On-premise GenAI for a bank: Itexus deployed an LLM inside a security-constrained bank for document classification, PDF splitting and field extraction.
The same week Visa warned that AI agents could turn cyberattacks autonomous, three other institutions moved to tighten control over data, access, and decisions. Visa open-sourced part of its cyber defense after an AI model exposed vulnerabilities it called humbling. Chase gave customers a single place to see and revoke third-party data sharing. Bank of America pushed generative AI deeper into treasury workflows while keeping employees accountable for decisions. And Valley National agreed to buy Bluevine for $340 million to pull a fintech's deposits and data onto its own books.
As AI reaches further into financial systems, what the technology can do matters less than who controls the data it sees, the systems it can reach, and the decisions it is allowed to influence.
Visa Open-Sources Part of Its Cyber Defense and Warns of Autonomous AI Attacks
Visa's president of technology, Rajat Taneja, told Reuters the company has open-sourced part of its AI-powered cyber defense system after vulnerabilities exposed by Anthropic's Mythos model proved humbling. He pointed to the AI-agent attack on Hugging Face as an early glimpse of a more serious threat, saying the industry has "seen the trailer." Visa processes roughly a billion payments a day, worth around $15 trillion a year, and has begun allowing certain AI agents to transact on its network. Taneja argued that adaptive, self-improving attacks will defeat current human-centered defenses, and that an agentic adversary requires an agentic defense.
Source: Reuters
Why It Matters
The threat model for financial infrastructure is expanding to include the AI itself, both as attacker and as the tool that finds the holes. When a frontier model surfaces vulnerabilities in the defenses of a company that clears $15 trillion a year, security posture becomes a moving target that has to be tested with the same class of tools attackers will use, at a pace human review cannot match alone.
Open-sourcing a defense system is the unexpected move, and it signals a strategic shift. Visa is betting that shared, collectively hardened defenses beat proprietary ones against an adversary that improves continuously, because no single institution can keep up alone. For teams that already let AI agents touch payments, the same capability that enables agentic commerce widens the attack surface, so the controls around what an agent can reach and authorize become core security architecture, not a feature.
What Teams Should Do
This applies to payment companies, banks, infrastructure providers, and any product allowing AI agents to transact or access sensitive systems.
- Test your own defenses with frontier AI models before an adversary does, since human-paced security review no longer matches machine-paced probing.
- Constrain what any AI agent on your network can reach and authorize, and treat that boundary as security architecture, not a product setting.
- Instrument agent behavior for anomalies the way you monitor external threats, since an agent that transacts is part of your attack surface.
- Evaluate open or shared threat-intelligence sources against a threat that adapts faster than any single team can track alone.
- Plan for post-quantum encryption on a real timeline, since the data you protect today can be captured now and decrypted later.
Chase Gives Customers a Central Place to Control Third-Party Data Sharing
Chase began a phased rollout of a Data Security Center in its mobile app, giving customers one place to see which third-party apps are connected to their accounts, review what data is shared, adjust how long an app can access it, and unlink apps. The tool consolidates account-linking controls that were previously scattered, adds plain-language education about data sharing, and reaches Chase's roughly 87 million digital customers. Chase notes that revoking access stops new data flows at the bank connection, though customers may still need to contact a third party about data it already holds.
Source: Business Wire
Why It Matters
The bank is positioning itself as the control point for consumer financial data, which reshapes the terms for every fintech that relies on account connections. When a customer can see and revoke a data connection in one tap inside the bank's app, continuous access to bank data stops being a background assumption and becomes something a customer actively grants and can pull back.
That raises the operational stakes for any product built on aggregated bank data. A revoked connection can break a budgeting view, an income verification, or a lending decision that assumed a live feed, so products need to detect a withdrawn permission and degrade gracefully rather than fail silently. It also sharpens the value of minimizing what you pull: a product that requests only the data it needs can give customers less reason to question the connection.
What Teams Should Do
This applies to data aggregators, budgeting and PFM apps, lenders using cash-flow data, and any product built on connected bank accounts.
- Detect a revoked data connection and degrade the affected feature gracefully, so a withdrawn permission does not corrupt a balance, a decision, or a report.
- Minimize the data scopes you request to what a feature actually needs, since a lighter footprint gives customers less reason to disconnect you.
- Re-request access transparently when a connection drops, explaining what breaks without it rather than failing silently.
- Reduce reliance on a single aggregation connection for critical decisions, so one revoked link does not take down underwriting or verification.
- Show customers the value of the connection inside your own product, so the choice they now control in the bank app stays in your favor.
Bank of America Expands Its Treasury AI While Keeping Employees Accountable for Decisions
Bank of America launched AskGPS Intelligence Hub, expanding the generative AI application it introduced in 2025 for Global Payments Solutions employees, which supports nearly 3,000 staff. New capabilities unite client, account, and relationship data to produce Intelligent Treasury Management Reviews, digital account schematics, and enhanced relationship insights, rolling out in phases. Separately, the bank added AI-powered Payments Insights to its CashPro platform, which processed 213 million payments in the first half of 2026. Bank of America states employees retain responsibility for decisions and client interactions, and that the tools operate under its Responsible AI framework.
Source: Bank of America
Why It Matters
The design pattern here is AI as a data-synthesis layer for employees, with the human explicitly kept as the decision-maker. Rather than automating treasury decisions, the tool assembles fragmented client, account, and relationship data into a briefing an employee acts on, which places the value in unifying proprietary data the bank already holds. The competitive edge is the connected data model underneath, not the model itself.
Keeping employees accountable is a governance choice with a practical catch: it only holds if the boundary is enforced in the workflow. Positioning AI as an insight tool rather than a decision engine can reduce some of the governance complexity that comes with automated decisioning, but the requirement is traceability. Recording which data fed a given insight and who acted on it is what lets a recommendation that shaped a client action be reconstructed under review.
What Teams Should Do
This applies to banks, treasury and B2B fintech platforms, and any product using AI to synthesize data for employees who make client-facing decisions.
- Unify the fragmented data an AI tool draws on (client, account, relationship), since the quality of the synthesis depends on the connected model beneath it.
- Enforce the line between AI insight and human decision in the workflow, so an advisory output cannot quietly become an unreviewed decision.
- Record which data and model version produced each insight, so an employee's action based on it can be reconstructed and audited.
- Measure the time saved and the accuracy of AI-assembled briefings, so adoption rests on verified quality rather than perceived speed.
- Stage the rollout by capability and enforce access controls, so employees only see the client data their role permits inside the AI layer.
Valley National Buys Bluevine for $340M to Bring Its Deposits and Data In-House
Valley National Bancorp agreed to acquire Bluevine, a digital small-business banking platform, for approximately $340 million in cash and stock, with the deal expected to close in early 2027. Bluevine brings about 175,000 active small-business customers, $2.1 billion in low-cost, digitally sourced deposits, and roughly 180 engineering, product, and data professionals. Valley plans to onboard Bluevine's deposits after terminating Bluevine's current partner-banking relationship within three to six months of close. Bluevine's co-founder and CEO will join Valley as head of small-business banking. Valley framed the deal as accelerating its digital and AI capabilities.
Source: Banking Dive
Why It Matters
A regional bank is buying its way out of building a digital small-business platform, and the deal structure reveals what it is really acquiring: deposits, an engineering team, and a modern tech stack. The plan to move the deposits off Bluevine's partner bank and onto Valley's own charter removes the sponsor-bank arrangement that let Bluevine operate without a charter of its own. Ownership replaces that relationship.
The integration is where the value is won or lost. Migrating 175,000 customers and $2.1 billion in deposits off a partner-bank arrangement onto Valley's core within months is a reconciliation and data-migration project, and account mappings, transaction history, and live balances all have to move without breaking a customer's access. The acquired engineering culture, described as AI-native, only compounds if Valley's core and risk systems can absorb it rather than force it back into legacy constraints.
What Teams Should Do
This applies to regional banks, BaaS providers, fintechs on sponsor-bank arrangements, and any team planning a deposit or platform migration.
- Plan a deposit migration off a partner bank as a reconciliation project, mapping accounts, balances, and history before moving a single customer.
- Preserve transaction history and account continuity through the migration, so a customer's records and access survive the move to a new core.
- Define which platform becomes canonical for each function, so the acquired stack and the legacy core do not run as two conflicting systems.
- Protect the acquired engineering practices from legacy constraints, since the modern stack loses value if forced back into slower release cycles.
- Model the funding economics of insourced deposits, since moving deposits onto your charter changes capital treatment and the cost of that funding.
Closing Insight
Look at where your product depends on data or access you do not fully control: a bank connection a customer can revoke, an AI agent acting on external rails, or deposits sitting on another institution's infrastructure. Then ask three questions: Can you detect when that access changes? Can you reconstruct what happened? Can the product keep operating safely?
Those boundaries are becoming part of the architecture itself. In our work with fintech teams at Itexus, we help design the data flows, permissions, audit trails, and migration paths that keep products working when those boundaries move.