About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

As AI Agents Enter Financial Workflows, Do Information Barriers Need to Follow?

Subscribe to our newsletter

The widely reported accidental disclosure of sensitive information at Morgan Stanley last month has brought data loss prevention (DLP) back into focus. The incident, in which an email reportedly exposed details of more than 100 investment banking deals, illustrates the risks that remain despite years of investment in communications monitoring and information barriers.

The incident also highlights a longstanding challenge for financial institutions: preventing sensitive information from crossing organisational boundaries. As banks introduce AI agents capable of accessing internal systems, retrieving confidential data and communicating with external parties, that challenge is acquiring new dimensions.

Controls originally designed to govern human communications must now extend to automated workflows in which agents may act with varying degrees of autonomy. This raises important questions about how firms maintain consistent permissions, information barriers and compliance policies, regardless of whether information is being exchanged by employees, applications or AI agents.

Preventing Data from Leaving the Firm

Financial institutions operate under strict regulatory requirements governing communications, yet many of the platforms their employees use were not originally designed for those environments. Email and collaboration tools such as Microsoft Teams were developed for general business communication, with financial services-specific controls subsequently added.

The key issue lies in where those controls are applied. In a conventional hub-and-spoke communications architecture, information travels from one institution through a central hub before reaching another. Depending on the platform and how its controls are configured, sensitive information may already have left the originating organisation before a potential breach is detected.

“A lot of controls happen in the hub, not the spoke,” observes Michael Lynch, Chief Operating Officer at Symphony, in conversation with TradingTech Insight. “What that fundamentally means is that when a bank sends a communication, even if it decides to block it, the data still gets to the hub. One of the things that’s unique about how we designed our controls is that they’re inside the spoke of the bank, so the data truly doesn’t get out in any way, shape or form.”

Symphony’s approach is to enforce DLP policies within the originating institution, before information reaches an external communications hub. Lynch says this allows firms to apply their existing DLP rules across supported messaging channels, including WhatsApp, SMS and WeChat, as well as Symphony’s own platform.

Those policies can be configured at individual, departmental or organisational level, reflecting the different requirements of investment banking, trading and operations teams. Content and attachments can be examined using deterministic rules, pattern recognition and AI-based techniques, with enforcement ranging from outright blocking to user warnings or subsequent compliance review.

Such controls inevitably involve trade-offs. Rules that are too restrictive risk disrupting legitimate communications, while those that are too permissive may allow sensitive information through. Maintaining consistent policies across different channels also depends on the capabilities and integration arrangements of each platform.

The distinction between prevention and detection is particularly relevant as communications become more fragmented. Financial institutions increasingly need to maintain consistent controls across internal collaboration tools, external messaging platforms and automated workflows, without creating unnecessary friction for employees.

Extending Information Barriers to AI Agents

The emergence of agentic AI introduces another dimension to this problem. Agents may be authorised to access multiple enterprise systems, invoke external tools and interact with other agents, potentially creating new routes through which confidential information could cross established organisational boundaries.

Lynch points to the separation between private-side investment banking and public-side trading as an example.

“Agents need to be treated like users in an organisation. They need to inherit the data controls, information barriers and rule sets that apply to the data, workflows and intelligence they might be using. If the investment banking team builds an agent around upcoming M&A activity, you have to make sure a public-side trader can’t accidentally call an MCP that brings in that agent’s intelligence.”

Model Context Protocol (MCP) provides a standardised mechanism through which AI applications can access external tools and data sources. While this simplifies integration, it also introduces additional access paths that institutions must govern.

An agent operating within a trading workflow, for example, could potentially retrieve information from a connected system that the human trader would not ordinarily be permitted to access. Preventing that requires permissions and information barriers to be enforced across the agent’s interactions with underlying systems, rather than simply controlling the information presented to the end user.

The same considerations apply beyond internal workflows. Lynch says Symphony is seeing growing interest in agents participating in inter-firm communications, particularly in middle-office operations and trade settlement.

As these workflows develop, institutions will need to establish what information an agent can access, which counterparties it can communicate with and what approvals are required before it acts.

Verified identity becomes particularly important as agents begin communicating across organisational boundaries. Firms need to establish not only which systems and data an agent can access, but also the identity and permissions of its intended recipients. This becomes more complicated when agents operate across different institutions, each with its own identity management and entitlement frameworks.

Building an Audit Trail for Agent Activity

Agentic workflows also raise questions about how institutions monitor and reconstruct automated decisions.

Traditional communications surveillance focuses primarily on messages exchanged between participants. With AI agents, the activity leading to a communication may be equally important, particularly when an agent retrieves information from several systems before producing a response or initiating an action.

Lynch argues that compliance records need to capture more than the initial prompt and final response, providing visibility into the tools and data sources an agent accesses along the way. “For agents operating on Symphony, all the prompting and thinking that the agent does is integrated with the compliance feed that goes downstream to the compliance officer. You don’t just have the prompt from the end user and the agent response; you have the underlying activity – what MCP did it call, for example, that gives the compliance officer an understanding of how and why that answer was provided.”

Capturing tool calls and other intermediate activity provides an audit trail that can help compliance teams establish which systems an agent accessed and how information was used. This becomes increasingly relevant as institutions consider allowing agents to undertake more complex activities with less direct human intervention.

Symphony’s AI Agent Studio, introduced in May, is designed to apply its existing communications controls to agents developed within the platform or connected from external environments. It builds on the company’s established workflow automation infrastructure, although extending controls from deterministic bots to more autonomous agents introduces additional challenges around permissions, monitoring and accountability.

Scaling AI Without Weakening Controls

Lynch says discussions with Symphony’s financial institution customers increasingly reflect a shift in priorities. Having established initial AI use cases and begun deploying applications into production, firms are now considering how to extend those capabilities into more sensitive business processes.

“The primary conversation appears to be around scaling with control. Firms have their use cases, their POCs and their first production deployments, and they’re promising. The question is how they apply AI to more use cases, more areas of the organisation and more sensitive use cases while ensuring they maintain that level of control. The last thing they need is to take 10 steps backwards because they moved too far with the business opportunity and too slowly with the risk controls.”

As financial institutions move towards increasingly autonomous workflows, established approaches to communications governance will need to accommodate a growing population of non-human participants. The challenge extends beyond applying existing DLP rules to agents: firms must also determine how permissions are assigned, how information barriers are maintained across interconnected systems, and where responsibility lies when an agent acts without direct human approval.

Much will depend on whether these controls can operate consistently across different AI platforms, enterprise applications and institutional boundaries. For banks seeking to move beyond isolated AI deployments, resolving those integration and governance questions will be essential to bringing agentic workflows into mainstream trading and post-trade operations.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Navigating the Build vs Buy Dilemma: Cloud Strategies for Accelerating Quantitative Research

For many quantitative trading firms and asset managers, building a self-provisioned historical market data environment remains one of the most time-consuming and resource-intensive steps in establishing a new research capability. Sourcing data, normalising symbologies, handling corporate actions and maintaining infrastructure can take months and absorb significant budget before a single model is tested. At the...

BLOG

OneChronos Brings Combinatorial Matching to European Equities

Periodic auctions came to Europe as an answer to the speed race. They are now routine. Several operators run them, and randomised auction lengths and speed-neutral matching have become standard rather than special. A venue arriving today has to say what it does that the others do not. OneChronos, which began production trading on its...

EVENT

Eagle Alpha Alternative Data Conference, London, hosted by A-Team Group

Now in its 8th year, the Eagle Alpha Alternative Data Conference managed by A-Team Group, is the premier content forum and networking event for investment firms and hedge funds.

GUIDE

AI in Capital Markets Handbook 2026

AI adoption in capital markets has moved into a more disciplined phase. The priority is now controlled deployment: where AI can be used safely, where it can deliver measurable value, and how outputs can be governed, monitored and evidenced. The 2026 edition of the AI in Capital Markets Handbook examines how AI is being applied...