Nobody Built a Door for the Assistant You Hired. It Uses Your Password Instead.
Send software to run your errands and no bank, airline or store has built it a way in — so it logs in as you, with your credentials. Britain solved this in 2017.
I owe you an admission before I point at anybody else, because I have done the exact thing this article is about.
A few years ago I wanted a budgeting app to show me all my accounts on one screen. It asked me to connect my bank — and instead of sending me there, it drew its own login box, on its own servers, and asked for my banking username and password. I sat there about two seconds, long enough to know better, and typed them in.
I've done it since. Different app, same box, same two-second pause. So, I suspect, have you.
Now I catch myself doing a stranger version of it: handing an AI assistant a chore and quietly hoping it can get in — without once asking the obvious question. Get in how? And as whom?
Nearly everywhere in America the answer is: as you, with your credentials, because nobody built the machine a door of its own. This isn't the story of an agent talked into something stupid by a hostile page, or of who pays when it buys the wrong thing — I've written both; they sit downstream of this one. The question underneath is what the institution sees when you delegate. It sees your password. And it concludes, reasonably, that the thing typing it is you.
What really happens when the assistant "connects to your account"
Two mechanisms are in wide use, and the difference is the whole article.
The old one has a name — screen scraping — and works as it sounds: as the data network Akoya describes it, consumers share their banking credentials with a third party, which then uses them to log in to the financial institution's digital channels. The institution is never told a machine is on the line. From its side of the glass, you logged in.
The better mechanism is neither exotic nor new. As the data platform MX lays out the contrast, scraping requires sharing your username and password; the alternative redirects you to log in at your own institution, and then a token is created and passed back. A token can be scoped, can expire, and can be killed without touching your password.
What does that arrangement mean legally? U.S. Bank spells it out in its digital services agreement: "We are not responsible for managing the authority of your third-party relationships," and "Any activity performed using your Login Credentials or your device will be presumed to be authorized by you unless you tell us otherwise."
Presumed to be authorized by you. That is the security model of the agentic economy in 2026.
The revocation procedure deserves a slow read too: if you have shared credentials and want that access to stop, you must contact us to block access to Digital Services until new credentials are established. So to fire the machine you lock yourself out, then re-key everything. That isn't revocation. That's arson.
One line of American law already forbids this. It has never taken effect.
Here is where it gets genuinely absurd.
The Consumer Financial Protection Bureau's Personal Financial Data Rights rule — the open banking rule, known by its statutory section, 1033 — saw this coming. One line of it says a data provider must not let a third party into its developer interface using any credentials a consumer uses to log in. Not a guideline; a prohibition, in the Code of Federal Regulations. And an authorized third party must give you a way out as easy to access and operate as the initial authorization.
Then nothing happened. In October 2025 a federal judge in Kentucky enjoined the Bureau from enforcing it. April 1, 2026 was supposed to mark the first compliance deadline; instead it marked, as one law firm put it, a regulatory regime in flux. The appeal went to the Sixth Circuit, where the case has been stayed while the agency rewrites what it wrote. On August 6, 2026 the Bureau sent that rewrite to the White House for review — a step that comes before publication, not after.
So the one American rule telling institutions the machine may not use your password is enjoined, on appeal, stayed and under rewrite. Not a conspiracy. Just what happens when nobody's job depends on the door existing.
And if it goes wrong, the line isn't where you assume
This is the part I most want you to remember — and where I refuse to overstate.
Under Regulation E, the definition the CFPB uses turns on authority: an unauthorized transfer is one initiated by someone other than you, without actual authority, from which you receive no benefit. If you were fraudulently induced into sharing account access information and someone used it to move money, that transfer is unauthorized. That's the scam case, and the protection is real.
But you weren't tricked. You handed the credentials over on purpose — and the same definition carves out transfers by a person who was furnished the access device to the account by the consumer, "unless the consumer has notified the financial institution that transfers by that person are no longer authorized."
Careful here, because this is exactly the sentence that gets hardened into something false on its way around the internet. I am not saying an AI agent voids your fraud protection; no source says that. I am saying that deliberate delegation and fraud sit on opposite sides of a line the regulation draws, and that the carve-out runs until you tell the institution otherwise. That "unless" is your handle.
Meanwhile, the doors that do exist are being welded shut
While Washington litigates, the private sector has answered — with a no.
Amazon blocks AI agents from its $575 billion marketplace, Forbes reported in February 2026, in a piece that also found every major bank requires human verification for AI-initiated transactions — and that framed the unanswerable question: how does a bank verify an AI agent has legitimate authority to access accounts?
Nor is it only banks. Delta's AI Terms of Use, effective April 15, 2025, prohibit accessing the service "through unauthorized means," and nowhere describe a means by which the agent you hired would count as authorized. Terms of that kind are not decoration, either: in a six-year scraping fight a federal court in California held LinkedIn's user agreement enforceable as a contract, separately from any computer-misuse claim.
So your assistant is contractually barred from the front door, technically able to walk through it wearing your face, and legally indistinguishable from you once it does.
Congress noticed — and wrote down a list of everything missing
On June 29, 2026 Senator Mark Warner released a discussion draft of the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act — the AI AGENT Act, a name plainly reverse-engineered from its acronym. His framing: agents must be accountable to the people they serve.
The central move is a right to designate what the draft calls a custodial user agent to act for you on the same terms as a user. Covered platforms — those with more than 50,000,000 customers or subscribers in the United States in a month, which is to say the ones you use — would maintain an interface for those agents on fair, reasonable, and nondiscriminatory terms. Warner's summary adds a Federal Trade Commission registry of trusted, secure AI agents. And those duties may not be waived, limited, or modified by contract, by terms of service, or by any form of user consent — so somebody on that staff read the Delta clause too.
The most revealing passage is the instruction to NIST — an inventory of what does not exist: scope-limited and revocable delegation credentials, verification of the agent's identity, real-time revocation, and auditable records of actions taken on behalf of users.
Scope. Identity. Revocation. Audit. Four things every locksmith on earth has understood since the Bronze Age — and the Senate must ask a standards body to invent them. It is also, as CyberScoop notes, a discussion draft released for feedback before any formal version. In Senate dialect: nobody has to vote on it yet.
The strongest case against everything I've just said
Take the other side seriously, because the good version of the objection isn't "platforms should stay closed."
It is that a mandate to open the door arrives before anyone has built the lock. Ellen P. Goodman, who teaches this at Rutgers Law School, reads the draft's status as the tell: releasing it as a discussion draft is, in her words, "a tacit acknowledgement that we do not have the technical capabilities to govern agents as specified." She has a point — the nearest thing to a standard is an Internet-Draft with no formal standing, and even identity is unsolved, since the header a bot uses to announce itself is, as Cloudflare's engineers put it, easily spoofable.
Industry told NIST much the same, not unreasonably: a coalition including TechNet, BSA and the American Bankers Association warned that premature mandates could freeze security approaches in place before the field has identified best-in-class techniques. The center-right Information Technology and Innovation Foundation, objecting in Brussels to an Android interoperability mandate, argued that forcing third-party access to sensitive features could expose European consumers to increased privacy and security risks. And the banks have an objection that isn't turf: the Bank Policy Institute notes that if a fintech you authorized is breached, the bank could still be liable.
But notice what none of it argues for. "We lack scoped delegation credentials" is a reason to build them, not a reason to leave your password standing in as the interface — which is the actual status quo. The alternative to a well-designed door is not safety; it's a machine climbing through the window in your clothes.
And the sequencing objection has an answer, because somebody answered it nine years ago.
Britain built the door in 2017, and it wasn't an AI policy at all
Here is where the comparison stops flattering us.
The British answer didn't come from a technology committee. The Competition and Markets Authority, the antitrust regulator, published its Retail Banking Market Investigation Order on February 2, 2017. Open banking was one of the remedies in it. Nobody was thinking about AI agents.
The Order does not ask nicely. It names nine banking groups — the CMA9 — and orders them to stand up an "Implementation Entity" to build and maintain common banking standards, free of charge, covering read and write access, so a third party could see accounts or initiate a payment on behalf of the customer — "subject to the customer's explicit consent," in those words, in 2017.
It even told the banks what to build, and the minimum list is uncomfortable reading today: "authorisation and authentication standards," "standardised permission frameworks," and "whitelisting as a system for approving third party providers fairly and quickly." Set that beside the four items a senator is now asking NIST to define. The gap isn't ambition. It's nine years.
Specification first, door second: access switched on in January 2018, and by September 2024 the CMA could confirm all nine banking providers had completed the roadmap. What does that buy an ordinary person?
A vetted counterparty you can look up. Only firms regulated by the Financial Conduct Authority or a European equivalent may enroll in the Open Banking Directory, they act only with your explicit consent, and you can check one against a public register. In the ecosystem's own words, you decide what information that firm can access, and for how long.
No credential handover, ever. You will never be asked to give access to your bank login details or password to anyone other than your own bank or building society.
A real door, not a bot in a browser. Banks offering online payment accounts will have to give AISPs and PISPs access with the user's consent and authentication, through a dedicated interface the regulator made them build.
Revocation that costs you nothing. Revoking consent at bank or TPP ends the interaction — either end of the rope cuts it — and banks provide what the standard calls an "authorisation dashboard," where permissions come off at the press of a button. No password change, no locking yourself out — and consent isn't perpetual, since the FCA now makes the third party reconfirm their consent with you directly.
A toy? Eight years in, that door has carried more than one billion Open Banking payments and 100 billion API calls across the CMA9. Parliament has since generalized the idea beyond banking, letting ministers require customer data to go to the customer or to a person the customer names.
You needn't take my word for it: the American banking industry makes the comparison itself. The Bank Policy Institute — arguing against the CFPB's rule, remember — notes that many other jurisdictions have taken significant steps to ban unsafe practices like screen scraping, while the U.S. does not prohibit screen scraping or generally provide for regulatory oversight of third-party data recipients. When the banks' own Washington shop says the American consumer is the less protected one, believe them.
Now run the clock forward five years
Two futures, and the fork is closer than it looks.
In the first, nobody builds the door and agent vendors quietly become credential custodians, because holding your logins is the only way to make the product work. Picture a company you've never heard of holding live banking, airline and pharmacy credentials for eleven million households — not scoped tokens, credentials — licensed as none of those things and examined like none. And on the day you want out, you do what the contract says: freeze your own access, mint new credentials, re-enter them across forty services while your life politely stops.
In the second, the four boring pieces exist. You ask your assistant to rebook a flight; the airline throws up a permission card. This agent, this account, ticket changes only, no profile data, expires in 48 hours, spend ceiling attached. It does the job, and afterward there is a line in a log with a name on it — not "user logged in from a data center in Virginia." Two months later you switch vendors: one tap, and your password never changes.
The distance between those worlds isn't model capability. It's four pieces of unglamorous plumbing that one country ordered built in a single antitrust order while another is still asking a standards body to consider the idea.
Who else is saying this, and from which direction
Encouragingly, this isn't a partisan concern.
The Electronic Frontier Foundation got there in 2021, when Bennett Cyphers and Cory Doctorow wrote that anything you can do with a mouse or a touch screen, you should be able to delegate to someone's code — and that such delegated agents could tip the balance of power toward users. The engineers, meanwhile, have published an answer: a January 2025 paper by researchers at MIT and elsewhere proposes extending OAuth 2.0 and OpenID Connect with agent-specific credentials and metadata, bolting delegation onto the login standards the web already runs on. Not a moonshot — an afternoon's argument at a standards meeting nobody has been forced to have.
America did build one narrow door of this kind — California's "authorized agent" provision, letting you designate a third party to make privacy requests — and it shows what happens without enforcement. When Consumer Reports tested it across 21 companies in February 2021, 12 confirmed they had stopped the sale of at least some data in response to all of the opt-out submissions, while 5 claimed not to sell consumer data at all and dismissed the requests. A right to send an agent is only as good as the duty to answer one.
So what do you actually do about it?
None of this requires giving up the assistant. It requires looking at the door it uses.
Tell the two connect screens apart. If an app asks for your bank or airline password in its own box, that's the scraping pattern, and your credentials now live somewhere else. If it bounces you to your institution's real login and back, you've been given a token. Prefer the second.
Read the revocation clause before you connect — not the privacy policy, the exit. If the only way out is "call us and we'll block your access until you establish new credentials," you know the cost of quitting before you're stuck with it.
Treat the human-verification step as a feature. Right now that friction is your only scoping mechanism.
When you end a delegation, tell the institution, in writing, immediately. Regulation E's carve-out runs "unless the consumer has notified the financial institution that transfers by that person are no longer authorized." That notice isn't a formality. It's the switch.
Say something while it's still being drafted. The AI AGENT Act went out for feedback precisely because it isn't finished, and the CFPB's rewrite will surface for comment. Consumer voices in those dockets are rare, and they get read.
The lesson, as I see it
Delegation is one of humanity's oldest technologies. A power of attorney. A spare key left with a neighbor. Every workable version has the same three properties — a defined scope, a record of what was done, a way to take it back — and not one requires you to become the person you're delegating to.
We now hand the most capable delegates in history a chore a day with none of the three. Not because it's hard; the British ordered it built in a year, as a footnote to a competition case. Because in America, nobody has been made to.
So my vote: stop arguing about whether the assistant can be trusted, and put the harder question to the institution. Not "is your AI safe?" but "why does the thing I hired still have to log in as me?" Until that has an answer, every delegation is an impersonation you authorized — and the only evidence it was you is that it had your password.
The HAIA Foundation keeps circling one idea: when a machine acts in your name, the terms should be yours to set, yours to see, and yours to withdraw. If that's an argument you'd like in your inbox rather than your rearview mirror, come along — no credentials required.






Ooooh, this is a great point! Impersonation is clearly suboptimal. Then there is a third option in which your agent books your flights with its own corporate credit card. This third option is less tied to a specific user, so the agent could make purchases on the behalf of multiple users--buying office supplies or catering an event. Shall we give agents money and trust them to spend some of it for the social good?