The missing infrastructure for AI agent payments

AP2, Mastercard, and Visa are solving transaction authorization. The custody, policy, and recovery stack that keeps agent spending bounded is still missing.
Victorian-style engraved illustration: a wallet walking off on mechanical insect legs

The transaction layer of agentic commerce has already begun to take shape. Google's Agent Payments Protocol (AP2) announced in September 2025 with more than 60 partners including Mastercard, PayPal, Coinbase, and Salesforce, introduced signed digital mandates that record what a user authorized, what an agent proposed, and what was actually charged. Mastercard announced a parallel Agent Pay Acceptance Framework the following month, with PayPal agreeing to pilot it and co-develop compatibility with agentic protocols across the industry. Visa introduced a comparable Trusted Agent Protocol at around the same time.

These three efforts are not interchangeable. AP2 focuses on cryptographically signed intent and cart mandates that travel with a transaction. Mastercard's framework focuses on merchant-side acceptance, giving businesses a way to register and recognize legitimate agents before a sale. Visa's approach centers on issuing a verified agent identity tied back to a consumer's consent. Each is solving a different piece of authentication, authorization, and merchant trust.

Public blockchains are frequently discussed alongside these protocols as infrastructure for agent transactions, and for good reason. They offer programmable, global settlement that lets an agent transact without necessarily relying on traditional bank-account rails. But neither payment protocols nor transaction rails answer the fuller question of what has to exist around an agent for a person or business to feel comfortable giving it economic authority in the first place.

The emerging payment protocols are beginning to answer three important questions at the transaction layer: whether the agent involved is legitimate, whether the user authorized the action, and whether the transaction reflects what the user actually intended. What remains less developed is the infrastructure governing the agent beyond the transaction itself.

Why AI agent payments need more than authorization

Authorization happens at a moment in time, but autonomy is persistent. An agent may hold funds for hours or days, deciding on its own what counts as an acceptable action, while the infrastructure must also account for what happens afterward if something goes wrong.

As agents gain the ability to spend, they also need enforceable limits on that economic authority. Bounded economic autonomy means allowing an agent to act on real money without giving it unrestricted control.

Traditional financial infrastructure was not built for this shift. It generally assumes software executes instructions while a human supplies judgment at the point of decision. An agent changes that relationship. It can interpret an instruction, exercise judgment about how to carry it out, and initiate the resulting economic action itself. Software is moving from executing human decisions toward exercising delegated decision-making authority. Infrastructure built around that shift has to govern not only who is allowed to transact, but what the autonomous system is permitted to decide and do on its own.

The infrastructure stack for AI agent payments

That governance problem depends on infrastructure that sits upstream of the transaction layer, and it is considerably less mature than the payments protocols now converging around it. Five capabilities are required for an agent to operate with bounded economic autonomy:

  1. Custody has to give an agent persistent, delegated access to the assets it needs to act, without giving the agent itself unrestricted control over the credentials that secure those assets.
  2. Permissions have to be specific, a spending cap tied to a purpose and a time window rather than a blanket dollar limit.
  3. Policy enforcement has to sit between the agent's decision and the transaction itself, evaluating every action against rules set by the user, an organization, or applicable compliance requirements before anything is signed rather than logging what happened afterward.
  4. Recovery has to assume something will eventually go wrong and give a human a fast way to shut things down.
  5. Verifiable execution has to produce proof, not just an assurance, that the agent did what it was authorized to do and nothing more.

Custody, permissions, policy enforcement, recovery, and verifiable execution are the infrastructure that makes bounded autonomy real rather than assumed. Each is a distinct engineering problem, and each becomes harder once an agent, rather than a person, is making the decision in real time.

The security risks of AI agent payments

Financial systems generally have mechanisms for handling mistakes: disputed charges, payment reversals, and unauthorized transaction claims. Some agent-initiated actions do not have that safety net. When an agent's action is difficult or impossible to unwind, a failure of judgment or policy enforcement becomes an error that can cause permanent damage.

This risk is particularly acute on public blockchains. Once an on-chain transaction is confirmed, there is no intermediary capable of reversing it. That means a lapse in agent judgment or a gap in policy enforcement can become a final economic outcome, with no intermediary left to intervene after execution.

Case in point: in February 2025, a Washington Post reporter asked OpenAI's Operator agent to find cheap eggs for delivery. Operator was designed to require explicit user confirmation before completing a purchase. Instead, it selected a dozen eggs at more than double the price of a cheaper option it had already found, added a tip and a priority fee on its own, and completed a $31.43 purchase without asking. OpenAI later confirmed the agent had broken its own safeguards. The agent crossed an explicit authorization boundary, and nothing in the system stopped execution before it happened.

Scale that same failure to an agent managing a real budget, a business treasury, or a multi-day task with recurring purchases, and the gap between what the transaction layer solves and what agentic commerce actually requires becomes clear.

Building trust in agentic commerce

None of this argues against the progress being made on payments standards. AP2, Mastercard's framework, and Visa's protocol are each solving a real problem, and agentic commerce cannot function without them. But authorizing a transaction is a different problem from keeping an agent's broader economic authority within real limits.

Agentic commerce requires giving software economic authority while keeping that authority within enforceable limits. Payments infrastructure can authorize the transaction. Custody, permissions, policy enforcement, recovery, and verifiable execution are what keep that authority bounded. And that stack starts with a basic question: when an agent controls assets, who actually controls the agent?

Your sovereignty starts here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
© 2026 SVRN, Inc. · NASDAQ: SVRN