The AI FinTech Index Brief
September 6 to September 19, 2026 · Published September 19, 2026
The week in one line
Two frontier labs launched finance products in one fortnight, and eight indexed vendors became connectors inside them, from Daloopa and Intapp in ChatGPT to Addepar and Zocks in Claude. The insurance core went headless at BriteCore and Sapiens, the payment rails consolidated at Bottomline and ACI, and a run of agents from CENTRL, Oscilar and Elliptic arrived showing their working before they acted. The question is no longer whether the assistant can reach the data. It is whose credentials it is holding when it does.
This issue covers two weeks, September 6 to 19: 53 entries across 50 vendors, 32 Verified against the vendor’s own materials and 21 Partially Verified from third party reporting. It is the largest issue this log has produced, and about a third of it is connector work. Funding rounds, valuations, and awards are not logged, here or anywhere on this index.
The data vendors became connectors
Two weeks ago this Brief said the data provider had stopped waiting to be logged into. This fortnight two frontier labs made that the product.
OpenAI launched ChatGPT for Financial Services on September 10, and three indexed vendors shipped into it the same day. Daloopa’s fundamental data is indexed and hosted natively, so verified, source linked financials are there when the model answers rather than fetched when it is asked. Quartr is reached through a connector instead, and OpenAI published the number: its optimisation work took Quartr’s connector error rate from 5.09 percent to 1.99 percent.
That figure deserves a pause. It is the first time a data vendor’s retrieval reliability inside an AI product has been quoted by the product’s maker rather than by the vendor. It also means native and connected are now different tiers, and the difference is measurable.
Intapp released a DealCloud plug in for the same product. A professional can query the firm’s own client, deal, investor and relationship records from inside ChatGPT, with information barriers, material non public information rules and independence obligations enforced on every answer. Roughly 1,700 private capital and banking firms run DealCloud, and this is the first time that record is reachable from a frontier model without a data export.
Four days later Anthropic launched Claude for Financial Advisors, and three more indexed vendors were connectors at launch. Addepar brings the consolidated portfolio view, including the private holdings most tools cannot see, which makes it the most valuable connector in the set and the most sensitive. Zocks brings what clients said in past meetings. SS&C Black Diamond brings portfolio, performance and rebalancing data. Recorded Partially Verified for two of the three.
Each of those carries its own question. For Addepar, which permissions the connector inherits before an adviser points an assistant at a family’s full balance sheet. For Zocks, how the firm’s archiving policy applies to what the assistant produces from meeting notes. For Black Diamond, whether the connector only reads or can stage a trade for review.
Two more entries belong in this set even though neither involves a frontier lab. LSEG released Workspace for Microsoft Teams, with AI Search, Deep Research and a cross firm directory, and it carries Microsoft 365 Certification, which means Microsoft vetted the data handling rather than LSEG asserting it. And Unit21 put a remote MCP server live, so Claude, ChatGPT, Cursor or any other MCP client can connect directly to a customer’s case management and transaction monitoring environment.
Unit21 is the one to think about longest. Alerts, cases and decisions are now readable by whatever assistant a compliance team permits, and the question is not whether the assistant can reach them. It is under whose credentials.
Our readEight vendors became connectors in one fortnight, and being a connector is now a tier with a measured error rate rather than a marketing line. The entitlement question sits under all of it: whether a firm’s existing subscription carries into the assistant or is sold to it again. Nobody in this fortnight’s entries answered that in public.
Buyer questionFor any data or record you can now reach from an assistant, ask three things. Is it indexed natively or fetched through a connector, and what is the connector’s error rate? Whose credentials does the assistant hold when it reads, and do your information barriers travel with it? And does your existing contract cover this access, or is it a second purchase?
The agent showed its work before it acted
CENTRL’s September release adds approval controlled actions to its agentic platform. The agent proposes a field update, a person reviews and approves it from a chat card, and only then does anything change. Every write gets a named approver and a moment of review, which is the pattern a vendor risk team can defend to an auditor.
Oscilar shipped a copilot that writes risk rules from plain English, and put backtesting against historical data and a diff view in front of it, so a rule change goes live with a measured historical effect and a visible difference. The same release bumps its AML alert scoring model to version 2.1. A published model version is exactly the disclosure model risk teams ask vendors for and rarely get.
Elliptic launched Decode, an agent that answers questions about cryptoasset addresses and their exposure. Every answer carries Thinking Steps showing how the question was read and the query that produced the result, and Elliptic states that the same question against the same data reaches the same conclusion. It is live with government customers, with private sector availability later in the year.
Determinism is a strong claim for an agent, and it is the right one for a tool whose every call has to be defended to an examiner. The test is whether the Thinking Steps cite the attributed intelligence underneath or only narrate the conclusion.
V7 Go moved its chats onto a new agent that names the model in the settings tooltip, GPT-6 Astra or a Gemini version, rather than hiding it behind a generic label. It keeps every turn of a run with each tool call stored beside its result, and records an MCP tool invocation as user activity with the sign in behind it. Knowing exactly which model produced an extraction is where any validation record starts.
Napier AI put an Agentic Test Simulator into closed beta. Autonomous agents generate labelled synthetic financial crime behaviour across up to 30 laundering typologies, so an institution can see where its monitoring fails before a regulator asks it to prove that it would not. The question to put to Napier is whether the simulator runs against a competitor’s system or only its own.
Two agents in the fortnight act rather than propose, and both are worth watching for that reason. Jump now opens accounts in real time with Schwab Advisor Services and Fidelity during the client meeting, pulling from the conversation, documents and CRM, flagging what is missing, and sending the application for signature before the client leaves. On Schwab it can also start asset transfers. Recorded Partially Verified.
Earnix launched Agent Hub, a catalog of more than 25 insurance agents that work inside pricing, underwriting and customer engagement, under what Earnix describes as defined permissions, traceability and human oversight. Pricing is a regulated decision in most markets. The question is which agents can change a live rate, and what record each action leaves for a rate filing.
Our readThe oversight design is converging on one shape: propose, show the working, wait for a person, then act, and leave a record with a name on it. Jump and Earnix are the ones to watch because they are furthest along the act end of that line. An account opened during a meeting is a wonderful thing until a field the agent filled from conversation turns out to be wrong, and the client has already left.
Buyer questionFor any agent that can write, ask to see the record of one action end to end: the proposal, the reasoning, who approved it, and what changed. Then ask which model produced it and what version. A vendor that can show that for one action can show it for a thousand. A vendor that cannot has an audit problem it has not met yet.
The core came apart and the rails came together
BriteCore announced headless core deployments for property and casualty insurers. BriteCore runs policy, billing and claims as the transactional backbone, and the carrier’s own underwriting workbench, agent portals, rating engine and distribution systems talk to it through governed interfaces. Recorded Partially Verified.
Most core replacements fail on the front end, not the ledger, because the applications a carrier built over a decade are where its differentiation and its agent relationships live. A headless option changes the negotiation. The insurer keeps what it built and swaps what it no longer wants to maintain.
Sapiens launched an Autonomous Insurance Platform whose most consequential piece is the Migration Hub. It ingests legacy files as they are, proposes data mappings with confidence scores for an expert to review, and keeps every transformation reversible.
Core migration is where insurance modernisation budgets run over, and confidence scored mappings with human review is the right shape. The first named customer is still evaluating, so ask for results from a completed migration.
Insurity took the rating engine out of the core entirely. Ratio ingests machine readable bureau content from ISO, NCCI and AAIS, applies a carrier’s own deviations, and delivers rating, forms and stat code logic to any downstream policy system through one API. Bureau circulars are the reason commercial rating changes take quarters, because every carrier re keys the same content into its own engine.
The claim to test is whether a carrier’s filed exceptions survive a bureau update without rework.
On the banking side, Avaloq put its first Swiss bank live on a SaaS mobile app whose interface is separated from the core, which means features can ship without touching the ledger. The proof will be that bank’s release cadence over the next two quarters.
The payment vendors moved the other way, toward one platform. Bottomline launched Global Pay Connect, bringing global and domestic connectivity across networks such as Swift and SEPA under one integration. ACI Worldwide added cloud native financial messaging to its Connetic platform, so messaging runs on the same platform as processing. Messaging is usually the oldest layer in a bank’s payments stack and the hardest to replace, and every ISO 20022 change is paid for in fragmentation.
And Broadridge launched DLX, a tokenisation platform that connects on chain and traditional market activity through one operating layer, launching with connectivity to the DTCC Tokenization Service via Canton. Recorded Partially Verified.
It builds on Broadridge’s distributed ledger repo platform, which has been running tokenised collateral at scale for years, so this is plumbing being extended rather than a roadmap being announced. Read it as one live network path today.
Our readUnbundling and bundling in the same fortnight look like opposite moves and are the same one. The core vendors are taking themselves apart so a buyer can keep its front end. The payment vendors are putting messaging and processing together so a buyer stops paying for the seam. Both are selling the same thing, which is a lower cost for the next change.
Identity moved from the customer to the staff
Sumsub launched Workforce Verification, which brings document checks, biometric liveness and background screening into enterprise identity and HR platforms such as Okta and Ashby, triggered at high risk moments from hiring to help desk account recovery. A password or a token proves someone holds a credential, not who they are, and help desk recovery is where deepfake social engineering is landing.
Jumio extended selfie.DONE, its reusable identity, to Asia Pacific, so an enrolled user can pass later checks with a selfie alone. Reusable identity cuts friction and means the first verification carries every later one. Ask how often the underlying document check is refreshed.
Incode shipped two releases in the fortnight, adding direct eKYC sources for Mexico and Argentina, then for the United Kingdom, the Netherlands and Finland. Direct register access is what separates a real match rate from a document upload. The second release also retires an identity search endpoint, so engineering teams should move off it now.
SEON expanded its signal intelligence to detect fraud rings and the fake identities now produced with generative AI. Synthetic identities pass document checks one at a time and give themselves away as a group, so ring detection is the right place to look. Socure removed a network round trip from its document check with an inline barcode flow, and added a reason code that turns a silent image quality failure into a labelled outcome an operations team can count.
Bits Technology added power of attorney support for organisation stakeholders during onboarding, which is a common blocker when the person applying is acting for someone else. And Riskified put its identity risk signals into Zendesk, so the service agent deciding a refund can see the fraud data the fraud team already has.
Market notes
Personetics launched Banking Console, a daily ranked list for relationship managers of which customers need attention, why, and what to say, layered onto the bank’s own CRM. The bank sets the priorities, and whoever sets them is deciding which customers get a call. Recorded Partially Verified.
Three wealth entries widened who can buy. Conquest Planning opened its planning engine to independent advisers and RIAs, who could previously reach it only through large institutions. Marloo introduced Ask Marloo, which lets an adviser query a whole client book, meetings, documents and emails included, which is the inherited book problem in one feature.
Transient.AI launched RIA prospecting for hedge fund sales built from ADV filings, running in the customer’s own tenant with zero data retention, which is the line that gets it past a vendor risk review.
In lending, Built added automatic draw submission and inspection data inside the draw budget, so a construction draw can be checked against verified progress rather than the request alone. TidalWave routes borrower permissioned payroll and bank data straight into Encompass and flags buy now pay later obligations that a standard credit report does not see.
Infrrd launched a self serve document API with bring your own model key and a learning loop scoped to each customer’s own data, so one lender’s corrections never train another’s extraction.
In compliance, Abrigo added an AI narrative to its CECL allowance tool that explains what moved between periods, which is the part auditors read and the part usually written by hand at quarter end. Aveni added case level outcome testing for Consumer Duty, the evidence format that regime asks for.
Aptus.AI launched a platform that turns regulatory text into structured data, with an efficiency figure from one unnamed client that should be treated as a claim to test. ACA Group introduced compliance data migration for firms moving personal trading records between platforms, where history is usually what stalls the move.
CUBE’s regulatory intelligence now powers horizon scanning inside IBM watsonx.governance, which helps only firms already on IBM’s product.
Digital assets picked up two monitoring entries. Scorechain added coverage of ADI Chain, an institutional network carrying dirham backed stablecoins and tokenised assets. Nasdaq Verafin integrated with Stablecore so fiat and digital asset activity can be monitored in one view, in beta with select customers.
And a scatter of platform work. Exiger re platformed 1Exiger onto an AI native release cadence that ships functionality continuously, which changes release cadence, integration surfaces and model dependencies for every customer at once.
Kore.ai added proxy control of every outbound call and entity level PII detection, the two items that usually hold up a bank’s security review. Feathery added a Japan data residency region and field level timestamps. AlphaSense brought clinical trial registries and drug labels into its knowledge graph. CSI launched a commercial payments suite for community banks.
Convr unbundled its underwriting intake into something a broker can try on five real submissions. ICE Mortgage Technology made two factor authentication mandatory on Simplifile eSign, and mandatory rather than optional is the detail, because optional controls are the ones nobody switches on. Napier also listed Continuum on the Microsoft Marketplace, which is a procurement change more than a product one.
What the fortnight says about the space
Fifty three entries, and the largest group by far is vendors becoming reachable from somebody else’s assistant. That was a pattern in the last two issues. This fortnight it became the product, with two frontier labs shipping finance editions and eight indexed vendors inside them on day one.
The second largest group is agents that show their working before they act. The third is cores taking themselves apart and rails putting themselves together. Different lanes, same direction: the vendor is giving up control of the surface the user works in, and competing instead on what it can prove about what happened underneath.
For buyers that changes the evaluation. The demo used to be the product. Now the demo is someone else’s chat window, and the product is the permission model, the error rate, the version number and the record of who approved what. Those are harder to show in a meeting and easier to grade, which suits an index and, more to the point, suits a buyer.
Which financial services AI vendors show their working?
Fewer than one in ten. Of the 490 vendors the AI FinTech Index has graded on Model Risk Management and Transparency, 34 reach the top grade. That grade means explainability and validation are built into the product and mapped to the supervisory instrument they serve: per alert attribution, backtesting or test before deploy, with a stated alignment to a framework such as SR 11-7, OCC 2011-12 or NYDFS Part 504.
Another 206 publish a real mechanism, such as per alert explainability, confidence scoring or split testing, without the validation package or the supervisory mapping behind it. The remaining 250 claim transparency in general terms with nothing a model validator could interrogate, or publish nothing at all.
Set that beside the same 490 vendors on Core Systems and Integration Depth, where 151 reach the top grade. The field documents how it connects far more readily than it documents how it decides. A vendor that cannot name the core never gets the demo, so it names the core. A vendor that will not show its working still gets the meeting.
This fortnight moved a handful of vendors from the second group toward the first. An answer that carries the query that produced it, a model named in a tooltip rather than behind a label, a scoring model with a version number, a rule change with a backtest and a diff. None of that is a framework mapping. All of it is something a validator can pick up and read.
The practical move is the one that works on every axis where the field mostly publishes posture: ask for the artifact rather than the claim. Ask for the model inventory entry, the last validation report, and the change log of model versions. A vendor graded A here can usually send all three the same day. The distance between B and C is rarely the product and very often whether anyone wrote the method down.
The full grading method and what separates each band are on the capability framework page.
The AI FinTech Index Brief is published by AI FinTech Index, an independent reference for evaluating AI vendors in financial services. No vendor pays for inclusion, placement, or rating. Compare any indexed vendors by capability at Compare and read the evaluation standards at Methodology.