AI

Exclusive: Célia Hassid on the New Rules of AI in Banking

Bakhtawar Majid

By: Bakhtawar Majid

9 min read

As Saudi Arabia’s financial sector accelerates its digital transformation, banks are rethinking the infrastructure and governance needed to bring agentic AI into everyday operations. 

[For more news, click here]

Artificial intelligence is moving from assisting banks to operating inside them. The open question for CIOs and CTOs is no longer whether to adopt it, but how much authority they are willing to hand over, and what happens the first time an autonomous decision needs to be unwound. 

Where this gets genuinely difficult is how much standing authority a bank is willing to give an AI agent, what happens when an autonomous action needs to be reversed, and who is accountable when it does. Those questions are becoming increasingly important as agentic AI moves from analysis into day-to-day banking operations. 

Ahead of Money20/20 Middle East in Riyadh, Tech Revolt spoke with Célia HassidMambu’s senior regional spokesperson, who works directly with banks and fintechs across the Middle East, about where that authority question stands today, what banks are asking for and what needs to change before AI can be trusted to act. 

The Shift From AI Assistance to Action 

Q1. Mambu just launched Intelligent Core, bringing core banking, payments and agentic AI into one architecture. In practical terms, what does it mean for an AI agent to have authorized access to live banking data rather than a read-only summary of it? 

At Mambu, we are thrilled about the unveiling of our Intelligent Core, as it has been a pivotal piece of work across all disciplines within our team and marks an important step in how AI can operate within banking infrastructure. In practical terms, many of the AI applications used by banks today still rely on information that has been extracted from the core, often overnight, and made available separately for analysis, which can be effective for reporting but means the AI is working from a copy of the bank rather than the bank itself, without a live view of what is happening at the moment a decision needs to be made. 

Authorized access to live banking data changes that relationship because an AI agent can work directly with the information held in the core at the point of need, whether that is the current status of a payment, an account balance or a transaction, and it sees exactly the same figure that a member of the operations team would see on their screen. There is one version of the truth and no second copy of the bank’s data sitting elsewhere. Crucially, that access is governed by the bank. The agent has an identity, a set of permissions and a defined scope in the same way a member of staff does, the institution determines in advance what it is permitted to see and which actions it can execute, and every action is recorded together with the reason for it. 

Bringing core banking, payments and agentic AI into the same architecture also means the agent sees the full picture in one place, which is where the most useful signals come from, and it creates a much stronger foundation for banks that want to move AI beyond analysis and into operations while retaining the controls, permissions and auditability expected in a regulated financial environment. 

Q2. You work directly with banks and fintechs across the region. When you sit down with a bank considering agentic AI for the first time, what is the first question they ask, and is it usually about capability or about control? 

In our conversations with banks across the region, control comes before capability almost every time. The most pressing question for a financial institution is how an AI agent can operate within existing risk, compliance and operational frameworks without creating a new layer of uncertainty around decision-making, and that conversation usually starts with a very practical scenario. What happens if an agent makes the wrong decision? 

We think that is exactly the right question to open with, because it is how a bank arrives at a well-scoped deployment rather than an open-ended experiment. From there, banks naturally move into questions around what the agent can and cannot touch, who approves each type of decision and where human oversight should remain in place, and once those points are agreed, everything that follows tends to be relatively straightforward. Capability comes second, and interestingly the question is rarely about the AI itself. What banks really want to know is whether the agent can see their data properly and in full, which is in practice a question about the platform it sits on. 

What we are seeing now, and what we consider a positive development, is that operations and risk teams are becoming involved from the very first conversation. Agentic AI is increasingly being approached as part of the bank’s operating model rather than as an isolated technology project, and that is a large part of the reason deployments are now going live rather than remaining in pilot. 

Q3. Saudi Arabia processed 14.6 billion electronic transactions in 2025, with 85% of retail payments already electronic. Does that scale of digital volume make banks more willing to hand decisions to AI, or more cautious, because the exposure of getting it wrong is so much larger? 

In our experience it does both, and the two responses tend to sit in different parts of the bank. As transaction volumes rise, the operational work surrounding those transactions rises with them, whether through reconciliation, exception handling, payment repairs or customer queries, and there is a practical limit to how far institutions can continue expanding those functions simply by adding more people. For operations teams, that scale is itself the strongest argument for automation, because AI can help banks absorb greater volumes without allowing operational complexity to grow at the same rate. 

At the same time, greater scale inevitably raises the stakes around control, particularly when an automated action could affect a customer, alter an account or move money, and that caution is entirely reasonable. The discussion therefore turns from how much decision-making can be handed to AI towards the conditions under which that authority can be granted safely. 

For Mambu, the answer is containment. The agent’s reach is scoped, the value it can move is capped, its activity is monitored live and there is a single, clearly understood point at which it can be stopped. Once those four conditions are in place, teams tend to move quickly and with confidence, which is why many institutions are starting with internal operational use cases where the outcome is measurable and the risk can be tightly managed before extending agentic AI into more complex areas of the bank. 

Q4. Open banking is putting pressure on banks to modernize their underlying infrastructure. Where does that pressure actually land first, the technology itself, or the governance and approval processes sitting on top of it? 

Open banking places immediate pressure on the technology because banks are being asked to expose data and services more quickly, more consistently and increasingly in real time, but in practice most of the timeline sits in the governance and approval structures surrounding that technology. 

A bank may identify the technical solution relatively quickly, yet moving from technical feasibility to production still requires risk assessment, internal approval, testing and coordination across different parts of the organization. Open banking also raises the importance of the underlying core because once another platform or provider is relying on a bank for real-time data or functionality, the performance of that infrastructure directly affects an external customer experience rather than remaining an internal technology issue. 

That is one of the reasons Mambu has long advocated for a composable approach to modernization. Instead of requiring a bank to commit to a single, multi-year transformation program, institutions can move individual products or capabilities onto modern infrastructure in stages, demonstrate the value and expand from there. Each step is reversible and delivers a result in months rather than years, which reduces the scale of each technical decision while also making the governance process considerably easier to manage. 

Q5. With 261 fintechs operating in Saudi Arabia by the end of 2024, are fintechs or incumbent banks moving faster on agentic AI right now, and what is actually holding the slower group back? 

Fintechs are generally able to move faster in the early stages because smaller organizations tend to have simpler technology environments, cleaner data, fewer products and shorter decision-making chains, which means a new capability can be tested and moved into production within weeks rather than navigating the same level of organizational complexity. 

Incumbent banks, however, bring a very different set of advantages, including scale, distribution, established customer relationships and far richer pools of data once those are properly organized, so the opportunity is potentially much larger once the foundations are in place. In our experience, three things make the difference for them. The first is agreeing data definitions across teams, so that everyone means the same thing when they talk about a customer or an active account, and that single step unblocks more than anything else. The second is a single owner who carries the outcome, rather than several sponsors sharing responsibility between them. The third is beginning with a clearly defined operational problem such as reconciliation or payment repair, where the value is measurable and the risk can be contained, before expanding into more complex applications. 

The growth of Saudi Arabia’s fintech sector is also playing an important role because fintechs are setting the pace that customers now expect around speed, product development and customer experience, and that competitive pressure is helping accelerate modernization across the wider banking market. 

Where Banking AI Goes Next 

The move toward agentic AI is ultimately forcing banks to reconsider the relationship between automation and authority. As AI systems become capable of working with live data and taking action, the boundaries around that action become as important as the technology itself. 

Saudi Arabia’s rapidly digitizing financial sector has a clear incentive to automate more of the operational work created by rising transaction volumes and increasingly complex financial services. Greater autonomy, however, also brings greater exposure when something goes wrong. 

The path forward, as Hassid describes it, is therefore unlikely to be about giving AI unrestricted freedom. It is about defining where it can act, what it can access and when a human needs to remain in control. That may prove to be the more important measure of AI maturity in banking. Not how much a system is capable of doing, but how confidently an institution can define the limits of what it should do. 

Célia Hassid will be available at Money20/20 Middle East in Riyadh from September 14 to 16, 2026, for further questions and press briefings, with Mambu at Booth H2.D61. 


Related Articles 

Middle East Banks Move Past AI Experiments as IBM Backs MEBIS 2026 in Dubai 

The AI Agent Security Gap Is Closing, and the Middle East Is Proving to Be the Fastest Market to Demand It 

Why Tamara's New "A-" Credit Rating Matters for Saudi Fintech 


 


 

Share this article

Related Articles