← All issues

The AI FinTech Index Brief

August 16 to August 29, 2026 · Published August 30, 2026

The two weeks in one line

The pattern of the past two weeks is vendors opening their products to agents they do not control: an insurance core published skills for outside coding agents, a wealth CRM shipped a permissioned MCP server, a portfolio data aggregator wired itself into an answer engine. The integration surface moved from the API to the agent, and the control that matters moved with it, from the API key to the permission model.

This is the second issue of the Brief. It covers August 16 to August 29: 25 entries across 23 vendors, 17 Verified against the vendor’s own materials and eight Partially Verified from third party reporting. Funding rounds, valuations, and awards are not logged, here or anywhere on this index.

Vendors opened the door to outside agents

Socotra published Socotra Skills, an open source set of reusable instructions and workflows that let external coding agents such as Claude Code, Codex, and Cursor operate against its insurance core: configuring billing, reporting, and integrations, and calling Socotra’s APIs to execute insurance workflows. Practifi launched Sentir, a wealth management CRM built around 16 specialized agents, and shipped it with a permissioned MCP server that extends CRM context to AI assistants outside the product. Flanks released a live data connector that exposes its regulated multi bank portfolio data, aggregated from more than 700 institutions across 33 countries, to Perplexity’s answer engine and Computer agent. Obin AI made its Financial Agent available inside Google Cloud’s Gemini Enterprise for Financial Services over A2A, the agent to agent protocol. And SEON’s August release note added four Model Context Protocol tools with connectivity to Grok.

None of these is an API in the sense the last decade meant it. In each case the caller is an agent the vendor does not run, and in four of the five the agent on the other side belongs to a general purpose model provider. The counterpart entry is Fiddler AI’s platform release 26.17, which adds Guardrails to its AgentGateway: redaction of personally identifiable information and secrets in real time, before a request reaches the underlying model. That is the same design seen from the institution’s side of the door, and the control sits at the gateway rather than in application code, which is where a security team can audit it.

Our read

For most of the software era the API key was the permission model: whoever held it could call. When the caller is an agent acting for a person, the questions become which person, with which permissions, and whether that answer travels with the request. Practifi’s design, where the outside assistant works inside the firm’s own permission model, is the one to insist on. A connector that puts regulated portfolio data in front of an answer engine is a data sharing decision, whatever the launch post calls it.

Buyer question

For any vendor exposing an MCP server, an A2A endpoint, or published agent skills, ask whose permissions apply when an outside agent calls, what is logged per call, whether redaction happens before the model sees the data, and what the agent’s provider retains.

The checkpoint became a feature

The August 16 issue asked whether a reviewer could trace every statement in an agent’s draft back to a source before signing. This fortnight three vendors shipped that as product. Hebbia released Matrix 2.0, which now carries a workflow through to the finished deliverable, models, memos, decks, and emails, drawing on a firm’s deal history and internal systems alongside external feeds, with a checkpoint in every workflow where a person signs off before the next step runs. Gradient Labs launched Collaborate, which lets operators and engineers change an AI agent the way they change code, with version control, built in evaluations, and continual learning. And ibl.ai added Projects and Workflows: a Project holds files, standing instructions, and assigned agents; a Workflow is a multi step execution expressed as a graph with branches, loops, and guardrail checks.

Two research entries belong to the same family. Boosted.ai launched Alfa Prime, a multi model investment committee in which independent models argue bull, bear, and moderating positions and the debate is synthesized into a citable memo, available initially to selected institutional partners. Quartr introduced Automations for Quartr Pro, recurring research tasks that run on a schedule or fire the moment a covered company publishes new earnings materials, with results delivered in chat or by push notification.

The common design is that the agent’s output now carries its own review record: a version, an evaluation result, a checkpoint, a citation. That record is what separates an agent a model risk function can approve from one it cannot. An agent that changes weekly with no version history is a model that cannot be validated, and for most agent tooling the change management process is still screenshots and meeting notes.

Our read

Version control for agents is not a developer convenience. It is the first artifact a validation team can actually review, and a vendor that ships it is choosing to be validated. The buyers who will feel this first are the ones whose model inventory already has a line for an agent and nothing to attach to it.

Buyer question

Ask to see the version history of the agent you are buying and the evaluation results attached to its last three changes. If the answer is a roadmap slide, the agent has no change management process yet.

Market notes

The notice to read first: nCino named the nCino Mortgage API the standard integration platform for nCino Mortgage, replacing the legacy SimpleNexus API. The new framework carries modern authentication, versioning, webhooks, and developer tooling. SNAPI stays supported with no sunset date announced, but nCino states it is adding no new endpoints or functionality to it, so an integration started on SNAPI today carries a migration later, and authentication, authorization, and payloads differ substantially between the two.

The other integrations landed on rails buyers already run. Sixfold released a MuleSoft connector with bidirectional connectivity to Salesforce, so submissions, enrichment data, and underwriting decisions move between the two systems without rekeying. CredoLab’s behavioural credit scoring went live on the FICO Marketplace. Finster AI released a PitchBook Premium Connector that brings private capital market data into its workflows with the figures traceable to PitchBook as source. And FE fundinfo logged two entries: Irish tax modelling in Nexus for Financial Advisers, and Product Mastering Core, a governed single source for fund, share class, and registration data with an Openfunds aligned model of more than 600 fields and validation at the point of entry.

Coverage and certifications moved in four places. Accertify achieved HIPAA compliance and extended its fraud platform into healthcare, which opens health savings account providers, pharmacy benefit operators, and healthcare payment processors as buyers. Marloo launched in the United States with US data residency on AWS, SOC 2 Type II, and a zero retention policy for customer data. AiPrise shipped single click business onboarding that queries official company registries and pre fills legal name, entity type, registration number, and ownership, live in more than 65 countries. And SEON’s release note, alongside the MCP tools above, expanded eKYC coverage to five new markets, added eIDAS certified identity proofing with session video recording, and introduced an evidence collection engine for source of funds documentation.

One model change, one cost control, and one quiet correction. Incognia launched AI Powered Browser ID, which applies a transformer to the semantic relationship between more than 200 browser metadata signals and tokenizes them rather than hashing them into a static fingerprint, so a returning user stays recognizable through the routine browser updates that break conventional fingerprinting. ibl.ai added server side spend caps on model usage, set per workspace, per agent, or per user and agent, with reset periods, near limit alerts, and a choice between blocking and alerting, and documented supported deployment paths for applications built on the platform. And Fenergo changed its Product Risk Assessment so that products with a lifecycle status of Offboarding or Offboarded are excluded before the score runs. It is the smallest entry in the log and possibly the one most periodic review teams will feel, because an entity’s product risk score no longer carries products the client has already left.

Consolidation: Socure acquired Fravity, an agentic platform for fraud, risk, and compliance operations, and will deliver it inside RiskOS as RiskOS_Agents. The agents carry out investigation and case work rather than returning a score, beginning with watchlist screening and monitoring and know your business checks, wired into Socure’s identity graph, models, and decision outcomes. Socure cites cost per case down 80 percent, resolution up to five times faster, and false positives down as much as 70 percent across Fravity’s existing deployments, all of it vendor reported. Two corporate entries with earlier dates also entered the log since the last issue: Bloomberg’s definitive agreement to acquire Canoe Intelligence, announced July 29 and not confirmed closed at the time it was logged, and Carta’s October 2025 acquisition of Accelex, since followed by three further Carta deals. RavenPack’s July move to per token pricing for licensed content on Bigdata.com is also in the log.

The shape across the three acquisitions is the same: the buyer of an AI vendor is another vendor already in the institution’s stack, and a product bought standalone can end up inside a bundle the buyer did not choose. A shortlist built around Fravity now runs through Socure, one built around Canoe will run through Bloomberg, and one built around Accelex already runs through Carta.

What the fortnight says about the space

Put the two themes together and the category is building, from both ends at once, the plumbing for agents to act inside regulated workflows. On one side vendors are opening their products to agents they do not control. On the other they are wrapping their own agents in versions, checkpoints, and citations so a reviewer can stand behind the output. The control that matters moved the same way on both sides, away from the API key and toward the permission model and the audit trail. It is the story the first issue told, one step further along: two weeks ago the draft moved to software and the signature stayed human. This fortnight the vendors built the record that lets the signature mean something.

The AI FinTech Index Brief is published by AI FinTech Index, an independent reference for evaluating AI vendors in financial services. No vendor pays for inclusion, placement, or rating. Compare any indexed vendors by capability at Compare and read the evaluation standards at Methodology.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746