AI & Banking

The Bank as a Tool Inside the Customer's AI Agent: Danske Bank's MCP Pilot and Four Questions to Settle First

Danske Bank connects corporate customers' AI agents to its APIs via MCP. What the pilot means and the four questions banks should settle first.

•

acceleraid Redaktion

4 min read

Bank building as an interface: a customer's robot assistant accesses financial data through a secured counter

On 16 September 2026, Danske Bank announced the pilot launch of an MCP server (Model Context Protocol, an open standard for connecting AI agents to data sources and tools). Selected corporate customers can connect their own AI agents directly to the bank's Premium APIs (application programming interfaces) and work with their financial data inside whichever agentic tool they already use. It sounds like one more API channel. In practice, it shifts the question of where a bank's customer interface will sit.

What Danske Bank is testing

According to the Danske Bank developer portal, the MCP Service lets AI agents work with the Premium APIs, and selected corporate customers can access, view and explore their own financial data in their preferred agentic tool. The service is in pilot; interested customers register by email. Banking 4.0 reports that the Premium APIs build on an embedded-finance offering launched twelve months earlier and cites example requests such as "What's my account balance?" or building a three-month cash-flow forecast.

Christie H. Kristensen, Strategic Integration Partnerships Director at Danske Bank, describes the shift: financial operations used to take place in the online bank or the ERP system (enterprise resource planning software); now there is "a third interface: whatever agentic AI tool your team has chosen." Banks, she says, "will shift from being the place you go to the connective tissue underneath wherever financial operations happen." The bank has not yet published details on authentication, permission scope or write access.

Not the first case, but the first in Europe with this reach

Danske Bank is not alone. US-based Grasshopper Bank says it became the first bank listed in Anthropic's MCP Directory in July 2026; business clients connect their accounts without manual configuration, access is explicitly read-only, and clients can revoke it at any time. The industry directory Open Banking Tracker now lists ten banks with MCP servers, including the UK banking-as-a-service platform Griffin, whose beta offers read and write access, including account opening and payments. The spectrum therefore runs from pure reading to executing actions.

Provider

Region

Status

Access

Target group

Danske Bank

Denmark

Pilot (from 16 Sep 2026)

View and analyse own financial data

Selected corporate customers

Grasshopper Bank

USA

Available via Anthropic directory

Read-only

Business clients

Griffin

United Kingdom

Beta

Read and write (account opening, payments)

Fintech and corporate clients

The current protocol version makes control easier

The MCP specification of 28 July 2026 moved the protocol to stateless requests: every request is self-describing, and method and tool names travel in HTTP headers. Gateways in front of the server can therefore route, authorise, rate-limit and meter requests using the headers alone, without parsing the payload. Also new is the mechanism for multi round-trip requests: if a tool needs "a confirmation or a missing parameter" from the user, the server returns the result type "input required" and the call is only retried once the answer is attached. For banks, this is the technical hook for a mandatory confirmation before any executing action.


Staged access for customers' AI agents: stage 1 read and analyse, stage 2 propose with review, stage 3 execute only after confirmation, each with permission scope, logging and revocation

Four questions a bank should settle first

First: what permission scope applies? Grasshopper's route of starting read-only and granting write rights separately and later is the obvious entry point from a risk perspective. Second: who is acting? The agent acts on behalf of a customer, but the bank must be able to distinguish, and log, whether a request originates from a person, from an agent or from an unattended automation. Third: where does the confirmation live? Executing steps should use the multi round-trip request rather than rely on checks inside the customer's agent, which the bank does not control. Fourth: what does the bank learn? Every request from a customer's agent is a signal about need and usage, for instance when cash-flow forecasts are pulled repeatedly. Such signals belong in customer lifecycle management, but only within the purpose the customer has consented to.

A European footnote: on 14 September 2026 in Vienna, ECB President Christine Lagarde noted that adopting AI means running a firm's data "through a system that belongs to someone else and sits under someone else's law"; a cloud only stores data, whereas a model reads it (ECB). If bank data routinely flows into the customer's agent, the customer chooses that provider, not the bank. Permission scope thus also becomes the instrument for limiting what the bank lets go.

Five takeaways

  1. Since 16 September 2026, Danske Bank has been piloting an MCP server through which selected corporate customers connect their AI agents to the bank's Premium APIs; permission details are not yet public.

  2. According to the industry directory, ten banks worldwide now offer MCP servers, ranging from read-only (Grasshopper) to payments and account opening (Griffin, beta).

  3. The July 2026 specification allows authorisation and rate limiting at the gateway via headers and, with multi round-trip requests, provides a standard path for confirmations before executing actions.

  4. Before launch, a bank should settle permission scope, the identity of the acting party, the location of the confirmation step and the handling of the resulting usage signals.

  5. The customer's agent becomes the third interface alongside online banking and enterprise software; the bank retains influence mainly through what it releases and what it logs.

Illustration: AI-generated. AI-assisted content: We use AI technologies and automated agents in the creation of our articles, including from Microsoft, Google, OpenAI, Anthropic and other providers. Topics, editorial direction and final approval remain with our team.

AI-assisted content: In the creation of our articles, we utilize AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers. Topics, editorial direction, and final approval remain with our team.

© 2026 Adtelligence GmbH. ACCELERAID is a brand of Adtelligence GmbH.

AI-assisted content: In the creation of our articles, we utilize AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers. Topics, editorial direction, and final approval remain with our team.

© 2026 Adtelligence GmbH. ACCELERAID is a brand of Adtelligence GmbH.

AI-assisted content: In the creation of our articles, we utilize AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers. Topics, editorial direction, and final approval remain with our team.

© 2026 Adtelligence GmbH. ACCELERAID is a brand of Adtelligence GmbH.