
Last week I spoke to three leadership teams, two at very large banks, and all highlighted to me how the recent launch of Meta’s Muse personal agent has captivated management's attention.
The bank leaders asked me: should we block this thing? Will it cause deposit flight? What if the agent gets compromised? Do we need to build our own?
Those questions took on a new urgency when Apollo’s chief economist, Torsten Slok, asked: “Is an Agentic Bank Run Coming?” The unsettling part is that the customer doesn’t have to be scared of their bank going insolvent. They just have to want a better deal, and an agent could move deposits earning 0.1% to somewhere above 3%.
I think the immediate bank-run risk is wildly overstated. What worries me more is how little has to change for banks to start losing.
Your salary can keep arriving in the same account while your agent finds your next credit card, insurance policy and savings account somewhere else. The bank still has you on its customer list, but it's no longer where you go to decide what to do with your money.
Consumer agents currently appear to be good for Meta, bad for banks. Since the launch of Muse, Meta stock has hit new highs, up 11 percent at Monday's close, while the S&P 500 Financials index fell to its lowest level since July.
For customers, though, this could mean finally getting the deal they never had time to chase. That's the threat I'd be working on if I ran a bank: what happens to a business that profits from customer inertia when the customer has someone else to do the work?

Build products that move money. moderntreasury.com.
It usually starts with a customer request. Can you support RTP? FedNow? Push-to-card? Stablecoins? Then comes the next one. Because new ways to move money don’t replace what came before. ACH, wires, and even checks are still part of the mix.
Without the right foundation, every new rail means another vendor, integration, and more time before you can ship.
Modern Treasury changes that. With one unified API, you can build across today’s payment methods and be ready for whatever comes next. So as the way your customers move money evolves, your product can evolve with them.
Trusted by Procore, Navan, Morse, and companies of all sizes. Powering $600B+ in payments.
Start building today: moderntreasury.com
1. How much should banks fear deposit flight?
Muse is Meta's personal agent. Wired nailed how it feels:
The user experience is less like prompting a chatbot, and more like texting a friend with task requests. The AI agent acknowledges messages with a thumbs-up emoji and gets to work in the background. Muse is also available through Meta's WhatsApp platform. Muse's default avatar is a beige-colored cross between an Ewok and a Labubu, with its arms outstretched, presumably to scoop up all my data.
Muse runs in its own cloud computer, browses websites the way you would, and asks before it spends. Sensor Tower estimated 3.4 million downloads in under three weeks. This is why the bank leaders are paying attention: a personal agent is suddenly something their customers can download and start using.
Meta has been aggressively integrating financial services. Muse already plugs into Plaid (read-only, for now), Stripe Link, PayPal and Shop Pay. It isn't moving deposits or managing your investments yet. Those would require another level of permission and trust.
For banks that depend on cheap, sleepy deposits, an agent shopping around on every customer's behalf could be brutal. The money doesn’t have to leave the banking system for this to hurt. It just has to leave the banks that rely on paying next to nothing for it. They’d have to pay more to keep the money, find other funding, or accept lower margins.
Dave Birch shared with me what that could mean for bank profits:
McKinsey points out that if just 5 to 10 per cent of current account balances moved to the best rates on the market, which is exactly the kind of chore AI agents will happily do, the industry's deposit profits could fall by 20 per cent or more. Across the whole business, it reckons that if banks don't adapt, global bank profit pools could shrink by around $170 billion, or 9 per cent, over the next decade or so, enough to push average returns below the cost of capital.
But look at the history. US commercial-bank deposits rose from $9.3 trillion at the start of 2013 to $19.6 trillion in September 2026. Fintech and easier account access arrived; aggregate deposits more than doubled.
Those are nominal totals; they don't tell us whether individual banks lost cheap funding or had to pay more to retain it. They do give us some perspective on the idea that making finance easier to access inevitably drains the banking system. The question is what customers will actually trust an agent to do, and how quickly that changes.
Canceling a subscription or shopping for cheaper insurance is one thing. Moving the account your salary lands in, with bills and direct debits attached, feels like a much bigger leap. An agent could move spare savings without touching any of that, but it still needs permission to move money and a customer willing to give it.
My read: low immediate likelihood, potentially high impact.
I'd raise that assessment when agents can move deposits and customers actually let them do it at scale. Banks should prepare for that possibility. They should also pay attention to what an agent can take away without moving the salary account at all.
2. You can keep the account and lose the customer
I keep coming back to the sentence:
"I don't want your agent, I want my agent to use your thing."
If agents like Muse become common, they could become the default interface to your finances in the way open finance and app aggregators never did. With mobile banking, banks could at least compete with neobanks and fintech companies in the same channel. Agents could take even that away.
Once the agent becomes the starting point, the customer makes the decision outside your app, in a channel you don't own. Your app can work perfectly and still never get opened.
For consumers, the personal "CFO in your pocket" is now within reach, provided you're willing to progressively give it more data. The early adopter crowd is already canceling subscriptions, making reservations and shopping for insurance.
A BMO analyst fed Muse his policies and photos of his roof. It found him $800 a year on car insurance before the kinks stopped him from switching. VC investor (and Brainfood reader) Angela Strange said that should make insurers “TERRIFIED” (yes, in all caps).
And don’t assume this is just consumer.
There are early signs that in banking agents are already impacting what customers buy.
AIVO ran 2,160 conversations with ChatGPT, Gemini and Perplexity, posing as small business owners choosing a bank. Mercury leads the chart below with 327 endorsements, followed by Wise with 184 and Relay with 68. Chase, the highest-ranked bank shown, got 60.
When the customer named their own bank and asked about it, Bank of America and Wells Fargo were never recommended outright on ChatGPT or Gemini. Not once.
The one place banks still win is credit. When customers named their bank and needed credit, banks won 74 per cent of outright recommendations.
(The whole study is required reading for anyone in banking.)

Source: American Banker using AIVO research. The original chart shows endorsements across ChatGPT, Gemini and Perplexity.
Four smaller banks, Popular Bank, East West Bank, Valley Bank, and Associated Bank, were never named in the study. These are obviously recommendations, not completed account switches, but they show how a bank can lose the decision before the customer ever opens its app. This idea would be my obsession as a bank C-suite.
My read: disintermediation is a higher-probability threat than a sudden bank run, and potentially more damaging over time. The recommendation layer is already moving; how many customers will let agents run their whole financial life is still uncertain.
You can keep the account and lose the customer's attention, their next product purchase, and the chance to shape the relationship. With mobile, you could build an app and offer something fairly similar to compete with. With agents? Not so simple.
Missing this will be bigger than missing mobile. By far.
3. What should banks do?
Muse wants to scan your inbox, read your messages, connect your bank accounts, and take your passport details so it can fill in forms quickly. All things most people will happily do if the app is useful, but that have enormous consequences if they go wrong.
For its part, Meta runs each user's assistant inside an isolated cloud environment, with credentials in a separate compartment so the agent can use your logins without seeing them. So that's somewhat comforting 🙂
But Meta has already patched a zero-day in Muse that could have handed an attacker every permission a user had granted it. Bank of America, NatWest and others are right to ask what the customer authorized, whether the agent stayed within that authority, and who pays if it didn't.
I'm a pro-innovation-leaning human. I expected to say no, don't block Muse. Then I found myself saying something different. Imagine an agent with the keys to every account a customer holds today, and the risks are frankly enormous.
It's rational for a regulated company to start at "we should protect our users." A risk can be uncommon today and still deserve limits because of the damage it could do. The question is how to protect customers while giving them a safe way to use something they want.
Should we block this thing?
Some non-banks already have. Amazon blocked Muse from shopping on its website (as I covered in Agent Wars Part 1). And Insurify, the insurance comparison marketplace, also blocked Muse from accessing its quote-comparison tools.
You can see why this matters to an insurer like Allstate. An agent that shops around for you at renewal could find a suitable policy for less money, without you spending an evening filling in forms. More customers comparing and switching would put pressure on insurers to offer a better deal.
Insurify says Muse can strip quotes of important context, such as coverage limits and deductibles. Those are real concerns. But there was also a very visible market reaction: Allstate shares fell 5.5 percent on Tuesday, then went green the day Insurify announced the block.
Blocking bought a day of share price.
Insurify still supports agent access through its own APIs and MCP integrations, and says it is open to a Muse connector that meets its standards. That's a more useful distinction for banks than simply being for or against agents.
Open finance and card rails already work with agents. Blocking bots on your website doesn't close every route in. Meanwhile, a competitor can give the customer a safe, official way to connect their agent. If your main reason for blocking something is that you monetize customer inertia, then frankly, you suck, and your product needs to get better.
When I said that to bank leadership teams, their next question was:
Should we build our own agent?
Only if it's actually good.
Nobody wants another shit chatbot. They really really really don't.
Mobile apps had the advantage of being quite hard to mess up. Login, display balance, recent transactions, maybe make a payment or deposit a check. Showing up was 90% of the battle.
Agents are different.

Muse is the first time people have experienced magic. Where most agents with computer use get stuck, don't quite understand you, or just fail to complete a task, Muse somehow figures it out. To the point where you want to peek under the hood and see if there's secretly a large team in the Philippines fixing stuff the agent can't do.
That takes dedication and skill most companies don't have. There's a real risk you'll ship an agent, and it will suck.
You should still experiment with it, and learn that skill. But if you're not already strong at design and rapid iteration around customer feedback, you're going to really struggle.
A bank can build a useful agent for the things it knows well. Competing to become the customer's assistant for everything is a much bigger job. And however good your own agent becomes, some customers will bring theirs.
Be the thing their agent uses
Whether or not you build your own agent, you need to be useful to theirs. Give consumer agents a secure, permissioned way into your services, perhaps through an MCP server built on your open banking APIs.
In this future, a customer securely connects their agent to your data service; you handle the customer's request, then hand it back to the agent. Your customer still has a relationship with you, probably even authenticates with you, but they may rarely need to open your app.
You're not a mobile app, website or branch. You're a promise. We'll keep your data and money safe.

Some perspective
It's easy to get carried away with future-gazing here, and there are some sensible caveats.
Usage drops off. Consumers can get gifted a perfectly smart personal agent, then forget to use it or run out of ideas how to. RevenueCat found that AI apps retained 6.1 percent of monthly subscribers after 12 months, against 9.5 percent for non-AI apps. That's a comparison of subscription apps, not Muse's own retention numbers, which we don't have yet.
There's also the cost of keeping these things running. One a16z partner estimates personal assistants cost $3k–$7k per user per year. That's roughly $250 to $580 a month per user. Imagine scaling that to 2bn users when Meta charges $0, $20 or $100 a month. The estimate could be way off and the economics would still deserve a very hard look.
Early adopters adore Muse. But if some pensioner loses their retirement fund with an agent, the pushback could come quickly.
Bank of America's analysts say what matters is deposit costs, not download numbers. That's a good point. It could also be complacency. For deposit flight, I'd watch funding costs. For disintermediation, I'd also want to know where customers start their next financial decision, which providers get recommended, and who wins the business.
A bank can be right that its deposits are safe today and still be too slow to respond to everything else that's changing around it.
We're in a war for consumer adoption and attention. Every big tech company sees the single biggest platform shift coming, possibly ever, and is throwing its enormous resources at winning.
The consumer agent won't go away. You need a strategy.
4. What I'd do now
Most fintech companies are already leaning in aggressively to serving agents as customers, and it's worth looking at what they're actually shipping.
Robinhood opened its brokerage and Gold card to third-party agents in May. More than 100,000 people had opened agentic accounts by its second-quarter earnings call. Customers fund a separate account for the agent, and card purchases can require their OK.
Mercury shipped an MCP server, a command-line interface, then Command, then cards issued to an agent with its own spend limit and its own audit trail. It is giving customers several ways to connect the agent they want to use.
Coinbase for Agents launched in June. Stripe is inside ChatGPT, Perplexity and Muse, and issues virtual cards to agents. Plaid powered Muse's finance tab from day one.
These companies are shipping incredibly quickly, with limits on what agents can do. Spend limits, audit logs and user notifications let them learn by putting products in customers' hands. That speaks much louder than warning the press about fraud risks.
You need to make your bank worth choosing, keep customers safe, and move fast enough to learn. In practice, I'd start here:
Give the agent a reason to choose you. Make your rates, fees, eligibility and terms easy to find and compare. Then make sure the product stands up to the comparison. A better API won't rescue a bad deal.
Give it a safe way to act. Treat the agent like a customer who turned up with a power of attorney. Check the ID (which agent, and is it the real one). Read the mandate (what the customer delegated, how much, until when). Keep both on file for the day it goes wrong.
Start with read-only access and add tightly limited actions as you learn. Anything that moves money out, adds a payee or raises a limit gets a second check with the customer, in your app, not in the agent's chat window. Banks call it step-up. The agent queues it, the customer releases it.
Learn with real customers. Experiment with your own agents and limited integrations. You'll learn more from 500 customers in a month than from a year of roadmap. Give them a clear way to see what the agent did and revoke its access.
The technical work is already under way. Visa, Mastercard and EMVCo are building standards for agents to prove what they were allowed to do. I covered the protocol soup here. Banks can use that work, but proving authority doesn't, by itself, settle who eats the loss when an agent exceeds it.
What happens if an agent deletes data, is compromised or hallucinates? Who pays: the merchant, the issuer, Meta, or the customer? Amex has committed to cover eligible purchase errors by registered agents when it receives the customer's authenticated instructions. That's a start, but it doesn't answer every question about an agent that's been compromised or gone beyond its remit.
The UK's APP fraud reimbursement rules offer a useful starting point: the customer's payment firm reimburses an eligible loss, and the sending and receiving firms share the cost. We need the same clarity for agents. Decide who pays by default, then let the parties argue about the split in private.
That also means shared identity, delegation and audit records. Which agent acted, what did the customer authorize, and what actually happened? The banks' own paper asks for exactly this: keep the instruction, the authentication, the intent and the outcome. Those records need to mean the same thing to the bank, the agent provider and whoever handles the dispute. Direct debit has had a mandate for over fifty years.
We also need a kill switch. Lose your phone, and you freeze the card in one tap. Lose control of your agent, and today you revoke it one connector at a time. Somebody needs to build the button.
Muse may be a fad people put down after three weeks. But I don't think we're going back to a world where customers have to do all this work themselves.
AI has an annoying habit of going nothing, nothing, nothing, SaaSpocalypse.
You do not want to get caught on the wrong side of that.
The cost of experimenting and learning has never been lower. You need to engage with this threat and generational opportunity on the front foot. It's not BAU, annual budget cycle, roadmap release stuff.
It's small teams, moving quickly, developing something new.
Like the early days of mobile.
But 100x faster.
ST.
If you enjoyed this, please do share it with someone else who might :)


