From Mainframes to Agentic AI: The Enduring Blueprint for Trust in Financial Technology

In the high-stakes world of global finance, the leap from clunky, monolithic mainframes to the agile, intelligent promise of agentic AI feels like a transition between different centuries. Yet, for veteran technology executives, the two worlds are far more similar than they appear. As financial institutions race to integrate autonomous agents into their core operations, a growing consensus suggests that the future of reliable AI doesn’t lie in the complexity of the models, but in the rigorous, often unglamorous, discipline of the mainframe era.

Alexis Peter Francis, a product and data executive with two decades of experience across IBM and major global card issuers, argues that the "move fast and break things" ethos is fundamentally incompatible with the mandate of modern banking. Instead, he posits that the key to building trustworthy AI lies in applying the rigid traceability, deterministic outcomes, and documented lineage that defined the backbone of 20th-century computing.

The Legacy Standard: Lessons from the Mainframe

Early in his career, while modernizing mainframe systems at IBM, Francis learned a lesson that would define his professional philosophy: trust is not granted to the most sophisticated system, but to the most predictable one.

In the mainframe environment, COBOL programs and CICS transaction systems were the bedrock of the global economy. They were not modern by today’s standards, but they possessed a core virtue that modern developers sometimes overlook: transparency. Every transaction was traceable, every failure was diagnosable, and every change was rigorously documented.

"The knowledge required to troubleshoot these systems existed primarily in the heads of a shrinking pool of specialists," Francis notes. The stakes were so high that wholesale migrations off these systems remain incredibly rare; industry data indicates that mainframe replacement rates hover at a mere 0.2 percent. When Francis and his teams were tasked with exposing these legacy systems to the web, they could not simply "modernize and hope for the best." They had to wrap these systems in layers of data lineage, error handling, and rollback protocols. Every interface had to behave deterministically, ensuring that downstream systems—and regulators—could rely on the output.

Chronology of a Data Evolution

The journey from batch-processed mainframes to the real-time, agentic AI landscape has been marked by several key turning points:

  • The Mainframe Era (1990s–2000s): The foundation of systemic stability. Focus was placed on data integrity and the "known-state" of transactions.
  • The Integration Phase (2010s): The era of mergers and large-scale data modernization. During the massive Express Scripts and Medco merger, engineers discovered that the risk was rarely missing data, but rather the "misinterpretation of embedded business logic" accumulated over decades. This served as a stark reminder that data is only as valuable as the context in which it was created.
  • The AI Proliferation (2022–Present): The current shift toward agentic AI. While AI productivity gains in exposed industries have quadrupled since 2022, only 4.5 percent of organizations currently trust these systems to act with full autonomy.

Supporting Data: The Trust Gap in AI

Despite the hype surrounding artificial intelligence, the transition to autonomous decision-making remains stunted by a profound "trust gap." According to recent industry surveys, while 75 percent of financial firms are actively utilizing AI, their deployment strategies remain cautious.

Nearly half of these organizations continue to mandate a "human-in-the-loop" requirement, where AI provides recommendations while human operators retain final decision-making authority. This is not merely a sign of technological immaturity; it is a direct response to the regulatory and operational risks inherent in autonomous systems.

The risks are not theoretical. In sectors like counterparty hierarchy validation, exposure aggregation, and FDIC 370 reporting, a single, unverified AI error can cascade into materially misstated credit assessments. Such failures have historically led to severe consequences:

From mainframes to Agentic AI, what legacy system discipline can teach us about building trustworthy customer data platforms
  1. Regulatory Fines: Massive penalties for reporting inaccuracies.
  2. Enforcement Actions: Mandated, multi-year remediation programs that drain internal resources.
  3. Operational Restrictions: In extreme cases, regulators have limited the ability of banks to conduct business or execute certain strategic operations.

Official Responses and Regulatory Shifts

The regulatory landscape is rapidly shifting to meet the challenges posed by these new technologies. Recognizing that AI cannot be treated as a "black box," global watchdogs are beginning to formalize requirements for transparency.

In October 2024, the UK’s Financial Conduct Authority (FCA) launched its AI Lab, an initiative specifically designed to address the risks of AI in finance. The lab features a "Supercharged Sandbox," allowing firms to experiment with AI in a secure, controlled environment. Perhaps more importantly, the FCA has begun deep research into AI bias, specifically focusing on how language models and automated credit-scoring algorithms function in practice.

The core message from regulators is clear: the "black box" is no longer an acceptable excuse. Whether it is a simple database query or a sophisticated Large Language Model (LLM) acting as an agent, the system must be able to answer four fundamental questions:

  • How was this decision made?
  • What data was utilized in the process?
  • Who provided the final approval?
  • Can this specific outcome be reproduced in an audit?

Implications: Building the "Defensible" Architecture

For firms looking to scale AI, the implications are profound. The most successful organizations will be those that view "human-in-the-loop" oversight not as a safety net to be bolted on, but as a foundational design requirement.

The Hybrid Model

The most effective way to deploy agentic AI is through a hybrid model that prioritizes "defensibility." For instance, when implementing AI for counterparty validation, the goal should be to reduce manual review effort—perhaps by 50 percent—while preserving 100 percent of the human attestation and audit traceability. This creates a workflow where the AI handles the "heavy lifting" of data aggregation and initial analysis, while the human expert acts as the final arbiter of truth.

Addressing the Fragmentation of "Customer 360"

Building a unified view of the customer—often called "Customer 360"—is perhaps the most difficult technical hurdle in banking. With some institutions managing up to 248 million customers and billions of network linkages, the fragmentation of master data remains a primary obstacle.

The lesson from the mainframe era is that proprietary algorithms are often necessary because vendor-provided tools simply cannot account for the decades of institutional knowledge embedded in how a bank’s data was originally structured. Success in this area requires an "obsessive attention to data lineage." Every piece of data in a modern Customer 360 platform must be treated with the same respect for its origin, transformation, and destination that a batch job in 1995 required.

The Future of Trustworthy AI

As the industry moves forward, the divide between firms that succeed and those that stumble will be defined by their ability to reconcile speed with accountability. The institutions that treat traceability, human accountability, and documented change as fundamental design requirements—much like the mainframe engineers of the past—will be the ones that earn the lasting trust of both regulators and customers.

The technology has indeed changed, but the requirements for building a robust financial system have not. Whether through a 1980s mainframe or a 2020s agentic AI, the goal remains the same: ensuring that every decision is defensible, every process is transparent, and every outcome is backed by a clear line of accountability. As Francis concludes, "The technology has changed. The requirements for trust have not."