Fiserv
Fiserv is one of the two companies whose software most United States banks actually run on, and this record grades the artificial intelligence line it has built on top of that position. The estate spans account processing and digital banking, card issuer processing and network services, payments, electronic commerce, merchant acquiring and processing, and the Clover point of sale and business management platform. The banking segment alone reports 2.4 billion dollars of revenue across more than 3,500 financial institutions, digital payments runs just under 4 billion dollars and serves 41 of the 50 largest United States banks, and the financial solutions side reports more than 6,000 clients globally.
The artificial intelligence line is agentOS, launched 14 May 2026 as an operating system for agentic artificial intelligence in banking and stated as widely available from August 2026. It runs natively across the company's own core, payments, issuer processing and servicing platforms rather than beside them, which is the point of it: an institution already running Fiserv systems can deploy agents into those workflows without a separate integration. Six financial institutions co developed it and two were running agents in beta at launch. Strategic collaborations with OpenAI and Amazon Web Services are named openly.
Its distinguishing feature is a marketplace. Institutions can run agents Fiserv built, build their own, or deploy agents from third parties, all inside the same governance, identity and audit controls. Four first party agents launched, covering commercial loan onboarding, daily operational analysis and reporting, deposit intelligence and anti money laundering triage, alongside nine third party agents spanning risk management, regulatory reporting, deposit operations and back office reconciliation.
The company is candid about a difficult period. Executives have publicly attributed higher than desired core banking attrition to past service failures, missed product deadlines and forced conversions, with a co president stating the company has a service problem rather than a technology problem, and have committed to supporting all cores with no forced migrations. Fiserv is listed on Nasdaq and is a member of the S&P 500.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
The vendor's own description of its agentic platform settles this. agentOS is stated to integrate directly with existing platforms and to extend the value of a bank's current technology investments, which is the language of a layer added on top rather than a foundation.
Remove the models and what remains is the company: account processing for more than 3,500 financial institutions, card issuer processing, network services, merchant acquiring, electronic commerce and a point of sale platform, none of which is learned and all of which predates the agents by decades. The agentic line launched in May 2026 into an estate that was already processing the majority of United States banking transactions. Two further points confirm the reading.
The four first party agents address workflows around the core rather than the core itself, covering loan onboarding, operational reporting, deposit intelligence and financial crime triage. And a substantial part of the company's publicly discussed artificial intelligence effort is internal engineering efficiency, with executives citing the share of engineers using it daily and the share of code it writes, which is how the company builds rather than what it sells.
Strong controls, and a structural accountability question the marketplace creates and the public record does not answer. Human oversight is stated as embedded in the design alongside policy controls and auditability, escalation paths exist, and platform level kill switches provide a hard stop, which together describe a genuinely governed environment for agents acting inside banking workflows.
What is unresolved is who is answerable for the agent itself. agentOS is explicitly an operating system for agents Fiserv did not necessarily build: an institution may run first party agents, build its own, or deploy any of nine third party agents, all inside the same controls. Nothing published describes what assessment a third party agent passes before listing, what behavioural standards bind it, or where responsibility sits when a partner built agent errs inside Fiserv's guardrails.
The exposure is not hypothetical given what the first party agents already do, since one performs anti money laundering triage and another handles commercial loan onboarding, both of which produce consequences for a customer who never sees the agent.
A claim of proof with no proof attached. The launch states that pilots are already proving the platform works and delivering measurable gains today, and across two passes no measurement of any kind was located: no accuracy figure, no error rate, no time or cost saving, no baseline, no sample, no observation period, and none of the six co developing institutions is named so a reader cannot pursue it independently.
The figures the company does publish about artificial intelligence describe its own engineering organisation rather than the product, covering the proportion of engineers using it daily and the share of code it writes, which speaks to internal adoption and says nothing about how the agents perform in a bank. The gap matters more here than at most vendors because of the deployment position.
Institutions putting agents into anti money laundering triage and commercial loan onboarding owe their supervisors documented model validation, ongoing monitoring and performance evidence, and none of the material a bank would need for that file is public.
Enormous verifiable scale for the company, almost none of it attached to the product this record grades. The scale is real and checkable through public filings rather than asserted in marketing: more than 6,000 financial institution clients globally, a banking segment reporting 2.4 billion dollars of revenue across more than 3,500 institutions, a digital payments business just under 4 billion dollars serving 41 of the 50 largest United States banks, membership of the S&P 500 and quarterly reporting obligations.
A named core banking relationship with a large United States bank was announced in August 2026. For the agentic platform the evidence is thinner and earlier stage: six co developing institutions, none named, two running agents in beta at launch, and a claim that pilots are delivering measurable gains today with no measurement published anywhere.
Something unusual belongs on this record and counts in the company's favour on candour rather than performance: its own executives have stated publicly that core banking attrition ran higher than desired because of service failures, missed product deadlines and forced conversions, and that the company has a service problem rather than a technology problem.
Four platform level controls named specifically, including one most vendors in this index do not offer at all. The published set covers deterministic guardrails with policy enforcement and access controls built into the platform, complete auditability so that every agent action leaves a traceable record, real time observability with anomaly detection, escalation paths and platform level kill switches, and identity bound access with role based permissions and data masking at the infrastructure layer.
The kill switch is the item worth drawing out: a documented ability to stop agents at the platform level is a containment control rather than a monitoring one, and it is the difference between detecting that an agent has gone wrong and being able to halt it.
The company's chief product officer for financial solutions states the underlying principle plainly, that agentic artificial intelligence only works when it operates within defined boundaries, and the platform is described as governance by design with identity bound execution, policy enforcement, observability and traceability. Absent across two passes: model card, evaluation methodology, red team result, incident disclosure and any statement on what client data trains or contextualises the agents.
A thin public surface beneath one of the heaviest data burdens in this index. This company processes deposit accounts for more than 3,500 financial institutions, issues and processes cards, and acquires merchant transactions, which places the financial records of a very large share of the United States population inside its systems.
Across two passes no privacy programme description, data processing disclosure, retention schedule or subprocessor list was located, and the Gramm Leach Bliley Act appears nowhere on the surfaces examined despite the company being a service provider to the institutions that statute governs.
What the agentic material does address, and it is relevant, is data handling at the agent layer: identity bound access with role based permissions and data masking at the infrastructure level are named as platform controls, which speaks to what an agent may see rather than what the company holds.
Independent commentary on the platform advises prospective buyers to verify client data ownership statements and masking rules for agent actions that cross platforms, which indicates those questions are open rather than answered publicly.
A disclosure gap standing in front of controls that certainly exist. Across two passes no trust centre, named certification, attestation report, penetration test summary or subprocessor list was located on the public surface. The controls behind that silence are not in doubt: a company acquiring merchant card transactions at scale operates under the payment card industry standard as a condition of doing business at all, a processor running deposit systems for thousands of banks is examined by those banks and by their supervisors as a service provider, and a listed registrant carries internal control obligations under securities law.
What is missing is the ability of anyone outside a procurement process to establish any of it. The agentic platform is the exception that proves the point: its security posture is described in real detail, covering identity bound execution, policy enforcement, observability, traceability, role based permissions, data masking and kill switches, so the company clearly can publish specifics when it chooses to.
A technology supplier to regulated institutions, correctly claiming no authorisation of its own, with public company obligations standing in for the regulatory record. As a listed registrant the company files quarterly and annual reports including risk factor disclosure, which is a form of mandatory public accountability no private vendor in this index carries, and it is subject to securities regulation accordingly.
That is real but it is corporate rather than financial services regulation, and the two should not be conflated. On the banking side the agentic platform is described as built for regulated banking, and the four named controls map recognisably onto what examiners ask for, but a design intention is not a supervisory outcome.
Across two passes nothing published was located on the company's own regulatory examinations as a bank service provider, on any position under the European artificial intelligence regulation despite deploying agents into regulated workflows, or on how the agents are positioned against model risk management expectations that institutions deploying them must satisfy to their own supervisors.
The governance published here is procedural rather than substantive, and the distinction decides the grade. Everything the company describes answers questions about permission and record: who the agent is, what it was allowed to do, whether the action was logged, whether it can be stopped. Those are real and well specified. None of them answers whether the agent treats people evenly. That question is live because of what the first party agents do.
Commercial loan onboarding sits inside a credit process, where an agent shaping who progresses raises fair lending and adverse action questions directly, and anti money laundering triage decides which customers are escalated for investigation, a determination with well documented uneven effects across geography and name origin. Deposit intelligence shapes treatment of account holders.
Across two passes no fairness testing, differential performance analysis, model card, bias statement or artificial intelligence regulation position was located for any agent, first or third party, and nothing describes what a customer affected by an agent decision is told.
No commercial instrument is published, and the marketplace introduces an allocation question the industry has not answered anywhere. Across two passes no terms of service, warranty, indemnity, liability cap or published service level was located, and nothing addresses what an institution is owed when an agent is wrong. The novel exposure is three sided. When a bank runs a first party agent, responsibility plausibly sits with the vendor.
When it builds its own on the platform, plausibly with the bank. When it deploys one of nine third party agents inside Fiserv's guardrails, using Fiserv's identity and audit controls, on Fiserv's core, and that agent wrongly triages an anti money laundering case or mishandles a loan onboarding, the public record does not indicate whether the builder, the platform or the institution carries it.
Auditability means the failure can be reconstructed afterwards, which is valuable and is not the same as knowing in advance who pays. Nothing published describes what a customer affected by an agent decision is told or how they contest it.
Named suppliers, which is rare enough in this index to be the distinguishing feature of this record. The agentic platform is stated to rest on strategic collaborations with a named frontier model provider and a named hyperscaler, and the company separately names a third party coding agent used to accelerate its own core modernisation engineering.
Naming the model provider lets a buyer assess that provider's own terms, data handling and model behaviour directly rather than inheriting an undisclosed dependency, and only one other vendor in this lane does the same. The marketplace adds a second layer of disclosure by making the third party agent estate explicit rather than presenting a blended platform as wholly proprietary. Two limits keep this out of the top band.
No model family or version is named, and nothing states which agents use which provider, so a buyer cannot map a specific workflow to a specific model. And nothing describes what governs the model dependencies of the nine third party agents, which sit inside Fiserv's controls but not necessarily inside Fiserv's supply chain.
This vendor is the core system for thousands of institutions, which makes integration depth a different proposition here than anywhere else in this index. agentOS is stated to run natively across the company's own core, payments, issuer processing and servicing platforms, so an institution already on Fiserv deploys agents into its systems of record without building an integration at all, and the company frames this explicitly as extending existing technology investments rather than requiring new ones.
The marketplace extends that reach outward: institutions can run first party agents, build their own, or deploy any of nine third party agents, all inside one governance, identity and audit layer, which makes the platform a distribution channel for other vendors rather than only a product. Strategic collaborations with a frontier model provider and a hyperscaler are named.
Two published commitments matter for institutions not already committed: support for all cores rather than a favoured one, and modular core agnostic capabilities adoptable on the client's own timeline, both introduced after the company acknowledged that forced conversions had damaged client relationships.
Not addressed publicly, in a company where the question has unusual reach. Across two passes nothing published states the hosting regions available for the agentic platform, whether data residency can be pinned, what the tenancy arrangement is, or how processing is separated between institutions sharing the same underlying core infrastructure. A hyperscaler collaboration is named as supporting the platform, which indicates public cloud is involved without describing the arrangement.
The reach point is specific to this vendor's position: because agentOS runs natively across core, payments, issuer processing and servicing, agent activity necessarily touches systems of record that hold customer account data for thousands of institutions, and cross platform agent actions therefore raise placement questions that a standalone application would not.
Independent commentary on the platform advises prospective buyers to inventory data residency and verify client data ownership statements and masking rules for exactly that reason, which indicates the question is open to the market rather than settled publicly.
No product pricing is published, and two passes produced no price, unit or tier for the agentic platform, the core, payments or issuing lines. The marketplace structure makes the omission more consequential than usual, because a buyer cannot tell whether agentOS carries a platform fee, whether first party agents are charged per agent or per workflow, whether third party agents are billed by Fiserv or by their builders, or whether any revenue share applies, and those are the first commercial questions a marketplace raises.
What partly offsets this is a form of transparency no private vendor in this index can match. As a listed company Fiserv publishes quarterly results, segment revenue, client counts and risk factors under securities law, so a buyer can establish the size, growth and profitability of the exact business unit selling to them, which is more financial disclosure than most vendors here provide at any level. Two published commitments also bear on cost: support for all cores and no forced core migrations, which removes a category of forced spend clients had previously experienced.
The widest institutional footprint in this index, and it reaches the segments most vendors here never address. More than 6,000 financial institution clients globally, over 3,500 in the banking segment alone, and 41 of the 50 largest United States banks on the payments side, which spans from the largest institutions in the country down through regional banks, community banks and credit unions, a tier that most vendors in this index address with a marketing page if at all.
Coverage extends across both sides of a transaction rather than one: account processing and digital banking for the institution, card issuer processing and network services for the issuing side, and merchant acquiring, electronic commerce and point of sale for the accepting side. The agentic platform inherits that reach by design, running natively across core, payments, issuer processing and servicing.
Two published commitments make the coverage meaningful for smaller buyers specifically, namely support for all cores rather than a favoured one, and modular core agnostic capabilities adoptable on the client's own timeline.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No price, unit of billing, tier or contract term appears on any vendor surface for the agentic platform or the underlying processing lines
|
Not published on any vendor surface. The estate spans account processing, digital banking, card issuer processing, network services, payments, electronic commerce, merchant acquiring and a point of sale platform, and nothing published indicates the commercial basis for any of them or how the agentic platform is charged. The marketplace structure leaves the central question open: whether agentOS carries a platform fee, whether first party agents are licensed individually, by workflow or by volume, whether third party agents are billed by the platform or by their builders, and whether any revenue share applies between them. As a listed company Fiserv does publish segment level revenue and client counts under securities law, which gives a buyer scale and unit economics at the business level without giving a price. | No tiered data protection terms are published. Data handling commitments appear only at the agent layer, where identity bound access with role based permissions and data masking at the infrastructure level are named as platform controls governing what an agent may see. Nothing published describes the company's own data processing terms, retention, subprocessors or residency for the underlying core, payments, issuing or acquiring platforms. Independent commentary on the agentic platform advises buyers to verify client data ownership statements and masking rules for agent actions that cross platforms, which indicates those terms are negotiated rather than published. | No implementation, conversion or professional services fee is published. Implementation cost is nonetheless the subject this company has addressed most directly in public, for reasons that were not favourable to it: executives have acknowledged that forced core conversions and missed product deadlines drove client attrition, and the corrective commitments are stated as support for all cores rather than a favoured one, no forced core migrations, and modular core agnostic capabilities clients adopt on their own timeline. Those commitments are about avoided cost and avoided disruption rather than about price, and they are unusually concrete because they were made in response to a named failure. For the agentic platform specifically, the integration burden is designed to be near zero for existing clients, since it runs natively across core, payments, issuer processing and servicing, and the marketplace is presented as the route to deployment. Nothing published describes onboarding effort, professional services requirements or timelines for either path. | Vendor Published |
Two passes across the company's site, its investor materials, its product announcements and the trade coverage produced no price, unit or tier for any line, including the agentic platform. Two things distinguish this from ordinary enterprise silence.
The first is that securities law supplies a substitute for part of it: quarterly and annual filings disclose segment revenue, client counts, growth and risk factors, so a buyer can size the business unit selling to them and read management's own account of its difficulties, which no private vendor in this index offers. The second is that the marketplace makes the pricing silence structurally more awkward.
A marketplace has at least three commercial relationships in it, between the institution and the platform, the institution and the agent builder, and the platform and the agent builder, and none of them is described. A buyer evaluating whether to build an agent, buy a first party one or take a partner's cannot compare those paths on cost using anything published.