Automation

Propose, Check, Release: What the Payment Agents of Sibos 2026 Teach About Customer Dialogue

Five large banks showed production AI agents at Sibos 2026: the model proposes, rules check, a person releases. The same pattern for customer dialogue.

•

acceleraid Redaktion

4 min read

Cutaway of a bank building with three floors and a conveyor belt: a robot checks documents with a magnifying glass on the ground floor, the belt passes a mechanical checking gate in the middle, a banker stamps the cards on the top floor

At Sibos 2026, held in Miami from 28 September to 1 October, five large banks described how AI agents work in their production environments. The examples come from payment repair, securities processing, lending onboarding and trade document checking. They share one feature that reaches well beyond the back office: nowhere does a model release a payment on its own. The agent proposes, deterministic rules check, a person decides. That pattern transfers to customer dialogue, which is exactly where it is still often missing.

What the banks showed

At BNY, the "digital employee" Eliza reads the fields of failed payments, checks ISO 20022 syntax and assesses whether the instruction makes sense. According to a customer story published by Microsoft, a single digital employee handles more than ten percent of the bank's global repair cases; Forrester counts more than 130 such agents in production, each action logged with its rationale. BNP Paribas cut a securities-services process from ten steps to six; within a few weeks the agent handled 80 to 85 percent of the work, with every model interaction passing through an observability layer with compliance, legal and HR guardrails. Deutsche Bank's Ada framework onboarded a corporate client and issued a loan in one day where the process normally takes a month; this was a single client. HSBC checks trade documents with "Smart Checking" in Hong Kong, the UAE and the UK; exceptions and high-value transactions stay with people. Citi said it walks supervisors through every use case, including whether the human sits "in, on or out of the loop".

Bank

Use case

Documented effect

Release

BNY

Payment repair (Eliza)

over 10% of repair cases handled by one agent (vendor figure)

Human

BNP Paribas

Securities processing

6 steps instead of 10; 80–85% of the work within weeks

Guardrails + human

Deutsche Bank

Lending onboarding (Ada)

one day instead of one month (one client)

Human

HSBC

Trade documents (Smart Checking)

live in three markets, no volume given

Human on exceptions

Finastra

Repair Recommendations (since 30 Sept)

checked against Swift, Fedwire, SEPA, UPI, Nexus

Human

The figures vary in robustness. The BNY number comes from the technology vendor, HSBC gives no volumes, Deutsche Bank describes a single case. What is robust is the architecture, and it was the same everywhere.

Three layers, one order

BNY summed up the pattern in one sentence: AI does the reasoning, deterministic guardrails do the vetting, and people make the judgement calls. Finastra, which launched a repair recommendation product on 30 September, builds in the same three steps: the suggestion is validated against Swift, Fedwire, SEPA, UPI and Nexus rules, and the final action remains subject to human review and approval.

Vanessa Lin of Goldman Sachs described at the same conference what the third layer has to deliver: if an agent independently triggers a ten-million-dollar payment, the bank must be able to explain why, which controls applied and how the sequence can be reconstructed. Citi CEO Jane Fraser called for safety controls before rollout and, alongside "know your customer", put agent authentication on the table: "know your agent".


Three layers in payments and in customer dialogue

Transferring the pattern to customer dialogue

In payments, separating the three layers is natural, because scheme rules are unambiguous and an error costs money immediately. In customer dialogue it is not. There, proposal, check and release often merge into one tool: the model picks the offer, writes the text and sends it. The Sibos examples suggest a different division.

The first layer is the proposal. An agent detects a signal, such as an unusual account movement or an expiring contract, and proposes the next sensible action. This is where model intelligence belongs. The second layer is deterministic: consent, contact rules, frequency, pre-approved text components and product eligibility are checked as fixed rules, not weighed by the model. What scheme rules are in payments, consent and contact policy are here. The third layer is human release for anything that crosses a boundary: new wording, sensitive customer groups, large amounts, complaint cases. Routine cases within the boundaries flow through; logging of signal, proposal, check result and decision applies to all of them.

The benefit of this division is not only safety. BNP Paribas reported that staff were taken off the old mailbox entirely, so adoption was total from day one. Whoever takes the rules out of the model can change them without touching the model, and can show the supervisor where the human sits. That is precisely what Citi requires of every use case.

Five takeaways

  1. Five large banks showed production AI agents at Sibos 2026; in no case does a model release a payment on its own.

  2. The shared pattern has three layers: the model proposes, deterministic rules check, people make the judgement calls.

  3. The impact figures vary in robustness: a vendor figure at BNY, a single case at Deutsche Bank, no volumes at HSBC. The architecture is the robust finding.

  4. In customer dialogue, consent, contact rules and approved components take the role of scheme rules; they belong as a fixed check between proposal and send.

  5. Taking the rules out of the model makes them independently changeable, every decision reconstructable, and the human's place in the process visible to the supervisor.

Illustration: AI-generated. AI-assisted content: We use AI technologies and automated agents in the creation of our articles, including from Microsoft, Google, OpenAI, Anthropic and other providers. Topics, editorial direction and final approval remain with our team.

AI-assisted content: In the creation of our articles, we utilize AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers. Topics, editorial direction, and final approval remain with our team.

© 2026 Adtelligence GmbH. ACCELERAID is a brand of Adtelligence GmbH.

AI-assisted content: In the creation of our articles, we utilize AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers. Topics, editorial direction, and final approval remain with our team.

© 2026 Adtelligence GmbH. ACCELERAID is a brand of Adtelligence GmbH.

AI-assisted content: In the creation of our articles, we utilize AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers. Topics, editorial direction, and final approval remain with our team.

© 2026 Adtelligence GmbH. ACCELERAID is a brand of Adtelligence GmbH.