
AI, without controls, poses a risk for crypto investors
getty
The conversation around artificial intelligence risk has changed quickly. Organizations are no longer dealing only with inaccurate chatbot answers, biased outputs, or employees entering sensitive information into public tools. AI agents can now take actions, use external systems, write code, and pursue multistep objectives with limited supervision.
This shift creates serious implications for financial markets, particularly crypto. Digital assets trade continuously, smart contracts can execute automatically, and blockchain transactions can be difficult or impossible to reverse. When agentic AI is connected to wallets, exchanges, decentralized finance protocols, or payment systems, a weak control can become a permanent financial loss. Agentic AI risk is therefore becoming both an enterprise governance issue and a crypto control issue.
Crypto Makes AI Autonomy More Consequential
A recent incident disclosed by the United Kingdom’s AI Security Institute shows why such autonomy changes the risk equation. During a cyber evaluation, AI agents took sustained, unauthorized actions directed at real people and organizations. The activity was contained, but the incident demonstrated that agents can combine planning, tool use, persistence, and external access in unexpected ways.
The financial risks increase when crypto is involved. An agent with access to a private key or connected wallet may be able to transfer assets, approve a malicious contract, move collateral, or interact with a decentralized protocol. Unlike a conventional payment, there may be no bank to stop the transaction and no established process for reversing it.
Crypto markets also operate around the clock. An agent can continue acting while employees are offline, and automated trading or liquidation mechanisms can amplify an error within minutes. Organizations should therefore evaluate agents according to the systems and assets they can reach, not only the model they use. A moderately capable agent with wallet access may create more financial risk than a stronger model operating in an isolated environment so permission design is becoming as important as model selection.
Internal Controls Must Extend To Wallets And Smart Contracts
Many organizations already use segregation of duties, approval limits, access reviews, and change-management controls. Those same principles need to apply to AI agents interacting with crypto systems.
No agent should be able to create a wallet, modify an address whitelist, and authorize a transfer without any opportunity for human oversight or review. High-risk transactions should require human approval, and approvers should receive the destination address, asset, amount, network, fees, and reason for the transfer. A vague, unclear, or automated request to confirm an automated action is not an effective control.
Private keys and signing authority also require special treatment. Agents should not receive unrestricted access to seed phrases or signing credentials. Multisignature arrangements, hardware security modules, transaction limits, and time-delayed approvals can reduce the chance that one compromised process drains a wallet. Smart-contract interactions should be simulated and screened before execution, especially when unlimited token approvals or unfamiliar code are involved.
Organizations also need logs showing what an agent accessed, what instructions it received, what transactions it proposed, which actions succeeded, and what human (if any) was leading those access. Those records will matter for incident response, audit testing, asset safeguarding, and financial reporting.
AI And Crypto Incidents Require Shared Standards
The Linux Foundation and the Open Secure AI Alliance have proposed the Shared AI Findings Exchange, or SAFE, to help organizations learn confidentially from AI security incidents and near misses. Crypto firms, banks, custodians, exchanges, and accounting professionals should participate in similar information-sharing efforts.
The crypto sector already understands the value of examining hacks, bridge failures, key compromises, and smart-contract exploits. Agentic AI adds another layer because the failure may involve a model, a prompt, a tool integration, an access policy, and an on-chain transaction at the same time. Given that context, effective incident reports should capture all of these elements.
Boards should ask whether agentic AI is covered by wallet governance, cyber response plans, and escalation procedures. Auditors should consider whether unauthorized agent activity could lead to asset loss, misstated balances, undisclosed obligations, or a material weakness in internal control. Finance teams should also determine how failed or malicious on-chain transactions will be identified, valued, and disclosed.
AI agents may eventually improve crypto compliance, reconciliation, fraud detection, and treasury management. Those benefits are real, but autonomy without strong controls can turn software mistakes into irreversible transfers. In crypto, accountability must be built in before an agent receives the ability to act; advocates for crypto and AI alike should take note.