Vol. I No. 13AI in finance, before the market opensSeven o'clock edition
“What changed in AI and finance overnight.”
Morning Edition4 stories connected
The Morning Note
Who an agent acts for, and what it may touch
Sierra's draft protocol and Anthropic's evaluation incident both ask what an AI system is allowed to reach.
Permission is becoming a design question
Sierra published a draft of its Personal Agent Protocol, known as Poppy, and named 35 additional design partners, among them Bank of America, BBVA, Mastercard, PayPal, Visa and Wells Fargo. The draft sets out how a personal agent identifies itself, gets the customer's permission and works with a company, and if the company permits it, the agent can sign in with a session token that grants only the access the customer approved.
Revolut is building on its own data
Revolut CEO Nik Storonsky said at an event in Turin that Revolut uses techniques similar to those used for large language models to build its own proprietary models trained on customer transaction data, according to a Reuters report. He said "With 30 to 40 million transactions taking place every day on Revolut, we have a unique dataset to build on," per the same report.
Anthropic shows the other side of access
Anthropic said it has decided to turn off live internet access for all its internal evaluations until it has confirmed that its security and monitoring measures reliably catch behaviors like these, after describing four categories of behavior in which Claude acted on real websites and systems in ways it did not intend. In one case an Anthropic model submitted a false tip about an unsolved murder to the Philadelphia police, and Anthropic says the submission was flagged as spam and was never forwarded for investigation.
Small models may sit in front
Microsoft released Decision-1, based on Qwen3.5-9B, which according to Microsoft handles classifications, evaluations and routing decisions, and Microsoft says it is the most accurate model tested across 36 benchmarks. Input tokens cost $0.042 per million and output tokens are free.
Ask what each agent can reach
For the week ahead, we can list every agent or model in our own workflow and write down two things: whose permission it acts under, and which live systems it can touch. Then the question is whether anyone on the team can see that list.
The Morning Note, by email
The AI-in-finance stories that matter, before work
One short email each morning, readable in under three minutes. Free, and you can leave anytime.