AI Agents Are About to Meet the Payment System's Hardest Question: Who Authorized This?
The Federal Reserve says agentic commerce changes payment authentication from proving who is paying to proving what an AI agent was authorized to do. That is an infrastructure market, not a chatbot feature.
The next important AI payment may not be made by a person. It may be made by software that searched for the product, compared the options, selected a seller, and submitted the transaction under instructions given hours or days earlier.
That possibility changes the central question in payment security. Today, a bank or payment network generally asks whether the person attempting the transaction is authorized to use the account. An AI agent adds another problem: even if the person is legitimate, was this specific software action within the authority the person granted?
Federal Reserve Governor Christopher Waller put that distinction at the center of a speech on payments and AI agents. In his September 28 remarks, Waller said agentic commerce shifts authentication toward proving “that an agent has the authority to pay on the buyer’s behalf.” PYMNTS reported the same point as the infrastructure challenge behind delegated AI shopping.
The business signal is not that autonomous shopping has arrived at scale. Waller described the market as early. The signal is that payments companies, banks, merchants, and software builders are being forced to define a new object: permission for a machine to act financially on someone’s behalf.
That object will need an identity, a scope, an expiry date, a record of consent, and a way to determine whether the final transaction matched the original instruction. The companies that provide that control layer may matter more than the agents producing the shopping recommendations.
Key Takeaways
- Federal Reserve Governor Christopher Waller says agentic commerce changes authentication from identifying an authorized payer to proving an agent has authority to pay on the buyer's behalf.
- The first commercial wave is likely to be agent-assisted shopping and workflow automation before fully delegated agents make autonomous purchases.
- Authentication, liability, and fraud are the three unresolved trust problems that could determine whether delegated agentic commerce scales.
- B2B purchasing is an attractive early market because approved suppliers, budgets, and recurring orders create usable guardrails, but transaction values raise the cost of mistakes.
- Builders should treat identity, consent, authorization scope, audit logs, and rollback as core product infrastructure for any agent that can spend money.
What Actually Happened
Waller’s speech separates two models of agentic commerce. In an agent-assisted model, an AI system helps with product search and discovery while the buyer remains in control of the decision and payment. In an agent-delegated model, the buyer gives an agent authority to shop and pay within constraints. Waller’s example was a pre-funded virtual card with instructions to purchase groceries based on past purchases.
The distinction matters because the risks are different. An assistant that finds three suitable products creates a recommendation risk. An agent that buys one creates a financial authorization risk. The second system needs to prove not only that it used a valid credential, but also that it stayed inside the buyer’s instructions.
Waller identified authentication, liability, and fraud as major barriers to scaling delegated commerce. Existing payment and e-commerce frameworks may be adaptable, but they were largely designed around human purchasers. Fraud models also learn from human transaction behavior. Agents may transact at different speeds, across more merchants, with repeated patterns that look abnormal to a system trained on people.
The Federal Reserve speech also places agentic commerce inside a broader payments transition. AI is already used in fraud detection, reconciliation, sanctions screening, and other operational tasks. Waller said large language models could improve the contextual review of sanctions alerts, while faster traditional anomaly-detection systems remain useful for speed-sensitive checks.
American Banker’s reporting on real-time and cross-border payments adds a practical constraint. Payment companies are interested in AI, but executives still describe the first phase as workflow simplification rather than a flood of autonomous transactions. For higher-value cross-border payments, human validation remains important because regulatory requirements, data quality, and liability are not solved by adding an agent.
The New Payment Object Is Delegated Authority
A payment credential answers one question: which account or card can fund the transaction? Agentic commerce requires another answer: what was the machine allowed to do with it?
That permission could be represented as a machine-readable authority record. It might identify the buyer, the agent, the merchant category, the maximum amount, the approved sellers, the payment rail, the geographic boundary, and the time window. It could also specify whether the agent may substitute products, negotiate prices, split an order, or make recurring purchases without another approval.
PYMNTS described this idea as a digital power of attorney attached to the transaction. The analogy is useful, with one important difference: software authority can be narrow, temporary, and automatically revoked. A business could authorize an agent to reorder office supplies from approved vendors up to a weekly limit, then require human approval for anything outside that pattern.
Payment networks and technology companies are already developing pieces of this model. PYMNTS points to Visa’s Intelligent Commerce technology and Mastercard’s Agent Pay work, including registered agents and mechanisms intended to capture verifiable user intent. Waller said market participants are working on standards for agent registration, approval records, and payments.
The market structure is not settled. Platform-specific standards could give a large retailer or AI provider tighter control over the experience. Interoperable standards could allow smaller merchants, banks, and independent agents to participate without joining one closed ecosystem. The choice will affect who owns the customer relationship and who gets to define a valid agent.
For builders, this is a warning against treating payments as the final API call in an agent workflow. The authorization decision should be represented throughout the workflow. The system should know which instruction created the action, which policy permitted it, and what evidence can be shown if the transaction is disputed.
B2B May Arrive Before Autonomous Consumer Shopping
Consumer shopping gets the attention because it is easy to imagine: “Buy the cheapest compatible printer cartridge.” But B2B purchasing may offer a cleaner early market.
Companies already have procurement rules. They maintain approved suppliers, purchase categories, budgets, recurring orders, and approval chains. Those rules are imperfect, but they give an agent a boundary to operate inside. An agent that reorders a known item from an approved supplier is easier to supervise than one that makes an open-ended purchase across the internet.
Waller said B2B buying could be well suited to agentic commerce because agents may eventually negotiate terms and select payment strategies to improve working capital. But the same characteristics make B2B errors expensive. A mistaken consumer purchase may be inconvenient. A mistaken enterprise order can create contractual, operational, tax, and cash-flow problems.
B2B also has more payment rails. A business may use cards, ACH, wires, or instant payments depending on the supplier, amount, urgency, and geography. An agent that chooses among those rails is not just shopping. It is making a treasury decision. That requires stronger policies, richer transaction context, and clear escalation rules.
There is an intermediate market here: agents that prepare, reconcile, and route payments without final autonomous execution. They can gather invoices, match purchase orders, flag exceptions, recommend a rail, and assemble an approval package. That delivers measurable value while keeping the final authorization with a person or established business control.
American Banker quoted Flywire’s chief payments officer saying AI agents will simplify the workflow first, while fully agentic payments remain limited. That is a useful reality check. The winning product may not be the agent that spends money alone. It may be the system that makes a human approval faster, better documented, and easier to audit.
Trust Is a Product Requirement, Not a Policy Memo
The hardest part of delegated payments is not getting a model to choose a product. It is deciding who is responsible when the model chooses incorrectly.
If an agent buys the wrong item, exceeds its budget, or follows a malicious instruction, who pays? The buyer, the bank, the merchant, the AI provider, or the company that assembled the workflow? Waller said existing liability frameworks could potentially be adapted, but technical standards may also need to record what the buyer intended and how the agent executed that instruction.
That record is essential. A transaction log should show the original authority, the agent identity, the data used, the policies evaluated, the tool calls made, the approvals received, and the final payment request. Without it, disputes become arguments about an opaque chain of model output.
Fraud detection will need similar changes. A human may buy one expensive item at an unusual time. An agent may make hundreds of small purchases, query multiple services, and change behavior when its data or instructions change. Systems need to distinguish authorized machine activity from compromised or manipulated machine activity.
This is why the control plane is the commercial opportunity. Identity binding, policy evaluation, consent records, spend limits, anomaly detection, reversible actions, and human escalation are not accessories around an agent. They are what makes the agent usable in a financial workflow.
What Builders Should Take From It
- Model authority explicitly. Define who authorized the agent, what it may buy, where it may transact, how much it may spend, and when that permission expires.
- Start with assisted workflows. Let agents search, reconcile, classify, and prepare transactions before allowing them to execute payments without review.
- Bind identity to the agent. A valid card or account credential is not enough; the payment system needs to know which registered agent acted and under whose authority.
- Log intent and execution. Preserve the instruction, policy decision, tool calls, approvals, and transaction details needed to resolve a dispute.
- Design for revocation. Buyers and administrators need a fast way to cancel an agent’s authority, freeze spending, and rotate credentials.
- Treat B2B controls as product features. Approved vendors, purchase categories, budgets, rail selection, and approval thresholds are the guardrails that make enterprise adoption possible.
- Measure exceptions, not demos. Track unauthorized attempts, human overrides, false declines, reconciliation errors, and the cost of review.
The first serious agentic-commerce products will probably look less like autonomous personal shoppers and more like permission systems with an agent attached. That is not a smaller opportunity. Payments are built on trust, and trust requires proof about who acted, what they were allowed to do, and whether the transaction matched the instruction.
AI agents can make commerce more automated. Before they can make it more autonomous, the payment system needs a reliable answer to one question: who authorized this?
Developer312 covers the AI business signals builders actually need to act on. Get the weekday briefing at developer312.com.
Sources
Get the next briefing
Signal-first AI briefings, weekday mornings.
One concise briefing with three signals, why they matter, and one action to take.
Free. No spam. Unsubscribe anytime. · Weekday mornings.
Share this article