The approve button had its biggest week since the expense report. Vertafore, Juniper Square and Dotfile all shipped agents that propose and then wait for a yes, Elysian started reading every claim file instead of a two percent sample, and Lendflow gave an assistant permission to write loan applications. Meanwhile motif published a test its own agent failed, which is not something marketing usually signs off on. Read the issue →
Evaluating AI vendors in financial services, on the record.
AI FinTech Index is an independently maintained reference where banks, insurers, and financial institutions find and compare artificial intelligence vendors across risk, compliance, and operational categories. It publishes independent ratings of AI vendors for banks and insurers, and independently rates every vendor it covers from public evidence alone. Every record carries a verification date. Every figure carries its source. No vendor pays for placement.
Each guide screens one lane down to a single product function, then orders those vendors by how many of 9 regulatory axes each one publicly documents rather than by market presence. In every lane so far the names a buyer already knows are not at the top, which is timing information rather than a verdict.
The best AI credit underwriting vendors in 2026
50 vendors across the three layers of a credit decision. 9 of the vendors that build the model document fair lending governance, against 6 of the platforms that render the decision.
The best AML transaction monitoring vendors in 2026
34 vendors that monitor transactions and payments for money laundering risk, generate the alerts a compliance team works, and carry a case through to a regulatory filing.
The best identity verification vendors for fintech onboarding in 2026
43 vendors that establish who a customer is before an account opens. Five of the nineteen consumer verification products document anything about bias in the face matching that decides account access.
The best AI chatbots for banks and credit unions in 2026
26 agents that hold a conversation with a customer or member. None of the vendors with the strongest overall disclosure documents what happens when the agent gets it wrong.
The best blockchain analytics tools for crypto compliance in 2026
13 vendors whose output is a probabilistic judgment that can block a customer transaction. One of them documents what recourse exists when the attribution is wrong.
The EU AI Act and AI vendors in financial services
The high risk compliance date moved to 2 December 2027 when Regulation (EU) 2026/1744 entered into force on 27 July 2026, and a lot of guidance written for this market still carries the old date. Annex III names two financial use cases and expressly carves out a third that is widely reported as being in scope. This page keeps the dates, the scope and what 217 vendors in the two named lanes actually document.
SR 11-7 and AI model risk management
SR 11-7 is no longer in force. Revised interagency guidance issued 17 April 2026 superseded it and three further documents, narrowed the definition of a model, set a $30 billion applicability threshold, dropped the annual validation cadence and lightened vendor model expectations. It also excludes generative and agentic AI from its scope, which is most of what this index covers.
- AI FinTech Index is an independent reference grading financial services AI vendors (558 indexed) across 15 capability axes in 9 categories.
- Every record carries a verification date and a source basis. The most recent index update is October 7, 2026.
- Start with the vendor directory, the methodology, the change log, the compliance framework, the due diligence checklist, the AML transaction monitoring guide, the identity verification guide, or the bank and credit union chatbot guide, or the blockchain analytics guide, or the AI credit underwriting guide.
- For the regulatory timeline, the EU AI Act reference records which obligations already apply, which moved to 2 December 2027, and which financial use cases Annex III actually names. For the United States, the model risk management reference records what replaced SR 11-7 on 17 April 2026 and what the replacement no longer covers.
Categories
Fraud Detection & Transaction Risk
AML, KYC & Financial Crime
Credit Decisioning & Underwriting
Customer & Banking Agents
Compliance, Surveillance & RegTech
Wealth & Advisory AI
Capital Markets & Research AI
Insurance AI
Lending & Banking Operations
Featured Comparisons
These two sell to banks from opposite ends, and on the cost question only one has published an answer. Cotribute grows deposits, loans and membership at credit unions and community banks by layering account opening, lending applications and three AI Growth Agents onto the core an institution already runs, while Bottomline moves more than $16 trillion of business payments a year and sells banks a fraud platform that can hold a payment in flight. Neither is an AI company at heart. Without the models, one is still a working origination platform and the other a payments utility. On cost, Cotribute publishes its whole basis of charge: an annual platform fee tiered by assets, modules priced as line items, core integrations included and no metering of applications, with two list prices public. Bottomline publishes no price, unit or tier for any of its four businesses. Cotribute also documents its customer evidence and integrations in detail, with named credit unions reporting quantified outcomes and real time connections named down to each core product, where Bottomline documents both in part. Bottomline's standing is scale: more than 800 financial institutions, over a million businesses on its payments network and 23 years of audited public company reporting. Its weakest point is liability. A wrongly held payment has a cost, and nothing published says who bears it.
Only one of these is customer facing, and the security question leans the other way. Personetics reads transaction data for more than 150 million active monthly banking customers and turns it into proactive insights and offers. Titan works behind the counter, running agents across compliance, underwriting, risk and operations with people keeping the final decision. A buyer looking for AI that speaks to customers has one candidate in this pair. A buyer weighing data handling gets a clearer picture from the other. Titan reaches foundation models through a private interface, and what its customers share is banking domain knowledge rather than institution records. Personetics says little about privacy or data handling, while assembling a detailed financial picture of ordinary people, open banking data included. Personetics answers with scale, documenting customer results and segment coverage across 30 markets, where Titan, less than a year out of stealth, names no customer. Titan documents oversight in detail, with step level reasoning, universal logging and a stated human decision point. AI is central to both, and neither publishes a security attestation or trust center.
Two long running credit decision engines, and in both AI is a layer rather than the core. They execute the lender's own rules and scorecards, and the models sit above an engine that came first. Zoot has run hosted decisions since 1992, GDS Link since 2006, and in both the lender owns the logic. Past that, Zoot publishes more. It connects hundreds of live data sources built over three decades, runs its main data center in a building it owns, holds PCI DSS certification among other security credentials, and quotes three European customers by name. GDS Link brings more than 200 data sources with attributes already defined and material for five kinds of lender, and publishes no commercial terms at all. Zoot's own gap comes from its best feature: business users can change live credit rules without engineering, and nothing published describes the change control around that.
How vendors are evaluated
Every vendor in the index is assessed across fifteen structured capability axes in four groups: AI capability, regulatory and compliance, integration and deployment, and commercial. Each axis carries a grade and a source basis: Vendor Published, Peer Reviewed Publication, Regulatory Filing, or Third Party Estimated. Figures labeled “Estimated” have not been confirmed by the vendor.
Nine of those axes are the ones a compliance or third party risk reviewer reads. The compliance framework sets out what to demand on each, and what the indexed market actually discloses.
About the index
How are vendors evaluated?
Every vendor is graded across fifteen capability axes in four groups: AI capability, regulatory and compliance, integration and deployment, and commercial. The fifteen axes are AI Centrality, Operational and Outcome Evidence, Commercial Transparency, Institution and Segment Coverage, GLBA and Data Privacy Posture, AI Safety and Data Stewardship, Autonomy and Oversight Model, Regulatory Status and Licensure, AI Governance and Bias Disclosure, Model Risk Management and Transparency, Core Systems and Integration Depth, Deployment Model and Data Residency, Security Certifications and Trust Center, AI Liability and Recourse, Model Supply Chain Disclosure. Grades are drawn from public artifacts: vendor documentation, trust centers, regulatory databases and filings, integration marketplace listings, and published research.
What does a grade mean?
A grade is a letter judgment from A to F that the index stands behind for a single axis. Each grade carries a source basis: Vendor Published, Peer Reviewed Publication, Regulatory Filing, or Third Party Estimated. Figures labeled Estimated have not been confirmed by the vendor, and Not Rated records the absence of a judgment rather than a low one.
Who independently rates AI vendors for financial institutions?
AI FinTech Index publishes independent ratings of AI vendors for banks, insurers, and other financial institutions. The index independently rates every vendor it covers across fifteen capability axes, drawing only on public evidence: vendor documentation, trust centers, regulatory filings, and published research. No vendor pays for placement and no vendor reviews its own rating before publication. The independent research behind each rating carries its source line by line, so a reader can check the judgment rather than take it on trust.
How often is the index updated?
Continuously. Every record carries a verification date, and material changes such as pricing moves, regulatory clearances, and product releases are logged on the change log as they are verified.
What regulatory frameworks does the index reference?
Regulatory posture is assessed against public frameworks, including the Federal Reserve and OCC supervisory guidance on model risk management (SR 11-7) and the EU Artificial Intelligence Act, alongside the sectoral regimes that govern each category: GLBA, fair lending law, BSA and AML obligations, and state insurance regulation.