Ken Griffin, the CEO of Citadel, put it plainly: “For the first time, AI is real. These are extraordinarily high skilled jobs being automated by agentic AI.”[1] He was not talking about call centre scripts or data entry. He was describing the automation of professional judgement, the kind of work that IFAs, paraplanners, and wealth managers spend their careers building. That statement, made in May 2026, is the most useful frame for what follows.
The question for a firm like yours is not whether agents will change how work gets done. They already are. The question is whether you will manage that transition deliberately, or stumble into it.
What has actually changed in the past twelve months
Until recently, AI tools in financial services were mostly copilots: they suggested, you decided. The shift underway now is different in kind, not degree. AI coding agents, workflow agents, and research agents no longer wait for you to approve each step. They execute sequences of tasks autonomously, report outcomes, and in some configurations spin up sub-agents to handle parallel workstreams.[2]
Asana’s acquisition of StackAI and Anthropic’s expanded workflow features both signal where the infrastructure is consolidating: around orchestration.[3] The tools being built assume that humans are managing fleets of agents, not using a single assistant. That assumption is already baked into the products arriving at your door.
For a financial services firm, this matters because the tasks these agents are taking on (research, document drafting, compliance checking, client data synthesis) are not trivial. They sit close to regulated outputs. And the governance frameworks most firms have in place were designed for human workflows.
The “agentic human sandwich” is your new operating model
The most useful mental model I’ve encountered for thinking about where humans fit is this: you are the bun, the agent is the filling. You provide the context and constraints at the start; you verify and approve the output at the end. The agent handles the execution in the middle.
The management skill that matters in an agentic firm is not delegation, it is the quality of your initial brief and the rigour of your final review.
This sounds straightforward. In practice it requires two skills that most firms have not yet developed: writing precise agent instructions (sometimes called “prompting less and steering more”[4]), and building a review process that catches agent errors before they become client-facing problems.
The first is learnable. The second needs to be designed. An agent that drafts a suitability letter still needs a human to read it and take responsibility for it. An agent that screens a client document for AML flags still needs a human to make the call. The review step is not optional, and in a regulated context it is not cosmetic. It is where your professional liability lives.
What changes about management when agents do the executing
Seventy percent of enterprise AI adoption in 2026 is moving toward integrated workflow redesigns rather than point-tool use[5], meaning firms are not just adding AI to existing processes, they are restructuring around it. For a firm with advisers, paraplanners, and admin staff, that restructuring touches how you deploy people, not just how you deploy software.
Three things shift noticeably:
The bottleneck moves. In a human workflow, the constraint is usually capacity: how many people you have and how fast they work. In an agentic workflow, as agents become faster and more autonomous, the constraint becomes the human review cycle. Your ability to approve, steer, and correct agent outputs becomes the rate-limiting step.[6] A paraplanner who previously spent six hours drafting a report might spend ninety minutes reviewing and adjusting one an agent produced. That is a productivity gain, but it requires the paraplanner to operate at a higher level of judgement throughout, not just at the end.
Role definitions become less about tasks and more about outcomes. If an agent handles the execution, the human role is to define what a good outcome looks like, set the constraints the agent operates within, and evaluate whether the output meets the standard. That is closer to a principal’s job than a practitioner’s job, and it requires different skills. Not everyone makes that transition easily, and managing it well is a leadership challenge, not a technology challenge.
Oversight is not passive. Managing agents well requires active monitoring: reviewing logs, checking outputs against expected behaviour, catching drift when an agent starts producing subtly wrong results. One of the more consequential findings in current enterprise AI research is that 54% of firms deploying agents have already experienced a security or reliability incident, yet most continue operating agents under the same conditions.[7] That gap between known risk and changed behaviour is not a technology failure. It is a management failure.
What your firm should do now
This is not a five-year horizon. Firms deploying agents in client-adjacent workflows today need governance in place now. Here is a practical starting point:
1. Map every agent or automation touching client data or regulated outputs. This does not need to be a formal project. It needs to be honest. If an agent is drafting documents, running compliance checks, or touching client records, it belongs on the list. If you do not know what is running, you cannot govern it.
2. Define the review step for each agent, in writing. Who reads the output before it is used? What are they checking for? What are they authorised to approve? If the answer is “whoever is around” or “the person who set it up”, that is not a review process. It is an assumption.
3. Test your agents against edge cases, not just typical inputs. Agents tend to perform well on common scenarios and fail unexpectedly on outliers. In financial services, the outliers are often the cases where errors matter most. Shadow testing, running the agent in parallel with your existing process before you depend on it, is the practical control here.[8]
4. Set access boundaries before you scale. An agent that needs to read client files to do its job should not have write access to your CRM, or access to credentials beyond what the task requires. The principle is least-privilege access: agents get exactly the permissions the task needs, and no more. This is where most firms are currently exposed, and it is fixable without significant cost.
5. Assign named accountability. Under SMCR, someone in your firm is responsible for the systems and controls around regulated activity. That accountability extends to automated systems. A named individual should own each significant agent deployment, not the IT team, not the vendor, but a named person who will answer for it.
The management identity shift
The harder change is not operational. It is how senior people in your firm think about their own role.
Ken Griffin’s comment is worth sitting with. The jobs being automated now are not low-skill. They are the jobs that required years to develop competence in. The professional whose identity was built around executing a particular kind of work, building a cashflow model, drafting a research note, reviewing a compliance checklist, will find that an agent can now do a credible version of that in minutes.
The human value in that world is not the execution. It is the judgement about whether the execution was right, the relationship with the client who receives the output, and the professional accountability that no agent can hold. Those things are not small. But they require a conscious shift in how people in your firm understand what they are for.
That shift does not happen by itself. It happens because leaders name it, make space for it, and manage the transition deliberately.
If you want to think through what that looks like for your firm specifically, a discovery call with Cordrey Consulting is a good place to start.
This article is for informational purposes only and does not constitute regulated financial advice or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.
Sources
[1] AI Daily Brief, reporting Ken Griffin (CEO, Citadel), public remarks on agentic AI, May 2026. [Cited for Griffin quote on agentic AI and high-skilled job automation.]
[2] van Riel, Z., ‘AI Coding Agents Tutorial’, Zen van Riel, AI Engineer Blog, 2026. Available at: https://zenvanriel.com/ai-engineer-blog/ai-coding-agents-tutorial. [Cited for shift from copilot/autocomplete to autonomous task-based execution.]
[3] TechCrunch, ‘Asana acquires no-code agent builder StackAI’, 28 May 2026. Available at: https://techcrunch.com/2026/05/28/asana-acquires-no-code-agent-builder-stackai. [Cited for consolidation of agent infrastructure around orchestration tooling.]
[4] Everyday AI, commentary on shift from prompt-box interaction to agent consumption, June 2026. [Cited for “prompting less, steering more” framing; no primary URL available.]
[5] Gadoci Consulting, ‘What We’ve Learned About AI and the Enterprise as of Today, June 5 2026’, 2026. Available at: https://gadociconsulting.com/articles/what-we-ve-learned-about-ai-and-the-enterprise-as-of-today-june-5-2026. Vendor-sourced. [Cited for 70% of enterprise AI adoption moving toward integrated workflow redesigns.]
[6] AI Daily Brief, framework note on human review cycle as production constraint in agentic workflows, May 2026. [Cited for observation that human approval and steering becomes the rate-limiting step as agents accelerate.]
[7] VentureBeat, ‘The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials’, 18 July 2026. Available at: https://venturebeat.com/ai/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials. [Cited for 54% enterprise AI agent incident statistic.]
[8] van Riel, Z., ‘Deploy Production AI in 2026, Cut Errors by 50% Fast’, Zen van Riel, AI Engineer Blog, 18 July 2026. Available at: https://zenvanriel.com/ai-engineer-blog/deploy-production-ai-2026-cut-errors-50-percent. [Cited for shadow testing as a pre-deployment validation control.]