Anthropic has spent most of this year telling people to be careful about what they hand an AI system. Its chief executive published an essay this month arguing the industry should slow down. Its safety team keeps publishing incident reports about its own models.
The next thing the company appears to want is read access to your bank account.
A feature called Claude Money turned up inside a test build of the Claude app for iOS on September 14, spotted by TestingCatalog. It sits in the sidebar as its own section, below Chats, alongside Code, Artifacts, Dispatch and Cowork. Anthropic has not announced it, has not confirmed a launch date, has not named a price tier, and has not said which countries would get it. What exists so far is interface plumbing in an unreleased build, plus a name.
That is enough to be worth understanding now, because the question people asked within about six hours of the screenshots going around was the right one. Not what can it do. What can it see.
The short version
- Claude Money is an unannounced personal finance section found in an unreleased build of the Claude iOS app
- It would let you link bank accounts so Claude can read them directly, instead of you uploading statements by hand
- What it would read: balances, transaction history, merchant names, dates, amounts, and the patterns those add up to
- What it would not read: your banking password or username, and any account you do not link
- It reportedly cannot move money. No transfers, no bill payments, no autonomous spending
- OpenAI shipped the same idea roughly four months earlier, through Plaid, across more than 12,000 institutions
- Nothing about Anthropic’s data provider, retention policy or training treatment for this data has been confirmed
What it would be able to read
Based on what has been reported so far, the access model looks like the one every other account aggregation feature uses. Broad read permission, no write permission.
| Claude would see this | Claude would not see this |
|---|---|
| Balances across checking, savings and credit cards you link | Your online banking username or password |
| Full transaction history: dates, amounts, merchant names | Accounts you choose not to link |
| Recurring charges, subscriptions and utility payments | Anything at a bank the provider does not support |
| Income deposits and their timing | Authority to transfer money or pay a bill |
| Where you shop, how often, and how that changes | Anything it can act on without you |
The right hand column is the reassuring one, and it is worth noting that it is genuinely reassuring. An AI assistant that can read your accounts but cannot move money out of them is a meaningfully smaller problem than one that can do both.
The left hand column is where the interesting part lives, and it has nothing to do with any single line item. A year of transaction data is not a list of purchases. It is a behavioral record. It shows where you live, what you earn and when, which pharmacy you use, whether you are paying a lawyer, how much you drink, whether you stopped going to the gym in March, and which month things got tight.
The part of the chain that is not Anthropic
Here is the detail that gets skipped in most coverage of features like this. Anthropic cannot connect to your bank. Neither can OpenAI. Neither can any of them.
Consumer banks do not open direct connections to AI companies. That job belongs to financial data aggregators, and in the United States that overwhelmingly means Plaid, which is the pipe underneath OpenAI’s version of this feature and most fintech apps you already use. Anthropic has not confirmed a provider for Claude Money. Whoever it turns out to be, there is a third company in the middle.
That middle link has history. In 2022, Plaid paid $58 million to settle a class action covering an estimated 98 million people, over allegations that it used login screens imitating banks and collected transaction data beyond what the apps using it needed. The company has changed a great deal since then. The point is not that the aggregator is untrustworthy. The point is that it exists, that most people linking an account never think about it, and that it holds a copy.
The question Anthropic has not answered
Anthropic’s current position on consumer accounts is that chats may be used to improve its models when a user has that setting enabled, and that raw content pulled in through connectors is excluded from that. So far, so reasonable.
What has not been said is how linked financial data would be classified. Is a bank connection a connector, and therefore excluded? Is the conversation you have about your spending a chat, and therefore eligible? Because the useful version of this feature involves you typing things like “why was last month so expensive” and Claude answering in detail, and that exchange is a chat containing financial data by any normal reading.
This is not a hypothetical worry about a company with a clean slate. Users of the other major assistant found out earlier this year that hundreds of contractors were reading real conversations, with the opt out buried two menus deep. The lesson was not that anyone acted in bad faith. It was that the default setting and the thing people assumed were different, and nobody found out until a report landed.
How far behind this is
Anthropic is not first here, and the gap is larger than it looks.
Being late is not automatically a problem. The version that arrives second gets to learn from the complaints about the first, and there is a real argument that a company currently publishing essays about slowing down should take longer over a feature like this rather than less.
It becomes a problem only if the lateness produces a rush. The uncomfortable context is that Anthropic and its rivals have reportedly been talking privately about how to slow each other down, precisely because none of them wants to be the one that blinks while a competitor ships. Personal finance is exactly the kind of product where that pressure shows up.
The risk that is not in the feature description
Every list of what Claude Money can and cannot see is a list about permissions. The thing security researchers have been flagging about these features all year is not a permissions problem at all.
It is concentration. Today your financial life is scattered. Your bank knows your balance, your card issuer knows your purchases, your broker knows your holdings, and none of them holds all three. Link all of it to one assistant and you have built a single place where a complete picture exists: net worth, spending habits, debts, income timing, and the things you are anxious about, written out in your own words in the chat history.
That makes the account holding it a different class of target. An attacker who takes over an email account gets your inbox. An attacker who takes over an AI account with linked finances gets a briefing document about you.
If you are thinking about linking an account, to any assistant
- Turn on the strongest login protection the AI account offers before you link anything. This account now matters as much as your bank login
- Link the narrowest account that answers your question. A single checking account is usually enough to analyze spending. The brokerage does not need to be in there
- Check the training setting first, not later. Find out what happens to the conversation, not just to the connector data
- Find the revoke button before you need it, and understand that revoking stops future access rather than erasing what has already been stored
- Assume the chat log outlives the connection. The connector can be unlinked. The conversation where you explained your debts is a separate object
Why they all want this anyway
It is worth being clear about why every assistant is racing toward your accounts, because it is not really about budgeting.
Financial data is the highest quality signal about a person that exists in consumer software. It is structured, timestamped, complete and honest in a way that browsing history and survey answers are not. It says what you actually did with your money rather than what you said you would do.
That is enormously useful for building an assistant that gives good advice. It is also enormously useful for anything downstream that depends on knowing what somebody can afford and what they are already buying. OpenAI has already started putting sponsored agents inside the chat window, which tells you the direction of travel for at least one of these companies. No AI firm has committed to keeping linked financial data away from commercial targeting, because none of them has been asked the question under oath.
What to watch
- Which aggregator Anthropic names. That decides who else holds a copy, and under what terms
- Whether conversations about your finances are treated as connector data or as chats. This is the single most important disclosure and the easiest one to leave vague
- Whether the feature ships to free accounts. A paid tier implies the product is the subscription. A free tier raises a different question
- Retention. How long a copy of your transaction history lives on Anthropic’s side after you disconnect
- Whether anything here survives contact with regulators in markets that take financial data more seriously than the United States does
None of this means the feature is a bad idea. An assistant that can look at twelve months of real transactions and tell you something true about your own habits would be genuinely useful, and far better than the category of budgeting app that mostly makes charts.
But the sales pitch for a product like this is always about what it can do for you, and the part that matters is the part written in smaller type. Anthropic has not published that part yet. Until it does, the honest summary of Claude Money is that it is a name in a sidebar, a promising idea, and a set of questions the company has had every opportunity to answer in advance and has not.

