The AI FinTech Index Brief
September 27 to October 10, 2026 · Published October 10, 2026
The two weeks in one line
Banks spent two weeks on both sides of the same agent. Backbase, InvestSuite and Kore.ai shipped agents that act for a customer inside limits the bank sets, while Darwinium and Incognia shipped ways to judge an agent that arrives from somewhere else. The insurance cores built agents of their own, research vendors started selling skills instead of screens, and Middesk began checking Street View to see whether a business actually has a front door.
This issue covers two weeks, September 27 to October 10. The log recorded 57 entries across 48 vendors, 47 Verified against the vendor’s own materials and 10 Partially Verified from third party reporting. Product changes led with 43, integration work followed with seven, four entries changed a model or the architecture around it, and one was published performance evidence.
The customer sent an agent
Two kinds of agent product shipped in the same two weeks, and they are built to meet each other. One acts for a customer inside a bank. The other checks an agent that shows up at the bank’s door.
Backbase made Conversational Banking generally available. A customer or a member of staff states a need by voice or text, and an agent maps it to a banking action, such as blocking and reissuing a lost card. It acts only within permissions, policies and approvals the bank defines, asks the customer to confirm anything consequential, and records what it decided and why. Backbase says it is in production at more than ten banks, including a large South African bank where self service containment rose from 20 to 70 percent.
Kore.ai worked on the moment before the agent acts. When a tool call needs approval, the customer now sees a plain question built from readable labels such as account and amount, with sensitive values masked and internal instructions hidden. An earlier release in the period made workflow and MCP tools count as having side effects by default, so a retry does not repeat the operation.
That second change sounds like plumbing, and it is. It is also the difference between an agent that pays a bill and an agent that pays it twice because the network blinked.
InvestSuite took the pattern into advice. Charlie for Advice sits inside a bank’s own investment app, asks a retail customer about their goal, builds a proposal with pessimistic, realistic and optimistic outcomes, and rebalances when the portfolio drifts. The bank decides which data, products and actions Charlie may use and when a human adviser takes over, and MiFID II suitability checks still apply. The April version explained. This one advises, and InvestSuite expects its first live banks in 2027.
WealthAi launched agents that run wealth client onboarding and KYC end to end, collecting documents, starting screening at the right stage and bringing in a person only where the firm’s own process requires it.
Now the other side of the counter. Darwinium launched MCP Protection, which puts an agent’s tool calls into the same journey record as web and mobile activity, verifies the agent’s credentials and can hold a payment for extra checks. Alongside it, Journey Transition Probability scores each step toward a login or a payment against the usual order and timing for that customer, whether a person, a bot or an agent is acting. Recorded Partially Verified.
Incognia launched AI Agent Detection for financial institutions, and its design choice is the interesting part. It judges the risk of each action an agent starts separately from the agent itself, and can check a doubtful action against the customer’s trusted devices and account history.
The last issue covered Baselayer’s Know Your Agent. Two weeks later the fraud vendors had moved one step further, from who sent the agent to what the agent is trying to do.
Our readBanks are building the agent they will let act for a customer and the check they will run on an agent they did not build, at the same time. Both land on the same unit: the single action, judged against permissions and history, with a confirmation before money moves. Before long a customer’s assistant will be negotiating with a bank’s assistant, and the record of who agreed to what will matter more than either one’s conversational skills.
The insurance cores built their own
The last issue’s insurance agents came mostly from specialists reading claim files. In the space of nine days, the core platforms answered with agent layers of their own.
Duck Creek launched Agentic FNOL to early access customers, built on Google Cloud and Gemini. A claimant describes a loss in their own words, and the agents decide which follow up questions to ask, verify coverage, assess injury and legal severity and flag anomalies against submitted images. Triage follows carrier rules, every determination is logged, and exceptions go to a person.
Sapiens launched Sapiens Brain, a knowledge graph built from the code, documentation and design artifacts of more than 40 years of its own systems. Its agents run outside the core and reach in through MCP, which Sapiens says lets the AI update faster than the core release cycle. It uses domain tuned models for contained tasks rather than one frontier model across a whole workflow.
Majesco’s Fall ’26 release took the opposite route and put the agents inside the screen. Its Immersive AI reads the context of the workflow a user is in, surfaces work agents have already processed, recommends next actions and completes routine tasks within guardrails. Underneath sit an agent studio, a model catalog and human approval steps, and P&C gains OFAC screening of claim payment recipients.
Akur8 launched one agent for each module of its pricing platform. They build pricing structures, write formulas and bring rating logic over from spreadsheets, but Akur8’s own actuarial engines still do the calculations, and users approve each change before it runs. Customer data is not used to train the models.
WTW added a natural language assistant to Radar Vision that pulls weak early indicators into one view and recommends pricing and underwriting actions. Vertafore made its Document Intelligence Agent generally available in ImageRight five days after the early adopter release, with every answer cited to the document and page.
Insurance core upgrades have long been planned in years and scheduled in seasons. The agents look set to keep a faster calendar than the systems they sit beside.
Our readWith Duck Creek, Sapiens and Majesco shipping inside the same nine days, having agents no longer separates one core from another. The useful question for a carrier is where the agent sits, who does the arithmetic, and whose release schedule it follows. Sapiens put its agents outside the core so they can change faster than the core does. Akur8 kept its agents away from the math. Both are answers to the same worry, a model updating on a different schedule from the system of record it touches.
Research vendors started selling the skill
Two issues ago, data vendors became connectors inside frontier assistants. Last issue, the connectors learned to write. This period the research vendors packaged the work itself.
Chronograph released plugins for Claude that pair its existing connector with curated skills. For private equity managers, the skills assemble quarterly review packs, generate investor reports from live portfolio data and rank valuation changes by their effect on NAV. For allocators, they forecast capital calls, distributions and NAV with the Takahashi-Alexander model and build commitment pacing plans.
A connector gives an assistant a library card. A skill gives it a job description and, in private equity, a quarter end deadline.
AlphaSense released the next generation of SuperAnalyst, which takes an objective rather than a prompt. It plans the work, reconciles evidence across filings, broker research, earnings calls, expert interviews and a firm’s own content, writes and runs code, and produces memos, models and decks. A context graph ties each data point to its source, and prebuilt skills cover earnings previews, buyer universes and competitive mapping.
Hebbia went a step further and sold the engine without the screen. Headless Hebbia is an API and MCP server that brings its retrieval and analysis into a firm’s own applications and into assistants such as Claude and ChatGPT, run step by step so findings can be checked against the source. Its October release added memory to its Max agent, a Word plugin and data room sync with Intralinks.
The data kept arriving inside the assistants as well. S&P Global Market Intelligence added nearly a million credit ratings from RatingsXpress to its AI Data Portal for MCP enabled applications. Quartr’s earnings calls, transcripts and filings went live inside Model ML, whose own September update split large tasks across parallel agents, added undo on every cell an agent changes in Excel and put the agent in Slack.
MSCI launched SignalLab, more than 600 investment signals updated daily. An AI agent turns research into tested signals, and an MSCI researcher validates what it produces. Shortcut introduced Sho, an agent with its own cloud computer that keeps working in the background and remembers between sessions, in early alpha. Recorded Partially Verified. Arch extended its private markets platform into diligence, extracting terms from offering materials and linking each one to its source document.
One detail repeated across the period. The riskier new features arrived switched off. Hebbia’s memory stays off until an admin enables it, and Vega Minds’ new Claude connector is read only and dormant until a firm admin turns it on.
Our readThe unit of sale in research AI is becoming the task. A skill encodes how a firm builds a quarterly pack or an earnings preview, know how that used to live in an analyst’s head and a shared drive. That makes evaluation more concrete for a buyer. A connector can only be tested for whether it connects. A skill can be run on last quarter and compared with what the team actually produced.
The document lost the benefit of the doubt
Generating a convincing bank statement now costs about as much as describing one. This period’s identity and onboarding releases read like vendors adjusting to that fact.
Persona shipped four releases. New checks for supplemental documents, the files other than an ID that customers upload, look separately for AI generated documents, visual tampering, PDF tampering and low effort fabrication, and customers set their own definition of high risk. Recorded Partially Verified.
Escalated Verifications runs Persona’s heaviest fraud models, including multi frame video analysis, after a verification has already passed, and flags the ones that look wrong in hindsight. Fraud Fight Flow is a verification step Persona maintains itself, updated from the attacks it sees. Vision Mode passes the document image straight to the model so layout counts as well as text, which helps with documents such as Chinese business licenses. Recorded Partially Verified. A new API version adds a country code derived from each session’s GPS location.
Middesk now pulls Street View imagery of an applicant’s address from several angles, reads the signage against the business name and classifies the property as a storefront, office, residence, mail drop or vacant land. It is the credit officer’s drive by, minus the drive. A new document agent screens IRS letters, formation filings, leases and bank statements for tampering and reconciles them against verified records, and teams set the confidence threshold below which a person must review.
Smart Capital Center launched fraud alerts for commercial real estate lending that compare documents from the same period, such as a rent roll against an operating statement, track the same figures over time and reconcile construction draws against budgets and inspection reports. Hawk’s new due diligence agent cross checks a customer’s declared profile against their actual transaction behavior and maps ownership chains through registries and adverse media. It never closes, escalates or submits a case without a person’s approval.
The other answer is to rely on the document less. Jumio finished the worldwide rollout of selfie.DONE, which lets a previously verified user take a selfie instead of rescanning an ID, with fresh biometric matching and consent on every reuse. Ondato began accepting European Digital Identity Wallets in its web verification flow, ahead of the EU AML Regulation that applies from July 2027. Recorded Partially Verified.
Our readA document used to be evidence. Now it is a claim that needs a second source. Verification is moving to cross checks: the document against another document, the declared profile against observed behavior, the address against the building, and the identity against a credential issued by someone who already checked. The vendors that do well here will be the ones with the most independent things to compare against.
The model became a line item
Several vendors this period treated the model as a named, priced and swappable component rather than a secret ingredient.
Vega Minds named every model it runs and the job each one does. GPT-6.1 Sol writes client deliverables, Claude Opus 5.5 and Sonnet 5.5 handle meeting prep and writing, and Gemini 3.8 Flash and GPT-6 Luna run background tasks. Its October update also added compliance review of full meeting transcripts.
Model ML tested Claude Sonnet 5.5 on its own financial services benchmark before switching it on. It reports Sonnet close to Opus 5.5 in four of five categories at 56 to 78 percent lower cost, and trailing open models such as DeepSeek 4.1 Flash and Kimi K3 on pure financial workflows. The benchmark is Model ML’s own and the scores are unpublished, but a cost and quality comparison by task is exactly the record a model policy needs.
Shortcut added three models to its picker and made background tasks follow whichever model the user chose. Five days later a newer GPT-6.1 Sol replaced GPT-6 Sol in the same list. Recorded Partially Verified. A validation memo can now be outlived by the dropdown it describes.
The platforms were explicit too. Sapiens chose domain tuned models for contained tasks, Duck Creek named Gemini, Hawk described its agent as working with any large language model, and Majesco shipped a model catalog. The governance around the model got a certificate as well. NICE Actimize says its financial crime software is certified to ISO/IEC 42001:2023, the international standard for AI management systems, with the certificate issued by SII-QCD and a scope covering development, provisioning and deployment.
Our readNaming the model used to be a marketing flourish. In this log it is becoming an operating fact, with versions, costs and a switch. That is good news for model risk teams, and the same transparency shows how fast the ground moves. The question to ask a vendor now is not only which model, but how you hear about the next one.
Market notes
Card payments got more legible. Spade’s merchant enrichment went into FIS debit processing and, nine days later, into Increase’s card issuing platform, so each transaction carries a recognizable merchant name, location and category, available during the authorization decision. The Increase integration is recorded Partially Verified. The row of capital letters behind most calls that begin “I didn’t buy this” is finally getting a name and a logo.
Unit21 went live inside Alkami’s digital banking platform. When a member logs in, changes a profile or moves money, Unit21 checks the event against the institution’s rules and returns pass, step up or block before the action completes. Its September release added configurable SAR autofill and sends post account warnings straight to Jack Henry Symitar. Finastra introduced Repair Recommendations, which proposes fixes for failed payments validated against Swift, Fedwire, SEPA, UPI and Nexus rules and sends every one to a person, and launched a cloud native supply chain finance module at Sibos.
ACI Worldwide and Cognizant ran the BASE24-eps switch on AWS managed services at more than double its target load for 30 minutes, processing more than 4.6 million transactions with no failures. The target itself was not disclosed, and production use still needs failover testing and network certification. Murex connected MX.3 natively to ICE’s real time consolidated feed, and Polly rebuilt its hedging inside the PollyOS core, so secondary desks see live positions and margin loan by loan instead of yesterday’s snapshot.
In credit, Moody’s Analytics and Allvue launched the EDF-X Private Credit Model, calibrated on observed private credit performance. It estimates hard credit events separately from the softer ones that tend to come first, covenant waivers and payment in kind arrangements. CRIF launched ORCHESTRA, a composable credit lifecycle platform with Raiffeisen Bank Romania as its named user. Ocrolus opened a Conditions API to mortgage lenders outside Encompass and added a check of loan documents against Fannie Mae and Freddie Mac age limits, and Cardo AI turned deal dashboards into scheduled investor reports and covenant packs.
On oversight, Feathery added a supervised mode that pauses its computer agents before consequential actions, and its audit logs now record refused requests too. Recorded Partially Verified. Bretton let teams edit and validate the output format its agents return. Recorded Partially Verified. Kore.ai moved one default the other way, switching off the voice guardrails introduced in its 1.7.0 release, so teams that relied on them now turn them on for each agent.
Elsewhere, LeapXpert let Webex users message clients on WhatsApp with data loss checks and full archiving. Fenergo stopped requiring a separate relationship file for agency bulk uploads. Owlin made its risk scores weigh a development by its likely impact on the specific company. Socotra removed a deprecated parameter from 57 list endpoints, a breaking change for anyone still passing it. Recorded Partially Verified.
In wealth, RightCapital’s planning agent Iris began flagging opportunities across tax, retirement, insurance and estate plans and reading uploaded documents such as annuity illustrations. Jump added Genesys Cloud call capture, a TradePMR custodian feed and an optional prep attestation before each meeting that leaves an audit trail.
What the two weeks say about the space
Fifty seven entries, and the common thread is that the unit of trust got smaller. Fraud vendors judged the action rather than the agent. Research vendors sold the skill rather than the connector. Onboarding vendors checked the document against the building, and research and wealth vendors named the model by version and job.
The approval step that led the last issue turned up again in Feathery, Finastra, Hawk and Akur8, and this time it barely counted as news. In two weeks it went from a design choice to the expected shape of a regulated agent.
Financial services is building its agent infrastructure the way it built payments, with every message checked against a rule and every rule written down. None of it makes for a dramatic keynote. All of it makes for a defensible file, which in this industry is the better product.
Which financial services AI vendors name the models underneath their product?
Very few name them outright. Of the 578 vendors the AI FinTech Index has graded on Model Supply Chain Disclosure, 22 reach the top grade. That grade means the models in the path are named, usually down to the provider and often the version, along with which model handles which work. The strongest also say what a customer can control, from bringing its own model contract to hearing about a new subprocessor before it is added.
212 vendors name part of the chain. A cloud host, a data provider or a technology partner is identified, and which models actually do the work is left open or answered only in general terms.
The largest group, 337 vendors, mention models without naming any. A typical description refers to large language models running in the cloud or on premises and stops there. A further 7 grade lower still.
That is the gap this period’s log started to close, mostly in research and wealth. Vega Minds named five models and the job each one does. Model ML published a cost and quality comparison by task before it switched on a new model. Shortcut put the choice in front of the user and made background work follow it.
Naming the model answers half of what a model risk team needs. The other half is what happens when the model changes, and the log showed how quickly that can come, with a newer version replacing an older one in a vendor’s model list five days after the older one was added. Supervisory guidance on model risk does not exempt a model because someone else built it, so a supply chain the vendor will not name becomes validation work the buyer absorbs.
On this axis, the vendors worth a closer look say who supplies each model, which version runs which task, and how a customer hears about a change before it ships.
The full grading method and what separates each band are on the capability framework page.
The AI FinTech Index Brief is published by AI FinTech Index, an independent reference for evaluating AI vendors in financial services. No vendor pays for inclusion, placement, or rating. Compare any indexed vendors by capability at Compare and read the evaluation standards at Methodology.