Ask a good underwriter why they approved someone three years ago, and they can tell you. The file, the judgement call, the reasoning at the time. That answer is the thing financial regulation is actually built on. Not the decision itself, but the ability to account for it, faithfully, long after the fact.
In Credit Craft, the piece that precedes this one, I argued that the craft of lending is moving from the desk to the design. The person doing the judging is no longer sitting at a keyboard reviewing a file. They are the person who designed the system that does the reviewing, and they remain on the hook for what it does. That idea holds up well against automation. Agentic systems test whether it holds up at all.
Three things that get blurred together
It helps to separate three things that get blurred together in most conversations about AI and lending. Automated underwriting is decades old: a system scores an application against fixed rules, and a human or a simpler system approves it. Agentic underwriting is a different kind of thing. Here, the system gathers its own evidence. It pulls a live bank feed, verifies income, checks for fraud signals, reasons across all of it, and then acts: it opens the facility, sets the limit, prices the loan, without a person in that specific loop. Agentic lending widens that same principle across the whole relationship with the customer, not just the initial decision but the ongoing management of the exposure: adjusting limits, handling collections, restructuring debt as circumstances change.
The case for agentic, stated plainly
The case for this is genuinely strong, and worth stating plainly rather than dismissing. There are borrowers a traditional credit scorecard simply cannot see clearly: people with too little conventional credit history to score well, who can be assessed instead on live financial evidence a human underwriter would never have the time to gather and weigh. Decisions arrive in seconds rather than days. Consistency improves, because the system doesn’t have an off day the way a tired underwriter on a Friday afternoon does. In the US, Upstart runs 80 to 90% of its approvals fully automated. OppFi is close to 79% instant. Zest AI sits at 70 to 83% inside credit unions, though it is worth noting those members were pre-selected savers long before the model ever assessed them, so some of that headline figure reflects selection upstream rather than the model itself. No UK lender has publicly disclosed automation rates for consumer credit decisions at a scale comparable to those examples. That gap will not persist for long.
Notice, though, where this technology is most commercially attractive: high volume, thin margins, fast decisions, and often the more financially vulnerable end of the borrower base. The cases where speed is most valuable to a lender are frequently the cases with the least tolerance for error. The selling point and the risk sit in the same sentence.
Reconstruction of the decision, well after the fact
A human underwriter can be asked, in front of the Financial Ombudsman, two years after the event: why this person, why this rate, why the yes. They can answer, because the reasoning lived in a person who is still available to explain it. An agentic system that pulled live data, reasoned across it, and acted within four hundred milliseconds has to be able to rebuild that same account on demand. Not an approximate summary. The exact inputs it used, the exact reasoning it followed, and the exact version of the lending policy in force on that specific day, long after the underlying data has moved on and the model itself has likely been retrained more than once.
This is what I call point-in-time reconstruction: the requirement that whoever is accountable for a decision must be able to reconstruct the system, the model, and the policy exactly as they stood at the moment that specific decision was made, not as they stand today. It is not a modelling problem you solve with a cleverer algorithm. It is an architectural one. It requires versioned policy, captured inputs, reproducible reasoning, and a trail that cannot be quietly rewritten after the fact. The decision itself takes a moment. The evidence of how it was reached has to survive for years.
The regulator arrives at the same place
The UK’s Financial Conduct Authority arrives at much the same conclusion. On 6 July 2026 it published the Mills Review, two years in development under Sheldon Mills, examining how AI will reshape UK retail financial services out to 2030. Its own organising idea is a five-stage spectrum describing how much genuine human control remains as a system takes on more responsibility: Operator, where AI is simply a tool a person uses directly; Collaborator; Consultant; Approver, where the system prepares an action and a human formally signs it off; and Observer, where the system acts continuously inside pre-agreed limits and a human merely watches the outcomes roll in. Human control thins measurably at every stage along that spectrum. The Review names, in its own words, exactly where it becomes structurally difficult: at Approver and Observer level, “meaningful human control likely to be difficult to evidence.” And on the specific reconstruction problem, independently and almost word for word: “a useful answer is not enough if the basis for it cannot be reconstructed.”
This is precisely where the reassuring phrase “human in the loop” quietly stops meaning anything. Nobody can meaningfully review a thousand automated decisions a second. Placing a person beside the machine purely to nod along is not oversight. It is theatre: accountability performed for show rather than actually exercised. The harder, more honest position is to be accountable for a system you cannot individually watch in real time: on the hook for how it was designed, not for each decision it makes. That only works, though, if the design can hand back a full account of its own decision process the moment anyone (a regulator, an Ombudsman, or a harmed customer) asks for one.
The frameworks still apply. The question is whether the code can answer to them.
Two of the UK’s core regulatory tools speak directly to this. The Consumer Duty requires firms to demonstrate that customers actually received good outcomes, not merely that a compliant-looking process was followed. The Senior Managers and Certification Regime, commonly shortened to SM&CR, requires one named, accountable individual to stand personally behind each area of regulated activity. Neither rule was written with a system in mind that generates its own evidence and acts before any person has had the chance to read it. The Mills Review’s own conclusion, delivered at its 6 July launch, was not a call for an entirely new rulebook. As Ashley Alder, the FCA’s Chair, put it that day: “The principles-based, outcomes focussed approach we’ve taken on AI, relying on the Consumer Duty and Senior Managers Regime, has been critical to us doing so.” The existing frameworks still apply in full. The open question is simply whether the code underneath a lender’s systems can actually answer to them when asked.
Nikhil Rathi, the FCA’s chief executive, had already signalled where this was heading a fortnight earlier. In a speech to techUK on 24 June, ahead of the Review’s publication, he told an audience of AI and financial services leaders that as systems move from advising towards genuinely transacting, “accountability for regulated activities and outcomes must remain clear.” That is the right principle to hold onto. It is also, in practice, the harder one to satisfy. Clear accountability for a decision made and executed in milliseconds is not something a governance policy alone can deliver. It is a requirement that has to be designed directly into the architecture of the system itself.
Build the agent. Own the design.
So the lenders who succeed through the agentic decade will not be the ones fielding the boldest models. They will be the ones who can still explain themselves, fully and specifically, on demand. The decision happens in a moment. The account of that decision has to survive for years. The agent can own the speed. A named, accountable human has to own the design, and be able to say why.
Build the agent. Just don’t build the bank clerk who couldn’t say why. Faster, and at scale, is only ever half the job.
Francis Hellawell
I solve hard problems in banking.