None of the banks and insurers interviewed for the study published on 9 July 2026 by the University of St. Gallen and Wavestone has an agentic artificial intelligence (AI) system in production. Around two-thirds have generative AI live in low-complexity work such as summarising, drafting and data extraction, with nothing agentic behind it. The organisation furthest along, a central AI lab inside a large insurer, said it was still waiting for the right use case.
The study draws on 30 semi-structured interviews conducted between October 2025 and May 2026 across the DACH region of Germany, Austria and Switzerland, with banks, insurers and selected technology providers. At most of the institutions both the IT side and the business side were interviewed, which is why the interview count runs ahead of the number of organisations. Its conclusion is that operating-model maturity decides how far an institution can scale agentic AI, because the models on the market already exceed what most of these organisations are in a position to absorb.
The study sorts the blockers into three layers: an external layer of regulation, a structural layer of compute capacity and digital sovereignty, and an internal layer of data, people and operating model. Regulation sits on the outside of the three, and it does not press evenly. The heaviest load lands on the core processes that produce much of the business, precisely because so much depends on them; they are the most tightly regulated and the hardest to change. The result is a drift towards small peripheral cases with an easy path through compliance and modest returns, and the automation with the greatest value stays out of production.
Underneath that sits the demand for explanation. A supervised institution has to be able to account to its supervisor for how a decision was reached, and to follow it back to the data underneath. That is straightforward for a fixed rule and harder for a system that settles its own path at run time. Nor does the scrutiny scale down: a minor improvement to a core process clears the same availability, audit and review bar as the process around it.
The study is DACH-wide and the instruments it names are largely European, among them the Digital Operational Resilience Act (DORA) and the EU AI Act. Switzerland has no AI-specific legislation in force, and the Swiss Financial Market Supervisory Authority FINMA supervises on a technology-neutral, principle-based footing, so the existing governance and risk-management requirements cover AI as they cover everything else. Swiss groups that run EU-regulated entities meet the European regimes through those.
FINMA set out its expectations in Guidance 08/2024 on 18 December 2024. It drew attention to model risks such as robustness, correctness, explainability and bias; to data risks covering security, quality and availability; to IT and cyber risks; to growing third-party dependencies; and to legal and reputational risks. It also recorded, from its supervisory work, that most institutions were at an early stage of development at that point and were still putting the matching governance and risk-management structures in place. Read next to the study, the supervisor and the practitioners describe the same ground from two sides.
The study is specific about what has to exist before agents can be composed across systems: data that is complete, correct, current and available on demand; interoperability across systems built to keep it apart; identity and access management for non-human actors, so that what an agent did can be traced; and governance that can keep autonomous action under control. None of the organisations in the sample holds that full set yet, and several of the practitioners interviewed expect serious agentic work to begin in 2027.
Structure follows the same logic. Most of the sample is converging on a central hub with spokes in the business units, and the study argues the hub belongs in IT, where composition, integration and access control already live. That is a move from where the AI function mostly sits today. On the study’s own indicative shares, about 42 percent of the organisations anchor the AI function in the business against 17 percent in IT. On a separate measure, about a third have no hub in place yet. The base is small and qualitative, and the study reads its shares per dimension rather than as one total, so these figures show a direction and nothing finer.
Sequencing is what matters for a Swiss institution planning against 2027. Data ownership, the access model for non-human identities and an audit trail a supervisor can follow all take longer to build than any single agent takes to pilot, and they are the work that makes the pilot deployable.
Penta works on that ground for regulated institutions in Geneva and Dubai: the operating model, control of data and the secure infrastructure the agents will eventually run on. If agentic AI sits on your plan for 2027, put the foundations on your 2026 agenda, and we can help you get them right.
References
1. FINMA, Guidance 08/2024, Governance and risk management when using artificial intelligence, 18 December 2024. https://www.finma.ch/en/news/2024/12/20241218-mm-finma-am-08-24/
2. University of St. Gallen and Wavestone, From GenAI to Agentic AI: Operating-model shift in financial services, published 9 July 2026. https://www.wavestone.com/en/insight/agentic-ai-in-financial-services-2/
3. Full study PDF: from-genai-to-agentic-ai.pdf
4. Trade summary, context only, not cited in the body: fintechnews.ch