Banking Already Fought the AI Agent War. The Ending Was a Contract
The fight over AI agents' access to the web feels unprecedented. It is not even unfamiliar. American banking fought the same war for twenty years. Automated software borrowed customers' identities. Institutions blocked it, then sued. Courts weighed in and settled nothing. A price formed on access anyway. That war is effectively over, and its ending was none of the things the combatants predicted. No verdict ended it. No regulation ended it. A contract did.
This site has spent the summer documenting the agent side of this arc: the passports, the court ruling, the security collapse. The web is replaying banking's script at roughly ten times the speed, and the script's last page is already written.
When the bot borrowed your password
The mechanics are the parallel. In 1999 a company called Yodlee started pulling customers' account data together from different banks. In September 2007, Mint launched at the TechCrunch40 conference and won its top prize. To use these tools, you handed over your real online-banking password. The company's software then logged into your bank's website as you, read your balances and transactions, and copied them out. The industry called it screen scraping: a robot driving the human interface on borrowed credentials. The robot kept your password on file.
The bank could not cleanly tell the robot from you. It held your credentials, so in every way that mattered it was you. Millions of people signed up. Which means the modern agentic browser, the AI that shops and reads mail inside your logged-in session, is not a new species. It is the Mint model with a language model at the wheel. The Ninth Circuit even blessed the identity this month: the bot is the user.
Block, sue, and offer them your own app
The banks' response ran through every move now aimed at agents. In October 2015, JPMorgan Chase throttled Intuit, Mint's owner, after its refresh requests flooded the bank's website. Bank of America and Wells Fargo were accused of quietly doing the same.
In December 2019, PNC rolled out a security upgrade that cut the aggregator Plaid off from customers' account and routing numbers. Venmo, which linked accounts through Plaid, broke for PNC customers overnight. PNC's retail chief said aggregators stored account numbers indefinitely and put customers' money at risk. Complaining customers were pointed to Zelle, a payment network owned in part by PNC itself. The defender's recommended alternative is never neutral. Amazon, which won and then lost an injunction against Perplexity's shopping agent this year, ships its own assistant, Rufus.
The courts got their turn and decided nothing about access. Visa agreed to buy Plaid for $5.3 billion in January 2020. The Justice Department sued, arguing Plaid was building a challenge to Visa's online-debit business, and the deal died in January 2021. The scraper was now worth billions, its legal status still unwritten.
View data table
| Date | Event |
|---|---|
| 1999 | Yodlee starts aggregating bank accounts with customers' passwords |
| Sep 2007 | Mint launches at TechCrunch40; millions hand a startup their bank logins |
| Oct 2015 | JPMorgan Chase throttles Intuit; Bank of America and Wells Fargo accused of the same |
| Oct 22, 2018 | Chase-Plaid data agreement: issued tokens replace stored passwords |
| Dec 2019 | PNC cuts Plaid off, breaking Venmo; customers pointed to Zelle |
| Jan 2021 | DOJ antitrust suit kills Visa's $5.3B acquisition of Plaid |
| Oct 6, 2022 | Chase declares screen scraping fully eliminated on its systems |
| Oct 22, 2024 | CFPB finalizes the open-banking rule; bank trade groups sue the same day |
| Jul-Sep 2025 | JPMorgan announces data-access fees; Plaid signs a paid agreement Sep 16 |
| Aug 6, 2026 | The rewritten rule reaches White House (OIRA) review; still unpublished |
The contract, the law, and the toll
The turn did not come from a courtroom. On October 22, 2018, Chase and Plaid signed a data agreement. Plaid stopped storing Chase usernames and passwords. Instead, the customer approves access and the bank issues Plaid a token: a credential of the bot's own, limited in scope, revocable at will. Chase had started signing such agreements in 2017. By October 2022 it declared screen scraping fully eliminated on its systems, after migrating thousands of apps for two years. The scraper did not lose this war. Plaid became the official rail the banks now maintain on purpose.
The law is still trying to catch up with that contract. On October 22, 2024, six years to the day after the Chase deal, the consumer-finance regulator finalized America's open-banking rule, ordering banks to share data through APIs at a customer's direction. Bank trade groups sued the same day. The agency then changed position with the administration, reopened the rule, and on August 6, 2026 sent its rewrite to the White House office that reviews regulations before they publish. Eight years after the contract settled daily practice, the mandate is still in drafting.
And once tokens replaced borrowed passwords, access got a price. In July 2025, JPMorgan told aggregators it would start charging for data access, noting its systems absorb around 2 billion account requests a month. A Stripe executive called the proposed fees extortionate in a letter to regulators. Plaid signed a paid agreement that September anyway. Readers of the passports essay will recognize the rule: every anti-bot system is a pricing system. The bank spent two decades building a turnstile, then priced admission.
View data table
| Model | Step | What happens |
|---|---|---|
| Borrowed credentials | 1 | You hand over your real online-banking password |
| Borrowed credentials | 2 | The bot logs in as you; the site cannot tell you apart |
| Borrowed credentials | 3 | Credentials sit stored; access is all-or-nothing |
| Borrowed credentials | 4 | The site's only defenses: throttle, block, sue |
| Issued token | 1 | You approve a specific scope of access |
| Issued token | 2 | The site issues the bot its own credential |
| Issued token | 3 | The bot is identified, limited and revocable |
| Issued token | 4 | Access survives, priced and on the record |
The same movie at ten times the speed
Now run the mapping. The Mint moment, software millions trust with their logins, arrived for agents in 2025 when the agentic browsers shipped inside users' logged-in sessions. The blocking stage, banking's 2015 through 2019, is running now: Amazon's injunction came in March, and Cloudflare begins blocking mixed-use crawlers by default on September 15. The courtroom stage arrived on August 4, when the Ninth Circuit decided who the bot legally is. Note what banking's courts never did: set the terms of access. The token stage is shipping as cryptographic bot passports, already in production at payment networks and CDNs. The toll stage is pay-per-crawl. Banking took eighteen years to get from Mint to JPMorgan's invoice. The web compressed blocks, lawsuit, rails and price into about two.
View data table
| Stage | Banking | AI agents |
|---|---|---|
| Mass credential borrowing | 2007: Mint takes your bank login | 2025: AI browsers ride the user's logged-in session |
| The defender blocks | 2015: Chase throttles Mint's owner | 2026: Amazon's March injunction; Cloudflare's default block |
| The court weighs in | 2020-21: DOJ suit kills the $5.3B Visa-Plaid deal | 2026: Ninth Circuit rules the bot is the user |
| The official rail | 2018: Chase-Plaid tokens replace stored passwords | 2026: bot passports ship in production |
| The toll | 2025: JPMorgan charges for access; Plaid signs | 2026: pay-per-crawl |
Two differences make the rerun sharper, not weaker. First, banking's contracts formed under the threat of a data-rights statute. The web has no equivalent of that statute: nothing obliges a retailer to serve your agent your own order history. Absent a mandate, the private deal is not one path to a settlement. It is the only path. Second, security now pushes the same direction as commerce. At Black Hat this month, researchers showed every AI browser analyzed could be hijacked by instructions hidden in the pages it reads. The borrowed session is not just commercially blockable. It is indefensible. Banking's answer and the security researchers' answer converge on the same architecture: kill the borrowed session, issue a scoped token.
Watch for the signature
Here is the stance to grade this essay on. By the end of 2028, at least one major platform that blocked or sued AI agents signs a paid, tokenized agent-access deal with an AI company: scoped permissions, revocable credentials, a rate card. That contract sets the terms the rest of the market copies, the way the 2018 Chase-Plaid agreement set terms that American law is still chasing eight years later. I am wrong if 2028 closes another way: agents winning durable open access in court, or the walls holding with no deals signed. Either outcome would break a pattern banking spent twenty years establishing.
The next moves are already on the calendar. Cloudflare's default block lands September 15. The rewritten open-banking rule comes back from White House review within months. The date that matters has no schedule yet: the day the first platform hands the first agent company a token and an invoice. Banking's version of that day was October 22, 2018, and almost nobody covering the agent wars has read that contract. It is the ending, published eight years early.