Big Tech

Equals Money restricts AI agents to read-only access on payment data

As fintech companies open their systems to customer AI tools via Model Context Protocol servers, payments firms face unique risks: a compromised agent could move money at scale. Equals Money is implementing strict identity controls and read-only access to mitigate the threat.

3 min read
Equals Money lets customers’ AI tools read data but not move money

Fintech companies are increasingly exposing Model Context Protocol servers to customer-controlled AI tools, but the payments industry faces a problem that data-focused sectors do not. When a rogue agent accesses customer records, the damage is exposure. When a rogue agent accesses payment systems, the damage is theft. That distinction is forcing identity providers and regulated financial firms to rethink how they authenticate, monitor and disable AI agents.

Okta Inc. has begun rolling out runtime enforcement and a broader kill switch for AI agents. For a regulated payments company, the safest approach is to treat agents as if they were employees with their own identities and access privileges, according to James Simcox, chief operations and product officer of Equals Money PLC.

As a financial services business, we've always had to audit everything our staff do. With agents, we also have to not only treat them like a human but [like] they've got their own identity [and like] they've got their own access.

James Simcox, Equals Money PLC

Simcox shared these views during an interview with theCUBE Research's Krista Case and Rebecca Knight at Okta's Oktane event, which was broadcast on theCUBE, SiliconANGLE Media's livestreaming studio.

Agent identity, kill switches and a read-only MCP server

Equals Money already deploys agents in customer-facing applications, and Simcox noted that AI now generates roughly 92% of the company's code. At that scale of adoption, establishing agent identity and the ability to revoke access becomes critical.

Having that identity on the agent is really, really key, but also the ability to cut them off. If a human goes rogue, it's one human. If an agent goes rogue, it could be 100,000 of them at the exact same time going crazy.

James Simcox, Equals Money PLC

Okta's Agent Gateway kill switch is engineered to revoke every active token belonging to a compromised agent in one action. Equals Money can already revoke agent tokens, but the process requires manual intervention. The company is seeking automated detection that can identify abnormal behavior and disable agents without human involvement.

What we really need is that automated view of going, this agent's not behaving like it's supposed to. It's meant to be the email change guy and he's not doing that. So let's just kill everything right now.

James Simcox, Equals Money PLC

Equals Money extends the same security posture to agents operated by customers. The company assumes full liability for any errors that occur on the customer side and conducts multiple reviews of each workflow before deployment.

https://www.youtube.com/embed/MTgOX3dIyOg?feature=oembed

If you use the AI tools available in your [enterprise resource planning] package or whatever [and] attach it to our MCP server, maybe we can just make that data exchange way quicker. We have made a choice, though, that customers can't instruct payments through MCP. It's data read-only for now, or write for nonsensitive stuff.

James Simcox, Equals Money PLC

Source: SiliconANGLE · Reporting supplemented by The Silicon Ledger staff.