
FIS launched a financial-crimes agent built on Anthropic’s Claude in May 2026, with BMO and Amalgamated Bank in development.
getty
Banks have found the safe way to use AI agents: point them inward. The headline deployments of 2026 put agents to work hunting money launderers and fraud, where the agent investigates and a human still signs off. The frontier no major bank has crossed is the one that matters for customers: letting an agent initiate a payment on its own. The first institution to cross it will write the rules everyone else inherits.
Start with what is actually shipping. In May, FIS, which by its own account powers nearly 12% of the global economy, launched a financial-crimes agent built on Anthropic’s Claude, with BMO and Amalgamated Bank in development and general availability set for the second half of 2026. The pitch is cost: US financial institutions spend $35 to $40 billion a year on anti-money-laundering work, and the agent compresses investigations from days to minutes. Useful, and entirely back-office. The agent reads and recommends. It does not move money.
The scale behind that deployment explains the caution. The UN estimates that $2 trillion in illicit funds moves through the financial system each year, and FIS, which sits as the system of record for transactions at thousands of institutions, is starting where the data it already holds is richest. Anthropic embedded its applied-AI engineers inside FIS to build the agent, client data stays within FIS-controlled infrastructure, and the roadmap runs from financial crime into credit decisioning, deposit retention, onboarding and fraud. Every one of those keeps a human on the decision. None of them moves a customer’s money on the customer’s behalf.
The frontier is customer-authorized spending
The harder use case is the one the card networks are racing toward. Visa’s Intelligent Commerce and Mastercard’s Agent Pay, both launched in 2025, let a consumer hand a verified AI agent a tokenized credential and a spending limit so the agent can buy on their behalf. The behavior is already visible at scale. Salesforce estimated AI and agents drove $262 billion in sales over the 2025 holidays, a fifth of all retail. The agents are shopping. The unresolved question is who answers for what they buy.
What the card networks have built makes the leap concrete. Visa’s Intelligent Commerce, launched in April 2025 with Anthropic, OpenAI, Microsoft, Perplexity, Stripe and others, issues an agent a tokenised credential that stands in for a card and lets the consumer set spending limits and conditions the agent must honour. Mastercard’s Agent Pay introduces Agentic Tokens, built with Microsoft, IBM’s watsonx, Braintree and Checkout.com, that confirm a chosen agent is authorised to transact. Both keep the consumer nominally in control by capping what the agent may spend. Neither yet answers what happens when the agent, acting inside those limits, buys the wrong thing.
The behaviour is already at scale, which is what makes the gap urgent. Salesforce attributed $262 billion of 2025 holiday sales to AI and agents, a fifth of the total, and the share of shopping traffic arriving from AI search channels doubled year on year. Agents are already shopping at scale. Payments are the last step the networks are now wiring up, and the liability rules are the part still missing when they do.
Nobody has settled who is liable
That question is not academic, and the people building the rails know it. Google’s Agent Payments Protocol, launched in September 2025 with more than 60 partners including Mastercard, PayPal and Coinbase, is built around cryptographically signed mandates precisely because an autonomous agent breaks the assumption that a human clicked buy. The IMF devoted an April research note to the problem, flagging legal uncertainty over authorization and liability as the binding constraint on agentic payments. When an agent is tricked into the wrong purchase, or buys the right thing at the wrong price, the chain of responsibility runs through the bank, the network, the merchant and the model, and no settled law assigns it.
The protocols racing to define it
The infrastructure is arriving faster than the law. Google’s Agent Payments Protocol, launched in September 2025 with more than 60 partners including Mastercard, PayPal, Coinbase and American Express, builds every transaction around signed mandates: an Intent Mandate that captures what the user asked for, and a Cart Mandate that locks the exact items and price before payment clears. The structure exists to create a non-repudiable record of who authorised what, precisely because an autonomous agent breaks the old assumption that a human clicked buy. A companion extension built with Coinbase, the Ethereum Foundation and MetaMask, called x402, carries the same machinery onto stablecoin rails. The engineering for agents to pay is largely solved. The question of who is accountable when they pay wrong is not.
A few firms have started to answer. American Express said it would cover erroneous purchases made by registered agents on its network, an early attempt to put a backstop under the behavior. It is a partial answer, because it addresses honest mistakes and not fraud, and fraud is where agentic payments get genuinely hard. An agent that can be manipulated by a malicious prompt is a new attack surface with no established rules of recovery.
Fraud is the harder half because it attacks the authorisation itself. As one payments analyst noted, the Amex backstop covers honest agent errors but says nothing about a bad actor who defeats the agent’s authentication, and the industry’s main tool for binding identity to a transaction, 3D Secure, has low adoption in North America and no clear place yet in the networks’ agent toolkits. An agent that can be steered by a malicious prompt is a new attack surface, and the card systems were built to confirm that a payment was authorised, not that the entity authorising it was really the customer. Closing that gap means moving identity resolution into the transaction itself, which no one has done at scale.
Why the first mover sets the defaults
This is why the first bank to let customer agents move real money matters beyond its own balance sheet. Whoever goes first will define the defaults: how an agent’s authority is proven, what limits sit on it, who eats the loss when it errs, and how a customer revokes it. Those choices will harden into the standard others copy, the way early card-network rules on chargebacks became the template for disputed payments. Accenture found that 57% of bank executives expect agents embedded in risk and compliance within three years. Embedding an agent in compliance is the cautious move. Letting one spend a customer’s money is the consequential one.
The appetite to deploy is not in doubt. Accenture found that 57% of bank executives expect agents embedded in risk, compliance and fraud within three years, and 56% expect them in credit and onboarding, while McKinsey has put the potential cost reduction at up to 20%. BNY is building 150 AI-powered offerings on an internal platform that lets staff design their own agents, and nearly half of banks and insurers are already creating roles to supervise them. All of that momentum points inward, at cost and operations, not outward at customer spending.
What the first mover actually decides
The bank that lets customer agents move real money first will fix the answers everyone copies: how an agent proves its authority, what limits bind it, who absorbs the loss when it errs, how a customer revokes it, and how the system tells a real agent from a hijacked one. American Express has supplied a partial version by covering honest errors on registered agents, but a partial answer on one network’s terms is not an industry standard. Whoever sets the full one will do it the way the card networks once set chargeback rules: by going first, taking the risk, and leaving everyone else to operate inside the framework they built.
Regulators have named the vacuum without filling it. The IMF’s April note frames agentic payments around a three-layer model of intent, authorisation and settlement and warns that legal uncertainty over authorisation and liability is the binding constraint, while the technology is largely ready. That is an unusually direct statement from a body that rarely front-runs markets, and it points where the engineering does: the missing piece is a decision about responsibility, and someone has to make it first.
There is a first-mover cost as well as a prize. The bank that lets agents move customer money will own the early failures, the fraud cases that test the new attack surface, and the regulatory scrutiny that follows. That is why most are pointing agents inward for now. But the institution willing to absorb those costs buys something the cautious cannot: authorship of the rules, and the customer relationships that form around the first trusted way for an agent to pay.
The capability is already in production. What is missing is someone willing to own the liability, and no model improvement supplies that. A person has to decide to carry the risk. The bank that makes that call will take on real risk and, in exchange, set the terms of a market everyone else has to operate in. More institutions should be weighing that trade while the rules are still unwritten, because the alternative is inheriting rules written by whoever was bolder.