Karsten Wenzlaff, Advisor
August 26th, 2025
July 13, 2026 | NCFA Market Activity | Cybersecurity And Fraud, Artificial Intelligence And Data, Banking And Credit

On June 25, 2026, Jack Henry expanded its Google Cloud collaboration to develop agentic AI security for banks and credit unions. The U.S. banking technology provider serves about 7,400 community financial institutions and plans to combine Google Security Operations, Gemini Enterprise Agent Platform, and Mandiant Consulting across Google Cloud, other cloud services, and on-premises systems.
The deal is less about access to an advanced model than the work required to deploy one inside a bank. Security evidence is spread across user accounts, devices, applications, networks, and cloud services. Analysts must connect those records quickly enough to determine whether an alert is harmless or part of an attack. Smaller institutions often lack the security teams and integration capacity to do that across several enterprise products.
The divide and conquer commercial logic of the deal is Google brings the models, security software, and threat expertise. While Jack Henry brings the bank relationships and operating knowledge required to put them to work.
Google Security Operations collects security data from across an institution’s systems and connects related alerts into an investigation. Its Triage and Investigation Agent can retrieve evidence, apply threat intelligence, assess likely causes, and explain its findings.
Google says the agent has processed more than five million alerts and reduced a typical 30-minute manual investigation to about 60 seconds. Those are Google product results, not outcomes reported by Jack Henry customers.
The operating gain comes from completing the early investigation before an analyst steps in. Instead of opening several products, finding related records, and rebuilding the sequence of events, the analyst receives an assembled case with supporting evidence and a proposed response.
Sensitive actions still require clear limits and human oversight. Google can pair AI investigations with fixed playbooks and require approval before isolating a device, disabling an account, or blocking traffic. Jack Henry hasn’t said where it will draw those boundaries, how customers will audit agent decisions, or what happens when an automated recommendation is wrong.
Release timing, pricing, implementation requirements, and the first participating institutions also remain undisclosed, so the announcement is good on tech direction but light on adoption or performance figures inside an operating bank.
Mandiant Consulting adds threat modelling, security assessments, and red team testing. That work tests the design before attackers do. Gemini handles reasoning, while Google Security Operations provides the data and investigation tools.
Jack Henry must make the combined service fit each institution’s systems, controls, and support model. That integration is the difficult part.
A bank could buy Google’s security products directly. It would still need to connect the right data, define agent permissions, build response procedures, satisfy audit requirements, and decide who remains accountable for each action.
Jack Henry already operates inside that environment. Its core processing, digital banking, payments, lending, and operational products support institutions that rarely replace critical systems. It also manages hosted and on-premises deployments that a cloud provider may not control.
The companies began working together in 2022 on cloud data, reporting, and integration services. Security extends that relationship into a product Jack Henry can configure around each customer and deliver through an existing technology and support contract.
That could make AI security another banking software service rather than a separate enterprise purchase. Core providers already control the connections, implementation work, and customer access needed to distribute agents at scale.
Security specialists still compete on detection quality, threat intelligence, and response tools. CrowdStrike and Palo Alto Networks are adding agents to their products, while Fiserv offers managed cybersecurity services and is developing AI capabilities. Jack Henry competes from a different position. Its advantage is knowing how community institutions run and where security tools must connect.
Google gains a route into thousands of regulated institutions without implementing its products one bank at a time. Jack Henry can add a service whose value depends on its knowledge of each customer’s systems and operating requirements.
This is where enterprise AI economics become clearer. Foundation models can be sourced from a small group of large providers. The commercial asset is access to the workflow where the model can complete useful work under controlled permissions.
That favours software companies with deep customer integration. Fintech founders don’t need to build a foundation model, but a general AI interface won’t be enough. TD’s AI loan decisioning deployment shows why the value comes from placing verification and decision tools inside an active lending workflow. A specialized process, regulated decision, proprietary dataset, or difficult integration gives an agent work that an incumbent can’t easily reproduce.
Jack Henry hasn’t announced a Canadian release, but the deployment problem is familiar. Canadian regulated AI workshops have identified vendor dependence, data quality, model validation, and accountability as barriers to production use.
Access to a capable model isn’t the constraint. Banks need to connect it to existing systems without losing control of data, permissions, decisions, or operational risk. National Bank’s Sardine deployment follows that reality by embedding external device intelligence and risk scoring into retail, commercial, and wealth operations.
The Canada AI Consortium is working on common controls for models, agents, users, and enterprise systems. Its use cases differ from Jack Henry’s security project, but the operating requirement is the same: agents need restricted access, visible decisions, and accountable people.
For Canadian banks and fintechs, the commercial challenge is solving those controls inside regulated workflows. Products that leave the integration and governance work to the bank may struggle to progress beyond a pilot.
As foundation models become easier to replace, will banking software competition depend less on who owns the AI and more on who controls the workflows where agents can act?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Leave a Reply