InsightsResearch · AI & finance

How AI Agents Will Change Corporate Finance

Where agentic AI is already working in treasury and payments, what the card networks and banks shipped in 2025 and 2026, the protocols underneath, and the control model that separates a governable agent from a liability.

An AI agent, in the sense that matters for banking, is software that can read a company's financial position, decide what to do about it within a policy, and act: prepare a payment, sweep a balance, hedge an exposure, reconcile a ledger. In 2024 that was a demonstration. By 2026 it is in production at large banks and in a growing number of corporate treasuries. This piece is about what has actually shipped, what the plumbing looks like, and what has to be true for a company to let an agent near its money.

What has shipped

The card networks

Mastercard announced Agent Pay on 29 April 2025 and Visa announced Intelligent Commerce within a day of it. Both work the same way at the core: a tokenised credential is bound to a specific agent, a specific merchant scope and a consent policy set by the account holder, so the agent never holds a raw card number and cannot spend outside its mandate. Mastercard completed the first live agentic transaction on 29 September 2025. Visa published its Trusted Agent Protocol on 14 October 2025 to let merchants distinguish authorised agents from bots, and both networks joined Google's Agent Payments Protocol. In June 2026 Mastercard extended the model to machine-to-machine payments with Agent Pay for Machines, and on 10 June 2026 Visa announced its integration into OpenAI's models, allowing an agent in ChatGPT to pay on the Visa network within user-set limits.

The banks

Goldman Sachs is building autonomous agents for trade accounting and client onboarding. Lloyds Banking Group committed to enterprise-wide agentic deployment in 2026, targeting around GBP 100 million of value from automating fraud investigations and complex complaints. J.P. Morgan's payments group describes a treasury agent loop of sense, predict, decide, execute and audit, with an agent detecting an overnight FX exposure and queuing a hedge for human approval inside policy bands as the canonical example. Oracle extended its agentic platform to corporate banking in April 2026. Fewer than one in ten large global companies had deployed AI in treasury when J.P. Morgan wrote that, which tells you how early this still is on the corporate side.

The corporate side

Mid-market and large corporates are running agents that ingest invoices, match them to purchase orders, batch payment runs, initiate ACH and SEPA disbursements and manage intraday liquidity. Surveys in 2026 put current adoption of agentic AI among finance leaders in single digits with a large majority planning to adopt within a year, which is the usual shape of an early curve. AI-enabled cash forecasting is showing 20 to 30% accuracy improvements over traditional methods in reported deployments.

The plumbing: how an agent talks to a bank

The piece that made this practical is a standard interface. The Model Context Protocol, released by Anthropic in November 2024, gives an AI model a uniform way to discover and call tools and data sources: read balances, fetch statements, prepare a payment, check a policy. A bank that exposes an MCP server can be used by any agent a client already runs, whether that is a family office's finance assistant, an ERP's built-in AI or the bank's own. A directory of banks shipping MCP interfaces began appearing in 2026, and the first production examples, like a ratings agency cutting credit-memo preparation from 40 hours to minutes, are exactly the sort of narrow, auditable task the protocol suits.

The same openness is the risk. Security researchers have shown that malicious instructions can be hidden inside the descriptions MCP tools present to an agent, and analysts have warned that banks adopted the protocol faster than the security frameworks around it. The answer is not to avoid the protocol. It is to treat every agent call as an untrusted request that must pass the same authorisation, policy and logging as a human user's, which is the control model set out below.

The control model that makes it safe

Every credible framework for agentic finance, from the US Treasury's AI risk management framework published in February 2026 to the governance guidance of NIST and ISO 42001, converges on the same structure. It has four parts.

  1. Policy before deployment. Humans define approval thresholds, reserve floors, permitted counterparties, netting logic and escalation rules as machine-readable constraints. The agent reads them; it cannot change them.
  2. Tiered autonomy. Below a threshold, within policy, the agent acts and every action is logged and reversible. Above it, the agent prepares and a person approves. Outside policy, the agent cannot act at all and the request is escalated.
  3. Pre-transaction enforcement. Policy is checked before execution, in the payment system, not reviewed after the fact in a report.
  4. An immutable, replayable audit log. Every decision links to its inputs, the policy it applied, its confidence and the human who approved it. Internal audit should be able to replay any agent decision end to end.

What the sceptics get right

  • Explainability lags speed. In a 2026 Association for Financial Professionals survey, only 32% of treasury practitioners using AI agents said they could fully explain how an agent reached a recommendation under audit conditions.
  • Human-in-the-loop is not free. An IMF note on agentic payments in 2026 observes that approval delays can themselves create liquidity risk and blunt hedging. The answer is well-designed thresholds, not approval of everything.
  • Correlated behaviour. If many companies run similar agents on similar signals, they may act in the same direction at once. Banks and regulators are beginning to stress-test for it.
  • Regulatory classification. The EU AI Act is likely to treat agents that take consequential financial actions as high-risk, which brings human-oversight, auditability and conformity-assessment obligations.

What changes for a corporate customer

Three things, in order of how soon they arrive. First, the busywork goes: reconciliation, invoice matching, statement retrieval and routine reporting become agent tasks, with humans reviewing exceptions. Second, treasury becomes continuous rather than periodic: cash positions, FX exposures and covenant headroom are watched and acted on within policy every hour, not reviewed every month. Third, and this is the structural shift, the bank's product surface becomes something a company's own software calls. The banks that win will be the ones whose accounts, payments and treasury products can be safely operated by an agent inside the customer's policy, rather than the ones with the most impressive assistant of their own.

Where Mosaic fits

Mosaic is being designed so that software agents can work across a company's finances while staying inside the approval policies, permissions and controls the business has set. The platform's approval thresholds, reserve floors and audit trail apply to an agent exactly as they apply to a person, and a native MCP server is on the roadmap so that any agent a client already runs can connect. These capabilities are in development and not yet live; talk to our team if you want to shape them.

Sources

  1. J.P. Morgan Payments, agentic AI in corporate cash and treasury management
  2. Mastercard, Agent Pay for Machines (June 2026)
  3. Digital Commerce 360, how Visa and Mastercard are approaching agentic commerce (April 2026)
  4. Eco, Mastercard Agent Pay vs Visa Trusted Agent 2026
  5. IMF Notes 2026/004, how agentic AI will reshape payments
  6. Stacklok, state of Model Context Protocol in financial services 2026
  7. The Financial Brand, why banks need MCP guardrails before access control slips
  8. Oracle, extends agentic AI platform to corporate banking (14 April 2026)
  9. PYMNTS, AI agents help treasurers move faster (2026)
  10. Kyriba, agentic finance: a no-hype guide for treasury teams

This article is general information as at its publication date and not legal, tax, regulatory or investment advice. Requirements and figures change; confirm current rules with a licensed Cayman Islands adviser and the relevant institution before acting.

More insights

All insights →
Guide · Offshore finance
How to Open a Corporate Account in the Cayman Islands
Guide · Treasury
Accounts for Cayman Investment Funds: A Practical Guide
Insight · Stablecoins
USDC vs USDT for Corporate Treasury

Your offshore entity deserves a better financial platform.

Accounts, payments, FX, stablecoins and treasury in one platform built for global companies.

Prefer to speak first? Talk to our team →