AI agents are no longer just automation tools - they are becoming a new class of digital participants in the financial ecosystem. Banks are moving from standalone AI models to autonomous agents that plan actions, use external tools, interact with banking systems and other agents, and initiate financial transactions. But when AI stops advising and starts acting, the nature of responsibility changes: new risks emerge across the entire agent lifecycle, from data governance and manipulation resistance to control over autonomous actions, explainability, and the allocation of liability between humans, organizations, and AI vendors.
This talk examines how regulators worldwide are responding - and why most are not creating separate AI-agent laws, but extending existing financial-sector requirements to new AI systems, from the EU's comprehensive AI legislation to the sectoral approaches of the US, UK, and Singapore. Drawing on the current regulatory framework of Uzbekistan - Central Bank requirements, banking secrecy, personal data, and information security legislation - we will show how to translate existing rules into system architecture: Governance by Design and Compliant by Design.

