Lyon, a San Francisco company that emerged from Y Combinator earlier this year with just two founders, is making an audacious pitch to the financial world: let us build foundation models from scratch on your transaction data, running them in your own cloud. The startup recently trained a model on 28 billion transactions for a fintech serving tens of millions of active users, improving premium-card conversion prediction by a factor of four over traditional rules-based systems, according to its Y Combinator profile.
The timing is no accident. Lyon enters a field that has become intensely crowded in the past year, as Mastercard, Stripe, and Plaid—companies that process massive volumes of transactions—race to build proprietary AI models on the sensitive financial data flowing through their networks. What makes Lyon different, at least in theory, is sovereignty: customers own the model weights and run everything inside their own cloud environment.
Whether that proves compelling enough to compete with giants who can throw vastly more data and resources at the problem is an open question. But the startup's emergence reflects a broader anxiety rippling through financial services about who controls the AI models making billion-dollar decisions on credit, fraud, and risk.
A Year of Rapid Movement
The shift accelerated sharply over the past twelve months. Mastercard announced work in March on what it called a "large tabular model" trained on billions of anonymized transactions, with plans to scale to hundreds of billions by incorporating merchant location, fraud, authorization, chargeback, and loyalty datasets. The company is collaborating with NVIDIA and Databricks on the effort, according to a blog post. Steve Flinter, a distinguished engineer at Mastercard, said in March the firm plans to "build hybrid cybersecurity systems that combine the best of both our current AI models and this new LTM." Early tests reduced false positives on high-ticket legitimate purchases.
Stripe, which processed $1.4 trillion in volume last year, markets what it describes as the "industry's first Payments Foundation Model," trained on tens of billions of transactions. The company says its Radar fraud product reduces fraud by 38% on average and network optimizations lift authorization rates by 2.2%, according to a company page accessed in August.
Plaid published performance metrics in late June for a sequential foundation model, reporting 26.5% more dollar value in ACH returns prevented at a fixed 1% action rate and a 13.6% reduction in default risk at a 70% approval rate in internal tests.
Feedzai launched something called RiskFM on March 24, billing it as "the industry's first Tabular Foundation Model purpose-built for financial data and risk decisioning." Tom Martin, business platform lead for economic crime prevention at Lloyds Banking Group, called it "an exciting milestone." Revolut published research on PRAGMA, a foundation model supporting credit, fraud, and lifetime-value tasks, in an April preprint and showcased the work at NVIDIA GTC sessions in March.
The appetite for these models is clear. A Cambridge Centre for Alternative Finance survey published in April found OpenAI the most-used foundation-model provider among financial-services respondents at 76%. But the survey also revealed a split: traditional financial institutions showed higher on-premises and local-cloud use at 39% compared to 23% at fintechs, a gap that hints at why Lyon thinks it has an opening.
Regulation Tightens While Fraud Climbs

The rush to build these models stems from pressures both external and internal. Global card fraud losses hit $33.41 billion in 2024, according to the Nilson Report published in early 2026. At the same time, regulators in the EU and United States are demanding greater transparency around how AI models make credit and risk decisions.
The EU AI Act classified credit scoring as high-risk, with transparency rules that took effect in August and conformity assessments required by December 2027 for high-risk systems, according to the European Commission. U.S. regulators issued revised model risk management guidance on April 17, establishing risk-based expectations for banks and emphasizing vendor model validation even for proprietary systems, per Federal Reserve and OCC documents. The CFPB reiterated in 2022 guidance, still operative today, that lenders must provide "specific and accurate reasons" for adverse credit decisions even when using complex algorithms. That complicates the use of black-box models considerably.
Lyon positions itself around what founder Gabriel Noya, a Stanford EE/CS graduate, describes on the company's site as models that "run in your cloud, and you own the weights." The startup lists SOC 2 Type 1 compliance and zero subprocessors on its Trust Center, accessed in August, and offers VPC deployment on AWS, GCP, and Azure.
The company declined to disclose funding beyond its Y Combinator participation and did not name a second team member publicly, an unusual level of opacity for a startup making bold claims about billion-transaction models.
McKinsey estimated global fintech revenues at roughly $650 billion this year, up 21% year-over-year, in an April report, with payments remaining the largest vertical. The firm flagged AI as a key tailwind but noted that risk, fraud costs, and deposit competition pressures persist—forces that could either accelerate or complicate adoption of foundation models depending on how compliance officers perceive the trade-offs.
Different Strategies, Same Goal

The industry's biggest players are pursuing varied approaches. Visa, rather than building its own transaction foundation model, integrated its network into ChatGPT for agentic shopping and payments on June 10. Jack Forestell, the company's chief product and strategy officer, told the Washington Post that "as AI agents become active participants in the economy, Visa's focus is to ensure transactions are trusted, secure and seamless." Mastercard launched Agent Pay the same day for machine-to-merchant payments, signaling both companies see AI agents as a new class of customer.
Lyon, by contrast, says it works with a major insurer and is moving the 28-billion-transaction fintech model from premium-card conversion to credit-risk deployment, according to its Y Combinator page accessed in August. The company lists downstream tasks including churn, credit risk, fraud, collections, income, and cross-sell but did not disclose customer names.
Pedro Bizarro, chief science officer at Feedzai, framed the challenge succinctly in the March press release: "Financial risk is an adversarial domain; fraudsters actively adapt to evade detection in real time." That dynamic creates pressure for continuous model retraining and adaptation, perhaps favoring companies with massive, constantly updating datasets over smaller players with on-premises architectures.
NVIDIA's moves suggest the chipmaker sees transaction foundation models as a wedge into enterprise AI infrastructure, not just a fintech niche. The company acquired Kumo AI, a relational foundation model startup, in June, with founders moving to NVIDIA in May, according to Fortune and Forbes. NVIDIA published a "Build Your Own Transaction Foundation Model" blueprint in June, and EXL announced integration to help financial institutions build fraud and risk models faster using the template on June 4.
Technical Architectures Converge

The technical approaches share common elements even as implementations diverge. NVIDIA's blueprint outlined an architecture using GPU tokenization, transformer encoders on transaction sequences, and embeddings for downstream classifiers, according to the company's technical blog published in June. Plaid's sequential foundation model uses self-supervised objectives that learn event-level meaning and sequence grammar without bespoke feature engineering, the company wrote.
Google Research announced TabFM, a zero-shot tabular foundation model, on June 30, with plans for BigQuery "AI.PREDICT" SQL integration. Stanford's STAR project has tracked relational and tabular foundation-model advances through this year, including the Relational Transformer and RelBench benchmarks.
Revolut's PRAGMA preprint, published April 9, described a pre-trained backbone supporting multiple risk tasks through embeddings and linear heads or light fine-tuning. The company featured the work in an NVIDIA case study and GTC session in March, illustrating how quickly academic research is crossing into production systems.
Control Versus Scale
The trajectory points toward foundation models becoming infrastructure rather than specialty tools. Deloitte's payments trends report, published early this year, said agentic AI is moving commerce from "push" to "pull" payments and requiring greater cross-functional governance. An IMF note published April 22 said agentic AI will reshape payments and compliance with new infrastructure and guardrails needed for anti-money-laundering and counter-terrorism financing.
The regulatory clock runs faster than the technology one, perhaps unavoidably. EU AI Act high-risk compliance arrives in December 2027 for most systems, with embedded high-risk requirements in August 2028. U.S. open-banking rules under CFPB Section 1033, finalized in November 2024 with phased compliance originally set for 2026 through 2030, faced reconsideration and litigation this year, leaving timelines uncertain as of mid-year, according to multiple regulatory trackers.
Lyon's pitch centers on giving customers control at a moment when regulators are demanding transparency and portability. The customer owns the model weights and runs inference inside its own VPC, eliminating the vendor-dependency inherent in hosted foundation models.
Whether that proves more attractive than the scale Mastercard and Stripe can bring to bear on fraud and authorization rates—or the multi-modal integrations Visa is building with OpenAI—depends on how compliance officers weigh portability against proven performance at billion-transaction scale. Lyon's SOC 2 Type 1 certification is complete, with Type 2 certification in progress as of August, a detail that may matter more to procurement teams than founders would like.
The early performance numbers from Plaid, Mastercard, and Lyon suggest the models work. But the harder question is who builds them and where they run. That Cambridge survey finding that 39% of traditional institutions already favor on-premises deployment, compared to 23% at fintechs, suggests the legacy banking world may be more receptive to Lyon's model than the fintech disruptors who helped create the opening for transaction AI in the first place.
Lyon is betting that gap widens. Two founders against the giants of global payments is a long shot by any measure, but then again, the entire premise of Y Combinator rests on exactly that kind of asymmetry.
