| |||||||||
| |||||||||
| | |||||||||
Happy Friday, Fintech Takers! Wow, what a fun week in Toronto. Between our fintech co-working day, after hours panel and dinner, and the FDATA Global Summit (Open banking! My favorite topic!), I learned A TON. The plan for today’s newsletter is simply to pass along what I learned, in its raw, unstructured form. My apologies if the topics feel a bit jumbled. We covered a lot of ground north of the border! - Alex P.S. — I have an event coming up, which I’d like to tell you more about. Scroll to the bottom of today’s newsletter for the details! Was this email forwarded to you? Sponsored by Lithic Lithic puts two decisions inside one authorization path: whether a transaction needs extra verification, and whether to approve it. Mercury used to run those as separate systems; 3D Secure in one, and the approve-or-decline decision in another. And when a transaction needs extra verification, the cardholder completes it inside the Mercury app and returns to checkout. Fintech NorthAllow me to start with an apology, which has two parts. Narrowly, I would like to apologize to my Canadian friends for the occasional jokes that I have made in this newsletter about the slowness of your country’s move toward a regulated open banking system. I think they were fair, at the time. Open banking regulations in Canada were moving very slowly, with deadlines continually pushed back. And, as an American, I was feeling a bit smug because we were moving fast towards (what I thought) would be final rules for implementing Dodd-Frank Section 1033. Of course, my smugness was short-lived. U.S. open banking regulation got run off the road and stuck in the ditch (which we may never get out of) and regulatory movement on open banking regulation (bolstered by new legislation!) has accelerated in Canada. It turns out that the fable of the tortoise and the hare is very instructive! More broadly, I would also like to apologize to my Canadian friends for the way that my country has treated your country over the last two years. Everyone I know thinks that the fight that the President has picked with Canada is bizarre and unnecessary. It’s not something that anyone here wanted or asked for. However, living in the U.S., I didn’t fully appreciate how much of an impact it has had on Canada’s economy, politics, and culture. It’s a huge deal up there and it has, from what I have been able to discern, motivated some major changes to the country’s domestic and international policy priorities. Some of those changes may end up, over the long run, being beneficial. But still, I’m sorry for it. You don’t deserve it.
Now, with that out of the way, allow me to share what I’ve learned this week! Scale Shapes PolicyI think I already knew this, but it became clearer to me after discussing the differences of the U.S. and Canadian open banking ecosystems (listen to the most recent episode of Bank Nerd Corner, recorded live from Toronto, to hear this discussion!) In the U.S., hundreds of fintech companies scraping banks’ data using credentials supplied by the banks’ customers constituted an emergency. The scale of the problem made the need to stand up APIs and bilateral agreements with the data aggregators urgent. However, that same scale has made the transition to a fully regulated open banking system in the U.S. hard. When hundreds of companies want to use your data to steal away your customers, you’re going to fight harder against regulations that formalize a system that enables and encourages that behavior (especially if you are being forced to stand up such a system for free … not getting paid to do something is galling to many bankers). In Canada, it’s the reverse; not much scraping (so less urgency to stand up APIs and bilateral agreements), but also far fewer fintech companies gunning for incumbents’ customers (so less of an allergic reaction to formal open banking rules). The lesson that I take away from this is that you can’t just pick up one country’s playbook for open banking and drop it onto another country. You have to account for the size, scale, and composition of the market. This also explains why Canada can do things that we can't do in the U.S., like a real accreditation regime and a central registry of participants. In a smaller market with fewer players, accreditation and a registry are achievable. In the US, with our sprawling fintech ecosystem (and a much larger number of banks), that's just not something our regulators have been willing to bite off. Pick TwoIn open banking policymaking (and perhaps in policymaking, more generally), you want three things: A system that works exactly the way you want it to, a system that develops fast, and a system where the industry participants are bought in and feel a sense of ownership. You can only have two. The UK chose exactly-what-they-want and fast. They used a heavy regulatory hand to get a highly prescriptive open banking system implemented, without much patience for industry consensus. In Canada, they also chose exactly-what-they-want, but they prioritized industry consensus and buy-in. That’s one of the reasons it has taken so long. In U.S. financial services policymaking — absent an acute crisis (and sometimes even during a crisis) — we always choose fast and industry-led. That’s why we’ve had a robust open banking ecosystem (including an effective industry-led standard setting organization) for years, but have failed (even with a mandate from Congress) to impose a stable set of rules for how it should work. There’s an Advantage to Going LastCanada’s slowness, when it comes to policymaking, has some advantages. A big one is that it allows them to learn from other countries. On open banking, they watched the UK over-index on speed and prescriptiveness, watched Australia's one-size-fits-all accreditation choke smaller players, and watched the U.S. finalize a rule and get sued into paralysis. Using those observations, they have been able to craft legislation (Wow, passing new laws! What a novel concept!) and rules to try to proactively correct for some of those mistakes. (Steve Boms, Dan Murphy, and I talked a little bit about this during this episode of the Fintech Takes podcast, if you’re curious to learn more.) It’s a similar story when it comes to crypto and stablecoins. From what I understand, there was real disappointment in Canada when the Clarity Act failed to advance through the U.S. Senate. It, and the implementing rules that would have followed it, would have been a useful framework for Canadian policymakers (who are very active on crypto and stablecoins) to learn from and adapt. The Liability Follows the DataNow, all of this isn’t to say that Canada has nailed everything when it comes to open banking. The rules aren’t finalized and operational yet (though I have high confidence that they will be) and there are some specific areas where they may run into challenges. One is liability. I remember asking Rohit Chopra, when he was running the CFPB, why the bureau did not articulate a clear principle for liability in the open banking rule. His response was essentially that the market would figure it out and that was a better approach than the government trying to define it. Canada is taking a different approach, writing a clear principle into the framework: Liability travels with the data, and the responsibility sits with whoever was holding the data when it broke. This principle makes a lot of sense, in theory. In practice, the concern is that there will be so many nuances and edge cases where that principle becomes muddier than you might expect. Canadian regulators are trying to think through those nuances and edge cases and provide proactive guidance on them. And they say that they will not be the arbiters of individual disputes between market participants on liability, but … I don’t know. I tell my kids the same thing, but I usually end up refereeing all the little fights they get into with each other. Even though I have told them, many times, that the liability follows the data! Write Access Needs a SolutionHere’s one of my favorite quotes I heard this week: “Read access is about mitigating information asymmetry. Write access is about mitigating friction and inertia." In other words, an open banking system that allows consumers to share information with third parties can reduce information asymmetry (which is very important!), but a system that empowers third parties to take action on a consumer’s behalf solves for a much more important problem in consumer finance: inertia. Canada has committed to tackling write access as part of its consumer-driven banking work. A second phase targeted for mid-2027, once its new real-time payments system is up and running. As Dan Murphy, Steve Boms and I discussed on this podcast, that would put Canada meaningfully ahead of everyone else; most regimes stop at read. And the timing is excellent. Discussions about write access in open banking are happening at the same time that agentic AI is making the idea of “taking action, autonomously, on a consumer's behalf” feel like science fact, rather than science fiction. The States Are Stepping InMeanwhile, in the U.S., as federal action on open banking continues to stall, the states are stepping in. New York already has open banking legislation in motion, and it's deliberately broader than the CFPB's 1033 rule: It covers small-business data, not just consumer accounts, reaches any institution serving even a single New York resident, and bans data-access fees. And it has real teeth behind it: A maximum penalty of $10,000 per violation, enforced by the Superintendent of Financial Services. From what I understand, other states are watching New York and, in some cases, working on similar legislation. If this is the direction that open banking policy goes in the U.S., it’s going to create some interesting problems. Outside of interest-rate exportation, we don't have clean preemption rules for federal law in financial services. The CFPB's forthcoming open banking rule rewrite is expected to let banks charge fees for data access after some number of free requests; New York's bill bans them outright. If both take effect, which one governs a national bank serving a customer in Buffalo? I don’t think anyone knows the answer, which is great for lawyers and awful for the rest of us. Your UI Is a (Bad) APII want to circle back to agentic AI because it was a HUGE point emphasis for all the open banking nerds I spoke with this week. A lot of the discussion revolved around Amazon’s lawsuit against Perplexity. In August, the Ninth Circuit vacated an injunction that had blocked Perplexity's Comet agent from shopping on Amazon, reasoning that when a user tasks the agent, it's the user — not Perplexity — who "accessed" Amazon's computers. The agent is "a tool, not a person" for purposes of the Computer Fraud and Abuse Act (which is the law that Amazon is arguing Perplexity violated). Translation: If the software is acting on the customer's orders, it’s the customer. It's not hacking. This is, functionally, a green light for agentic screen scraping. The AI drives a browser using the customer's own authenticated credentials, it looks exactly like the customer, and a court has now said it is the customer. You may not be able to block it on "unauthorized access" grounds, because there's nothing unauthorized about it. This is the exact fight that banks have been fighting forever — screen scraping versus sanctioned access — just with an AI agent sitting in for the human. The ‘A’ in API Will Stand for AccountabilitySo, if the courts just blessed agentic screen scraping, why would any fintech developer in 2026 bother routing through Plaid or even directly through a bank's API or MCP server? Why not build the agentic capability straight into the center of your app and scrape whatever you need? The answer is accountability. When a customer connects through the sanctioned API or MCP and something goes wrong, they’re covered. There's a number to call. There's a dashboard showing what happened to the data. There's a counterparty who is answerable. Today, banks treat their APIs as the default, the thing the market has to use, not a service they have to earn. AI disrupts this status quo. The moment screen scraping is a low-cost, legal(ish) alternative, the sanctioned connection has to compete on quality: Better reliability, better observability, better recourse when an AI agent does something dumb. The banks that build the most accountable, best-instrumented connection will pull developers toward it voluntarily. The ones who keep treating API access as a grudging compliance checkbox will watch AI agents route around them. Instinctual TerrorThe company that scared pretty much everyone I spoke with this week is Instinct; the invite-only personal AI assistant that is reportedly working on raising $1B at a $10B valuation, despite being less than a year old and only having 100,000 users. I’m one of those 100,000 users and, I have to say, the product is pretty slick. It connects to your email, messages, calendar, screen, and location and then goes and does things for you. It feels a bit like magic … and it terrifies every risk and compliance person who looks at it. One of the reasons it terrifies them is the data retention. Testers found that disconnecting an account didn't delete the data already indexed from it, and, in one now-famous incident, it sent a user an email summary three hours after she'd revoked its access to her Google account. That's the exact nightmare open banking's consent-and-accreditation machinery was built to prevent, but the fear is that Instinct (and its well-funded peers in the B2C agentic AI space) will get too far down the road before that machinery can be extended to govern what they’ve built. Frontier Models Out-Negotiate Less Powerful ModelsAnother interesting thing I learned this week (and another reason to worry): The sophistication of the AI model that you use plays a large role in the financial outcomes that AI agents utilizing those models can deliver. Anthropic's "Project Deal" experiment had employee AI agents autonomously buy, sell, and haggle over real goods, and the more capable model (Opus 4.5) consistently secured better prices and closed more deals than the smaller model (Haiku 4.5), while aggressive-negotiation instructions made no statistically significant difference. Prompt tricks didn't move the needle. Model quality did. And, most interestingly, the humans using the weaker model getting the objectively worse deals rated the fairness of their transactions just as highly. The disadvantage was invisible to them. Now, imagine a world where more of our financial negotiations — insurance renewals, rate shopping, bill lowering, maybe eventually salaries — are run through model proxies. What happens when my non-frontier model sits across the table from your frontier one? It’ll be like showing up with a public defender against someone who hired an expensive lawyer, except I won’t even know I’m outgunned. A New Merchant Concern About Agentic CommerceI'm accustomed to the standard merchant complaint about agentic commerce; "we don't want to be disintermediated from our customers and forced to buy ads to reach them." But I heard a new one during this trip. As you likely know, chargeback fraud is a growing headache for merchants and they are losing trust in Visa and Mastercard to enforce network rules fairly and consistently. The example that came up: "Goods not received" chargebacks going through at gas stations, where the physical reality makes the claim absurd — and yet the merchant eats the loss anyway. That experience is feeding a new concern. If merchants can't trust the networks to enforce the rules fairly on ordinary card transactions involving actual humans, why should they trust them to fairly enforce the (still-being-written) rules for agentic commerce? Agentic transactions will spawn entire new categories of disputes — the agent bought the wrong thing, the agent got tricked, the agent and the merchant disagree about what was authorized — and the networks are asking merchants to trust them as the neutral arbiter of all of it. Merchants (particularly the large ones that are already grumpy with the networks over fees) are looking at their current chargeback rates and shaking their heads. Sponsored by Taktile Plenty of onboarding teams use AI to move faster, but few have a clear answer for where automation should end. The full Q&A gets into exactly where automation stops at Brex, and why. WHERE I’LL BE ON SEPTEMBER 30TH AT 1PM ET For the entirety of my career, the prime directive in lending has been to strip as much friction out of the process as possible. The logic is obvious: Make people do less, and more of them will make it through the funnel. But that’s not exactly how lending works. Lenders aren’t trying to get the most customers. They’re trying to get the most good customers. They are trying to curate the most profitable portfolio of customers possible. And in 2026, when low friction is the default rather than the exception, I’m increasingly unconvinced that removing more friction always gets you the portfolio you want. For example, if you ask a borrower to retype their name and phone number when you already have it, that’s dumb friction. However, ask that same person for a one-time passcode instead, and you've added a different kind of friction that builds trust. Borrowers aren’t racing to get through an application as fast as humanly possible; they also need to trust the institution on the other side of the screen. That’s the challenge I want to tease apart. Which is why on September 30 at 1 PM ET, I’m sitting down with Tomás Campos, co-founder and CEO of Spinwheel, for The Science (and Fiction) of Friction. The right amount of friction for mortgages is different from credit cards and is different from BNPL. There’s no universal answer, which is why The Science (and Fiction) of Friction is anyone who's ever chased the Goldilocks Effect in their own application or product: Not too much friction, not too little, but just right. If you work for a lender and are responsible for product, risk, fraud, UX, marketplaces, or lead gen, I’d really love to have you there, with all your toughest questions in tow. We’ll try to make this the most useful friction in your workday! Register here to join. Thanks for the read! Let me know what you thought by replying back to this email. — Alex | |||||||||
|
