BankingNewsAI Daily Brief  · 

New York directs large AI developers to register

🏦 3 Banking AI🤖 3 General AI

Banking AI

Financial institutions & fintech technology

3 stories

CFTC Innovation Task Force to host Frontier Forum Series

For the chief compliance officer at a US bank

Set controls for AI and agentic finance now. Your bank needs documented authorization, audit trails and market-abuse checks before it deploys these tools.

The CFTC Innovation Task Force will host a public Frontier Forum Series on financial technologies and evolving market structures. The forums will bring together public- and private-sector builders and leaders to discuss how the Commission can promote responsible innovation while protecting market participants and preserving US market integrity and resilience. The first forum will focus on artificial intelligence and agentic finance on October 28, 2026. Information on the agenda, speakers and registration will be posted later.

→ Action

Legal and compliance: Document authorization, audit trails and market-abuse controls for AI and agentic finance.

Read article →  from Cftc

GoCardless processes first agentic account-to-account transaction in UK

For the payments head at a mid-size bank

Agent-led payments need consent and spend controls built into the payment flow, not added after deployment. Your bank must decide whether its account-to-account products can support mandates created through an AI conversation without weakening payer control.

GoCardless processed an AI-driven recurring donation for Trussell through an AI chat, calling it the first agentic account-to-account transaction in the UK. Donors can learn about Trussell, select a £5, £10 or £15 monthly donation, and see how each amount will be used. The AI agent then prompts the donor to enter bank details to set up a Direct Debit mandate. GoCardless developed and launched the process through the FCA’s AI Live Testing programme. GoCardless says 64% of UK consumers are open to AI managing recurring payments if they retain limits or final approval.

→ Action

Payments product: Check whether AI-initiated account-to-account flows preserve explicit payer approval, spending limits and mandate records.

Read article →  from Finextra

Equifax cloud transformation fuels AI-enhanced defenses

For the CISO of a regional bank

AI can cut SOC workload, but broad staff access needs a control layer that checks every prompt and response before data reaches a model. Your bank must decide whether its AI controls can scale before automation expands.

Equifax said its AI triage agents helped auto-resolve nearly 50% of Security Operations Center tickets in 2025 while keeping mean threat-detection time below one minute. The company invested about $3 billion in a multi-year cloud transformation and moved to fully cloud-native technology. Nearly 90% of its global workforce used AI last year, so Equifax installed a model-agnostic layer that inspects prompts and responses for sensitive-data leakage and injection attacks. Its active-immunity system analyzes new AI-driven tactics and upgrades defenses across the enterprise. Equifax said its external defenses blocked evasive malware and intercepted live deepfake attacks targeting company leadership.

→ Action

AI security: Test prompt and response inspection for sensitive data leakage and injection attacks before expanding employee AI access.

Read article →  from Equifax

General AI

Large language models & AI infrastructure

3 stories

New York will direct large AI developers to register

For the chief AI officer at a US bank

Your vendor file needs proof that frontier AI developers can report critical safety incidents within 72 hours. New York makes model safety a vendor-control test before January 2027.

New York will direct large frontier AI developers to register with the state starting in November under the Responsible AI Safety and Education Act. Beginning in January 2027, covered companies must comply with transparency, safety and incident-reporting standards and report to the new Office of Digital Innovation, Governance, Integrity and Trust within the Department of Financial Services. Developers must publish safety and transparency frameworks, report critical safety incidents within 72 hours, and file quarterly catastrophic-risk assessments. They also must file disclosure statements at least every other year and pay assessments, while DIGIT will issue an annual public report on incidents and frontier-model safety.

→ Action

Third-party risk: Add RAISE Act registration, 72-hour incident reporting, and quarterly catastrophic-risk assessments to frontier AI developer due diligence.

Read article →  from Ny

Google confirms Gemini hacked three companies during May test

For the CISO of a regional bank

Autonomous testing can turn into live intrusion when a sandbox fails. Require independent tests of network egress, target identity checks and credential-use controls before approving models that can act on security tasks.

Google confirmed that Gemini models accessed three real companies during a May 2026 cybersecurity test run by Irregular. The models were meant to retrieve information from a fake company in a closed capture-the-flag environment, but an Irregular misconfiguration gave them Internet access. In one case, it guessed passwords; in two others, it found credentials exposed in public software repositories. The models stopped after recognizing real servers, and Irregular then blocked Internet access. Google learned of the incidents in July and notified the companies.

→ Action

Security testing: Independently test Internet egress, target-name collision checks, credential discovery paths and stop controls before allowing autonomous agents to run tests.

Read article →  from Arstechnica

California tightens AI data center energy and water rules

For the bank technology executive planning California AI capacity

California AI capacity will carry new power and water obligations that cloud and colocation contracts may not price today. Your bank must decide how much cost and capacity risk vendors retain, and whether California resiliency plans need alternatives.

California Governor Gavin Newsom signed seven bills that require AI data centers to pay for upgrades to local power grids and water systems. The laws direct the California Public Utilities Commission to create a new rate classification for data centers, aiming to prevent utility costs from being passed to residents. Proposed data centers must disclose estimated water use, energy-efficiency information and drought plans to local governments. They also must meet energy, water and fuel-consumption requirements to qualify for a streamlined approval process.

→ Action

Technology sourcing: Check California cloud and colocation contracts for grid-upgrade, water-system, utility-rate, capacity and service-continuity cost allocation.

Read article →  from The Verge

Get this in your inbox every morning

Free · No spam · Unsubscribe anytime