Skip to content
AI & Finance

Form3 gives banks read-only AI access to payment data

Form3 has launched an adaptor letting authorised AI agents read but not act on payment data, a cautious opening move that leaves UK banks' governance duties unchanged.

By

Published
An open ledger book on a wooden lectern next to a sealed glass case containing a single fountain pen that cannot be reached.

Form3, the UK payments infrastructure provider, announced on 23 September 2026 that it has launched what it calls AI-enabled payments infrastructure, with an initial adaptor built on the Model Context Protocol (MCP) — an emerging standard through which AI applications connect to external tools and data. The adaptor lets authorised AI agents and staff using natural-language interfaces retrieve and interpret existing payment information held on the Form3 platform. Form3 says those agents are read-only: they cannot initiate changes and remain outside the payment flow itself.

The launch matters to UK banks and payment firms because it sets out a proposed use of agentic AI in core payment operations, at a moment when the Financial Conduct Authority (FCA) is actively examining how such systems fit its existing rules on accountability, operational resilience and third-party risk. Form3 names Barclays, Santander and JPMorgan among institutions that trust its platform, though — as set out below — that is not the same as saying any of them has deployed this particular adaptor.

What Form3 has launched

Form3's announcement describes the MCP adaptor as exposing existing payment information to authorised AI applications through an application programming interface (API). The stated use case is payment operations: helping teams investigate and resolve payment issues by letting an agent query and interpret data that would otherwise require a manual search across systems. Form3 says the AI layer wraps around its existing platform and remains subject to that platform's existing data and security controls, and that payments continue to move through its existing processing infrastructure rather than through the AI layer.

This is a vendor description. FinTechPulse found no independent technical assessment, product specification or customer case study that verifies how the adaptor is built, what data fields it exposes, or how tightly access can be scoped by customer, account, payment rail or role.

Read-only, explained

The distinction Form3 draws is between retrieving and interpreting information on one hand, and initiating, approving, amending or rerouting a payment on the other. Under the adaptor as described, an agent can only do the former. It cannot move money.

That is a materially different model from Santander's separate pilot with Mastercard, completed on 2 March 2026, in which an AI agent initiated and executed a live payment within predefined limits in a controlled environment. Santander described that as Europe's first live end-to-end payment executed by an AI agent, but it was not a commercial rollout. Form3's adaptor and the Santander-Mastercard pilot are different products built on different control models; readers should not treat them as versions of the same thing.

The efficiency pitch — and what's missing

Form3 says the adaptor can help operations teams investigate and resolve payment issues, reduce manual workloads and lower operational costs by allowing natural-language queries in place of manual data retrieval across systems. That claim is Form3's own; it remains unquantified and independently unverified. The FCA's separate multi-firm review of frontier AI and cyber resilience, published on 2 September 2026, found that firms generally see AI's value as dependent on the governance, tooling, validation and human expertise surrounding it — a general finding about AI adoption, not a validation of Form3's claims for this specific adaptor.

However, Form3 supplied no adaptor-specific customer result, benchmark, time saving, cost saving, deployment count or pilot count as of 25 September 2026. It also describes its underlying infrastructure as trusted by "hundreds" of financial institutions, without a precise number, methodology or as-of date. That figure describes Form3's broader platform, not adoption of this new adaptor, and should not be read as evidence of MCP-specific uptake.

The security boundary, and its limits

Preventing an agent from writing data or initiating payments reduces one specific risk: that the interface itself could be used to move money in error or without authorisation. That is a reasoned inference from the stated permission boundary, not a demonstration of complete security.

Read-only access does not remove several other risks that UK regulators and the Information Commissioner's Office (ICO) have flagged for agentic AI generally:

  • Confidentiality and data exposure. Reading sensitive payment information still requires strong authentication, authorisation and minimisation controls. The ICO's guidance on agentic AI says organisations need a defined purpose for processing personal information and should not give an agent access merely because the information might prove useful later. It points to granular permissions, careful tool and database selection, data masking, observability and human permission as possible controls — none of which Form3's announcement specifies for this adaptor.
  • Inaccurate outputs. An agent can still misinterpret or misstate what the underlying payment data shows. The ICO warns that inaccurate AI-generated information can cascade across tools, databases or other agents once it is acted on.
  • Protocol maturity. Form3 describes MCP as a standardised way to connect AI applications to tools and data. The MCP project's own specification update, published 28 July 2026, shows that authorisation and security hardening — including issuer validation and issuer-bound credentials — remain active areas of development for the protocol itself. Standardisation is not, by itself, an assurance of security.
  • Model and data handling. FinTechPulse could not establish which AI models or hosting providers the adaptor supports, where processing takes place, whether prompts and retrieved payment data are logged or retained, or whether any of that information reaches a model provider's systems or is used for training.

What UK banks must still govern

None of this changes where regulatory accountability sits. The FCA's guidance on outsourcing to the cloud and other third-party IT services (FG16/5) states that regulated firms retain full responsibility and accountability for their regulatory obligations and cannot delegate that responsibility to a third party. The Prudential Regulation Authority's supervisory statement SS2/21 on outsourcing and third-party risk management has applied in its current form since 31 December 2024; a revised version was published on 18 March 2026 but does not take effect until 18 March 2027, when new material third-party reporting arrangements are also due.

The FCA has said accountability for regulated activities and outcomes must remain clear as agentic systems develop, and in a speech on 24 June 2026 its chief executive noted that 98% of operational incidents reported to the FCA in 2025 related to technology and cyber issues — though the speech did not give the underlying number of incidents. Separately, the FCA's review into the long-term impact of AI on retail financial services (the Mills Review, published 27 January 2026) says the regulator does not plan AI-specific regulation and is instead examining how existing accountability, operational-resilience and third-party frameworks apply.

The practical implication for a UK bank considering Form3's adaptor is that it remains accountable for its regulatory obligations and must assess which existing third-party risk management, operational resilience, data protection and audit requirements apply to its particular implementation — including whether the arrangement falls within an outsourcing or material third-party perimeter — regardless of how the AI layer is marketed.

InstrumentPublisherStatus
FG16/5 cloud and third-party outsourcing guidanceFCAPublished 6 July 2016; currently applicable
SS2/21 outsourcing and third-party risk managementPRA/Bank of EnglandCurrent version in effect since 31 December 2024; revised version takes effect 18 March 2027
Mills ReviewFCAPublished 27 January 2026; no new AI-specific rules proposed
Frontier AI and cyber resilience reviewFCAPublished 2 September 2026; introduces no new rules or expectations

Barclays and Santander: relationship, not confirmed use

Form3's launch announcement names Barclays, Santander and JPMorgan among banks that trust its platform. That wording is Form3's own characterisation of its broader customer relationships, not evidence of adoption of the MCP adaptor specifically. For Barclays, a separate Form3 announcement documents a longstanding partnership giving fintech customers direct technical access to SEPA Instant and SEPA Credit Transfer services, including a statement from a Barclays executive — but that announcement concerns SEPA connectivity and does not reference the MCP adaptor. No equivalent documented partnership was found for Santander or JPMorgan, and FinTechPulse found no confirmation from either bank that it has deployed, tested or contracted for the new adaptor.

Santander's confirmed AI-agent activity is the separate Mastercard pilot described above, which is a transaction-capable design distinct from — and a useful contrast to — Form3's read-only approach.

What's not yet known

Several questions bear directly on how much weight to put on this launch. Form3 has not disclosed whether the adaptor is generally available, in private preview, or limited to specific pilot customers. It has not specified which payment data fields agents can retrieve, how access is scoped, which identity and authorisation mechanisms are used, whether queries and outputs are logged for audit, or how a bank could independently verify an agent's interpretation against the underlying payment records. No independent penetration test, assurance report or regulatory assessment of the adaptor has been located.

What to watch next

The clearest signals of how far this moves beyond an announcement will be a published technical specification from Form3, a named bank confirming a live deployment or pilot, an independent security or assurance assessment, and measured operational results such as investigation-time or cost reductions from an actual customer rather than a vendor claim. Readers wanting the underlying regulatory detail should consult the FCA's published frontier AI review and the Mills Review directly, and the PRA's SS2/21 for third-party risk expectations, rather than relying on vendor summaries of them.

Sources

  1. Frontier AI and cyber resilience (opens in a new tab)

    Financial Conduct Authority · · Accessed

  2. Data protection and privacy risks (opens in a new tab)

    Information Commissioner's Office · Accessed

  3. Rethinking regulation for the age of AI (opens in a new tab)

    Financial Conduct Authority · · Accessed

  4. SS2/21 – Outsourcing and third party risk management (opens in a new tab)

    Prudential Regulation Authority and Bank of England · · Accessed

  5. The 2026-07-28 Specification (opens in a new tab)

    Model Context Protocol project · · Accessed