# I Built an AI Money Agent That's Structurally Incapable of Touching the Money

> Source: <https://dev.to/yaseenyk04/i-built-an-ai-money-agent-thats-structurally-incapable-of-touching-the-money-5h0j>
> Published: 2026-09-12 08:46:14+00:00

[ EXECUTIVE TEARDOWN // TL;DR ]

Personal-finance apps ask for the most sensitive data a person owns and then ship it to someone else's cloud. AI finance apps go further: they hand that data to a language model and let probabilistic text decide what happens to real money. I built Sable to reject both premises at the architecture level — a local-first AI financial agent where all data lives on-device in SQLite, and where the model can *propose* but is structurally incapable of *committing*.

Sable is a React Native app with no cloud backend. Every debt, every payment, every balance lives in on-device SQLite — full stop. When the AI layer needs context ("how is my spending pacing this month?"), it queries the local database. What crosses the network to the model is a distilled, minimal context — never the ledger. Most products bolt privacy on as a policy. Sable has it as a topology: there is no server to breach because there is no server.

The agent uses OpenAI function calling — but every function call is a **dry run**. When the model decides "log a ₹5,000 payment against the car loan," that intent renders as a Review & Confirm card in the UI. The model's output is a proposal object; the database mutation only executes when a human taps confirm. An LLM hallucination in Sable can produce, at worst, a card you dismiss. It can never produce a wrong number in your ledger.

The question that should govern every agentic product: *what is the blast radius of the model's worst output?* In Sable the answer is "one dismissible card" — by architecture, not by prompt engineering.

Every enterprise deploying agents faces Sable's problem in costume: healthcare records, legal documents, internal financials — data that wants AI leverage but cannot tolerate AI authority. The propose/confirm boundary and the local-context pattern transfer directly: give the model read access to distilled context, render its intents as reviewable artifacts, and reserve the commit for a human or a deterministic policy. I built the reference implementation into a product I use every day — the full breakdown is [on Sable's product page](https://yaseenkhatib.streamerosai.com/products/sable/).

YK

Yaseen Khatib · MERN + AI Architect

Ships autonomous AI products solo — five in the last twelve months. [More about Yaseen →](https://yaseenkhatib.streamerosai.com/about/)

I'm Yaseen Khatib — a Senior Full-Stack AI Engineer (MERN + TypeScript) who ships production AI systems solo. Open to senior and lead roles, remote or on-site.

[Get in touch →](https://yaseenkhatib.streamerosai.com/#contact)[See what I've shipped](https://yaseenkhatib.streamerosai.com/products/)

*Originally published at [yaseenkhatib.streamerosai.com/blog/sable-ai-agent-never-touches-money/](https://yaseenkhatib.streamerosai.com/blog/sable-ai-agent-never-touches-money/).*
