PenFed Spent a Full Year on AI Governance Before Its First Agent Ever Talked to a Member
Digital Transformation

PenFed Spent a Full Year on AI Governance Before Its First Agent Ever Talked to a Member

PenFed's AI agent rollout deflects 70 percent of internal IT requests, but the more useful detail for regulated-industry CIOs is the year of governance work the credit union did before any agent touched a customer.

PublishedAugust 12, 2026
Read time5 min read
Share

A Credit Union's Four-Agent Rollout

PenFed, the Pentagon Federal Credit Union, serves 2.9 million members and holds 31 billion dollars in assets, making it one of the larger member-owned financial institutions in the United States. Built on Salesforce Agentforce, the organization has now deployed four distinct AI agents: Penny, which handles IT support tickets; Max, which supports collections research; Wingman, which assists employees with service tasks; and ACE, the first agent PenFed has put in front of members directly on its banking platforms.

The sequencing is the story here as much as the technology. Three internal-facing agents went live and matured before ACE, the external one, was cleared to interact with actual credit union members, and that ordering was a deliberate governance choice rather than a resourcing constraint. Olivia Boles, PenFed's Assistant Vice President of Solution Architecture, was explicit about why the company built in that order rather than leading with the customer-facing capability that generates the most executive attention.

What Governance-First Actually Looked Like

Boles described a full year, 2025, spent testing governance structures alongside the internal agent pilots, rather than treating governance as a parallel workstream that could catch up after launch. 'We spent an enormous amount of time piloting, designing, and developing, augmenting those governance statutes that we had in place,' she said, describing an approach where existing risk and compliance frameworks were extended specifically to cover agentic behavior, not replaced wholesale with something built from scratch for AI.

That included what Boles called design and development gateways specific to agentic technology, checkpoints that an agent had to pass before it could move from a limited pilot group to a broader employee rollout, and eventually to member-facing status. Her framing of the threshold for going external was direct: 'By the time you get to your first member-facing agent, you have to have ironed out all of the critical features,' naming security, trust, and privacy of member data as the non-negotiable gate.

The Numbers the Internal Agents Are Already Producing

Penny, the IT support agent, now deflects 70 percent of internal IT service requests, a result substantial enough that PenFed turned off its dedicated employee IT phone line entirely. Boles noted plainly that 'Penny handles ITSMs, and so we were actually able to turn off our IT phone number support line for employees,' which is a concrete operational change, not a soft productivity claim that is hard to verify from outside the organization, and one that a CFO can size directly against the headcount and telephony costs it replaced.

Wingman, the broader employee service agent, delivered a 10 percent reduction in handle time and a 30 percent drop in back-office support calls, meaningful numbers for an organization whose call centers field roughly 10,000 member calls every day. Those internal wins built the operational and governance track record that made the case for extending the same underlying platform to ACE, the agent members now interact with directly, and gave the executive team a defensible answer for the board the first time someone asked what member data the new external agent would actually be allowed to see and act on.

Why Regulated Industries Are Becoming the Agentic AI Leaders

PenFed's approach inverts a common assumption about regulated industries and AI adoption, that compliance obligations slow deployment down relative to less regulated sectors. The credit union's experience suggests the opposite dynamic in practice: because governance had to be built rigorously and early to satisfy financial services compliance requirements, PenFed arrived at member-facing deployment with a validated framework already in place, rather than retrofitting governance under regulatory or reputational pressure after a public incident.

That sequencing advantage does not happen automatically just because an institution is regulated. It required PenFed to treat the internal agent deployments as governance test beds on purpose, not merely as a lower-risk starting point to build organizational comfort with the technology. Institutions that skip that deliberate testing phase and go straight for a customer-facing pilot are taking on the governance risk without having built the same operational muscle first.

What This Costs a CIO in Time

The trade-off is not free. A full year of governance groundwork before the first external launch is a real cost in a market where competitors are announcing customer-facing AI agents on a much faster timeline, and a CIO advocating for PenFed's pace inside their own organization needs to be ready to defend that delay to a board asking why a rival bank already has a public-facing chatbot live and generating headlines.

The defense PenFed's numbers provide is that the internal deployments were not idle time. Penny and Wingman produced measurable operational savings, the deflected support calls and the reduced handle time, while the governance framework was being built and tested in parallel, so the year was not spent standing still waiting for legal sign-off. It was spent extracting value from lower-risk deployments while the harder governance problem got solved alongside them, which is the more transferable lesson for a CIO in a regulated sector than the specific agent capabilities themselves.

The Playbook for Other Regulated CIOs

The transferable structure is straightforward: start agentic AI deployment internally, where the blast radius of a mistake is limited to employees rather than customers or members, and use that period deliberately to stress-test governance frameworks against real usage patterns rather than hypothetical ones drawn up by a risk committee. Only extend to external, customer-facing deployment once those frameworks have absorbed real operational load across multiple agent use cases and demonstrated, with data, that they hold up under it consistently.

PenFed's four-agent structure, three internal gatekeepers before one external face, is a concrete reference architecture that other regulated CIOs in insurance, healthcare, and banking can point to when building their own board-level case for a similarly paced rollout. The 70 percent IT deflection rate and the 30 percent drop in back-office calls give that governance-first argument something a spreadsheet-driven board will actually respond to, alongside the risk-avoidance argument that tends to dominate these conversations on its own.

Tagged#news#digital-transformation#enterprise#cio#erp#strategy#governance#penfed#salesforce#agentforce#olivia-boles#financial-services#ai-agents#ai-governance