Agentic AI Enters the KYC Compliance Room

Agentic AI & Automation

Compliance isn't the obstacle. Ungovernned automation is.

A Swiss bank's KYC proof of concept shows agentic AI can handle risk assessment — without sacrificing auditability.

Plus Bytes · Agentic AI & Automation Published: September 8, 2026 3 min read

Know Your Customer processes sit at the intersection of regulatory obligation and operational drag. They are slow by design — multi-step, document-heavy, and deliberately conservative — because the cost of a mistake is measured in fines, reputational damage, and in some cases criminal liability. That is precisely why the proof of concept completed by Kyndryl and Incore Bank, a Swiss private bank, deserves more than a passing glance.

The trial used Google Cloud's Gemini models to automate customer onboarding and risk assessment within a KYC framework. The reported design goals were not simply speed: the system was built to be explainable and fully auditable. That distinction matters more than anything else in this story.

Why KYC Is the Right Stress Test for Agentic AI

Most early deployments of agentic AI target workflows where mistakes are recoverable — scheduling, first-pass triage, draft communications. KYC is different. A miscategorised customer risk profile, an incomplete sanctions check, or an undocumented decision step can trigger regulatory action. The workflow demands that every decision leave a traceable record.

That is what makes this proof of concept structurally significant. If agentic AI can operate inside KYC with full auditability intact, it challenges the assumption that autonomous agents and high-stakes compliance workflows are fundamentally incompatible. The Incore Bank trial appears to treat explainability not as a feature to be bolted on after the fact, but as a design constraint from the outset.

Auditability isn't a compliance checkbox. In agentic systems, it's the architecture.

This is consistent with a broader pattern in governed AI deployments: the organisations moving furthest, fastest are those that treat oversight as a first-class engineering requirement rather than a legal afterthought. The governance questions that feel like friction early in deployment are what make scale defensible later.

What 'Explainable' Actually Requires in an Agentic System

Explainability in a multi-step agentic workflow is considerably harder than explainability in a single-model prediction. When an agent orchestrates several tools — document parsing, sanctions screening, risk scoring, case note generation — the explanation must trace across all of those steps, not just the final output. A regulator asking 'why was this customer classified as high risk?' needs an answer that spans the entire chain of reasoning, not a black-box score.

Building that kind of transparency requires deliberate architectural choices: structured logging at every decision point, clear handoffs between agent steps, and the ability to surface a human-readable account of what the agent did and why. These are not trivial engineering problems, and they are not solved simply by choosing a capable underlying model.

The Incore Bank proof of concept, by foregrounding auditability as a design goal, suggests that the team understood this distinction. A capable model inside a poorly governed wrapper would not satisfy a Swiss financial regulator. The governance layer is the work.

The Signal for Businesses Running Autonomous Agents

The KYC story is instructive beyond its specific regulatory context. Any business deploying autonomous agents in workflows that touch sensitive decisions — patient intake, credit assessment, financial onboarding — faces a version of the same challenge: how do you let an agent act at speed while preserving the ability to explain and audit every step after the fact?

The answer is not to slow the agent down. It is to design the governance layer before the agent is deployed, so that auditability is structural rather than retrofitted. Proof of concepts like the Incore Bank trial are valuable precisely because they surface these requirements under controlled conditions, before the system is live and the stakes are real.

For any operator considering autonomous agents in a regulated or high-accountability context, the relevant question is not whether the underlying model is capable. It is whether the deployment architecture can produce a complete, defensible account of every decision the agent makes. That is the baseline — and it is achievable, but only if it is treated as a requirement from day one rather than a compliance checkbox added at the end.

Further Reading: fintech.global

Ready to Put Agentic AI to Work?

See how autonomous AI agents can handle booking, intake, and follow-up for your business.