The first European bank to give AI assistants a key to customer accounts also published exactly which doors it locked, and the second list matters more than the first.
Scalable Capital, the Munich broker that received a full banking licence from the ECB last year, opened its platform this week to ChatGPT, Claude and Grok. The feature is called Agentic Investing. Clients turn it on in their profile settings and connect through either a hosted MCP server or a command line tool installed on their own device. Once connected, an agent can search instruments, pull live quotes and price history, draft orders, build savings plans, and set watchlists and alerts. It can also read parts of the firm's own analytics. Execution is where the design stops. Every order needs manual approval in the app. Cash transfers and withdrawals are shut out of the interface entirely. Existing account permissions carry over, two-factor authentication is required at intervals, and access can be switched off at any time. Scalable says agent outputs do not come from the firm and are not advice. Bitpanda in Vienna shipped a similar interface weeks earlier.
Three Decisions Worth Copying
Three decisions here are worth copying. Letting an agent draft an order but not place it is a real boundary, not a cosmetic one. Keeping money movement out means the worst likely incident is unwanted positions rather than missing funds, which is the difference between a cleanup and a headline. And reusing existing account permissions, instead of building a second set alongside them, avoids the drift that follows every bolt-on access scheme.
Where the Risk Actually Sits
The risk sits elsewhere. The danger to an agent that can draft orders is not theft but manipulation. An assistant reading news, filings and whatever else a client points it at cannot reliably tell an instruction from its owner apart from an instruction hidden in the material it was asked to read. Nobody in the industry has solved that. The only defence against it is one person clicking approve on a trade the assistant has already explained, and that defence is strongest the week it launches. The device running the connection belongs to the client, not the bank. The login perimeter moves too, because breaking into someone's assistant account now opens a path into their brokerage through a sign-in the bank never sees. The model itself changes when its provider updates it, not when the bank finishes a review. And the record left behind shows an instruction with no trace of the reasoning that produced it, which matters the first time a client disputes a trade or a supervisor asks how a pattern started.
Every control described sits on the bank's side. Every open question sits on the agent's side. Nobody owns the space between them, and that is what a risk committee is really being asked to approve when this lands on the roadmap, which for most firms is a quarter or two away.