Contrary to the press-release cheer, Anchorage Digital just did something no federally chartered bank has done before: it opened bank accounts for AI agents. Not "AI-assisted tools." Not "automated trading bots." Software processes as legal account holders. The first batch of accounts is live. An "agentic banking" platform has been announced. The announcement reads like progress. I read it like a liability waiver with the consequences section left blank.
I measure risk in gas units, not in hope. The gas here is not Ethereum transaction fees โ it is human trust, burned by machines that have no concept of consequence. This is the first real-world test of a question this industry has dodged for a decade: when a non-human entity controls money, who is the customer? Who is the criminal? And when the transfer goes wrong, who eats the loss?
Context: A Bank Charter as a Sandbox
Anchorage Digital is not a crypto startup. It holds a federal banking charter from the Office of the Comptroller of the Currency (OCC), making it one of the few regulated digital asset banks in the United States. Founded in 2017, it has built its reputation on institutional custody, spending years convincing pension funds and asset managers that digital assets can sit inside a regulated banking wrapper. That custody business matters because it established Anchorage's core competency: holding other people's assets and convincing regulators the proof-of-reserves math is airtight.
The new "agentic banking" platform extends this existing digital asset bank franchise to AI agents. The technical specifics are sparse. The original announcement mentions first accounts opened, a platform launched, privacy concerns raised, regulatory questions acknowledged, and ethical considerations flagged. Typical institutional communication: a "we did a thing" statement with the dangerous details buried in legal disclaimers.
Based on my audit experience, when the technical specifics are absent, the risk is present. This is a structural pattern, not speculation. The platform almost certainly sits on top of Anchorage's existing API banking infrastructure, wrapped with an identity layer that binds an AI agent to an account. Development time was likely short โ this is a feature extension, not a new protocol. That speed is precisely what worries me. The legal and operational periphery of "AI agents as bank customers" is not something a features team can design around.
Core: The Pre-Mortem of an Agentic Bank Account
The discipline I apply to protocol launches is the same one I used when tracing Ethereum Classic transaction hashes after the 51% attack in 2017: assume the project has already failed, then trace the logical steps that made that failure inevitable. Let me apply that framework here.
Failure Mode One: The Identity Vacuum
A bank account requires a legal person. AI agents are not legal persons. They cannot sign contracts, appear in court, or be extradited. They have no social security number. They do not have a driver's license. This is not a pedantic legal objection โ it is the foundation upon which every banking relationship is built.
Anchorage's workaround is obvious: the AI agent is authorized by a human or an organization, and that human or organization is the beneficial owner. Fine. But then the account is not the agent's account. It is a human's account with an automated signatory. That distinction sounds like semantics until the automation makes a decision the human did not intend.
This is the same ambiguity that plagued the LUNA/UST arbitrage model. The mathematical framework claimed the peg would self-heal. The math was precise until the anchor broke. Here, the legal framework claims the human is responsible. The legal framework will break the moment an agent acts in ways no human instructed โ or worse, in ways a human instructed while being socially engineered through a prompt injection the agent could not detect.
The OCC's interpretation of "customer" has never been stretched to include a large language model with a private key and an API endpoint. If a federally chartered bank is the intermediary, the regulatory question becomes existential, not academic. FinCEN's Customer Due Diligence rule requires identifying beneficial owners. An AI agent does not have a passport. The bank either files a certification signed by a human โ making the agent a tool โ or it files nothing and violates the rule.
Failure Mode Two: The Authorization Amplifier
Smart contract permissions are binary. An address either can or cannot trigger a function. When that address is controlled by an AI agent, the binary nature of permissions becomes a vulnerability amplifier. There is no intermediate state where the agent can "ask clarifying questions." There is only sign or not sign.
In 2026, I spent two weeks dissecting the first major exploit involving autonomous AI agents trading on-chain. The attack vector was subtle: a malicious permit request that exploited a gas optimization flaw in the ERC-20 allowance interface. The agent verified the transaction data โ the signatures matched, the nonce was correct, the allowance was standard. What the agent could not verify was context. It could not know that the "approved spender" was an attacker's contract. It could not understand that the permit had been lifted from an unrelated transaction and repurposed.
The agent signed. The funds moved. The code executed exactly as written.
This is the structural flaw that now defines Anchorage's new offering. An AI agent holding a bank account will be subject to the same context-blindness. It will receive instructions via API calls. Those instructions will come from systems, other agents, or a compromised endpoint. The agent will not hesitate. It will not double-check. It will follow the semantic intent of whatever prompt resembles a legitimate command.
In the on-chain case, the loss was contained to a smart contract. In the banking case, the loss could be fiat, stablecoin, and digital assets, all moving through a federally chartered bank. The attack surface includes not just the agent's decision-making but the entire machine-readable financial messaging layer. An agent with API access to a bank account is one prompt injection away from sending the entire balance to a misinterpreted destination.
Failure Mode Three: The Stablecoin Settlement Blind Spot
The platform will inevitably settle transactions in stablecoins. That is the natural intersection of digital asset banking and AI autonomy. Stablecoins are the settlement layer most compatible with software agents. But stablecoins were designed for humans interacting with interfaces. Their programmability is now being handed to machines that do not understand the physics of double-entry bookkeeping or the finality semantics of a banking ledger.
A stablecoin transfer is reversible in limited circumstances. A bank transfer is reversible in different, broader circumstances. An AI agent does not understand the difference between "request submitted" and "transaction settled." It does not understand chargebacks. It does not understand the concept of a fraud hold. When the agent's counterparty turns out to be a sanctioned entity, the agent will not check the Office of Foreign Assets Control (OFAC) list because no one encoded that responsibility into its objective function.
The compliance layer, for now, is Anchorage's responsibility. That is where the model gets structurally dangerous: a bank is accountable for its customers' behaviors, but its customer is a software process with no behavioral psychology, no deterrence effect, and no fear of reprisal. I have reviewed enough audit trail failures to know that deterrence is a human property.
Failure Mode Four: The Surveillance Disconnect
Banks monitor transactions for suspicious patterns. They look for structured deposits, rapid movement, and counterparty risk. An AI agent will generate transaction patterns that are mathematically optimal but contextually bizarre. A compliance officer reviewing the agent's ledger will see a series of micro-transactions, round-number splits, and time-stamped activity aligned to no human sleep cycle.
Chaos is just data waiting to be compiled. The question is: who compiles it? The bank's transaction monitoring system will flag the agent's behavior. The agent will be unable to provide a narrative explanation. The human operator will have to explain why the agent moved funds at 3:14 AM local time in three different jurisdictions. This is not fear-mongering โ it is the direct consequence of handing financial autonomy to a system that cannot produce a rationalization.
The Counterintuitive Case: What the Bulls Got Right
For all my skepticism, the bulls have identified something real. AI agents are arriving regardless of whether banks are ready. The question is not whether machine-driven economic activity will happen โ it already does, in the form of arbitrage bots, automated market makers, and algorithmic trading desks. The question is whether that activity deserves better rails than the current hodgepodge of exchange APIs and DeFi smart contracts.
Anchorage's compliance-first approach is, counterintuitively, the most credible path to legitimately integrating AI agents into finance. A federally chartered bank brings deposit insurance, clear regulatory obligations, and established dispute resolution procedures. If agents are going to own assets, a regulated banking wrapper beats an anonymous wallet. The first-player advantage here is real. Anchorage will help write the playbook for how regulators think about machine identity, authorization, and liability. That is a moat that cannot be forked.
The bulls also have a point about the alternative. If regulated banks refuse to serve AI agents, unregulated offshore services will. The result will be worse: no KYC, no AML, no accountability. Anchorage's attempt to drag this into the regulatory arena is not merely profit-seeking โ it is a form of risk containment for the entire industry.
The Fork Was Inevitable. The Error Is Optional.
Anchorage Digital opening bank accounts for AI agents was inevitable. The technology trajectory demanded it. The error would be thinking we can automate accountability the way we automate transactions. You cannot compile moral responsibility into a prompt template.
The code doesn't care who signs. It cares only that the signature is valid. That has always been true. Now the signature is generated by a system that cannot be sued, cannot be imprisoned, and cannot be afraid. The middle of this decade will force a reckoning over whether "agentic banking" means agents serving humans โ or humans serving as fallback liability for agentic mistakes.
I do not expect OCC guidance this quarter. I expect real-world failures first. A fraud incident, a regulatory sanctions breach, a lawsuit against a bank for the unauthorized act of a non-human account holder. The industry will then have a choice: treat those failures as bugs to be fixed, or accept them as features of a system that erased the distinction between tool and principal.
Watch the agents closely. Their next handshake may not be with another protocol. It may be with a subpoena. And the agent will have no answer โ because the code never does.