A person or authorized system asks the bank to act.
Examples include paying a bill, releasing a wire, changing a card limit, or sending a disclosure. The request alone does not move money.
How regional and national banks can become the trusted operating system for AI-driven commerce.
A Strategic FrameworkA customer or authorized system asks MidFirst to do something. MidFirst checks its own rule and decides what happens. Hive adds a signed receipt so the decision can be checked later without relying only on the bank's own log.
Select any box for the plain-English explanation. MidFirst keeps the customer, rules, keys, decisions, and money. Hive provides only the independent proof layer.
Examples include paying a bill, releasing a wire, changing a card limit, or sending a disclosure. The request alone does not move money.
MidFirst owns the policy, the authority limits, the approvals, and the signing keys. Hive does not write the rule and cannot change it.
The bank remains responsible for the customer relationship and the decision. Hive never touches the account or the money.
The receipt records which rule was presented, which authority was used, what action was recorded, and when. It proves the record, not that the decision was legally correct.
An examiner, auditor, lawyer, counterparty, or customer can check the receipt without a MidFirst login and without trusting Hive's database. If one fact changes, the verification fails.
The question is no longer whether software will initiate banking and payment activity on a customer's behalf. It is who the customer, the regulator, and the counterparty will trust when an autonomous agent, not a person, starts a transaction, and how that trust is proven after the fact.
MidFirst enters this era from strength. It is the largest privately owned bank in the United States, with more than $42 billion in assets, a 19.7% total risk-based capital ratio, $13.8 billion in available liquidity as of March 31, 2026, and four consecutive decades of profitability, according to figures the bank reports through its own newsroom (MidFirst newsroom, Forbes profile). It is expanding deliberately, most recently announcing the acquisition of Dallas Capital Bank to deepen its Texas commercial and private banking franchise (MidFirst acquisition release), and it is already staffing an internal AI function, evidenced by an open role that manages a bank-wide AI use-case backlog in a regulated environment (MidFirst AI role posting).
The direction of travel is set by others already. Visa has launched Intelligent Commerce and a Trusted Agent Protocol (Visa Intelligent Commerce); Mastercard has launched Agent Pay (Mastercard Agent Pay); and the Federal Reserve Bank of New York's Innovation Advisory Council devoted its December 2025 session to agentic AI and payments, concluding that the industry is approaching a shift comparable to the move from face-to-face transactions to e-commerce (NY Fed Innovation Advisory Council minutes).
MidFirst writes the rules. MidFirst systems do the work. Hive receipts the authority chain.
MidFirst writes and owns the authority rules that govern what any agent, its own systems, a customer's assistant, or a counterparty's software, may do on an account. MidFirst owns the customer, the policy, the decisions, the signing keys, the execution systems, and the regulated relationship. MidFirst systems and MidFirst-authorized agents perform the work. Hive receives the minimum signed event evidence it needs and issues independently verifiable receipts. Hive is not the bank, lender, payment network, custodian, policy-maker, or execution engine.
Three forces make this urgent rather than merely interesting. First, the rulebook for agentic AI is being rewritten in real time, with a gap exactly where agent-initiated transactions live: in April 2026 the OCC, Federal Reserve, and FDIC revised model risk management guidance and explicitly excluded generative and agentic AI from scope, calling them novel and rapidly evolving (OCC Bulletin 2026-13), a narrowing that Federal Reserve Vice Chair for Supervision Michelle Bowman confirmed was deliberate (Bowman speech, May 2026). Second, settlement is being solved by others, through stablecoins under the GENIUS Act (GENIUS Act text) and tokenized deposits under the FDIC's clarified framework. Third, MidFirst already operates nearly every workflow this future requires; it simply has not yet instrumented those workflows with independently verifiable, agent-ready proof.
The recommendation is not to chase a flashy feature. It is to make MidFirst the bank whose authority rules, controls, and receipts are the most provable in its peer group, starting inside workflows it already runs, and building deliberately toward 2032.
For a century, a bank's customer was a human being who walked into a branch, signed a card, and later logged into an app. The next actor initiating activity on an account will increasingly be software: a customer's assistant paying a bill, a corporate treasury system moving cash overnight, or a counterparty's bot completing a purchase.
These agents are not customers in a legal sense, and this paper does not treat them as one. An agent is an authorized economic representative, a software actor operating under authority the human customer delegated and the bank enforces. The human customer, and the bank's relationship with that customer, remain the anchor of every obligation.
This distinction matters because the law that allocates loss was not written with software agents in mind. Under Regulation E, a consumer transfer is presumed authorized once the consumer furnishes access credentials to an agent, even if the agent acts outside what the consumer intended (12 CFR 1005.6; Goodwin Law analysis). The practical consequence is that the party who can most cleanly prove what authority existed, and what policy was checked, at the moment an agent acted is in the strongest position when something goes wrong.
That is the strategic opening. The bank that can answer "what was this agent allowed to do, who granted it, and did the check run" with an independently verifiable record, rather than an internal log the counterparty must simply trust, becomes the trusted place for delegated financial authority.
Each era of banking added a new core function without discarding the last. The agentic era adds a fourth.
The vault. Keep deposits safe. Trust rests on the strength of the institution holding the cash.
Checks, cards, ACH, and wires. Trust rests on rails that move value reliably between parties.
Online banking, open APIs, and aggregators. Trust rests on permissioned, connected access to accounts.
Software acts on accounts. Trust rests on proving who was allowed to do what, and that the check ran.
Protecting, moving, and connecting money are now table stakes provided by many players. Governing and proving delegated authority is the function still in contention.
MidFirst already performs the first three functions at scale. The fourth, governing authority and proving it, is where a durable advantage is still available, because it is the one function that settlement vendors, card networks, and fintech issuers are not positioned to own on a bank's behalf.
This is the reference architecture MidFirst can use to reason about every agentic initiative. Read left to right: each layer answers one question, and the bank owns every layer except proof.
MidFirst owns identity, authority, policy, settlement, and audit. Hive contributes only at the proof layer, and only ever as a sidecar.
Identity asks who or what is acting, verified through MidFirst's own identity and access management, which already runs on an enterprise IAM platform (MidFirst IAM procurement record). Authority asks what that actor may do and who granted it; these are bank-defined delegation grants and entitlement rules that MidFirst writes and owns. Policy is the set of specific, executable limits enforced in MidFirst's own core, card, and treasury systems. Proof is the only layer Hive touches: MidFirst's systems submit signed, minimal evidence at the moment of action, and Hive converts it into an independently verifiable receipt. Settlement is how value moves, through card rails, ACH, wire, FedNow, or increasingly stablecoins and tokenized deposits. Audit is how the full chain is reconstructed for exams, disputes, or litigation, using the receipt chain alongside the bank's own books, which the receipts corroborate rather than replace.
The layer that matters most for this doctrine is proof, and the layer most often confused with it is settlement. Neither a stablecoin nor a tokenized deposit proves that the party who initiated a transfer had the authority to do so, or that the policy check that should have run actually ran.
These are directional product concepts, not present commitments. Each extends a capability MidFirst already runs, and each is instrumented with independent receipts from day one.
Agent Accounts™ is a working label only. No conflicting live U.S. financial-services trademark was found in the sources reviewed, but that is not a clearance. A full USPTO and common-law search plus outside counsel review is required before any public use (USPTO Trademark Center).
The term is also descriptive, which raises registrability questions, and marketing copy must never imply that the agent is a legal agent in the fiduciary sense unless the bank intends those duties. It requires trademark clearance and consumer testing, and it is not presented here as an existing MidFirst or Hive product.
Stablecoins and tokenized deposits solve settlement: moving value with programmable, near-instant finality. The GENIUS Act created a federal framework for payment stablecoins with full reserve backing, monthly attestations, and executive certifications (GENIUS Act text; Richmond Fed overview), and the FDIC has clarified that tokenized deposits remain insured bank liabilities distinct from stablecoins (coverage of FDIC guidance).
But settlement answers only how value moves. It does not answer three questions that matter more as software initiates transactions:
Settlement will get commoditized. Trust, authority, and proof will not.The strategic premise of this paper
A programmable dollar that moves instantly but carries no proof of the authority behind it simply moves a disputed transaction faster. The proof layer is a separate function from settlement, and it is the one this framework recommends MidFirst source independently rather than assume a settlement vendor will provide.
These are workflows MidFirst already runs, unchanged. In each, Hive receives signed evidence from MidFirst's own systems and issues an independently verifiable receipt, without touching the decision path. Every row restates a cautious claim limit: the receipt proves an event was recorded, not that the decision was lawful, fair, accurate, or compliant.
| Bank action (unchanged) | Receipt records | What it does not prove |
|---|---|---|
| Treasury multi-level approval before ACH or wire release (Business Online Banking) | Each approver's authenticated action, role, and the final release event | That approvers held actual authority under the client's own governance |
| Positive Pay and ACH Positive Pay matching and exception decisioning (Information Management) | The file version, the match result, and the pay or return outcome | That the underlying check or payee was legitimate |
| Card controls: commercial limit changes and consumer Card Controls (Commercial Card) | Each control change and the authenticated session that made it | That the limit was appropriate; it does not resolve a Reg E or TILA dispute |
| Open Access consent capture for aggregator data sharing (Open Access) | Which aggregator, which accounts, what scope, and when | That the consent was informed, voluntary, or legally sufficient |
| Mortgage disclosures and E-SIGN delivery (FDIC E-SIGN manual) | What was rendered and delivered, through which channel, and when | ECOA, Reg B, or TILA-RESPA compliance of the underwriting decision |
| Fraud and security events, including Fraud Text Alert confirmations (card security) | The alert sent, the customer reply, and the resulting action | Whether a transaction was in fact unauthorized under Reg E |
| Model and governance records for AI-assisted outcomes (OCC Bulletin 2026-13) | Which model version and evaluation applied to an outcome | The correctness of the model or the bank's model governance |
None of these require a new banking product, a new charter posture, or a new counterparty risk. They strengthen the evidence trail on services MidFirst already provides. The interactive demonstration in Section 8 shows one of these chains built and checked live.
Every phase is deliberately reversible and instrumented with receipts from the start. Dates are directional and contingent on the regulatory clarity tracked in Section 10.
| Phase | Focus | What ships | Gate to advance |
|---|---|---|---|
| Phase 0 · now | Instrument today's workflows | Signed receipts as a sidecar on the Section 7 workflows; no decision path changes | Third-party risk review of the proof sidecar (OCC Bulletin 2023-17) |
| Phase 1 | Machine identity | Extend the entitlement engine to recognize a machine-identity actor type, reusing existing IAM | Internal AI governance sign-off; identity-fraud controls tested against deepfake risk (FinCEN alert) |
| Phase 2 | Narrow delegated execution | Agent-initiated actions in reversible categories, such as bill pay on existing rails and zero-balance sweeps | Card-network agent-program registration where relevant; dispute-liability posture documented |
| Phase 3 · toward 2032 | Bank as operating system for delegated authority | Programmable cards, treasury agents, and private-banking delegation at scale, each receipted end to end | Agentic-AI-specific supervisory guidance that regulators have signaled is coming |
Run a realistic treasury sequence in your browser. An invoice above a threshold triggers a chain of approvals and checks; if every gate passes, a signed receipt is issued and the bank executes. Change a policy or an input after signing to watch verification fail, then reset. Everything runs in this tab. Made-up example, not MidFirst data.
In-browser · offline A real hybrid Ed25519 and ML-DSA-65 signature is built and checked locally.
Press Run the authority chain to build and check the treasury receipt.
A bank's balance sheet has always listed what it holds and what it owes. In the agentic era, a parallel ledger becomes strategically decisive, made of assets that do not appear in a call report but determine who wins the delegated-authority relationship.
| New asset | What it is | Why it compounds |
|---|---|---|
| Authority | The rules the bank writes for what any actor may do on an account | Once customers delegate through the bank's rules, switching cost rises with every grant |
| Identity | Verified identity of people, systems, and authorized agents | A trusted identity graph is hard to rebuild elsewhere and gates every action |
| Delegation | The living record of who authorized whom, for what, and until when | The delegation-of-record position is a natural monopoly per relationship |
| Policy | Executable limits enforced in the bank's own core systems | Policies encode institutional expertise that competitors cannot copy quickly |
| Trust | Independently verifiable proof that the above were honored | Provable trust is the one asset a settlement vendor cannot provide for the bank |
These assets reinforce one another. Authority is only credible with verified identity; delegation is only safe with enforced policy; and all of it is only defensible when the honoring of each is independently provable. The receipt layer is what turns the first four from internal claims into external evidence.
Never state or imply that a receipt alone proves legality, fairness, truth, accuracy, intent, or compliance. A receipt proves that a specific, defined event occurred, as attested by signed evidence from a specific system, at a specific time. Every guardrail below is read with that limit in place.
The table separates present, binding-adjacent obligations from forecasts and proposals that are not yet law or binding guidance.
| Topic | Present obligation today | Forecast / proposal |
|---|---|---|
| Model risk management | Revised April 2026 guidance excludes generative and agentic AI and is non-binding by its own terms (OCC 2026-13) | A request for information on AI and agentic-AI model risk is planned |
| Third-party risk | 2023 interagency guidance applies now to any proof or AI vendor (OCC 2023-17) | Simplification of TPRM guidance for AI signaled, not yet issued (Bowman) |
| Agentic payment liability | Reg E, TILA/Reg Z, and UCC Article 4A apply today, unmodified for agents (Goodwin Law) | No agent-specific liability statute exists; card-network rules are private contract |
| Stablecoins | GENIUS Act enacted and in force since July 2025 (Congress.gov) | Implementing rulemaking still underway |
| AI chatbots and UDAAP | UDAAP authority applies now to AI-driven customer interactions (CFPB spotlight) | No agentic-specific UDAAP rule yet |
| ECOA/FCRA and AI credit | Apply in full today regardless of model type (CFPB Circular 2022-03) | No agentic-lending-specific rule yet |
| International AI governance | FSB, BIS, and NIST frameworks exist as voluntary or consultative | FSB sound-practices report in consultation, comments closed July 22, 2026 (FSB) |
The practical takeaway: independently verifiable receipts of the authority grant and the security procedure followed are directly useful evidence inside the frameworks that already apply, especially UCC Article 4A's commercially reasonable security procedure standard for commercial payment orders. They do not change the law; they materially strengthen the bank's ability to demonstrate good-faith compliance with it.
The operating model is a clean separation of duties, which is precisely what lets the bank adopt agentic capabilities aggressively while keeping the audit trail independent of the systems being audited.
The sidecar receives a signed, minimal, purpose-built evidence packet at the moment of an event and returns a receipt that MidFirst, its customer, its auditors, or a court can check without relying solely on MidFirst's own logs. Each decision is recorded as a one-way fingerprint, never the underlying message. This is evidentiary infrastructure, not a new decision-maker. It does not judge.
These are the building blocks under the receipt layer, in plain English. The tag shows whether each is ready to attach to today's workflows or is part of the longer build. Patent-pending methods are marked.
The evidence floor. Holds a decision still using content-addressed roots and a hybrid signature, so changing one byte breaks the seal.
Signed Inference Guarantee Receipt. Seals the model, inputs, and outcome of one decision into a single signed exhibit.
A pre-attestation gate. Signs a clearance before an action runs and refuses any call without a valid, unexpired pass.
Attested Fragmented Inference Routing. Breaks a request into signed sub-tasks so only the pieces that matter are signed.
The same fragmented proof approach for continuous flows, such as an ongoing treasury or payments stream.
Receipt Proof Vector. Rolls many receipts from one event into a single trust score that flags the weakest link for triage.
Model Identity and Relineage. Pins each step of a run to the exact model version that served it, and flags a silent swap.
Binds an actor to a named identity so a receipt can say who acted, not just that something happened.
Records what kind of actor signed: a person, a bank system, or an authorized agent operating under delegated authority.
Records where an input came from, so the source of a document or instruction is part of the evidence.
Cross-checks a claim against independent signals so a single forged input cannot stand alone.
Where a customer sees and manages their own receipts and, in the build-ahead, their delegation grants. A surface composed from the primitives above rather than a separate rail of its own.
Where the bank's risk and audit teams view receipts across business units and triage exceptions. A viewing surface over the rail, not a proof primitive.
The signed catalog of policies, model versions, and authorities that receipts point back to.
The proof plane, including CarnacPrompt™, Carnac Gateway™, and Carnac Live Ink™, that carries evidence through a request.
The entry point where inbound work picks up proof obligations before it is allowed to proceed.
Captures proof as work happens, in the moment, rather than reconstructing it afterward.
The origin record for a prompt or instruction that an agent acts on, tying the first cause to the chain.
The routing spine that carries proof obligations across systems as an action moves through the bank.
A signed map of how an agent's task was routed, so the path itself is part of the evidence.
A signed alarm for an agent drifting off task, reaching for an unscoped capability, or taking in data it should never have seen. The receipt type is live; wiring the probe into a running model is design-partner work.
A hardware root of trust. Keys are born from quantum-grade randomness, live in silicon, and cannot be exported.
The high-assurance signing path for the most sensitive receipts, where the strongest guarantees are required.
A neutral venue where authorized agents meet, do work, settle, and leave with a receipt that outlives the venue.
Reframes a high-value payment receipt as risk, compliance, and recovery infrastructure rather than a log line.
See the full canon of primitives at the Hive canon. Help now means it can attach to a workflow MidFirst runs today; help next means it is part of the deliberate build toward 2032.
Two notes so nothing here is taken for more than it is. Capitolare, Command Center and CarnacPrompt Genesis are named roadmap surfaces and do not yet have entries in the canon registry, so you will not find them if you go looking. SPIRE exists today as a live MCP relay rather than as the full routing spine described above, and SmartAgent Route Graph and XCALIBUR are recorded in the canon as non-operational. Everything marked help now has a registry entry and a live verification route.
MidFirst writes the rules. MidFirst systems do the work. Hive receipts the authority chain.
MidFirst remains the bank in every sense that matters: it owns the customer, writes the authority, sets the policy, holds the keys, runs the execution systems, and answers for every decision. Hive contributes one thing, at one layer: independently verifiable proof that the authority chain was honored. A receipt proves what authority, policy version, input, approval, or action was recorded, and when. It does not prove legality, fairness, accuracy, truth, intent, or compliance by itself.
The recommendation is disciplined and reversible. Start inside the workflows MidFirst already runs, where receipts attach as a sidecar and change nothing about how the bank decides. Build machine identity and narrow delegated execution only as internal governance and external rules mature. Keep every step provable from the first day. The bank that fills the current governance vacuum with disciplined, independently verifiable controls will set the market's expectation for everyone that follows.
Charter 001 is a one-of-one genesis concept, an illustrative invitation for the first bank that chooses to make its automated decisions independently provable. It does not exist until MidFirst affirmatively participates. There is no signed deal, no category lockout, no customer status, no pilot, and no endorsement, and Hive does not promise broad exclusivity.