What AFSP v0.1 Won't Let Your Agent Do
The first agent-to-bank protocol requires three minutes of cryptographic handshaking to open a savings account.
The first formal standard for how AI agents talk to banks is 57 pages long. It covers one use case: opening a savings account.
AFSP, the Agentic Financial Services Protocol, went to public review on September 28. The spec is architecturally serious.
FIDO2 biometric consent on enrolled devices. Hardware TEE-signed authorization tokens. ECDSA-P256 cryptography. A five-signal attestation package the agent must present before the bank sees a single API call.
All of it for the lowest-risk operation in consumer banking.
I think the protocol gets the trust architecture right. I also think starting with account opening tells you exactly how far the industry is from letting agents touch money.
Five signals for a savings account
Before an agent can open an account on your behalf, it has to assemble what AFSP calls a Pre-Credential Agent Attestation. Five signals, bundled into a cryptographically signed package, verified before any API access.
S1 is agent provenance. A certified, registered, unmodified build from an accountable operator. The operator registers the agent in an AFSP certification registry, except that registry, AFSP-07, is still on the roadmap.
S2 is biometric consent. You authorize the session on your enrolled device using FIDO2. Your phone's secure enclave signs a token that locks down what the agent can do: which action classes, which product categories, what time window. The agent cannot expand its own scope.
S3 is a federated referral. Optional. A bank you already have a relationship with vouches for your identity, sharing only the data you have explicitly permissioned under Section 1033.
S4 is financial identity. Behavioral signals consistent with an established financial profile. Transaction history that matches who you claim to be.
S5 is session integrity. Conditional. Is a human actually operating this session, and does the behavior fall within normal parameters?
The whole handshake takes about two minutes and fifty seconds. Then the agent opens a savings account. The session ends.
What the roadmap reveals
The weight of PCAA makes more sense when you see what AFSP plans to do next. Six more components beyond v0.1. Three of them point directly at where the hard problems live.
AFSP-09 is Pre-Execution Revalidation. Before each action in a session, re-verify that the authorization still holds. This matters when the agent's next action is a $50,000 wire transfer. It does not matter for a savings account application.
AFSP-10 is the Behavioral Envelope Engine. Real-time monitoring of whether the agent stays within the boundaries the human defined. You authorized "open a high-yield savings account." The agent starts browsing brokerage products. Something needs to intervene.
AFSP-12 is Post-Opening Session Continuity. What happens after the account exists? Can the agent fund it? Move money in? Set up recurring deposits? v0.1 does not say.
These three components mark the line where identity stops being the problem and authorization begins. Proving who you are uses mature tools: FIDO2, biometrics, device attestation, cryptographic signing. That infrastructure works. Defining what an agent can do with your money, monitoring it in real time, deciding who absorbs the loss when it exceeds its scope: none of that has shipped.
AFSP v0.1 builds the identity layer and stops at the edge of the authorization layer.
The Robinhood contrast
While AFSP assembled its attestation framework and opened a public comment period, Robinhood shipped.
At Hood Summit 2026, Robinhood announced agent integration through MCP server endpoints. Since May, 150,000 customers have connected AI agents to their brokerage accounts. Those agents process roughly 30 million tool interactions per day. Free until year-end, with a subscription or per-agent fee expected in January.
Robinhood built MCP endpoints, let agents call them, and wrapped rate limits and existing risk controls around the edges. The entire integration shipped without a protocol spec, an attestation framework, or a governing foundation.
AFSP says: standardize the trust layer before agents access financial systems. Robinhood says: ship the integration, instrument everything, learn from production traffic.
Neither is obviously wrong. AFSP's caution makes sense when the failure mode is an agent draining a checking account. Robinhood's speed makes sense when the agent operates within risk controls Robinhood already enforces for human traders.
But the gap between the two approaches is measured in years. AFSP's governing foundation will not form until early 2027. The public comment period on v0.1 runs through November 16. By the time AFSP-09 through AFSP-12 are ratified, Robinhood will have processed billions of agent interactions and built its risk model from observed behavior, not protocol specification.
What AFSP cannot solve alone
AFSP is authored by Primitive, a startup serving as interim protocol administrator. Visa, Mastercard, and Ant International are building their own agent trust framework. ACP, AP2, and x402 are competing on agent payment authorization. The compliance stack is assembling its own layers. Policy engines are shipping independently.
Multiple groups building different slices of the same puzzle. No single authority deciding how they connect.
AFSP's slice is specific and well-built. The four-party trust model puts control where it belongs, with the consumer, who retains sovereign authority and approves every step on their own device. Tamper-evident audit trails are retained for seven years. Examination-ready from day one.
But account opening is the operation that needs this infrastructure least. Who is liable when an agent buys the wrong thing? What replaces strong customer authentication when the payer is software? How does dispute resolution work when there is no chargeback code for "my agent hallucinated"?
I have been tracking these questions for months. None of them have a protocol answer yet.
Fifty-seven pages of protocol for a savings account is a strong foundation. Nobody has written the spec for what happens when the agent needs to move $50,000. That version of AFSP is the one worth watching.
Sources
- AFSP v0.1 Public Review Draft - Protocol specification, PCAA architecture, four-party trust model, and roadmap components AFSP-07 through AFSP-12
- AFSP GitHub Repository - Public comments and extension proposals, open through November 16, 2026
- Robinhood Hood Summit 2026 - Agent integration announcement, MCP endpoints, 150,000 agentic accounts since May
- Airwallex: The Agentic Banking Era - Jack Zhang on agent-to-bank infrastructure and why banks lack MCP endpoints
Frequently Asked Questions
Built by Trio, a fintech-native engineering partner helping teams build the next generation of financial technology and infrastructure.
Subscribe to Ledger Drift for high-signal insights into how modern fintech is built, from systems to code to teams.