
What happened
Equals Money's James Simcox said the firm opened an MCP server to customers' AI tools, but chose that customers cannot instruct payments through it. Agent access is read-only for now, with write limited to nonsensitive data.
Why it matters
For a regulated payments company, folding agents into the same controls that govern staff is the safest path, according to Simcox.
What to watch
Equals can already cancel agent tokens, but the process is manual, and Simcox said what the company wants is detection that acts on its own. Watch whether automated misbehavior detection arrives to trigger that kill switch.
WHO IT HITSCompliance and payments-operations teams at regulated fintechs evaluating MCP connections will face pressure to keep agent access read-only and to add automated controls that can revoke agent tokens.
Summaries like this, in your inbox every morning.
Equals Money's decision sits at the intersection of two trends the interview highlights. MCP servers have become a standard way for fintech companies to let customers' AI tools reach their data, but in payments, a misbehaving agent does not merely leak information — it moves money. That difference raises the bar for how agents are identified, logged and stopped, and it is why identity providers such as Okta are adding controls like runtime enforcement and a wider kill switch for AI agents.
Simcox's answer is to treat agents less as software features and more as identities. He noted that as a financial services business, Equals has always had to audit everything its staff do, so agents should not only be treated like a human but should have their own identity and their own access. The company already uses agents in customer-facing roles, and Simcox estimated that AI now writes about 92% of its code, which is what makes the ability to revoke that access essential rather than theoretical.
The practical gap is automation. Equals can cancel agent tokens today, but Simcox described the process as manual, while Okta's Agent Gateway kill switch is designed to revoke every active token held by a compromised agent. Whether Equals closes that gap by adopting such automated detection — rather than relying on staff to notice and react — is likely to determine how much customer-facing agent access it can safely allow.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Among respondents at companies with 1,001+ employees, 50.0% said AI is used company-wide, and 46.0% flagged AI…

Google published four design patterns from the top entries of its Google for Startups AI Agents Challenge, jud…

OpenAI refreshed Codex CLI with a full-screen interface, /agents to see and jump between running tasks, /fork…

OpenAI said Ultrafast is available today for GPT-6 Astra in Codex, ChatGPT Work, and the API, running up to 8x…

At OpenAI DevDay 2026, OpenAI launched a Codex plugin for ModRetro's Chromatic handheld, letting users develop…

In cmux (version 0.64.25), the shell environment includes a cmux preload file in NODE_OPTIONS; once that file…
