Subscribe to get high-signal insights on how modern fintech is built.

opinion

What AFSP v0.1 Won't Let Your Agent Do

The first agent-to-bank protocol requires three minutes of cryptographic handshaking to open a savings account.

By Alex Kugell ·

The first formal standard for how AI agents talk to banks is 57 pages long. It covers one use case: opening a savings account.

AFSP, the Agentic Financial Services Protocol, went to public review on September 28. The spec is architecturally serious.

FIDO2 biometric consent on enrolled devices. Hardware TEE-signed authorization tokens. ECDSA-P256 cryptography. A five-signal attestation package the agent must present before the bank sees a single API call.

All of it for the lowest-risk operation in consumer banking.

I think the protocol gets the trust architecture right. I also think starting with account opening tells you exactly how far the industry is from letting agents touch money.

Five signals for a savings account

Before an agent can open an account on your behalf, it has to assemble what AFSP calls a Pre-Credential Agent Attestation. Five signals, bundled into a cryptographically signed package, verified before any API access.

S1 is agent provenance. A certified, registered, unmodified build from an accountable operator. The operator registers the agent in an AFSP certification registry, except that registry, AFSP-07, is still on the roadmap.

S2 is biometric consent. You authorize the session on your enrolled device using FIDO2. Your phone's secure enclave signs a token that locks down what the agent can do: which action classes, which product categories, what time window. The agent cannot expand its own scope.

S3 is a federated referral. Optional. A bank you already have a relationship with vouches for your identity, sharing only the data you have explicitly permissioned under Section 1033.

S4 is financial identity. Behavioral signals consistent with an established financial profile. Transaction history that matches who you claim to be.

S5 is session integrity. Conditional. Is a human actually operating this session, and does the behavior fall within normal parameters?

The whole handshake takes about two minutes and fifty seconds. Then the agent opens a savings account. The session ends.

Pre-Credential Agent Attestation
S1Agent ProvenanceCertified, registered, unmodified buildrequired
S2Biometric ConsentHuman authorized on enrolled device via FIDO2required
S3Federated ReferralPrior KYC from a trusted institutionoptional
S4Financial IdentityBehavioral signals match established profilerequired
S5Session IntegrityHuman-operated, normal behavioral parametersconditional
PCAA Package
ECDSA-P256 signed · nonce-verified · validity window enforced
Bank API · Account Opening
Savings account opened · ~2 min 50 sec

What the roadmap reveals

The weight of PCAA makes more sense when you see what AFSP plans to do next. Six more components beyond v0.1. Three of them point directly at where the hard problems live.

AFSP-09 is Pre-Execution Revalidation. Before each action in a session, re-verify that the authorization still holds. This matters when the agent's next action is a $50,000 wire transfer. It does not matter for a savings account application.

AFSP-10 is the Behavioral Envelope Engine. Real-time monitoring of whether the agent stays within the boundaries the human defined. You authorized "open a high-yield savings account." The agent starts browsing brokerage products. Something needs to intervene.

AFSP-12 is Post-Opening Session Continuity. What happens after the account exists? Can the agent fund it? Move money in? Set up recurring deposits? v0.1 does not say.

These three components mark the line where identity stops being the problem and authorization begins. Proving who you are uses mature tools: FIDO2, biometrics, device attestation, cryptographic signing. That infrastructure works. Defining what an agent can do with your money, monitoring it in real time, deciding who absorbs the loss when it exceeds its scope: none of that has shipped.

AFSP v0.1 builds the identity layer and stops at the edge of the authorization layer.

AFSP coverage: shipped vs. roadmap
Identity
AFSP-01 – 06
Pre-Credential Agent Attestation
Five signals, PCAA assembly, account opening
v0.1
Authorization
AFSP-07
Agent Certification Registry
Who certifies agent builds and maintains the registry
roadmap
AFSP-09
Pre-Execution Revalidation
Re-verify authorization before each action in a session
roadmap
AFSP-10
Behavioral Envelope Engine
Real-time monitoring of agent scope boundaries
roadmap
AFSP-12
Post-Opening Session Continuity
What the agent can do after the account exists
roadmap

The Robinhood contrast

While AFSP assembled its attestation framework and opened a public comment period, Robinhood shipped.

At Hood Summit 2026, Robinhood announced agent integration through MCP server endpoints. Since May, 150,000 customers have connected AI agents to their brokerage accounts. Those agents process roughly 30 million tool interactions per day. Free until year-end, with a subscription or per-agent fee expected in January.

Robinhood built MCP endpoints, let agents call them, and wrapped rate limits and existing risk controls around the edges. The entire integration shipped without a protocol spec, an attestation framework, or a governing foundation.

AFSP says: standardize the trust layer before agents access financial systems. Robinhood says: ship the integration, instrument everything, learn from production traffic.

Neither is obviously wrong. AFSP's caution makes sense when the failure mode is an agent draining a checking account. Robinhood's speed makes sense when the agent operates within risk controls Robinhood already enforces for human traders.

But the gap between the two approaches is measured in years. AFSP's governing foundation will not form until early 2027. The public comment period on v0.1 runs through November 16. By the time AFSP-09 through AFSP-12 are ratified, Robinhood will have processed billions of agent interactions and built its risk model from observed behavior, not protocol specification.

What AFSP cannot solve alone

AFSP is authored by Primitive, a startup serving as interim protocol administrator. Visa, Mastercard, and Ant International are building their own agent trust framework. ACP, AP2, and x402 are competing on agent payment authorization. The compliance stack is assembling its own layers. Policy engines are shipping independently.

Multiple groups building different slices of the same puzzle. No single authority deciding how they connect.

AFSP's slice is specific and well-built. The four-party trust model puts control where it belongs, with the consumer, who retains sovereign authority and approves every step on their own device. Tamper-evident audit trails are retained for seven years. Examination-ready from day one.

But account opening is the operation that needs this infrastructure least. Who is liable when an agent buys the wrong thing? What replaces strong customer authentication when the payer is software? How does dispute resolution work when there is no chargeback code for "my agent hallucinated"?

I have been tracking these questions for months. None of them have a protocol answer yet.

Fifty-seven pages of protocol for a savings account is a strong foundation. Nobody has written the spec for what happens when the agent needs to move $50,000. That version of AFSP is the one worth watching.

Sources

Frequently Asked Questions

What is AFSP and what does it cover?
The Agentic Financial Services Protocol is the first formal standard for AI agent-to-bank communication. Version 0.1, published September 28, 2026, covers one use case: opening a deposit account. It requires five attestation signals including FIDO2 biometric consent and hardware-signed authorization tokens.
Can AI agents make payments through AFSP?
No. AFSP v0.1 only covers account opening. Payments, transfers, credit applications, and trading are not in the current spec. Components for pre-execution revalidation and behavioral monitoring are on the roadmap but have not shipped.
How does AFSP compare to Robinhood's agent integration?
AFSP requires a five-signal attestation package and a 57-page protocol spec before agents access bank APIs. Robinhood shipped MCP endpoints directly, onboarding 150,000 agent accounts with 30 million daily tool interactions since May 2026, without a formal protocol standard.
Who created the AFSP protocol?
Primitive authored the spec and serves as interim protocol administrator. The AFSP Foundation, which will govern the standard through open working groups, is targeted to form in early 2027. Public comments on v0.1 are open through November 16, 2026.

Built by Trio, a fintech-native engineering partner helping teams build the next generation of financial technology and infrastructure.

Subscribe to Ledger Drift for high-signal insights into how modern fintech is built, from systems to code to teams.

Keep reading

ai & mlTabular Foundation Models Are Coming for Your Risk TeamNVIDIA's Kumo Tabular compresses months of model-building into one forward pass. The catch is that regulators still want...
analysisThe Card Networks Are Going Back to Co-opsThe two largest card networks chose to co-own their stablecoin instead of controlling it outright.
opinionFinancial Inclusivity Is a MythThe systems fintech operates around are designed to benefit those with money. The math of lending to the underserved doe...
View more ›