Form3, an account-to-account payments infrastructure provider trusted by Tier 1 banks including Barclays, Santander, and JPMorgan, along with fintechs like Klarna, Mollie, and SumUp, has launched an AI-enabled payments platform designed to let banks and fintechs use AI agents within their payments operations, while keeping those agents deliberately restricted from actually touching payments themselves.
The launch centers on a Model Context Protocol (MCP) adaptor, a standardised way for AI platforms and agents to connect with external tools and data. Through it, authorised AI agents and humans using natural language can retrieve and interpret payment information directly within an AI interface, intended to help operations teams investigate and resolve payment issues faster, cut manual workloads, and make better use of existing payments data.
The key design choice is that the agent is read-only. It can surface and interpret payment information, but it cannot initiate a payment, change a record, or take any action on its own. The AI layer wraps around Form3’s existing platform capabilities and remains subject to the same data and security controls already in place, with actual payment processing still running through the same infrastructure the company says hundreds of financial institutions already rely on.
Mike Walters, Form3’s Chief Executive Officer, framed the launch around what’s actually at stake behind every payment, tying the company’s caution to the real-world consequences of getting this wrong.
“Every payment tells a story,” Walters said. “Behind it is a person receiving a salary, a business paying a supplier, a family buying a home or someone splitting a dinner bill. Every one of these payments is critical and cannot afford to fail. We are thrilled to be launching our agent-ready infrastructure that will enable our customers to deliver faster answers and resolution for customers, lower their operational costs and future-proof their payments operations. Form3 pioneered introduction of cloud platforms to financial services infrastructure, which was the last big technological upgrade within payments. We are proud to remain at the forefront of innovation for this important sector, leveraging our decade of experience in providing financial institutions with trusted, secure and agile technology to turbocharge their services for customers.”
Edward Wilde, Form3’s Chief Technology Officer, was more explicit about the governance thinking behind the read-only restriction, framing it as a deliberate choice to start narrow rather than hand agents broad authority from day one.
“AI is set to transform payments operations, giving banking teams faster and more intuitive ways to investigate issues and manage critical payment information,” Wilde said. “Our starting point is controlled access rather than unrestricted autonomy, coupled with a read-only approach, which means that agents can view but not change data. This is vital to prevent agents going rogue and initiating payments without permission. Perhaps most crucially, the security protocols surrounding the AI interface match the enterprise-grade standards of our existing payments platform, which is already trusted by Tier 1 banks across the UK, Europe and the US. Agents have the power to add value to the payments process and are the logical next step, but a good governance and trust must prevail.”
For most bank customers, none of this changes anything they will ever see directly; this is infrastructure sitting inside a bank’s operations team, not a consumer-facing feature. What it’s meant to change is how quickly a bank’s own staff can investigate a payment issue when something goes wrong, asking an AI interface a plain-language question instead of manually digging through payment logs and systems. For an industry increasingly nervous about handing AI real authority over money movement, keeping agents read-only while still calling it “agentic” is a deliberate, cautious middle ground rather than a fully autonomous rollout.
Herald View: The read-only restriction is the actual story here, not the AI itself. Every payments company launching an AI feature right now faces the same question: how much authority do you actually hand an agent that can touch real money movement? Form3’s answer is effectively none, at least for now, as agents can look, but they can’t act. That’s a conservative choice, and probably the right one for a sector where a single wrongly executed payment is a regulatory incident, not just a bug.
