Nobody Runs Toward Liability
Happy Wednesday, Fintech Listeners!
I have an exciting announcement to share with y’all: The Fintech Takes Network (our community for financial services professionals) has a new name and a new look:

What we realized is that the community that has formed around the newsletter (more than 7,000 members!) is much bigger than Fintech Takes, and, more importantly, made up of many more expert voices than just mine and Kiah’s. Our new name reflects that, and, over the next few months, we will be rolling out new capabilities to help further amplify those expert voices.
If you’re not already a member of Finity, I’d strongly encourage you to apply. There are great conversations happening (and content being published … and events being hosted) on the platform and I’d love to include you in them!
Nothing is changing with the Fintech Takes newsletter or podcast, nor with Fintech Takes Banking or Bank Nerd Corner. If you have any questions about Finity, or need any help with your application, just hit reply to this email and let me know!
— Alex
P.S. — It feels inevitable that we will have, in the not too distant future, AI agents conducting transactions on our behalf. However, standing in the way of this inevitable future are a whole host of technical, operational, and legal obstacles that need to be solved. Next week, I’m chatting with Persona, Lithic, and Glenbrook Partners about those obstacles. Join us!
P.P.S — Tomorrow’s Fintech Office Hours event is open to everyone. Come join us for a candid and thoroughly unrehearsed session on what’s happening right now in banking and fintech.
3 BIG IDEAS FROM THE PODCAST
.png?sig=b646968b3560ee2e152b9721f6792bbd1ec14f5212b228a1280f0e9ee5801456)
This week's episode of the Fintech Takes podcast brings back two of my favorite repeat guests from policy land: Steve Boms (Executive Director of FDATA North America) and Dan Murphy (Founder of Sunset Park Advisors; formerly CFPB).
We set aside the ongoing squabble over Section 1033 for the moment (that episode is coming!) to ask the open banking-adjacent question we’ve been circling for a while: What happens when agents, working on your behalf and with your explicit permission, don't just read your financial data, but take action inside your accounts?
Large language models are why this conversation has teeth. An LLM that can reason and act on your behalf turns write access into something regulators, banks, and fintech companies need a real answer for, including the question of how a rule like Reg E (written for electronic transactions between a bank and a human) is supposed to hold up once AI agents are the ones initiating transactions on your behalf in the wild.
Editor’s Note — FDATA published a white paper on this exact topic. That paper informed my conversation with Steve and Dan, as you’ll hear. I’d strongly recommend giving it a read!
Tune in for the full conversation here
And read below for my three big ideas...
#1: Read, Instruct, TransactCopy anchor linkCopied
For most of the history of fintech, open banking has been synonymous with letting a third party read data from a financial account. That sounds modest, but it powered an enormous amount of innovation.
Budgeting apps could see your transactions. Lenders could assess your cash flow. Payment apps could retrieve your account and routing information in order to initiate an ACH transfer.
The important distinction is that read access lets an app see what’s happening inside an account, without touching said account.
Steve offered a useful framework for what comes next after read access: instruct and transact.
Instruct is the next level up. It allows a third party to change something inside an account without moving money out of it (like an investment tool that rebalances your portfolio as retirement approaches, based on the goals and constraints you gave it).
Transact goes one level further. It allows an agent to move money out of an account on your behalf.
From the outside, instruct and transact may look identical: software did something you authorized. From a risk perspective though, they are different animals. Rebalancing a portfolio raises questions about discretion, duties of care, and whether the agent must act in your best interest. Moving money brings authentication, authorization, and liability to the center of the conversation.
The higher you climb this ladder, the less open banking is about access to data and the more it is about the understanding of intent and the authority to act. That's the real problem with treating "write access" as one thing: it isn't.
As Dan argues, the duties attached to an agent should scale with the discretion it receives. Rebalancing a portfolio and transferring money may both count as acting on a customer's behalf. But they don’t create the same risks, and they shouldn’t require the same protections.
That’s why “write access” is a useful shorthand but an incomplete framework. The real policy question is what the agent may do, how much discretion you gave it, and who owns the mistake when the action goes wrong.
#2: The Real Product Is Beating InertiaCopy anchor linkCopied
I put two use cases in front of Dan and Steve: an "anti-inertia robot" built around my high-yield savings account that flags the moment the rate stops being competitive, finds a couple of better options, and moves the money the second I say yes, basically acting as my own deposit broker.
(Dan later pointed to a paper by Todd Phillips making the same case about Siri. Todd, a Director at Klaros Group, also wrote a great guest post for us based on his paper here.)
The other, more fanciful use case was an AI assistant that remembers birthdays and buys a gift (before I even remember I forgot). Like the high-powered personal assistants that you see in movies and TV shows (Donna, basically).
Dan made a good point in response to these use cases: The value is action, not information.
Read access already solved the information side of these problems. Plenty of tools can tell you your APY isn’t competitive. The calendar app on my phone can remind me when a birthday is coming up! Knowing isn't the hard part. Doing something about it is, and that's exactly where write access earns its keep.
A good agentic product is one that removes the most friction between a notification and an action, for the decisions most people never get around to making on their own.
Wealthy people have long been able to pay personal assistants to remember and pick out birthday presents and deposit brokers to shop their money around for the highest rate. Now technology can delegate help for smaller decisions that would otherwise never justify the cost of a human intermediary.
The common thread is follow-through. Financial tools can already tell you that you should be doing something differently. The information is there; you still have to act on it. The agent creates its value by helping the customer cross that stubborn gap between intention and action.
#3: Old Rules for New ActorsCopy anchor linkCopied
Steve closed the episode by picking a fight, on purpose, for the sake of a good conversation: He doesn't think financial regulation needs a ground-up rebuild to handle agentic finance. Fiduciary duty exists. Liability apportionment in payments exists. The question is how to apply these rules to agentic AI.
Should a company like OpenAI, if its agent starts moving money out of your account, be covered by Reg E or Reg Z, the same way a bank would be?
Reg E was written for a world where authorization was simple and unambiguous, not a world where malicious AI agents can trick someone into authorizing something they never meant to, or invisible instructions can be injected into a prompt to get an AI agent to do something it wasn’t intended to do.
New technology doesn't break Reg E's underlying principle. It breaks how that principle gets enforced.
So, does policy lead, or does the market lead?
Steve expects incumbent institutions to resist new uses of financial data unless clear rules establish how the law applies. Dan expects the answer to vary by use case. Merchants, for example, may welcome agents that generate new transactions.
The hardest cases will be the ones where an action serves the customer’s interest while working against the incumbent’s business interests. Nobody's written that rulebook yet.
WHAT I'M LISTENING TO
#1: A New Framework for Sponsor Banking (Breaking Banks) 🎧Copy anchor linkCopied
No better group of people to discuss this particular topic than Jason, Jason, Ellen, and Reid. I hope regulators with an interest in making sponsor banking work better give this a listen!
#2: The Affordability Debate Comes for Banks (Banking With Interest) 🎧Copy anchor linkCopied
I’d never really linked the affordability crisis to the war on so-called junk fees until I listened to this conversation between Lindsey and Rob. It’s an interesting perspective.
From my POV, banks put themselves in a tough position on affordability by not having invested (proactively) in other solutions focused on savings and financial health. This made the fees a more glaring target.
*Bonus: Lending, Unbundled (by me, with TruStage) 🎧Copy anchor linkCopied
Credit risk can move downstream. Reputation risk cannot. In Episode 3, Aditya Khandekar, CRO at Corridor Platforms, joins me and my co-host for the series, TruStage’s Bjoern Nordmann, to explore why accountability has to run end to end even when the loan itself is split across separate players. Tune in here!
*This rec is brought to you by one of our fantastic brand partners.
Thanks for the read! Let me know what you thought by replying back to this email.
— Alex
