AI Agents
15 articles in this category
The First 90 Days of a Mortgage AI Deployment: The Controls We Stand Up Before the Agent Touches a Live File
Most mortgage AI deployments fail at the start, when the agent goes live before the controls that make it safe exist. The first 90 days are a control build, not a rollout. What we run in shadow mode before the agent touches a file, why the go-live gate is set per control instead of globally, and how deploying controls-first is also the posture an examiner expects to see.
AI Agents Inside the LOS: The System-of-Record Boundary, the Write-Back Discipline, and the Audit Trail That Survives an Exam
Most mortgage AI fails not at the model but at the integration. How we run an AI agent against a loan origination system without corrupting the system of record. The propose-then-record pattern, idempotent write-backs, MISMO field mapping, and the change log an examiner will ask for under SR 11-7.
UCC Article 4A and the AI Wire-Verification Architecture: Commercially Reasonable Security Procedures When the Caller Is Verified But the Instruction Is Not
Wire fraud losses are running at multi-billion-dollar annual totals and the legal allocation of those losses runs through UCC Article 4A's commercially-reasonable-security-procedure standard. AI voice authentication of the caller does not, by itself, satisfy the security procedure for a payment instruction. The architecture we run so the bank's Article 4A position holds in court when the instruction was the fraud.
Voice Cloning and the End of Voice Biometrics as a Sole Factor: A Caller-Verification Architecture for Banks
Cheap, high-fidelity voice cloning has collapsed voiceprint and knowledge-based authentication as standalone factors on bank phone channels. The NIST 800-63 level we hold caller authentication to, the phishing-resistant factors that survive a synthetic caller, and the agent-side controls we wire around them.
Prompt Injection Defense for Banking AI Agents: Threat Model, Controls, and a Red-Team Cadence
Prompt injection is the highest-impact attack against an AI agent in a bank because the agent has tools that move money. The threat model, the architectural controls, and the red-team patterns we exercise before every deployment.
Building AI Agents for Open Banking While the 1033 Rule Is Enjoined
Section 1033 was finalized in 2024, enjoined in 2025, and is now under reconsideration. How we architect AI agents for personal financial data sharing so the design survives whichever way the rewrite lands.
AI Agents for Credit Unions: An NCUA-Aligned Deployment Guide
A practical guide for credit unions deploying AI voice and chat agents — covering NCUA expectations, Reg E, share-draft language, member experience, and the small-shop realities of CU technology stacks.
Preventing AI Hallucinations in Bank Customer Service: A Grounding and Citation Architecture
How regulated banks can architect AI agents that do not hallucinate — covering retrieval grounding, citation enforcement, confidence gating, and the eval harness needed to keep policy-true answers in production.
Build vs. Buy: Should Your Bank Build an AI Agent or License One?
A decision framework for banks and credit unions weighing whether to build AI agents in-house or license a regulated-finance platform — covering total cost, time to value, model risk, and the in-house capabilities you actually need.
From Bot to Banker: AI-to-Human Handoffs for Regulated Financial Institutions
How to build AI-to-human handoff experiences that are fast, compliant, and human-ready — for banks, lenders, servicers, credit unions, and insurers.
Voice Agents for Finance: Top Mistakes To Avoid
Agentic AI has crossed from demos to durable programs. Here are the most common mistakes financial institutions make when deploying voice agents — and how to avoid them.
Conversational AI in Financial Services
A practical guide to deploying conversational AI across banking, credit unions, lending, servicing, and insurance — with compliance, auditability, and measurable ROI.
You Ain't Seen Nothin' Yet
- Any loan type, any agency guideline or custom investor overlays.
- Every finding cited to the guideline or document it came from