AFSP v0.1 · Public comment open through November 16, 2026

AI agents are caught in a web. AFSP is the way through.

The Agentic Financial Services Protocol (AFSP) is an open industry protocol for one moment: when an AI agent arrives at a regulated financial institution on behalf of a person. Before the agent reaches the institution's systems, AFSP lets the institution verify who the agent is, who it is acting for, and that the person is present and in control. Version 0.1 covers the first use case, agent-assisted opening of a new deposit account, and is open for public comment until November 16, 2026.

  1. Caught in the web
  2. AFSP cuts through
  3. Five signals
  4. Governed access

The web

AI agents are becoming a banking channel. Banks have no standard way to say yes safely.

Agents already search, compare and buy on people's behalf, and they will arrive at banks ready to act. Today there is no agreed standard for deciding whether to let one in, so the only safe answer is no. OAuth, FAPI, FDX and FIDO assume a relationship already exists. AFSP governs the moment an agent asks to start one.

  • No shared identity for agentsA bank cannot tell which software is knocking, or who is accountable for it.
  • No proof of consentNothing shows that the person authorized this specific session.
  • Bilateral deals everywhereWithout a standard, every bank negotiates separately with every AI platform.
  • No human-presence signalA live customer and an unattended script look the same.
  • No record examiners can readNo consistent record of who authorized what, when, and on whose behalf.
Without a standard25 bilateral arrangements
With AFSP1 certification, 1 integration pattern

The protocol

Five questions, answered before the agent gets in.

Before any open banking API is called, the AFSP platform delivers a signed PCAA (Pre-Credential Agent Attestation) package to the receiving institution. S1, S2 and S4 are mandatory: if any fails, the package is rejected. S3 is optional and S5 is conditional. Their absence is disclosed to the institution, and an S5 anomaly is routed to human reauthorization, never automatically declined.

  1. S1MandatoryAgent provenanceA certified, registered, unmodified build from an accountable operator.
  2. S2MandatoryBiometric consentA real human, on their enrolled device, explicitly authorized this session.
  3. S3OptionalFederated referralA trusted network institution has previously KYC'd this consumer.
  4. S4MandatoryFinancial identityBehavioural financial signals consistent with an established profile.
  5. S5ConditionalSession integrityThe session is human-operated, within normal behavioural parameters.

Ready to validate a package.

PCAA packageAppendix A · Illustrative
{ "afsp_version": "0.1", "package_id": "pkg_1a3c…0c2e",
  "S1": { "agent_id": "agt_aip_assistant_20260801_prod", "build_hash": matched },
  "S2": { "type": "FIDO2_BIOMETRIC", "tee_attestation": verified },
  "S3": { "federated_referral": present },
  "S4": { "account_longevity": "MATURE", "provider_signature": valid },
  "S5": { "normalized_score": 0.91 },
  "platform_signature": { "algorithm": "ECDSA-P256", "signature": "MEUCIHx7a3…" } }

Regulatory grounding

Built to align with regulatory guidance

Signal 4 derives from consumer-permissioned data under Section 1033. Pre-access attestation supports the FFIEC's 2021 authentication guidance. Every session produces a tamper-evident audit record, retained for seven years.

Institutional control

The bank stays in charge

AFSP decides nothing about the person. It is not a model, not a fraud score and not a replacement for KYC. Every KYC, underwriting and account-opening decision stays with the receiving institution.

Consumer sovereignty

The consumer stays in control

They approve every consequential step on their own device, outside the AI model. Existing banking relationships come first; other institutions are considered only if the consumer chooses, with their identity kept private until then.

Who it's for

Clear roles for everyone in the session.

The principle throughout is simple: the agent presents, the human decides, the bank executes.

01

Receiving institutions

Banks and credit unions get a verified, pre-screened session before their own processes begin, with no change to how they perform KYC or make decisions, and first consideration for existing customers.

You make every decision

02

Consumer Layer Operators

AI platforms, bank-embedded assistants, widgets and core-banking platforms present the session, run the consumer's biometric authorization and route discovery to the AFSP marketplace.

CLO certification

03

Agent operators

Certify your agent build in the AFSP agent registry and reach participating institutions through one certification and one integration pattern, instead of a separate arrangement with each.

One certification · one integration

04

Signal providers

Certified providers contribute the financial identity attestation (S4), derived from Section 1033-permissioned data, and the session integrity score (S5), in standard signed formats.

Standard, signed attestations

05

Regulators and examiners

A tamper-evident record of who authorized what, when, on whose behalf, and with what signals present. AFSP creates no new data rights and no new decision-making authority.

Examination-ready by design

06

Consumers

Your agent acts only within what you explicitly authorized, confirmed with a biometric check on your own device. No institution learns who you are until you choose it.

The sovereign authority

In banking · the v0.1 use case

Opening a savings account, from discovery to account open.

Version 0.1 covers one use case: agent-assisted opening of a new deposit account. This is the worked example from Appendix A of the specification. It is non-normative, and its values are illustrative.

The agent asks

Imagine a customer, we'll call her Alice, asking her AI assistant for the best high-yield savings account: APY above 4.5%, no monthly fees, minimum balance under $500.

AFSP verifies

The assistant checks its registered AFSP tool and the Discovery Declaration published by Alice's bank. Alice authorizes the session with Face ID, and her device's TEE signs the authorization token.

  • S1Agent provenance
  • S2Biometric consent
  • S3Federated referral
  • S4Financial identity
  • S5Session integrity

Authorization token signed on Alice's enrolled device.

The institution decides

The session defaults to institutions Alice already banks with. She chooses to look further and confirms with a second Face ID, which signs a scope expansion token.

Stage A of D

From authorization to account open2 minutes, 50 seconds.

Identity disclosed to one institution. AFSP absent from KYC and the account-opening decision. The bank remains the regulated trust anchor.

Certify and authorize

Every agent certified. Every session authorized by the person it serves.

Under AFSP, an agent never arrives at a bank unannounced. Its operator certifies the build in the AFSP agent registry, the consumer authorizes each session on their own device, and the institution verifies both before anything proceeds.

  1. 1

    Agent operator

    Certify the agent buildThe build is registered in the AFSP agent registry. Institutions verify its provenance attestation and build hash (S1).
  2. 2

    Consumer Layer Operator

    Present the sessionThe CLO discloses who operates the agent and which data will be used, then runs the biometric authorization ceremony.
  3. 3

    Consumer

    Authorize the sessionFace ID on the enrolled device. The TEE signs a token that fixes the action classes, product categories and time limit.
  4. 4

    AFSP platform

    AttestFive signals are bound into one ECDSA-P256-signed PCAA package, which is bound to a single institution.
  5. 5

    Receiving institution

    Verify and decideThe institution validates the package and returns PROCEED_TO_KYC, REQUEST_ADDITIONAL_VERIFICATION or DECLINE_SESSION.
  6. 6

    Regulator

    ExamineA signed, tamper-evident audit record, retained for seven years, is available to authorized regulators on request.
Session record Appendix A · Illustrative
Agent
agt_aip_assistant_20260801_prod
Build
sha256:c3f9a1e2… certified
CLO
Standalone AI assistant · certified
Device
dev_9f3a1c2e · FIDO2_BIOMETRIC
Action classes
READDISCOVERPRESENT
Products
SAVINGSMMA
PCAA package
pkg_1a3c…0c2e · ECDSA-P256
Clearance
PROCEED_TO_KYC · 180ms
Audit
Tamper-evident · retained 7 years

Under the hood

One signed package. Verified at the front door.

AFSP governs one question only: should this AI agent session proceed to the open banking API layer? Its job ends at the clearance decision.

  1. 01 · Consumer and CLOSession authorizedThe consumer authorizes on their enrolled device. The biometric never leaves the device's hardware TEE.
  2. 02 · AFSP platformPCAA package assembledSignals S1 to S5 are sourced independently, in parallel within one second, and bound into one ECDSA-P256-signed package.
  3. 03 · Receiving institutionValidated before any API callNonce, platform signature, validity window and each signal are verified (VAL-01 to VAL-10).
  4. 04 · Existing controlsBusiness as usualKYC, underwriting and account opening proceed through the institution's own channels. AFSP is absent from them.

The agent presents. The human decides. The bank executes.

The principle behind every component of AFSP.

Governance

An independent foundation to govern the standard.

The AFSP Foundation, an independent non-profit targeted for formation in early 2027, will ratify and maintain the specification, run the working groups, and administer certification and the participation registry. Until then, Primitive acts as interim protocol administrator. After that, it is one voice in the Foundation's governance.

ConsumersThe sovereign authority in every session
Agent operators and CLOsCertified agents and consumer interfaces
AFSPTrust layer
  • Agent registry
  • Participation registry
  • PCAA attestation
  • Audit record
Standard and certification governed by the AFSP Foundation · platform operated by Primitive
Receiving institutionsEvery KYC and account decision
Existing controlsKYC · underwriting · fraud, unchanged

What the AFSP Foundation does

  • Govern the specificationRatify and maintain it through open working groups and public comment.
  • Certify participantsAdminister certification under the Network Participation Agreement.
  • Govern the participation registryWhich institutions are certified, with their keys, endpoints and status.
  • Open governanceFree to read, reproduce and comment on. Essential patent claims licensed on FRAND terms.

Help build the trust layer for agentic banking.

Speak to us