Skip to content
AI & Finance

HSBC's HSBCnio lets clients' AI tools access permitted account data

HSBC's new HSBCnio service lets corporate clients' authorised AI tools read permitted account and transaction data via the Model Context Protocol, using their existing HSBCnet login and permissions.

By

Published
A thick ledger sealed shut with wax, beside a single page cut free from it and propped upright on a small stand.

HSBC has launched a feature that lets corporate clients connect their own artificial intelligence tools through HSBC's Model Context Protocol implementation to retrieve permitted account and transaction information, rather than having a person log in and copy it out. The mechanism is the Model Context Protocol (MCP), an open standard for connecting AI applications to external data and tools. HSBC's version of it sits inside HSBCnio, a digital banking service for corporate and institutional clients that the bank launched on 29 September 2026, during Sibos 2026 in Miami. HSBC says features and availability vary by market and client configuration, and it has not published a confirmed UK availability date for AI-tool access.

This matters to UK finance and treasury teams because HSBC Bank plc, authorised by the Prudential Regulation Authority (PRA) and regulated by the Financial Conduct Authority (FCA) and the PRA under Financial Services Register number 114216, has published a UK product page for HSBCnio. That page says UK users keep their existing HSBCnet login and permissions when accessing the service through desktop, mobile or an MCP-connected AI tool. HSBC has not disclosed whether any additional credential or access control applies on top of that existing identity for the AI-connected route.

The timing is relevant because the FCA, the PRA and the Bank of England are introducing a new operational-incident and material third-party reporting regime for specified regulated firms, which takes effect from 18 March 2027. Any UK business connecting external AI tools to its banking data will be doing so against that backdrop, even though the available material does not establish that every HSBCnio–AI connection will count as a material third-party arrangement under those rules.

What HSBC has actually launched

HSBC says HSBCnio can be accessed through web and mobile channels, direct system connections, or a client's authorised AI tools. The capabilities it currently lists are: checking cash balances and transactions, tracking payments, and arranging trade loans and foreign exchange services. For integration, HSBCnio supports application programming interfaces (APIs) and connections into enterprise resource planning (ERP) and treasury management systems, backed by developer documentation, software development kits and a sandbox for testing. Host-to-host connectivity, a common method for moving files between a corporate system and a bank, is described on the UK page as planned for the future rather than available now.

HSBC's own description of MCP is that it gives AI agents structured, authenticated access to services and data, built on permissions and auditable controls that treasury use requires. That is HSBC's characterisation of its intended connectivity model. It is not an independent security assessment of HSBCnio, and no such assessment, certification or penetration-test result specific to this service has been published.

How the protocol fits in

MCP itself is not a banking product. Anthropic introduced it as an open standard on 25 November 2024, and in December 2025 the protocol was donated to the Linux Foundation's Agentic AI Foundation. It defines a common way for an AI application to ask an external system for data or to call a tool, so that a bank, or anyone else, does not need a bespoke integration for every AI product a client might use. Using MCP tells a reader that HSBC has adopted an open connection standard rather than a bespoke one. It does not, by itself, tell a reader what HSBC's implementation allows an AI tool to see, retain or do, because that detail is set by HSBC's own server configuration and the client's permissions, not by the protocol.

What a UK finance team could plug into this

For a treasury or finance function, the practical draw is reducing manual data-gathering. A permitted AI tool could, in principle, retrieve current balances and transaction details, or answer a query about those figures, using the same entitlements a staff member already has in HSBCnet. HSBC separately lists payment tracking among HSBCnio's capabilities, and the service supports API, ERP and treasury management system integrations, but the material reviewed does not confirm that an AI tool can combine these routes, retrieve payment status, or feed data into an ERP or treasury management system workflow. HSBC's own commentary on this area cites a Treasury Pulse Survey of more than 500 companies across 33 countries, published 11 September 2026, in which 53% of respondents named reducing operational costs, 50% lowering financing costs, and 48% adopting new technologies as treasury priorities. HSBC also cites research suggesting more than half of treasury functions worldwide run with fewer than ten full-time staff. These are global, company-supplied figures rather than UK-specific statistics, and the survey's fieldwork dates and methodology are not set out in the material reviewed for this article.

Where the controls sit, and where they do not

The strongest control HSBC has disclosed is identity continuity: HSBC says a UK user's AI-connected access runs on their existing HSBCnet login and permissions. Beyond that, HSBC has not published the technical detail a finance team would need to assess the connection properly, including whether any additional credential or authentication layer applies. There is no public specification of token scopes, session limits, audit-log format, or how access is revoked if a device, tool or employee changes. HSBC has not said whether account data passes into a third-party AI provider's infrastructure, whether it can be retained there, or whether it can be processed outside the UK. It has not detailed encryption, monitoring, defences against prompt injection, or safeguards against an AI tool returning information outside what a specific user is entitled to see.

What HSBC has confirmedWhat remains undisclosed
MCP access to authorised account and transaction informationNamed list of compatible AI tools or model providers
Existing HSBCnet login and permissions carried overToken scopes, session controls, revocation process
Balance checks, payment tracking, trade loans, FX listed as availableWhether any of these can be initiated, not just viewed, via an AI tool
Developer sandbox, SDKs and documentation for testingData location, retention, and use in third-party AI models
Features vary by market and client configurationA confirmed UK availability date, eligible client segments, and pricing

Read access now, "controlled execution" later

HSBC's launch announcement specifically confirms AI-tool access to authorised account and transaction information. A separate HSBC article on dynamic banking goes further, saying MCP can let clients retrieve information and initiate services, but that broader claim is not matched by confirmation, in the HSBCnio launch material, of which service-initiation functions are actually live through AI tools today. Reasonably, this should be read as read access to banking data now, with action-taking functions unconfirmed.

Ask HSBC: planned, not yet defined

HSBC describes a forthcoming feature called Ask HSBC, an AI agent intended to help users interpret account and payment information, connecting through HSBCnio's desktop and mobile channels. The UK product page is inconsistent in how it presents this: one section uses present-tense marketing language describing its benefits, while the page's own FAQ labels Ask HSBC "Coming soon." No launch date has been given. HSBC says the feature is intended to help teams move from interpreting information towards what it calls controlled execution, but it has not defined that phrase. There is no published detail on which transactions it might eventually carry out, what human approval or maker-checker sign-off would sit in front of any action, who would be liable for an erroneous AI-driven instruction, or whether Ask HSBC will be available through external AI tools as well as HSBC's own channels.

The UK legal backdrop

Where HSBCnio's account or transaction data includes personal data, UK GDPR Article 5 requires it to be adequate, relevant and limited to what is necessary, and protected against unauthorised processing or loss. The Information Commissioner's Office (ICO) has said that organisations using AI to process personal data should assess the resulting security risk, map how data flows through connected systems, and build in data minimisation from the design stage and during procurement of any third-party AI tool. None of this means an AI tool connecting to HSBCnio is itself FCA-regulated, or that a client automatically gains Financial Ombudsman Service or Financial Services Compensation Scheme cover through the connection.

What to watch

The clearest open questions are a confirmed UK availability date and eligible client types for HSBCnio's AI access, a named list of compatible AI tools, and whatever technical and contractual documentation HSBC eventually publishes on data location, retention and liability. Ask HSBC's actual launch, and the detail of what "controlled execution" permits, will be the next test of how far this moves from reading bank data to acting on it. Readers wanting the primary detail should go to HSBC's own HSBCnio product pages and developer documentation rather than to summaries, and firms assessing the FCA's incoming reporting regime should consult the FCA's published policy statement directly ahead of its effective date of 18 March 2027.

Sources

  1. HSBC launches HSBCnio digital banking solution for businesses (opens in a new tab)

    HSBC Holdings plc · · Accessed

  2. Sandbox Toolkit (opens in a new tab)

    HSBC · Accessed

  3. Introducing the Model Context Protocol (opens in a new tab)

    Anthropic · · Accessed

  4. How should we assess security and data minimisation in AI? (opens in a new tab)

    Information Commissioner's Office · Accessed

  5. PS26/2: Operational incident and third party reporting (opens in a new tab)

    Financial Conduct Authority · · Accessed