
August gave Open Finance risk practitioners a concentrated run of stories that collectively make a single argument: the infrastructure for agentic, AI-driven finance is arriving faster than the standards designed to govern it. Here is what happened, and what the evidence actually supports.
The CFPB Rule: Where the Regulatory Floor Actually Stands
The Consumer Financial Protection Bureau (CFPB) submitted its rewritten Open Banking proposal to the White House’s Office of Information and Regulatory Affairs, the final procedural step before public release. That matters because the rule has been paused, contested, and rewritten for close to two years, while states including New York have drafted their own data rights legislation in the interim.
What the regulatory history adds to this picture: the CFPB did finalise a Section 1033 rule in October 2024, with implementation originally set to begin in April 2026, according to the Congressional Research Service. The compliance timeline was tiered: the largest bank and nonbank data providers faced that April 2026 deadline, while the smallest depository institutions covered by the rule would not have had to comply until April 2030. What the current OIRA submission represents, therefore, is a further rewrite of a rule that was technically finalised but subsequently contested. For banks that shelved API build plans during the uncertainty, an OIRA-cleared proposal removes the ambiguity over whether Section 1033 applies at all.
Alongside the rule itself, the CFPB recognised Financial Data Exchange (FDX) as the first standard-setting body under the 1033 framework, a five-year recognition running through January 2030, according to the Open Banking Tracker. That recognition matters because it begins to answer the accreditation question the rest of August kept raising.
Open Finance Risk in August: What the Data Shows
First Internet Bank began allowing customers to link account data to ChatGPT and Claude for plain-language queries on cash flow and spending. The rollout is read-only, opt-in, and revocable. What it does not answer is what happens when a second bank makes a different call on what safe AI access looks like, with no shared standard for verifying it and no consistent answer on where liability sits if access is misused.
One day later, Plaid and AI agent platform Sierra announced that an agent can request permission to connect a customer’s bank account mid-conversation and act on that data to keep a workflow moving. Plaid and Sierra have built safeguards, but safeguards are not the same as a shared accreditation standard. PYMNTS research cited in the announcement finds loan applications carry the highest concentration of “know your agent” threats. A separate, smaller integration between Plaid and Vikar Technologies illustrates the same root cause one layer further down the chain, with community banks inheriting a sub-processor’s access posture through a vendor relationship.
A ComplyAdvantage survey of 200 senior compliance leaders across the UK and France found over nine in ten confident that incoming AI regulation will manage the risks that matter most, even though the rules in question are not yet finalised. Confidence in a future rulebook is not the same as being able to show a regulator today why a specific alert was closed. The same survey found 97% of firms running two or more disconnected screening systems, which makes producing that evidence harder even when the underlying control is sound.
OpenAI disclosed it could not rule out its highest cybersecurity warning level for its next model, the threshold at which a model may independently discover and exploit real-world vulnerabilities. The IMF’s analysis makes the sharpest point for banking specifically: AI does not need new categories of attack to change the risk equation; it needs only to accelerate discovery across infrastructure banks already share. A vulnerability entering through an aggregator several steps removed remains every connected institution’s exposure.
An American Banker and Plaid study of 143 fraud decision-makers found that 85% report increased fraud risk from real-time payments, and only 15% can consistently intervene before funds move. The study’s own card-network comparison points to a second standing layer that transaction data cannot supply alone: card networks pair transaction-level defence with merchant and acquirer accreditation and defined liability rules.
Consumer lender Heights Finance is notifying more than 1.2 million people after hackers accessed a third-party, cloud-based platform the company used for customer data storage. Heights’ own loan management systems, by its own account, were never touched. The affected population extends further than any one relationship, including former borrowers inherited through a history of mergers and rebrands. A periodic compliance check confirms what was true at the last review, not what is true today, and that gap is precisely where this breach occurred.
The FDX recognition as standard-setter under Section 1033 is one concrete structural response to the accreditation questions August kept surfacing. Whether the rewritten CFPB rule, once cleared by OIRA, lands close to the October 2024 version or departs from it materially is the next question the compliance calendar will force.



