Trend Shift

NAB Moves Agentic AI Toward Customer Deployment Tests

NAB is testing security and operational guardrails for agentic AI before deploying it to banking customers; employees using approved AI tools have risen from 15,000 to about 25,000.

National Australia Bank is moving agentic AI from employee productivity tools toward a stage of control validation before customer deployment. This does not mean agents are already serving customers at scale, but it suggests that the central question for regulated banks is shifting from whether to adopt AI to whether agents can be shown to remain controllable across permission, operational and failure scenarios.

From internal projects to deployment preparation

In FY25, NAB still described agentic AI as an AI-of-tomorrow priority. It had more than 100 AI projects in production or the pipeline, and more than 15,000 employees using AI to reduce routine work. By 1H26, NAB said its agentic platform supported use cases on a single scalable platform, while approved AI tools reached about 25,000 employees. Bloomberg reported that the bank will soon test security and operational guardrails in preparation for broader customer deployment.

Guardrails become the operating mechanism

NAB links its agentic platform to a modern data platform, multicloud infrastructure and management structures responsible for policy, controls, oversight and performance. That design treats agents as participants in operating workflows rather than standalone chat interfaces. Customer-facing agents may access data, invoke systems and take actions, making identity, permissions, audit trails and human takeover capabilities central to turning model output into an operable service. Wider employee use also makes those controls an ongoing operational requirement.

Bank buying criteria may shift to verifiable controls

If NAB’s testing advances to controlled customer deployment, agentic AI competition may increasingly depend on whether governance components can fit existing bank systems, rather than task-completion demonstrations alone. The strongest countercase comes from APRA, which found that AI adoption at major regulated institutions was advancing faster than governance, risk management, assurance and operational resilience. It calls for fallback processes, privileged-access controls, testing and controls for agentic workflows where AI is business-critical.

What to watch next

Watch for NAB to identify its first customer-facing agent use cases, their permitted business scope and human-supervision model; to disclose how guardrail testing handles permissions, escalations and auditability; and to report measurable operational, risk or customer-service outcomes as employee adoption expands. Those observations would show whether the platform has moved from deployment preparation to repeatable operations.

Sources