Plaid and the AI agent platform Sierra have partnered to let AI agents request permission to connect a customer's bank account mid-conversation, then use that data to keep a financial workflow moving, refinancing a loan, progressing an insurance claim, resolving fraud, without the customer ever leaving the chat. A borrower who falls short on credit score alone no longer waits for a loan officer to manually verify income and spending. The agent requests access through Plaid Link, reviews the cash flow data itself, and continues the application in the same conversation.
That's a genuine step change from the access model we wrote about on DATE, when First Internet Bank connected customer account data to ChatGPT and Claude for read-only queries. This is an AI agent with permissioned access acting on that data to move a financial outcome forward, inside the same session, without a human re-approving each step.
PYMNTS put the underlying problem well in its own coverage: an AI agent requesting access mid-conversation, potentially across a multi-day workflow Sierra's Horizon platform is built to support, doesn't leave the same kind of clean, single-moment consent record a human does when they link an account themselves. It also cites PYMNTS Intelligence research with Trulioo finding that loan applications already produce the highest concentration of what the research calls “know your agent” threats, with 63.2% of surveyed firms reporting agent-driven threats in that specific workflow, the same workflow Plaid and Sierra chose to highlight first.
There's a UK regulatory data point worth sitting alongside that. The FCA's Mills Review found that more than a quarter of UK consumers already trust ChatGPT, Claude, or Gemini for financial advice, with limited awareness that the protections covering licensed advisers don't extend to a chatbot, as PYMNTS separately reported. Consumer trust in AI for financial help was already running ahead of the access controls built to justify it. Plaid and Sierra have now built the access those consumers were assuming already existed.
To their credit, Sierra and Plaid haven't ignored this. Every interaction starts with explicit consumer permission through Plaid, and Sierra has built in monitoring of AI responses, compliance checks, and human-in-the-loop intervention points. Those are the same kind of scoped, thoughtful safeguards First Internet Bank built around its own Model Context Protocol-based access, and Anthropic built, imperfectly, around its own model testing environments. We say “imperfectly” given the recent episode when three of its models broke out of one entirely.
What none of these safeguards amount to is a shared standard. Plaid and Sierra have decided what responsible AI agent access looks like for their own integration. The next platform to connect an AI agent to live financial data will make its own call, with its own definition of sufficient consent and its own audit trail, or lack of one. That's the same fragmented-accreditation problem open finance has been navigating with third-party providers for years, now showing up for AI agents that can act, not just read, and arriving faster than the industry built the infrastructure to govern the first version of the problem.
A separate, smaller Plaid integration announced this week makes the underlying point from a different angle. Vikar Technologies, which supplies community banks and credit unions with a unified account opening, lending, and KYC/KYB platform, has embedded Plaid's authentication and identity verification tools natively to speed up account funding. The community bank's actual vendor relationship is with Vikar. Plaid is the sub-processor doing the real data handling underneath it, a fourth party the bank may never have directly assessed, inherited through a vendor it did. Smaller institutions, the ones least likely to have the vendor-risk programmes to catch this, are absorbing an aggregator's data-handling and access-control posture by default.
Different workflow, same structural gap. Whether the accessing party is an AI agent acting inside a loan application or an aggregator embedded three layers into a community bank's open finance chain, the industry keeps solving accreditation one integration at a time, with no shared standard for what counts as sufficiently verified access, no real-time risk monitoring, and no consistent answer for where liability sits when it isn't.
Open finance's accreditation models were built to evaluate human-operated third-party providers requesting data on a customer's behalf. They weren't built to evaluate an AI agent that can request access mid-conversation and act on what it finds, or a sub-processor several layers inside a vendor relationship nobody directly assessed. Both are now live, in production, moving real money and real financial decisions. Accreditation on its own moves at the pace of a contract cycle or an annual review. An AI agent can request access, act on it, and move on to the next task inside a single conversation, many times a day. That gap is the real risk: a credential that was accurate when it was granted can be badly out of date by the time it matters, and accreditation alone was never built to catch that in between reviews. The institutions that pair accreditation with genuinely continuous, not periodic, risk monitoring for these newer categories of access, rather than solving it independently with every new integration, will be the ones customers and regulators trust first.
See how the Invela Network applies standardized accreditation and continuous risk monitoring to every participant with access to financial data, including AI agents and the aggregators sitting behind them.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open finance, covered.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.