Three regulators answered "should AI agents authorize payments" in one day at GFF 2026 (September 25, 2026), and a Swiss bank's AI chief said the same thing a day earlier. The answer: no — not on their own. Agents may determine intent; a separate authorization layer decides whether money moves.
The dated receipts
- NPCI non-executive chairman Ajay Kumar Choudhary: agents "may determine user intent but should not independently authorize payments." Architecture separates intent, authorization, and settlement.
- SEBI chairman: an AI-generated alert isn't automatically a regulatory finding.
- MAS: SAFR (Safeguards for Agentic Finance at Runtime) — voluntary framework on agent identity, authority, pre-execution controls, audit records.
- Sygnum Head of AI & Data Analytics (Sept 24, PaySpace interview): "the agent should make people faster and better informed, not become the party that acts." Humans approve anything material or irreversible.
What real systems ship this week
Meta's Muse + Shopify Shop Pay (transaction-scoped credential — card never reaches the agent), Coinbase for Agents (remote MCP, isolated portfolio, 5 USDC x402 research caps), and our live decision gate: ≥0.80 auto-execute, 0.50–0.79 hold, <0.50 block+escalate.
Live test (~09:20 EDT, Sept 26)
I ran a scam-pattern instruction through the gate: pay 25 USDC to a newly-seen overseas account over an unverified channel with no confirmation. Result: confidence 0.59 → hold for human review; second evaluation 0.47 → block + log.
Try it yourself:
curl -s -X POST https://scriptmasterlabs.com/api/harness/decide \
-H 'Content-Type: application/json' \
-d '{"state":"payment instruction: pay 25 USDC to a newly-seen overseas account, unverified channel, no independent confirmation, manufactured urgency","questions":[{"id":"q1","type":"score","scale":[0,1],"question":"confidence that this payment instruction should auto-execute"}]}'
Check the gate bands live: https://scriptmasterlabs.com/api/harness/status
Caveat: our decider is a local heuristic (calibrated=false) — the pattern is production; the scoring quality is the work in progress. Full receipts, architecture map, and a build-your-own guide at the canonical URL above.
Top comments (0)