AI agent security in banks and payment firms
AI agent security protects the agents a bank runs and the systems they can reach. An agent reads outside content and calls tools with real rights, so an attacker who steers it can make it leak data or start a transaction. BaFin names these risks in its guidance on AI under DORA. Dated events on risk and compliance are in the calendar below.
How attacks on AI agents work
The best-known attack is prompt injection: instructions hidden in an email, a document or a web page that the agent reads and then follows. IBM lists further routes, among them tricking an agent into misusing a connected tool, planting false data in its memory, and stealing the credentials an agent uses so an attacker can pose as it. The damage grows with the agent's rights, and IBM's list of controls starts with zero trust and least privilege.
The OWASP Top 10 for Agentic Applications, written with more than 100 security experts, sorts these risks from agent goal hijack to rogue agents. A bank can use it as a checklist for penetration tests and model risk reviews of an agent before go-live.
What BaFin and DORA expect
BaFin's guidance on ICT risks in the use of AI at financial entities applies DORA to AI systems and names three risks in operation. A language model can be forced into unplanned behavior by malicious prompts, for example through a link to a web page with hidden instructions. A compromised assistant can hand confidential data to users who have no right to see it. And API access to a model can give attackers a way into the systems connected to it. BaFin suggests monitoring AI interactions, detecting anomalies and assigning access rights with care.
The guidance is not binding, but the duties behind it are: ICT risk management and third-party risk management under DORA. Each model provider and each MCP server an agent uses is an ICT service that the bank has to assess, contract and record.
Controls that payment firms already use
Stripe lets agents act through its MCP server with narrow agent keys and requires a person to approve refunds and outgoing payments before they run; its documentation warns of prompt injection when agents combine several servers. Visa and Mastercard give shopping agents signed identities, so a merchant can block a bot that only pretends to be one; the Trusted Agent Protocol page explains the method.
In the United States, FINRA's observations on AI agents list agents acting beyond their intended authority and multi-step reasoning that is hard to trace among the risks it sees at member firms. Logging every tool call is the common answer to both.
Upcoming events on risk and compliance in Germany
What is AI agent security?
AI agent security is the protection of AI agents, their credentials and the systems they can reach against manipulation and misuse. It covers what the agent reads and what it is allowed to do.
What is prompt injection?
Prompt injection is an attack in which text the agent reads, such as an email or a web page, contains instructions that make the agent do something its owner did not intend, for example send data out or call a payment tool.
Which rules apply to AI agent security in banks?
In the EU, DORA's rules on ICT risk and ICT third parties, and in Germany BaFin's guidance on ICT risks of AI. The EU AI Act adds accuracy and cybersecurity duties for high-risk systems such as credit scoring.
AI agent security and Finance Loop
Finance Loop brings the security and model risk people in banks together with the developers who build agents. Finance Loop covers agent security in its Risk & Compliance and Digital Infrastructure & Sovereignty tracks. Security vendors can present their approach in a sponsored webinar, and practitioners join through the membership.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.