At Sibos 2026, Bank AI Agents Fix Payments a Person Still Releases

BNY, BNP Paribas, Deutsche Bank, HSBC and Citi showed production AI agents at Sibos 2026. All of them work payment repair or trade exceptions, with scheme-rule checks and a person keeping the release decision.

By Rajesh Beri·October 2, 2026·9 min read
Share:
A bank payments operations desk at night with two monitors showing a long queue of flagged wire transfer records, one record highlighted with a corrected address field, and an operator's hand resting over a physical appr

Illustration generated using AI

If you run payments or trade operations and are choosing where to put your first production AI agent, Sibos 2026 gave you a clear answer: the exception queue. The banks that described live agents in Miami this week (BNY, BNP Paribas, Deutsche Bank, HSBC and Citi) had pointed them at payment repair, trade document checking and process dispatch. Each design shares one shape. A model proposes the fix, deterministic rules from the payment scheme or the ICC check it, and a person keeps the decision that moves money.

That pattern is now also a product. Finastra launched Repair Recommendations on September 30, which suggests fixes for failed payments, validates them against Swift, Fedwire, SEPA, UPI and Nexus rules, and leaves "the final action subject to human review and approval." For an operations head, this quarter's decisions are which repairs to hand over first, how to measure what the agent clears, and whether to build that gate or buy it.

What the Banks Actually Put in Production

The live deployments described at Sibos sit in back-office exception handling, and none of them lets a model release a payment unsupervised. Here is what was on stage, per The Fintech Times' day-two report.

BNY built what it calls a digital employee for payment repair on its Eliza platform. It targets the small share of instructions that fail straight-through processing "because the beneficiary, the reference data, the address or the purpose of the payment is wrong." The agent reads each field for meaning, checks the syntax against ISO 20022, then asks whether the payment as a whole makes sense. The report's summary of the design: "AI does the reasoning, deterministic guardrails do the vetting, and people make the judgement calls." Microsoft's customer story on the bank says that one digital employee handles over 10% of BNY's payment repair issues globally. That is a vendor-published figure about a vendor's customer.

BNP Paribas cut a securities-services trade processing flow from ten steps to six, with the agent dispatching work between steps. Within a couple of weeks it was handling 80 to 85 per cent of the work. Charles Holive, the bank's chief AI officer for corporate and institutional banking, said every model interaction runs through an observability layer carrying guardrails set by compliance, legal and HR.

Deutsche Bank described Ada, its agentic framework. Its German lending business used knowledge graphs to onboard a new client and issue a loan in a day, a process that would have taken a month. That is one client.

HSBC presented Smart Checking for trade documents, which breaks the job into modules from digitisation to reasoning over the conditions a transaction must meet, "built on the ICC's rules and the tacit knowledge of HSBC's trade specialists." Global Trade Review reports it is live in Hong Kong, the UAE and the UK, with people brought in for exceptions and higher-value transactions.

Citi's Stephen Randall added the regulatory piece: banks are walking supervisors through each use case, including where the human sits in, on or out of the loop.


Why Repair Is the Right First Job

Payment repair is a good first agent job because the input is structured, the correct answer can be checked by rules, and the cost of a wrong answer is caught before money moves. An exception queue is a backlog of payments that failed automated validation and wait for a person to fix a field, confirm a beneficiary or reject the instruction. Every item in it has a scheme rulebook that says what a valid message looks like.

That gives you a verifier you did not have to build. A model can propose that the town name belongs in its own tag or that a purpose code is missing; the ISO 20022 schema and the scheme's usage guidelines can say yes or no deterministically. Compare that with a credit memo or a customer email, where "correct" is a judgement and your only check is another model or another person.

The calendar is also forcing the issue. Swift's coexistence period for MT and ISO 20022 payment messages ended in November 2025, and Swift left room until November 2026, when additional validations and charges apply to institutions still sending MT payment instructions. From the same month, the Swift network will no longer accept unstructured postal addresses in CBPR+ messages. An address is one of the four failure causes BNY named. If your corporate clients still send free-text addresses, your repair queue is about to grow, and the fix is exactly the kind of field-level restructuring a model does well and a rule can verify.

Most banks are not there yet. Bottomline's 2026 Payments Intelligence Gap report, covering 300-plus professionals, found 36% have no AI integration in payment systems, 48% call it a critical or high priority for the next 12 months, and 65% cite structured data quality as the biggest barrier to ISO 20022 enablement.

Where the Pattern Is Weaker Than It Sounds

The numbers on stage are thinner than the confidence around them, and you should read them as such. BNP Paribas's 80 to 85 per cent is a share of work on one flow. The same report notes that "with staff taken off the mailbox entirely, adoption was total from day one." That is a management decision, and it means the adoption figure measures the mandate as much as the agent. Deutsche Bank's month-to-a-day result is a single client. HSBC declined to give volume or time-saved figures and declined to answer questions on trade operations headcount.

The human gate has its own failure mode. A person who approves hundreds of agent-proposed repairs a day starts to approve on autopilot, which is the automation bias problem this publication covered in how reviewers defer to vague AI explanations. The counter-argument came on day three, when EY's Stephany Kirkpatrick answered the review-fatigue worry with "humans make mistakes every day." She has a point, and so do the worriers. The point of the deterministic check is that it does not get tired, so put as much of the vetting there as the rulebook allows and reserve the human for what rules cannot decide: is this beneficiary plausible, does this purpose match the client's pattern.

Auditability is the other part regulators will ask about. Forrester's write-up of BNY reports more than 130 digital employees in production and says every action they perform is fully auditable, with the rationale logged. Bottomline's Natasha Lapierre made the same demand from the vendor side: AI outputs "need to be traceable, auditable and understandable." If your pilot cannot show a supervisor the proposed fix, the rule that passed it and the person who released it for any single payment, it is not ready for the conversation Citi described.


Build or Buy the Repair Agent

The build-versus-buy split at Sibos ran along platform lines, and your answer depends on whether you already own a payments hub with an exception workflow. BNY built on Eliza, which BNY describes as a multi-vendor model platform with over 100 digital employees that carry their own personas, credentials and supervisors. HSBC built Smart Checking in-house while, per Global Trade Review, JPMorgan and Lloyds use Cleareye, Deutsche Bank and SMBC use Traydstream, and BNP Paribas and ING use Conpend for trade documents.

Finastra's module is the buy option for banks on its payments stack: it sits inside AI OperatorAssist and complements Global PAYplus and Payments To Go. The vendor claims it reduces resolution times and errors; it has published no customer figures yet. A bank on a different hub gets the same architecture by wiring a model to its existing repair screen and its existing scheme validation, which most hubs already run.

The deciding question is ownership of the verifier. If your scheme-rule validation lives in your payments hub, a vendor repair module on that hub inherits it. If you build on a general agent platform, you are responsible for keeping the rulebook current through every Swift standards release, including November's. The governance shape matches what this publication saw at DBS, where 1,500 bankers ran credit memos on agents and the headline figure was a target, and at TD Bank's first mortgage agent: a narrow task, a measured baseline and a named human owner.

What to Do Before November's Swift Release

This Week:

  1. Pull last quarter's repair queue and split it by failure cause: beneficiary, reference data, address, purpose. BNY's four categories are a workable starting taxonomy. Count how many repairs per day each cause generates and the median handling time.
  2. Count the instructions in that queue with unstructured addresses. That is the volume the November 2026 address rule will turn into rejections if nobody restructures them.

This Month:

  1. Pick one cause, most likely addresses, and run an agent in suggest-only mode against a copy of the queue. The metric is the share of repairs where the agent's proposed fix passes scheme validation and the operator accepts it unchanged. Track it daily, the way BNY reports a share of repair activity.
  2. Write down where the human sits for each repair type (in, on or out of the loop) and take that document to your supervisor before go-live, as Citi described. Keep release with a person for every payment in the first phase.
  3. Log the proposed fix, the rule result and the releasing operator for every item. Measure operator override rate and time-to-approve; a falling override rate with a collapsing approve time is the early sign of rubber-stamping.

Before Renewal:

  1. If you are on Finastra's payments stack, ask for Repair Recommendations reference customers and their acceptance rate before you pay for it. If you are elsewhere, ask your hub vendor for its roadmap date for the same capability and price it against building on your own platform.
  2. For trade, decide whether document checking is a build like HSBC's or a buy from the specialist vendors that several large banks already use, and agree the human threshold by transaction value before either.

The Bottom Line

The agents that reached production in banking this year went where a rulebook already defined the right answer: the repair queue and the trade-document check. Straight-through processing already automates the payments that pass validation and leaves people with the failures. The agents now work those failures against the same rules, and the bank still decides who presses release. A payments team can copy that design on its existing hub, and it answers the supervisor's first questions in a way most of the agent pilots banks have struggled to move into production could not.

Start with the address repairs, because November's Swift release will send you more of them.

Continue Reading

Share:

Frequently Asked Questions

Which banks showed AI agents in production at Sibos 2026?

BNY described a payment-repair digital employee on its Eliza platform, BNP Paribas a trade processing agent handling 80 to 85 per cent of one flow, Deutsche Bank its Ada framework, HSBC its Smart Checking trade-document system, and Citi how it walks supervisors through each use case.

What is payment repair in banking?

Payment repair is the manual fixing of payment instructions that fail automated validation, usually because the beneficiary, reference data, address or payment purpose is wrong. Each item sits in an exception queue until a person corrects, confirms or rejects it.

Does Finastra Repair Recommendations release payments automatically?

No. Finastra says the tool suggests how to repair a failed payment, validates the suggestion against Swift, Fedwire, SEPA, UPI and Nexus rules, and leaves the final action subject to human review and approval. It sits inside AI OperatorAssist.

How does the November 2026 Swift address change affect payment repair?

From November 2026 the Swift network no longer accepts unstructured postal addresses in CBPR+ ISO 20022 payment messages; only structured or hybrid addresses pass. Banks whose clients still send free-text addresses should expect more repairs or rejections.

What should a bank measure when piloting a payment repair agent?

Track the share of repairs where the agent's proposed fix passes scheme validation and the operator accepts it unchanged, plus operator override rate and time to approve. A collapsing approval time with falling overrides can signal rubber-stamping.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →