Danske Bank is piloting a Model Context Protocol service that lets selected corporate customers connect AI agents to the bank’s Premium APIs and view their own financial data inside an agentic AI tool.

The bank’s developer portal describes the service narrowly: customers can access and explore their own information. It does not announce autonomous payments or give agents an unrestricted ability to transact. That restraint is precisely why the pilot matters. It provides a practical example of how banks may expose trusted financial services to AI interfaces without immediately handing those systems broad transactional authority.

MCP is an open protocol for connecting AI applications to tools and data sources. In simple terms, it gives an AI system a structured way to discover what a service can do and call those capabilities. In banking, however, MCP sits above the hard controls that matter most: authentication, entitlements, API permissions, confirmation and audit.

Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.

The strategic question is therefore not whether banks will have APIs. They already do. It is whether a customer’s AI agent becomes a new interface through which those APIs are used.

That creates a useful authority ladder for financial services: read, analyse, recommend, prepare, approve and execute. A bank can permit the first two without permitting the last two. As systems advance, the industry will need clear answers about whose identity an agent acts under, how authority is delegated, which actions require a human confirmation step, how consent is recorded, and how access is revoked.

For corporate treasury teams, the potential upside is straightforward. Instead of switching between bank portals, spreadsheets and treasury systems, an authorised agent could retrieve balances, analyse cash positions or prepare actions inside the tools the customer already uses. The governance burden rises sharply, however, once the workflow moves from information retrieval into irreversible financial action.

Danske’s pilot is therefore less important as a product launch than as a signal about banking architecture. The customer interface may increasingly be an AI layer, while the bank’s APIs and identity controls remain the regulated rails underneath. The institutions that work out that division of responsibility early will have a clearer path to agent-enabled services without sacrificing control.


Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.
Share this post
The link has been copied!