How Mercury uses AI in Command

Mercury Command is powered by AI and designed to complete financial work for you. It retrieves information, stages actions, and executes — with your confirmation as the final step before anything changes in your account.

When you use Command, nothing ever happens without your explicit approval. 

The AI's role

When you send a message in Command, the AI interprets what you're asking, retrieves the relevant information from your account, and prepares a response or stages an action for you to review.

The AI does the legwork — finding the right transactions, pre-filling the right fields, surfacing the right details — so that by the time you see a result, all you need to do is confirm or adjust.

Every Command response links directly to the underlying transaction, invoice, or account data behind it so you can verify the source before you act.

What the AI can see

Command authenticates through your existing Mercury session. This means it can only access the data and actions a user is already authorized to see and take in their Mercury account. There is no elevated access — if you can't do something in the Mercury web or mobile product, Command can't do it either.

The context shared with the AI for each session is limited by design. It includes basic session information like your first name, business name, and timezone. It does not include session cookies, authentication secrets, or API keys.

What the AI never sees

Sensitive personal and financial data is not transmitted to the AI model. This includes:

  • Card numbers
  • Social Security numbers
  • Dates of birth
  • Home addresses

When Command needs to reference something sensitive — like a card number — it passes the model a reference ID instead of the real data. The Mercury interface handles the conversion, so you see what you need to see, but the underlying data never passed through the AI.

Third-party AI providers

Mercury Command is powered by third-party AI providers. Some account data is shared with these providers to generate responses. Your conversations are not used to train their models, and sensitive financial data is never transmitted to them.

All AI vendors that power Mercury products go through a thorough security and privacy review before we engage them, and are contractually prohibited from using your data for any purpose beyond providing services to Mercury — including training their own models. We also review vendors on an ongoing basis to ensure they continue to meet our standards.

Every action requires your confirmation

Command can retrieve information and stage actions, but it cannot execute anything without your explicit approval. Before anything happens in your account, Command shows you exactly what it's about to do and waits for you to confirm. You can also edit what's been staged before approving.

There is no auto-approve under any circumstances.

 

Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC.

AI-generated responses and suggested actions may vary and are not guaranteed. Please review outputs before taking action.

Did you find this article helpful?