AI Pulse Daily Brief logo

AI Pulse Daily Brief

Archives
Log in
Subscribe
September 14, 2026

AI Pulse Daily Brief | 2026-09-14

Reading time ~12 mins

Three institutions land on the same conclusion in a fortnight: an AI agent's authority to act has to be enforced outside the model. New York's financial regulator tells the firms it licenses to find their single points of failure, and names AI as one of the risks. Mastercard is defining what counts as consumer authorisation for an agent purchase. Amazon published working blueprints for automated onboarding checks and risk assessment. A Dutch printing company can now be bought from inside ChatGPT.

Regulatory

New York tells regulated firms to find their single points of failure. Media

American Banker reported on 11 September on new guidance from the New York Department of Financial Services. It tells the firms New York licenses to identify single points of failure, assess concentration risk and model how an incident at one third party would spread to other systems. It covers banks, credit unions, insurers, mortgage brokers, money transmitters and virtual-currency firms, and names AI, quantum computing, ransomware and attacks arriving through software suppliers as evolving risks. The guidance adds no new obligation under the state's existing cybersecurity rule, Part 500, but sharpens what supervisors expect on interconnected providers, customer-data visibility and cloud environments. New York put AI inside an existing concentration expectation rather than writing a separate AI rule, which is the route the Financial Stability Institute reports authorities converging on.

American Banker

Perspectives

An agent can finish its task and still cause the incident. Media

Sandra Galletti argued in American Banker on 10 September that an AI agent does not have to fail its assigned task to create a material incident at a bank. While completing an approved workflow it could expose data, affect a customer or start a payment nobody authorised, a pattern outside evaluations have recorded in tests that were not of bank systems. Her recommendation is to route unusual agent activity into the incident processes a bank already runs, with defined thresholds and named owners for containment and escalation. She adds that an agent can keep acting while people are still deciding whether the event is material. Incident triggers today key off a failed process, so a workflow that succeeds while exposing data produces no record at all.

American Banker

A prominent critic asks who is paying the people who evaluate AI models. Skeptic

Gary Marcus, a cognitive scientist and long-standing critic of the field, wrote on 13 September in qualified support of Dario Amodei's proposal to pace frontier AI development and publish more. His objection is that evaluators tied closely to the frontier labs, or to their funding and policy networks, may not be as independent as a buyer assumes. He names the evaluation organisation METR as his example, and treats how well a system can be monitored as a separate question from a vendor's promise to slow down. He argues for liability, and in serious cases criminal consequences, where a company negligently releases an agent that causes harm. A bank's assurance evidence for a frontier model today is largely a vendor-selected evaluation label, and the independence behind it is procurable separately.

Gary Marcus

AI personalization must improve banking outcomes, not just message relevance Perspective

Perspective. McKinsey's captured September 2026 article and Richard Turrin's critique form a useful test for bank leaders: personalization is strategically meaningful only when it improves the underlying customer relationship. McKinsey reports that customers in six European markets held 2.6 banking relationships on average in 2025, up from two in 2021, while 48% of 112 million observed relationships had only one product and 81% had two or fewer. Digital-first rivals, lower pricing, stronger user experience, and greater transparency are intensifying the fight for share of wallet.

McKinsey's proposed customer-value-management model combines integrated data and decisioning, behavior-based triggers, personalized journeys, measurement and marketing technology, and an operating model able to run these capabilities continuously. Its cited work reports upper-quartile product-penetration banks achieving 13% higher balances, 5% higher revenues, and 22% more product ownership than weaker peers; it also reports observed gains in engagement, customer value, and experience. Those ranges come from McKinsey benchmarks and implementations, however, and the article does not establish independent causality. Turrin's counterpoint is that relevant notifications cannot by themselves repair high fees, weak service, or undifferentiated products.

My takeaway is a durable preparation stance: a bank should govern AI engagement against substantive outcomes, not click-through alone. Before scaling, management can audit the product, pricing, and service journey; pilot a focused use case with a control group; and track retention, usefulness, satisfaction, complaints, cost to serve, customer value, consent, fairness, and human escalation together. Near-real-time triggers and higher contact frequency should remain bounded by customer experience and opt-out signals. Privacy and consent rules are explicit constraints, while Turrin's skepticism is a hypothesis to test rather than a settled conclusion. The decision is not whether personalization sounds compelling, but whether it makes banking better in measurable, trusted ways. This framing also changes monitoring: the bank should distinguish higher engagement from genuine retention and value, test whether service satisfaction improves rather than merely interaction counts, and review complaint, fairness, consent, and escalation signals before allowing broader automation. executives should compare the promise of engagement with actual service recovery, product fit, and customer loyalty, while preserving the ability to stop a campaign that raises contact volume without improving outcomes.

McKinsey Financial Services Practice via LinkedIn (shared by Richard Turrin)

AI adoption friction requires segmented governance Perspective

Perspective. Cognizant's captured report offers bank leaders a useful correction to generic AI-adoption programs: the binding constraint is often not technical capability but the fit between people, tools, workflows, and controls. Its analysis of more than 10,000 workers across more than 20 geographies identifies seven adoption archetypes. The report says 80% of workers have a positive Activation Gap between aspiration and actual use, while up to 82% in any archetype say their enterprise tools do not meet their needs. These are signals of trapped potential, not proof of realised productivity.

The report's mechanism is segmentation. Disposition toward technology, risk, and work is presented as more informative than hierarchy alone, so each group needs a different intervention. Advanced adopters can expose real workflows and help refine guardrails; willing but blocked workers need approved access, practical use-case libraries, and fewer organisational obstacles; hesitant groups need trusted proof, role-specific sustained training, peer support, mentoring, and visible sponsorship. The source also says current use is concentrated in lower-complexity tasks, while strategic planning, capital allocation, autonomous-agent direction, and governance or compliance see less use. The implication is that adoption should be designed around work and decision rights, not tool distribution.

My takeaway is that a bank should treat adoption posture as a control and preparation variable. Management can map users by observed friction and task risk, then pair each segment with an enablement path, approved data access, workflow integration, human review, and monitoring. Low-risk role-level pilots can test whether better access changes adoption, quality, time saved, customer outcomes, and control exceptions; advanced users can help discover governed use cases without becoming an unexamined source of risk. This belongs on a quarterly monitoring agenda because it changes how leaders judge readiness for scale. Cognizant's approximately $6 trillion figure is an illustrative macroeconomic counterfactual based on a uniform 5% productivity uplift, not a forecast. Activation Quotient and Activation Gap are modeled from worker responses, and the report does not establish causal gains in banks. Its commercial perspective therefore calls for local validation: measure outcomes and exceptions, retain accountability, and adapt controls as real usage becomes visible. Source: Cognizant Research.

Cognizant Research via LinkedIn (shared by Tony Moroney)

Netherlands & Sovereignty

A Dutch printing company can now be bought from inside ChatGPT. Corporate

Print.com, a print-commerce business based in Deventer, launched what it says is the first print platform with its own ChatGPT plugin. A customer with an account can ask in ordinary language for prices, delivery times, product options and deadline-based shipping choices, then move to the order in the company's own web app. Product specifications are exposed through a machine-readable connection that lets an outside assistant read structured data directly, turning the assistant into a transactional channel rather than a search box. Emerce reports no usage figures, so what matters is not proven demand but that a Dutch seller is now answerable inside an assistant the customer already uses, which makes being findable there a channel decision.

Emerce

Dutch broadcasters put an AI screen in front of every television advert. Corporate

Talpa Media's ReclameChecker went live on 8 September for industry-wide use through Screenforce, Ad Alliance and STER, the bodies that handle Dutch television advertising sales. It reviews logos, slogans, spoken words and visual elements against advertising codes, including the rules covering alcohol and gambling. The tool sits inside an existing commercial-quality workflow rather than beside it, so adverts moving through that pipeline are screened before broadcast. Anything it flags goes to a person for the substantive decision, so the tool triages rather than approves, and Emerce gives no accuracy or volume figures. The boundary is the transferable part, because a bank running AI checks over customer communications has to show a supervisor which decisions a named human actually made.

Emerce

Industry & competition

A treasury software vendor splits the work between a calculator and an agent. Vendor

Ripple Treasury said on 10 September that its GSmart product is in production across its enterprise customers for forecasting, liquidity, risk, reconciliation and reporting. Fixed, predictable engines do the arithmetic, while agents interpret policy, flag anomalies and propose actions that a person must approve. A separate component checks each proposed action against the organisation's own written controls before it reaches that approver. Ripple reports that 60% of eligible customers have switched on its risk feature and 44% its forecasting feature, with no breakdown by customer, so those are the numbers a vendor chose to publish. The split is the reusable part, because it puts the agent on the interpretation side of a treasury process and leaves the money arithmetic somewhere auditable.

Ripple Treasury

Mastercard is writing the rules for how an AI agent is allowed to buy something. Vendor

Mastercard announced Agent Connect and an expanded agent suite for merchants on 9 September, giving merchants one integration to reach AI agents, digital platforms and payment providers. Merchants expose product, pricing, availability and fulfilment data to AI experiences while keeping their own business rules. An agent can complete a purchase only after the consumer confirms it, which is the scheme's answer to who authorised what. The company says the work builds on a collaboration with Anthropic, with participation planned from Fiserv, Worldline, Nexi and Global Payments, and the first rollout is United States only. A card scheme is defining what counts as consumer authorisation for an agent purchase ahead of any European rulemaking, and the issuing bank inherits that definition by default.

Mastercard

Experian is moving loan comparison inside ChatGPT. Media

PYMNTS reported on 10 September that Experian has added its AI decisioning engine to its own marketplace for credit cards, personal loans and car insurance. The engine combines credit data, analytics, financial information the consumer has agreed to share and each lender's underwriting rules to produce offers and risk views in real time. Experian says the same capability is being extended to outside experiences including ChatGPT. The report carries no independent outcome measure, and its full text sits behind an email form, so the deployment is described rather than evidenced. If the comparison step moves into an assistant, a bank whose products are only visible in its own channels is left out of the comparison rather than losing it.

PYMNTS

Innovation

OpenAI now gives away the orchestration layer many banks are building in-house. Vendor

OpenAI put its Agents API into public beta on 10 September, opening the harness and infrastructure behind its own coding agent to outside developers. The service builds agents with tools, selected environments, long-running sessions and parallel sub-agents, and connects to outside data through a common machine-readable protocol. Hosted sandboxes and partner environments are available, and OpenAI says there is no fee for the service beyond the tokens and tools an application consumes. It remains a beta that will keep changing before general release, so the commercial terms are not yet fixed. Charging nothing above usage for the orchestration layer removes the cost argument from a build-versus-buy decision, which leaves data residency and identity control as the reasons left to build it.

OpenAI

Amazon published working blueprints for automated onboarding checks and risk assessment. Vendor

Amazon Web Services published two financial-services reference builds on 11 September. The first runs customer and business onboarding checks as five independent agent modules covering adverse media, sanctions, business details, source of wealth and company structure. Pluggable data sources feed them, and the final decision stays with a compliance analyst. The second maps agents to architecture, security, risk and internal-audit roles to produce traceable risk assessments while a system is still being designed, and ships as sample code with deployment scripts. AWS tested the onboarding system on synthetic data, and says its audit agent is not yet fully deterministic, so it shows findings rather than blocking a workflow.

The claim worth testing is minutes instead of days on pre-reasoned review. What decides whether this becomes a programme is the false-clear rate on the hard declined and escalated cases the synthetic set did not contain. A component the supplier itself calls not yet deterministic is one the second line has to pin down as advisory in writing before any pilot starts.

Amazon Web Services: Multi-agent KYC and KYB | Amazon Web Services: Multi-agent risk assessment

Research

Three institutions converge in a fortnight: an agent's authority must sit outside the model. Institute

The Bank for International Settlements' Financial Stability Institute, University College London and a team from ETH Zurich and Georgia Tech each published within two weeks. The BIS paper reports that AI-enabled attacks rose 89% in 2025 and that the average time an intruder needs to move deeper into a network fell to 29 minutes. University College London built a 48-case payment prototype in which a conventional agent accepted all 36 authorisation attacks, and an agent policed by written policy instructions still accepted 20. The ETH Zurich benchmark found an agent's stored memory inventing permissions in half of unauthorised finance requests, with the agent then acting on them 98.6% of the time.

A supervisory review, a payment prototype and a memory benchmark reach the same answer by three routes. Instructions given to a model are not a control. What holds is machinery the model cannot reach, meaning an inventory, a permission limit, a check at the point of execution and governed memory. That is an architecture-review question, and it arrives before any agent is allowed near a payment rail.

Bank for International Settlements Financial Stability Institute: When Machines Attack | arXiv: Authority-Inference Separation | arXiv: EAL-BENCH

On the radar

  • The identity-verification vendor IDScan, which held more than 100 million identity documents, was breached, and more than 150 million IDs were reportedly offered for sale on criminal forums. American Banker
  • Anthropic published tooling to cut the cost of running its models, reporting savings of roughly 52% to 73% on public benchmarks that contain no bank workload. Anthropic

Don't miss what's next. Subscribe to AI Pulse Daily Brief:
Older → AI Pulse Daily Brief | 2026-09-11
Powered by Buttondown, the easiest way to start and grow your newsletter.