
MCP in Banking: Protecting Customer Ownership as AI Platforms Become Financial Channels
Open Banking separated access from the bank channel
Financial intent can move outside the bank before the money does
A raw MCP server makes the bank easier to consume
External AI platforms are developing a branded distribution layer above MCP
Branded presence does not restore channel ownership
Bank-owned agent changes MCP from an inbound channel to an outbound one
The defensible position is dual distribution
Financial authority has to remain independent from conversational interpretation
Delegated authority becomes part of the banking product
Machine-readable products change how banks compete for distribution
Customer context becomes infrastructure
Finpace Halcyon provides the agent-facing layer without moving financial authority
The bank can lose the app session without losing the relationship
Executive summary
In May 2026, OpenAI introduced a personal finance experience that allows US users to connect financial accounts through Plaid and discuss their actual financial position inside ChatGPT. The connection can cover institutions holding current accounts and investment products, while ChatGPT becomes the environment in which the customer examines spending, considers savings decisions and adds information about future financial plans. OpenAI says more than 200 million people already use ChatGPT each month for personal-finance questions. The bank does not have to deploy an AI assistant, publish an MCP server or approve a ChatGPT integration for this shift in customer interaction to begin.
The current service does not execute financial transactions. OpenAI explicitly prevents ChatGPT Finances from moving money or changing account settings. The distribution effect appears earlier than execution because the system can already become the place where the customer interprets financial information and develops an intended course of action. Once that behaviour is established, connecting approved bank functions through Model Context Protocol changes the problem from financial analysis outside the bank to financial servicing outside the bank.
This creates a difficult strategic choice for financial institutions. An MCP server can make the bank easier for AI clients to use, which improves access to new distribution channels. The same server can reduce the reason for customers to visit the bank's own digital environment because the external AI platform can request the banking function directly. The technical decision to expose an account or payment tool therefore affects more than integration architecture. It determines which organisation receives the customer interaction that surrounds the financial transaction.
Open Banking raised the same concern when banks first had to accept that account access could originate outside their own channels. Agentic banking extends the separation further because the external system can participate in interpreting intent before calling the bank. The practical response is unlikely to be either complete resistance to external agents or unrestricted MCP access. Banks need an architecture in which their financial capabilities can travel across AI platforms without allowing the commercial relationship to become detached from the institution that provides them.

Make existing banking systems agent-ready with Halcyon
Open Banking separated access from the bank channel
The early strategic debate around Open Banking concentrated heavily on customer disintermediation. Once authorised third parties could retrieve account information or initiate payments, the banking application was no longer the only digital route into the account. The Basel Committee considered scenarios in which customer-facing fintech firms controlled distribution while regulated banks remained behind them as product and infrastructure providers. The technology changed the location from which financial services could be accessed, even though the bank continued to maintain the account and produce the financial outcome.
The effect was significant but narrower than some early forecasts suggested. Open Banking APIs made financial data programmable, yet they were still normally consumed by organisations that built fixed applications around those APIs. A personal-finance application could aggregate accounts and a payment application could initiate a transfer, but another development team still had to decide which API function supported the product journey. The user also continued to make most of the higher-level financial decisions.
That operating limitation helped banks retain more of the relationship than API access alone suggested. A third-party application could show the customer that GBP 30,000 was sitting in a current account, but the customer still had to decide whether the money should remain liquid, move into a deposit or serve another purpose. The institution could compete for that decision through its own channels because the external application did not necessarily control the reasoning that preceded product selection.
AI clients change the consumer of the access layer. A conversational system can receive the customer's objective, combine it with connected financial information and determine which financial capability is relevant. MCP becomes important at this point because it gives that AI client a structured mechanism for discovering and invoking approved functions.
The progression from Open Banking APIs to MCP therefore has an identifiable operating logic. Open Banking made regulated financial access programmable. Fixed applications remained responsible for turning that access into customer journeys. AI agents reduce the need for a fixed journey because the client can interpret the request at runtime, while MCP provides the connection between that interpretation and an approved bank capability.
The resulting disintermediation occurs one stage earlier in the commercial process. The external platform can influence what the customer should do before the bank receives an instruction about how to do it.


Expose banking capabilities to AI clients under institutional control
Financial intent can move outside the bank before the money does
Transaction data has long been treated as one of the strongest information assets held by banks because it shows recurring income and financial behaviour. Banks have used that history to support risk models and identify product needs. An external AI environment can acquire another type of information that is difficult to infer reliably from transactions: the customer's stated intention.
ChatGPT Finances illustrates the distinction. OpenAI allows users to supplement connected financial data with information about a property or a planned purchase, and the service can retain selected information as financial memory. The external platform can therefore combine historical banking data with information about what the customer expects to do next.
Consider a customer whose primary bank sees GBP 85,000 in cash and regular salary income. Those facts support useful analysis, but they do not explain whether the balance represents excess liquidity. If the same customer tells an external assistant that a property transaction is expected in six months and that GBP 25,000 must remain available for renovation work, the platform has a materially different basis for discussing the remaining cash. The value does not come from categorising another transaction. It comes from receiving the financial objective before a transaction has occurred.
Repeated use makes the effect stronger because the conversational environment can preserve continuity between decisions. A customer who previously explained why liquidity was required does not need to reconstruct the requirement every time another product is considered. The platform becomes the location where financial history is combined with declared intent.
This is a more serious engagement risk than a decline in mobile-app sessions. A customer can remain active with the bank while the information that shapes future product demand accumulates somewhere else. The bank continues to see booked financial activity, but an external platform begins to understand the circumstances that will create the next transaction.
A strategy based only on preserving app traffic would address the wrong part of the problem. Banks need to preserve access to financial intent and remain visible when an external AI environment becomes the place where that intent is expressed.

A raw MCP server makes the bank easier to consume
MCP addresses a genuine technical constraint in agent deployment. Traditional banking APIs expose deterministic functions, but an AI client needs a way to understand which functions exist and under what conditions they can be called. MCP standardises that discovery and invocation layer so an approved client can work with tools exposed by the institution.
Griffin provides an early banking example. The UK bank released an MCP server in beta in May 2025 that allows an MCP-compatible client to interact with Griffin's API. The implementation can open operational accounts and submit payments, although Griffin currently limits the public MCP server to its sandbox. The important feature is architectural: an AI client can work with banking functions through a standard agent interface rather than through a bespoke application built specifically around Griffin's API.
This improves the economics of integration because the bank no longer needs a separate client implementation every time an agent platform wants to use the same capability. The MCP specification has also moved towards infrastructure requirements associated with larger deployments. Its July 2026 revision introduced a stateless core and authorization changes intended to make MCP servers easier to route through conventional enterprise infrastructure.
The commercial effect moves in the opposite direction. Standardisation makes the bank easier to substitute inside an agent-controlled experience because the external client can interact with several compatible providers without reproducing each provider's complete digital journey.
A payment instruction demonstrates the difference. In a bank-owned application, the institution controls the interaction in which the customer selects the account and confirms the beneficiary. Through a generic agent, the customer can state the desired outcome in natural language while the agent determines which banking capability to call. The bank may receive a valid and authorised payment request without owning any of the interaction that produced it.
The bank has gained machine distribution while surrendering part of the customer journey.
This does not make MCP undesirable. It means that an MCP server cannot be treated as a neutral extension of the API estate. The tools exposed through it need a distribution model because every callable capability changes how much of the banking experience an external agent can assemble without the institution's own channel.

Connect AI agents to banking systems without moving financial authority
External AI platforms are developing a branded distribution layer above MCP
The strongest answer to anonymous MCP access is already emerging inside the AI platforms themselves. MCP can remain the technical connection while another application layer preserves provider identity and defines the experience around the capability.
OpenAI's current structure is particularly relevant. Its Apps SDK allows developers to build applications that operate inside ChatGPT, including an application-specific interface connected to the provider's existing backend. The SDK is built on MCP, which means the underlying bank tools can remain compatible with the wider protocol while the customer sees a named application rather than a generic collection of functions.
OpenAI has subsequently moved application discovery into its Plugin Directory. A plugin can package an app with workflow-specific skills, while the underlying app retains responsibility for connecting ChatGPT to external data or actions. Users can connect the provider and authenticate the underlying service. For a financial institution, this creates a materially different position from publishing an MCP endpoint alone.
A bank can use MCP to expose approved capabilities while packaging those capabilities inside a bank-identified application. Existing customers could authenticate their banking relationship and use institution-specific functions from the ChatGPT conversation. Interactive UI can also be rendered by the application, allowing the institution to present its own transactional component rather than returning every result as generic model-generated text.
The model has already been demonstrated in financial services, although not yet at scale by a major retail bank. Anthropic announced in May that Moody's had launched an MCP application that brings its proprietary credit information and an interactive provider interface directly into Claude. Moody's remains identifiable as the source of the financial capability while Claude remains the conversational environment.
That distinction is likely to become important for banking distribution. The external AI platform can own the surrounding conversation without forcing every connected financial service to become invisible infrastructure.

Branded presence does not restore channel ownership
A branded ChatGPT application protects attribution, but it does not reproduce the economics of a bank-owned mobile channel. The surrounding conversation still belongs to the AI platform, and OpenAI's own product design shows why that difference matters. ChatGPT can suggest an application when the system determines that it is relevant, while users can also call available apps directly. The bank may therefore own the service being invoked without owning the point at which the provider was selected.
This introduces platform power into financial distribution.
Suppose an authenticated customer uses a bank application inside ChatGPT to review available cash. The interaction can retain the bank's identity because the bank application provides the account capability. If the customer subsequently asks whether a better savings option exists, the conversational platform is no longer confined to the bank's product catalogue. The system can potentially introduce another financial service if the platform permits that service and considers it relevant.
The bank remains visible, but it no longer controls the complete commercial environment in which its product is evaluated.
This resembles marketplace distribution more closely than conventional digital banking. A supplier can retain a recognisable brand while the marketplace controls search and the ordering of alternatives. Brand presence reduces the risk of becoming anonymous infrastructure, but the platform still sits between customer intent and provider selection.
The response therefore cannot consist only of producing a branded plugin for every major AI platform. That model gives the bank representation inside external channels, which is valuable, but it leaves discovery and conversational context under another company's control.
Banks need a second position in which the institution itself becomes the agent through which customers interact with financial services.

Control how external AI platforms access your banking capabilities
Bank-owned agent changes MCP from an inbound channel to an outbound one
The same protocol that allows ChatGPT to consume bank capabilities can allow a bank-owned agent to consume external services.
This reverses the distribution relationship. Instead of the customer's external agent deciding which banking function should respond, the bank's agent interprets the financial requirement and uses approved external capabilities where the bank cannot fulfil the requirement internally.
The difference is strategic because the institution retains the interaction that creates the financial decision. The customer can explain a requirement inside the bank's environment, and the bank agent can evaluate the financial context already held by the institution before determining what action is appropriate.
This model also changes the value of Open Banking connectivity. Account aggregation was originally attractive to third parties because it allowed them to assemble a broader customer view than any single bank possessed. A bank-owned agent can use permissioned external financial data for the same purpose while combining it with the bank's authoritative internal information.
The credible bank agent is therefore not a conversational wrapper around mobile banking. If it only answers balance questions and routes customers towards existing menus, an external assistant with broader context will remain more useful. The bank agent needs to operate at the level of financial intent and connect that intent to controlled financial capabilities.
The institution has an advantage because it already maintains a verified banking relationship and authoritative financial records. It can combine those assets with information the customer explicitly provides during advisory interaction. The resulting financial context can remain available to the bank agent across subsequent decisions instead of existing only in the external platform's memory.
This does not require the institution to manufacture every product itself. A credible financial agent may need to work with services outside the bank. The bank retains the relationship because it owns the reasoning environment and the authority model through which the customer's request is converted into an executable financial instruction.
MCP then becomes useful in the opposite direction from the raw-server scenario. It allows the bank's agent to reach external systems without forcing those systems to become part of the bank's core architecture.
The defensible position is dual distribution
Customer behaviour is unlikely to converge around one financial interface. Some customers will prefer to interact directly with their bank, particularly where an established relationship carries significant value. Other customers will spend more of their digital time inside general-purpose AI platforms and expect banking services to become accessible from those environments.
A bank that supports only its own agent risks becoming difficult to access from an increasingly important distribution channel. A bank that supports only external agents risks losing the interaction in which customers form financial decisions.
The resulting operating model has two distribution surfaces built on one controlled banking capability layer.
The bank-owned agent serves customers who maintain a direct relationship with the institution. External AI platforms receive access through bank-identified applications rather than through an unrestricted catalogue of anonymous tools. Both routes call the same underlying financial services, which prevents each new agent platform from creating another implementation of payment or account logic.
This architecture reduces a major cost problem associated with agent adoption. Without a common capability layer, every new conversational product can create another integration programme. Authentication logic becomes duplicated across channels while transaction workflows begin to diverge. The institution then carries higher OPEX because each interaction layer needs maintenance when underlying products or controls change.
Separating financial capabilities from agent-specific interfaces changes the investment structure. Existing APIs and workflow services remain responsible for deterministic integration. The MCP layer presents approved capabilities to compatible clients, while platform-specific applications deal with the user experience required by ChatGPT or Claude.
The institution can therefore add distribution channels without rebuilding the financial function behind each one.
The more difficult investment moves into governance. The bank has to determine which capability is available through which external environment and under what authority. That work does not disappear because MCP standardises tool access. It becomes more important because the same capability can now be invoked from environments the bank does not operate.

Turn existing banking APIs into controlled agent capabilities
Financial authority has to remain independent from conversational interpretation
The most consequential architectural boundary in agentic banking sits between understanding intent and authorising financial execution.
An AI system can infer that a customer wants to send a payment. That interpretation should not itself create financial authority. The bank still needs to establish that the authenticated customer has permitted the action and that the requested transaction is valid under the institution's controls.
The current agentic-payment experiments show how this boundary can work.
Santander and Mastercard completed a live end-to-end payment initiated by an AI agent in March 2026. The transaction ran through Santander's live payment infrastructure, while Mastercard Agent Pay provided the agentic transaction framework. The agent operated inside predefined permissions rather than receiving general authority over the account.
The example matters because the bank did not need to control the customer reasoning process in order to retain control over the transaction. An AI system could initiate the action, but the bank's payment infrastructure remained responsible for producing the financial outcome.
That separation should continue inside MCP-based banking.
The AI client interprets intent and requests an approved capability. The institution controls authentication and execution, while existing systems continue to produce definitive financial state and audit evidence. MCP authorization provides a transport-level framework for controlled client access, but the protocol does not replace the bank's own transaction mandate.
The distinction is commercially useful as well as regulatory. Even when an external platform controls the conversation, the bank can remain the recognised source of authority for a high-value financial action. A payment confirmation or approved lending decision carries more weight than a generic conversational response because it represents a contractual outcome produced by the institution.
Banks therefore do not need to retain every interaction to retain a meaningful customer position. They do need to preserve the boundary at which conversation becomes financial commitment.
Delegated authority becomes part of the banking product
Current digital banking permissions are usually designed around authenticated humans or predetermined application integrations. Agentic interaction creates a more granular requirement because the customer may want the agent to act without providing unlimited authority.
The customer may permit routine transfers between personally owned accounts while requiring explicit approval for an external payment. A business may allow an agent to prepare supplier payments but retain its existing corporate approval process before submission.
These arrangements cannot be represented adequately by a simple decision that an MCP client is either authorised or unauthorised.
The bank needs a delegated-authority model that evaluates the requested function in the context of the customer's mandate. The MCP client can authenticate through the supported authorization mechanism, but the banking policy layer still determines whether the requested financial action falls within permitted scope.
Payment networks are already working on the same problem from the commerce side. Visa's Trusted Agent Protocol provides a mechanism for merchants to identify approved AI agents and validate agent intent. Mastercard Agent Pay applies permissioning rules to agent-initiated transactions so execution can remain within defined customer limits.
For a bank, the control model has to sit closer to the account because the available actions extend beyond a single purchase. Agent identity establishes who is making the request. Customer mandate determines what that agent is allowed to do.
This distinction also affects customer engagement. A bank that owns the mandate remains involved in the ongoing definition of how an external agent may use the financial relationship. The external platform can simplify the interaction, but it cannot determine the financial authority independently.
Authority therefore becomes part of the relationship model rather than a technical permission hidden behind the interface.

Keep identity, permissions and execution inside the institution
Machine-readable products change how banks compete for distribution
Agent access will also expose a weakness in the way many financial products are currently presented.
Bank product information is designed largely for human discovery. Websites combine explanatory copy with rate information, while important conditions may sit in separate disclosures. A general-purpose agent evaluating products across institutions needs a more deterministic representation.
The requirement is already familiar from comparison engines, but agents increase the pressure because they can potentially make product evaluation part of an ongoing customer conversation. The customer does not need to visit a comparison website deliberately. The comparison can occur when another financial question reveals that an alternative product may be relevant.
This changes the value of machine-readable product information. A deposit product needs sufficiently precise terms for the agent to establish whether the customer is eligible and whether the quoted return applies to the relevant balance. A lending product requires enough structure for the system to distinguish indicative marketing terms from a customer-specific offer.
If the bank does not provide that representation, the agent will rely on information available elsewhere. The institution then loses control over how its product is interpreted while still being exposed to comparison.
The response is not to make every product universally callable. It is to create a controlled machine distribution layer in which product information and executable offers are treated differently.
Public product attributes can support discovery. A customer-specific quotation belongs inside an authenticated bank process because the economics may depend on the customer's existing relationship and current financial position.
This preserves room for relationship pricing in an environment where agents reduce search friction. The bank competes on an actual offer to a known customer rather than allowing the external platform to reduce the relationship to a public headline rate.
Customer context becomes infrastructure
The strongest bank-owned agent will depend less on the choice of language model than on the quality of the customer context available to it.
Banks already hold structured information about the financial relationship, but much of the customer's decision history remains fragmented between channels. An agent changes the value of that information because previous interactions can materially affect the next recommendation.
A bank therefore needs a persistent financial context layer that distinguishes authoritative facts from conversational context. A confirmed liability has a different status from a customer mentioning that a property purchase is being considered. The agent should be able to use both, but the institution needs to know which information came from a system of record and which came from the customer's stated intention.
That distinction becomes critical when the context begins to influence financial execution. An external platform can create its own customer memory, as ChatGPT Finances already does for selected financial information. If the bank does not maintain an equivalent relationship model, the external platform can become the only system that remembers the reasoning behind previous decisions. This creates a different definition of customer ownership.
The institution does not need exclusive possession of customer data, which Open Banking already made unrealistic. It needs enough authoritative context to understand the customer without depending on another platform to reconstruct the relationship.
The value of that context extends beyond the bank-owned agent. The same model can determine what information is appropriate to expose to an external AI client and what context should remain within the institution.
Customer memory then becomes part of the banking architecture rather than a feature of the conversational interface.

Finpace Halcyon provides the agent-facing layer without moving financial authority
For institutions with established cores and API estates, the implementation requirement is a controlled layer between those systems and the growing number of AI clients.
Finpace Halcyon provides that layer by exposing approved banking capabilities through an MCP-compatible agent interface while existing core systems remain responsible for definitive financial state. Authentication and transaction execution continue under institutional control rather than moving into the external AI client.
The architectural purpose is to avoid building separate agent integrations around each financial system. Halcyon can sit above existing APIs and connected banking infrastructure, providing the translation between agent requests and controlled financial functions. This allows the institution to support its own AI experience and external AI distribution without duplicating the underlying banking workflow.
The same separation gives institutions control over how much capability each distribution surface receives. A bank-owned agent can operate with broader internal context, while an external platform can receive a narrower set of approved functions through a branded application. Both interaction models still reach the same authoritative systems beneath the agent layer.
This approach also avoids making MCP deployment dependent on core replacement. Banks can introduce agent access where existing systems already provide adequate financial APIs and expand coverage as the operating model develops.
The practical value lies in sequencing. Institutions can establish the access and authority architecture before committing large amounts of capital to proprietary AI channels whose customer adoption remains uncertain.

Deploy agentic banking without rebuilding the core
Banks can lose the app session without losing the relationship
The traditional digital-banking model made engagement relatively easy to observe because customer interaction happened inside the institution's own channel. App sessions and digital product journeys provided a direct view of the relationship.
Agent distribution breaks that measurement model. A customer may interact with the bank less frequently while using its financial capabilities more frequently through an external agent. Another customer may keep substantial balances with the institution while allowing ChatGPT or another platform to become the place where every meaningful financial decision is considered.
Those situations have very different commercial implications even though traditional engagement metrics could describe both as declining channel usage. Banks therefore need to distinguish channel engagement from relationship control. The more useful measures will concern where financial decisions originate and whether externally initiated interactions retain identifiable bank participation.
Branded applications can preserve that participation when the customer prefers an external AI environment. A bank-owned agent can retain the primary interaction where the institution has enough trust and context to justify a direct relationship. The authority layer protects the institution's role when another platform initiates the transaction.
MCP does not determine which of these positions the bank occupies. It reduces the technical friction required to connect them.
The distribution decision sits above the protocol. A bank can expose MCP tools and become an invisible supplier, or it can use the same infrastructure to maintain a bank-owned agent while establishing branded representation inside external AI platforms. The technology is similar in both cases; the customer relationship is not.
The institutions that treat MCP only as another API standard will make themselves easier for agents to consume. The institutions that treat agent access as a distribution architecture can decide where the bank remains visible, where it retains financial authority and where another platform is allowed to own the interaction.
That distinction will determine whether agentic banking extends the bank's reach or completes the disintermediation that Open Banking first made possible.

Let’s build the future of banking together
Whether you’re scaling what works or starting something new, we’re here to help. Book a discovery session and explore what’s possible with Finpace.