Open Finance risk: Eight things that happened in August you need to know about
Louise Beaumont | Insights, Women In Open Banking
01 Sep 2026
August was the month AI stopped being a side conversation in Open Finance risk and became the main one. Here is what happened, why it matters, and what it means for risk management.
Payments: agentic commerce is heading multi-rail, not toward a single winner
Cards are carrying almost all of today’s agentic commerce volume, but account-to-account payments are projected to grow sharply too, and it is tempting to read that as A2A overtaking cards. It is not that simple. Cards were built for a human tapping a card at a point of sale, and A2A rails were built for occasional, human-initiated transfers, so neither is a clean fit for the continuous, high-frequency micro-payments agents are best placed to make. Stablecoins look better suited to that layer. Whichever rail carries the volume, the same question follows it: Is this participant accredited to move money on someone else’s behalf, is that authority being monitored in real time, and where does liability land if something goes wrong? More here(opens in new tab)
AI access: banks are already letting AI assistants read account data – who is accrediting the AI?
First Internet Bank now lets customers link their account data to ChatGPT and Claude for plain-language queries on cash flow and spending. The rollout itself is careful: read-only, opt-in, revocable. What it does not answer is what happens once a second bank makes a different call on what “safe” AI access looks like, with no shared standard for verifying it and no consistent answer on where liability sits if access is misused. Read-only will not stay read-only for long, either, as agentic commerce pushes AI assistants toward initiating action, not just reading data. More here(opens in new tab)
AI access: Plaid’s AI agents can now act on a bank account, not just look at it
One day later, the access model moved a step further. Plaid and AI agent platform Sierra now let an agent request permission to connect a customer’s bank account mid-conversation and act on that data to keep a workflow, a loan refinance, a claim, a fraud case, moving forward. Sierra and Plaid have built real safeguards, but that is not the same as a shared accreditation standard, and PYMNTS research already finds loan applications carrying the highest concentration of “know your agent” threats. A separate, smaller integration between Plaid and Vikar Technologies shows the same root cause one layer further down the chain, with community banks inheriting a sub-processor’s access posture through a vendor relationship they did assess. More here(opens in new tab)
US regulation: the CFPB’s Open Banking rule just reached the White House
The Consumer Financial Protection Bureau (CFPB) has submitted its rewritten Open Banking proposal to the White House’s Office of Information and Regulatory Affairs, the final procedural step before public release. The rule itself has been paused, contested, and rewritten for close to two years, while individual states, New York among them, have started drafting their own data rights legislation in the meantime. An OIRA-cleared proposal will not settle every open question, but it removes the ambiguity over whether Section 1033 applies at all. For banks still sitting on shelved API build plans, that is the signal to start building again. More here(opens in new tab).
Governance: compliance leaders trust future AI rules more than they trust their own evidence
A ComplyAdvantage survey of 200 senior compliance leaders across the UK and France found over nine in 10 confident that incoming AI regulation will manage the risks that matter most, even though the rules in question are not finalised. Confidence in a future rulebook is not the same asset as being able to show a regulator, today, why a specific alert was closed or a specific payment was allowed through. The same survey found 97% of firms running two or more disconnected screening systems, which makes that evidence harder to produce even when the underlying control is sound. More here(opens in new tab).
Cyber risk: AI cyber risk just became a boardroom problem, not just a security-team one
OpenAI disclosed it could not rule out its highest cybersecurity warning level for its next model, the threshold at which a model may independently discover and exploit real-world vulnerabilities. The IMF’s own analysis makes the sharper point for banking specifically: AI does not need new categories of attack to change the risk equation, it just needs to accelerate discovery across the infrastructure banks already share. That shared architecture is exactly what turns one AI-discovered flaw into many institutions’ problem at once, and it extends straight into Open Finance chains, where a vulnerability entering through an aggregator several steps removed is still every connected institution’s exposure. More here(opens in new tab).
Fraud: two layers of risk – what’s happening in a transaction, and who’s behind it
An American Banker and Plaid study of 143 fraud decision-makers found real-time payments have made fraud faster than most institutions’ defences can follow: 85% report increased fraud risk, and only 15% can consistently intervene before funds move. The case for network-level fraud intelligence is genuinely strong. But even the study’s own card-network comparison points to a second, standing layer transaction data cannot supply on its own: card networks pair transaction-level defence with merchant and acquirer accreditation and defined liability rules. Open Finance needs both layers for the same reason, knowing a transaction looks right is not the same as knowing the participant behind it is trustworthy enough to be on the network at all. More here(opens in new tab).
Third-party risk: a lender’s data breach happened exactly where its own controls don’t reach
Consumer lender Heights Finance is notifying more than 1.2 million people after hackers accessed a third-party, cloud-based platform the company used for customer data storage. Heights’ own loan management systems, by its own account, were never touched. The affected population reaches back further than any one relationship too, including former borrowers inherited through a corporate history of mergers and rebrands. A periodic compliance check confirms what was true at the last review, not what is true today, and that gap between the two is precisely where this breach happened. More here(opens in new tab).
Dr Louise Beaumont leads marketing, communications and design at Invela
Invela is the infrastructure layer that makes Open Finance trustworthy – accrediting who’s in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open Finance, covered.
Invela is an Event Partner of Open Banking Expo UK & Europe 2026. Find out more about partnering, attending and speaking here.