Workweek Newsletter {beacon}

Reporting back from Salt Lake City.  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Fintech Takes
Alex Johnson
Oct 2nd, 2026
{cta_url_read_in_browser = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_browser"}{cta_url_read_in_app = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_app"}{cta_url_join_conversation = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=join_conversation" + "#comments"} {if profile.vars.member_status == "lead" || profile.vars.member_status == "unfit"} {else}{if profile.vars.member_status == "fit"} {else}{if profile.vars.member_status == "member"} {else} {/if}{/if}{/if}

In partnership with

Sponsor logo

Happy Friday, Fintech Takers!

The WNBA playoffs are in full swing (Go Wings!) The VCs are bickering. And fall weather is well and truly here and it is glorious.

What’s not to like?

Plus, at the start of this week, I got to spend a day with my fellow AI-native banking and fintech nerds at the AI-Native Banking and Fintech Conference. Plenty of interesting conversations were had and I have distilled those conversations down to a set of key questions, which I share below.

I hope you enjoy it!

- Alex

Was this email forwarded to you?


Sponsored by Taktile

KYB automation has always been good at the easy calls. The harder cases are the ones where the right decision isn't obvious: incomplete records, contradictory information, context that only makes sense once a person looks at it.

Customers feel that lag long before anyone on the bank's side does.

EY research* found 42% of SMEs are dissatisfied with onboarding speed, and 36% with how little of the process is automated.

Taktile's new blog post walks through 8 steps to reliably automate investigative work before it reaches reviewers, so the straightforward applications clear themselves and human experts spend their attention where it actually changes the outcome.

Onboarding gets faster, which means more applicants make it all the way through.

*https://www.ey.com/en_ca/insights/banking-capital-markets/the-augmented-sme-experience-art-of-the-possible-through-data-aggregation


OK, five questions about agentic finance.

"Chills. Literal chills."

Here we go.

#1: Is this a feature? A product? Or a company?

I’ve been using Instinct for the last few days, and I have to say that I’m very impressed.

I’m not sure what combination of models are being used in the background, but the packaging of those models into a text-only user interface is very slick. Compared to ChatGPT and Claude — which both jam together so many tools, modalities, and model choices into a single product that it's overwhelming for non-power users — Instinct is simple. And clearly hyper-focused on taking painful administrative tasks off the shoulders of its users.

I’ve been giving it different long-tail tasks from my to-do list, and one of the ones that it did an especially good job on was a 401(k) rollover.

I asked it to track down an old 401(k) account that I had, from several jobs ago, and figure out the easiest way to get it rolled over to my current non-employer account, and it immediately sprang into action. It didn’t even ask me for the information on my account. It just went through my email inbox, tracked down the account information and rollover instructions, and prepared the appropriate forms for me to print out, sign, and mail in.

It was, to be honest, kinda magical.

And it made me wonder: Perhaps we need to completely rethink the old “Is this a feature, a product, or a company?” question.

In the old days, if you built something new that solved an unsolved (or badly solved) problem, you had a product. If that problem was sufficiently urgent for a large number of prospective customers (and you could find a way to get it in their hands), you had a company. And once you had a company operating at sufficient scale, you usually had competitive moats that made it difficult for other companies to copy you.

Rolling over old 401(k)s is a good example. There’s roughly $2T in forgotten or stranded retirement savings in the U.S. If you could build a product that could recover those savings for consumers and distribute that product through brokers and employers, you’d have a very viable and defensible business. One that investors might be willing to pour more than $30M into over the last six years.

In Q3 of 2026, this is a job-to-be-done that any number of personal AI assistants can do for you. A couple of years from now, it may very well be a capability that every bank, brokerage, and employer’s in-app AI assistant can do for you, right out of the box.

Put differently, the distinction between a feature, a product, and a company used to be a question of the size and urgency of the problem being solved and the quality of the resulting solution. With agentic AI, it seems increasingly likely that even the best solutions to the biggest and most urgent problems will quickly become features in every company’s product.

If I were a fintech VC investor, this change would terrify me.

#2: Can the humans in the loop stay awake?

Michael Hsu, former Acting Comptroller of the Currency, was interviewed at the conference and he pointed out one of those things that no one really talks about but sounds incredibly obvious after you hear it.

One of the biggest problems with humans in the loop as a governance model for agentic AI — apart from being impractical when machine-to-machine transactions are happening at a large scale and at super-fast speeds — is that humans get bored.

There’s a more technical term for this: Automation complacency. This is a phenomenon in organizational psychology and ergonomics in which critical tasks become highly repetitive and rarely yield negative outcomes, leading humans to become complacent and to perform the tasks with less diligence.

The former Acting Comptroller argued (and I agree with him) that this habituation effect is highly likely to render AI governance models that depend on frequent human review and approval ineffective. Indeed, that ineffectiveness is likely to increase as the capabilities of AI agents improve, because there will be fewer errors for humans to catch and, therefore, a greater likelihood to become complacent. 

As I said, I’d never heard this argument against human in the loop before, but it was immediately intuitive to me.

#3: Is AI a model? Software? A vendor product?

This was another point made by Mr. Hsu in his remarks.

In banking, there are three different governance models that could, conceivably, be applied to AI.

Is AI a model?

Yes, clearly. Which means that it should be governed by a robust model risk management framework.

Is AI software?

Also yes, quite obviously. Especially when we are talking about agentic AI. So, naturally, it should be governed by the same software development lifecycle that all other software products go through.

Is AI a vendor product?

Frequently yes at an application layer. Almost always yes at an infrastructure level. And that means that it should be governed by rigorous third-party risk management processes.

MRM, SDLC, and TPRM. They all kinda fit AI.

And they all kinda don’t.

MRM assumes you can validate a model for a specific use, but foundation models are general-purpose, opaque, and updated by vendors on their own schedule. SDLC assumes you can define correct behavior in advance and test against it, but AI outputs are probabilistic, and a system's behavior can change when a model, prompt, or data source changes, with no change to the code at all. TPRM assumes a vendor's controls and contractual commitments tell you what you need to know, but a SOC 2 report says nothing about whether a model will hallucinate on your use case, and vendors increasingly switch on AI features mid-contract without triggering any new review.

Federal regulators recently descoped generative and agentic AI from their updated model risk management guidance, which is understandable in a narrow, technical sense (LLMs are a bad fit with some of the specific requirements under the old MRM guidance). However, it’s also concerning to me that regulators did that without (yet) coming up with a new governance framework (perhaps drawing on elements of MRM, SDLC, and TPRM) to replace it. 

#4: How is it possible that the same frontier AI labs that are telling us that there is a 10% chance that the models they are building will kill us all are not willing to accept an ounce of liability for a problem that is comparatively trivial, like booking the wrong plane ticket?

We’re not going to make a lot of headway in deploying agentic AI in financial services until we develop a shared responsibility model that can apportion liability when stuff inevitably goes wrong.

In the case of something like agentic commerce, we can argue about what a fair liability split between issuers, merchants, and the developers of AI assistants like Instinct looks like all we want. However, that entire debate sits downstream of a more important question that I don’t think we’ve adequately engaged with yet: How much liability should the frontier AI labs have?

Employees at the frontier AI labs are, by their own account, building something that has a small (but not that small) chance of ending human civilization.

And yet these same companies won't accept liability for their models getting a refund calculation wrong or booking the wrong flight. Their terms of service disclaim any warranty that the output is accurate. Imagine a pharmaceutical company announcing that its new drug carries a one-in-ten chance of ending humanity, and then asking you to sign a waiver absolving it of responsibility for the headaches.

This is what makes the conversation about third-party risk management for AI in banking (to use just one example) so surreal. TPRM assumes the bank can diligence a vendor, negotiate meaningful contractual protections, and hold the vendor accountable when things go wrong.

But the models banks are deploying were trained (meaning their core dispositions and incentives were set) by companies that had no input from banks, that won't disclose how those decisions were made, and that publicly describe their own products as potentially existential threats. A bank can't validate those choices, can't change them, and can't recover anything when they fail.

So why, exactly, should banks, or merchants, or consumers, accept even a sliver of the resulting (non-existential) liability?

As long as the people who build these systems are the only ones who understand them, shape them, and profit most from them, it's hard to see a principled reason why the risk should sit anywhere else.

#5: Is payments the solution for keeping AI assistants free and aligned with their users?

Noah Shinn, Instinct’s CEO, recently sat for an interview with Patrick O'Shaughnessy. The entire interview is worth a watch, but the most interesting bit was when he was asked about Instinct’s business model, and the inherent tension in trying to make a powerful technology as widely accessible as possible while also generating a sufficient level of profit (Instinct just raised $1B at a $10B valuation!)

The obvious answer to this question is advertising, which is a business model that Shinn is very opposed to. His reasoning is compelling: An AI assistant that's smarter than its user is the most powerful manipulation engine ever built, and pointing it at ad revenue is asking for trouble.

His alternative is that Instinct is already facilitating a huge and fast-growing volume of commerce transactions, so it can monetize through payments the way Apple did with Apple Pay. Free, ad-free, and aligned with the interests of the users.

I like that vision (and I really appreciate the intention behind it), but I think it’s going to be much harder to pull off than he thinks.

From the outside, payments revenue looks like a toll: Money you collect simply for being close to a lot of transactions.

That's not how it works

Payments revenue isn’t a toll you collect without doing any work. It's a fee you earn for making transactions safe. Most of the economics in card payments flow to issuers, because issuers carry the credit risk, the fraud losses, and the regulatory obligations to cardholders. A meaningful slice goes to Visa and Mastercard, because they write and enforce the rules that let millions of strangers trust each other. Everyone else in the chain is fighting over what's left.

Now, in the case of Apple, Shinn’s intuition isn’t that far off. Apple did manage to extract a toll for Apple Pay on top of the existing card payments stack: Reportedly around 0.15% on credit transactions, paid by issuers. However, just because Apple was able to do this doesn’t mean that other companies like Instinct will be able to.

First, Apple had tremendous scale when it negotiated its Apple Pay deal. The iPhone is arguably the most successful consumer product in history, and card issuers and the networks felt that they couldn't afford to be absent from it. Second, Apple used the implicit threat that it could (and would, if necessary) build its own closed-loop network and route around the incumbents entirely to get the deal it wanted. The networks and issuers blinked. Ask around the industry today and you'll find plenty of people who think it was a bluff, and who wish they'd called it.

Instinct is a great product, but it already has major competitors like Muse and (one imagines) plenty of smaller unknown competitors taking aim at it. It's not the iPhone, which means the company does not and likely will never have the leverage that Apple had. Plus, the card networks have learned their lesson. Visa, Mastercard, and Amex are already building their own agent registration, tokenization, and intent-authentication rails, and that's essentially the infrastructure you'd need to keep AI assistants from becoming the next toll booth.

If Instinct wants payments revenue, it will probably have to earn it the hard way: By taking on real risk, like fraud liability, dispute resolution, and accountability for agent errors. That’s possible, of course, but it would be a tough row to hoe.

WHERE I'LL BE

I’m not tired. Why are you even asking me that? I don’t get tired. NO SLEEP TILL BROOKLYN!!!!

✈️ Money20/20 | October 18 – 21 | Las Vegas

Last year at The Venetian, so let’s make it count! For the first time in at least five years, I’m not speaking at the actual event. So I have some time to catch up with folks!

If you’ll be around on Sunday morning, come play/watch basketball. It’s healthy to get away from the Strip for at least a few hours!

✈️ AFC Policy Summit | November 17 | Washington D.C.

One of the best possible places to go if you’re looking for dense and nerdy finreg conversations. Plus, somehow Phil Goldfeder manages to hi five or shake hands with every single person.

✈️ Fintech NerdCon | November 18-20 | San Diego

I’ll be flying from D.C. to San Diego (arrghhhh), but it’s worth it for year two of NerdCon! Plus, San Diego rules.

Thanks for the read! Let me know what you thought by replying back to this email.

— Alex  

LinkedInXInstagramPodcast

@Alex Johnson

Unsubscribe
Community home