← Blog

The trust gap: why 95% of fund managers use AI and only 7% run agents

95% of fund managers use AI. 7% run agents. A former ops operator on what the gap is made of, what closes it, and what agents still cannot do.

Every trading day, at every fund, the same race starts the moment the market closes. The trades are done. The day is not. Trade files go out to the prime brokers and the administrator, files come back, and somewhere in operations a person starts tying the day out: do the positions the fund thinks it holds match what the administrator booked, does the cash match, did every trade land where it was sent. There is a deadline, and it is not an arbitrary one. Books roll overnight, other time zones open, and tomorrow's trading starts from tonight's numbers. If tonight's numbers are wrong and nobody catches it, tomorrow starts wrong. Wrong compounds.

Key takeaways

  • 95% of fund managers already use generative AI at work (AIMA/Marex, 2025), but only 7% have deployed agentic AI that does work rather than drafting text (EY, 2026).
  • The gap is not a technology gap. It is a trust gap: identity, 2FA, data handling, and what the agent does when it is unsure.
  • The near-term value of agents in operations is hands, not judgment: the mechanical work before the first real decision, run at a frequency no human team can match.
  • FINRA's 2026 oversight report reads as a build sheet for trustworthy agents: scoped non-human accounts, human approval, auditable reasoning, contractual data terms.

What is strange is how manual the inside of that window still is, given what rides on it. Portal logins. A two-factor prompt. A report queue that takes its time. Totals read off one screen and typed into another because there is no clean export. A workbook where the checks actually live. If everything ties, sign off, go home. If something does not tie, the race turns into an investigation with the clock still running.

I spent eight years around this hour at a bank and a hedge fund, and now I sell software into it, which means I sit in conference rooms with the people who run it today. Here is the strange thing about those rooms in 2026.

Everyone already uses AI. AIMA surveyed 150 fund managers last September and 95% said they use generative AI at work. But when EY asked wealth and asset managers whether they had deployed agentic AI, AI that does work instead of drafting text, 7% said yes.

Use generative AI at work AIMA/MAREX · 2025 95% Run agentic AI in production EY · 2026 7% THE TRUST GAP
Survey of 150 fund managers (AIMA/Marex, Sep 2025) · wealth & asset managers on agentic deployment (EY, 2026)

Ninety-five and seven. The whole industry lives in the space between those numbers, and I don't think the space is made of technology. Every ops leader I meet has tried the chatbots. The question that decides whether an agent gets deployed is never "is the model smart enough." It's a version of: whose login does it use, what happens when it hits our two-factor prompt, where does our data go, and what does it do when it's not sure. In roughly every second first meeting, 2FA is the opening question. These are architecture questions, and a lot of what's being sold can't answer them, so buyers stall, reasonably.

There's a second reason for the stall that vendors don't like to bring up. MIT's NANDA project looked at about 300 enterprise AI deployments last year and found that 95% of pilots produced no measurable P&L impact. Buyers have noticed. Skepticism isn't a failure of imagination on their part; it's pattern recognition.

Hands, not judgment

Mercer's 2026 survey found 6% of asset managers let AI touch investment decisions. That's great. I believe it should stay near there for human judgement investments.

The mistake is concluding that low number means AI has no place at a fund. Walk back through the hour after the close and count the decisions in it. Logging in is not a decision. Requesting the report is not a decision. Downloading, pasting, retyping the totals: not decisions. The first actual decision arrives when two numbers disagree by more than tolerance, and someone has to figure out why. Everything before that moment is hands. At most funds, expensive, capable people spend most of their day being hands.

That's the entire case for computer-use agents in operations. The agent works the same screens a person works, no API project, and stops exactly where judgment starts: it surfaces the break with the cause attached, drafts the email to the administrator, and doesn't send it. Someone on the team decides. The shape repeats everywhere we look. Managers reconciling across three prime brokers and an admin. Allocators processing capital calls from a hundred GP portals that each deliver notices as their own flavor of PDF (there's a reason the ILPA had to publish a standard template). Family offices in K-1 season. Fintechs reconciling settlements with partners that will never build an API. Different industries, same anatomy: portal-bound, credential-gated, mechanical until the exception, human at the exception.

Ops veterans have heard automation promises before, and the RPA scars are real: scripts that died every time a vendor moved a login button. The honest difference this time is narrow but it matters. An agent reads the screen. When the login page changes, it logs in anyway.

Frequency is the product

Vendors, us included, like to talk about saved time. After enough of these conversations I think that's the weaker half of the argument.

Reconciliation at most funds runs once a day, in a fixed window, because a person can only do it once. So an error that appears after the check has run gets found tomorrow, or at month-end, or by the auditor. When a recon run costs close to nothing, you don't run it faster. You run it constantly: every file arrival, every half hour, all afternoon. A trade amended after the file cut gets caught minutes later, while the person who can fix it is still at their desk.

Nobody's year is ruined because a tie-out took forty minutes instead of four. Years get ruined by the break nobody caught. Time saved is nice. Errors that stop being able to hide is the thing worth paying for, and it's the one thing a human team genuinely cannot scale, because humans can't do the same hour six times an afternoon.

The regulator told us what to build

FINRA's 2026 oversight report, published in December, added its first standalone section on generative AI. No new rules; the existing technology-neutral ones apply. What's useful is how precisely it names the risks of agents: acting "autonomously without human validation and approval," acting "beyond the user's actual or intended scope and authority," reasoning that can't be audited. It even tells firms to extend least-privilege access discipline to non-human accounts, and to demand data-retention and destruction terms from AI vendors.

Strip the regulatory language and that's a build sheet. Own scoped account per system. Human approval on anything final. A complete log of actions and reasoning. Nothing retained, nothing trained on. When we design to that list it isn't compliance overhead; the list is what a trustworthy employee looks like, human or not. Vendors who treat it as friction are telling you something. (How we build to it.)

What we won't automate

A fair question for any vendor is what the tool can't do, so: ambiguous corporate actions where the data vendors themselves disagree. Fund structures whose legal terms have two defensible readings. Anything a regulator expects an accountable human to sign. Anything that moves money. Moody's wrote in June that human exception-escalation in these systems is a permanent design feature, not a transitional one, and that matches what we see. The boundary isn't a limitation we apologize for. Drawing it clearly is why the other 90% of the hour can be handed over at all.

If you're evaluating any agent vendor, five questions settle most of it in the first meeting: whose identity does the agent use; who clears the 2FA prompt; what's retained after a run; what does it do when it's unsure; and can you watch it work and shut it off yourself. Then don't buy a vision. Run one workflow for thirty days against success criteria you wrote, and look at the numbers. Almost nobody in this industry has published a measured production result at a normal-sized firm yet. The first firms that run real pilots will know what agents are worth while everyone else is still reading surveys.

Common questions

How do AI agents handle two-factor authentication?

They stop and a person approves. The agent has its own account, credentials stay in the firm's vault, and the 2FA push goes to someone on your team. Every session starts with a human tap. A vendor that bypasses 2FA has answered your security question, just not the way they think.

Do AI agents replace fund operations staff?

The deployments that work are capacity plays: the same team handles several times the volume, and people shift from re-keying to reviewing exceptions. The judgment work stays human, and only 6% of managers let AI near decisions (Mercer, 2026).

How is this different from RPA?

RPA replays recorded clicks and breaks when the screen changes. An agent reads the screen, follows the procedure, and escalates exceptions instead of failing silently. The scars your team has from RPA are from brittleness; brittleness is the specific thing that changed.

What does FINRA say about AI agents?

FINRA's 2026 oversight report (December 2025) applies existing technology-neutral rules to AI and names the agent-specific risks: autonomy without human validation, scope creep, unauditable reasoning. It also tells firms what to demand from vendors on data handling. Read it before you buy anything, including from us.

Where does our data go?

In a properly built deployment, nowhere. The agent runs in your cloud or on your hardware, artifacts and logs stay on your machines, the vendor retains nothing, and nothing trains on your data.

About ZommaZomma builds computer-use agents for financial operations. They work the portals and screens your team already uses, with a human at every approval. If you want an honest read on what's automatable on your desk, we run 45-minute working sessions with ops teams: you leave with a map of where the hours go, in your team's words.

Next step

Raise what your team can do.