Enterprise technology has long been sold through a familiar unit: the seat. A bank buys licenses. Employees log in. Procurement compares features, security, integrations, uptime, and price per user. Management turns the tool into an outcome.

AI is starting to break that model.

An agent does not only help a person use software. It can retrieve information, call tools, update a record, route an exception, draft a communication, and complete a defined sequence of actions. The commercial unit is beginning to move from access to activity: a conversation, an action, a completed case, or a pool of machine capacity.

The phrase digital labor is imperfect. An AI system is not an employee, and the label does not create judgment or accountability. But it captures a real market shift.

Banks are no longer buying only software that people operate. They are beginning to buy systems that perform part of the work.

The institutions that understand this early will ask very different questions from the ones still negotiating AI as another SaaS contract.

The pricing model is already moving

Look at how major vendors describe their agent products.

Salesforce offers Agentforce pricing based on conversations or credits consumed when an agent performs actions. Rates and packaging may change, and its claim that credits align cost with value is a vendor claim. Still, the unit is revealing: customers can pay for activity, not only users.

Microsoft's 2026 Copilot Studio guide similarly meters agent answers, grounding, and actions through credits, offered in capacity packs or pay-as-you-go. This is product pricing, not proof of customer value. It shows the direction of the model.

The buyer now has a meter running against machine work.

That creates a new problem. A bank knows what a seat costs. It may not know how many actions an onboarding case should consume or who pays when poor orchestration turns one outcome into fifty billable steps.

Per-action pricing can align cost with use. It can also make a badly designed process expensive at machine speed.

Banks are also changing the language of capacity

The demand side is moving too.

BNY's 2025 annual report says the bank had 160 enterprise AI solutions in production and 134 "digital employees," which it defines as multi-agent systems operating alongside human colleagues. The same report says these systems work within its enterprise AI platform, while employees receive broad access and training.

Those are company-reported figures, not an industry benchmark. They matter because a regulated institution is describing AI as operating capacity, not merely a feature.

This is a more important signal than another chatbot launch. Once a bank assigns an agent credentials, a workflow, permissions, a supervisor, and performance expectations, the governance problem begins to look partly like technology management and partly like workforce design.

Who owns the output? What work can it accept? Who reviews exceptions? What happens when the model or vendor changes?

The future I described in The Model Is the Cheapest Part of Enterprise AI follows directly from this. Model access will become easier to buy. Reliable work will remain difficult to design.

A software contract is not enough

Traditional contracts focus on availability, security, data, support, and function. Those still matter. They do not fully describe a system performing regulated work.

An agent preparing a payment investigation needs a defined unit of work and evidence standard. One changing a client record needs an authority boundary. One communicating externally needs review conditions and a record. Multiple tools create a dependency chain the bank must understand.

This is why banks are buying AI with contracts written for 2015. The issue is not that every legacy clause is obsolete. It is that uptime and data-processing terms do not answer who is responsible for a bad action taken by a system that can plan and execute.

The contract has to follow the work.

Seven things to buy when the product performs labor

I would expect serious AI procurement to move toward seven operating commitments.

1. A defined unit of work

Name the thing being purchased: one reviewed alert, one prepared client file, one resolved service request, one reconciled exception.

"Access to an AI agent" is not a measurable deliverable.

2. A baseline and an outcome

Record cost, cycle time, error, rework, and service level. Define what must improve.

Usage is not the outcome. A busy agent can create more review work than it removes.

3. An authority envelope

Specify which systems and fields the agent may access or change, its limits, and decisions reserved for people.

The permission should belong to the workflow, not to a vendor's broad product category.

4. Evidence and auditability

The bank should reconstruct inputs, sources, tool calls, approvals, actions, and results for material work.

An answer log is not enough when the system can act.

5. Failure economics

Define who absorbs retries, loops, duplicate actions, unavailable tools, and human remediation. Consumption pricing needs cloud-style cost controls.

6. Portability and exit

Models and prices will change. The bank needs to move workflows, logs, evaluations, and policy without rebuilding from zero.

7. A named human owner

Every production agent needs an accountable business owner with the authority to narrow scope, pause work, and decide when performance is good enough to expand.

As with any consequential AI process, human oversight needs an operating design, not a sentence in a policy.

The dependency risk gets larger, not smaller

Usage-based agent markets may give banks more flexibility. They can also deepen dependence on a small number of providers.

The Bank of England and FCA's 2024 survey found that one-third of reported AI use cases were third-party implementations. The top three named providers accounted for 44% of model providers and 73% of cloud providers. The survey population and methodology limit how broadly those numbers should be applied, but the concentration signal is clear.

The Financial Stability Board identifies third-party dependency and provider concentration as potential vulnerabilities. An agentic workflow may depend on a model, cloud, data provider, orchestrator, and external tools at once.

When software assists an employee, an outage is disruptive. When an agent owns part of a queue, an outage can remove operating capacity.

Banks will need tested fallbacks, substitutable components where practical, process-level service measures, and clear responsibility for every control.

What may happen between 2027 and 2030

The following is a market scenario, not a forecast presented as fact.

First, I expect hybrid pricing: a platform fee plus metered actions, capacity, or outcomes. Per-seat pricing will remain where a person is the primary user, but fit continuous machine work less naturally.

Second, AI budgets and workforce plans will meet. Finance teams will compare machine capacity with internal processing, outsourcing, and managed services. The useful comparison is total cost and quality for a unit of work, including oversight and exceptions.

Third, the control layer will become strategic. Identity, permissions, runtime policy, evaluation, audit, and cost will matter as much as model quality. Singapore's 2026 safeguards for agentic finance point toward identity, authority, pre-execution controls, and audit records.

Fourth, some software vendors will resemble service providers. If they promise completed work, buyers will expect operational performance, not just availability. Liability and outcome definitions will get harder.

Fifth, models may commoditize while supply risk remains concentrated. Easier model switching will not remove dependence on a narrow cloud, compute, and platform layer.

None of this means banks will replace their workforce with agents by 2030. That would be a claim without evidence. It means the boundary between software spend, operations spend, and outsourced capacity is likely to blur.

Buy work, but keep accountability

The appeal of digital labor is obvious. Capacity can scale, routine work can move faster, and human attention can shift to exceptions, relationships, and decisions.

The danger is equally obvious. An institution can outsource activity without outsourcing responsibility.

A bank remains accountable for the customer outcome, the control environment, and the resilience of the process. No credit meter changes that. No "digital employee" label changes it either.

The winning model will combine software flexibility with operational discipline: define the work, bound authority, meter economics, test controls, and preserve an exit.

Banks spent the last decade buying software by counting users.

The next decade will require them to buy intelligence by understanding work.

Sources

• BNY — Annual Report 2025

• Salesforce — Agentforce pricing

• Microsoft — Copilot Studio Licensing Guide, April 2026

• Bank of England and FCA — Artificial intelligence in UK financial services 2024

• Financial Stability Board — Monitoring AI adoption and related vulnerabilities, 2025

• Monetary Authority of Singapore — Building the financial system of the future, 2026