| |||||||||
| |||||||||
| | |||||||||
| In partnership with Happy Monday, Fintech Takers! I trust you had a good weekend and I hope that your week is off to a productive start! I have a rare non-travel week this week and I will be in Salt Lake City next week for the AI-Native Banking and Fintech Conference, followed by my virtual event on the science and fiction of friction (register to join us!) Then we start gearing up for Money20/20 (we still have some room on Sunday morning, if you want to join us for 3x3 basketball!) In short, it’s all about the fun here at Fintech Takes! - Alex Was this email forwarded to you? Sponsored by Middesk On paper, Orchard Crest was the applicant every risk team hopes for. Active registration, good standing, application details that matched the record, clean watchlist screens. Nothing obvious suggested a problem. Every standard check also evaluates a business as a single entity. The risk was in its relationships, and that’s what Middesk’s entity graph uncovers. Middesk found one person tied to 10 other companies. Seven more businesses surfaced behind those. One connected company had submitted 15 applications across 10 institutions, and Orchard Crest's registration number turned up in an archived shelf-company listing. Would your existing process have caught this? That's not even everything the entity graph found. ![]() View of Toledo (1599–1600) by El Greco. 3 FINTECH NEWS STORIES#1: Amazon’s War Against Agentic AI ContinuesWhat happened?Amazon is mad! Very Mad! GeekWire reports:
So what?I wrote about Amazon vs. Perplexity in Friday’s newsletter, which is roughly the same issue (an AI agent accessing Amazon customers’ accounts with their permission and using their credentials). The big difference in that case is that Amazon accused Perplexity of violating the Computer Fraud and Abuse Act (i.e., accusing Perplexity of hacking), which is an argument that the Ninth Circuit Court of Appeals rejected. In this case, Amazon is merely attempting to block Muse from accessing its website, and returning a message that tells users that using Muse to access Amazon is a violation of Amazon’s conditions of use. The fact that Amazon had to take this step is interesting, by itself, as Meta apparently refused to voluntarily exclude them from the activities that Muse can take on behalf of users. I imagine that this specific fight between Amazon and Meta may end up getting resolved, without either party turning to litigation, given the larger commercial relationship that exists between the two companies (e.g., Meta signed a multibillion-dollar deal earlier this year to run agentic AI workloads on Amazon’s cloud). Meta may even agree to pay Amazon for direct (and controlled) access for Muse to Amazon customers’ accounts (with their permission). However, there is no reason to think that similar fights between Amazon and other providers of agentic AI assistants will be resolved quickly or pleasantly. The company’s fight with Perplexity continues and, as Elon Musk points out, there’s no sure-fire way for Amazon to block all AI agents from accessing its site: ![]() This is what distinguishes the 2026 fight over screen scraping in agentic AI from the 2000s/2010s fight over screen scraping in open banking. Back then, it was expensive to build and maintain scrapers for every bank’s website, and such scrapers were fairly easy to identify and block, since they came from a small number of centralized IP addresses. Modern agentic screen scraping is cost-effective and decentralized. From the perspective of the company getting scraped, it’s not dissimilar to a DDOS attack. The reality is that companies won’t be able to stop AI agents, acting under the direction of those companies’ customers, from accessing their websites and taking actions. And, unfortunately, when those actions result in harm to the customers, those companies will not be shielded from the fallout. Just ask banks how many customer service calls they get when an open banking integration doesn’t work, or how quick Senator Warren is to send them a letter when a high-profile consumer problem relating to open banking is reported. You have to find a way to deal with the pressure that agentic AI is going to put on your website. And, more fundamentally, you have to ensure — long term — that you aren’t making money by artificially imposing friction, cost, or information asymmetry on your customers. Because agentic AI will cut right through that shit. I don’t think it’s an accident that Shopify — one of Amazon’s largest, most orthogonal competitors — has already integrated with Muse, while Amazon’s own sellers are finding ways to use AI to automate the company’s obtuse return reimbursement process. #2: B2B Banking Bundling … At Two Different SpeedsWhat happened?Mercury launched an accounting product, embedded directly within its core banking app:
And AmEx launched a high-yield savings account for businesses and is planning offerings around business checking rewards and payroll as well:
So what?Well, if this doesn’t illustrate the differences between a 9-year-old company and a 176-year-old company, I’m not sure what does. AmEx launched checking accounts for small businesses in 2021, following its acquisition of Kabbage. By itself, that seems a bit strange given that AmEx launched its first small business credit card in 1988 and officially became a bank in 2008. But whatever. It got a late start in small business banking. Fine. But how could it take them FIVE YEARS to bolt a high-yield savings account onto that checking account? Did they not realize that small business owners might want a place to earn a little interest on their excess deposits? Do they not realize that this statement — lifted directly from the press release quoted above — was table stakes back in 2019, when Mercury launched it:
You can apply for both in one application! Why are we bragging about that? Why, realistically, are we even thinking of these products — checking and savings — as separate things, given that every small business would naturally want both and think of them more as a package deal? Meanwhile, Mercury is launching its own embedded accounting product, which, from a scope perspective, puts it even further outside the reach of traditional B2B payments and banking providers like AmEx, and more into the realm of full-service B2B operating systems like Intuit QuickBooks. These two companies — both banks — are building B2B banking bundles, but they are doing so at radically different speeds. #3: Revolut Got ScammedWhat happened?Revolut has informed some of its customers that their data has been compromised:
So what?As Jason Mikula’s excellent reporting illuminates, there are a couple of weird things about this incident. First, it targeted crypto “whales”:
Second, the perpetrator didn’t hack Revolut. It hacked an Italian government email system and then used its access to that system to impersonate law enforcement and convince Revolut to hand over a ton of personal information about the victims:
Make sure to read Jason’s entire newsletter from yesterday, as he goes into a great deal more detail. I just have a few quick thoughts to add in:
Sponsored by Brico Charter, sponsor bank, or state licenses? Now that the OCC is answering the phone again, every fintech company with a payments or lending product has to pick. But before you do, hear from someone who sat on the other side. On September 22, Donna joins Snigdha Kumar, CEO of Brico, the compliance and licensing platform for regulated fintech companies, for a live conversation on what it takes to get a charter. Free, 45 minutes, live Q&A. 2 READING RECOMMENDATIONS#1: Winding Down Banks’ Free Money Machine (by Kiah Haslett, Fintech Takes Banking) 📚Kiah’s series on deposits continues! I’ve learned a lot about this side of banks’ business, and how it has changed over the last couple of years, by reading her coverage. #2: Crypto Blew Its Big Moment—and the Blame Game Has Begun (Wall Street Journal) 📚An interesting accounting of the aftermath of Clarity’s failure. To be honest, I’m not sure how you can not assign at least a little of the blame to Coinbase and Brian Armstrong. It feels like they overplayed their hand significantly. *Bonus: Stop Competing For Your Own Customer (by me, with Method) 📚Most lenders pay to acquire a borrower, then pay again to reacquire that same borrower when their next need hits. Part of the problem is that bureau data lags a borrower's actual life by 22 days on average, so lenders often learn a borrower's situation has changed after the window to act has closed. Read how permissioned liability data changes the cross-sell math. *This rec is brought to you by one of our fantastic brand partners. 1 QUESTION FROM FINITYThere are a TON of interesting questions being asked in Finity (our digital community for fintech and banking nerds). I’ll share one question, sourced from the community, each week. However, if you’d like to join the conversation, please apply to join! What motivation does Amazon have to allow any agentic AI assistant/bot customer-permissioned access to its website?I’ve heard some folks compare the predicted outcome here to what we saw in open banking, where JPMC relented once it got paid. However, the incentives in that case seem completely different. Amazon has A LOT of leverage and no mandate (legal or otherwise) to play nicely.If you have any thoughts on this question, reply to this email or DM me in Finity! Thanks for the read! Let me know what you thought by replying back to this email. — Alex | |||||||||
|
.png?sig=3869ddaa7451fe5f452941d02052da072ea348e419f7cd0536a46c7fd83a4455&size=email-body&dpr=2)

