02/07/2026
As Agentic AI enters core business processes, early identification and assessment of new risks is essential, particularly in trust-dependent sectors such as finance and insurance.
Both sectors are entering a new phase of AI-driven transformation as agentic capabilities are gradually integrated. While GenAI and LLMs enhanced content analysis, summarisation and generation, Agentic AI enables autonomous action: agents can plan tasks, use tools and APIs, interact with other agents, retain context and execute decisions in operational systems.
Financial institutions already use advanced technologies to serve customers, stakeholders and society. However, Agentic AI can amplify operational risks, and uncontrolled adoption may undermine trust or create systemic impact. Institutions must therefore deploy it responsibly and prepare for malicious use by adversaries.
Developed by the EFR Cyber Working Group, this White Paper outlines the risks introduced by Agentic AI and proposes mitigation measures.
It complements the 2025 EFR paper on GenAI security risks by focusing on risks amplified or created by agent autonomy, tool orchestration, persistent memory and multi-step execution, with a scope limited to security risk management.