Friday, 2 October 202602:00 UTCWire updated 02:00 UTC

Follow @0xNotMarc

Notes from the Terminal
Delayed ·

The Morning Note

AI now runs inside the bank, and so do the risks

Barclays and Trust Bank show agentic AI doing real operational work, while a breach at Korea's Shinhan Bank and warnings from the ECB and Australia's central bank show why security and oversight need to keep pace.

From pilot to production

Barclays expects most of its developers to be using Anthropic's Claude Code by the end of 2027, and its Global Markets business already runs 120,000 client emails a day through Claude models. In Singapore, Trust Bank's AI agents now triage IT incidents in about two minutes, down from 15 to 20, and the bank says about 65% of their root-cause analyses are actionable before an engineer even joins the ticket. Both banks are describing AI inside daily operations, doing the first pass on work that people then act on.

Where it already breaks

Shinhan Bank said hackers broke into its loan broker login site on Wednesday and leaked loan amounts, annual income, names and phone numbers for about 25,000 customers, and sources told the Korea Herald the attackers, suspected to be overseas, used AI tools. An industry official told the paper the entire financial industry is vulnerable to AI agent-assisted attacks and that institutions need to run their own security inspections promptly. Customer-facing portals like this one belong at the top of that list.

Two central banks agree

On September 28, Christine Lagarde told the European Parliament that global equity valuations are concentrated in a small number of AI-related firms that are rapidly increasing their debt, with AI-related borrowing already around a quarter of credit growth to firms as they put roughly 10% of total investment into AI this year. Days later, Australia's central bank made a similar case in its Financial Stability Review. It warned that the AI boom runs on a debt-financing cycle that is becoming more opaque and circular, with chipmakers funding the neocloud firms that buy their products, and that AI agents could push markets into herd behavior as they take on more investment decisions.

The thread connecting them

So put these stories together: AI agents now do real operational work inside banks, the money financing AI itself is concentrated and increasingly circular, and the tools making banks faster are making attackers faster too. None of that argues against deploying agents. It argues for building the audit trail, the security budget and the kill switch at the same speed as the rollout.

What to watch next

Watch whether South Korea's financial watchdog finds Shinhan's gap was a one-off or something other loan broker portals share. And ask the question both central banks are raising: if sentiment on AI turns, what happens to the banks lending into it, when AI-related borrowing is already about a quarter of credit growth to firms by Lagarde's count?

The stories behind this note

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5