On September 10, 2026, OpenAI launched ChatGPT for Financial Services, a version of its enterprise product built with Morgan Stanley and Evercore as design partners and aimed at investment banking and equity research. Running on OpenAI's new GPT-6 Astra model, it's meant to research companies, build financial models, and produce client materials like pitchbooks in a firm's own templates, with citations traced back to source. Finextra reported the launch as OpenAI's answer to Anthropic's Claude for Financial Services, part of a broader race between the two companies to embed themselves into Wall Street workflows.
The headline is “OpenAI launches an AI tool for banks.” The more useful read is what's actually sitting behind that one tool.
According to OpenAI's own launch article and VentureBeat's reporting, the product isn't a single data relationship wrapped in a chat interface. It's built on at least three separate layers of third-party data. Built-in datasets from Daloopa, PitchBook, LSEG News, Crunchbase, and Quartr are indexed directly on OpenAI's own infrastructure. Shared sign-in and entitlement integrations are being built with S&P Capital IQ, LSEG, MSCI, Dow Jones Factiva, and Moody's, so those providers can recognize a user through their ChatGPT login and apply data access the firm already pays for. On top of that sits a connector ecosystem OpenAI says now exceeds 50 integrations, including FactSet, S&P Global, Preqin, Datasite, Box, and Intapp.
A bank that licenses ChatGPT for Financial Services isn't onboarding one vendor. It's inheriting direct dependencies on a dozen-plus named data providers, layered across three different integration models, most of which that bank never negotiated, audited, or reviewed on its own terms. Whereas the bank just reviewed OpenAI.
The built-in tier isn't a live pass-through to each provider's own systems. OpenAI says that data is indexed on its own infrastructure, specifically to improve retrieval and enable the granular citations the product is built around. That means licensed data from Daloopa, PitchBook, LSEG News, and others now has a working copy sitting inside OpenAI's environment, a location distinct from the provider's own systems and from the bank's. Whatever security posture, refresh cadence, or error-correction process each of those providers runs on its own data no longer fully determines what a banker is looking at. OpenAI's handling of that indexed copy now sits in the chain too.
That copy is what feeds directly into valuation models and client pitchbooks carrying the bank's own name and templates. A stale figure or a licensing dispute at any one of those providers doesn't stay contained to that provider. It shows up in a document a client reads as the bank's own analysis.
OpenAI has built genuine controls into this: role-based access, encryption, and workspace logs compliance teams can export into their own audit workflows. That's certainly not nothing, and it's worth acknowledging. But those controls govern OpenAI's own platform. They don't extend to an independent, ongoing view of Daloopa's security practices, PitchBook's data pipeline, or whatever provider gets added to the connector list next. The audit trail tells a compliance team what happened inside ChatGPT. It doesn't tell them what's happening inside the many companies whose data now runs through it.
This isn't a criticism specific to OpenAI. Anthropic's own competing product runs on the same basic model: one AI provider, multiple embedded data sources, one interface. That's simply how this category of product gets built, and it's a reasonable way to build it. The real issue is what happens once that architecture spreads across an open finance chain rather than sitting inside a single institution.
ChatGPT for Financial Services is starting with investment banks, but the same category of tool, and its direct rivals, won't stay there. Open finance aggregators, lenders, payment platforms, and the fintechs sitting between them do the same kind of research, underwriting, and client-facing work, and all of them are candidates to run on a version of this same architecture. Once that happens, the dozen-plus data providers sitting behind one interface stop being a risk contained inside one institution's own third-party review. They become a shared dependency sitting underneath multiple, unrelated participants across the same chain at once. A licensing dispute or security incident at any one of those providers wouldn't stay contained to whichever institution reviewed its AI provider most carefully. It would surface across every bank, aggregator, and platform running on the same underlying data, at the same time.
That's a concentration risk no single participant's own assessment is built to catch, because no single participant can see who else in the chain depends on the same providers it does. It only shows up to something which monitoring the chain as a whole, continuously, rather than reviewing one counterparty relationship at a time. This is exactly the same open finance problem that this blog keeps coming back to, just one layer further up the stack.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.