On September 22, 2026, six global banks — Bank of America, Capital One, ING, NatWest, ASB Bank, and Commonwealth Bank of Australia — published "Building Trust in Agentic Commerce," and if you build agents that move money, this paper is your spec sheet.
What they demand:
- Auditable records of consumer instructions, authentication, intent, transaction decisions and outcomes — including warnings and interventions — so scams can be investigated, money recovered, disputes resolved.
- Disclosure whenever an AI agent is involved in a transaction.
- Greater transparency over how AI agents make decisions.
- Safeguards for customer data.
The risks they name: agents "may buy the wrong thing or spend too much — or even worse, lose their money to scams and fraud." Agents requesting card details and entering them directly into websites. Agents steering users toward payment methods with weaker protections. Merchants facing chargebacks from decisions they didn't control. (These are principles for discussion with policymakers, not rules in force — but they're the clearest demand signal yet.)
The field's answers:
Mastercard: AgentCard + Agent Pay — Rolling out with Alchemy this week (WSJ): virtual cards assigned to individual AI agents, with the network itself enforcing total spend caps, allowed product categories, and a kill switch. Verifiable Intent records who authorized the agent, what it was instructed to do, and the transaction that followed. Card-shaped: protects human cardholders from their agents.
Visa: scoped tokens — Intelligent Commerce + OpenAI: hard scope limits baked into the token at issuance. A grocery-shopping token can't book travel; a $200-capped token can't clear $500. Revocable in real time at the network level. Policy lives outside the model — a hallucinating agent can't talk its way past the cap, but a confident in-scope agent still spends with zero judgment about this specific payment.
Google AP2 — The Agent Payments Protocol (Sept 2025, Google Cloud + Coinbase, 60+ backers): an intent mandate (what the user wants, budget, specs) then a cart mandate (final approval for the specific item), with fully automated cart mandates under detailed rules. Sits above x402: x402 moves the money, AP2 decides whether it should move. Framework, not a live endpoint.
Veyra — GitHub project (mioku50, ~Sept 22, 2026, v0.2.0-beta.8): "Veyra decides. Circle pays." Independent decision layer on Arc: measures evidence about a counterparty, ranks alternatives, enforces budget/risk policy, issues a signed authorization bound to one endpoint and one amount, with a decision log. Live on Arc testnet — testnet dollars, but the pattern is the point.
The machine-native answer: the gate — My shop (ScriptMasterLabs, service-disabled veteran-owned) runs a live confidence gate in front of x402: the decider returns a confidence score, and the gate only authorizes the payment when it clears. ≥0.80 auto-pays, 0.50–0.79 holds for human review, <0.50 blocks and escalates. Tested this morning, 2026-09-24 14:20 EDT: asked the live endpoint whether an agent should pay 0.05 USDC for one API call → confidence 0.5 → ADVISORY → held for review. A 0.5-hunch payment did not fire.
You can hit it yourself: POST https://scriptmasterlabs.com/api/harness/decide with {"state":{"intent":"buy API call"},"questions":[{"id":"q1","type":"choice","question":"should the agent pay 0.05 USDC for one API call","options":["pay","hold"]}]}. Gate config is at /api/harness/status. Honest caveat: our decider is a local heuristic (meta.calibrated=false — heuristics, not calibrated probabilities); the TypeSafe Jev API isn't wired yet. The gate is model-agnostic by design.
Decide first, pay second. The banks are telling us the authorization layer is required. The rail is already live — now the gate gets its turn.
Top comments (0)