Banks Need Audit Trails Before AI Agents Get Autonomy
iTNews Asia’s interview with 0G Labs CEO Michael Heinrich framed bank AI agent adoption as a control problem built around audit trails, identity, memory and inline governance.

Banks moving AI agents out of pilots face a proof problem before they face a model problem: iTNews Asia carried an interview with 0G Labs chief executive Michael Heinrich in which the main adoption barrier was evidence that autonomous systems can be trusted, controlled and audited.
The issue begins with the record each agent leaves behind.
Heinrich argued that every action by a banking AI agent has to produce evidence strong enough for compliance teams, auditors and regulators.
A useful audit trail needs to be complete, tamper-evident and reproducible, covering successful actions as well as blocked or failed attempts and allowing a decision to be replayed with the same inputs, model version and policy set.
That framing changes how banks would introduce autonomy.
Rather than hand broad authority to an agent once the underlying model appears capable, banks would phase autonomy through individual processes, beginning where decisions can be reversed and only later extending it to higher-consequence work.
The control path matters because financial institutions may eventually have thousands of automated decisions happening at once across connected workflows.
Model selection becomes a smaller part of the stack under that approach.
Heinrich described the model as the most commoditised component and put more weight on durable memory, orchestration, identity, permissions, logging and enforcement.
A powerful model without memory or accountability becomes an operational liability, not a deployable asset, because the institution cannot explain or constrain what it did.
Existing bank controls would also need to run during execution rather than sit as quarterly policy checks.
Least privilege, segregation of duties and approval steps have to be translated into agent controls: scoped and expiring credentials instead of borrowed employee permissions, second approval for irreversible actions, separation between the system acting and the system recording the action, and safeguards that stop an agent from repeating a credit, payment or other transaction-level action.
Shadow AI adds another pressure point.
Staff use of consumer AI with customer data and unsanctioned internal agents can leave sensitive work outside formal controls.
A ban alone pushes that activity out of sight; sanctioned internal routes bring the work back inside an auditable perimeter if they are easier and more effective than unsupervised alternatives.
The early payoff may come from the less visible parts of banking rather than customer-facing chatbots.
Reconciliation, compliance review, fraud and anti-money-laundering triage, settlement, payment exception handling, routine credit pre-checks and regulatory report assembly all fit the type of bounded, evidence-heavy work Heinrich expects agents to take on first.
That shift would also change board metrics.
Instead of judging AI primarily by chatbot deflection or satisfaction scores, banks would need to track autonomy rates, error and reversal rates, time to detect and correct problems, auditability, blocked actions and the cost of completed work against a human baseline.
If models keep becoming easier to access, the defensible advantage moves to proprietary data and the infrastructure for safe deployment in regulated settings.
The practical test is whether a bank can clear new agent workflows through compliance quickly while preserving identity, durable memory, verifiable execution and inline controls.




















