Welcome to AI for FIs, from Dixon Strategic Labs. Each week, this newsletter tracks agentic AI and explains what it means for community banks and credit unions.
At DBS, one of Southeast Asia's largest banks, a chain of agents does the research behind a corporate credit memo. Rockland Federal Credit Union, a $3.7 billion credit union in Massachusetts, runs about 2,000 dealer auto loan files a month through an automated review system Neither lender let the software approve a loan.
Zenity Labs, a security research firm, looked at a different problem. It had a worker sign in to ChatGPT and click one malicious link. That link led to a malicious agent, which inherited every app the worker had already connected, without a new approval. It read email and document stores, sent data outside the company, and posted a phishing message to colleagues.
DBS and Rockland can answer which systems their agents reach, which documents the answers came from, and who checked them. Nobody could have answered any of that about the agents in Zenity's test.
What is the collective noun for a group of agents, anyway?
A hallucination?
An aquifer?
J.k. Let’s dig in.
DBS checks the work between every stage
Sources: Computer Weekly, Jul 28 · DBS, Jul 20

DBS keeps its production agents behind identity checks, logs, policy rules, and an emergency stop.
Singapore-based DBS has strung together roughly 70 to 80 AI agents to prepare credit memos for large corporate loans. A relationship manager used to spend days reading market and industry reports, working through financial statements and annual reports, and meeting with the customer so the bank could judge whether the company could repay the loan and how much it might lend.
Now the agents gather those records and assemble a draft. The relationship manager questions it in chat and asks for its sources. A credit manager decides on the loan.
DBS uses 70 to 80 agents because smaller jobs are easier to control. An agent that handles dozens of tasks in sequence can bury a bad source or faulty conclusion deep in the chain. The failure then becomes harder to trace. Each of these agents does less: DBS gives each one a narrow job, limits the actions each one can take, and checks the work between stages. The bank gets more chances to catch an error and fewer steps to retrace. DBS also keeps agents built by employees walled off from live bank systems.
Nimish Panchmatia, DBS's data and transformation chief, says all of these controls are necessary right now because agents’ capabilities are developing 5x faster than our ability to control them.
DBS wraps its entire AI infrastructure in a system of controls that verifies identity, records every action, enforces policy, tests performance, and scans for security risks…all with a big red kill switch for when an agent goes off course.
Rockland CU increased its dealer auto loan reviews by 567%
Sources: CU Today, Jul 27

Rockland's software flags exception files, and lending staff still make the loan decisions.
Rockland Federal Credit Union is a $3.7 billion credit union in Massachusetts. It processes about 2,000 indirect auto loans (loans made at the dealers) each month. Traditionally, the staff has had capacity to check around 15% of the files for quality, and each review took about 20 minutes.
Kintera AI turned Rockland's policy checklist into an automated document review. The software reads each file, applies 55 compliance checks, records each decision, and sends flagged files to lending staff. People handle the lending decision and the exceptions.
Rockland says review time fell from about 20 minutes to two. Quality checks expanded from 15% of files to every file. Their chief lending officer estimates $250,000 in annual savings.
Rockland's indirect auto production has nearly tripled since the project began, without added staff (note that the reporting doesn’t specify how much of that growth came from Kintera). Next up, Rockland is extending the review to mortgage files, which can exceed 600 pages.
One malicious link built and scheduled a hidden ChatGPT workspace agent
Sources: SecurityWeek, Jul 23 · Zenity Labs' AgentForger report, Jul 23

Zenity mapped the normal builder path that AgentForger drove from a malicious link. Source: Zenity Labs.
OpenAI's ChatGPT Workspace Agents lets employees build agents that can use email, access cloud files, and message the team chat. Zenity Labs, a security research firm, wanted to know what one bad link could do inside it. The firm had a worker sign in to ChatGPT and click a malicious link. Hidden commands in the link did the rest.
The commands built a new agent inside the worker's ChatGPT account and attached the apps the worker had already connected. The agent could reach that person's email and files without a new approval. The commands also changed Outlook's write setting from "Always ask" to "Never ask," published the agent, and scheduled it to run about every five minutes.
The agent got to work. In Zenity's test, it searched email and document stores, sent data out, posted an internal phishing message, and prepared a wire-fraud lure.
Take a peek:
All the attack needed was a signed-in ChatGPT user with Workspace Agents, at least one connected app, and a click on the malicious link.
Zenity named the flaw AgentForger and reported it on June 4. OpenAI fixed it on June 8, and the researchers made the flaw public on July 23.
Agent builders are arriving inside tools staff already use, and employee-built agents can inherit their creator's access to connected apps and permissions. The exposure begins as soon as an org turns on the feature. An institution needs records of who can create agents, which apps they can reach, and whether they can run on their own schedules.
A useful inventory records each agent's reach, schedule, outbound messages, permission changes, owner, and removal status. A revocation test can show whether cutting access stopped the agent.
Prompt injection was part (but not all) of the Zenity attack path. It happens when an AI system treats untrusted text as instructions. Here, attacker-written instructions were packed into a URL, and ChatGPT’s Agent Builder submitted them as if the employee had entered them. In this case, the flaw that made the hack possible is a type of attack called a Cross Site Request Forgery (CSRF).
One great (and very different) example of prompt injection in the wild is this teacher who used it to catch his students cheating:
Lawyer and journalist Kate Klonick gives us the flow chart for navigating any and all AI crises.

Kate Klonick, “AI Crisis Flowchart,” shared on LinkedIn.
On the Radar
Glia’s customer service AI now sets response rules by topic. Strict Mode repeats approved text, and Rephrase Mode reworks it. Compose Mode writes new answers from approved documents. Its Zero Hallucination Guarantee covers Strict Mode only.
Genpact put five agents on the first review of anti-money-laundering alerts. Australia's AMP Limited is deploying them. Genpact claims up to 80% faster handling and up to 10% less manual work.
The UK AI Security Institute fooled agents that monitor other agents. It found flaws in every Anthropic monitor it tested and in one from Google DeepMind.
Presence is OpenAI’s new service for companies to build and run voice and chat agents. Each agent gets one task and only the access it needs. Spanish bank BBVA is evaluating it for everyday banking support in Mexico, CIO reports.
Natural launched six payment products for AI agents, including Vaults, an account an agent can put money into but cannot take money out of. Pay and Request move funds to and from agents, businesses, and consumers. The company plans 13 products in all, with debit and charge cards for agents due in the coming months and lines of credit in Q4.
OpenWorker is an open-source desktop agent in open beta. It works across files, more than 25 apps, and a local terminal, then asks for approval before it sends a message, changes a calendar, or runs a command. A bounded test can use sample files and separate credentials to verify that those approval prompts really do appear every time.
d1g1t joins a growing group of financial platforms opening their data and tools to AI agents through Model Context Protocol (MCP). Fifth Third’s Newline, Blend, Bud Financial, and Digits now offer connections for payments, lending, transaction data, or accounting.
Agentic AI is rewriting operational rules. I help community-finance leaders learn with their hands and sort out what this means for their strategy. Drop me a note at [email protected].
How this newsletter is made: Brent curates the research and writes the analysis, with AI tools helping with research, drafting, and editing. It is published on Beehiiv. ⚡ Alakazam ⚡.
A colleague sorting out AI governance, vendor risk, lending, fraud, or member and customer trust can subscribe to AI for FIs here.



