Request a demo

Find out today the difference that Callsign’s unique solution can make to your business.

Seeing is believing.

General enquiries, support and press

By submitting this form, you agree to Callsign’s Privacy Policy

Success

Error

Thank you for your request

Success

In the meantime, connect with Callsign for insights on authentication and fraud prevention

Back to Knowledge & Insights

Agentic Banking Has Already Arrived, and Your Fraud Stack Can't See It

Agentic AI
AI
Banking & Finance
Agentic Banking
Fraud Prevention
56% of UK adults, roughly 28.8 million people, used AI to manage their money in the past year.

Lloyds Banking Group research puts personal finance as the single most common use of AI in the country, ahead of writing assistance, recipes and medical queries. That figure spans everything from asking a chatbot to explain an ISA to letting software move real money, so treat it as a measure of appetite rather than autonomous execution. But that is precisely the point: the appetite is already mainstream.

For a while it was easy to file all of this under interesting but not urgent. That stopped being a defensible position for banks in 2026.

In March this year, an AI agent bought a book. It chose the merchant, presented a live Visa credential and completed the purchase with full authorization, tokenized payment and settlement, no manual input from the customer at any point. Banco Santander called it Europe's first live end-to-end agentic payment, and it was not a demo: real credential, real merchant, real settlement.

The same month, Visa launched its Agentic Ready program. By 2 July it was announcing live agentic commerce across Europe: AI agents completing purchases at real merchant sites on behalf of cardholders, with more than 30 issuers behind it, most of the UK high street among them. Barely four months separated program launch from live agent-executed transactions across a continent.

The demand side is moving just as fast. In May, OpenAI launched a personal finance experience inside ChatGPT, connecting users to over 12,000 financial institutions through Plaid. Read-only and US-only for now, yes. But anyone in UK banking who concluded it wasn't their problem has misread the direction of travel entirely.

Every category of money, the same move

And it is not confined to card rails or to one corner of finance. In trading, Robinhood opened its platform to AI agents in late May, letting an agent place real equity trades and spend on a virtual card through Robinhood's MCP servers, in beta across its 27 million customers. In crypto, Coinbase launched Coinbase for Agents in June, connecting an agent directly to a funded Coinbase account to trade and pay on the customer's behalf, where an on-chain transfer, once made, cannot be reversed. In EU business banking, Qonto runs a first-party hosted MCP server that lets an agent issue virtual and physical cards, change their limits and raise multi-transfer requests.

Three different verticals, three different regulators, the same architectural move: an agent given a sanctioned path to act on money or assets, with the human stepped out of the individual transaction.

What unites these examples is the irreversibility, not the technology. A trade executes and clears. An on-chain transfer settles and is gone. A card gets issued and spent. There is no chargeback rail behind most of this. A compromised agent gets caught before execution or not at all.

UK open banking API calls reached 24 billion in 2025.

Which brings me on to banking, because banking is different in one decisive way. In every other vertical, the agent channel had to be built. Banking is the one industry where the machine-access layer already exists, standardized, regulated and mandatory, because PSD2 built it nearly a decade ago and it has been open since 2018.

Agentic traffic is already beginning to route through those APIs, and AI adoption is widely cited as a primary driver of their growth. So the question was never whether to enable agentic banking. It is whether your fraud controls were built for the world that is now operating.

They weren't. And the reason is structural, not a matter of tuning.

Every control you run assumes a human

Walk through the stack. Transaction monitoring was designed to catch anomalous payment values or destinations. It is blind to a perfectly normal payment that originates from an abnormal source. Device intelligence was designed to flag compromised or unfamiliar devices. It is blind to a legitimate device operated on behalf of a compromised human. Behavioral biometrics, a control I have a lot of time for, was designed to read how a human physically types and swipes. It is blind to an agent tool call, because there is no human interaction to measure at all.

Virtually every fraud and authentication control in your current stack was built with one assumption embedded so deeply that nobody states it out loud: there is a human at the end of this session.

Agentic banking removes the human, and with it the signal your entire detection apparatus depends on.

This produces three distinct problems. The first is token theft and replay: stolen agent credentials grant access that looks entirely valid, with no behavioral signal to separate a hijacked agent from a legitimate one. The second is prompt injection: malicious instructions buried in content the agent processes, silently redirecting its behavior mid-session, with no authentication event to trigger anything. This is no longer theoretical. In July, researchers at Zscaler reported live campaigns hiding instructions in ordinary web content; in their controlled tests, four of the 26 AI models evaluated were manipulated into executing payments. The third is the quiet one, and it is the one that should concern UK banks most: the loss of the human signal itself. The more agents you deploy, the larger that gap grows.

The liability math is already against you

Here is where the third problem stops being abstract. Under the PSR's mandatory reimbursement rules, in force since October 2024, banks must reimburse APP fraud victims up to £85,000 per claim. And the exposure is growing, not shrinking: UK Finance reported APP fraud losses of £576.4 million in 2025, up 19% on the prior year and the first full year under mandatory reimbursement. Most of that bill now lands with the banks, with the cost split equally between the sending and receiving institution.

Now place an agent in that chain. A customer is socially engineered into authorizing an agent to make a payment. The agent executes those instructions faithfully. It passes every check. No step-up friction fires, because the agent holds standing authorization. The human behind the instruction was being scammed, but there was no human session through which any of your controls could have caught it. In this scenario, the customer bears nothing, the AI provider bears nothing and the aggregator bears nothing.

The reimbursement bill lands entirely on the banks, from a channel you can barely see and cannot intervene in.

That is the exposure, stated plainly. A growing volume of traffic you have only limited visibility into, carrying liability you cannot offload onto the channel that carried it, governed by controls that were architected for a human who is no longer there.

And there is a second-order effect that is rarely stated. In the channel where you can see an agent, your own internet banking, many banks already block it, because much of the agentic traffic hitting that interface today is malicious: automation, credential stuffing, scraping. That blocking is rational and it largely works. But by closing the door on the one channel where agentic activity is visible, you push the legitimate, customer-authorized agent toward the only channel left open to it: the API. The blind spot does not fill up by accident. It fills up because the control you are most confident in, on the channel you can see, is working exactly as designed and herding the genuine traffic to the place you cannot.

The gap is already open and the traffic is already flowing. The only question is how long the industry operates inside it before the controls catch up.

In part two of this three-part series I will follow that genuine traffic onto the API route and ask what it takes to recognize a customer when there is no session, no device and no screen to read, only an agent acting on their behalf. Because enforcement is not the only force pushing agents toward that route. The whole promise of agentic finance is aggregation: one agent with sight of every account, card, pension and loan a customer holds. This makes the channel you cannot see the one set to grow fastest.

Chris Stephens is Callsign's VP Product Innovation. This is part one of a three-part series on fraud and identity in agentic banking. Parts 2 and 3 will be released in subsequent months.


Sources:

More Insights

Beyond the EU Digital Identity Wallet, Where…
Data for fraud prevention in Europe is changing
From Passwords to Passkeys: Meeting Banking…