Skip to content
All articles

Sep 14, 2026 · 4 min read

Weekly brief 7–13 Sep: AI moves from answering to acting

A quiet week for Mendix releases, but one requirement is getting clearer: AI that takes part in critical processes needs an identity, a defined scope of authority, trustworthy data and decisions that can be traced.

The week of 7–13 September 2026 was quiet for Mendix product releases. The signal was elsewhere: several announcements pointed at the same requirement. AI that takes part in critical processes needs an identity, a scope of authority, trustworthy data and traceable decisions — not just good answers.

Siemens and Mendix

Siemens brings the digital thread to AI in banking and insurance

On 9 September 2026 Siemens argued that AI in banking, financial services and insurance (BFSI) should be designed outwards from regulation rather than having compliance added later. In this setting "mostly right" is not acceptable: outputs must be explainable and auditable, often with a human in the loop.

The digital thread, a familiar idea in manufacturing, is extended to BFSI: connecting data, context and the trail of decisions across onboarding, lending, underwriting, fraud and financial crime.

Why it matters: it is a good reference model for any system with AI-assisted assessment. The AI makes a recommendation, but what makes a complete solution is the workflow, approval rights, rationale and audit trail around that recommendation.

Source: Siemens — Insuring trustworthy AI for BFSI

On 11 September 2026 Siemens described how Polarion, together with PLM such as Teamcenter, turns regulatory obligations into structured requirements and links them to architecture decisions, software changes, testing, validation and release documentation. It uses the EU Data Act and automated driving regulation as examples of compliance now being tied to day-to-day development.

Why it matters: the principle carries over to LIMS, ISO/IEC 17025 laboratories, quality management and any system that has to answer "which requirement was verified by which evidence".

Source: Siemens Polarion — Regulation is no longer a silo

Mendix: no new release this week

The latest release on the Mendix blog is still Mendix 11.14, published 26 August 2026. It adds Java 25 support and ships with Agents Kit 2.2, which lets users be asked for approval before an agent invokes a tool.

Why it matters: companies running Mendix can use the lull to test Agents Kit 2.2, Java 25 and human approval flows in a test environment before deciding to upgrade production.

Source: Mendix — Mendix Release 11.14

Market

Backbase and Mastercard combine AI capabilities for banks

On 9 September 2026 Mastercard announced it is bringing four capabilities into the Backbase Banking OS: Dynamic Yield for personalisation, Test & Learn to measure the commercial impact of product, pricing and campaign changes, SpendingPulse for sector-level spending data, and Cyber Quant for cyber risk assessment. The two position it as the infrastructure to move agentic banking from experiment to production. According to Fintech News Singapore, it is their second collaboration of 2026.

Why it matters: banking platforms are competing on ecosystems of capability and data, no longer just on digital interfaces or chatbots.

Source: Backbase · Fintech News Singapore

Visa, Mastercard and Ant International start on "Know Your Agent"

On 10 September 2026 the three announced work towards a shared interoperability framework so card networks, digital wallets, marketplaces and agent platforms can identify and verify AI agents transacting on a user's behalf. Each already has its own protocol: the Visa Trusted Agent Protocol, Mastercard Verifiable Intent and the Agentic Mobile Protocol from Ant International.

This is a starting point, not a finished standard. PYMNTS reports the three will explore common principles; Forkast notes that no technical specifications, governance bodies or rollout timelines have been disclosed.

Why it matters: alongside user identity, enterprise systems will need to manage agent identity — who owns the agent, what it is authorised to do, its limits, and how its access is revoked.

Source: PYMNTS · Forkast

A quiet week in Vietnam

We saw no new major project or investment in Vietnam directly related to low-code or enterprise applications that was confirmed well enough to include. The strongest regional signals were in agentic banking, payments and agent identity governance.

What the week had in common

Side by side, these items show the question shifting. It used to be "does the model answer well"; now it is "is the AI allowed to do this, who allowed it, based on which data, and what trail does it leave".

For companies in Vietnam considering AI in their processes, those four things should be designed in from the start: the agent's identity and owner, its scope of authority, trustworthy data sources, and a log that traces each decision. Adding them after the system is running always costs far more.