The payments industry has spent the past year building rails so AI agents can pay on your behalf. Most finance and security teams have never granted a piece of software the authority to spend, and that gap is about to matter.
For two years, the question about AI agents was whether they could do the work. The payments industry has quietly answered a different one: whether they can pay for it.
Over the past year, the biggest names in payments have built infrastructure so an agent can complete a purchase as a principal rather than a tool. Mastercard’s Agent Pay issues tokens that bind a card credential to a specific agent, a specific merchant, and a specific consent policy, and it has already run a live agent payment with a bank in a regulated environment. Visa has partnered with OpenAI and built agent-trust scoring, an agent registry, and real-time authorisation into what it calls Intelligent Commerce. Stripe, Google, and Coinbase have all shipped competing protocols, and an open standard for agent payments now sits under the Linux Foundation with Visa, Mastercard, Stripe, AWS, and Google among its members. The rails are arriving faster than the controls.
Which reframes the question in front of finance and technology leaders. It is no longer whether an agent can draft an order. It is whether it can place one, pay for it, and commit your money, and whether anyone has yet decided how much it is allowed to spend.
From Tool to PrincipalThe shift worth noticing is that agents are starting to act in the payments system as principals, not tools. They can discover, compare, and settle a transaction without a human approving each step. Today the volume is tiny. Morgan Stanley projects agentic commerce could reach $385 billion of US e-commerce by 2030, yet only around 1% of shoppers use the agentic route right now. The volume is small, the direction is not, and the infrastructure is already being wired into the tools you use.
Traditional controls don’t fit this well, because payment systems and finance approvals were built for a human clicking “buy,” not autonomous software firing high-frequency, machine-to-machine payments. A split is already emerging: card rails for consumer retail, where chargebacks and dispute protection matter, and stablecoin rails for machine-to-machine and cross-border settlement, where a transaction costs a fraction of a penny. The value is being captured in the new layer too. One major provider already charges a 4% fee on agent-initiated checkout. This is not a pilot looking for a use case. It is a market forming around a capability most enterprises have not governed yet.
The Controls Most Companies Don’t Have YetAn agent that can spend money needs a set of controls that most organisations have never had to build, because they have never handed spend authority to a piece of software. Four matter most.
None of this is exotic. It is the discipline you already apply to a member of staff with a corporate card, extended to a piece of software that can act thousands of times a day without getting tired or asking permission.
Why This Is Arriving Sooner Than It LooksIt is tempting to file agentic payments under “someday,” and for autonomous consumer shopping that may be fair. The enterprise case is closer. Procurement, reordering, and supplier settlement are exactly the high-frequency, rules-based tasks agents are being pointed at first, and the payment capability is increasingly one connector away from the agents you already run. The realistic risk is not that you rush into agentic payments. It is that an agent quietly gains the ability to spend before anyone has written the rules.
The scale of the bet behind the rails tells you how seriously the industry takes it. The major payment networks have spent well over a billion dollars each acquiring stablecoin infrastructure in the past year, precisely because they expect agents to start moving real money. The rails will be ready. The question is whether your controls are.
Decide the Rules Before the Agent DoesThe order of operations is the whole point. Spend authority, identity, and audit are decisions to make before an agent is connected to a payment rail, not clauses to draft after the first transaction you cannot explain. A finance director who is told “the agent authorised it” and an auditor who asks “under what control” both deserve a better answer than a shrug. Getting there is straightforward if you start now, and painful if you start after the fact.
Q&A: Governing Agents That Can SpendIsn’t agentic payments mostly a consumer shopping thing?
Consumer checkout is where it started, but the larger enterprise case is procurement, reordering, and machine-to-machine settlement, where agents handle high-frequency, rules-based transactions. If your agents touch purchasing or supplier workflows at all, this reaches you sooner than the consumer headlines suggest.
The card networks say they’ve built the security. Isn’t that enough?
Their work secures the rail and the transaction through tokenisation, agent-trust scoring, and fraud monitoring. It does not set your internal policy: how much a given agent may spend, on what, and who signs off above a limit. That governance is yours to define, and no payment network defines it for you.
How is this different from the agent identity problem we’ve already looked at?
It’s the same discipline applied to a higher-stakes action. Identity is the prerequisite; spend authority is the new layer on top. An agent that can pay needs not only its own scoped identity but a defined, enforced limit on what it is allowed to commit, and a clear line back to an accountable human.
Should we adopt agentic payments now, or wait?
There’s no prize for transacting autonomously before you’re ready, and good reason to move carefully. But the rails are being built into tools you already use, so the practical danger is that an agent gains the ability to spend before you’ve decided the rules. Decide the rules now, and adopt when it genuinely pays back.
What’s the first practical step?
Map every place an agent could plausibly initiate a purchase or payment, today or the moment a connector is switched on. For each one, define the spend limit, the approval threshold, the identity, and the audit trail before it goes live. If you can’t answer “how much can this agent spend,” that is the gap to close first.
Deciding what an agent is allowed to do with your money, and proving it afterwards, is exactly the kind of problem our AI Consultancy practice is built for. Most AI deployments are performance theatre. We integrate AI where it demonstrably pays back, and we build the spend authority, approval thresholds, and guardrails into the agent from the start, rather than discovering the limits after a transaction nobody sanctioned. Our Generative AI Implementation Playbook covers where those controls belong in an adoption plan, and it’s a useful place to start thinking this through.
Our Cybersecurity and cross-cutting work brings the identity and access side, giving each transacting agent its own scoped identity, least-privilege permissions, and a full audit trail, so a financially binding action always traces back to a policy and a person. Our Software Consultancy practice handles the build, integrating agents into your finance and payment systems safely rather than bolting a payment rail onto an agent nobody has governed. Who can spend, how much, and with whose sign-off is an architecture decision, and architecture is where we start.
Because we work across the major model, cloud, and payment providers rather than for any one of them, the controls we design are the ones your business and your regulators actually need.
If you want an honest read on whether your governance is ready for agents that take financially binding actions, our free AI Readiness Audit covers the governance and risk ground this article is about. For a direct conversation about letting agents transact safely, get in touch with us below.
Use our AI to tailor your resume for this Your AI Agents Are About to Start Spending Your Money position at Vertex Agility.