Choose which optional cookies and similar storage we may use. Strictly necessary storage is always on, because the site cannot work without it.

AI agents for banks, lenders, payments firms and fintechs

Financial firms are starting to put AI agents to work on the casework that slows their teams: onboarding checks, financial crime alerts, scam claims and complaints. We build those agents into the systems you already run. Each one gathers the facts, drafts and routes; a person makes every decision about a customer, and every action is logged for your auditors and your regulator.

Last updated

Challenges we help with

  • Onboarding checks that keep good customers waiting.
  • Financial crime alerts, each needing the facts gathered before anyone can decide.
  • Scam claims to assess and reimburse within set time limits.
  • Complaints to answer by fixed deadlines, and good customer outcomes to evidence.
  • Showing your board and your regulator how every model and agent is controlled.

What is changing in financial services?

Agents are moving from pilots into financial crime, service and operations, while new payment, data and resilience rules arrive on fixed dates. What is in use now, and what is coming, with the source for each.

In use now

  • Scam victims must be reimbursed in the UK

    Since October 2024, UK payment firms have had to reimburse victims of authorised push payment scams up to £85,000, normally within five business days, with the cost split between the sending and receiving firms. Each claim needs its facts gathered fast.

    Source: PS25/5: APP scams reimbursement, consolidated policy statement (Payment Systems Regulator, 2025)

  • Payee names checked across the euro area

    Since 9 October 2025, banks in the euro area have had to check the payee's name against the account before a credit transfer, under the Instant Payments Regulation. Member States outside the euro follow from 9 July 2027.

    Source: Instant Payments Regulation (European Central Bank, 2025)

  • Agents still work under a person's sign-off

    The Bank of England's Financial Policy Committee said in April 2026 that firms had not yet adopted generative or agentic AI in a way that posed a systemic risk, but that the risks were likely to increase, potentially rapidly, and it asked for more work on agentic AI in payments and markets.

    Source: Financial Policy Committee Record, April 2026 (Bank of England, 2026)

  • Model risk rules take in AI

    The PRA's model risk principles for banks, in force since May 2024, use a definition of a model broad enough to take in AI. In the US, model risk guidance issued in April 2026 leaves generative and agentic AI out of scope for now, with a request for information promised.

    Sources: SS1/23: Model risk management principles for banks (Prudential Regulation Authority, 2023); SR 26-2: Revised guidance on model risk management (Federal Reserve, 2026)

  • Responsible AI guidance from the UAE Central Bank

    The Central Bank of the UAE's guidance note of February 2026 asks licensed financial institutions to keep human oversight of AI, explain its outcomes and stay in control of the models they use, with the board accountable.

    Source: Guidance note on consumer protection and the responsible adoption and use of AI (Central Bank of the UAE, 2026)

Coming next

  • Agents that pay

    Card networks have launched ways for an AI agent to pay on a customer's behalf, such as Visa's Trusted Agent Protocol and Mastercard Agent Pay, and Google's Agent Payments Protocol records what the customer approved. Volumes are at pilot scale, and liability and strong customer authentication for agent payments are not yet settled.

    Sources: Trusted Agent Protocol (Visa, 2025); Mastercard Agent Pay (Mastercard, 2026); Announcing the Agent Payments Protocol (AP2) (Google Cloud, 2025)

  • Customers' own AI agents

    The FCA's Mills Review, published in July 2026, looked at how AI could change retail finance, including customers' own AI agents acting within limits they set, and recommended foundations for agentic finance rather than new AI-specific rules.

    Source: The Mills Review (Financial Conduct Authority, 2026)

  • One EU rulebook on money laundering

    The EU Anti-Money Laundering Regulation applies from 10 July 2027, with one set of customer due diligence rules across the EU, and the new Anti-Money Laundering Authority begins direct supervision of selected groups from 2028.

    Source: Single Programming Document 2026 to 2028 (Anti-Money Laundering Authority, 2026)

  • Credit scoring becomes high-risk AI

    Under the EU AI Act, as amended in July 2026, AI that assesses the creditworthiness of individuals or sets their credit score is high-risk from 2 December 2027, with human oversight, logging and a fundamental rights impact assessment for firms that use it.

    Sources: Regulation (EU) 2026/1744 (Digital Omnibus on AI) (EUR-Lex, 2026); AI Act, Annex III (AI Act Service Desk, European Commission, 2026)

  • Quantum-safe cryptography

    The NCSC expects organisations to finish discovery and planning for post-quantum cryptography by 2028, move priority systems by 2031 and complete the move by 2035, and a G7 roadmap for the financial sector followed in January 2026. The first step is knowing where cryptography is used.

    Sources: PQC migration roadmap unveiled (National Cyber Security Centre, 2025); Advancing a coordinated roadmap for the transition to post-quantum cryptography in the financial sector (HM Treasury, 2026)

Checked against these sources on . Rules and dates change: we check them again at the start of every project.

What we offer

AI agents for financial firms

Agents for onboarding, financial crime, customer, lending and compliance teams. Each one prepares the case; your staff decide it.

Onboarding and financial crime

  • Onboarding and KYC agent

    Checks identity and company documents for completeness and consistency, runs the checks your policy sets, and prepares the file for your onboarding team.

    A person approves: Whether to take a customer on. It never accepts or declines anyone.

  • Financial crime alert agent

    Gathers the facts behind transaction monitoring and sanctions screening alerts, and drafts the case notes for an investigator.

    A person approves: Closing or escalating an alert, and every suspicious activity report.

  • Scam and fraud case agent

    Brings a customer's scam report, the payment trail and call notes into one case file, and drafts the reimbursement assessment.

    A person approves: Every reimbursement decision, and every contact with a customer who may be vulnerable.

Customers

  • Complaints handling agent

    Logs complaints from every channel, finds the facts, drafts the final response and tracks each deadline.

    A person approves: Every final response, before it is sent.

  • Service voice agent

    Answers service calls, books appointments and chases documents, says it is an AI at the start of every call, and never takes a payment or changes a payee.

    A person approves: Any account change, complaint, dispute or sign of vulnerability goes to a person, and a voice is never the only check of who is calling.

Payments and operations

  • Payment data agent

    Structures names, addresses and party data in ISO 20022 payment messages, and checks payee names before Confirmation of Payee and Verification of Payee.

    A person approves: Operations approves every change to a customer's details.

  • Reconciliation agent

    Matches payments, statements and ledgers, investigates the breaks, and explains each one.

    A person approves: Adjustments and write-offs.

Lending, risk and compliance

  • Business credit paper agent

    Drafts credit papers for business lending from financial statements and your own data, for a credit analyst to review.

    A person approves: The credit decision and every figure in the paper. It is not used to score or decide on individuals.

  • Regulatory change agent

    Tracks new rules and guidance from your regulators, and maps each change to the policies and controls it affects.

    A person approves: What changes in your policies, and who owns each change.

Every agent is logged, tested before launch and after every change, and given only the access its task needs. How we keep agents in control

The systems they connect to

An agent is only useful inside the systems your teams already work in. These are the platforms and standards financial firms run on.

Core banking and lending

Temenos, Thought Machine, FIS, Fiserv, Mambu, nCino.

CRM

Salesforce Financial Services Cloud, Microsoft Dynamics 365.

Open banking and open finance

UK Open Banking Standard, Berlin Group NextGenPSD2, FDX in the US, Al Tareq in the UAE.

Payments messaging

ISO 20022 (pain, pacs and camt messages), Swift CBPR+, Confirmation of Payee, EU Verification of Payee.

Agent payments

Visa Intelligent Commerce, Mastercard Agent Pay, Agent Payments Protocol (AP2), Agentic Commerce Protocol.

Early, competing protocols. We design for them without betting on one.

Financial crime data and case management

Companies House and GLEIF, OFSI, EU, OFAC and UN sanctions lists, LSEG World-Check, Dow Jones Risk and Compliance, NICE Actimize, Quantexa.

Accounting and e-invoicing

Xero, Sage, QuickBooks, NetSuite, SAP, Peppol.

We connect through each system's own interfaces, its open standards and the Model Context Protocol (MCP), and confirm each connection at the start of a project. Naming a product here does not mean we are its maker's partner.

Standards and safeguards

  • A person makes every decision about a customer: onboarding, reimbursement, complaints and credit.
  • No credit scoring of individuals. The EU AI Act classes AI that assesses people's creditworthiness as high-risk, and we leave it out.
  • Every agent documented, tested and monitored like any other model, so it fits your model risk management.
  • Every action logged, so a decision can be explained to a customer, an auditor or a regulator.
  • Designed around UK GDPR and EU GDPR, including their rules on automated decisions about people.

Evidence

  • Gateway Global has filed three UK patent applications, covering secure cloud computing, control over where AI requests can go, and voice AI orchestration. See our patent portfolio
  • Every agent we deliver has a named human checkpoint, an action log and tests that run again whenever its model, instructions or tools change. How we keep agents in control

What does a firm need before AI agents can pay?

Five things: checkout information an agent can read, a record of what each customer authorised, spending limits, confirmation above the limit, and fraud checks on agent traffic. Agents can already pay through the card networks and new payment protocols, though volumes are at pilot scale so far, and we build these five for a pilot.

See what is changing in financial services
  • Checkout information agents can read. For merchants and the payment firms that serve them: products, prices and checkout terms published in a structured form an agent can read and check, and your checkout mapped to the protocols you choose to support.
  • A record of what each customer authorised. A mandate and consent log: what the customer allowed an agent to buy, up to what amount and until when, and which agent acted on it, so a dispute or complaint can be answered with evidence.
  • Spending limits. Limits the customer sets, per payment, per day or per merchant, checked before any payment goes ahead.
  • Confirmation above the limit. The customer sets up each mandate and its limits through strong customer authentication with their bank or card issuer, and a payment above the limit waits until the customer confirms it the same way. Where else strong customer authentication applies is for your compliance team and legal advisers to decide.
  • Fraud checks on agent traffic. Agent payments marked as such, signed agents told apart from unknown ones, and unusual patterns sent to your fraud team under rules they set.

A person decides: The customer sets up each mandate and its limits, and confirms every payment above the limit. Your fraud team owns the rules: which agents are accepted, the limits on offer and what is flagged. Your product or merchant team approves the product, price and checkout data published to agents, and which protocols are switched on. No agent can change a limit or a rule.

Each protocol works differently. Visa offers Visa Intelligent Commerce and its Trusted Agent Protocol, which lets a merchant recognise a genuine agent from its signed web requests. Mastercard Agent Pay gives agents their own payment tokens. Google's Agent Payments Protocol (AP2) records the customer's instruction as a signed mandate. The Agentic Commerce Protocol from OpenAI and Stripe, still in beta, sets out how an agent completes a merchant's checkout.

These protocols compete. Under European payment rules, which were not written with agents in mind, who is liable when an agent pays for the wrong thing and how strong customer authentication applies are still open questions (legal analysis by Osborne Clarke). So we keep the mandate records, limits and fraud rules in your own systems, and connect them to the protocols you adopt, through your own card network, acquirer or payment provider arrangements.

We start with a pilot: one product or channel, a small group of customers who opt in, low limits, and a switch that turns agent payments off at once. You see how agents behave on your own traffic, and you decide whether to go further.

Nothing we build lets an agent pay without a customer mandate given with strong customer authentication. We do not give legal advice: we work alongside your legal advisers and compliance team. Naming a network or protocol here does not mean a partnership with the company behind it.

Questions people ask

Do your agents make decisions about customers?

No. They gather the facts, draft and route. Decisions about a customer, such as taking them on, reimbursing a scam or upholding a complaint, stay with your staff.

Do you build credit scoring?

No. Under the EU AI Act, AI that assesses people's creditworthiness is high-risk, and we do not build it. For business lending, we can draft credit papers for an analyst to review and decide.

Where does our customers' data go?

Only where you allow. Agents can run on your own infrastructure or in the region your data must stay in, and each one can reach only the data its task needs.

Do you give financial advice?

No. We build and run technology for financial firms. We do not give regulated financial or investment advice, and we do not arrange investments.

Tell us which task costs your team most.