Skip to main content

Realistic Guardrails Can Help Banks Reap AI’s Promise with Less Risk While Maintaining Trust

By Rathi Murthy, Chief Technology Officer, Varo Bank

Published on September 30th, 2026 in Banking Technology

Simple Subscribe

Subscribe Now!

Stay on top of all the latest news and trends in the banking industry.

Consent Granted*

Financial services technology leaders are used to thinking about trust in technology in concrete terms: Is the system reliable? Is it secure? Is the data accurate?

With AI, those measures remain essential, but they only tell us part of what we need to know. Increasingly we rely on AI to interpret situations, recommend what should happen next and, in some cases, act on that recommendation.

Reality check: A system can perform exactly as designed and still produce an outcome we would not want — or be willing — to defend. Trust has to extend beyond whether the technology works to the conditions we create around how it is allowed to operate.

Consider a simple financial services example: An AI system identifies a transaction as potentially fraudulent. We may trust its ability to recognize the pattern, but that does not tell us what should happen next. Should it flag the transaction for review? Decline it? Freeze the account? Contact the customer? Each step gives the system a different level of authority and consequence if it is wrong.

Deloitte’s 2026 Global Human Capital Trends research found that 60% of executives now regularly use AI to support their decisions.

Key question: What conditions need to be in place before we can responsibly rely on AI to influence or act on consequential decisions for us, our employees and our customers?

I believe AI can only be as trustworthy as the architecture an organization builds around it. Leaders have to think deliberately about truth and context, what the system is optimizing for, how much authority it should have, whether people retain meaningful agency, and, ultimately, who owns the outcome.

These are the conditions that make trust possible.

Need to Know:

  • AI is not infallible, so before it is set loose on a bank function it must be clear how it handles incomplete information.
  • “Human in the loop” is meaningless if employees are simply expected to check the boxes.
  • Capability is not permission, so banks must be deliberate in delegating tasks to AI.
  • Accountability remains a human function, and that means AI’s operations must be traceable.
  • Varo Bank’s Rathi Murthy poses eight questions that will sharpen your bank’s thinking on AI implementation.

Truth Requires Context

For me, trust begins with the data. Before I let an AI system near a consequential decision, I want to know the data underneath it is authoritative, current and governed.

Earlier in my career, I helped bring a large portfolio of brands onto a common platform because fragmented foundations produce fragmented outcomes.

AI does not solve that problem. In fact, it can amplify fragmented data and inconsistent systems at a speed and scale that make them harder to detect and correct.

Accurate data also does not mean the system understands the full situation. I expect it to be honest about what it does not know.

Key insight: Generative AI is probabilistic, and a confident tone is not the same thing as a correct answer. Financial services leaders need to understand not only how often a system gets the answer right, but where its knowledge becomes incomplete and what happens when context is missing.

Your Institution’s Values Must Shape AI’s Objective

Every AI system is optimizing toward something: lower fraud losses, higher conversion, faster service, reduced risk, greater efficiency.

But optimization is not judgment.

Reality check: I have seen systems hit the metric they were given and yet produce an outcome the business unit, regulator or customer would never accept.

The objective we give an AI system is a values statement, whether leaders treat it that way or not.

The frame I use consists of three human-centered questions:

  • Does this elevate human potential?
  • Does it prevent harm?
  • Does it preserve human agency?

Those questions force the tradeoffs into the open.

Tighter fraud controls can reduce losses while locking legitimate customers out of their money. Earlier in my career, I worked closely on financial products serving underbanked customers, where a false decline could mean rent or groceries. A credit model tuned narrowly to minimize risk can restrict access for someone whose potential is not fully represented in traditional data. An automated interaction can be faster while removing empathy, explanation and recourse.

Technology cannot decide which tradeoffs an organization is willing to make.

Leaders have to define success more completely:

  • What outcome are we pursuing?
  • Who should benefit?
  • What harms are unacceptable?
  • What choices should remain with the person affected?

Read more: Your Bank’s AI Ambitions Are Only as Strong as Your Governance

-- Article continued below --

Authority Delegated to AI Must Be Granted Deliberately

There are real differences between AIs that surface information, recommend an action, make a decision and independently carry it out. Each reflects different levels of authority, and leaders must grant them explicitly.

Capability is not permission.

The authority I am willing to give a system depends on potential harm, whether an action can be reversed, whether we can explain it to the person affected, and whether the system has operated inside its guardrails.

I favor earning that authority progressively:

  • Start in shadow mode: Let the system produce recommendations, compare them against actual outcomes, and keep the customer unaffected.
  • Then move into a limited pilot with narrow thresholds and lower-risk, reversible decisions.
  • Expand authority only after evaluating accuracy, consistency, bias and real-world impact.

Why this matters: AI might draft code, respond to a customer, change a workflow or trigger another system. Moving from suggestion to action should not happen simply because technology can do it. It is a leadership decision.

Read more: How to Succeed with Agentic AI: Give It Major Tasks, But Don’t Hand It Entire Jobs

Human Agency Must Be Real Or You’re Kidding Yourself

A “human in the loop” is not necessarily the same thing as human agency.

If an AI presents one confident recommendation and an employee is expected to click “approve” inside a service-level target, that person may technically hold authority but they are exercising almost no judgment.

Why this matters: Approval becomes a ceremony rather than a meaningful choice. I think of this as the silent surrender of human decision-making.

If people are supposed to remain in control, we have to design the workflow so that control is real.

That means:

  • The AI should show the evidence behind its recommendation, identify what it does not know, and communicate uncertainty.
  • The person reviewing it needs the time and standing to disagree, ask another question, or choose another path.

Culture matters too. When someone overrides an AI recommendation, leaders should not automatically treat that as friction or failure. An override may reveal something important about the model, workflow or context the technology could not see.

There is also a human dimension that deserves more attention. The quality of our judgment depends not only on the information available, but on the state of mind we bring to a decision. A hurried or reactive mind can surrender judgment to a machine very easily, particularly when that machine is usually right.

This is one reason meditation and breathwork have been important in my own leadership. They create the clarity and steadiness to pause and make a conscious choice rather than an automatic one.

As AI gets faster and more capable, our ability to pause and discern becomes more important, not less.

Technology can expand our capacity to process information. It cannot replace awareness.

Read more: How a 160-Year-Old Law Will Regulate AI for National Banks for Years to Come

Accountability Remains Human, No Matter Who Is Driving

AI can influence a decision and execute an action, but it cannot accept responsibility for the outcome. It cannot answer to the customer who was harmed, explain itself to a regulator or board, or bear the consequences of failure.

Key insight: In a regulated financial institution, “the model decided” is not an acceptable answer. I do not believe it should be acceptable anywhere.

Before AI becomes part of a consequential process, ownership needs to be clear:

  • Who owns the business outcome, the data, the model and the controls?
  • Who has the authority to intervene when something goes wrong?

Distributed responsibility cannot become diluted accountability.

How this should work: Accountability requires traceability. We should be able to reconstruct what information the system used, what it recommended, where it expressed uncertainty, whether someone overrode it, and what ultimately happened.

I learned this while leading through a major production outage earlier in my career. The first responsibility was to restore the customer outcome. Then we had to understand the failure and improve the system without turning accountability into blame. I apply the same discipline to AI. A bad result does not always mean the process was bad, just as a good result may sometimes be luck.

Read more: Who Will Protect Banking Consumers’ Rights in the Age of AI?

Implementation Imperative: Different Starting Points, Shared Principles

No single architecture will look exactly the same in every organization. A legacy institution may have decades of domain expertise, mature controls and institutional judgment, while also carrying fragmented systems and years of accumulated technology. Before layering AI onto that environment, leaders need to know which foundations can be trusted and which need to be rebuilt.

AI-native companies can design their data, workflows and operating models around AI from the start. Their risk is speed without institutional judgment. They may not yet have the experience that teaches you how systems fail at scale. Traceability, escalation and accountability need to be built early rather than retrofitted later.

Financial services makes these tensions visible because decisions around fraud, credit and access can immediately affect real people. But the principles extend well beyond banking.

Whether an organization is 100 years old or built around AI from day one, the questions remain the same:

  • What does the system know?
  • What are we asking it to optimize?
  • What authority are we willing to give it?
  • Can people meaningfully intervene?
  • And who will stand behind the outcome?

Trust cannot be bolted on as a final compliance checkpoint. It has to shape how an organization governs its data, chooses its objectives, grants authority, preserves human agency and owns outcomes from the beginning.

I am enormously optimistic about AI’s ability to expand human capability. But greater capability raises the stakes of the choices we make about where and how it is used. AI can help us understand what is probable and optimize what is measurable. It is still our responsibility to decide what matters.

Read more: Banks Adopting AI that Don’t Rethink Processes Leave Productivity — and Money — on the Table

-- Article continued below --

Eight Questions to Guide Your Organization’s Thinking About AI

1. Where does our model’s underlying data become incomplete or not authoritative, and how does the system explicitly communicate its own uncertainty when context is missing?

2. What specific tradeoffs are we making in pursuit of our optimization metrics, and does the system’s objective preserve human agency, elevate potential, and prevent harm?

3. Is this system operating with a level of authority granted explicitly by leadership based on explainability and reversibility, or simply because the technology is capable of it?

4. Are our employees acting as genuine decision-makers with the time, evidence, and standing to disagree with the AI, or are they merely rubber-stamping recommendations to meet operational targets?

5. How are we capturing and analyzing human overrides to identify blind spots in our models, workflows, or real-world contexts that the technology failed to see?

6. If this AI system produces an adverse outcome for a customer or regulator today, which human leader bears ultimate responsibility, and can we fully reconstruct every step that led to that result?

7. Do we know the precise lineage, original source, and transformation history of the data powering this model, and are we certain we have the legal, ethical, and regulatory rights to use it for this specific decision?

8. How current is the underlying data feeding this decision, and what is the operational risk if the model is acting on information that is minutes, days, or months out of date?

Read next: How ‘Watson Era’ Thinking Is Holding Back Banks’ AI Benefits

About the Author

Rathi Murthy is Varo Bank's Chief Technology Officer, leading technology strategy for its digital banking experience. Previously, she was the CTO and president of Expedia Services, where she unified 21 brands onto a single platform. Murthy has held CTO positions at Verizon Media and Gap Inc. Her experience also includes roles at American Express, Yahoo, Sun Microsystems, and WebMD.