🔒 Data & Trust

Should You Connect Your Bank Account to an AI Assistant?

By Caolan Preston August 2026 8 min read

Connecting an assistant to your finances is three different decisions wearing one name. Pasting a statement, granting read-only access, and handing over the ability to move money carry completely different risks — and lumping them together produces bad calls in both directions. Here is how to tell them apart.

The short answer

Connecting an assistant to a read-only view of your finances is a reasonable thing to do, provided you can answer four questions: who holds the connection, what exactly it can reach, whether it can change anything, and who is accountable if it goes wrong. Connecting an assistant to anything that can move money is a different decision entirely, and today almost nobody should be making it. The distinction is not a detail. It is the whole question.

The honest answer is “it depends what you mean by connect”

The question gets asked as though there is one thing called connecting your bank account to an assistant. There are at least three, and they carry completely different risks.

The first is pasting: you copy a statement, or export a CSV, and drop it into a chat window. No connection exists at all. The data is now in that conversation and wherever that provider stores conversations, and it goes stale the moment you paste it.

The second is reading: an assistant is given permissioned, read-only access to a live view of your financial data. It can see. It cannot touch. This is the arrangement most people mean, and it is the one this article is mostly about.

The third is acting: an assistant is given the ability to do things — move money between accounts, make payments, cancel a subscription, change a setting. This is the arrangement that sounds most useful in a demo and is the least defensible today.

Lumping these together produces bad decisions in both directions. People refuse a read-only connection because they picture an assistant with a debit card. Others enthusiastically hand over payment powers because they enjoyed a read-only experience. Separate them and the question becomes answerable.

Four questions to ask before you connect anything

These are the questions worth putting to any product that wants access to your financial life, whether or not an assistant is involved. If a provider cannot answer all four clearly and in public, that is itself the answer.

1. Who actually holds the bank connection?

There is a meaningful difference between an assistant that connects to your bank, and an assistant that connects to an app that connects to your bank. In the second arrangement, the bank connection stays where it already was, under existing regulated permissions, and the assistant only ever sees a downstream view. Your banking credentials are not in play, because they were never shared with anybody in the first place — UK Open Banking authenticates you at your own bank, not at the app.

Ask where the credentials live. The correct answer is “nowhere, because we never see them”.

2. What exactly can it reach?

“Your financial data” is not a specification. A good provider will list what is exposed, item by item, and the list should be shorter than everything. Categorised spending is different from raw transaction descriptions. A net worth total is different from your account numbers. A summary of your subscriptions is different from your card details.

Vague scope is a warning sign for a practical reason: you cannot consent to something you have not been told.

3. Can it change anything?

This is the question that separates the reasonable from the reckless. “Read-only” should mean that no capability to write, move, cancel or amend exists at all — not that such a capability exists and is switched off, and not that the assistant has been instructed not to use it.

The difference matters because instructions can be talked around and switches can be flipped. Absence cannot. Ask whether the mutating capability exists. If the answer is “it exists but is restricted”, you are relying on a policy. If the answer is “it does not exist”, you are relying on the shape of the thing.

4. Who is accountable when it goes wrong?

Nothing is risk-free, so the question is not whether something can go wrong but who answers for it. In the UK there is a concrete test: is the firm authorised by the Financial Conduct Authority, or an Appointed Representative of a firm that is? You can check on the FCA register in about a minute, and you should.

Regulation is not a guarantee of competence. What it gets you is specific and useful: rules about how financial data is handled, obligations under the Consumer Duty to act in your interests, and access to the Financial Ombudsman Service if a complaint cannot be resolved directly. An unregulated app may be perfectly well run, but if it goes wrong your options are commercial rather than regulatory.

What read-only actually guarantees — and what it does not

Read-only is worth a great deal, and it is oversold constantly. Being precise about it is more reassuring than overclaiming, because the claims are checkable.

Read-only does guaranteeRead-only does not guarantee
No money can be moved by the assistantThat what the assistant tells you is correct
No payment can be created or authorisedThat your conversation is private from the assistant’s provider
No account settings can be changedThat the data shown to you is complete
No subscription can be cancelled or startedThat you should act on what it says
Nothing is written back to your bankThat the connection cannot be misused if your account is compromised

The right-hand column is the one people skip. An assistant reading real numbers can still reason badly about them. It can misread a one-off transfer as recurring income, miss that a category is incomplete because an account is not connected, or produce a confident summary of a period it only partly has data for. Read-only protects your money from the assistant. It does not protect your decisions from a bad answer.

The practical consequence is that a read-only assistant is a good tool for orientation and a poor tool for irreversible decisions. Asking what you spent on eating out last month is exactly the sort of question it should handle. Asking whether to move your pension is not, and no amount of connection quality changes that.

The risk that is actually worth worrying about

For a read-only connection, the realistic risk is not theft. It is disclosure — your financial position now exists inside a conversation held by a third party — and misplaced confidence in an answer that sounds authoritative. Both are manageable. Neither is what most people picture when they imagine the danger, which tends to be an assistant emptying an account. That specific fear is the one thing a genuine read-only design does eliminate.

Why accountability matters more than assurances

Every provider says its product is secure. The claim carries no information, because no provider says the opposite. What carries information is the structure behind the claim.

Three things are worth more than a security page. The first is regulatory status you can verify independently, on a register the firm does not control. The second is an audit trail — a record of what was accessed and when, visible to you, so that “we would never” can be replaced by “here is what actually happened”. The third is revocation that you control, that takes effect immediately, and that does not require you to contact anybody.

Those three between them convert trust from a feeling into something closer to a check. You do not have to believe the provider; you can look.

Where earmarkIQ sits, stated plainly

We build one of these things, so the honest thing is to state our own position against the same four questions rather than write an apparently neutral article that happens to conclude in our favour.

earmarkIQ Context, against the four questions
  • Who holds the connection? earmarkIQ does, through Open Banking provided by Finexer Ltd (FRN 925695), an FCA-authorised firm. The assistant never touches your bank and never sees your credentials, because earmarkIQ never sees them either.
  • What can it reach? Your categorised earmarkIQ picture: accounts and balances, spending by category, subscriptions, net worth and property equity, and your payday allocation plan. That list is the whole list.
  • Can it change anything? No. earmarkIQ Context is read-only by construction — no mutating capability exists in it, and a test in our build fails if one is ever added.
  • Who is accountable? earmarkIQ Ltd, as an Appointed Representative of Finexer Ltd, which you can verify on the FCA register. Every access through Context is audited, and you can revoke it yourself at any moment.

What we do not do: earmarkIQ does not move money. No assistant connected through Context can initiate a payment, and no capability exists for it to do so. Payment initiation sits within the permissions earmarkIQ operates under and is on the roadmap, but it is switched off today. If it is ever turned on, it will be something you start and confirm yourself, payment by payment, with your bank authenticating you — never something an assistant decides to do. The distinction between showing and moving is worth reading in full, because it is the line that matters most.

So: should you?

If the connection is genuinely read-only, the scope is written down, the firm is on the FCA register, and you can revoke access yourself in seconds — then yes, connecting is a reasonable thing to do, and the main thing you are risking is that your financial position exists in one more place than it did before. Judge that against how much use you will get from it.

If any of those four is missing, or if the product can act rather than only read, the calculation changes and the burden of proof should sit with the provider. “Trust us” is not a security model, and enthusiasm about what an assistant could do for your money is not a reason to give it the ability to do it.


Frequently asked questions

Is it safe to connect my bank account to an AI assistant?
It depends entirely on what the connection permits. A read-only connection through an FCA-regulated Open Banking provider, where the assistant can read a categorised view and cannot move money or change anything, is a reasonable risk for most people — the main exposure is that your financial position now exists in one more place. A connection that lets an assistant initiate payments or change your accounts is a very different proposition and is not something most people should agree to today. Ask who holds the bank connection, exactly what can be reached, whether anything can be changed, and who is accountable if it goes wrong.
What does read-only actually mean?
Properly implemented, it means no capability to write, move, amend or cancel exists at all — not that such a capability exists and has been switched off, and not that the assistant has been told not to use it. That distinction matters because instructions can be worked around and switches can be flipped, whereas an absent capability cannot be invoked. Read-only guarantees your money cannot be moved by the assistant. It does not guarantee that the assistant's answers are correct, or that your conversation is private from the assistant's provider.
Can an AI assistant see my banking password?
Not under UK Open Banking, and not through any properly built product. Open Banking authenticates you directly with your own bank, using your bank's own login screen. The app you are connecting receives a limited, revocable data feed — it never receives your credentials, so it has nothing to pass on. If any product asks you to type your online banking username and password into its own interface, that is screen scraping rather than Open Banking, and you should not do it.
What are the real risks of a read-only connection?
Two, mainly. The first is disclosure: your financial position now exists inside a conversation held by a third party, subject to that provider's retention and privacy terms. The second is misplaced confidence: an assistant reading real numbers can still reason badly about them, miss data from an account you have not connected, or produce a fluent summary of a period it only partly covers. Neither risk is theft, which is the thing most people picture and the thing a genuine read-only design does actually eliminate.
How do I check whether a money app is FCA regulated?
Search the firm on the FCA register at register.fca.org.uk. You are looking for either direct authorisation or Appointed Representative status under a principal firm that holds it. Regulation is not proof of competence, but it does get you concrete things: rules on how financial data is handled, Consumer Duty obligations to act in your interests, and access to the Financial Ombudsman Service if a complaint cannot be resolved. If a firm claims regulation but does not appear on the register, treat that as decisive.
Can I disconnect an assistant once I have connected it?
You should be able to, instantly and without contacting anyone. Look for revocation you control from your own account, taking effect immediately, and ideally an audit log showing what was accessed while the connection was live. With earmarkIQ Context you can revoke access from your earmarkIQ account at any time, or remove the connector in the assistant; either ends access there and then, and neither affects your bank connections or the app itself.

About earmarkIQ

earmarkIQ is a UK personal finance app for iOS and the web. It is an FCA Appointed Representative of Finexer Ltd (FRN 925695) and ICO registered (CSN2001882). It connects to UK bank accounts through read-only Open Banking, categorises spending automatically, builds a payday allocation plan, and tracks subscriptions, property equity and net worth. Website: earmarkiq.app

Start with the boring version

Before connecting anything to anything, it helps to know what your money is actually doing. earmarkIQ categorises your spending from read-only Open Banking data and builds a payday allocation each month — the assistant connection is optional, and it is the last step rather than the first.