Banks Don't Need Another Agent. They Need a Context Layer.
An agent that fails inside a bank rarely fails because the model was stupid. It fails because it was guessing.
The demo always works. Someone stands up a sharp agent, wires it to a few clean tables, and watches it answer questions about balances, exposures, or delinquency like a seasoned analyst. Then it ships, meets the real data estate, and starts confidently reporting the wrong number. The reasoning did not break. Nothing ever told it what “the number” means.
That gap between a good demo and a governed deployment is the whole game right now, and it does not live in the model. It lives one layer down, in the thing the industry has started calling the context layer. Almost nobody demos that layer, because it is unglamorous plumbing. It is also where banking AI is quietly won and lost.
The graveyard has a common cause
Start with the sober numbers, because the hype numbers are useless.
Menlo Ventures, surveying enterprise decision-makers for its 2025 State of Generative AI in the Enterprise, put enterprise spend on generative AI at thirty-seven billion dollars, more than triple the year before. The same report found that only sixteen percent of those deployments were true agents, systems that actually plan, act, observe, and adapt. The rest were assistants and scripted workflows wearing the costume.
Gartner stapled an expiration date to the froth. It expects more than forty percent of agentic AI projects to be canceled by the end of 2027, undone by cost, unclear value, and inadequate risk controls. It also named the disease: “agent washing,” the rebranding of chatbots and RPA as agents. By Gartner’s count, roughly a hundred and thirty of the thousands of vendors claiming agentic capability are the real thing.
Banking sits at the cautious end of all of it. McKinsey’s read on the front line is that agentic AI across financial institutions remained very limited in 2025, with most institutions stuck in pilots and almost none scaling.
Read those three findings together and one cause shows through the noise. The projects that die are the ones where the agent was asked to reason over data it did not understand. The model was fluent. The context was missing. I made the broader version of this argument in Agent as a Service Is Real. The Vendor Pitch Isn’t., where the layers that actually carry an agent turn out to be the ones no keynote shows.
What a context layer actually is
Retrieval-augmented generation, the pattern most teams reach for first, fetches text. It finds the paragraphs that look relevant and hands them to the model. That is useful for a policy document and useless for a question like “what was net charge-off in commercial real estate last quarter,” where the answer depends on how the institution defines the metric, which entities roll into it, whose permission gates the rows, and which system of record is authoritative.
A context layer supplies that. Not text, meaning. Metric definitions, lineage, ownership, access policy, and the relationships between entities, served to the agent at the moment it reasons rather than left for it to infer from raw tables. The category has picked up a family of names, context layer, context engineering, context orchestration, and they all describe the same move: put a governed tier of business semantics between the data and the model.
The delivery mechanism has largely settled. Anthropic published the Model Context Protocol in late 2024, and within a year it had been adopted across OpenAI, Google, Microsoft, and AWS and moved under open governance. MCP is not the context layer. It is the socket the context layer plugs into, which is why almost every vendor in this space now speaks it.

The reason this matters more in a bank than anywhere else is grounding. An agent that invents a definition in a marketing tool writes a bad email. An agent that invents a definition in a bank misstates a regulated number. The context layer is the difference between an agent that knows and an agent that guesses, and in a regulated shop that difference has a legal weight.
Read the market by its bloodline
The vendors crowding into this space did not start from the same place, and the fastest way to tell them apart is by where they came from.
- The semantic-layer bloodline. These grew out of analytics, defining metrics once so every tool computes them the same way. dbt’s Semantic Layer is the incumbent, and defines metrics inside the data project itself. Cube has repositioned its semantic layer explicitly as an AI context layer, and offers the cleanest finance proof point on the board: by Cube’s telling, Brex evaluated it against dbt and LookML, chose it, and built “Brex Spaces,” an embedded AI financial analyst, on top. When the definitions are already governed, grounding an agent is a short step.
- The knowledge-graph bloodline. Glean built enterprise search and turned its graph of people, documents, and projects into the context tier that agents query. The pitch is that the map of who-knows-what and what-relates-to-what is itself the context.
- The catalog and governance bloodline. Atlan and DataHub came from metadata management, and now serve their governed catalogs, glossaries, lineage, and access rules to agents over MCP. Their own “state of context” surveys should be read as marketing, but the underlying asset, a governed map of the data estate, is exactly what an agent needs and most banks already half-own.
- The finance-native, consulting-led entrant. reknew.ai is the odd one out and worth naming precisely. It is not a platform. It is an enterprise data and AI transformation firm, founded by people who ran data and AI programs inside large financial institutions, that sells a methodology it calls Context Engineering, staffs a role it calls Context Architect, and partners with DataHub for the governed-metadata piece. Its case studies are anonymized “Top 20 US bank” engagements, and it is small and thinly documented, with no public funding or named customers I could verify. The bet is different from the platforms: not “buy our layer” but “we will build yours, the way a regulated shop needs it built.”
Underneath these sit the agents that live or die on whatever context layer feeds them. Norm Ai turns regulations into compliance agents, and tellingly raised from incumbent financial institutions, Citi Ventures, New York Life, TIAA, and others. Greenlite runs anti-money-laundering and know-your-customer work. Hebbia and Rogo do investment research over dense documents. Every one of them is only as good as the grounded meaning it is handed. The agent is the visible product. The context layer is the part that decides whether it is right.
In a bank, the context layer is the audit trail
Here is where banking stops looking like every other industry.
Outside a regulated wall, the context layer is a quality and performance concern. A better-grounded agent gives better answers. Inside a bank, the same layer is doing three jobs at once, and only one of them is performance.
It is the grounding surface, so the agent cites the authoritative number instead of a plausible one. It is the permission surface, because the layer that knows what a row means is the same layer that must know who, or what, is allowed to see it. And it is the provenance surface, the place where you record which definition was used, which identity invoked it, and what the downstream effect was. An ungrounded agent that hallucinates a figure is not a user-experience bug in this world. It is a control failure.
That third job is the one the vendor demos skip. When the actor reasoning over your data is a non-human identity, the questions an examiner asks do not change. Which credential did this action run under. What did it access. Can you reconstruct the chain. Most agent frameworks cannot produce that chain today, and the context layer is the natural place to make it, because it already sits between the agent and everything it touches. I have written before about why non-human identities are the unsolved governance frontier here, and the context layer is where that frontier and the grounding problem meet.
This is also why the returns look different. The context layer is real work, and real work does not produce the ten-times number the vendors promise. It produces something closer to three, which is the argument I made in The Compliance Tax, and three is still transformational. The tax is not a bug in banking AI. It is the price of the number being defensible.
The question isn’t which vendor. It’s who owns the meaning.
Strip away the logos and the real decision is older than any of these companies.
Once the context layer holds your metric definitions, your lineage, your access policy, and the accumulated corrections of a hundred analyst arguments about what a number means, it stops being infrastructure and becomes the institution’s compiled knowledge. That asset is more valuable than any agent that reads it, and where it lives is an architecture decision with consequences, which is the case I made in The AI Context Portability Problem.
A platform, Glean or Cube or Atlan, hands you a product and a dependency. Your compiled meaning lives in their model, and leaving means rebuilding it. A consulting-led approach like reknew’s transfers the discipline and, in principle, leaves the artifact in your estate, but you have to make ownership and portability an explicit term rather than a hope. Neither answer is wrong. The mistake is not asking the question, and discovering two years in that the most valuable thing you built is the one thing you cannot take with you.
The framing I keep coming back to is that context engineering is not a feature you buy, it is infrastructure you own, and I laid out that blueprint in Context Engineering Is Infrastructure, Not a Skill. The vendors are useful. They are not a substitute for owning the meaning.
The category is early and the labels are already dirty
I want to be honest about how new all of this is.
“Context layer” is already being stamped on old data catalogs that changed a landing page. The vendor “state of context” surveys are self-serving, and I would not price a decision off any of them. reknew is real and the finance pedigree is credible, but it is a small firm with anonymized case studies, and enthusiasm is not verification. Even the sober counterweights, Menlo’s sixteen percent and Gartner’s forty, are snapshots of a category still forming.
So do not buy the layer as a product and assume the problem is solved. Buy the discipline underneath it. Every agent you point at regulated data should be grounded in governed meaning it did not invent, running under an identity you can name, leaving a trail you can reconstruct. Some vendor will help you build that. None of them will do it for you, and none of them will own the consequences if it is wrong.
The model was never the constraint. The banks that win the next round will be the ones that figured out the least glamorous part first: the ungoverned meaning underneath the agent was always the thing holding it back, and building that layer well is the actual work. Everything above it is just the demo.
The companion read is Context Engineering Is Infrastructure, Not a Skill, which lays out the blueprint this post argues banks have to own. For the same thesis seen through the Fiserv and Salesforce data wall, see The Data Was Always the Problem. And for why the returns land at three times rather than ten, see The Compliance Tax.
I write about AI-assisted development, enterprise architecture, and building in regulated environments. If you’re weighing a context layer against your own data estate, I’d like to compare notes. Find me on X @orestesgarcia or LinkedIn /in/setsero.