When a bank speaks about a digital employee, it is always about cost cutting in the first place. Everybody expects that they will cut costs for human employees, and second, they believe they will have higher quality. That second part is a long way off. The first impression of implementing support with AI was terrible for everybody, and for now everybody is afraid, or writes the first message to the AI bot and then calls a human or leaves it to a human, because the trust is still not there. There are a lot of poor implementations, although the technology already allows beautiful services here.
How a digital employee is built inside a bank
A digital employee is a layered system: a model that reasons, an orchestration layer that calls tools and holds memory, and a governance wrapper that decides what the thing may do alone. Four properties separate it from the robotic process automation banks already run:
- it handles input that does not fit a fixed template
- it plans several steps rather than executing one
- it calls tools and queries systems on the way
- it escalates on its own confidence rather than on an error
A lot of decisions and a lot of optimisation could be done with machine learning, with strict models or automatic models, without AI in the marketing sense and without a language model. But that is boring, and it is difficult to sell, and therefore everybody is trying to add AI everywhere.
I have seen several services where developers deleted the search field and added an “ask AI” field instead. Terribly inconvenient. It makes mistakes, you have to explain what you want, when I want to just search for part of the keywords to find the necessary materials. That is the failure mode in miniature, and it is what our AI integration work spends its first conversation ruling out.
I agree with using AI for RPA-like automation over legacy systems. That is fine, and it is our honest approach. What I do not agree with is when the product overweights common sense. It is sometimes a good idea to implement RPA to cover a legacy system, but the permanent solution should be APIs and real automation. Some vendors here are not lying, but of course they want their services to be in usage for a long time.
The compliance wrapper: why governance architecture comes before features
In compliance, the most important and the most expensive part is the first start and the growth of AI usage. On one hand you should keep your compliance staff and ask them to teach the model and to monitor how it works. Only after that can you minimise human usage. Banks that plan the saving before that ramp are planning a number they have not earned yet.
The EU AI Act makes automatic event logging a build-time property under Article 12, and Article 14 requires human oversight to be designed into the system, naming automation bias in the legal text. Under Article 25(1), a bank that puts its own name on a bought high-risk system, or modifies it substantially, becomes its provider with the full set of provider obligations. Under DORA, an exit plan for a critical ICT service has to be comprehensive, documented and sufficiently tested, and the European Supervisory Authorities named the first 19 critical ICT third-party providers on 18 November 2025.
Traceability and security in these operations are crucial. If they are not in the architecture, it will be impossible to implement at later stages. The security side of giving an agent real access is covered separately in smart agents and secure banking.
Building the layer the agents will plug into?
Our free practitioner guide sets out the orchestration-layer pattern we use for core banking integration: one middle-tier orchestrator, one wrapper per legacy system, collect-then-distribute for long flows, with two anonymised field examples and a build checklist.
Where banks are deploying them and how to read the results
Vendors always show successful scenarios. They show how it works in a demo, how beautifully it is organised, and they even go to active operations like a transfer between accounts through a chatbot. The main problem is how to integrate it into a real ecosystem, into the real infrastructure of the bank. The second problem is the impression of the customer: how they will measure and how they will ensure that customers are still happy. I think that is the main metric for implementing support services.
Adoption is not the constraint. More than 85% of the banks under European banking supervision already use AI in some form, the ECB reported in February 2026. What the same supervisor found when it looked closely is more interesting: in workshops with 13 supervised banks across nine countries in 2025, no bank allowed self-learning after deployment, and none used generative AI for credit scoring or fraud detection, citing development time, cost and trustworthiness.
That finding is read wrongly more often than not. Self-learning is not the same as retraining. Learning and updating models after deployment is necessary, and without it you will not be able to go far. What those banks refuse is letting a model change itself while it is running, which is a different thing entirely, and the ECB's own guide to internal models sets out the alternative: monitoring that recognises drift and prevents a material change being implemented automatically. Models are retrained. They are not left to retrain themselves in production.
On generative models I believe it is better to use them, because there are a lot of stages where you have documents that are not strict as an input, and you still have to consider them and take them into account.
Why the productivity numbers need scrutiny
The cost-cutting conversation underestimates something. Banks should allow people to grow. The new model of bank staff is not people who are dealing with Excel spreadsheets and putting one number from one row to another, but people who are comfortable with AI, who understand how guardrails work, and who take affordable and cleverly estimated risk.
Klarna is the case both sides quote. In February 2024 it said its assistant had handled 2.3 million conversations in its first month, two thirds of its customer service chats, the equivalent work of 700 full-time agents. By May 2025 the chief executive told Bloomberg that cost had become too dominant a factor and quality had suffered, and the company began hiring people again. Any figure from the first announcement has to be quoted with the second.
When choosing a vendor, I would focus on routing between models rather than on the model itself, and on the possibility to run the engine fully on premise, or in a properly controlled cloud. Those two decisions are architectural. Traceability is the third, and it is the one that cannot be retrofitted.
AI and banking work we have shipped
Weighing up a digital employee for your bank?
WislaCode builds regulated banking software where the governance layer is designed with the feature, not after it: decision logging, escalation thresholds and the integration underneath them.
What is an AI-powered digital employee in banking?
A software agent that performs a defined banking task across several steps, calling systems and escalating when its confidence drops. It differs from robotic process automation in that it handles input which does not fit a template. It differs from a chatbot in that it acts rather than answers.
Do banks actually save money with digital employees?
Eventually, and not at the start. The most expensive phase is the first start and the growth of AI usage, when compliance staff have to teach the model and monitor how it works before human involvement can be reduced. A saving booked before that ramp is a forecast, not a result.
Should every automation in a bank use AI?
No. A lot of decisions and a lot of optimisation can be done with machine learning and ordinary automatic models, without a language model. That approach is harder to sell, which is why so much of what is marketed as an agent does not need to be one.
Do AI models in banks keep learning after they go live?
Not by themselves. In the ECB's 2025 workshops with 13 supervised banks, none allowed self-learning after deployment. That is not the same as not retraining: models are retrained, and have to be, but as a governed change. The ECB's guide to internal models expects monitoring that recognises drift and prevents a material change being implemented automatically.
What should a bank look for when choosing a digital employee vendor?
Routing between models rather than a single model, and the option to run the engine fully on premise or in a properly controlled cloud. Then traceability, which has to be in the architecture from the start because it cannot be added at a later stage.
What are the regulatory obligations for deploying an AI agent in an EU bank?
The AI Act requires automatic event logging under Article 12 and human oversight designed into the system under Article 14, and under Article 25(1) a bank that brands or substantially modifies a bought high-risk system becomes its provider. DORA adds the register of ICT arrangements, the concentration assessment before contracting and an exit plan that has been tested.




