SWIFT Doesn't Touch Money: How a Non-Settling Company Sat at the Center of Cross-Border Payments for 50 Years
It holds no funds, bears no credit risk, and competes with no customer. The six things it got right are now replaying in agentic payments.

Cross-border payments are slow, expensive, and opaque, and most people's first instinct is to blame SWIFT. That impression rests on a fundamental misunderstanding: SWIFT has never touched your money.
It doesn't settle. It doesn't hold client funds. It doesn't bear credit risk. There is not a single dollar of client deposits on its balance sheet. The only thing it does is enable more than 11,000 institutions that don't trust each other and compete fiercely to use a common language to say clearly, "Who is paying whom, how much, and when."
The money moves over correspondent banks' ledgers and through clearing systems like CHIPS, Fedwire, and TARGET2. What travels over SWIFT is only the instruction.
This distinction is not a technical detail. It is the key to understanding something else: how a company that doesn't touch money has sat at the center of global capital flows for fifty years. And that story is now replaying on the new track of agentic payments.
1. Founded by the demand side, not sold by the supply side
In 1973, 239 banks from 15 countries jointly founded SWIFT in Brussels. The system went live in 1977.
Note the starting point. It wasn't a tech company building a product to sell to banks. It was banks, fed up with the status quo, pooling their own money to build it themselves.
The status quo then was telex. Its problem wasn't slowness—it was unreliability: free-form text, no standardized formats, no uniform institution identifiers, and manual verification of test keys to confirm authenticity. A single remittance could take days of back-and-forth, and often failed to match because the counterparty's name was written differently.
This has a direct implication for today. Anything that aspires to be "shared infrastructure" is never ultimately sold—it is pulled into existence by a group of people fed up with the current state. Finding that group matters more than building a better product.
2. The moat is standards and directories, not code
SWIFT holds two things of real value.
The first is the BIC (Bank Identifier Code)—the 8-to-11-character code you fill in when wiring money, like DEUTDEFF for Deutsche Bank Frankfurt. It's the ISO 9362 standard, and SWIFT is its registration authority—the unique identifier for every institution worldwide is maintained by SWIFT. It's an address book.
The second is ISO 20022, the common language for financial messages. The old MT messages had few fields and limited characters; ISO 20022 is structured, capable of carrying full payment purpose, both parties' identities, and invoice details—precisely the fields compliance reviews need most. SWIFT is also the registration authority for this standard.
This leads to a counterintuitive conclusion: message transmission itself is the least special layer. You could write message software far better than SWIFT's, but you wouldn't have the address book, and you couldn't unilaterally dictate "what a payment instruction looks like." The value lies in "everyone agrees to use this one set," not in "how clever this set is."
For agentic payments, the implication is concrete: protocol layers like x402, A2A, and MCP already have multiple open-source implementations running. This layer is no one's moat. What's genuinely vacant are the two layers above—the identity directory linking agents to legal entities, and the expression of authorization and compliance credentials.
3. Neutral ownership structure is part of the product
SWIFT is a cooperative under Belgian law. Its shareholders are its member institutions, governed by a board elected by members, with the Belgian central bank leading and G10 central banks forming a joint oversight mechanism. Surpluses aren't distributed to shareholders—they go to price cuts and reinvestment. SWIFT has publicly lowered its message prices multiple times over its history.
An ordinary company holding this kind of position would be jacking up prices. SWIFT cuts them. That's not kindness; it's defense. Once prices rise high enough to hurt members, they'll build alternatives—and SWIFT's members happen to be the institutions best positioned in the world to do exactly that.
But the more fundamental point is ownership itself. Citi and HSBC are archrivals. Why would they hand all their cross-border traffic to the same rail? Because that rail belongs to neither Citi nor HSBC. If SWIFT were a JPMorgan subsidiary, no competitor would use it—that would mean handing over customer flows, transaction rhythms, and partnership networks to a rival every single day.
So "neutrality" here isn't a moral posture; it's commercial design. For anything aiming to be a common standard, its ownership structure determines whether competitors dare to use it; whether they dare determines adoption; adoption determines whether the standard is worth anything.
4. Compliance business is monetizing the position, not a means to get it
Today SWIFT sells sanctions-list screening, the KYC Registry, and compliance analytics. But these came decades later.
They work because SWIFT was already sitting in that position—it sees all message flows, so its screening is naturally more comprehensive than anyone else's. In other words: position first, compliance business second.
This is a reminder to everyone in agentic payments: selling compliance services directly is skipping the first step.
But the sequence isn't the only one. SWIFT secured its position through network effects—a path that requires critical mass, is slow, and burns capital. The other path is securing position through data and credibility—on-chain analytics firms start with compliance tools and, through adoption by law enforcement and exchanges, become de facto industry infrastructure. The first step on that path isn't signing up a hundred users; it's signing up one authoritative adopter and turning it into a source others cite.
5. The 2016 incident was a full rehearsal for prompt injection
In February 2016, the Bangladesh central bank lost $81 million.
What's notable isn't the amount—it's the attack method: the SWIFT network itself was never breached. What was breached was the terminal on the member's side. The attackers obtained valid credentials and sent messages that were fully format-legal.
You cannot defend against this kind of attack by "checking message format"—the messages themselves had nothing wrong with them.
SWIFT's response, therefore, wasn't to harden the network but to launch the CSP (Customer Security Programme): mandating that all members make annual declarations about security controls on their own side, and making those declarations visible to counterparties—whether they've declared, and what they've declared.
This is a complete rehearsal for prompt injection in AI agents. When an agent's "brain" is compromised, it sends a payment request that is equally format-legal: the amount is within authorization limits, the recipient address is correctly formatted, and the signature is valid. Any mechanism that inspects the request itself will fail to stop it.
The viable direction is the same as SWIFT's back then: don't try to determine whether the agent's thoughts are compromised; instead, enforce boundaries outside reasoning and make those boundaries verifiable by third parties. Concretely, three things—define the controls an agent must satisfy before initiating a payment; require operators to make verifiable declarations about their own side; and let the paying counterparty check that declaration before settlement.
It's not about solving prompt injection; it's about making it no longer determine the outcome.
6. When used as a weapon, it starts to erode its own monopoly
In 2012, due to EU sanctions, SWIFT disconnected Iranian banks; in 2022, it disconnected some Russian banks.
The effect was immediate—but the cost was that countries realized this rail is not neutral. Since then, China has advanced CIPS (Cross-Border Interbank Payment System), Russia built SPFS, and the EU attempted INSTEX. Each alternative has its own limitations, but the direction is clear: once monopolistic infrastructure is used as a weapon, it begins to erode its own monopoly.
This is a warning for designers of new standards: if your standard can be unilaterally cut off by a country or a company, then from the day it becomes valuable, someone will start building a backup. Neutrality isn't just about making others dare to use it—it's also about making the standard last.
It has reached this point itself
On July 9, 2026, SWIFT announced its blockchain shared ledger was ready, with 17 banks—including Citi, HSBC, Standard Chartered, UBS, DBS, MUFG, Wells Fargo, ANZ, BNP Paribas, and BNY Mellon—set to pilot tokenized deposits for cross-border payments, aiming to extend cross-border money movement from business days to 24/7. SWIFT positions itself as the orchestration layer: funds move on the shared ledger, while final settlement still returns to existing clearing rails.
Worth noting separately is the official language: SWIFT lists "programmable money and agentic commerce" as functional directions the ledger will support going forward.
In other words, it has acknowledged the direction but hasn't yet done it.
Before this, SWIFT's CBDC interoperability sandbox had completed two phases of testing, with over 38 institutions including more than 7 central banks, completing over 750 simulated transactions—its positioning on CBDC is likewise not as an issuer, but as "the layer connecting national digital islands."
So which layers are vacant
Break SWIFT into layers, then look at the corresponding positions in agentic payments, and the conclusion is fairly clear:
- Transport protocol layer—multiple open-source options already exist; no need to compete.
- Settlement layer—stablecoins and various chains already handle it; no need to touch.
- Identity directory layer—which agent belongs to which legal entity is currently done piecemeal by each player; there's no common directory (OceanAlt has a single-point registry, but a registry isn't an industry directory).
- Credential language layer—how to express an agent's authorization scope, intent, and compliance conclusions so the counterparty can understand them is still up for grabs.
- Control baseline layer—who defines the controls agent operators must meet and declare externally is something no one has done before; OceanAlt launched the first version of an Agent Control Baseline in September 2026 (public control list + self-attestation + counterparty verifiability before settlement), with external adoption still to be proven.
- Governance layer—who owns these rules is not yet designed by anyone.
All three gaps are concentrated in identity, control baselines, and governance—not in the technology layer. On the control baseline, someone has just taken the first step. The technology layer is saturated—writing yet another better payment protocol won't change anyone's position.
SWIFT proved over fifty years that in the payments business, the layer that doesn't touch money is often the hardest to replace. The precondition is that you have to get there first.
Primary Sources
- SWIFT official press release, "Swift's blockchain ledger ready for use as 17 banks set to pioneer tokenised cross-border payments," July 9, 2026.
- SWIFT CBDC sandbox Phase 2 results report (Connecting digital islands: Swift CBDC sandbox project – Phase 2).
- ISO 9362 (BIC) and ISO 20022 standard texts and registration authority information.
- Public materials on the 2016 Bangladesh central bank incident and SWIFT's Customer Security Programme (CSP).
Note on framing: All specific figures cited in this article come from the public sources above. The judgments about the current state of each layer in agentic payments, and the conclusion about "where the gaps are," are OceanAlt's analytical assessments, not established facts.
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-09-07
- Last updated
- 2026-09-07
- Content type
- Original analysis
- Source material
- View primary source ↗
Related reading
Someone poisoned your wallet: how a $0 transfer steals your next payment

Visa and Mastercard Join Ant International on a KYA Interoperability Framework as Agent Identity Standards Begin to Converge

Consumers Use AI Assistants but Won't Hand Over Their Wallets: Visa Data Reveals the Agent Payment Trust Gap
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

