By – Shreya Vakkaleri
Abstract
This article contends that AI-powered banking is not a neutral process of automation. Once an algorithm affects a customer’s financial choices, existing frameworks that rely on human intent and time-bound responsibility become strained. Therefore, banks should be held to higher standards of oversight, transparency, and accountability.
Introduction
In September 2025, YTL Group partnered up with Sea Limited to launch Ryt Bank, Malaysia’s first AI-powered bank. Licensed by Bank Negara Malaysia (BNM), its deposits are covered by Perbandan Insurance Deposit Malaysia (PIDM), with amounts staggering up to Malaysian Ringgit (RM) 250,000 per customer. It seeks to provide financial services that are inclusive and accessible through its AI-powered assistant Ryt AI, which has been trained to understand human conversations in Bahasa Malay, English and Mandarin. It can read and pay bills, track spending, and explain financial basics in simple language, balancing convenience, cultural familiarity, and security. This indicates a structural shift in how banking decisions are made, explained, and experienced by customers. As AI evolves from supporting staff to influencing financial decisions and consumer interactions, the question remains whether it assists customers or drives choices in ways requiring stricter bank regulation
Ryt Bank as a legal signal
Ryt Bank matters because it illustrates how far AI has already entered consumer banking. Though its features might seem consumer-friendly at first glance, they also reveal the legal issues at stake. An AI banking assistant that converses with its customers, prompts their financial actions, and explains products in a simple manner is overstepping its role as a passive software interface, consequently becoming a direct participant in its customers’ decision-making. This participation raises issues about inducement, reliance, correction of errors, and understanding the underlying rationale behind decisions made by an AI system.
Why duty matters
Under ordinary banking negligence and accountability principles developed after Barclays Bank PLC v Quincecare Ltd., institutions remain responsible for harmful outputs from algorithmic systems just as they are for those produced by human employees. The traditional model of accountability assumes that a bank employee can be identified as the decision-maker. Instructions can be audited in conventional terms, and that negligence can be traced to a person’s failure to act. However, AI complicates this structure as models are trained, deployed, and used through interfaces that may build trust without revealing their limits, making harm widespread and difficult to trace.
Existing law under pressure
The Quincecare line of authority gives banks the right to refuse executing a transaction on reasonable grounds suspecting misappropriation of funds. The later UK Supreme Court clarification in Philipp v Barclays Bank UK PLC confirms that the bank’s duty is still framed through ordinary principles of authority, instruction, and reasonable care. In other words, courts remain cautious about expanding bank liability simply because modern fraud or banking technology is highly sophisticated.
While such caution is understandable, it also exposes the limits of the Quincecare duty. The Philipp decision emphasised that banks must follow customer instructions, while broader loss allocation is for lawmakers and regulators. However, AI banking raises a different issue: whether algorithms shape instructions, choices, eligibility, pricing, or advice opaquely. This is where the law begins to look incomplete. A duty built around human instruction may be too narrow for systems that actively curate decisions, especially where customers cannot tell whether they are receiving information, persuasion, or commercially driven advice.
Transparency and explanation
AI banking requires greater regulation because transparency is essential to informed consent and meaningful engagement. Opaque decisions can have severe consequences, such as loan refusals, biased financial recommendations, or encouraging borrowing and spending without customer understanding. AI research consistently highlights explainability and accountability as central concerns.
Regulatory thinking is moving in the same direction. BNM has issued a discussion paper on AI in the financial sector, indicating supervisory attention to the risks and governance needs created by AI adoption. Guidelines issued by Malaysia’s Automated Decision Making and Profiling Guideline (ADMP) point toward a future in which people affected by automated decisions may have rights to be informed, to refuse certain fully automated decisions, and to seek human review.
That direction matters because the legitimacy of algorithmic banking depends on more than uptime or accuracy. Customers should know when AI is used, its role, and how to challenge it. Otherwise, banks may comply technically while undermining informed choice.
Responsibility and governance
A duty of care for AI in banking should not mean that the machine is blamed like a guilty human party. Rather, it means that banks and their governance frameworks must view the outputs generated by AI as risky decisions to be subject to supervision, review, and traceability. The most compelling regulation materials do not imply full automation without accountability; rather, they stress on human oversight and clear governance.
That approach is also consistent with the emerging Malaysian framework. The National Guidelines on AI Governance and Ethics note principles such as accessibility, trustworthiness, comprehensiveness, alignment with industry standards, synergy, calling for action and live documentation. Meanwhile, industry discussions linked to Bank Negara Malaysia indicate increasing attention to AI governance frameworks in banking. These are not abstract principles; rather, these are the fundamental elements upon which the legal responsibility will be established in a trust-based environment where damage can propagate rapidly. Therefore, the appropriate legal response is not personifying AI but imposing tougher obligations on the banks deploying it. Hence, they should be required to account for AI model usage, provide a reasonable explanation for major decisions in simple terms, have escalation procedures for disputed outputs, and check for biases, drifts, and harm maximisation. In short, the more decisive the algorithm, the stronger the duty to supervise it.
Consumer protection lens
Consumer protection provides the clearest normative basis for this argument. Banking customers are not buying software for its own sake; they are entrusting regulated institutions with financial judgment, data, and risk. If AI systems are used to personalise, recommend, prioritise, or automate financial choices, then the customer’s vulnerability increases, especially where the interface is conversational and persuasive rather than purely informational.
Ryt Bank’s design illustrates this tension well. The same features that make AI banking attractive, namely plain-language explanations, instant bill payment, and conversational assistance can also make it easier for customers to rely too heavily on the system’s output. That is concerning when a bank’s system combines convenience with product promotion, because the line between helpful guidance and commercially oriented nudging can become difficult to see.
Consequently, consumer law should demand more than general disclaimers. It should insist on measured disclosure, clarity of information, right of review for major decisions, and internal controls which enable identifying that the recommendation provided by the model was made based on flawed data, biased training, or commercially driven optimisation.
A workable standard
A realistic duty of care framework for AI banking should have four parts. First, the bank must assess the extent to which AI materially influences each customer-facing or decision-making process. Second, the bank must keep human control over all significant processes and outcomes, particularly those concerning credit decisions, fraud detection, pricing, and product recommendation. Third, the bank must give customers an explanation and a means of challenging that explanation. Fourth, they should keep auditable records of model behaviour, testing, and incident response.
This is not an argument against AI in banking. If properly designed, AI could enhance accessibility, minimize friction and increase inclusion, especially in linguistically diverse markets like Malaysia. Convenience does not absolve one of responsibility, but increases it, since clients are much more prone to trust and depend upon smart, responsive and personalised systems. The deeper point is that legal responsibility should track functional power. Where AI only assists a bank employee, the duty may remain ordinary. Where AI shapes the customer’s options, filters information, or materially influences a financial choice, the law should recognise a heightened duty of care grounded in oversight, explainability, and accountability.
Conclusion
AI-powered banking is forcing law to confront a familiar but sharpened problem: when institutions delegate meaningful judgment to machines, who bears the moral and legal burden when things go wrong? Malaysia’s Ryt Bank shows that this is no longer a speculative question. Technology already forms an integral part of the bank’s interface with customers, as well as the decision-making process.
The right approach is not to treat AI as a legal person, nor to pretend it is a mere neutral tool. The banks using AI technology owe greater responsibility since they make the choice of technology to use, they benefit from it, and they are also in the best position to control the risks involved. If banking is built on trust, then algorithmic banking must be built on explainability, human oversight, and enforceable responsibility.
Author’s bio
Shreya Vakkaleri is a second-year law student currently pursuing B.A LL. B (Hons.) from Jindal Global Law School, Sonipat. Her areas of interest include banking & securities law, aviation law, constitutional law and commercial international arbitration.
Image Source: https://www.artificialintelligence-news.com/news/malaysia-launches-ryt-bank-its-first-ai-powered-bank/

