On Thursday 10 September 2026 OpenAI unveiled ChatGPT for Financial Services: an edition of its assistant built on ChatGPT Work and the GPT-6 Astra model, with financial data from Daloopa, PitchBook, Crunchbase, Fiscal.ai and LSEG News built in, and the ability to produce valuation models, research notes and pitchbooks in a bank's own template. According to the announcement, Morgan Stanley and Evercore shaped the product as design partners, and the starting point is explicitly investment banking and equity research. Nick Turley, OpenAI's vice president of product and head of ChatGPT, told Fortune it was “the canonical product we are hoping the industry adopts”.
The public interpretation settled on the day of the launch, and it sits in CNBC's headline: OpenAI is going after the work of junior bankers. The question is a fair one, and this piece comes back to it. For an institution in the European Union, though, it is the second question. The first arises at the contract: a bank that buys an analyst tool, data vendors included, from the model provider is buying a chain of subcontractors, and supervisors have so far named only the bottom of that chain. The list of 19 critical ICT third-party providers published by the three European supervisory authorities on 18 November 2025 carries Microsoft, Google Cloud, Amazon Web Services and the data vendor LSEG. It carries no model vendor, in London no more than in Frankfurt. The bank therefore holds the chain on its own, under Articles 28 to 30 of the Digital Operational Resilience Act (DORA), and it holds it from the moment it signs.
What: on 10 September 2026 OpenAI unveiled ChatGPT for Financial Services, described on its product page as “a tailored ChatGPT Work experience” with GPT-6 Astra, natively hosted data from Crunchbase, Daloopa, PitchBook, Fiscal.ai and LSEG News, sign-in integrations for S&P Capital IQ, LSEG, MSCI, Dow Jones Factiva and Moody's, and more than 50 connectors under the Model Context Protocol (MCP). Design partners are Morgan Stanley and Evercore; availability is limited to “eligible financial institutions” and no price has been published
Who else: Google Cloud on 25 August 2026 with Gemini Enterprise for Financial Services, in preview for capital markets and corporate banking, with Deutsche Bank as design partner for the Financial Research Agent; Anthropic on 14 September 2026 with Claude for Financial Advisors for wealth advisers, following Claude for Financial Services, which has existed since July 2025
For whom: investment banks and research houses as users; in the EU their boards, COOs, CIOs and the people responsible for ICT third-party risk, compliance and research governance
Legal basis: DORA, Regulation (EU) 2022/2554, Art. 28 (principles, register of information), Art. 29 (concentration risk, subcontracting chains), Art. 30 (contractual provisions), Art. 31 (critical third-party providers); Delegated Regulation (EU) 2017/565 Art. 36 and 37 on investment research; AI Act Art. 4 (AI literacy) and Annex III
Status at the editorial deadline (18 September 2026): no bank named as a customer, no price, no regional rollout; the Financial Stability Board's final report on sound practices for AI is due in October 2026
Three vendors, twenty days, the same data providers
The 10 September announcement is part of a sequence that barely featured in the day's coverage. On Tuesday 25 August 2026 Google Cloud had unveiled Gemini Enterprise for Financial Services, according to its own press release “initially available in preview for the capital markets and corporate banking industries”, with Deutsche Bank as “key design partner for the Financial Research agent”. On Monday 14 September, four days after OpenAI, Anthropic followed with Claude for Financial Advisors, which WealthManagement.com reports comes with connectors to Charles Schwab, BlackRock, Addepar, Vanguard and other wealth-management providers. Anthropic's base product, Claude for Financial Services, has been around since 15 July 2025 according to its own announcement page, with LSEG and Moody's connected since October 2025. Three vendors have thus launched a finance product each within 20 days, and OpenAI was neither the first nor the last.
The list of data providers is more striking than the pace, because it is almost the same for all three. Daloopa, PitchBook, LSEG, FactSet, S&P Global and Moody's appear in Google's press release, on OpenAI's product page and in Anthropic's announcements. Emily Prince, Group Head of Enterprise AI at LSEG, is quoted by OpenAI as saying the collaboration “advances our LSEG Everywhere AI strategy”; LSEG uses the same strategy formula for its work with Anthropic. Whatever exclusivity an announcement full of partner logos suggests, it does not sit with the data. If it sits anywhere, it sits with the design partners, and this piece returns to that point.
The race itself is also older than the headline implies. According to Evident's Use Case Tracker, which records every publicly announced AI use case at the 50 largest banks, Anthropic was “the most referenced vendor” in the first quarter of 2026, and agentic systems reached a record 31 per cent of new use cases, up from 15 per cent the quarter before. A vendor that already has scale in capital markets is being challenged by a rival arriving with a premium product for one niche. That is interesting for the competition. For the bank it changes little: the contract question is the same with each of the three.
The vendor hosts the data, and the contract hangs on it
What OpenAI is delivering is described more precisely by the product page than by any summary. According to Fortune, a bank needs a ChatGPT Enterprise account; the finance product sits on top of it, and Nick Turley told the press briefing it was “a distinct offering from ChatGPT Work, although many of its features are derivative of it”. Administrators can, in OpenAI's words, publish “Excel, Word, and PowerPoint templates through a dedicated admin page”, and the model produces valuation models, research notes and pitchbooks “in their firm's format and style”. Every figure, the vendor says, carries a citation down to the source table. A dial sets the reasoning effort at three levels; according to Fortune the highest level uses more tokens and therefore costs more, and a sample slide deck took “about 10 minutes” in the demonstration. This is not a chat that answers. It is a tool that works and writes an invoice while it does.
The difference from the rival offerings lies in the architecture of the data, and for the contract that matters more than any benchmark. By its own description, OpenAI hosts the core data from Crunchbase, Daloopa, PitchBook, Fiscal.ai and LSEG News itself, indexed and prepared; for S&P Capital IQ, LSEG, MSCI, Dow Jones Factiva and Moody's it is working on “shared sign-in and entitlement integrations”, a pass-through of existing subscriptions. More than 50 connectors under the Model Context Protocol sit on top, among them Datasite, Box, Preqin, FactSet and Intapp. Anthropic, by its own announcements, mostly attaches its data partners as connectors, so the data stays with the supplier. For the analyst at the screen that makes no difference; citations work either way. For the third-party contract it is the difference between a vendor and a chain: in the first case the bank's licensed data sits in a second company's infrastructure, on that company's terms, in that company's locations.
The enterprise controls OpenAI lists are standard for the class: SAML single sign-on, SCIM provisioning, role-based access, encryption, configurable retention, export of workspace logs through the OpenAI Compliance Platform and separate workspaces “to enforce information barriers”. The sentence “Your firm's business data is not used to train our models by default” is a standard promise with a qualifier, and the qualifier is “by default”. What is missing can be read from the page as easily as what is there: no price, no region, no customer by name. Nick Turley declined, according to CNBC, to name banks that have signed up; there was “a ton of demand”. For a pre-contract assessment under Art. 28 (4) DORA, that is a thin file.
Supervision reaches the cloud, not the model
For an EU institution, an analyst tool procured from outside is an ICT service, and since the ninth revision of the German MaRisk took effect on 30 June 2026 such services no longer run through section AT 9 of MaRisk, according to BaFin circular 06/2026, but exclusively through DORA. Art. 28 (3) requires a register of information covering every contractual arrangement with ICT third-party providers, reported annually to the supervisor. Art. 28 (4) requires, before signing, an assessment of whether the service supports a critical or important function, and Art. 28 (8) a documented exit strategy where it does. Whether equity research and pitchbook production count as an important function is for the bank to decide; a bank that puts the tool at the core of its investment banking will struggle to answer no.
The article that aims at the chain is Art. 29. Paragraph 1 requires an assessment of whether the provider is “not easily substitutable”. Paragraph 2 goes further: where the contract allows the provider to subcontract services to other firms, the bank must weigh the benefits and risks “in particular in the case of an ICT subcontractor established in a third-country” and assess “whether and how potentially long or complex chains of subcontracting may impact their ability to fully monitor the contracted functions”. Art. 30 (2) then writes the chain into the contract: point (a) requires a statement of whether subcontracting is permitted and on what conditions, point (b) the regions and countries “where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location”, point (d) the return of data on insolvency or termination. A product that holds data from five suppliers in its own infrastructure and itself runs on someone else's cloud is exactly the arrangement these sentences had in mind.
The list of critical third-party providers under Art. 31, published on 18 November 2025 by the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA) and the European Insurance and Occupational Pensions Authority (EIOPA), shows where direct oversight starts today. It names 19 companies: four cloud providers, five network and data-centre operators, six IT service and consulting firms, two data vendors and two financial-software houses, by my own grouping. Microsoft Ireland Operations is on it, Google Cloud EMEA, Amazon Web Services EMEA, Oracle Nederland, Bloomberg and LSEG Data and Risk. OpenAI is not on it, Anthropic is not, and Google appears as a cloud, not as a model. The ESAs therefore oversee the layer the models run on and the data vendor found in all three products. The layer that replaces the analyst is, for now, the bank's affair alone. Frank Elderson, vice-chair of the ECB's supervisory board, described the position plainly in a speech on 3 June 2026: DORA “has also enhanced the oversight of critical third-party providers, such as cloud service providers”; vulnerabilities in a single, widely used infrastructure could “quickly escalate into disruption across an entire sector”.
The gap is known, and it is being negotiated internationally as we speak. On 10 June 2026 the Financial Stability Board (FSB) put sound practices for the responsible adoption of AI out for consultation; the twelfth practice requires institutions to exercise due diligence over AI providers “given provider concentration”, explicitly down to “4th and nth party vendors”, in other words along the chain. The Bank Policy Institute and the Institute of International Bankers countered in their July response that “vendor substitutability may not always be a viable risk management strategy” when only a handful of model providers exist, and asked for concentration risk to be treated as a matter for the sector rather than homework for each bank. The final report, the FSB says, is due in October 2026. Anyone signing today signs ahead of it.
London and Washington draw the same line
A look across the Channel and across the Atlantic shows that the line between cloud and model is no European peculiarity. On 10 July 2026 HM Treasury designated the first four Critical Third Parties under the Financial Services and Markets Act 2023, effective 13 July: Microsoft Ireland Operations, Google Cloud EMEA, Amazon Web Services EMEA and Oracle Corporation UK. The regime is, in the words of the press release, “rolling”, and further providers may follow. Until they do, the London list is shorter than the ESAs' and bears the same signature: four hyperscalers, no data vendor, no model vendor. The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority oversee the infrastructure on which Morgan Stanley's London analysts will use their new tool, and not the tool itself.
In the United States, where both design partners are based, there is no such list at all. In its Regulatory Notice 24-09, dated 27 June 2024, the Financial Industry Regulatory Authority (FINRA) stated that its rules are technology-neutral: Rule 3110 on supervision and Rule 2210 on communications with the public apply unchanged, whether a person or a model produced the text. In its oversight report for 2026 FINRA defines hallucination as a risk in its own right and recommends prompt and output logs as well as “human-in-the-loop review of model outputs”. The Securities and Exchange Commission (SEC) lists AI tools among its examination priorities for fiscal year 2026. And for the retention duty under Rule 17a-4, an analysis by the law firm Skadden from September 2024 concludes that an AI draft never sent is not a record to be kept, whereas a pitchbook that is sent is one, whatever its origin. Whether the prompts themselves are records remains open.
On the research side the EU applies the same technology neutrality, but without a clarification of its own. Art. 37 (1) of Delegated Regulation (EU) 2017/565 obliges investment firms that “produce, or arrange for the production of” investment research to put conflict-of-interest arrangements in place for the analysts involved; Art. 37 (2) prohibits trading with knowledge of unpublished research, requires information barriers and bars the issuer from seeing the draft before publication. Who drafted the research is of no concern to the rule. The analyst who signs off the model's draft is the “relevant person”, the firm remains the party bound by the rule, and Art. 20 of the Market Abuse Regulation still requires facts to be separated from opinion and the person making the recommendation to be identifiable. My own search found no AI-specific ESMA guideline on the point; the reading follows the text. Three supervisory jurisdictions, one answer: the tool does not change who is responsible.
The design partner pays in commitment
Morgan Stanley is no newcomer to this partnership. According to the bank's press release on its AI @ Morgan Stanley Debrief tool, OpenAI became “its only wealth management strategic partner” in March 2023; the full rollout of the AI @ Morgan Stanley Assistant followed in September 2023, and in June 2024, according to CNBC, Debrief was rolled out to around 15,000 advisers. The bank puts usage at 98 per cent of its adviser teams. The design partnership for investment banking is thus the third stage of a relationship that is three and a half years old and was exclusive on the wealth-management side. Evercore, the second partner, doubled net revenue to USD 1.4 billion in the first quarter of 2026 according to eFinancialCareers and raised headcount by just 65 to 2,635, mostly among senior managing directors. A firm that grows like that has an interest in scaling output per head.
The design-partner role sounds like influence, and Nick Turley describes it that way: “There's a difference between what looks good in a demo and what is actually a usable output, [and] you kind of rely on the experts.” Morgan Stanley's statement on OpenAI's page speaks of “a product increasingly informed by our people, our methods, and the work that matters to our clients”. That is accurate, and it describes the other side of the bargain at the same time: a firm that carries its methods into a vendor's product ends up with a vendor whose product knows its methods. For Morgan Stanley, which has relied on OpenAI since 2023, that deepens an existing tie. For Deutsche Bank, which took the same role with Google on 25 August, initially for German mid-cap corporate clients, it is the same decision with the sign reversed. And for the rest of the industry it raises the question of whether to buy a product that a competitor helped design.
The alternative is to build a layer of one's own, and it has a price that not every firm can pay. JPMorgan Chase runs its LLM Suite as what chief financial officer Jeremy Barnum calls “a generative AI platform that's model agnostic”, with access for more than 200,000 employees; Forbes put usage at more than 230,000 on 1 July 2026. Jamie Dimon summed up the attitude behind it: “We're going to be quite cautious on software-as-a-service, how we deal with cloud providers.” Goldman Sachs runs an in-house tool in the GS AI Assistant, and Citi unveiled Arc, an agent platform of its own, in April 2026. The case for one's own layer is a strong one, since it makes the model interchangeable and the assessment under Art. 29 easier. But a firm of 2,635 people does not build an LLM Suite, and for that firm a vendor's canonical product is the only option it can have running within twelve months. The design partner has chosen. The follower chooses with it, without having been asked.
The employment question comes second
Now to the story everyone reached for on the day. Asked by CNBC whether the product would reduce the need for junior bankers, Nick Turley answered with an analogy: “If you study the life of an analyst or of a banker, depending on the industry, they're working 100-hour weeks. I think in the same way that Microsoft Excel transformed the industry and allowed them to produce better analysis faster, you will see technology like this do the same.” The analogy has history on its side; the spreadsheet did not shrink the industry's headcount. What it skips is what Chris Churchman had said just over two weeks earlier on CNBC's podcast: Excel never did anyone's thinking. A model that drafts both the analysis and the conclusion removes precisely the repetition through which judgement used to be built. Chris Churchman, who ran foreign-exchange trading at UBS before joining Goldman, put it in a sentence: “You learn by doing, and a lot of knowledge is tacit, it was never written down.” And his own system on the Marquee platform, pressed hard, had conceded: “I'm better at sounding thorough than being thorough.”
The numbers are still young, but they point in one direction. In the revision of its Canaries in the Coal Mine study dated 12 August 2026, the Stanford Digital Economy Lab reported no broad displacement by AI, but employment of 22- to 25-year-olds in AI-exposed occupations 19 per cent below where it would be had it tracked less exposed peers; in August 2025 the figure was 15 per cent. The adjustment, according to the authors Erik Brynjolfsson, Bharat Chandar and Ruyu Chen, comes through fewer hires rather than layoffs, and the authors call their findings “descriptive patterns, not causal estimates”. The Federal Reserve Bank of Dallas reached the same pattern from wage and employment data on 24 February 2026. David Solomon had already told Axios in October 2025 that anyone assuming Goldman Sachs would therefore have fewer people misunderstood how it works; Jamie Dimon told Bloomberg on 21 May 2026 that JPMorgan would hire “more AI people and fewer bankers in certain categories”. Both sentences can be true. One is about the total, the other about categories.
For a bank in the EU none of this yields a forecast, but it does yield a checklist. A firm that introduces a tool which, in the words of Joseph Kim, product lead at OpenAI, gives the new intern everything “pre-loaded and ready to go” on day one changes its training whether it intends to or not. The question of how a firm will still have senior analysts in five years' time who can check a model's analysis for plausibility belongs in the same board paper as the register of information. It appears in no article of DORA. It appears in Art. 4 of the AI Act, which since 2 February 2025 has required every deployer to ensure a sufficient level of AI literacy among its staff, and in Art. 37 of the Delegated Regulation, which presupposes an analyst who knows what he or she is signing. The tool is not a high-risk system under the AI Act: Annex III covers creditworthiness assessments of natural persons and risk pricing in life and health insurance, not the valuation of companies. The heavy deployer duties do not apply here. The light ones are enough.
Recommendations
Before signing: determine the criticality of the function under Art. 28 (4) DORA and enter the service in the register of information, with the chain behind it: model vendor, cloud infrastructure, every natively hosted data supplier. For each link demand the particulars required by Art. 30 (2): location of processing, conditions of subcontracting, return of data on termination. A vendor that cannot supply them has already answered the Art. 29 assessment.
In procurement and legal: for every data vendor hosted natively in the product or passed through by sign-in, check whether the bank's existing licence permits use inside a third party's infrastructure at all and who is liable if it goes wrong. The same suppliers appear with OpenAI, Google and Anthropic, so the question arises regardless of vendor, and it arises before the first prompt.
In architecture: store house templates, valuation logic and prompt libraries so that they can be moved to a second tool; export prompt and output logs and keep them in the bank's own archive, not only in the vendor's compliance platform. That is the exit strategy under Art. 28 (8) in practical form, and it is the answer to the substitutability question the Bank Policy Institute has described as open for the industry.
In research and investment banking: every analysis and every pitchbook drafted by the model passes through sign-off by a named individual, with a documented plausibility check of the citations; that satisfies Art. 37 of the Delegated Regulation and FINRA's expectation in one step. In parallel, decide which tasks entry-level staff continue to do by hand, so that in five years there is someone in the building who can judge the model's output.
Glossary
Design partner: a customer that shapes a product together with the vendor before launch and receives early access and influence over its features in return. For the bank that means influence over the tool and, at the same time, a tie to a vendor whose product now knows the bank's methods.
Critical ICT third-party provider (CTPP): a provider that the three European supervisory authorities oversee directly under Art. 31 DORA because of its importance to the financial sector. The first list, of 18 November 2025, names 19 companies, among them cloud providers and data vendors but no provider of language models; for the contract with a model vendor the bank remains solely responsible.
Register of information: the record of all contractual arrangements with ICT third-party providers under Art. 28 (3) DORA, reported to the supervisor annually. An analyst tool and its data suppliers belong in it, with a statement of whether it supports a critical or important function.
Model Context Protocol (MCP): an open standard through which language models call tools and data sources. With a connector the data stays with the supplier and is fetched at run time; with native hosting it sits with the model vendor. For the third-party contract that is the difference between a vendor and a chain.
Effort dial: the setting with which the user chooses the model's reasoning effort at three levels. More effort means more tokens, more cost and, the vendor says, better results; for the bank the quality of an analysis becomes, as a result, a cost decision per task.