Banking Already Fought the AI Agent War. The Ending Was a Contract

The fight over AI agents' access to the web feels unprecedented. It is not even unfamiliar. American banking fought the same war for twenty years. Automated software borrowed customers' identities. Institutions blocked it, then sued. Courts weighed in and settled nothing. A price formed on access anyway. That war is effectively over, and its ending was none of the things the combatants predicted. No verdict ended it. No regulation ended it. A contract did.

This site has spent the summer documenting the agent side of this arc: the passports, the court ruling, the security collapse. The web is replaying banking's script at roughly ten times the speed, and the script's last page is already written.

When the bot borrowed your password

The mechanics are the parallel. In 1999 a company called Yodlee started pulling customers' account data together from different banks. In September 2007, Mint launched at the TechCrunch40 conference and won its top prize. To use these tools, you handed over your real online-banking password. The company's software then logged into your bank's website as you, read your balances and transactions, and copied them out. The industry called it screen scraping: a robot driving the human interface on borrowed credentials. The robot kept your password on file.

The bank could not cleanly tell the robot from you. It held your credentials, so in every way that mattered it was you. Millions of people signed up. Which means the modern agentic browser, the AI that shops and reads mail inside your logged-in session, is not a new species. It is the Mint model with a language model at the wheel. The Ninth Circuit even blessed the identity this month: the bot is the user.

Block, sue, and offer them your own app

The banks' response ran through every move now aimed at agents. In October 2015, JPMorgan Chase throttled Intuit, Mint's owner, after its refresh requests flooded the bank's website. Bank of America and Wells Fargo were accused of quietly doing the same.

In December 2019, PNC rolled out a security upgrade that cut the aggregator Plaid off from customers' account and routing numbers. Venmo, which linked accounts through Plaid, broke for PNC customers overnight. PNC's retail chief said aggregators stored account numbers indefinitely and put customers' money at risk. Complaining customers were pointed to Zelle, a payment network owned in part by PNC itself. The defender's recommended alternative is never neutral. Amazon, which won and then lost an injunction against Perplexity's shopping agent this year, ships its own assistant, Rufus.

The courts got their turn and decided nothing about access. Visa agreed to buy Plaid for $5.3 billion in January 2020. The Justice Department sued, arguing Plaid was building a challenge to Visa's online-debit business, and the deal died in January 2021. The scraper was now worth billions, its legal status still unwritten.

The bank-data war, 1999-2026Vertical timeline of ten events. 1999: Yodlee starts aggregating bank accounts with customers' passwords. September 2007: Mint launches and millions hand a startup their bank logins. October 2015: Chase throttles Intuit as big banks squeeze the scrapers. October 22, 2018: the Chase-Plaid agreement replaces stored passwords with issued tokens. December 2019: PNC cuts Plaid off, breaking Venmo, and points customers to Zelle. January 2021: a Justice Department suit kills Visa's 5.3 billion dollar Plaid acquisition. October 6, 2022: Chase declares screen scraping eliminated on its systems. October 22, 2024: the CFPB finalizes the open-banking rule and bank groups sue the same day. 2025: JPMorgan announces data-access fees and Plaid signs a paid deal. August 6, 2026, highlighted: the rewritten rule reaches White House review; the law is still unsettled, the contract long since signed.The bank-data war, 1999-2026From borrowed passwords to a priced, tokenized rail1999Yodlee starts aggregating bank accounts with customers' passwordsSep 2007Mint launches; millions hand a startup their bank loginsOct 2015Chase throttles Intuit; big banks squeeze the scrapersOct 22, 2018Chase-Plaid agreement: issued tokens replace stored passwordsDec 2019PNC cuts Plaid off, breaks Venmo, points customers to ZelleJan 2021DOJ suit kills Visa's $5.3B Plaid acquisitionOct 6, 2022Chase declares screen scraping eliminated on its systemsOct 22, 2024CFPB finalizes the open-banking rule; bank groups sue the same day2025JPMorgan announces data-access fees; Plaid signs a paid dealAug 6, 2026The rewritten rule reaches White House review;the law still unsettled, the contract long since signedSources: Chase press release, Oct 22, 2018; Financial Planning, Nov 2015; Banking Dive, Dec 2019 and Jan 2021;American Banker, Oct 2022; CFPB filings and client alerts, 2024-2026; Payments Dive, Sep 2025
View data table
The bank-data war, 1999-2026
DateEvent
1999Yodlee starts aggregating bank accounts with customers' passwords
Sep 2007Mint launches at TechCrunch40; millions hand a startup their bank logins
Oct 2015JPMorgan Chase throttles Intuit; Bank of America and Wells Fargo accused of the same
Oct 22, 2018Chase-Plaid data agreement: issued tokens replace stored passwords
Dec 2019PNC cuts Plaid off, breaking Venmo; customers pointed to Zelle
Jan 2021DOJ antitrust suit kills Visa's $5.3B acquisition of Plaid
Oct 6, 2022Chase declares screen scraping fully eliminated on its systems
Oct 22, 2024CFPB finalizes the open-banking rule; bank trade groups sue the same day
Jul-Sep 2025JPMorgan announces data-access fees; Plaid signs a paid agreement Sep 16
Aug 6, 2026The rewritten rule reaches White House (OIRA) review; still unpublished

The contract, the law, and the toll

The turn did not come from a courtroom. On October 22, 2018, Chase and Plaid signed a data agreement. Plaid stopped storing Chase usernames and passwords. Instead, the customer approves access and the bank issues Plaid a token: a credential of the bot's own, limited in scope, revocable at will. Chase had started signing such agreements in 2017. By October 2022 it declared screen scraping fully eliminated on its systems, after migrating thousands of apps for two years. The scraper did not lose this war. Plaid became the official rail the banks now maintain on purpose.

The law is still trying to catch up with that contract. On October 22, 2024, six years to the day after the Chase deal, the consumer-finance regulator finalized America's open-banking rule, ordering banks to share data through APIs at a customer's direction. Bank trade groups sued the same day. The agency then changed position with the administration, reopened the rule, and on August 6, 2026 sent its rewrite to the White House office that reviews regulations before they publish. Eight years after the contract settled daily practice, the mandate is still in drafting.

And once tokens replaced borrowed passwords, access got a price. In July 2025, JPMorgan told aggregators it would start charging for data access, noting its systems absorb around 2 billion account requests a month. A Stripe executive called the proposed fees extortionate in a letter to regulators. Plaid signed a paid agreement that September anyway. Readers of the passports essay will recognize the rule: every anti-bot system is a pricing system. The bank spent two decades building a turnstile, then priced admission.

Two ways to let a bot inTwo-panel diagram. Left panel, borrowed credentials, 1999 to 2022: one, you hand over your real password. Two, its bot logs in as you and the site cannot tell you apart. Three, your credentials sit stored and access is all-or-nothing. Four, the site's defenses are throttle, block and sue. Right panel, issued token, 2018 onward: one, you approve a specific scope. Two, the site issues the bot its own credential. Three, the bot is identified, limited and revocable. Four, highlighted: access survives, priced and on the record. Footer: the agent-era equivalents are the logged-in browser profile on the left and the bot passport on the right.Two ways to let a bot inThe access model banking abandoned, and the one it signedBorrowed credentials · 1999-2022Issued token · 2018 to now1You hand over your realonline-banking password2Its bot logs in as you;the site cannot tell you apart3Your credentials sit stored;access is all-or-nothing4The site's defenses:throttle, block, sue1You approve a specificscope of access2The site issues the botits own credential3The bot is identified,limited and revocable4Access survives,priced and on the recordAgent-era equivalents: the logged-in browser profile on the left, the bot passport on the right.Sources: Chase press release, Oct 22, 2018; American Banker, Oct 6, 2022
View data table
The two access models
ModelStepWhat happens
Borrowed credentials1You hand over your real online-banking password
Borrowed credentials2The bot logs in as you; the site cannot tell you apart
Borrowed credentials3Credentials sit stored; access is all-or-nothing
Borrowed credentials4The site's only defenses: throttle, block, sue
Issued token1You approve a specific scope of access
Issued token2The site issues the bot its own credential
Issued token3The bot is identified, limited and revocable
Issued token4Access survives, priced and on the record

The same movie at ten times the speed

Now run the mapping. The Mint moment, software millions trust with their logins, arrived for agents in 2025 when the agentic browsers shipped inside users' logged-in sessions. The blocking stage, banking's 2015 through 2019, is running now: Amazon's injunction came in March, and Cloudflare begins blocking mixed-use crawlers by default on September 15. The courtroom stage arrived on August 4, when the Ninth Circuit decided who the bot legally is. Note what banking's courts never did: set the terms of access. The token stage is shipping as cryptographic bot passports, already in production at payment networks and CDNs. The toll stage is pay-per-crawl. Banking took eighteen years to get from Mint to JPMorgan's invoice. The web compressed blocks, lawsuit, rails and price into about two.

Five stages, two warsTable-style chart mapping five stages of the bank-data war to the agent war. Mass credential borrowing: banking 2007, Mint takes your bank login; agents 2025, AI browsers ride the user's logged-in session. The defender blocks: banking 2015, Chase throttles Mint's owner; agents 2026, Amazon's March injunction and Cloudflare's default block. The court weighs in: banking 2020 to 21, a DOJ suit kills the 5.3 billion dollar Visa-Plaid deal; agents 2026, the Ninth Circuit rules the bot is the user. The official rail: banking 2018, Chase-Plaid tokens replace stored passwords; agents 2026, bot passports ship in production. The toll: banking 2025, JPMorgan charges for access and Plaid signs; agents 2026, pay-per-crawl. Bottom annotation: Mint to the toll took eighteen years; agent browsers to the toll, about two.Five stages, two warsThe bank-data war (left) and the agent war (right), stage by stageBankingAI agentsMass credentialborrowing2007Mint takes your bank login2025AI browsers ride the user'slogged-in sessionThe defender blocks2015Chase throttles Mint's owner2026Amazon's March injunction;Cloudflare's default blockThe court weighs in2020-21DOJ suit kills the $5.3BVisa-Plaid deal2026Ninth Circuit: the botis the userThe official rail2018Chase-Plaid tokens replacestored passwords2026Bot passports shipin productionThe toll2025JPMorgan charges for access;Plaid signs2026Pay-per-crawlMint to the toll: 18 years. Agent browsers to the toll: about two.Sources: this essay's timeline; Cloudflare and IETF material as cited in the bot-passports essay, Aug 2026
View data table
Five stages, two wars
StageBankingAI agents
Mass credential borrowing2007: Mint takes your bank login2025: AI browsers ride the user's logged-in session
The defender blocks2015: Chase throttles Mint's owner2026: Amazon's March injunction; Cloudflare's default block
The court weighs in2020-21: DOJ suit kills the $5.3B Visa-Plaid deal2026: Ninth Circuit rules the bot is the user
The official rail2018: Chase-Plaid tokens replace stored passwords2026: bot passports ship in production
The toll2025: JPMorgan charges for access; Plaid signs2026: pay-per-crawl

Two differences make the rerun sharper, not weaker. First, banking's contracts formed under the threat of a data-rights statute. The web has no equivalent of that statute: nothing obliges a retailer to serve your agent your own order history. Absent a mandate, the private deal is not one path to a settlement. It is the only path. Second, security now pushes the same direction as commerce. At Black Hat this month, researchers showed every AI browser analyzed could be hijacked by instructions hidden in the pages it reads. The borrowed session is not just commercially blockable. It is indefensible. Banking's answer and the security researchers' answer converge on the same architecture: kill the borrowed session, issue a scoped token.

Watch for the signature

Here is the stance to grade this essay on. By the end of 2028, at least one major platform that blocked or sued AI agents signs a paid, tokenized agent-access deal with an AI company: scoped permissions, revocable credentials, a rate card. That contract sets the terms the rest of the market copies, the way the 2018 Chase-Plaid agreement set terms that American law is still chasing eight years later. I am wrong if 2028 closes another way: agents winning durable open access in court, or the walls holding with no deals signed. Either outcome would break a pattern banking spent twenty years establishing.

The next moves are already on the calendar. Cloudflare's default block lands September 15. The rewritten open-banking rule comes back from White House review within months. The date that matters has no schedule yet: the day the first platform hands the first agent company a token and an invoice. Banking's version of that day was October 22, 2018, and almost nobody covering the agent wars has read that contract. It is the ending, published eight years early.