AI in banking is moving from experimentation into practical financial workflows, but a panel at WSO2Con Africa 2026 showed that the harder question is how much authority banks should give these systems once they are connected to real customer data and financial processes.
Speakers from alBaraka Bank Tunisia, CRDB Bank and the Central Bank of Nigeria discussed applications ranging from credit assessment and productivity to fraud detection, while returning repeatedly to governance, transparency and institutional accountability. The discussion placed a clear boundary around AI adoption: a bank can use AI to support a decision without transferring responsibility for that decision to the technology.
Haithem Abdelkefi, CIO at alBaraka Bank Tunisia, argued that AI now sits within the core of digital transformation rather than at its edges. Banks have already digitised channels, automated processes and built technology around their operations, he said, creating a base on which AI can make existing activities more efficient. His distinction between AI as technology and AI as a business capability is important because it moves the discussion away from whether banks should adopt AI and towards where it can produce useful business outcomes.
That distinction becomes clearer in the examples coming from CRDB Bank. Mturi Matwiga, Portfolio Manager for IT & Digital Transformation Projects at the bank, pointed to productivity, lending and fraud-related processes as areas where AI can provide practical value. In credit assessment, analysts may need to work through information held in databases and other formats before producing a report for a decision-maker. AI could reduce some of that manual work and help make the assessment process more consistent.
Lending shows where AI authority becomes difficult
Credit assessment also illustrates why financial services cannot treat every AI use case as an automation problem. Mturi said the bank was cautious about fully automated credit assessment, drawing on benchmarking with financial institutions in India and South Africa where AI was being used to support credit assessment rather than make the final judgement. His conclusion was direct: “AI should support credit assessment, but not the judge.”
That boundary has implications for the architecture around AI as well as the model itself. A banking agent may be able to retrieve customer information, analyse documents, access an internal scoring capability or prepare a recommendation, but those permissions do not necessarily give it authority to approve or reject a loan. The design of those interfaces, permissions and approval points therefore becomes part of the bank’s risk controls.
This is where the broader agentic enterprise discussion becomes relevant to financial services. An AI agent is useful because it can move beyond producing an answer and interact with the systems that run a business, but that capability needs boundaries. A bank can expose an API for checking an account, retrieving a transaction record or submitting a workflow without giving an AI system unrestricted authority over the underlying financial operation. The design of those interfaces, permissions and approval points therefore becomes part of the bank’s risk controls.
Fraud detection is pushing banks and regulators to act
Fraud detection presents a different case because transaction volumes can make purely manual monitoring impractical. Ajakaiye Waiyeola, Deputy Director in the Payments Innovation and Regulation Division at the Central Bank of Nigeria, said the regulator had mandated banks to use AI for fraud detection, giving them an implementation period because the scale of payments made it difficult for human teams to identify every suspicious pattern.
The same approach comes with requirements around explainability and governance. Waiyeola said banks need to be able to explain their results, models and biases while maintaining appropriate governance around their use of AI. That combination is significant because it shows how regulation can encourage adoption while still requiring institutions to understand and control the systems they deploy.
The Nigerian approach also recognises that implementation capacity varies across the financial system. Waiyeola said larger banks were given 18 months while smaller entities were given 24 months, with institutions required to submit implementation plans explaining how they intended to comply. The regulator was also exploring whether service providers could help smaller institutions access some of the required capabilities, although he described that part as informal rather than a formal programme.
For banks, fraud detection may therefore become one of the clearest areas where AI moves from optional experimentation into operational infrastructure. It also exposes the consequences of getting AI wrong. A system that incorrectly flags a legitimate transaction can disrupt a customer’s access to funds, while a system that misses fraudulent activity can expose the institution and its customers to financial loss.
Governance is becoming the bridge from pilot to production
The panel’s discussion about moving AI from pilots into production repeatedly returned to issues outside the model itself. Abdelkefi pointed to performance, scalability and security requirements alongside compliance, regulation and operational resilience, ultimately identifying governance as a major condition for successful AI initiatives.
Matwiga reached a similar conclusion from the banking side. He identified data quality and governance as important lessons from his benchmarking work with financial institutions in other markets, arguing that production AI depends on more than the underlying technology.
That fits closely with the wider technical discussions around enterprise AI. An AI application needs access to business information and capabilities through tools, APIs, MCP and RAG. The model itself does not automatically know the latest customer information, company policies or operational status of a transaction. Those capabilities have to be connected to it, and the organisation has to determine what the agent can access and what it can do with that access.
The implication for financial institutions is straightforward. AI governance cannot sit separately from data governance, API management, identity or workflow design because the model’s ability to act depends on all of those layers. The more access an AI system receives, the more important it becomes to know which system supplied the information, which identity authorised the action and what happens when a decision requires human intervention.
Banks still own AI-driven decisions
The most consequential part of the panel came when the speakers were asked what happens when AI makes a wrong decision. The examples were deliberately ordinary for financial services: a loan incorrectly declined or a legitimate transaction incorrectly flagged as fraud.
Matwiga said the bank remains responsible for the decision. The accountability does not move to the algorithm or the technology simply because AI was involved in the process.
Abdelkefi connected that responsibility to transparency. Customers need a way to escalate an AI-driven decision, particularly when something has gone wrong, and there should be a mechanism for human intervention and correction. He linked that directly to the human-in-the-loop principle discussed elsewhere at the conference.
For banking, that kind of architecture matters because human oversight needs to be part of the process rather than an emergency workaround. If a credit recommendation requires an authorised officer to make the final decision, the workflow needs to know when to stop, who can intervene and how the resulting decision is recorded.
Human oversight has to be built into the workflow
The Central Bank of Nigeria’s position adds another layer to the accountability question. Waiyeola said liability for AI-driven decisions remains with the banks using the technology. Even where different models are reviewed or approved, the institution implementing the model remains responsible for how it is used and for the resulting decisions.
That principle has consequences beyond compliance. It means banks need sufficient visibility into their AI systems to investigate decisions, explain them to regulators and customers, and intervene when the result is wrong. An AI system that produces an accurate recommendation but cannot be audited or challenged can still create operational and regulatory problems once it becomes part of a customer-facing process.
It also explains why identity has become such an important part of enterprise AI architecture. When an agent can retrieve information, call APIs, update records or trigger workflows, the institution needs to know which agent acted, what it was permitted to do and whether a human approved the relevant action.
Trust will depend on what happens when AI gets it wrong
The panel’s closing discussion brought the technology and governance questions back to trust. Abdelkefi said financial institutions need to build customer confidence in AI while establishing robust internal governance. Matwiga emphasised trust in the bank itself and the need to validate data through pilots, while Waiyeola pointed to continued education for customers and regulators around AI’s capabilities and reliability.
That puts financial institutions in a different position from companies deploying AI for lower-risk administrative tasks. A banking AI system can influence access to credit, determine whether a transaction is treated as suspicious or interact with information that customers expect the institution to protect. The value of automation therefore has to be measured alongside the institution’s ability to explain, supervise and correct what the system does.
The wider enterprise AI discussion has established the technical pieces required for enterprise agents: APIs to reach existing capabilities, enterprise data and tools to provide context, identity to define permissions, and durable workflows that can preserve state while waiting for human decisions. The financial-services panel adds the governance question that sits above those components: which actions should an AI system actually be allowed to complete without a person deciding the outcome?
For African banks, that question will become more practical as AI moves deeper into lending, payments, fraud management and customer operations. The panel suggests that the institutions able to scale these systems will need more than capable models. They will need reliable data, controlled access to business systems, clear decision boundaries, human escalation and governance that keeps accountability with the financial institution when the AI gets the answer wrong.
Real ESG impact doesn’t happen in panels alone, it happens in the rooms where financiers, operators, and policymakers actually align. Our GreenShift Forum 2026 cuts the noise, bringing together the people rewiring Africa’s sustainability and energy frameworks for one focused day in Nairobi. Secure your seat.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to info@techtrendsmedia.co.ke





