The AI FinTech Index Brief
September 20 to September 26, 2026 · Published September 27, 2026
The week in one line
The approve button had its biggest week since the expense report. Vertafore, Juniper Square and Dotfile all shipped agents that propose and then wait for a yes, Elysian started reading every claim file instead of a two percent sample, and Lendflow gave an assistant permission to write loan applications. Meanwhile motif published a test its own agent failed, which is not something marketing usually signs off on.
This issue covers September 20 to 26. The log recorded 74 entries across 67 vendors, 58 Verified against the vendor’s own materials and 16 Partially Verified from third party reporting. Product changes led with 34, integration work followed with 19, and six entries were published performance evidence.
The agent learned to wait for a yes
The most common design choice in this week’s log was an agent that does the work and then stops before it counts.
Vertafore released four Velocity AI agents to early adopters, and two more for MGA underwriting. The Policy Check Agent compares policy documents with the agency management system and recommends corrections for a person to approve. The Change Request Agent summarizes what changed across renewal and endorsement applications, and the summary is saved only after an underwriter approves it.
Juniper Square launched Capital Intelligence inside its investor CRM, matching a fund manager’s contacts against Nasdaq eVestment data on more than 30,000 institutional firms. Every match and every record update stays a suggestion until someone on the team accepts it.
Dotfile rebuilt its compliance analytics so a user can ask its Autonomy agent for any chart in plain language. The agent saves the chart to a dashboard only after the user clicks Approve, and every figure opens the underlying case records.
Socotra put a Configuration Assistant inside its insurance product studio. It builds a product configuration from a prompt or an uploaded filing, proposes a plan the user must confirm, and retries a failed validation up to five times on its own.
A button marked Approve is about the least glamorous feature in software. In a regulated workflow it is also the moment responsibility changes hands, so this week it did a great deal of work.
The oversight itself is getting configurable. Bretton let administrators set the quality control sample rate for each agent in Settings, which previously took a conversation with Bretton. SymphonyAI introduced Symphony Risk Intelligence, a financial crime platform whose oversight runs from semi autonomous to fully autonomous, with the same governance applied to agents an institution builds itself. Recorded Partially Verified.
At the far end of the line, Ripjar upgraded the models behind Screening Assistant, its triage feature that closes low risk alerts on its own. That is the act end of the pattern, and it is where the quality of the classifier stops being a technical detail.
Our readPropose, wait, then act is now the default shape for an agent that touches a regulated record, and vendors are arriving at it from very different products. The competition has moved to the dial. Who sets the sample rate, which outcomes skip review, and what the record shows when an agent acts alone. Those are the settings a compliance team asks about first, and this week they started appearing in release notes rather than sales decks.
Insurance handed the agents the whole file
Elysian launched two claims products, and one sentence in the release carries the idea. Ely Audit reviews open and closed claim files across a whole book, rather than the roughly 2 percent sample a claims audit usually covers. Ely Adjust reviews every open claim daily, ranks them by risk and recommends next steps, with an optional supervisor review layer.
A two percent sample was never a statistical choice. It was a staffing choice wearing a lab coat. When reading a file costs almost nothing, the sample becomes a census.
CLARA Analytics put agents on every complex casualty and workers compensation claim from first notice of loss to resolution. They track changes in severity, litigation potential and fraud risk, and every score carries lineage, a version and a rationale tied to specific claim documents. The adjuster keeps the final decision.
BriteCore covered the front of the same lifecycle. Its FNOL Copilot takes first notice of loss by conversation, checks coverage and creates the claim record. Its Submission and Quote Copilot ingests applications, schedules of values and loss runs, flags missing data, applies rating and checks carrier appetite.
Underwriting moved to the portfolio level. Sixfold launched Distribution Intelligence, which scores every broker on volume, quality, appetite fit and hit ratio from submissions it has already processed, then recommends where underwriters should spend their time. Cytora reported that Zurich’s commercial underwriting deployment now spans more than 20 countries, with digitization accuracy at 98 percent. Recorded Partially Verified.
The data moved with it. Verisk and Equifax introduced a credit based insurance score for homeowners built on trended credit rather than a single snapshot. LexisNexis Risk Solutions put its telematics scoring into a smartphone SDK that scores driving on the device, so trip data never has to leave the phone.
Our readInsurance is the lane where the agent pattern is most complete. In one week the log recorded agents at intake, quote, claim, audit and broker management, all with the same shape: read everything, rank it, recommend, and leave the decision with a named person. The competitive question has shifted from whether the agent can read the file to whether its recommendation arrives with a reason an adjuster can defend.
The connector learned to write
The last issue covered data vendors becoming connectors inside frontier assistants. This week the connectors started doing more than reading.
Lendflow launched a hosted MCP server that connects a customer’s lending environment to ChatGPT, Claude and Grok. Users can query applications, offers and statuses, and they can also create applications, add notes and upload documents. What the assistant may do is set by the user’s own Lendflow permissions.
Read access to a loan pipeline is a convenience. Write access is a new front door, and it opens from whichever assistant the loan officer happens to prefer.
AlphaSense took a different route to the same problem. Its new Snowflake and BigQuery connectors query a firm’s data warehouse live, under each user’s own role, and keep no copy. The data stays where it was and so do the permissions. Recorded Partially Verified.
The research vendors kept wiring into each other. Model ML added connectors for Daloopa’s fundamental data and for Blackroom data rooms, both over MCP. FinTech Studios reached general availability in the Claude and ChatGPT connector directories, read only. Rogo added Octus credit data as a source its agents can use, and RavenPack’s Bigdata.com server gained tools that resolve people, places and companies by name.
Then the layer underneath all of it. Baselayer launched an Agentic Identity Suite that includes Know Your Agent, which verifies which platform runs an agent, who delegated it, and whether that delegation can be proven. Recorded Partially Verified. KYC now has a sibling, and compliance teams have one more acronym to enjoy.
CipherOwl rebuilt its command line tool so each action describes its typed inputs, outputs, effects and retry rules, specifically so an AI agent can call it safely. Kore.ai added a switch that runs account guardrails before any MCP tool executes.
Our readThe connector story has moved from reach to responsibility. Last issue the question was whether the assistant could reach the data. This week it was what the assistant may change, under whose permissions, and how anyone can tell which agent did it. Lendflow and Baselayer are the two entries to read together. One lets an agent write to a loan file. The other is building the way to prove who sent it.
Vendors published the results that did not flatter them
motif added a dated validation run for its private markets agent to its public evaluation docs. On a fixed five question set it scored 100 percent citation grounding, but a reviewer signed off on only one of the five answers. motif states plainly that the agent does not yet pass its own release gate.
Vendors almost never publish a test their product failed, and it is exactly the record a model risk team wants to see. A release gate that nothing ever fails is not a gate.
Terminal X published a scorecard for three new frontier models, grading retrieval, processing and answer generation separately on the same test sets. The model that led retrieval, Opus 5.5, was kept out of production because it refused routine finance prompts. Terminal X also kept its existing answer model, Sol 5.6, after its answers were preferred over the newer Sol 6 in 68 percent of head to head comparisons.
The lesson in that scorecard is that the best model on a benchmark and the best model for a regulated workflow are not always the same model. The only way to know is to publish the breakdown.
Socure corrected logic in its identity fraud and synthetic fraud models that had treated the last four digits of a Social Security number as a full nine digit value, which generally produced riskier scores. Scores for four digit inputs now shift slightly lower. A published model correction is a model risk artifact, and most vendors never write one down.
Bretton benchmarked its new agent architecture against the old one on 250 subjects each for KYC and KYB, with every run graded by an LLM judge. It reports errors down 37 percent on KYC and 23 percent on KYB, with no added run time. Recorded Partially Verified. AI Rudder published self evaluated voice agent benchmark results and, usefully, disclosed the full stack it tested, from speech recognition to model to voice.
The customer results were more conventional. nCino published a case study in which OSB Group cut mortgage offer to completion from 44 days to 22. DiligenceVault reported a client saving one to three hours per manager review. Both are recorded Partially Verified.
Our readTwo kinds of evidence arrived this week, and they are worth telling apart. The case studies say a customer got faster. The scorecards, the failed gate and the model correction say how the system behaves and where it breaks. The second kind is rarer and harder to publish, and it is far more useful to anyone who has to sign off on a model. A vendor that publishes it is telling the market its validation process exists.
The strict setting became the default
Incode made its capture endpoints reject uploaded images by default. Uploading a selfie from the photo gallery is now a setting that stays off unless a customer turns it on, and it carries a fraud risk warning. The same release adds US driver license checks against AAMVA’s updated verification service.
Microblink made card data redaction the default in its BlinkCard SDK, masking the card number in both the image and the result and removing the CVV entirely. Entrust changed its iOS identity SDK so capture videos are deleted once they are no longer needed and no session data is left behind in the host app.
ibl.ai extended personal data filtering to files uploaded into chat, images and PDFs included, and added network allowlists for agent sandboxes that fail closed. S&P Global Market Intelligence’s Kensho library moved an OAuth refresh token out of the URL, so it no longer appears in access logs.
Fraud detection kept moving into the session itself. Incognia added behavioral biometrics that can tell whether mouse and keyboard events came from a person or were generated synthetically. Bureau introduced authentication that rescores risk throughout a session and steps up when someone adds a beneficiary or sends a large transfer. Recorded Partially Verified.
And Pave broke gambling activity into eleven cash flow attributes, with sweepstakes casinos, sports betting, lotteries and prediction markets each counted separately. Prediction markets now have their own column in an underwriting file, which says something about the year.
Our readSecure by default used to be a slogan. This week it was a set of release notes. That matters for how these products get sold. An optional control has to be sold to every customer and switched on by each one. A default is sold once and holds everywhere, which is why the vendors who ship them tend to spend less time in security review.
Market notes
FactSet acquired bccg, a German developer of market data distribution software, and is folding its ONE Platform into FactSet’s real time suite. It is a plumbing acquisition, and in market data the plumbing is where entitlements and cost control live.
Murex certified MX.3 on Google Cloud, its third supported hyperscaler after AWS and Azure. Bloomberg launched CLO data with loan level detail on every loan in a portfolio. Solidus Labs said its surveillance now runs on GTN’s global order book, with dedicated tenants available to GTN’s institutional clients. Recorded Partially Verified.
In banking, Glia launched an AI CRM that joins voice, digital and branch history with core banking data in one customer record, updated after every interaction, along with a Branch product for in person conversations. Jack Henry added general ledger and transaction dispute APIs to its developer documentation, and Pega shipped its card network rule updates for dispute handling.
In wealth, Marloo introduced a three layer knowledge base. Marloo maintains the regulatory layer, the firm sets its own instructions and approved wordings, and each adviser adds a personal style within those limits. SS&C added an AI portfolio management assistant to Advent Genesis, which its executives describe as in beta. Vise rolled Bitwise crypto model portfolios out to more than 135,000 accounts, managed in the same account as everything else in the household.
Elsewhere, Sardine launched Agent Routines, so fraud agents can run on a schedule and report findings ranked by severity. Feedzai launched Farol, an agent inside its RiskOps Studio with a SAR drafting skill, running inside each institution’s own environment. Elliptic launched Pulse, which gives a frontline officer a plain language risk summary for a wallet address.
TidalWave added home equity lines of credit as their own product line rather than a setting on the mortgage flow. And Socure went live as the identity and fraud layer on Arc, the blockchain built by Circle.
What the week says about the space
Seventy four entries, and one shape keeps repeating. The agent does the work, stops, shows its reasoning and waits. It turned up in insurance claims, fund marketing, compliance analytics and product configuration, from vendors that do not compete with each other.
Around that shape, the rest of the week filled in the controls. Defaults got stricter. Connectors learned to write and started proving who is writing. A handful of vendors published evidence that included their own failures.
Financial services is not adopting agents the way the rest of software is. It is adopting them the way it adopted every other risky thing, with a sign off, a sample and a record. That is slower to demo and much easier to buy.
Which financial services AI vendors publish how a person oversees their AI?
Most of them say a person is involved, and far fewer say how. Of the 551 vendors the AI FinTech Index has graded on Autonomy and Oversight Model, 76 reach the top grade. That grade means three things are published. What the system runs alone, what constrains it, and how a person checks it, down to the thresholds, the sampling controls and the route a case takes to human review.
The middle band is where this market lives. 336 vendors commit in writing that the models work alongside human judgment and show real review surfaces, then stop short of the full structure. What is usually missing is the threshold at which the system stops, or what happens after it is wrong.
The remaining 139 use human in the loop as a phrase rather than a described control. No vendor in the index is silent on the question altogether. Almost everyone says something here, which makes the gap between saying and specifying the whole story.
That is the gap this week’s log started to close. Bretton let administrators set the quality control sample for each agent. Juniper Square made every AI match a suggestion until a person accepts it. SymphonyAI described an oversight setting that runs from semi autonomous to fully autonomous. Each is a threshold or a sampling control written down, which is the exact part the middle band leaves out.
Human in the loop has been the most repeated phrase in this market for two years. The vendors that stand out now say where in the loop, how often, and what the human is allowed to overrule.
The full grading method and what separates each band are on the capability framework page.
The AI FinTech Index Brief is published by AI FinTech Index, an independent reference for evaluating AI vendors in financial services. No vendor pays for inclusion, placement, or rating. Compare any indexed vendors by capability at Compare and read the evaluation standards at Methodology.