First Internet Bank has started letting business and personal customers connect their account data to ChatGPT and Claude, so they can ask questions about their own cash flow, spending, and payroll readiness in plain language instead of pulling a spreadsheet. It's a small, sensible-looking rollout. It's also a live example of a question the industry hasn't answered yet: once an AI assistant has standing access to financial data, who decides it's trustworthy enough to have it, and who's accountable if that access gets misused?
The connection runs on the Model Context Protocol (MCP), an open standard that lets AI assistants query external data sources under permissions the data owner controls. First Internet Bank's implementation is read-only: customers choose what account information is shared, can revoke it at any time, and the AI assistants can't move funds, initiate transactions, or change account settings. The bank has also stated customer data isn't used to train the underlying models. On the details that are public, this is a careful, well-scoped rollout, not a reckless one.
Business customers can ask whether cash on hand covers upcoming payroll or which vendors account for the largest share of spend. Personal customers can ask about recurring subscriptions or savings progress over the year. It's the same shift open finance has been driving for years, moving financial data from static statements into something a customer can actually interrogate, just with a conversational interface instead of a dashboard.
Here's the part the rollout doesn't answer: First Internet Bank has decided, on its own, what "safe" access looks like for ChatGPT and Claude. That's a reasonable set of guardrails for one bank's implementation. It says nothing about what happens when a second bank makes a different call, a third AI assistant enters the market with a different permission model, or a customer's AI assistant is quietly swapped out or updated in a way the bank never evaluated.
This is precisely the pattern open finance has already been through with third-party providers and aggregators, and precisely the pattern that's still unresolved for them: every institution deciding independently what "accredited enough to access customer data" means, with no shared standard for verifying it and no consistent answer for where liability sits if an accessing party misuses its permissions. AI assistants reading account data are now a new category of accessing party, arriving faster than the industry built the infrastructure to govern the first one.
MCP-based access is explicitly non-transactional right now, and that's a genuinely important safeguard. But the direction of travel across agentic commerce and agentic payments is toward AI assistants doing more, not less, with the access they're given. An AI assistant that can already read a customer's full transaction history and spending patterns is a natural candidate to be granted initiation rights next, whether that's approving a payment, moving money between accounts, or acting on a standing instruction. The accreditation and risk monitoring question doesn't get easier once that happens. It gets urgent.
None of this is an argument against what First Internet Bank has done. Extending sophisticated financial analysis to customers who don't have dedicated finance teams is a genuinely good use of the technology, and the safeguards described publicly, read-only, opt-in, revocable, no model training on customer data, are the right instincts. The gap isn't in any one institution's implementation. It's in the absence of a shared standard across the market for accrediting which AI assistants get access to what, monitoring how that access is actually used once it's granted, and settling who's responsible when something goes wrong.
That's the same infrastructure gap open finance has been navigating with third-party providers for years, just showing up in a new form. As more banks connect account data to AI assistants, the institutions that get ahead of the accreditation and risk monitoring question, rather than each solving it independently, will be the ones customers and regulators trust first.
See how the Invela Network applies standardized accreditation and continuous risk monitoring to every participant with access to financial data, including AI systems.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open finance, covered.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.