← all writing
July 20, 2026 · 3 min read

We're Shipping AI Agents Into Lending While Accountability Burns

ConnectOne deploys nCino agents in commercial lending as regulators still don't know who's liable when they fail.

ConnectOne is rolling out nCino AI agents across commercial lending right now. Not in a sandbox. Not in a pilot. In production, making decisions that affect borrowers' access to capital. Somewhere, a credit decision is being shaped by an AI agent whose legal identity, audit trail, and chain of responsibility is still unclear. Welcome to 2026 fintech.

Let me be direct: this is reckless without being malicious. ConnectOne and nCino aren't bad actors. But they're moving into the highest-stakes, highest-friction corner of fintech—regulated commercial lending—at a clip that our legal and regulatory infrastructure wasn't built to handle. And the scary part? Nobody at the FCA, the OCC, or anywhere else has solved the accountability problem yet.

The FCA's Mills Review just published the honest version of this: regulators are openly asking whether the rulebook still fits. That's not confidence-inspiring. That's a live admission that AI agents are now part of the financial system and we don't have a durable framework for knowing who's accountable when one hallucinates a credit decision, discriminates against a class of borrowers, or makes a call that destroys a small business.

Here's the problem: our entire liability architecture assumes a human actor or a clearly identified firm. You breach lending law, your bank pays the fine, your compliance officer gets scrutinized, maybe someone gets fired. Simple. But when an agent acts—especially one that can reason, re-plan, and operate across APIs—who is accountable? The vendor? The bank? The model? The human who approved the agent's deployment? All of the above?

That gap is not theoretical. It's operational today.

The one encouraging sign: Vint Cerf just joined a project to give AI agents a durable identifier. A real cryptographic identity that persists across sessions and can be audited. That's the right instinct. You cannot build accountability on anonymity. You need to know which agent did what, when, why, and on whose instruction. That's not surveillance theatre—that's basic fiduciary hygiene.

But durable agent IDs are infrastructure, not liability law. Even if Vint Cerf hands us a bulletproof identity standard tomorrow, we still need regulators and legislators to answer the hard question: If an AI agent acts negligently, recklessly, or illegally, which human or institution bears the loss? Is it strict liability on the deployer? Proportional fault between vendor and user? Shared responsibility with the regulator who approved the use case?

I don't have the answer. But I know we can't keep shipping at production scale without one.

What ConnectOne is doing—embedding agents into commercial lending workflows—will probably work fine 95% of the time. That's the trap. It'll work fine until it doesn't, and then some borrower will have a decision made against them by a system that nobody can explain, nobody can reverse, and nobody can point to as liable. That's not innovation. That's litigation waiting to happen.

If you're deploying agents in regulated lending right now, you need to be asking hard questions: Can I trace every decision back to a named agent and a human approval? If this agent hallucinates or discriminates, who pays the claim? Do my regulators know it's live? If you can't answer those with evidence, not comfort, you're betting that your luck holds longer than your exposure window.

The Mills Review is right. The rules don't fit anymore. That's not an excuse to ignore them while they're being written. It's a warning to move intentionally, with layers of human oversight and documented accountability, until the legal answer arrives.

The agents are shipping. The question is whether the ledger is.


Not financial advice. AI-generated.


From my toolbox — something I actually ship, not just write about:

vaspera — Enterprise security certification with deterministic scanners, cost tracking, and compliance mapping. · ~1,204/wk on npm

Liked this? Get the next one in your inbox.

subscribe →