commit consumers to contracts, collections agents that negotiate: each of these creates commitments to consumers at scale, under consumer-protection law that was written assuming a human somewhere approved the offer. An agent constructing a thousand bespoke retention offers an hour is a thousand commitments an hour, and the question of who authorised the discount structure has to have an answer better than "the model optimised it".

The third is the one telcos are structurally first to meet: multi-agent interaction. A modern network is already a field of autonomous systems acting into each other, vendor-supplied and home-built, each optimising locally. Our analysis of multi-agent execution governance covers the mechanism: emergence lives between agents, not inside them, and no amount of single-agent validation predicts what the fleet does under stress. Our Executive Authority Brief on Competitive Acceleration states the structural fact: interaction introduces effects no single authority controls.

Govern first: the boundary between recommend and act in network operations (the single most consequential authority line in the sector), and the customer-commitment agents, because consumer regulators move faster than infrastructure ones.

Retail and consumer products: agents on both sides of the counter

Retail's agentic exposure is unique because it is the first sector where the enterprise's agents meet the customers' agents. Everyone else worries about their own systems; retail also has to govern a counterparty it does not control.

On the enterprise's own side, two agent families concentrate the risk. Pricing agents act into a competitive field: your repricer reacts to their repricer, and the interaction can cascade into price wars and margin destruction no single company chose. This is Competitive Acceleration again, in its most visible consumer form: at scale, small actions trigger disproportionate reactions, and outcomes move beyond the organisation's control. A pricing agent needs the same thing a treasury agent needs: an authority designed for the conditions that will eventually arrive, not the conditions the backtest contained. Buying and replenishment agents commit spend, and everything we wrote in authority limits for AI that spends applies directly: mandates with quantified limits, silence escalating rather than permitting, and a gate that arms on the irreversible.

On the customer side, shopping agents are beginning to transact against retail platforms: comparing, negotiating, purchasing. The retailer's question, which has already reached our search data verbatim, is what governance to put in place before allowing them to transact. The short answer is that you govern the interface, since you cannot govern the counterparty: agent identification, transaction limits per agent identity, commitment terms that are machine-legible, and records that attribute every transaction to an agent and the principal behind it. The full treatment is in the purchasing article's FAQ.

And beneath both sides sits personalisation, the sector's oldest AI, which agentic execution quietly upgrades from suggestion to action. A recommender that adjusts what a consumer sees is influence; an agent that adjusts price, credit terms, or availability per person is a decision about a natural person, and profiling of natural persons is precisely the line at which the EU AI Act's derogations stop applying.

Govern first: pricing authority (bounded ranges, rate limits, and a defined answer to "what happens when the competitor's agent responds"), and the buying agents, because spend is where finance will eventually find the ungoverned decisions anyway.

The pattern underneath all three

Read the three sectors side by side and the pattern is hard to miss. In every case, the dangerous agents are not the newest or the most sophisticated. They are the ones wired into the systems where the sector's core commitments are made: the loan book, the network, the price. And in every case the failure story is the same story told three ways: an authority defined for expected conditions, exercised correctly under unexpected ones.

That is why the cross-sector discipline is identical even though the risk shapes differ:

  1. Inventory the agents that already act, sector-wide, before writing any policy. The method is in AI agent inventory and non-human identity: work from evidence, not surveys.
  2. Define authority explicitly per agent: what it may commit, within what limits, under which conditions it must stop. Undefined delegation expands silently.
  3. Enforce in the execution path, with deterministic checks at machine speed and human gates armed only where commitments become irreversible.
  4. Record every decision so the sector's natural adversary, the regulator in banking, the incident inquiry in telco, the competition authority in retail, reads evidence rather than reconstruction.

Frequently asked questions

How is agentic AI used in banking and financial services?

The established uses are credit pre-screening and decisioning, transaction and fraud monitoring, collections and claims handling, and execution systems in treasury and markets. The newer wave is agents that act across workflows: preparing and submitting regulatory filings, managing liquidity within limits, and negotiating at machine speed. The governance point is that most of these were regulated activities before agents arrived, so the question is rarely whether the use is permitted; it is whether the delegation to the agent is defined, bounded, and demonstrable to a supervisor who asks who authorised the action.

What are the risks of agentic AI in telecommunications?

Three concentrations. Network-facing agents carry the widest blast radius in any industry, because a wrong autonomous action affects everything running on the network, which is why critical-infrastructure safety components sit in the EU AI Act's high-risk categories. Customer-operations agents create consumer commitments at scale: offers, contract changes, and collections actions that consumer-protection law assumes someone approved. And multi-agent interaction arrives earliest in telco, because a modern network is already a field of autonomous systems optimising into each other, where emergent behaviour lives between agents rather than inside any of them.

What governance do retailers need before allowing AI agents to transact?

Govern the interface, because you cannot govern the counterparty: require agents to transact under an identifiable agent credential tied to a principal, set per-identity transaction limits, publish machine-legible terms of commitment, and record every transaction with both the agent and the principal attributed. On the retailer's own side, the same discipline applies to pricing and buying agents: bounded authority, deterministic limits at machine speed, and human gates on irreversible commitments. The fuller treatment is in our article on authority limits for AI that spends.

What new roles and skills does AI create in financial services?

The genuinely new work clusters around authority and evidence rather than model-building. Someone has to write and maintain agent mandates, which is a hybrid of credit policy, legal, and systems thinking that no existing role owns. Someone has to own authority conformance monitoring: not whether the model performs, but whether actions stayed inside their delegation. Incident work shifts from operator-error analysis to authority-design review. And model risk teams extend into agent risk, adding entitlement and delegation review to validation. The skill in shortest supply is the ability to translate a policy into machine-enforceable limits, because that is the seam where the two speeds of the organisation meet.

Which industries are most exposed to agentic AI risk?

Exposure tracks two variables: how much autonomous commitment-making the sector has already deployed, and how consequential a single commitment is. Banking and financial services score high on both, with the added property that confidence collapse is existential there. Telecommunications concentrates blast radius: fewer customer-facing agents than banking, but network agents whose failures propagate to everything above them. Retail concentrates interaction risk: pricing agents acting into competitors' pricing agents, and customers' shopping agents transacting against the platform. Manufacturing and energy follow the telco pattern with physical consequences added.

Where NATARAJA fits

The discipline above is what our platform enforces: agent mandates as evidence, deterministic limits checked at machine speed, human gates that arm on the irreversible, and an attested record per decision that reads as evidence to whichever adversary your sector supplies. The protocols are public, from EU AI Act classification for the systems you are deploying to purchase authority for the agents that spend.

If one of these sectors is yours, request a governed pilot: we take one agent that already acts, put its next decisions under governance, and hand you the record.