Retail, corporate and investment banks, payment institutions

Claude AI agents for banking

Preparing KYC files, building credit analyses, tracking regulation: Claude agents connected to your tools, within DORA and the EU AI Act, with the decisions that commit a customer left to your teams.

DORAEU AI ActAMLbanking secrecy
Definition

An AI agent for banking is a Claude agent that handles the document-heavy, repetitive work of a bank: assembling know-your-customer files, preparing credit analyses, monitoring regulation and answering first-level requests. It operates inside the institution’s DORA perimeter and leaves every decision that commits a customer to the bank’s own teams.

Industry framework

The rules that shape an agent project

A bank does not deploy an agent the way an unregulated company does. Four frameworks weigh on every project, and they need reading before the first line of code.

01

DORA and ICT providers

The Digital Operational Resilience Act (EU 2022/2554), in application since 17 January 2025, governs the ICT risks of financial entities, including those coming from their providers. An agent calling an externally hosted model falls within it: contractual clauses, register of information and resilience testing, plus an exit strategy as soon as the service supports a critical or important function.

02

Credit scoring of individuals is high-risk

Annex III of the EU AI Act lists systems that evaluate the creditworthiness of natural persons or establish their credit score as high-risk, with financial fraud detection explicitly excluded. The corresponding obligations apply from 2 December 2027: risk management, documentation, human oversight, traceability.

03

Anti-money laundering duties

AML rules require banks to know their customers, monitor transactions and report suspicions to the national financial intelligence unit. An agent can gather documents, spot an inconsistency or draft a note. Qualifying a suspicion and filing the report remain human acts, justified and logged.

04

Banking secrecy and customer data

Professional secrecy rules and the GDPR require full control over where data travels: chosen cloud environment, hosting region, contractual retention terms, access logging. These choices belong to the scoping phase, not to the aftermath of a pilot.

Full EU AI Act timeline →
Use cases

Where a Claude agent adds the most value

KYC files and periodic reviews

The agent collects documents, checks their consistency, screens watchlists and prepares the file for the compliance officer. Periodic reviews, often overdue, start from a file that is already built.

Corporate credit analysis

Tax returns, accounts, sector notes: the agent assembles the material and drafts a first reasoned analysis with its sources. The analyst reviews, completes and recommends. The credit committee decides.

Regulatory watch and compliance

EU texts, EBA guidelines, national supervisor publications: the agent flags what changes, identifies the internal procedures affected and drafts an impact note for compliance.

Support for advisers and customer service

First-level answers, meeting preparation, customer history summaries. Customers are told they are talking to an AI, as the EU AI Act has required since 2 August 2026, and sensitive requests go to an adviser.

Deployment

Deploying without taking chances

01Classify each use case before building it

High-risk under the AI Act, in scope of DORA, covered by banking secrecy: classification drives the architecture, the level of control and the documentation. It happens upfront, with compliance and the CISO.

02Keep the decision where it commits someone

Granting credit, onboarding a customer, filing a suspicion report, handling a complaint: the agent prepares, an authorised person decides. That is also the logic of Article 22 of the GDPR, which strictly limits decisions based solely on automated processing that produce legal or similarly significant effects on a person.

03Log everything for audit and supervision

Every agent action is logged with its source, the model version and the instruction version. Internal audit and the supervisor alike can reconstruct what was done, by whom and on what basis.

Demos

Agents to try for this industry

Go further

Related pages

FAQ

Frequently asked questions

Can an AI agent decide on a loan on its own?
We do not recommend it. For individuals, creditworthiness assessment is high-risk under the EU AI Act, and the GDPR restricts fully automated decisions with legal effects. The agent prepares and argues the analysis; the analyst and the committee decide.
Does DORA apply when a bank uses Claude?
Yes, as soon as the model is supplied by an ICT third-party service provider. Depending on the architecture (Anthropic API or a cloud platform such as Amazon Bedrock, Google Cloud or Microsoft Foundry), the contractual provider changes, but the requirements stay: register of information and contractual clauses in every case, concentration risk assessment and exit strategy when the service supports a critical or important function.
Is our customer data used to train the models?
On Anthropic’s commercial offerings, data sent to the models is not used for training by default. You still need to check the retention period that applies to the model and plan you use, and record it in your compliance file.
Which use case should a bank start with?
An internal, document-based and reversible one: regulatory watch, procedure summaries, KYC files reviewed by a person. It validates the architecture, the logs and the governance before touching a process that affects customers or credit.
How does Koneetiv govern an agent in a bank?
With LOOP™, our governance method aligned with the EU AI Act, ISO/IEC 42001 and the NIST AI RMF: every agent action is classified by risk level, with proportionate human oversight and an action log that audit can consult.
Let’s talk about your context

A use case in your industry?

We start from your processes and your regulatory constraints to find the first agent worth building, and the framework that goes with it.

Book a call →