This policy brief is based on BIS Working Paper, No 1310 “AI agents for cash management in payment systems”. Views are those of the authors and not necessarily those of the Bank for International Settlements or the Bank of Canada.
Abstract
This brief summarizes new evidence on the use of general‑purpose artificial intelligence (AI) agents to assist cash management in real‑time gross settlement (RTGS) payment systems. Using prompt‑based experiments with a reasoning-capable large language model, we test whether an AI agent can maintain precautionary liquidity buffers, prioritize payments under tight constraints and uncertainty and balance the trade‑off between settlement speed and liquidity (or borrowing) costs. Even without domain‑specific training, the agent consistently replicates key prudential practices, issues calibrated recommendations and adapts to incoming information, suggesting scope to automate routine cash‑management tasks and improve intraday liquidity efficiency. The results also underscore important safeguards (human‑in‑the‑loop governance, transparency, cyber resilience and third‑party/vendor risk management) if AI tools are to be integrated responsibly into systemically important financial market infrastructures.
High‑value payment systems are the plumbing of modern economies. In RTGS systems such as Fedwire, CHAPS, TARGET2/T2 and Lynx, participants continuously trade off the cost of liquidity against the cost of delay (Bech and Garratt, 2003). Upfront funding is typically secured against collateral at an opportunity cost, while intraday payment choices aim to recycle incoming funds and triage queues to meet urgent obligations (Bank of England, 2021; Bank of Canada, 2022). Recent advances in generative and “agentic” AI — large language models (LLMs) that can reason, plan and act step‑by‑step — raise the practical question: can AI agents safely assist parts of this daily cash‑management workflow?
Aldasoro and Desai (2025) address this question using controlled, prompt‑based experiments. The paper places an AI agent into stylized cash‑management situations that resemble the environment faced by a bank’s cash manager. Each scenario presents the agent with the current liquidity position, a queue of pending payments, the likelihood of urgent requests and the probabilities of incoming funds that can be recycled. The agent is asked to decide whether to send, delay, or partially execute queued payments and to recommend initial pre‑funding that balances expected delay and borrowing costs. Responses are stress‑tested by varying probabilities, amounts and wording. The authors also evaluate an “operator mode”, where the agent autonomously completes a structured questionnaire of cash‑management tasks (e.g. prioritization, anomaly detection) and defers to human review when appropriate.
A useful way to understand the workflow is to visualize the agent’s information inputs and decision outputs. Figure 1 depicts how the agent ingests policy constraints, collateral and liquidity, internal queue data and expected incoming payments, before producing decisions on payment triage and liquidity allocation. This end‑to‑end view helps clarify the agent’s reasoning pathway and the points where human oversight should remain in the loop.
Figure 1. AI agent as assistant cash manager in high‑value payment systems

Before turning to the scenarios, the paper situates capabilities within a progression framework for AI agents in payment systems: from simple tools and assistants to operators, actors and fully autonomous agents (Figure 2). This framework clarifies that the experiments assess “assistant‑level” use cases (propose actions; humans execute or override), emphasizing feasibility and boundaries of safe deployment.
Figure 2. High-level progression framework for AI agents

Across a sequence of scenarios, the agent displays prudent behavior consistent with sound intraday cash management. When faced with tight constraints and a plausible urgent payment in the next period, the agent typically delays small, non‑urgent payments to preserve a liquidity buffer — replicating standard practice without being explicitly programmed to do so. This precautionary stance proves robust to wide changes in probabilities (down to very low odds), scaling of amounts (from small to very large values) and wording variations. In settings where likely inflows could replenish liquidity, the agent processes lower‑risk payments while withholding other outflows to keep headroom for potential urgent needs. As scenarios include more contingencies, choices remain sensible but exhibit some run‑to‑run variation — mirroring the discretion observed in human operations under uncertainty.
When asked to pre‑fund the day, the agent weighs the upfront cost of liquidity against expected delay and borrowing costs over subsequent periods. With high‑probability incoming funds later in the day, it recommends modest initial liquidity and relies on recycling — accepting a small risk that is quantitatively outweighed by savings on opportunity cost. This behavior aligns with the liquidity‑saving logic that underpins RTGS operations and liquidity‑saving mechanisms (Bank of England, 2021; Bank of Canada, 2022) and with research showing how recycling and timing choices can affect gridlock risk and externalities across participants (Rivadeneyra and Zhang, 2022; Castro et al., 2025). In a simulated “operator mode”, the agent completes a multi‑step set of cash‑management tasks, responds quickly and coherently and appropriately escalates atypical or potentially fraudulent instructions for human oversight. This is consistent with good operational risk practice and human‑in‑the‑loop principles (FSB, 2024; BIS, 2024; Aldasoro et al., 2024).
The experiments suggest that purpose‑built AI agents could automate routine cash‑management tasks (such as triaging non‑urgent queues, recommending precautionary buffers and pre‑screening for anomalies) potentially lowering operational costs and improving intraday liquidity efficiency by recycling funds more effectively throughout the day. These gains are particularly relevant as payment systems move toward always-on operations.
Prudent, precautionary behavior emerges even without domain‑specific training, which is encouraging for baseline safety and early prototyping. At the same time, responsible integration into FMIs requires safeguards. Model opacity, data quality and out‑of‑distribution (“black swan”) events necessitate human‑in‑the‑loop governance, explainability, robust testing, staged deployment and cyber resilience (BIS, 2024; FSB, 2024; Aldasoro et al., 2024).
System‑wide considerations also matter. Coordination across participants influences gridlock risk and liquidity externalities (Rivadeneyra and Zhang, 2022), while widespread reliance on similar models or providers could introduce correlated behaviors or vendor concentration risks (Gambacorta and Shreeti, 2025). Evolving regulatory frameworks — such as the EU’s risk‑based approach to AI — underscore supervisory expectations around governance, model risk management, third‑party risk, transparency and meaningful human oversight (Crisanto et al., 2024; FSB, 2024).
Prompt‑based experiments indicate that general‑purpose AI agents can produce sensible, precautionary recommendations for intraday cash management, prioritizing payments under uncertainty and balancing liquidity-delay trade‑offs. Early use cases should keep humans firmly in the loop and target low‑risk workflows (e.g. non‑urgent queues), with rigorous testing, guardrails, audit logging, cyber protections and fallback procedures. Before any system‑wide deployment, participants and operators should explore multi‑agent simulations to capture payment recycling, queuing externalities and gridlock dynamics across institutions. Taken together, the evidence points to practical opportunities for efficiency gains, provided that adoption is gradual, transparent and aligned with emerging regulatory expectations. Policymakers and market operators can use such controlled pilots to refine governance, build resilience and ensure the benefits of AI are realized without compromising the safety of systemically important payment systems.
Aldasoro, I., S. Doerr, L. Gambacorta, S. Notra, T. Oliviero and D. Whyte (2024). Generative artificial intelligence and cyber security in central banking. Journal of Financial Regulation, 11(1), 119–128.
Aldasoro, I. and A. Desai (2025). AI agents for cash management in payment systems. BIS Working Papers No 1310.
Bank of Canada (2022). An overview of Lynx, Canada’s high‑value payment system.
Bank of England (2021). Liquidity saving mechanism (LSM) user guide.
Bech, M. L. and R. Garratt (2003). The intraday liquidity management game. Journal of Economic Theory, 109(2), 198–219.
BIS (2024). Artificial intelligence and the economy: implications for central banks. Annual Economic Report, Chapter III.
Castro, P., A. Desai, H. Du, R. Garratt and F. Rivadeneyra (2025). Estimating policy functions in payment systems using reinforcement learning. ACM Transactions on Economics and Computation, 13(1), 1–31.
Crisanto, J.-C., C.-B. Leuterio, J. Prenio and J. Yong (2024). Regulating AI in the financial sector: recent developments and main challenges. Bank for International Settlements.
FSB (2024). The financial stability implications of artificial intelligence. Report to the G20.
Gambacorta, L. and V. Shreeti (2025). The AI supply chain. BIS Papers No 154.
Rivadeneyra, F. and N. Zhang (2022). Payment coordination and liquidity efficiency in the new Canadian wholesale payments system. Bank of Canada Staff Working Paper 2022‑3.