Agentic AI is here. Not the chatbots of a few years ago that answered questions, but autonomous agents that act. Consumers are already deploying AI assistants to monitor accounts, automate savings, flag suspicious charges, and manage subscriptions, all without lifting a finger. Gartner projects that by the end of 2026, 40% of enterprise applications will include task-specific AI agents, and the consumer side is moving just as fast.
At Akoya, we're seeing this play out firsthand across the financial institutions we work with. And there's an uncomfortable reality that most haven't fully reckoned with: if you haven't built a secure, API-based open finance infrastructure, you may already have limited visibility into what's happening with your customers' data. Once agentic AI goes mainstream, that blind spot only grows.
The path of least resistance is the wrong one
AI agents need data to do their jobs, and they will get it one way or another. If your institution offers secure, standards-based APIs, an agent can connect through a structured, permissioned channel. You know who's accessing data, what they're pulling, when consent was granted, and when it expires. You and your customer can see it, manage it, and revoke it.
If you don't offer that path, the agent may fall back on screen scraping. The consumer hands over their banking credentials to an AI platform, which logs in as if it were them, potentially thousands of times a month, invisibly, indistinguishably from a human. If the AI agent has access to the consumer’s email or texts, it may even complete MFA.
This isn't a hypothetical future problem. Today, more than 53% of all web traffic comes from bots and automated systems, with financial services among the most targeted industries (Imperva, 2026). The average cost of a financial data breach now stands at $5.56 million (IBM, 2025). Agentic AI will push both of those numbers higher for institutions that haven't built a better path.
Why the agentic era makes screen scraping a greater liability
Screen scraping has always been a liability. Credential sharing opens the door to fraud, account takeovers, and privacy violations. Financial institutions can face liability exposure for unauthorized transfers even when a third-party app is the source of the problem, depending on the facts and the applicable framework.
Agentic AI does more than magnify the old problem. It changes its shape as volume, traceability, and accountability all break in ways credential sharing never did before.
|
Negative impacts |
How they happen |
|
Volume escalates dramatically |
A human logs in occasionally. An AI agent queries account data continuously, in real time, at machine speed. Infrastructure built for human-scale access will buckle. |
|
Traceability disappears |
When a consumer shares credentials with an AI platform, there's no structured consent event, no record of what was authorized, what's being accessed, or for how long. The consumer has essentially handed a master key to software the institution can't identify or communicate with. |
|
Consent becomes impossible to verify |
In a well-governed API environment, agents act on authority that a human explicitly granted, within defined limits of scope, purpose, and duration. In a credential-based world, none of that exists. And the gap between what consumers think is happening and what's actually happening is already alarming: a Clearing House survey found that 73% of fintech app users don't know apps have access to their banking credentials, and 78% have no idea data access can continue after they delete an app. Agents will make that gap much worse. |
|
New attack surfaces open up |
In December 2025, OWASP, a leading cybersecurity research body, released its Top 10 for Agentic Applications, cataloging the risks that are specific to autonomous AI systems: manipulation of agent behavior by malicious inputs, tool misuse, and data leakage. An agent running through shared credentials has no structured boundary on what it can reach, and no accountability trail when something goes wrong.. |
|
Behavioral lock-in happens fast |
Once consumers embed credentials into AI agents and those agents become part of how they manage their financial lives, it's very hard to change that behavior. Institutions that don't build an alternative path now will find themselves trying to unwind something deeply embedded, with no easy lever to pull. |
The new imperative: Know Your Agent
Financial services has always been rigorous about knowing who it's doing business with. Know Your Customer. Know Your Business. The agentic era calls for a new category: Know Your Agent.
Just as KYC creates an authoritative, identifiable record of who a customer is, KYA should establish who an agent is, what it does, and under whose authority it's operating. For any institution that wants real visibility, the questions are: Who runs this agent? Under what authority is it accessing my customer's data? What constraints govern its behavior? And how do I revoke access if something goes sideways?
None of those questions have answers in a credential-based world. They're only answerable at scale through structured, permissioned API access.
In a properly governed open finance environment, agents get registered and treated as identifiable actors, subject to the same security review and contractual accountability we apply to third-party apps today. The technology stack doesn't change who's responsible: data recipients and agent operators stay accountable for what happens downstream, including data forwarded to external tools, model providers, or other third parties.
Traceability is the new security perimeter
Security in the agentic era is less about keeping bad actors out and more about maintaining clear visibility into legitimate access and making sure "legitimate" really means something: defined, bounded, and revocable.
When a consumer connects an AI agent through a permissioned API, a structured consent event is created. The institution can see exactly who's requesting access, what data is being shared, when, and when it expires. Every connection is auditable. Access can be revoked by the consumer, or by the institution if something looks off.
There's an important distinction worth naming here: revocation and deletion are not the same thing. Revoking access cuts off future data flows, and that's technically enforceable. But what an agent has already processed, summarized, or incorporated into its reasoning is a harder problem with no clean technical solution today. At minimum, institutions with governed API access have a clear record of what was shared, when, and under what authorization. Institutions that relied on screen scraping have nothing to work with.
Akoya's Open Finance Solution is built to address exactly this: a full-service platform sitting between your institution and the broader data-sharing ecosystem, with standards-based APIs, security and risk reviews for every data recipient, a consumer-facing consent dashboard showing every active connection including agent-mediated ones, and the administrative tools your team needs to maintain visibility into third-party access.
The governed path has to be the better path
At Akoya, we believe the governed path only wins if it's genuinely better, not just safer, but easier, more reliable, and more useful than the alternative. Institutions and AI platform operators will choose structured access because it works, not because someone made the other option harder.
And it can work better. An AI agent operating through a governed API can do things a screen-scraping agent simply can't: initiate permissioned actions, operate within clearly defined scope that only expands with explicit user consent, and build a real trust relationship with both the consumer and the institution over time.
The regulatory environment supports this direction too. As of publication, a federal court has enjoined the CFPB from enforcing its Section 1033 rule while the Bureau reconsiders it, but the underlying requirement for consumer-permissioned data access isn't going anywhere. Institutions building API infrastructure now will be in a stronger position regardless of how the rule lands.
The real question isn't whether you can block unauthorized screen scraping. It's whether you've built the infrastructure that makes your institution the right place for customers' AI agents to connect, with visibility and control on your side, and genuine transparency on theirs.
The window is narrowing
This isn't a trend to watch from a distance. Agentic AI is reshaping consumer behavior right now, and every month without a secure data-sharing infrastructure is another month where that behavior gets shaped by screen scraping and credential sharing instead.
Institutions that move now get to influence how this plays out, through structured, auditable channels where they stay informed and in control. Institutions that wait may find themselves trying to reverse habits that have already hardened.
The case for secure open finance has always been strong. In the agentic era, it's urgent.
Akoya provides a secure, full-service open finance solution for financial institutions. To learn more, visit akoya.com/openfinance or contact us at info@akoya.com.
Citations
- Gartner, "Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026," August 2025. gartner.com
- Imperva, "Bad Bot Report 2026: Bots in the Agentic Age," April 2026. imperva.com
- IBM, "Cost of a Data Breach Report 2024," July 2024. ibm.com
- The Clearing House, "2021 Consumer Survey: Data Privacy and Financial App Usage," December 2021. theclearinghouse.org
- OWASP GenAI Security Project, "Top 10 for Agentic Applications 2026," December 2025. genai.owasp.org
