When AI Agents Manage Your Money, Who Controls the Agent?
The rails are poured. The mandate is the product.
In the last week of April 2025, the two card networks moved within a day of each other: Mastercard announced Agent Pay on the 29th, Visa launched Intelligent Commerce on the 30th. By September, Google had shipped an open Agent Payments Protocol with sixty-plus partners, built on cryptographically signed mandates — Intent, Cart, Payment — carried as verifiable credentials. Mastercard’s agentic tokens bind a payment credential to a specific agent, merchant scope, and consent policy, so the agent can spend without ever seeing a card number. By 2026 the networks were extending the same machinery to continuous machine-to-machine micropayments.
The plumbing for software that spends is being poured right now, by the most conservative institutions in commerce. Every one of these announcements answers the question how does the agent pay. The question they only partly answer is the one every CFO, trustee, and regulator asks first — the one this series opened with: who controls the agent?
Finance solved this once — for humans
Delegating money is not a new problem; it is arguably the oldest problem in finance. Power of attorney. Discretionary versus non-discretionary trading authority. Investment policy statements. Corporate treasury delegation-of-authority matrices. Card controls, spending limits, four-eyes approvals. Strip away the products and finance is, at bottom, delegation technology: centuries of machinery for deciding who may move whose money, how much, under what mandate — and proving it afterward.
None of it transfers automatically to agents, because all of it quietly assumed a human on the other end — someone who can be questioned, fired, sued, or jailed. Deterrence was doing half the work. An agent cannot be deterred; it can only be constrained. Which means every control that used to live in an employment contract and a compliance manual now has to be engineered: explicit, machine-readable, enforced at transaction time.
What the new rails get right — and the four gaps
The encouraging part: the rails are converging on exactly the right primitive. A signed mandate that records what the user authorized, an agent credential scoped to a merchant and a consent policy, an agent that holds execution rights but never viewing rights over the card — that is the first essay’s argument arriving in production: authority made explicit, portable, and verifiable instead of implied and reconstructed.
But an operator putting real money behind an agent today still owns four gaps:
Granularity. “May buy” is not a mandate. A real one scopes transaction classes, counterparties, and data elements — what the agent may spend, see, and commit to, item by item. Coarse authority is how a shopping agent becomes a procurement incident.
Aggregates and velocity. A per-transaction cap without an aggregate is a loophole at machine speed: a $500 limit means little to software that can execute it every second. Ceilings need totals, rates, and time windows — the way card controls always worked, now enforced against something far faster than a cardholder.
Revocation in flight. Authority changes mid-stream: the employee leaves, the budget freezes, the fraud team calls. What happens to the payment already moving when the mandate dies? If the answer isn’t fail safe by default, with written exceptions, the answer is a dispute. Real-time access without real-time authorization doesn’t create speed; it expands the blast radius.
Decision evidence. Transaction logs tell you money moved. They don’t tell you the movement matched the mandate — who granted the authority, what was in scope, what was checked at the moment of execution. That record has to be captured at authorization time, not reconstructed in discovery.
Deposits that move themselves change banking
Commerce is only the visible half. The quieter revolution is money management: agents that sweep idle cash to the best yield, rebalance a portfolio, refinance a liability, pay down the most expensive balance first — continuously, unemotionally, at machine speed. The foundational assumption of retail banking is that deposits are sticky because switching takes human effort. An agent removes the effort. When deposits can move themselves, the stickiness premium evaporates, and the industry’s oldest moat becomes a daily auction.
For anyone running revenue in financial services, that inverts the go-to-market: you win the customer once — then you have to win the customer’s agent every single day, on rate, on terms, on machine-legible trust. The agent is simultaneously your new distribution channel and your new counterparty. Institutions will need the inbound version of everything above: know not just your customer but your customer’s agent — verify its mandate, decide what authority you accept from it, and price for a relationship that re-shops itself continuously.
Price the rails honestly while you’re at it. The unit that matters is the completed, collectible transaction. Interchange, for all its cost, bundles authorization, fraud controls, dispute rules, and risk transfer; a cheaper rail that strips those out doesn’t eliminate the costs — it re-imports them as your own returns, recovery, and collections. Total cost per verified outcome is the only comparison that survives contact with a chargeback.
What to do now
Write the mandate before the wallet. Scope, counterparties, per-transaction and aggregate limits, velocity, time window, escalation thresholds. If the mandate doesn’t fit on a page, the agent isn’t ready for money.
Separate authority from identity. The credential says who the agent is; the mandate says what it may do. Never let the first imply the second, and make sure you can revoke either independently.
Decide revocation semantics up front. In-flight transactions fail safe when authority is withdrawn; exceptions are written down, not improvised during an incident.
Evidence every movement at authorization time. Record the decision — what mandate applied, what matched, what was released — alongside the transaction itself. One ledger serves the auditor, the dispute team, and the renewal review alike; it’s the half of this problem I’ve been working on in the open, in a proposed OCSF extension for recording authorization decisions at the data element.
Treat inbound agents as a channel. Publish what mandates you accept, verify them at the door, and instrument the relationship — because the counterparty that re-shops daily is also the counterparty you can win daily.
Provable control is the license to operate
Here is where the whole series has been heading. In regulated money, the winner won’t be whoever fields the smartest agent — intelligence is table stakes there too. The winner will be whoever can hand agents real authority safely: more delegation, more automation, more of the customer’s financial life under management, because every movement is scoped in advance and provable afterward. The agentic economy will move money at machine speed. The institutions that thrive on it will be able to answer, for every dollar, in real time: who authorized this — and prove it.
That capability has a name. It’s called infrastructure — and building trust as infrastructure is where this series ends.
Sources
- Google Cloud — Announcing the Agent Payments Protocol (AP2) (September 2025): cloud.google.com
- Mastercard — Mastercard launches Agent Pay for Machines (2026; builds on Agent Pay, April 2025): mastercard.com
- Digital Commerce 360 — Visa, Mastercard offer support for AI agents (May 2025, on Visa Intelligent Commerce and Mastercard Agent Pay): digitalcommerce360.com
This is the fifth essay in Field Notes on the Agentic Enterprise. Previous: AI Doesn’t Fix Operational Debt. It Compounds It. Next: “Trust Is Becoming Infrastructure for the AI Economy.”
Helping revenue leaders, founders, and investors build the future of go-to-market.
© 2026 Todd Yancey. All rights reserved.
