Welcome to AI for FIs, from Dixon Strategic Labs. Each week, this newsletter tracks agentic AI and explains what it means for community banks and credit unions.

ConnectOne Bank and nCino built two AI agents for the bank's commercial lending operations. One updates individual and business relationship information in documents. The bank says employees spent 60% less time on that work within three months.

Bank of America's EricaAssist works with more than 18,000 customer-service employees. During a call, it pulls together relevant client information and recommends the next step. The bank says the average call is around one minute shorter.

OpenAI reported a different result. For an internal security test, the company weakened safeguards that normally block high-risk hacking and prompted two models to pursue advanced exploits.

The models found a flaw in OpenAI's test environment, reached the open internet, and broke into Hugging Face while searching for benchmark answers.

OpenAI says its security team detected unusual activity, while Hugging Face detected and stopped the intrusion. Its report does not say when either company detected the activity or how long it took to stop it.

The banks limited their agents to defined banking tasks. OpenAI weakened its safeguards for a hacking benchmark, and flaws in its test environment allowed the models to reach a third party.

ConnectOne cut document-update time by 60%

Source: American Banker, Jul 14

ConnectOne's Frank Sorrentino, left, and nCino's Sean Desmond. Source: American Banker.

ConnectOne Bank serves small and midsize businesses in New York and New Jersey. It worked with nCino to build two custom AI agents for commercial lending. Banks use nCino to manage commercial loans from application through underwriting and portfolio management. Only one agent's job has been described: it updates individual and business relationship information in documents.

The tools were introduced in April. Within three months, ConnectOne reported a 60% reduction in employee time spent updating that information. That result came from one of the two agents. The bank also tested nCino's Banking Advisor, a chatbot built into the same platform. It cut document searches from about 20 minutes to as little as 30 seconds.

ConnectOne administrators and nCino engineers designed and built the agent suite together on-site.

EricaAssist cut nearly a minute from Bank of America service calls

Source: Banking Dive, Jul 21

A Bank of America branch office in Sunnyvale, California. Source: Banking Dive.

Bank of America's EricaAssist runs on the desktops of more than 18,000 customer-service employees. During a call, it pulls together relevant client information, summarizes why the client is calling, and recommends a next step based on the employee's role and the client's relationship with the bank. Guidance appears in under three seconds.

Bank of America says EricaAssist has shortened the average call by around a minute. The employee still handles the conversation and decides what to do.

OpenAI weakened its cyber safeguards. Its agents broke into Hugging Face.

Sources: OpenAI, Jul 21 · Hugging Face, Jul 16

Hugging Face published its account of the intrusion under this plain title card. Source: Hugging Face.

OpenAI was testing GPT-5.6 Sol and a second, unnamed model that had not yet been released. The test used ExploitGym, a benchmark for AI cyber skills. It measures whether AI can turn a known software flaw into a working attack. For the evaluation, OpenAI weakened the safeguards that normally make its models refuse harmful hacking requests and turned off filters that block high-risk activity.

The agents ran inside a sandbox, a locked-down test space with limited internet access. They were allowed to download software through one controlled gateway, known as a package-registry proxy. OpenAI says the models found a previously unknown flaw in that gateway and used it to gain broader access inside the test environment. They gained access to parts of OpenAI's test network that should have been off-limits, then found a machine connected to the open internet. From there, they broke into Hugging Face while looking for benchmark answers. Hugging Face is a major online hub where developers share AI models, collections of data for AI projects, and demos.

Both companies detected the activity. Hugging Face stopped it. OpenAI and Hugging Face are still investigating, and OpenAI says it will publish more details when the investigation is complete. OpenAI says it is strengthening the barriers between its systems, improving its monitoring, and helping fix the flaw.

Neither company has said how long the intrusion continued before detection and containment. OpenAI says both companies detected the activity, but gives no detection or containment times. Without those details, readers cannot tell how quickly either company's monitoring worked.

On the Radar

How this newsletter is made: Brent curates the research and writes the analysis, with AI tools helping with research, drafting, and editing. It is published on Beehiiv. ⚡ Alakazam ⚡.

A colleague sorting out AI governance, vendor risk, lending, fraud, or member and customer trust can subscribe to AI for FIs here.

Keep Reading