Sirma was at Nordic Fintech Week in Copenhagen (21–25 September), where agentic AI was a recurring theme. AI agents can now act on live financial systems. What most banks and businesses have not yet settled is how to govern them: what an agent may do, on whose data, and who answers when it gets something wrong. Three developments from late September show why that question can no longer wait.
Three signals from one week
-
Agents can pay. On the opening day of Nordic Fintech Week, Danske Bank and Mastercard completed Denmark’s first payment made by an AI agent, on live card rails.
-
Settlement is going digital. The Eurosystem launched Pontes, which settles tokenized assets in central bank money.
-
Banks want rules. Six global banks, including ING, NatWest and Bank of America, published joint principles for agentic commerce.
The common thread: delegated action needs governed infrastructure
Each development moves a financial action one step further from a person pressing a button. An agent initiates a purchase. A distributed ledger settles a tokenized asset. Both now work on live infrastructure.
What is not yet settled is accountability. The banks’ principles state the questions plainly: whether an agent is acting in the customer’s interest, how much authority it holds, and who is accountable if it buys the wrong item, exceeds a spending limit or falls victim to fraud. Visa research published in September found that 23% of US consumers trust generative AI with payment transactions, rising to 61% when Visa secures the transaction. Trust follows control.
Supervisors frame it the same way. The Danish Financial Supervisory Authority’s Strategy 2030 names technological opportunities and risks as one of three focus areas, and is explicit that adopting new technology must not come at the expense of resilience or customer protection.
What this means beyond the pilots
For most European institutions, the first agent in production will not be a shopping assistant. It will sit in operations: preparing a regulatory report, reviewing a credit file, triaging a dispute, answering an internal policy question. Тhe questions debated at Nordic Fintech Week apply there just as directly.

Four requirements follow:
-
Bounded authority. Every agent acts under a defined role, within limits the institution sets and can change.
-
Grounding in the institution’s own data. Answers and actions draw on the organization’s documents, systems and policies, not on a model’s general knowledge.
-
A reconstructable record. Each step an agent takes can be traced for a supervisor, an auditor or a disputed customer claim.
-
A deliberate choice of infrastructure. Where models run, and under which jurisdiction the data sits, is a governance decision as much as a technical one.
Where Sirma fits
Sirma has built software for banks and financial institutions since 1992. Sirma.AI Enterprise, our sovereign agentic AI platform, is designed around the four requirements above.
Agents are grounded in the institution’s own data and run through a governed orchestration layer that controls what each agent can access and do. The platform deploys on-premise, air-gapped or in a European cloud, and works with more than 500 AI models, so the institution decides which model handles which task. It is built for compliance with GDPR, the EU AI Act and NIS2.
The Nordic market has shown that agents can transact live rails. The next step for European institutions is to ensure that whenever an agent acts, they can explain what it did, why, and on whose authority.
Talk to our team about deploying governed AI agents on your own infrastructure: sirma.ai