{"slug": "how-should-ai-agents-be-authorized-to-pay-for-things-the-sept-22-bank-paper-and", "title": "How Should AI Agents Be Authorized to Pay for Things? (The Sept-22 Bank Paper, and the Live Answer)", "summary": "Six global banks — Bank of America, Capital One, ING, NatWest, ASB Bank, and Commonwealth Bank of Australia — published a September 22 paper, \"Building Trust in Agentic Commerce,\" laying out principles for authorizing AI agents to make payments, including spend caps, category limits, and kill switches. The paper arrives alongside competing implementations: Mastercard's AgentCard and Agent Pay with Alchemy, Visa's scoped tokens built with OpenAI, Google's AP2 agent payments protocol, and the open-source Veyra decision layer on Arc. ScriptMasterLabs also demonstrated a live confidence gate in front of x402 that held a 0.05 USDC agent payment at a 0.5 confidence score rather than auto-paying it.", "body_md": "On September 22, 2026, six global banks — Bank of America, Capital One, ING, NatWest, ASB Bank, and Commonwealth Bank of Australia — published \"Building Trust in Agentic Commerce,\" and if you build agents that move money, this paper is your spec sheet.\n\nWhat they demand:\n\nThe risks they name: agents \"may buy the wrong thing or spend too much — or even worse, lose their money to scams and fraud.\" Agents requesting card details and entering them directly into websites. Agents steering users toward payment methods with weaker protections. Merchants facing chargebacks from decisions they didn't control. (These are principles for discussion with policymakers, not rules in force — but they're the clearest demand signal yet.)\n\nThe field's answers:\n\n**Mastercard: AgentCard + Agent Pay** — Rolling out with Alchemy this week (WSJ): virtual cards assigned to individual AI agents, with the network itself enforcing total spend caps, allowed product categories, and a kill switch. Verifiable Intent records who authorized the agent, what it was instructed to do, and the transaction that followed. Card-shaped: protects human cardholders from their agents.\n\n**Visa: scoped tokens** — Intelligent Commerce + OpenAI: hard scope limits baked into the token at issuance. A grocery-shopping token can't book travel; a $200-capped token can't clear $500. Revocable in real time at the network level. Policy lives outside the model — a hallucinating agent can't talk its way past the cap, but a confident in-scope agent still spends with zero judgment about this specific payment.\n\n**Google AP2** — The Agent Payments Protocol (Sept 2025, Google Cloud + Coinbase, 60+ backers): an intent mandate (what the user wants, budget, specs) then a cart mandate (final approval for the specific item), with fully automated cart mandates under detailed rules. Sits above x402: x402 moves the money, AP2 decides whether it should move. Framework, not a live endpoint.\n\n**Veyra** — GitHub project (mioku50, ~Sept 22, 2026, v0.2.0-beta.8): \"Veyra decides. Circle pays.\" Independent decision layer on Arc: measures evidence about a counterparty, ranks alternatives, enforces budget/risk policy, issues a signed authorization bound to one endpoint and one amount, with a decision log. Live on Arc testnet — testnet dollars, but the pattern is the point.\n\n**The machine-native answer: the gate** — My shop (ScriptMasterLabs, service-disabled veteran-owned) runs a live confidence gate in front of x402: the decider returns a confidence score, and the gate only authorizes the payment when it clears. ≥0.80 auto-pays, 0.50–0.79 holds for human review, <0.50 blocks and escalates. Tested this morning, 2026-09-24 14:20 EDT: asked the live endpoint whether an agent should pay 0.05 USDC for one API call → confidence 0.5 → ADVISORY → held for review. A 0.5-hunch payment did not fire.\n\nYou can hit it yourself: POST [https://scriptmasterlabs.com/api/harness/decide](https://scriptmasterlabs.com/api/harness/decide) with {\"state\":{\"intent\":\"buy API call\"},\"questions\":[{\"id\":\"q1\",\"type\":\"choice\",\"question\":\"should the agent pay 0.05 USDC for one API call\",\"options\":[\"pay\",\"hold\"]}]}. Gate config is at /api/harness/status. Honest caveat: our decider is a local heuristic (meta.calibrated=false — heuristics, not calibrated probabilities); the TypeSafe Jev API isn't wired yet. The gate is model-agnostic by design.\n\nDecide first, pay second. The banks are telling us the authorization layer is required. The rail is already live — now the gate gets its turn.", "url": "https://wpnews.pro/news/how-should-ai-agents-be-authorized-to-pay-for-things-the-sept-22-bank-paper-and", "canonical_source": "https://dev.to/scriptmasterlabs01/how-should-ai-agents-be-authorized-to-pay-for-things-the-sept-22-bank-paper-and-the-live-answer-4h9e", "published_at": "2026-10-04 01:30:54+00:00", "updated_at": "2026-10-04 01:37:34.543100+00:00", "lang": "en", "topics": ["ai-agents", "ai-policy", "agent-protocols", "ai-products", "ai-infrastructure"], "entities": ["Bank of America", "Capital One", "ING", "NatWest", "ASB Bank", "Commonwealth Bank of Australia", "Mastercard", "Visa"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/how-should-ai-agents-be-authorized-to-pay-for-things-the-sept-22-bank-paper-and", "markdown": "https://wpnews.pro/news/how-should-ai-agents-be-authorized-to-pay-for-things-the-sept-22-bank-paper-and.md", "text": "https://wpnews.pro/news/how-should-ai-agents-be-authorized-to-pay-for-things-the-sept-22-bank-paper-and.txt", "jsonld": "https://wpnews.pro/news/how-should-ai-agents-be-authorized-to-pay-for-things-the-sept-22-bank-paper-and.jsonld"}}