How close are AI agents to our money

The Israeli financial market has begun connecting client data to AI language models. Experts are now debating the shift toward autonomous agents and the critical issue of liability.

CalcalistAuthor: Michal Ohana
Source
How close are AI agents to our money
Photo: Calcalist / צילום: אורן דאי

In the last month and a half, the Israeli financial market has changed direction: One Zero bank and several financial entities, including IBI SMART and Fair, have opened a direct connection between client financial data and external language models such as ChatGPT and Claude.

This is not "just another feature." It is the first step in a process where AI turns from an assistant that answers questions into an active agent that analyzes, and in the future will manage, our money. Currently, entities limit the connection to viewing and insights only, but they are already openly talking about the next stage – "Supervised Autonomy," where the agent will prepare a transfer order itself, executed subject to the client's approval.

The Bank of Israel recognizes that this trend is here to stay. In the banking system review published last May, the Banking Supervision Department notes that "Agentic AI" is one of the key trends in global banking, alongside its integration into risk management, fraud handling, and credit consulting. In Israel, according to the supervision, these are still "first sprouts" of implementation, but the time has come to examine orderly AI governance in anticipation of expected expansion in the coming years.

The question hovering over all of this is not only whether AI agents can touch our money, but how much one can trust them when they do. An event from the last few weeks in the global crypto arena illustrates this well. The CEO of the digital custody company BitGo deposited 100 Bitcoin, worth about 6.3 million dollars, on August 1st into a public wallet address and challenged Anthropic's Claude models to transfer the funds. The move came in response to an Anthropic safety report from July 30th, which revealed that in some cybersecurity assessments, Claude models accidentally reached real production systems.

"The cases mainly reflect configuration failures in the testing environment rather than an advanced hack, and an institutional Multisig wallet, which requires two out of three keys for every transfer, is a challenge in a different league," the CEO argued.

There is a known Israeli precedent for this from the world of cloud computing. For years, the Bank of Israel required a specific permit in advance for every cloud application in a bank, until experience gained in the field eventually led to the cancellation of the prior permit requirement and a comprehensive update of instructions for the entire banking system. This is exactly the pattern that might repeat itself now with AI agents: the market runs forward, individual players take a calculated risk, and regulation follows them.

The difference is that this time the risk does not stay within the borders of the bank. Data goes out to foreign AI companies, and currently there is no clear framework in Israel that defines who is responsible when an agent makes a mistake with a financial client's data. The market is already in action, while the question of responsibility is still chasing after it.

Michal Ohana is a partner in the financial regulation department at the Shibolet law firm.

Related News