Before an AI agent touches a bank's operations, ask five questionsAI 智能体碰银行运营之前,先问五个问题
Banks are not short of AI pilots. They are short of AI they can defend to an auditor. Five questions separate the two.银行不缺 AI 试点,缺的是经得起审计的 AI。五个问题,把两者分开。
October 7, 2026 · 4 min read2026 年 10 月 7 日 · 阅读约 3 分钟

Banks are not short of AI pilots. Most have a chatbot in testing, a document summariser in a sandbox and a slide about generative AI in the annual strategy. What they are short of is AI they can defend: to an auditor, to a regulator, to a board that wants to know what happens when it goes wrong.
The difference between the two is rarely the model. It is the answers to five questions, and a bank should get them in writing before an agent touches its operations.
1. Where does the data stay?
For a bank, this is the first question, not the last. Customer records, credit files and transaction data cannot be sent wherever a model happens to run.
The answer we give is that the model moves in and the data does not move out. Roles that touch sensitive data use a private model running inside the bank's walls: in the bank's own cloud account, on a dedicated machine never shared with another customer, or in the bank's own data centre, which can be cut off from the internet entirely. Roles that do not touch sensitive data can keep using public cloud models. Both are assigned in the same layer, so the processes on top do not change.
2. What exactly can the agent see?
"Roughly what the person who set it up could see" is not an access policy.
In ADIS, every agent has its own identity, a service user that cannot log in and holds no rights of its own. What it can read is granted through the groups it belongs to and narrowed by the restrictions on its key. The result is an intersection, not a union: an agent in the operations group reads operations data and nothing else, and an agent in no group reads nothing at all. Sensitive records carry markings that travel with them, so a document marked for compliance stays with compliance whichever agent touches it.
3. What can it change, and who approves?
Reading and drafting are where agents earn their keep: preparing a reconciliation, checking a loan file for missing documents, drafting a response to an internal query. None of that changes the bank's books.
Anything that does change them goes through a defined Action, and an Action that writes to a business system is a proposal until a person approves it. Who approves is defined by role, so it survives reorganisations, and actions involving money can require two approvers by design. Agents can draft, check and submit; they cannot approve, and they cannot approve their own work.
4. Can you reconstruct what happened?
An auditor will not ask whether the agent is usually right. They will ask what it did on a specific day, with which data, and who signed it off.
Every Action and every approval is written to the Action Log with the records it touched, when and on whose behalf. Answers cite the records they were based on. File operations are kept in an audit trail. Reconstructing a decision becomes a query, not an investigation.
5. What happens when the model changes?
Models improve every few months. A bank cannot re-validate its processes every time a vendor ships a new version, and it should not be locked to one vendor either.
In ADIS, the model layer is separate from roles, processes and data. Switching a role to a different model, public or private, happens in that layer; the roles, the processes and the documents they work with stay as they are. If a private machine has the capacity, the next generation of open models can go straight on it.
In a bank, the bar for AI is not whether it can answer. It is whether every answer, and every change, can be explained afterwards.
Where a bank should start
Start inside the bank, not in front of customers. The best first candidates are internal operations with clear rules, high volumes and a person who already checks the result:
- preparing reconciliations and exception lists for operations teams;
- checking loan and onboarding files for completeness before they reach a credit officer;
- answering staff questions about internal policies and procedures, with the policy cited;
- drafting the first version of recurring internal and regulatory reports for the team that owns them.
In each case, the digital employee prepares and a person decides, and the measure of success is agreed in advance: a set of twenty to fifty real questions from the team, scored before and after.
How to begin
A deployment starts with a two-week assessment: one department, one line of work, and a written plan that answers these five questions for that department, including where each model runs, what each agent may read and which actions need whose approval. Only then does anything get built.
That order is slower than a pilot. It is also the only order that survives an audit.
银行不缺 AI 试点。大多数银行都有一个在测试的聊天机器人、一个在沙箱里的文档摘要工具,年度战略里还有一页讲生成式 AI。银行缺的,是经得起追问的 AI:经得起审计、经得起监管,也经得起董事会问一句「出了错怎么办」。
两者的差别很少在模型上,而在五个问题的答案上。在智能体碰银行运营之前,这五个答案应该先白纸黑字地拿到手。
一、数据留在哪里?
对银行来说,这是第一个问题,不是最后一个。客户档案、授信材料、交易数据,不能模型在哪儿跑就送到哪儿。
我们的回答是:模型搬进来,数据不出去。接触敏感数据的岗位,用部署在银行自己墙内的私有模型——在银行自己的云账号里,在一台不与任何其他客户共用的专属机器上,或者在银行自己的机房里,可以完全断开互联网。不接触敏感数据的岗位,继续用公有云模型。两种模型在同一层分配,上面的流程不用改。
二、智能体到底能看到什么?
「大概等于当初搭它的那个人能看到的」不是一条权限策略。
在 ADIS 里,每个智能体都有自己的身份:一个服务用户,不能登录,本身没有任何权限。它能读什么,通过它所在的组授予,再被它的 Key 上的限制收窄。结果是交集,不是并集:运营组里的智能体只读运营数据;不在任何组里,就什么都读不到。敏感记录带着标记,标记跟着数据走:标给合规的文件,无论哪个智能体经手,都只留在合规。
三、它能改什么,谁来批?
智能体真正挣到钱的地方,是查和写:准备对账、检查一份贷款材料缺什么、起草一份内部问询的回复。这些都不会改动银行的账。
凡是会改动账的,都要走一个定义好的动作;写回业务系统的动作,在有人批准之前都只是提案。谁来批按角色定义,换岗也不失效;涉及资金的动作,可以按设计要求两人批准。智能体可以起草、检查、提交,但不能批准,更不能批准自己的工作。
四、能不能还原当时发生了什么?
审计不会问智能体通常对不对。审计会问:某一天,它做了什么,用了哪些数据,谁签的字。
每一个动作、每一次审批,都和它碰过的记录、时间、代表谁,一起写进 Action Log。回答附上它依据的记录。文件操作记在审计记录里。还原一个决定,变成一次查询,而不是一场调查。
五、模型换了怎么办?
模型几个月就更新一次。银行不可能每次厂商发新版本都把流程重新验证一遍,也不该被锁死在一家厂商身上。
在 ADIS 里,模型层和岗位、流程、数据是分开的。把一个岗位换到另一个模型,无论公有还是私有,只在模型层动;岗位、流程和它们处理的文件都不变。私有机器容量够的话,下一代开源模型可以直接换上去。
在银行,AI 的门槛不是它答不答得上来,而是事后每一个回答、每一次改动,都说得清楚。
银行该从哪里开始
从银行内部开始,不要先面对客户。最好的第一批候选,是规则清楚、量大、本来就有人复核的内部运营工作:
- 为运营团队准备对账和差异清单;
- 贷款与开户材料送到信贷人员之前,先检查是否齐全;
- 回答员工关于内部制度和流程的问题,并引用制度原文;
- 为负责的团队起草例行内部报告和监管报表的第一版。
每一种情况,都是数字员工准备、人来决定;成功的标准事先约定:团队出 20 到 50 道真实的题,上线前后各打一次分。
怎么开始
部署从两周的部署评估开始:一个部门、一条业务线,一份书面计划,针对这个部门回答上面五个问题——每个模型在哪儿跑、每个智能体能读什么、哪些动作要谁批准。这些都定下来,才开始建。
这个顺序比试点慢,但它是唯一经得起审计的顺序。
AIDC · AI Deployment CompanyAIDC · AI Deployment Company


