Usually, yes, if the connection is read-only through your accounting software's bank feed or your bank's official data-sharing route, you never type your online-banking password into the AI tool, the tool can't make payments, and you can revoke access from your bank. It's riskier when a tool asks for your login, can move money, or works inside your live banking session.
The bigger everyday risks usually sit elsewhere: bank statements exported and pasted into chatbots on personal plans, too many people with access to the accounts in your ledger, and payment fraud that no connection setting prevents. A careful connection with sloppy habits around it is less safe than people think; a careful team with a well-chosen read-only feed is safer than most assume.
Five ways AI tools reach your bank data, safest first
| Route | What it sees | Can it move money? | Main risk | Verdict |
|---|---|---|---|---|
| Accounting software bank feed | Transactions and balances for chosen accounts | No | Who in your team can see the ledger | Safe with sensible user permissions |
| Third-party app via your bank's data-sharing route or an aggregator | Transactions and balances, as consented | No, if read-only | The vendor's security and data retention | Fine for reputable vendors; check them first |
| Uploading statements or CSVs to an AI assistant | Whatever is in the file | No | Plan's training and retention settings; files forgotten in chats | Fine on a business plan with names removed |
| Giving a tool your banking username and password | Everything your login can see | Potentially, yes | Credential theft; often breaches your bank's terms | Avoid |
| A browser agent inside your logged-in banking | Everything on screen | Yes, it can click | Mistakes and hidden instructions on web pages | Avoid for banking |
Any tool that has permission to initiate payments sits in a category of its own. Payment permissions can be legitimate (some accounting and payables tools pay bills directly), but they should come with approval steps inside your bank, not just inside the tool.
Read-only and payment access look alike on a consent screen
When you connect a tool properly, you're sent to your bank's own website or app, you log in there, and the bank shows what the tool is asking for before you approve. Read that screen. "View your account details, balances and transactions" is read-only. Anything that mentions making payments, setting up payees or "initiating" transfers is a different level of access.
A read-only bank feed gives the software a permission to fetch data, not your credentials. Xero's help pages, for instance, say its bank feeds are read-only, that it can't move a customer's money, and that neither Xero nor its connection partner can see your online-banking credentials. That's the standard to expect from any tool: ask the vendor to confirm it in writing if the consent screen isn't clear.
Two practical points often missed. You can usually choose which accounts to share on the consent screen, so a forecasting tool doesn't need your savings or client accounts. And some banks ask you to re-confirm the connection periodically; if a feed stops, that's often why, and it's a good moment to ask whether you still need it.
Browser agents and online banking: the vendor's own warning
Browser agents are AI assistants that operate a web browser for you: reading pages, clicking buttons, filling forms. Claude in Chrome became generally available in August 2026, and others work similarly. They're genuinely useful for research and admin. For banking, the vendor's own guidance is blunt. Anthropic's help page says Claude asks for permission before accessing financial sites, and that it "strongly" advises against using Claude in Chrome to manage financial accounts. It also points out that whatever is visible in the tabs Claude is working in is captured in screenshots and becomes part of the conversation.
The underlying risk is called prompt injection: instructions hidden in a web page or document that an AI reads and follows as if they came from you. An agent that's logged into your bank and reading an invoice with hidden text in it is the scenario to avoid. Vendors add classifiers to catch this, but "rarely" isn't the standard you want for the account your wages are paid from. Keep agents out of banking tabs, and close banking before starting an agent session.
Personal-finance features aren't business banking tools
Consumer AI apps have started offering bank linking. ChatGPT launched a personal-finance feature in 2026 that connects accounts through the aggregator Plaid on a read-only basis, first for Pro and then Plus subscribers, and only in some markets. It's designed for personal accounts: spending, subscriptions, investments.
That's a reasonable product for its purpose, but it isn't built for a business: there are no roles for staff, no separation between business and personal data, and the account belongs to one person rather than the company. For business accounts, the better-controlled routes are your accounting software's own feed and its built-in AI, or a business tool whose data terms and admin controls you've checked.
Warning signs a tool is connecting the wrong way
Most reputable tools connect properly. The warning signs when one doesn't are consistent, and any one of them is reason to stop:
- It asks for your online-banking username and password on its own page rather than sending you to your bank. That's credential sharing, sometimes called screen scraping, and it often breaches your bank's terms, which can matter if money goes missing.
- It asks for a one-time passcode from your bank's app or card reader. Those codes authorise actions. Nobody legitimate needs you to read one out or type it into their site.
- It asks you to turn off two-factor sign-in "so the sync works". The fix for a broken sync is never weaker security.
- It can't name how it connects. A vendor should be able to tell you whether it uses your bank's data-sharing interface directly or a named aggregator.
- It wants every account by default, with no option to choose, or asks for payment permissions it doesn't obviously need.
- Nobody can tell you how it makes money. A free tool with bank access and no visible business model is making money from something, possibly your data.
A realistic example: an owner installs a free "AI spending insights" browser extension that asks for the business banking login "to import transactions". The consent flow never leaves the extension's own pop-up. That's the moment to uninstall it, change the banking password and check the bank's recent activity and device list, before anything else.
Twelve questions to ask before you click connect
Here are the questions, with illustrative answers for a cash-flow forecasting tool that a small business might consider. Answers you can't get from the vendor's documentation or support are themselves an answer.
| Question | What a good answer looks like (illustrative) |
|---|---|
| 1. Is access read-only? | Yes, confirmed on the bank's consent screen |
| 2. Do I ever enter my banking password into your site? | No, you log in at your bank |
| 3. Can I choose which accounts to share? | Yes, per account |
| 4. Who connects: you directly or an aggregator? | Named aggregator, with its own security documentation |
| 5. Is my data used to train AI models? | No, or off by default with a written commitment |
| 6. What independent security audits do you have? | A current SOC 2 Type II report or ISO 27001 certificate |
| 7. How long do you keep data after I disconnect? | A stated period, with deletion on request |
| 8. Can I give staff different permissions? | Yes: view-only and admin roles |
| 9. Is two-factor sign-in available, and can I require it? | Yes, enforceable for all users |
| 10. Which subprocessors see the data? | Published list |
| 11. How will you tell me about a breach? | Stated notification commitment |
| 12. Can I export my data if I leave? | Yes, in a standard format |
Question 6 is the one most small businesses skip, and what SOC 2 and ISO 27001 mean when checking a vendor explains what those reports do and don't prove. For the privacy terms themselves, what to check in an AI tool's privacy policy has a line-by-line list. Question 7 matters more than it used to: AI suppliers do close, and one calendar assistant that shut down in 2026 deleted users' data rather than transferring it.
A letting agency with a client account: deciding what to connect
Consider an illustrative letting agency managing 420 tenancies with nine staff and three bank accounts: its own office account (about 300 transactions a month), a client account holding tenants' rent before it's paid to landlords (about 1,100 a month) and a reserve account.
The agency wants two things: AI-assisted reconciliation in its accounting software, and a cash-flow forecasting tool for the business. Its decisions:
- Office and client accounts feed the accounting software. Read-only, through the software's standard bank feed. Reconciliation needs both, and the software is already where the data lives.
- Only the office account feeds the forecasting tool. The client account isn't the agency's money, so including it would make the forecast look far healthier than reality. And the client account's references contain tenants' names, which the forecasting vendor has no need to see.
- Two of nine staff can see the client account in the ledger. The accounts manager and one director. Property managers see landlord balances through the lettings software instead.
- No uploading client account statements to chat assistants. Rent arrears questions are answered with the ledger's own AI features, not by exporting 1,100 lines of tenants' names into a chatbot.
- A quarterly review of connections, logged in a simple sheet.
Written down as a permission table, the agency's setup looks like this:
| Role | Online banking | Ledger: office account | Ledger: client account | Forecasting tool |
|---|---|---|---|---|
| Directors (2) | Approve payments | Full | One director full | Admin |
| Accounts manager | Prepare payments only | Full | Full | View |
| Property managers (4) | None | None | None (landlord balances in lettings software) | None |
| Negotiators and admin (2) | None | None | None | None |
The result is that the most sensitive data touches the fewest systems. The forecasting tool still does its job with one account, and the reconciliation still has everything it needs.
A car dealership: where the real money risk sits
An illustrative used-car dealership pays auctions and other dealers large sums, often the same day a car is bought. Its owner worried about connecting a forecasting tool to the business account. The connection was the smallest risk in the room.
The real risks were in payments. Emails from an auction house can be intercepted and resent with changed bank details. And with AI voice cloning now easy, a call that sounds like the owner asking the administrator to "pay this dealer now, I'll explain later" is a realistic attack. None of that is affected by whether a read-only feed is connected. What stops it is how payments are released:
- Dual authorisation in online banking for any payment over a set amount (the dealership chose $5,000), so one person can't release it alone.
- A call-back rule for any new payee or changed bank details, using a number from your records, never from the email.
- A code word between the owner and the administrator for urgent payment requests by phone.
- Using any payee name-checking service your bank offers when adding new payees.
AI helps on the detection side: capture tools and some ledgers now flag bills where a supplier's bank details differ from last time. Catching duplicate invoices and payment fraud with AI covers those checks. But the final control is a person, in the bank, approving the payment.
Checking and revoking what's connected
Most businesses have more connections than they realise: a forecasting trial from last year, an app a former bookkeeper added, a receipt tool nobody uses. Once a quarter:
- Open your bank's list of connected apps (in online banking, often under security or data-sharing settings). Note every third party with access and which accounts they see.
- Open your accounting software's connected apps list. It's separate from the bank's and often longer.
- Revoke anything you don't use, or that you can't identify. You can reconnect a tool in minutes if you were wrong.
- Check user access to the ledger and to each tool. Remove anyone who has left or changed role.
- Log it. A three-column sheet (date, what was connected, what was removed) is enough.
An illustrative log entry: "12 Sep: bank shows 4 connections (ledger feed, forecasting tool, receipt app, old expense app). Removed old expense app, unused since March. Ledger shows 7 apps; removed 2 trials. Removed ex-bookkeeper's ledger login." Fifteen minutes, and the attack surface is smaller than it was.
If you've already pasted statements into a chatbot
This is common and usually recoverable. Check which plan you used. On a business plan, content isn't used for model training by default; on a personal plan, check the model-training switch in privacy settings and turn it off for the future. Delete the conversations containing the statements, and remember that deleting doesn't always mean immediate removal from the provider's systems, since retention periods vary by provider and plan. If the statements included other people's personal data (customers' or staff's names in references), note what happened and ask your data-protection adviser whether anything further is needed.
For next time, export only the columns you need, replace names with codes and use a business plan. Keeping customer data private when your team uses AI sets out a simple team policy, and the main AI security risks for small businesses puts bank data in context with everything else worth protecting.
Bank connections: follow-up questions
Does connecting a bank feed let the software see my banking password?
Not with a proper bank feed or regulated data-sharing connection. You're sent to your bank's own site or app to log in and approve access, and the software receives a permission token rather than your credentials. If a tool asks you to type your online-banking username and password into its own screen, stop and ask how it connects before going further.
Can a read-only connection still cause harm?
It can't move money, but it does expose data: balances, payees, amounts and the names in payment references, which can include customers' and staff's personal details. If the tool is breached or shares data carelessly, that information is what leaks. That's why it's worth connecting only the accounts a tool needs and disconnecting tools you've stopped using.
How often should I review connected apps?
Quarterly is a sensible rhythm for most small businesses, plus whenever someone with finance access leaves or you stop using a tool. Check both your bank's list of connected apps and your accounting software's list, because they're separate. The review usually takes 15 minutes and often turns up a trial tool nobody remembers connecting.
Further reads
- AI Security Checklist Before Connecting Tools to Email and Files — The same checks for connecting AI to email and files.
- How to Train Staff to Spot AI-Written Phishing Emails — Train staff for the fraud a bank connection can't stop.
- Can AI Do My Bookkeeping? What Still Needs an Accountant — What the bank feed then does inside your books.
- How to Automate Bank Reconciliation With AI and Check the Matches — Put the connected feed to work, with checks on matches.
- How to Add Human Approval Steps to AI Automations — Keep a person on any step that could move money.
- AI Accounts Payable: Approvals and Payment Runs Without Chaos — Approval rules that sit between AI and payments.
- AI Bookkeeping Software vs a Human Bookkeeper: Accuracy and Cost — Which transactions software gets right and which need a person, three cost scenarios, and a 30-transaction audit to measure accuracy in your own books.
- AI Cash Flow Forecasting Tools for Small Businesses Compared — Nine ways to forecast cash compared on what matters: weekly or monthly view, forecast horizon, what the AI actually does, integrations and list price.
- What Can Go Wrong When AI Agents Take Actions for You? — The five ways AI agents go wrong when they act for you, how each shows up, and the approvals, access limits and tests that contain them.
- How to Spot Deepfake Voice and Video Scams Aimed at Your Business — Spot deepfake voice and video scams by the request, not the voice: warning signs, a copyable verification protocol and a drill to test it on staff.
- How to Choose an Outsourced Bookkeeping Service That Uses AI — Why your books must stay in your own file, twelve questions for any service, a trial month on real transactions, and a yoga studio's worked example.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Xero Central on bank feeds and read-only access; Anthropic's help article on using Claude in Chrome safely; launch reporting on ChatGPT's personal finance feature (May-June 2026). Checked September 2026.