Webinar: How to Build an AI-Ready Open Banking API
Is your Open Banking API ready for AI?
Open Banking APIs are no longer consumed solely by developers and third-party providers. Increasingly, AI-powered tools and agents are relying on API definitions to discover, understand, and interact with banking services.
For API teams at European banks navigating PSD2 today and preparing for PSD3, this raises an important question: Is your API ecosystem ready?
Join Joe Joyce, Solutions Architect on July 8 for a 30 mins webinar, exploring how OpenAPI specifications can help financial institutions build APIs that are compliant, governable, and ready for the next generation of consumers.
Community Spotlight
Marco Antonio Sanz: Where AI Belongs in APIOps
Marco Antonio Sanz works across API governance, security, design, operations, and artificial intelligence. He is the chief executive of APiquality, an APIOps platform, and serves as an API and AI evangelist with the APIAddicts Foundation, where he also teaches and supports its open source work. Through APIAddicts, he has helped build a community focused largely on Spain and Latin America that reports more than 10,000 members, over 100 events organized during the past decade, and more than 500 people trained through its academy.
His approach to AI begins with the API lifecycle already in place. APIOps treats the API specification as the source for automated checks, artifact generation, deployment, testing, and documentation. Sanz places AI within those existing stages rather than using it as an independent layer that makes decisions without context.
During API design, AI can help create schemas, examples, and parts of an OpenAPI specification. The model needs access to the organization’s style guide, API templates, existing components, and service catalog so that its output reflects the wider platform. Generating an entire specification in one step gives the model too much scope and makes governance harder to maintain.
Sanz draws a clear line between deterministic checks and tasks that require interpretation. Syntax validation, linting, test execution, scoring, and deployment should remain inside predictable tools and automated pipelines. AI is more useful when it explains a validation failure, proposes a correction, creates realistic examples, expands functional test cases, or analyzes test results. This keeps the final decision tied to repeatable controls while using AI to reduce the manual work around them.
The same separation applies to production operations. AI can help write a deployment template or continuous integration step, but the API manager and delivery pipeline should perform the deployment. It can draft onboarding material for a developer portal, but that material still requires review before publication.
Sanz also extends APIOps with an AI readiness check covering experience, reliability, security, safety, and semantic discovery. The assessment asks whether an agent can understand the specification, interpret errors, authenticate correctly, operate within defined permissions, and use the API without human guidance. His broader contribution is a practical boundary for AI in API engineering. Use it where context and interpretation add value, while keeping validation, scoring, execution, and production control inside systems that behave consistently.
API Feed
Know the Latest from the World of APIs
Google made the Agent Registry API v1 generally available on its Gemini Enterprise Agent Platform, with cloud client libraries across seven languages. The release adds support for the Agent-to-Agent (A2A) protocol v1.0, letting teams declare transport endpoints and bindings directly. Terraform support for managing agents, MCP servers, and endpoints also reached general availability.
Anthropic released Workload Identity Federation for the Claude Platform, bringing keyless authentication to all its API endpoints, SDKs, and Claude Code. It swaps static API keys for short-lived, scoped credentials issued at request time, and works with any OIDC-compliant identity provider. The release also adds support for service accounts and the Admin API for programmatic identity management. Paired with interactive login for sessions, it means developers never need to handle a static key when building on the platform.
Google shipped a security-only hotfix for the Apigee Emulator, version 2.0.1, addressing ten vulnerabilities in the Netty networking library and an embedded health-check binary. There are no functional, API, or configuration changes, making it a drop-in replacement for v2.0.0. The fix updates Netty to 4.1.135 and refreshes the Cassandra base image used by the health-check binary. The image is available in the Google Artifact Registry, with upgrades applied via the VS Code Cloud Code settings.
Big Story
Are We Building COBOL for the AI Era?
AI coding tools increase velocity, but teams treating AI output as finished code are accumulating a new, harder-to-reverse form of technical debt.
The problem is not that AI writes bad code. The problem is that nobody fully understands the code AI writes.
Guardrails, architectural review, quality checks, and deliberate refactoring determine whether AI accelerates delivery or mortgages it.
The organizations that win will be the ones that treat AI output as a first draft, not a final answer.
COBOL was introduced in 1959 as a language for business computing. Organizations built critical systems on it quickly, effectively, and at scale. Decades later, millions of lines of COBOL still power banking, insurance, and government infrastructure.
The same pattern may be taking shape now, at a far greater speed.
AI coding tools are generating code at an unprecedented scale. During Google Cloud Next 2026, CEO Sundar Pichai stated that 75% of all new code at Google is now AI-generated and reviewed by engineers, up from 50% just six months prior. In Meta's core product engineering divisions, internal targets set for the first half of 2026 require 65% of engineers to generate more than 75% of their committed code using AI tools. GitHub's Octoverse 2025 report found that over 1.1 million public repositories now use LLM SDKs, a signal that AI-assisted development has moved well past experimentation and into the default engineering workflow. The velocity gains are real, measurable, and significant. But velocity is only half the picture.
A growing body of evidence points to a mounting quality problem. GitClear's 2025 research analyzed 211 million changed lines of code across repositories from Google, Microsoft, Meta, and enterprise organizations between 2020 and 2024. It found that refactored code dropped from 25% of all code changes in 2021 to under 10% in 2024. Duplicate code blocks of five or more lines increased eightfold. For the first time in the study's history, copy-pasted lines exceeded the number of refactored lines. Refactoring is the slow, unglamorous work that keeps codebases navigable over time. Developers are doing dramatically less of it.
The root problem is not code quality in the narrow sense of whether a function works. It is what researchers are calling cognitive debt: the loss of understanding of why software was built the way it was. When a developer writes code, understanding accumulates alongside the output, tradeoffs are weighed, dependencies are recognized, and the reasoning behind decisions is preserved. When AI generates code, and a developer accepts it without deep review, the output may be functionally correct, while the understanding never forms. The system works, but nobody truly understands it.
This matters especially for API teams. APIs are long-lived contracts between systems. The quality of those contracts, how errors are communicated, how versioning is handled, and how authentication is structured compound over time. An API built on unreviewed, AI-generated logic may appear stable today while hiding fragility that surfaces only when requirements shift or integrations expand.
Without architectural review, deliberate refactoring, and engineering guardrails built into the development process, AI-generated code accelerates the creation of systems that become progressively harder to understand and maintain.
COBOL worked, and it kept working for decades. The problem was that the people who understood why it was built that way moved on, and the systems outlasted the knowledge behind them. That gap is what made COBOL costly to maintain, not the language itself.
AI-generated code can repeat that pattern on a shorter timeline. Code that ships quickly and runs correctly can still arrive with no record of the reasoning behind it. For API teams, where contracts are meant to hold for years, that missing context is the main concern. The fix is to ensure the reasoning behind the code is recorded and reviewed through architectural reviews, regular refactoring, and guardrails built into the workflow.
Resources & Events
📅 apidays Munich (Smartvillage Bogenhausen, Munich, Germany - July 8-9, 2026)
apidays Munich brings together API architects, platform engineers, and enterprise technology leaders for two days focused on API strategy, platform operations, and AI-driven enterprise systems. The 2026 program includes sessions on API lifecycle management, developer experience, event-driven architectures, and the operational challenges of managing APIs across distributed environments. Designed for teams scaling enterprise API programs, the event combines technical discussions, practitioner-led case studies, and platform engineering perspectives on how APIs are evolving alongside automation and AI-connected workflows. Details →
📅 apidays India (Conrad Bengaluru, Bengaluru, India - August 19-20, 2026)
apidays India brings together API architects, platform engineers, developers, and enterprise technology leaders for two days focused on the next generation of API-driven systems. The 2026 program explores how APIs are evolving to support AI agents, autonomous workflows, and machine-driven ecosystems, alongside sessions on API monetization, security, governance, platform strategy, and AI-driven automation. Designed for teams building and operating modern digital platforms, the event combines technical deep dives, practitioner-led case studies, and real-world discussions on how APIs are being designed, secured, and managed in an AI-connected world. Details →
You can find a list of all Apidays events here
Apply to speak at Apidays Singapore, NY, London, Paris, and more here
📅 WeAreDevelopers Conference India 2026 (Bengaluru, India - November 25-26, 2026)
WeAreDevelopers brings its global developer community to India, gathering software engineers, platform teams, AI practitioners, security professionals, and engineering leaders to explore modern software development in the AI era. The conference will feature technical sessions, hands-on learning, and discussions spanning AI-assisted development, cloud platforms, developer experience, security, platform engineering, and software architecture. Details →
📊 Report Spotlight: The Shift to Agentic AI (OpenAI)
This report analyzes anonymized Codex usage across personal, organizational, and OpenAI employee accounts. It finds that active usage grew more than fivefold during the first half of 2026, that more than 10% of users now operate at least three agents concurrently in a typical week, and that 26.6% use reusable skills for repeatable workflows. It documents the shift from conversational assistance to agents that use tools, inspect systems, modify artifacts, and execute longer workflows. It also examines how this changes verification, coordination, workflow design, and the role of developers as work shifts from direct execution toward delegation and review. Read →
Insight of the Week
Governing AI Assets at Scale with MCP Gateway and Registry
AWS released an open-source MCP Gateway and Registry to manage MCP servers, AI agents, reusable skills, and workflows across enterprise environments. The Apache 2.0 project provides a searchable catalog, one gateway URL for tool access, enterprise identity integration, scope-based permissions, audit logging, and automated security scanning. It supports federation with external and internal registries, including Amazon Bedrock AgentCore and Anthropic’s MCP Registry. Expedia Group is already using the platform to manage hundreds of MCP servers, tools, and skills alongside dozens of agents.
For the Commute
Agentic API (apidays)
In his Apidays Helsinki & North session, Dan Erez explores how AI-native application architectures are changing the role of APIs. He explains how Model Context Protocol (MCP), AI agents, and AI gateways introduce a new orchestration layer that sits alongside existing API infrastructure. As AI systems autonomously invoke tools, databases, and enterprise services, gateways are expected to handle responsibilities beyond authentication and routing, including prompt validation, model selection, identity, security, and governance.
That’s it for this week.
Stay tuned for bold ideas, fresh perspectives, and the next wave of API innovation
-The Apidays Team


