error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

Loading

The page is loading.

Please wait...


      KPMG’s Trusted AI Framework sets the principles by which banks should build and govern AI. This article is about what those principles look like at the customer interface, something that has moved to the top of the regulatory agenda following the July publication of the Mills Review, the FCA’s long-term review of AI in retail financial services.

      Most retail banking executive teams we speak with are grappling with how best to optimise the return on investment from agentic AI. This is unsurprising. The redesign of workflows for the agentic era remains a relatively new discipline and there is uncertainty about the degree to which this work will enable banks to become more efficient.

      There is much less focus on what the customer is supposed to see, feel and do differently when an agent is supporting customers in one way or another. While customer-facing agent deployment is in its relatively early stages, there is little doubt that soon they will be put into the service of customers to help them make more of their money in new and creative ways.

      To date, focus has overwhelmingly centred on the producer-side conversation – governance, model risk, regulatory compliance. The customer-side conversation is mostly absent, beyond a focus on protecting customer data.

      This partial focus on the impacts of AI – and agentic in particular – carries risk. Not that customers reject AI. They are already using it (heavily) for financial advice, just not from their bank. The Lloyds Banking Group Consumer Digital Index 2025 found that over 28 million adults are now using AI tools to help manage their money.1

      Rather the risk is that customers form their habits, mental models, and trust relationship with someone else’s AI, not those of the bank.

      There is also a second, significant challenge. The gap between using AI and trusting an agent to act on your behalf remains significant. The Mills Review’s Yonder Consulting survey of 5,026 UK adults found that while 55% identified at least one benefit of using AI for financial services, only 20% would use AI that acts autonomously.2 The gap between openness in principle and comfort with delegation in practice is where banks must focus on building customer readiness.

      Few applications of AI in banking offer a clearer path to value than customer engagement. Success can be measured in tangible outcomes—higher satisfaction, faster resolution of enquiries and greater product adoption. Because these objectives are observable and quantifiable, agentic systems can be trained and refined to improve them. That makes customer-facing functions a natural proving ground for AI. But banking depends as much ontrust as on efficiency. In a heavily regulated industry, the case for deploying AI is matched by the need for strong governance, oversight and accountability.

      The banks that win the agentic decade will be those that make AI-driven outcomes comprehensible, contestable and reversible from the customer’s point of view. A small number of practical interventions could move the dial.

      Paul Riseborough

      Partner, Financial Services Advisory

      KPMG in the UK


      Seven practical moves for customer readiness

      Customers can’t trust what they can’t see. Today, AI-touched journeys in retail banking are mostly indistinguishable from human or rules-based ones. That ambiguity risks being corrosive as the capability of AI evolves.

      In our view, customer interactions that involve an AI decision, from a service recommendation to an agentic action, should carry a persistent, plain-English marker. This should not be a legalistic disclosure but something as simple and recognisable as a virtual sticker.

      The food industry does this best. Food labelling that uses traffic-light systems on packaged food has been proven to work because it is glanceable, standardised and helpful. Energy ratings on appliances do the same job.

      For banking this could look like a small, consistent visual indicator alongside any AI-driven outcome (‘This decision was made by our AI assistant. Tap here to see how’). A necessary pre-step, of course, is to be clear on which decisions do in fact involve AI and where AI is being used in combination with human judgement. Such visual indicators need to have limits to be meaningful to customers. For example, nearly all retail credit decisions will involve machine learning, which could lead to ‘over-stickering’ and confusion.

      The test should be that any retail customer, in any channel, can tell at a glance which parts of their banking experience were AI-driven, within a given scope of activity defined by the bank. This moves the disclosure from a compliance overhead into a brand asset. We believe customers will reward visibility, not punish it.

      Most customers don’t know what banking tasks AI can helpfully do. The emerging nature of the technology means that they underestimate the simple stuff (budgeting, payment categorisation, summarising statements) and overestimate the complex stuff (regulated advice, tax planning). Because of this, explicit, customer-facing signposting of an agent’s scope creates trust (‘Our AI assistant can do A, B, C. It can suggest D, but you’ll need to confirm. It can’t do E’). In practical terms, banks should explore building into a mobile app or desktop home screen an “ask your agent” guide, refreshed as agent capability evolves. Clear escalation paths when the customer hits the edge of the agent’s competence should be engineered now. The first thing a customer should see when they enter an agent journey is an interstitial screen that says “here’s what I do”. Such clear signposting is the strongest evidence a firm can give that it is supporting, not advising.

      Customers will tolerate AI in routine interactions if they know a human is reachable when it matters. The single fastest way to lose trust in an AI system is to make that human path harder than it needs to be.

      A guaranteed, one-tap route from any agentic interaction to a named human channel, with the agent handing over the full context, avoiding the need for the customer to start again, builds trust and is something customers experience in other contexts. Premium experiences, for example with airlines, don’t mean that you avoid an IVR, but they often do mean that when you need a human, you reach one fast, and they already know who you are and what you need.

      In practical design terms, we are therefore likely to see a proliferation of “speak to someone” buttons, present on nearly all agent-mediated screens. The agent’s context, what the customer was trying to do, what was offered and where they got stuck, passes to the human automatically. The customer service assistant is then empowered to override the agent’s decision, on the spot, with a clear audit trail.

      Importantly, this is not about ‘more humans’ but it is that the availability of a human, and the quality of the handover, are made visible parts of the AI product.

      Our expectation is that customers will accept AI errors at roughly the rate they accept human errors, provided the recourse path is faster, clearer and demonstrably fair. We need to protect against AI-driven outcomes in retail banking having worse recourse than human ones because no one has thought to design the appeals flow.

      Banks need to provide customers with an explicit right to appeal any AI-driven decision, ensuring that they publish a Service Level Agreement, commit to a human reviewer and a written explanation of the outcome.

      This may make alarming reading for bank executives focused on delivering improvements in cost-to-income ratios and concerned about creating additional complaints and generalised customer service demand.

      Yet without the right to appeal, agent mistakes will not only drive complaints, they risk destroying the levels of trust in banking that provide banks with a unique position in their customer’s lives.

      A ‘challenge this decision’ link on AI-driven outcomes, with a guaranteed response time and a commitment to a human in the loop, would deliver accountability and unlock broader agent uses cases. Visible aggregate data on appeal volumes and reversal rates, published quarterly, would not only act as training data for agents but also support a commitment to transparency that customers will support.

      Customers must be able to inspect what the agent has done on their behalf and, under certain conditions, have the option to undo it. In the future, agentic systems will quietly accumulate actions that the customers can neither see nor reverse cleanly unless customers are better able to inspect what they have been doing.

      In practice, this could be a regular, plain-English digest of agent activity on customer’s accounts or interactions with the bank. In the future this could cover limits adjusted, subscriptions cancelled or spending categories changed. An ‘undo’ option on every line where unwinding is low stakes and feasible would put customers in control.

      The best analogy here is Apple’s Screen Time weekly summary or the Google Your Activity digest. Both work because they prioritise disclosure, summarise behaviour the user wasn’t tracking and let customers act in one tap.

      A weekly in-app digest, opted-into by default, summarising every action the customer’s agent has taken, with clear undo paths, can help banks build the cleanest evidence base for Consumer Duty outcomes testing and bring home the value of agents to the banking relationships (‘your agent has saved you £43 this month by automatically sweeping balances into your current account’). This would also serve as a clear example of putting not just Humans in the Loop, but Customers in the Lead.

      Most consent debates in AI assume the customer is being asked to agree to an agent’s behaviour after the fact. The better model is to let customers pre-commit to what they want and use the agent to honour those pre-commitments.

      A ‘ground rules’ interface where the customer sets standing instructions for what the agent can and cannot do would be powerful. As customer-facing agents evolve, this could cover spending caps, subscription reviews and even times of the day the agent is forbidden from acting. The analogy here is smart-thermostat providers enabling pre-sets or streaming services providing parental control systems. They work because they put the customer in the position of control.

      Such a ‘ground rules hub’, discoverable at a journey or account summary page, with sensible defaults that reflect both customer protection and Consumer Duty foreseeable-harm logic, are inevitable if banks are to explore new and creative ways to put agents in the service of customers. This is also the cleanest way to ensure vulnerable-customer policy drives actual product behaviour, with vulnerability characteristics becoming tighter default pre-commitments not just status flags.

      The previous six moves all have the potential to generate one thing: human escalations.  A customer who taps ‘speak to someone’ after a stickered AI decision, a customer who appeals an agent’s account configuration move, or a customer whose pre-commitment guardrails were tripped will all ladder up to a colleague. If that colleague cannot see what the agent did, cannot explain it, and confidently override it, these new strategies just won’t work.

      The frontline readiness gap is large and well documented. The Financial Services Skills Commission’s Annual Skills Report 2026 found that AI skills are among the largest supply-demand gaps in the sector.1 For a UK bank with several thousand customer-facing colleagues across telephony, branch, complaints, and relationship management, the implication is that the people most likely to receive an AI related escalation are the last prepared to resolve one.

      A bank-wide frontline AI literacy programme built around three capabilities – comprehension, override authority, and vulnerability recognition, so that colleagues are trained to spot vulnerability indicators that an agent have missed – can position banks to create a differentiated position on trust.

      This frontline enablement is the operationally grounded reality of the human oversight pillar of KPMG’s Trusted AI framework. Human oversight as a principle is meaningless if the humans on the other end of the escalation cannot see what the agent did or override it confidently. Upskilling is the mechanism by which bank accountability becomes a tangible, customer-side experience.



      Trust expands the agentic envelope

      The seven moves discussed here could be viewed as constraints on agentic AI ambition. In reality, they are the opposite. The ceiling on agentic AI is not technical capability but customer trust. A bank with a customer who can see, contest and unwind an agent’s actions will tolerate agent behaviour at several times the autonomy of a bank without that architecture. This is where trust evolves beyond recommendation into transaction authority, unlocking the true agentic value pool.

      The Mills Review formalises this dynamic through an autonomy spectrum – five stages ranging from AI as a tool (the human as operator) through to AI as a collaborator, consultant and approver, to AI as observer, acting continuously within pre-set limits. The Review concludes that each step along the spectrum places greater weight on consent, accountability and redress.

      The strategic prize

      When a customer’s financial relationship is intermediated by a third-party AI such as a Gemini-powered price comparison flow or an OpenAI-fronted budgeting agent, the bank risks quickly becoming a utility on someone else’s technology stack. Over time, banks risk becoming decreasingly relevant in the customer’s mind.

      Banks can defend their franchise by being the AI the customer trusts most for their own money. The challenge, therefore, is a customer experience one.

      Regulators are alive to both the risks and the opportunities. The FCA has been explicit that it will enforce the Senior Managers Regime and Consumer Duty on AI-driven decision making. The window for incumbents to define the customer-comprehension standard, before the regulator does it for them, is closing.

      KPMG’s Trusted AI framework rests on ten ethical pillars across the AI lifecycle – fairness, transparency, explainability, accountability, data integrity, reliability, security, safety, privacy and sustainability. These are the right producer-side commitments. They are the foundation on which every bank’s agentic AI estate should be built.

      They also recognise that responsible AI architecture is not the same as comprehensible AI experience. The seven practical moves outlined here are the design choices that translate transparency into stickering, explainability into signposting, accountability into a right to appeal, and human oversight into a right to a human.

      Each play is a way of making one of the Trusted AI pillars visible, tangible and actionable at the moment a customer is interacting with an agent.

      The Mills Review makes clear that the regulator’s own agenda over the coming years will be built around the same premise: that AI in retail financial services succeeds only when the customer can see it, understand it, and challenge it. Banks that begin building the seven plays now will not only be ready for those regulatory shifts, but they will also play a role in defining them.



      How to get started

      Most banks have legacy AI-touched journeys – chatbots, fraud cases, credit decisioning, marketing personalisation – that are not signposted today. Stickering and signposting should be retrofitted onto the existing estate before any new agentic use cases go live. This is a 90-day exercise, mostly user experience and content, not technology.

      The human route, appeal and weekly digest should be designed into the next agentic use cases taken to market, not retrofitted afterwards. Pre-commitments offer banks an important way to differentiate themselves and should be thought of as a competitive asset. Banks that get pre-commitment design right within the next 12 months will have something hyperscalers do not: customer-set boundaries for a regulated environment. This is hugely valuable.

      Concurrent with all this, a periodic or real time tracker, monitoring comfort with autonomous AI, willingness to grant the bank’s agents specific permissions, complaint volumes by AI decision types, appeal volumes and reversal rates will help leaders to understand the degree to which customers trust and find utility in agentic processes, giving product teams and boards data on which to make future decisions.

      Customers will accept AI in their financial lives. They will not accept being unable to see it, question it, or unwind it. The work to give them all three is largely not technical, and the banks that do it first will define what trusted agentic banking looks like for everyone else.



      1 Lloyds Banking Group Consumer Digital Index 2025, 31 October 2025.

      2 The Mills Review: AI and the future of financial services, Financial Conduct Authority, July 2026, p.39

      3 Financial Services Skills Commission, Annual Skills Report, March 2026.

      Our AI and machine learning insights

      Something went wrong

      Oops!! Something went wrong, please try again


      MTD

      Get in touch


      Discover why organisations across the UK trust KPMG to make the difference and how we can help you to do the same.