
Banks are handing your money to AI. The next question is whether you should trust it
One Zero, IBI and Fair are connecting customers’ financial data to ChatGPT as banks embrace a future of AI-powered personal finance. But cybersecurity experts warn that convenience could come with unprecedented privacy risks.
Artificial intelligence is moving from answering questions to analyzing the most personal data people have: their money.
Last week, Israeli digital bank One Zero launched a new capability allowing customers to connect the bank’s financial AI agent, “Ella,” directly to OpenAI’s ChatGPT models. The integration allows customers to ask questions about their latest account activity and financial situation through a natural-language conversation, without manually entering information or uploading files.
One Zero may be among the first banks globally to offer such a connection, but it is not the first financial institution to move in this direction. In recent weeks, Israeli investment house IBI and investment platform Fair have launched similar integrations, allowing customers to connect AI tools to their investment portfolios and financial assets through the IBI SMART app and Fair’s platform.
The developments mark the beginning of a broader shift across the financial industry, including moves by U.S. companies such as Robinhood, as banks and investment firms acknowledge a reality they can no longer ignore: millions of customers are already using AI tools to manage their finances.
Until now, many users have done so through workarounds that financial institutions consider risky, uploading screenshots of investment accounts, manually copying financial data into chatbots, or relying on third-party tools that scrape information and may require users to share login credentials.
Rather than attempting to stop this behavior, banks and investment firms are increasingly choosing to build controlled and secure channels that allow customers to use AI while keeping financial information within a supervised environment.
The promise is straightforward: turning complex financial data into a conversation that anyone can understand.
But the move also raises difficult questions. How much information should customers share with AI systems? Can financial institutions truly prevent leaks? And will today’s AI assistants eventually evolve from explaining money decisions to making them?
The common theme among the new AI integrations is meeting customers where they already are: inside AI interfaces.
Financial information has traditionally been difficult for many consumers to understand. Bank statements, investment reports and portfolio breakdowns contain large amounts of data, but extracting meaningful insights often requires financial knowledge or professional advice.
AI tools aim to change that by translating complex information into simple conversations.
In banking, the focus is on helping customers better understand their spending habits, income patterns and household finances. Instead of reviewing months of transactions manually, users can ask questions such as: “How much did I spend on restaurants in the past six months compared with the previous period?” or “How have my mortgage payments changed?”
The system can analyze trends in income and expenses, identify changes in spending patterns and help customers better manage their budgets.
For investment platforms such as IBI and Fair, the focus is naturally different: helping investors understand their portfolios.
The AI connection allows users to analyze risk exposure, examine their concentration in specific sectors or currencies, understand how market events affected individual holdings, compare performance against benchmarks and examine returns relative to risk over different periods, including during periods of war or changing interest rates.
“The world of investments and mutual funds has always suffered from excess complexity and technological barriers,” Elad Shefer, CEO of Fair, told Calcalist. “The goal of integrating AI is not to create a gimmick, but to meet the investor at eye level, to reduce the fear of financial data and allow people to understand what is really happening with their money within seconds.”
The significance of the shift is not only the ability to analyze data, but also the way people interact with financial institutions.
For decades, banks have built increasingly sophisticated digital applications, but those systems still require users to navigate menus, understand financial terminology and know which information to search for.
AI agents introduce a different model: instead of customers learning how to use financial systems, the systems learn how to communicate with customers.
“One of the biggest changes is that the customer no longer needs to know where to look,” said executives involved in the new integrations. “They can simply ask.”
The approach reflects a broader trend across technology: the replacement of traditional interfaces with conversational ones.
However, unlike many consumer applications, financial AI carries a higher level of risk. A wrong recommendation about a restaurant or travel destination may be inconvenient; a mistake involving savings, investments or payments can have real consequences.
That is why the first wave of financial AI tools is deliberately limited. They are designed to explain and analyze information, not make decisions or execute transactions.
The next challenge for the industry will be determining how far these systems can go while maintaining security, regulatory compliance and customer trust.
Behind the simple user experience lies a more complex technological architecture.
Today, there are two main approaches being used by financial institutions to connect customers with AI systems. The first, adopted by One Zero and IBI, relies on a new communication protocol called MCP (Model Context Protocol), developed by AI company Anthropic.
MCP is designed to serve as a standardized and secure way for AI models to communicate with external tools and information sources. Instead of allowing an external AI model such as ChatGPT to directly access raw financial data, the financial institution’s internal AI agent acts as an intermediary.
The customer interacts with ChatGPT, but the bank or investment house’s own AI system remains responsible for understanding the financial data, applying business rules and determining what information can be shared.
“Just as USB-C became a common standard for charging and transferring data between phones and computers, MCP is a secure communication standard that allows an AI agent to connect to external tools and information sources,” Dr. Orel Babayoff, AI director at One Zero, told Calcalist.
“The innovation here is that we connected one agent to our internal financial agent, which has already processed the data in the most accurate way, instead of allowing an external AI to dig into raw information,” he said. “We are essentially building an architecture in which the bank’s financial agent holds the knowledge and business logic, while the external model is only the interface through which the customer communicates.”
The second approach is a dedicated application inside ChatGPT’s ecosystem, as implemented by Fair. Instead of creating a direct connection through a communication protocol, users connect to Fair’s official ChatGPT application through a secure identification process.
From the customer’s perspective, the experience is similar: the user authenticates once, and then can ask questions about their financial information through a conversational interface.
For now, these services are primarily available through ChatGPT, reflecting OpenAI’s dominant position in the consumer AI market.
However, financial institutions are already preparing for a more fragmented AI landscape.
One Zero has said it plans to expand the service to Anthropic’s Claude models and later to additional platforms from Google and Microsoft.
The broader expectation in the industry is that financial institutions will not want to depend on a single AI provider. Instead, they will seek to create secure infrastructure that allows customers to use whichever AI assistant they prefer.
The biggest challenge facing financial AI adoption is not the technology itself, but trust.
Cybersecurity experts have warned for years about the risks of transferring sensitive financial information to large technology companies. The concern is that once personal data enters an AI system, users may lose visibility and control over how that information is processed.
The financial institutions launching these services argue that their systems are designed to minimize those risks through two main principles.
The first is data anonymization.
According to the companies, personally identifiable information such as names, identity numbers, account numbers and full credit card details are not transferred to external AI models. Instead, the AI receives financial information stripped of identifying details.
“We do not transfer any personal information,” said Yair Bratspiess, product manager at IBI Smart. “I don’t tell the chat, ‘this is the customer’s information.’ I tell it, ‘these are the stocks in the portfolio.’ There are no personal identifiers.”
He added that customers go through the same secure authentication process used when entering the investment application itself, and that all information is transferred using encrypted communication standards.
The second principle is separation between analysis and execution.
All current systems operate in a read-only format. They can analyze transactions, explain portfolio performance and provide insights, but they cannot independently transfer money, buy securities or execute financial decisions.
The logic is simple: allowing AI to understand financial information is one step; allowing it to act on behalf of customers is a much bigger regulatory and security challenge.
Not everyone is convinced that existing security models are sufficient for the AI era.
Some cybersecurity experts argue that traditional concepts such as anonymization may not fully address the risks created when information enters a conversational AI environment.
“All the definitions of anonymization and old security standards are simply irrelevant once the data enters the conversation in AI,” said Moshe Karako, chief technology officer of NTT Israel.
“From the perspective of the language model, the financial information is not isolated. It joins everything you have told it in the past and creates a complete profile of the person.”
2 View gallery


Elad Shefer of Fair, Dave Lubetzky of IBI and Eyal Gafni of One Zero.
(ןPhotos: Ilan Bsur, Dana Kopel, Shaul Golan)
Karako argues that connecting financial information to external AI platforms could shift responsibility away from financial institutions and toward customers.
“It’s like the bank telling you: ‘We keep the money in a safe, but if you sent a courier and asked us to give him the box, from the moment it left the bank, the responsibility is yours,’” he said.
“Once you approve the connection, ownership of your information has passed to a third party, and the bank is exempt from responsibility for what happens to it from that moment on.”
He also warned that financial institutions offering these connections could create a false sense of security among customers.
“When the bank tells you, ‘Come do it,’ it gives you the feeling that it is safe and that you can trust the chat, just like you would trust your doctor,” he said.
Karako compared the trend to other areas where consumers have already traded privacy for convenience, such as email services and smart fitness devices.
“Consumers will make the same compromise with their money and its management,” he said. “The benefits are significant.”
While today’s financial AI tools are focused on analysis and explanation, the industry views this as only the first stage.
The next step will be moving from AI assistants that answer questions to AI agents that can actively help manage finances.
One Zero says its future roadmap includes a form of “supervised autonomy,” where AI agents could prepare actions for customers, such as drafting a bank transfer or preparing a deposit instruction, before requiring customer approval.
However, fully autonomous financial operations remain far away.
Even if technology allows an AI agent to prepare a transaction, the final execution would still require customers to leave the chat environment, enter the official banking application, complete secure identification and actively approve the action.
Beyond technology, regulators would also need to approve any move toward AI-driven financial execution.
The industry’s challenge is clear: customers increasingly want AI that can do more, but financial institutions must balance convenience with security, accountability and regulatory responsibility.
The hallucination problem: Can AI be trusted with financial data?
Another major challenge facing financial AI is a problem familiar across the technology industry: hallucinations.
Large language models can sometimes generate incorrect information, invent facts or present inaccurate calculations with complete confidence. In a financial environment, where decisions can affect people’s savings and investments, such errors carry far greater consequences.
Financial institutions launching these tools say they are addressing the problem by limiting the role of external AI models. Rather than allowing the language model to independently analyze raw financial information, internal systems first process, verify and structure the data before presenting it to the AI interface.
The goal is to ensure that the AI is explaining validated financial information rather than generating its own interpretation of unprocessed data.
Still, executives at the companies emphasize a clear limitation: these tools are not investment advisors and are not designed to make financial decisions.
Shefer, CEO of Fair, said users are already asking questions that would previously have required a professional advisor.
“‘I have four funds, which one would have performed better in terms of return and risk level during the war?’ This is a different level of conversation that was previously inaccessible to the average retail investor without an advisor,” he said.
“But there must be complete separation. The system is read-only and does not replace financial advice.”
IBI’s Bratspiess made a similar point.
“The tool is not intended by any definition for investment advice,” he said. “We strongly recommend not using it for advice, but rather using it to better understand the data, portfolio diversification and risk levels. The role of AI is to make the full picture accessible, not to make decisions for the investor.”
Despite the concerns, the direction of travel appears clear: financial institutions expect AI to become a much deeper part of how people manage money.
The current generation of tools is primarily reactive. Customers ask questions, and AI responds.
The next generation is expected to become proactive, monitoring financial behavior, identifying patterns and offering suggestions before customers even ask.
Industry executives envision AI agents that could warn customers about unusual spending, identify opportunities to reduce costs, suggest better savings options and provide personalized financial insights that were previously available only to wealthy clients working with private bankers or family offices.
“We are at a turning point in the way people interact with their money,” said Babayoff from One Zero.
“The vision is that AI will be at the customer’s side like a 24/7 personal financial assistant, one that knows their behavior, helps them make more informed decisions and saves them time and money.”
For investment markets, supporters of the technology argue that AI could help democratize access to financial analysis.
“The goal is the complete democratization of financial information,” said Shefer from Fair. “In the future, the ability to analyze an investment portfolio at the level of a professional analyst will be available to anyone on their mobile phone in simple language.”
The emergence of AI-powered financial assistants reflects a broader transformation taking place across the economy.
Consumers have already become accustomed to sharing personal information with technology companies in exchange for convenience. The question now is whether they will make the same trade when it comes to their finances.
The financial industry believes the answer will be yes, provided the experience is simple, useful and secure.
Cybersecurity experts remain more cautious, arguing that AI introduces new risks that traditional security models were not designed to handle.
Karako of NTT Israel believes adoption will continue regardless.
“An AI agent has no morals,” he said. “It will simply find ways to achieve its goal.”
He warned that the same technology designed to help consumers could eventually create new risks if used irresponsibly.
“Tomorrow, a credit company agent could enter your chat conversations, see that you are trying to close a large overdraft, and say: ‘This customer is risky, you should not lend to him,’” he said.
The debate highlights the central challenge facing financial AI: the technology’s biggest promise, its ability to understand people and their behavior, is also what creates its greatest risks.














