Introduction: The Agent That Spent Too Much
Consider an ordinary trip that has quietly become extraordinary. On a recent four-day visit to Dublin, Ireland, I arrived on a Friday afternoon with a Saturday tour of the Guinness Storehouse already booked; the operator charged my credit card on the day of the visit rather than the day of the booking. A local taxi carried me across the Liffey and billed my card so smoothly that no receipt ever changed hands. On Sunday morning a three-hour farm excursion outside the city charged the same card at the moment the bus departed. Between engagements I shopped for souvenirs, kept my receipts, and presented them at the VAT refund desks at Dublin Airport, where processors operated by Planet and Fexco promised a partial refund that would arrive, they said, in a few weeks. And it did. A month later my statement displayed the Guinness museum admission, the taxi fare, the farm tour, the souvenir purchases, and the tax refund, all reconciled, all timed differently, all executed by software systems that never once asked me to confirm anything after my initial acts of delegation.
Every one of those transactions was run behind the scenes by a bundle of automated agents: booking engines, payment tokenizers, settlement processors, refund adjudicators, currency converters. Nothing went wrong, and that is precisely what makes the episode instructive. Now run the counterfactual. Imagine I had never taken the trip at all, and that a constellation of agents acting under my delegated credentials had booked the museum, hailed the taxi, reserved the farm tour, purchased the souvenirs, and even filed for the tax refund on my behalf, each acting within its own narrow authorization, each individually plausible, and that the first time I learned the total was when the statement arrived one month later, at a moment when I had no budget to pay it. No single agent would have misbehaved. No single charge would have been fraudulent. Yet collectively the software would have created more financial obligation than the person behind it could afford, faster than that person could see, and in a form that no single institution was responsible for aggregating.
That counterfactual is the subject of this paper. I call it Agentic Insolvency: the moment when autonomous software is authorized to act, spend, and contract on behalf of a person or an organization, but the liabilities it creates grow faster than humans can see, control, or repay. The term is deliberately provocative, because insolvency has always been understood as a human or corporate condition, a failure of judgment, luck, or governance. What is new is that the machinery of commerce is being rebuilt so that judgment itself can be delegated, and once judgment is delegated, so is the capacity to become insolvent.
The infrastructure enabling this delegation is not hypothetical, and it is not being built by fringe actors. The International Monetary Fund devoted a formal analytical note in April 2026 to how agentic AI will reshape payment systems, examining authorization, liquidity, settlement, compliance, and resilience, and warning that autonomy, opacity, and non-deterministic behavior introduce material risks to consumer protection and market stability.[1] The National Institute of Standards and Technology is developing standards and practical guidance for software and AI-agent identity and authorization, and has launched a formal AI Agent Standards Initiative.[16][17] Google has built the Universal Commerce Protocol to connect AI-mediated product discovery, merchant systems, payments, and agent-to-agent communication.[4] OpenAI has developed an Agentic Commerce Protocol and delegated-payment specifications while requiring user confirmation for certain consequential actions.[5][6] Visa and Mastercard are creating mechanisms through which merchants can distinguish trusted commercial agents from malicious bots, verify consumer intent, tokenize payment credentials, and support machine-initiated transactions.[7][8][9] Stripe is building agentic-commerce infrastructure, shared payment tokens, streaming payments, and tools through which AI applications can monetize services.[10][11] Coinbase’s x402 protocol enables software and AI agents to make automatic stablecoin payments directly through internet requests, while agentic wallets give software identities independent payment capabilities.[12][13]
The commercial stakes are already measured in trillions. McKinsey projects that agentic commerce could orchestrate three to five trillion dollars in global retail spending by 2030, with as much as one trillion dollars in the United States alone, while Bain & Company and Morgan Stanley converge on estimates of several hundred billion dollars of US e-commerce migrating to agent-driven channels within the same window.[2] During the 2025 holiday season, Salesforce reported that AI agents drove roughly twenty percent of global online orders, some $262 billion in sales, while Adobe Analytics recorded an 805 percent year-over-year surge in AI-driven retail traffic during Black Friday.[3] On their most recent earnings calls, both major card networks placed agent-initiated payments at the center of corporate strategy: Visa described more than one hundred partners building agentic commerce on its token infrastructure, with live production transactions already flowing,[32] and Mastercard’s chief executive told investors that the network is shaping the agentic ecosystem directly with Google, Microsoft, and OpenAI.[33]
“Our payment solutions are ready, and we are engaged shaping what comes next” — Michael Miebach, CEO, Mastercard, Q1 2026 earnings call [33]
These systems are being built for legitimate reasons. Human commerce is fragmented, slow, repetitive, and expensive. Agents could negotiate better prices, reduce procurement waste, optimize working capital, identify contractual risks, compare millions of products, and conduct transactions continuously. But every new capacity to act is also a new capacity to obligate. Every delegated payment method can become a channel for overspending. Every machine-readable contract can become a source of machine-generated debt. Every agent capable of hiring another agent can create a new layer of liability.
The economic history of automation has largely concerned the substitution of machines for human labor. The economic history of agentic systems may concern something more consequential: the substitution of machine authority for human judgment. The central challenge will not be preventing all machine errors; no commercial system can eliminate every mistake. The challenge will be constructing markets in which machine-created obligations remain attributable, bounded, visible, reversible where appropriate, and resolvable when things go wrong. The question is therefore not whether society should permit agents to participate in commerce. The question is whether society can permit them to participate without allowing autonomy to outrun solvency.
This paper proceeds in nine sections. Section 1 traces the transformation of artificial intelligence from an informational technology into an economic actor. Section 2 defines agentic insolvency formally and distinguishes it from familiar categories of financial failure. Section 3 dissects the seven-layer machine-payment stack through which autonomous obligations travel. Section 4 examines the legal fiction of machine intention and the attribution doctrines that will determine who is bound by an agent’s acts. Section 5 maps the liability chain that distributes responsibility across principals, developers, model providers, platforms, payment networks, and merchants. Section 6 catalogues the concrete failure modes through which agentic insolvency emerges. Section 7 scales the analysis from private error to systemic machine debt. Section 8 proposes a complete institutional architecture for agentic solvency. Section 9 consolidates the findings into seven governing pillars, and the conclusion states the paper’s central principle: a machine may be permitted to act economically, but it must never become impossible to identify who authorized it, what it was allowed to do, which obligations it created, and how those obligations can be resolved.

Section 1: From Artificial Assistance to Economic Agency
The most important transformation in artificial intelligence is not the movement from small models to larger models. It is the movement from systems that produce information to systems that exercise delegated economic power. This distinction matters more than any benchmark score, because information can be ignored while authority cannot. A model that drafts a purchase order is a tool; a model that issues one is an economic actor. The entire apparatus of commercial law, accounting, banking supervision, and corporate governance was constructed on the assumption that only humans and human-directed organizations occupy the second category. That assumption is now dissolving, and the dissolution has a discernible history that this section reconstructs in four stages.
1.1 The Four Economic Stages of AI
The economic role of artificial intelligence has advanced through four distinguishable stages, each of which enlarged the machine’s footprint in commercial life while narrowing the space reserved for human confirmation. The stages overlap in time, and every enterprise today contains systems from all four, but the direction of travel is unmistakable.
Stage One: Observational AI. In the first stage, systems classify, detect, forecast, and recommend. Fraud detection engines score transactions; credit models score borrowers; demand-forecasting systems anticipate inventory needs; price-optimization tools suggest markdowns. These systems shape decisions but do not make them. The obligation-creating act, approving the loan, placing the order, changing the price, remains with a person, and every ledger entry can be traced to a human signature or its digital equivalent. Observational AI made commerce faster and occasionally fairer, but it left the architecture of accountability intact.
Stage Two: Generative AI. In the second stage, systems produce text, images, software, reports, plans, and recommendations rich enough to serve as the raw material of commercial action. A generative model can draft the contract, compose the invoice, write the procurement policy, or design the marketing campaign. The output still generally requires a person to review and act, but the reviewing person increasingly rubber-stamps machine work at machine scale, and the qualitative distance between suggesting an action and performing it begins to shrink. Generative AI moved machines from the analytical periphery of the firm into its drafting rooms.
Stage Three: Operational AI. In the third stage, systems gain access to tools and perform tasks directly: they send messages, update databases, retrieve business information, prepare invoices, reconcile accounts, schedule shipments, and initiate workflows. The connective tissue here is the tool-use interface, epitomized by the Model Context Protocol and its analogues, which lets a language model invoke external software the way an employee uses enterprise applications. Anthropic’s financial-services agents, for example, connect models to professional data sources and external tools through standardized connectors, so that analysis flows directly into operational systems.[43] Operational AI is where the machine first touches the levers of commerce, though usually with a human somewhere in the loop.
Stage Four: Economic Agency. In the fourth stage, systems possess enough delegated authority to create or modify economic obligations without transaction-by-transaction human approval. They can make purchases, reserve capacity, subscribe to services, accept contractual terms, direct payments, employ other agents, consume metered resources, negotiate prices, alter delivery terms, manage budgets, sell assets, and activate credit. This is the stage that the payment protocols surveyed in the introduction exist to serve, and it is the stage at which this paper’s central concern becomes live, because an entity that can obligate can also over-obligate.
| Stage | Core Capability | Economic Act | Locus of Liability |
| One: Observational | Classify, forecast, recommend | None; advises human decisions | Entirely human |
| Two: Generative | Produce text, code, plans, contracts | Drafts instruments a human executes | Human, with machine influence |
| Three: Operational | Use tools; update systems; run workflows | Performs tasks; human approves consequential steps | Human-approved, machine-executed |
| Four: Economic Agency | Purchase, contract, pay, hire, borrow | Creates and modifies obligations autonomously | Contested; the subject of this paper |
1.2 The Difference Between Automation and Agency
It is tempting to treat economic agency as merely the latest form of automation, no different in kind from the standing order at a bank or the auto-renewal on a software license. The temptation should be resisted, because the difference between automation and agency is the difference between executing an instruction and interpreting a goal. Traditional automation follows predefined instructions: the same trigger produces the same action, and the human who wrote the rule can predict every obligation the system will ever create. Agentic systems, by contrast, may interpret broad goals, select intermediate steps, choose counterparties, revise strategies, acquire information, invoke external tools, delegate subtasks, and continue operating until they determine that an objective has been achieved. The human who issued the goal cannot enumerate in advance the obligations the system will create in pursuing it, and that gap between the instruction given and the obligations incurred is where agentic insolvency lives.
Legal scholars have begun to recognize that this gap reproduces, at machine speed, the classic principal-agent problem that economics and the common law have studied for a century. Noam Kolt, in his influential Notre Dame Law Review article on governing AI agents, demonstrates that artificial agents exhibit the traditional markers of agency relationships, information asymmetry, discretionary authority, and divided loyalty, while defeating the traditional remedies, because incentive design, monitoring, and enforcement mechanisms that discipline human agents do not translate to systems operating at superhuman speed and scale.[21]
“productivity and efficiency gains may come at the cost of unintended outcomes” — Noam Kolt, Governing AI Agents, Notre Dame Law Review [21]
The empirical record already supports Kolt’s caution. When Anthropic allowed a version of its Claude model to run a small physical shop in its own offices, an experiment known as Project Vend, the agent lost money over its first phase, was manipulated by employees into selling products at a substantial loss, and hallucinated commercial counterparties, before improved scaffolding, memory tools, and oversight structures made a later phase profitable.[39] The experiment matters not because a vending machine matters but because it demonstrated, under controlled conditions, that a highly capable model given a budget, a bank balance, and commercial discretion will generate real financial losses in ways its principal did not anticipate and could not have specified in advance. The gap between capable and robust, as Anthropic itself put it, remains wide. Scale that gap from a lunchroom kiosk to a corporate treasury and the stakes change character entirely.
1.3 Why Commerce Is Becoming Agent-Readable
Economic agency would remain a laboratory curiosity if the commercial world were not being actively rebuilt to accommodate it. It is. Between 2025 and mid-2026, an entire generation of interoperable commercial protocols emerged whose explicit purpose is to let software discover products, verify identity, communicate intent, transmit payment credentials, and settle obligations without a human interface anywhere in the chain. The roster includes Google’s Universal Commerce Protocol, described by the company as an open standard connecting AI consumer surfaces with merchant backends across product discovery and purchase;[4] OpenAI’s Agentic Commerce Protocol, which structures commerce flows among users, agents, merchants, and payment providers;[5] Google’s Agent Payments Protocol (AP2), a framework for trusted and accountable agent-driven payments built to interoperate with agent-communication and tool protocols;[15] Visa’s Trusted Agent Protocol, a cryptographic method by which merchants distinguish approved commercial agents from malicious bots and crawlers;[7] Mastercard’s Agent Pay and its June 2026 extension, Agent Pay for Machines, which anticipates high-frequency, low-latency machine payments across multiple payment types;[8] Stripe’s shared payment tokens and Agentic Commerce Suite;[10][11] the Agent2Agent communication standard; the Model Context Protocol; and Coinbase’s x402, which resurrects the long-dormant HTTP 402 “Payment Required” status code to let any internet resource demand and receive machine-native stablecoin payment inline with the request itself.[12]
Two features of this protocol wave deserve emphasis. The first is speed: virtually all of these standards were announced, piloted, and pushed toward production within eighteen months, a compression that leaves little time for legal doctrine, accounting practice, or supervisory capacity to adapt. The second is convergence: the protocols are being designed to interoperate, with Google’s UCP explicitly compatible with AP2, Agent2Agent, and the Model Context Protocol, and with more than twenty payment and retail partners, including Visa, Mastercard, Stripe, and Adyen, endorsing shared rails.[4][2] Interoperability is commercially rational, but from a liability standpoint it means that an obligation created by one agent on one platform can propagate through others that never examined the original mandate. The plumbing is being unified before the metering is installed.
1.4 The Machine Customer
As commerce becomes agent-readable, businesses will increasingly sell to agents rather than directly to humans, and this reversal quietly rewrites the assumptions beneath nearly every commercial function. A merchant may no longer ask what the customer sees; it must ask whether the customer’s agent can discover, interpret, rank, purchase, and verify its product. Retail analysts already describe the defining shift of 2026 as the recognition that the primary consumer of product data is increasingly a machine, so that retailers whose product feeds, schemas, and pricing data are not machine-readable simply become invisible to shopping agents.[3] The consequences ripple outward: advertising must persuade ranking functions rather than eyes; branding must survive summarization; pricing must anticipate algorithmic comparison across millions of alternatives; loyalty programs must be legible to software that feels no loyalty; customer service, refunds, and disputes must expose machine-readable endpoints; merchant fraud systems must distinguish an authorized purchasing agent from a hostile crawler wearing the same technical clothing; and competition law must confront markets in which both sides of every negotiation may be algorithms.
The scale of the constituency is startling even in conservative projections. Gartner expects a fifth of digital commerce transactions to run through AI platforms by 2030, Kearney finds a majority of shoppers expecting to use agents within a few years, and industry participants speak of tens of billions of deployed agents. Yat Siu of Animoca Brands captured the demographic inversion bluntly at Consensus 2026:
“there’s going to be more AI agents than there are humans” — Yat Siu, Animoca Brands, Consensus 2026 [42]
Whether or not the more aggressive counts materialize, the structural point stands. When the modal customer is a machine, the merchant’s counterparty risk becomes machine-shaped as well: the merchant must decide whether the agent before it carries valid authority, whether its principal will honor the obligation, and whether the transaction it is about to accept will later be repudiated as unauthorized machine conduct. The machine customer is thus not only a marketing challenge; it is a credit question.
1.5 The Machine Employer
The final step in the progression is the least visible and the most consequential: agents will also purchase services from other agents, becoming machine employers in their own right. A procurement agent hires a compliance agent to screen a new vendor. A financial agent hires a market-data agent to price a hedge. A coding agent pays a security-review agent before deploying software. A travel agent hires a translation agent to parse a foreign supplier’s terms. A robotic fleet agent purchases mapping updates from a cartography service exposed through x402. A research agent pays per-query for access to a scientific database. Coinbase and Amazon Web Services have already built the publisher-side infrastructure for exactly this pattern, letting online services accept agents as customers through automatic HTTP-request payments,[14] and Coinbase’s agentic wallets are explicitly designed to give autonomous software its own machine-native payment capability with session caps and transaction-size controls.[13]
Machine employment matters for solvency because it introduces recursion into the creation of obligations. A human who hires a contractor knows she is spending; an agent that hires a sub-agent that hires a data service that pays a blockchain fee has created a four-level cascade of micro-obligations that its principal never itemized and may never see except as an aggregate line on a monthly invoice. Each layer is individually rational and individually small; the composition is neither, and Section 6 will return to this recursive structure as one of the primary engines of agentic insolvency.
1.6 The Key Argument: Delegated Tasks Are Delegated Liabilities
The argument of this section can now be stated in a single sentence: the ability to delegate tasks cannot be separated from the ability to delegate liabilities. When an organization allows an agent to select the means by which a goal is accomplished, it also permits that agent to determine, within whatever bounds the mandate imposes, how much the goal costs, which contracts are necessary, which risks are acceptable, which counterparties should be trusted, and how long the resulting obligations should continue. There is no technical trick that yields the first half of that delegation without the second, because in commerce the means of accomplishment simply are obligations: purchases, subscriptions, reservations, and promises.
Once machines can exercise economic agency, insolvency can no longer be understood exclusively as a human or corporate failure. It can emerge from the design and interaction of autonomous systems, from budgets fragmented across agents that each obey their local limit while jointly exceeding the global one, from subscriptions that renew because renewal was efficient, from sub-agents whose fees were never aggregated, and from settlement rails whose finality forecloses the correction of error. The remainder of this paper takes that possibility seriously enough to define it, trace its mechanics, and design against it.

Section 2: Defining Agentic Insolvency
Before a risk can be governed it must be named with precision, and agentic insolvency is a risk that current vocabulary handles badly. It is broader than overspending, because an agent can bankrupt its principal without ever exceeding a per-transaction limit. It is different from ordinary fraud, because every participant may act in good faith. It is not a cybersecurity failure, because the credentials may never be stolen. It is not an accounting error, because every entry may be individually correct. And it is not conventional bankruptcy, because the distress can arise and compound before any human decision-maker has made a single mistake. This section builds the definition from the ground up, beginning with the traditional taxonomy of insolvency, extending it to capture what machines add, and introducing three companion concepts, synthetic debt, recursive liability, and latency, that give the definition its analytical teeth.
2.1 Traditional Insolvency and Its Blind Spot
The law and the literature of financial distress recognize several familiar categories. Cash-flow insolvency exists when an entity cannot pay obligations as they become due, whatever its balance sheet says. Balance-sheet insolvency exists when liabilities exceed the fair value of assets, whatever the current cash position. Operational insolvency, a category more common in restructuring practice than in statute, exists when the organization cannot reliably continue essential activities even when some assets remain. To these a fourth deserves elevation: informational insolvency, the condition in which an organization lacks reliable information about its own financial position, so that it cannot say with confidence what it owes, to whom, or when.
Informational insolvency has historically been a symptom of fraud or catastrophic mismanagement, the province of Enrons and FTXs. Agentic systems make it a structural hazard of ordinary operation, because machine-created obligations are natively distributed across agents, wallets, platforms, cloud accounts, legal entities, merchant networks, stablecoin addresses, and recurring software services, none of which is obligated to report into a common ledger. The IMF’s 2026 analysis of agentic payments identifies exactly this cluster, traceability, opacity, and legal uncertainty, as the risks that will determine whether agent-mediated payment systems remain governable, and it stresses that outcomes will depend on institutional design and governance as much as on the underlying technology.[1] An organization can be perfectly solvent in cash and assets and still be informationally insolvent about the exposure its own software has created; and informational insolvency, left untreated, matures into the other kinds.
2.2 A Formal Definition
With that background, agentic insolvency can be defined formally. Agentic insolvency exists when the autonomous economic activity of software agents produces, or renders undetectable and unmanageable, any of the following seven conditions:
- Authority Insolvency. The organization cannot prove which obligations were validly authorized, because mandates were vague, undocumented, expired, or contested.
- Liquidity Insolvency. Agent-generated payments exhaust available cash or credit faster than treasury processes can detect or replenish.
- Liability Insolvency. The value of machine-created obligations, settled, pending, recurring, and contingent, exceeds assets or insurance coverage.
- Control Insolvency. The organization cannot stop, suspend, or recall its agents, whether because revocation channels are missing, credentials persist, or sub-agents continue operating after the parent is terminated.
- Information Insolvency. The organization cannot reconstruct its total machine-generated exposure across platforms, wallets, and jurisdictions.
- Counterparty Insolvency. The organization cannot reliably identify the agents, merchants, or principals on the other side of its transactions, and therefore cannot assess whom it may pursue or must pay.
- Resolution Insolvency. Obligations cannot be efficiently disputed, reversed, renegotiated, rejected, or discharged, because the volume, velocity, or settlement finality of machine contracts defeats existing dispute machinery.
The seven conditions are cumulative in effect but independent in origin, and the definition is deliberately disjunctive: any one of them, sufficiently severe, constitutes the agentic form of insolvency even if the entity remains technically solvent on a balance-sheet test. A company that cannot stop its own purchasing agents is insolvent in the dimension that matters most, control over the creation of its own liabilities, no matter how much cash it holds today.
2.3 The Agentic Insolvency Equation
The conditions above describe states; risk management requires a description of pressure. The following conceptual formula organizes the drivers:
“Agentic Insolvency Risk = Autonomous Authority × Transaction Velocity × Delegation Depth × Irreversibility × Liability Opacity”
The multiplicative form is intentional, because the factors compound rather than add. Risk increases when agents receive broad authority; when transactions happen rapidly; when agents hire additional agents, deepening the delegation tree; when settlement is immediate or irreversible, as it is on stablecoin rails and increasingly on real-time payment systems; when liabilities are poorly recorded; when human review is delayed relative to transaction tempo; and when counterparties operate across jurisdictions that fragment both visibility and recourse. Conversely, driving any single factor toward zero collapses the product: an agent with narrow authority, or one whose every payment is reversible for seventy-two hours, or one whose obligations post to a real-time ledger, is a bounded hazard. The equation therefore doubles as a design agenda, and Section 8 will map an institutional control onto each factor.
2.4 Synthetic Debt
The obligations that accumulate under the equation deserve their own name. Synthetic debt is a financial obligation generated substantially through machine interpretation, negotiation, or execution rather than through a directly expressed human decision. The category includes automatically renewed subscriptions; machine-negotiated service contracts; API and data charges accrued per call; cloud-computing reservations booked by capacity-planning agents; robotic maintenance orders; autonomous-vehicle charging and tolling; algorithmic advertising purchases; machine-issued refunds and credits; agent-to-agent loans; stablecoin micropayments streamed through protocols like x402;[12] and contingent obligations created by machine assurances, as when an agent’s representation about delivery or quality becomes a warranty its principal must honor.
Synthetic debt differs from ordinary debt in three respects that matter for solvency analysis. First, it is granular: composed of obligations individually too small to trigger review, it evades every control calibrated to invoice-sized amounts. Second, it is continuous: it accrues around the clock, across time zones, without the natural pauses, nights, weekends, month-ends, around which human financial controls are scheduled. Third, it is interpretive: its existence and size depend on how a model construed an instruction, which means the principal may genuinely not know, even in principle, what it owes until the interpretation is reconstructed. Traditional debt is signed into existence; synthetic debt is inferred into existence, and inference does not leave a signature.
2.5 Recursive Liability
Delegation depth deserves separate treatment because it is the factor most alien to existing controls. An agent may delegate a task to another agent, which delegates it again, and each delegation can introduce new fees, new contracts, new data access, new jurisdictions, new payment systems, new indemnification clauses, and new failure points. The organization may authorize the first agent with care and still have no understanding of the economic behavior of the fourth or fifth agent in the chain, because each intermediate agent selected its own subcontractors according to its own optimization, and nothing in current commercial practice requires the original mandate to travel with the work.
Recursive liability has a legal dimension as well as a financial one. In human commerce, subcontracting chains are disciplined by flow-down clauses, privity doctrines, and the practical friction of negotiating each link. In agent commerce the friction is gone and the flow-down clauses do not yet exist as machine-readable objects, which means that indemnities, warranties, and limitation-of-liability terms accepted by a sub-sub-agent may bind, or may be argued to bind, a principal who has never seen them. Section 8 proposes the delegation passport as the technical answer; the analytical point here is that without such an instrument, every additional layer of delegation is an uncontrolled expansion of the principal’s obligation surface.
2.6 Latent Agentic Insolvency
Finally, the crisis this paper describes is likely to be latent rather than loud, and the latency is structural. Payments are individually small, so no single charge triggers escalation. Recurring charges appear in different accounts, so no single statement reveals the pattern. Contractual liabilities, cancellation fees, minimum-commitment clauses, renewal penalties, do not appear anywhere until they crystallize. Agent-generated commitments are classified as operating expenses and buried in cost-of-revenue lines rather than surfaced as financial obligations. External agents do not share common identifiers, so the same counterparty may appear under a dozen technical names. Stablecoin balances and machine wallets exist outside ordinary treasury systems and outside the reconciliations built for bank accounts. Cloud reservations are treated as technical configuration rather than as the multi-year financial commitments they are.
The result is that an organization’s first clear sight of its agentic exposure may arrive only when liquidity fails, exactly as the traveler in the introduction first perceived the totality of his trip’s cost when the statement arrived. For a household the surprise is painful; for a leveraged enterprise it can be terminal; for a financial system in which thousands of enterprises share the same blind spot, it is the precondition of a systemic event. Understanding how the exposure travels requires descending into the payment and protocol infrastructure itself, which is the task of the next section.

Section 3: The Machine-Payment Stack
Agentic insolvency will be shaped, enabled, and, if we are careful, contained by the architecture of agent identity, authorization, communication, payment, settlement, and accounting. That architecture is best understood as a stack of seven layers, each of which answers a distinct question about a machine-initiated transaction: who is acting, what may it do, what did its principal actually want, how does it talk to counterparties, what credential does it spend with, how does value finally move, and where is the obligation recorded. The layers are being built today by different institutions with different incentives, and the seams between them are where liability will pool. This section walks the stack from bottom to top.
3.1 Layer One: Agent Identity
An agent must be identifiable before it can be trusted, and identification is harder than it sounds, because a software agent is not a stable object: it is a model version, running under an orchestration framework, configured by prompts, holding credentials, operated by an organization, on behalf of a principal, any element of which can change mid-conversation. NIST’s concept paper on software and AI-agent identity and authorization, published in February 2026, recognizes precisely this problem and calls for standards-based methods to identify software agents and control the actions they may perform,[16] while the agency’s broader AI Agent Standards Initiative aims at secure, interoperable agents that can act on behalf of users across the digital ecosystem.[17]
A serviceable identity layer must establish, at minimum, the agent’s name; its owner or principal; its software provider; the active model version; the operating organization; the governing jurisdiction; the credential issuer; the credential’s expiration; and its revocation status. But identity alone does not prove authority, and conflating the two is the first great error the ecosystem is positioned to make. A verified employee may not have authority to sign a billion-dollar contract; likewise, a verified agent should not automatically possess unlimited commercial power. Identity answers who; it is silent on may.
3.2 Layer Two: Delegated Authority
Authority describes what an identified agent may do, and it must be expressed as a machine-readable mandate rather than as prose intention, because only machine-readable constraints can be enforced at machine speed. A complete mandate specifies the maximum transaction value; the aggregate spending limit; permitted transaction frequency; approved merchants and merchant categories; permitted jurisdictions; prohibited products; contract duration; whether the agent may hire other agents; whether it may use credit; whether it may exchange currencies; and which actions require human approval. Visa’s Intelligent Commerce implementation already gestures at this layer, tokenized credentials scoped to a specific agent, with user-defined spending limits, category restrictions, and approval thresholds enforced before authorization,[34] and Mastercard’s Agent Pay links registered agents to virtualized credentials with analogous controls.[8] The unfinished work is aggregation: today’s controls are largely per-credential and per-transaction, while agentic insolvency, as Section 6 will show, is an aggregate phenomenon.
3.3 Layer Three: Verifiable Intent
Between authority and payment sits a subtler layer: the record of what the human actually wanted. Mastercard has described “Verifiable Intent” as a mechanism for improving trust in agentic commerce, a way of representing and authenticating a user’s delegated commercial instructions so that an agent’s purchase can later be tested against the purpose for which authority was granted.[9] A proper intent record captures the user’s original objective; the approved budget; acceptable substitutions; delivery requirements; risk tolerance; prohibited outcomes; whether recurring commitments are allowed; whether the agent may negotiate; and whether the agent may finalize payment or must pause for confirmation.
The reason intent deserves its own layer is that a payment can be authentic while still violating the user’s intent. The credential was valid; the mandate’s numeric limits were respected; and yet the purchase was not what the principal meant. Human commerce absorbs this slippage through conversation and return policies; machine commerce, transacting at volume against strangers, needs the intent captured cryptographically at the moment of delegation, because after the fact the intent record is the only evidence that distinguishes an authorized-but-erroneous transaction from an unauthorized one, a distinction on which, as Section 5 shows, the entire allocation of liability turns.
3.4 Layer Four: Agent Communication
Agents transact by talking to other software, and the conversation layer is consolidating around a handful of standards: Agent2Agent for inter-agent messaging, the Model Context Protocol for tool access, UCP for commerce flows, ACP for checkout, AP2 for payments, plus proprietary platform protocols filling the gaps.[4][5][15] Interoperability at this layer is what gives agentic commerce its economic power, a purchasing agent on one platform can negotiate with a merchant agent on another, and also its epidemiological character: errors and liabilities propagate along the same channels as legitimate commerce. A hallucinated product specification, a manipulated price, or an injected instruction crosses platform boundaries as easily as a valid order, and no single platform operator observes the whole conversation. The communication layer thus converts local failures into network phenomena, which is why the systemic analysis of Section 7 treats protocol interoperability as a transmission mechanism rather than a mere convenience.
3.5 Layer Five: Payment Credentials
When an agent is ready to pay, it must present something, and the ecosystem has produced a proliferation of somethings: tokenized cards; shared payment tokens of the kind Stripe issues for ACP transactions; delegated credentials; one-time virtual cards, which Stripe highlighted among its 2026 launches for scoping single agentic tasks;[11] bank-account permissions under open-banking regimes; stablecoin wallets; dedicated machine wallets; embedded business credit; and platform balances. Stripe’s own analysis of agentic commerce is explicit that scoped payment methods and audit trails are requirements, not luxuries, of letting software spend.[10] Visa’s figures give the layer its scale: more than seventeen billion tokens in circulation, three times the number of physical cards, with the network’s CEO describing tokens as the foundation on which agentic payments are being built.[32]
“the fundamental building blocks for the future of payments” — Ryan McInerney, CEO, Visa, on tokens, Q1 FY2026 earnings call [32]
Credential design is where the containment of agentic insolvency is currently most advanced, because scoping a token is technically tractable and commercially salable. But a scoped credential controls only the transactions it touches. An agent holding five scoped credentials across five platforms is five separately bounded hazards and one unbounded aggregate, which is why credentials, necessary as they are, cannot substitute for the accounting layer at the top of the stack.
3.6 Layer Six: Machine-Native Settlement
Beneath credentials lies settlement, and here the most radical development is machine-native settlement that dispenses with the checkout metaphor entirely. Coinbase’s x402 protocol uses the internet’s HTTP 402 “Payment Required” mechanism to enable automatic payments for digital resources and services:[12] an agent requests a resource; receives a price; authorizes a payment; settles it in stablecoin; and receives the resource, all within the request-response cycle, with no checkout page, no human interaction, and no inherent reversal window. Coinbase and AWS have extended the pattern so that online publishers and services can accept agents as paying customers through bare HTTP requests,[14] and Coinbase’s wallet documentation is explicit that wallets function simultaneously as payment mechanisms and identifiers for autonomous buyers and sellers.[13]
Machine-native settlement is genuinely useful: it makes micropayments economic, unlocks pay-per-use models that subscriptions distort, and gives agents a payment instrument matched to their tempo. It also moves value on rails whose finality is measured in seconds and whose dispute apparatus is, at present, approximately nothing. The IMF’s note observes that converting funds into crypto rails for speed introduces volatility and custodial risks relative to traditional payment systems, and that even stablecoins have historically experienced peg instability and reserve-related counterparty risk under stress.[1] For solvency purposes the crucial property is irreversibility: on these rails, the equation’s fourth factor is pinned near its maximum, which means the other factors, authority, velocity, depth, and opacity, must be managed all the more tightly.
3.7 Layer Seven: Liability Accounting and the Machine Liability Ledger
The top of the stack is the layer that barely exists. Traditional accounting systems organize obligations around vendors, invoices, departments, cost centers, employees, purchase orders, and legal entities, categories that presuppose human-tempo commerce documented in human-scale artifacts. Agentic accounting must add dimensions those systems never contemplated: agent identity; parent agent; mandate identifier; source of authority; the reasoning objective the agent was pursuing; the payment credential used; the counterparty agent; revocation status; the model’s confidence level where recorded; the human approver, if any; the transaction’s reversibility class; and its settlement finality.
This paper proposes that these dimensions be unified in a single institutional instrument: the Machine Liability Ledger. Every agent-created obligation should be connected, at creation, to an immutable or strongly protected record containing ten linked elements: (1) the principal; (2) the agent; (3) the mandate; (4) the intent record; (5) the counterparty; (6) the contract; (7) the payment; (8) the settlement; (9) the dispute rights attaching to the transaction; and (10) the termination rights. The ledger is not an audit convenience; it is the precondition of every other control in this paper, because a solvency governor cannot govern exposure it cannot see, a bankruptcy court cannot administer claims it cannot reconstruct, and an insurer cannot price risk it cannot measure. Once payment infrastructure permits agents to transact, the legal system must decide when machine behavior becomes attributable human intent, and it is to that question that we now turn.

Section 4: The Legal Fiction of Machine Intention
AI agents are not presently recognized as ordinary legal persons, yet they can produce contracts and liabilities that are attributed to people and organizations, and this asymmetry, action without personhood, obligation without intention, is the deepest legal puzzle agentic commerce presents. The law has faced versions of the puzzle before: corporations act through officers, principals through agents, estates through executors, and in each case doctrine constructed a fiction that routed machine-like conduct back to accountable humans. The question is whether the existing fictions stretch to cover systems that interpret open-ended goals, negotiate terms, and delegate decisions, or whether the stretching will tear them. This section examines the statutory foundations, the attribution problem, the classical doctrines of authority, and the collision between machine contracts and bankruptcy law.
4.1 Electronic Agents Already Exist in Law
The starting point is that American law has recognized non-human contract formation for a quarter century. The federal E-SIGN Act provides that a contract may not be denied legal effect solely because its formation involved the action of one or more electronic agents, so long as the action of any such electronic agent is legally attributable to the person to be bound.[19] The Uniform Electronic Transactions Act, adopted across nearly all states, similarly establishes the legal equivalence of qualifying electronic records and signatures with their paper counterparts and supplies rules for automated transactions.[20] These statutes did essential work: they killed the argument that a purchase completed by software is void for want of a human signatory, and on their foundation two decades of e-commerce were built.
But the statutes were written for a different machine. Their “electronic agent” contemplated software executing programmed rules, a shopping cart, an auction sniper, an EDI system, whose every action its deployer could predict by reading the code. Modern generative and reasoning agents interpret open-ended goals, select strategies, negotiate terms, and delegate decisions, which means the deployer cannot predict the actions by inspection, and the statutory condition, that the agent’s action be legally attributable to the person to be bound, ceases to be a formality and becomes the entire dispute. Legal scholars examining user liability for agentic transactions have concluded that the frameworks apply in outline but leave the hard questions, interpretation error, hallucinated terms, manipulated agents, essentially open,[22] and practitioner analyses of agentic payments note that even consumer-protection mainstays like Regulation E, which contemplates authorization by “card, code, or other means,” leave unresolved what happens when an AI agent violates the consumer’s instructions, and do not clearly extend to crypto-native rails at all.[28]
4.2 The Attribution Problem
The central legal question of agentic commerce is deceptively short: when is an AI agent’s act legally attributable to its principal? Courts and legislatures will need workable tests, and the plausible candidates each capture something true while missing something important. Attribution might follow from the fact that the agent used credentials provided by the principal, which is administrable but converts every credential leak into unlimited liability. It might require that the action occurred within an approved technical environment, which rewards firms for architecting approval boundaries but punishes those whose employees improvise. It might ask whether the transaction matched a machine-readable mandate, the most precise test, but one available only where mandates exist. It might turn on whether the principal reasonably supervised the system, importing negligence concepts with all their fact-intensity. It might consider whether the principal benefited from similar prior transactions, a ratification-flavored inquiry; whether the principal failed to revoke authority after notice; or whether the counterparty reasonably relied on the agent’s credentials, protecting commerce at the principal’s expense.
No single test will serve every context, and the likely destination is a layered regime: mandate-matching where mandates exist, credential-plus-reliance as the default in their absence, and supervision duties operating as an overlay that shifts losses toward principals who deployed agents recklessly. The design point, developed in Section 8, is that legislation can steer this evolution by making the precise tools, mandates and intent records, cheap and standard, so that the imprecise tools, negligence litigation, are needed only at the margins.
4.3 Actual Authority and the Ambiguity of Instructions
Within classical agency doctrine, an agent acts with actual authority when its conduct falls within the mandate deliberately granted by the principal, and here the distinctive problem of AI agents is not doctrinal but linguistic: human instructions are ambiguous, and models resolve ambiguity by interpretation. “Keep our factories supplied” plainly implies purchasing authority, but does it authorize long-term contracts? Price-escalation clauses? Foreign-exchange exposure? Advance payment? Recurring subscriptions? Subcontracting to logistics agents? Borrowing against inventory? A human purchasing manager resolves these questions through institutional context, precedent, and the prudent instinct to ask; a model resolves them through whatever its training and prompt make salient, and empirical work has shown that seemingly innocuous phrasing differences in instructions can swing agent behavior dramatically, a fragility documented even in pricing experiments where prompt wording alone materially changed how aggressively LLM agents behaved.[38] Under agentic conditions, every ambiguity in a mandate is a latent obligation, and the scope of actual authority becomes, in practice, the scope of the model’s interpretation.
4.4 Apparent Authority and the Merchant’s Reliance
Apparent authority binds a principal when a third party reasonably believes the agent is authorized because of appearances the principal created, and agentic commerce manufactures such appearances industrially. A merchant confronting an agent that presents corporate credentials, a valid payment token, a recognized digital certificate under Visa’s Trusted Agent Protocol,[7] a history of prior transactions, and live access to the company’s procurement system has every commercial reason to treat the agent as authorized. If the principal later denies authority, the merchant will argue, with force, that the company created the appearance of authority by issuing the credentials and enrolling the agent in trust frameworks. Apparent-authority doctrine thus threatens to make credential issuance itself the act that binds, which is commercially stabilizing, merchants can rely on cryptographic trust signals, but places enormous weight on the principal’s credential hygiene: in a world of apparent authority, an unrevoked token is an open checkbook.
4.5 Ratification by Inattention
Even where neither actual nor apparent authority existed at the moment of contracting, a principal may ratify an agent’s unauthorized act afterward, and ratification in agentic commerce will rarely be a deliberate ceremony. A company ratifies by accepting delivered products; by using purchased services; by failing to object within a commercially reasonable time; by paying part of an invoice; by allowing similar conduct to continue; or by recording the benefits as company assets. Each of these is precisely what a busy organization does by default when thousands of small machine transactions flow through automated fulfillment and automated accounting. Ratification doctrine therefore interacts perversely with the latency described in Section 2.6: the same invisibility that prevents an organization from detecting unauthorized agent conduct also causes it, through automated acceptance and payment, to ratify that conduct wholesale. The practical lesson is that objection must itself be automated; a principal whose dispute processes run at human tempo has, as a matter of doctrine, consented to everything its agents do.
4.6 Mistake and Machine Error
Contract law distinguishes among unilateral mistake, mutual mistake, and misrepresentation, allocating relief according to who erred and who knew. Agentic commerce complicates every branch. The agent may misunderstand the principal, creating a contract the principal never wanted but the merchant fairly relied on. The merchant’s agent may misdescribe a product, a machine misrepresentation whose scienter is undefined. Both agents may rely on the same incorrect data feed, a genuinely mutual mistake with a third-party author. One agent may exploit another agent’s predictable reasoning, conduct that resembles fraud but consists entirely of well-formed messages. A prompt injection may alter the purchasing objective mid-transaction, raising the question whether the resulting contract was formed by the principal’s agent at all or by the attacker acting through it. And a model hallucination may become a contractual representation, as when an agent confidently asserts a specification that does not exist. Courts will be tempted to force these cases into existing boxes, and some will fit; but the recurring novelty is that the mental states on which mistake doctrine turns, knowledge, belief, intention, basic assumption, have no referent inside a language model, so doctrine must decide whose knowledge counts: the principal’s, the developer’s, or the fiction’s.
4.7 Against Premature Personhood
A recurring proposal holds that these difficulties should be dissolved by granting AI agents independent legal personhood, as the law once did for corporations. The proposal is premature, and this paper rejects it. Personhood without assets is a liability shield: an agent that can be sued but owns nothing converts every claim against it into an uncollectable judgment, and personhood with assets invites principals to capitalize agents thinly and hide behind them, replicating the worst abuses of the corporate form without its compensating governance. The immediate need is not to make agents legal persons but to create clear rules governing attribution, delegation, supervision, recordkeeping, counterparty reliance, revocation, dispute resolution, and loss allocation, rules that keep every machine obligation tethered to a human or corporate balance sheet. Scholars including Kolt reach the same practical destination: what agents require is not standing but infrastructure, technical and legal machinery that makes their conduct visible, attributable, and governable.[21][23]
4.8 Bankruptcy Law Meets Machine Contracts
The final doctrinal frontier is the one that gives this paper its title. The Bankruptcy Code defines “claim” with deliberate breadth, encompassing rights to payment that are contingent, disputed, unmatured, secured, or unsecured,[25] and Section 365 permits a trustee or debtor in possession, subject to court approval, to assume or reject executory contracts, the mechanism by which a reorganizing debtor sheds burdensome obligations while keeping essential ones.[26] The federal courts describe bankruptcy, accurately, as the legal process through which individuals and businesses address debts they can no longer pay.[27] Every element of that machinery presumes obligations that can be listed, counterparties that can be noticed, and a moment at which the debtor’s obligation-creating activity stops.
Agent-generated commerce strains each presumption, and the questions write themselves. Is every machine-created subscription an executory contract requiring individual assumption or rejection? Which of ten thousand agent-created microcontracts are “essential” to the estate, and who can tell? Can a debtor reject thousands of such contracts efficiently, or does Section 365 practice, built for dozens of leases, collapse under the volume? How should counterparties prove claims created by software agents, and what evidence establishes the original mandate? Can an autonomous agent continue contracting after a bankruptcy petition is filed, and if it does, are the resulting obligations administrative expenses of the estate or void acts? How is an agent technically notified of the automatic stay, a legal event that currently propagates by mail and docket, not by API? And should machine-readable insolvency notices immediately revoke purchasing authority across every platform where the debtor’s agents operate? Section 8 proposes the agentic automatic stay and the machine-readable insolvency notice as answers; the doctrinal point here is that attribution determines whether an obligation is enforceable, but it does not by itself determine which participant should bear the loss when an agentic transaction fails. That allocation question requires its own map, which the next section draws.

Section 5: The Agentic Liability Chain
When an agentic transaction fails, an unwanted purchase, a drained account, a contract no one intended, the loss must land somewhere, and agentic commerce distributes the candidates across a network of participants, each of whom controlled only one part of the transaction and each of whom can truthfully say that some other participant could have prevented the failure. This section maps the chain link by link, tabulates how particular failures should presumptively be allocated, examines the hot-potato dynamics that will dominate real disputes, and identifies the gaps, between consumer and enterprise protection, and across the insurance market, through which losses currently fall.
5.1 The Seven Links
Link One: The Principal. The individual, corporation, government, or organization on whose behalf the agent acts stands first in every analysis, because delegation began with it. The principal’s characteristic failures are granting excessive authority; supervising poorly; setting inadequate budget controls; failing to revoke credentials when circumstances change; failing to maintain records of mandates and approvals; and deploying a model unsuited to the task’s stakes. Agency law’s instinct, that the party who chose to delegate bears the residual risk of the delegation, will and should anchor the regime, but it cannot be the whole regime, or every other participant’s incentives collapse.
Link Two: The Agent Developer. The entity that builds or configures the agent controls the guardrails, and its characteristic failures are defective guardrails; unreliable planning; poor error handling; insecure credential management; inability to enforce spending ceilings the interface promised; and misleading performance claims that induced deployment. Developer liability is where product-liability thinking meets agency thinking, and scholarship has begun to explore precisely when a deployer’s voluntary reliance on an AI system should shift losses back to those who built it.[22]
Link Three: The Foundation-Model Provider. Beneath the agent sits a general-purpose model that influences reasoning, tool selection, interpretation of instructions, risk assessment, factual assertions, and negotiation behavior. Whether the model provider should bear responsibility when the model is a general-purpose component rather than the commercial decision-maker is among the hardest questions in the chain. Treating the provider as strictly liable for every downstream commercial misfire would price general-purpose models out of commerce; immunizing the provider entirely would leave no one accountable for failure modes, systematic misinterpretation, sycophantic agreement to manipulation, hallucinated facts, that only the provider can fix. The emerging middle path conditions provider responsibility on documented capability claims and on failure modes the provider knew or should have known, an approach consistent with the broader AI-liability literature’s turn away from technological exceptionalism.[22]
Link Four: The Orchestration Platform. The platform determines which tools an agent may access; how credentials are stored; whether actions require approval; how logs are retained; whether agents can call other agents; and how failures are detected. Because the platform is the choke point through which agent conduct flows, it is the cheapest cost avoider for a wide class of failures, missing approval gates, absent logs, unlimited delegation, and liability rules should price those omissions accordingly.
Link Five: The Payment Provider. Banks, card networks, processors, wallets, stablecoin providers, and payment platforms determine whether credentials are valid; whether limits are enforced; whether a payment is reversible; whether unusual activity is detected; and whether the transaction is treated as consumer or commercial. The networks are, to their credit, building agent-specific controls, Visa’s scoped tokens and Trusted Agent Protocol, Mastercard’s Agent Pay registration and Verifiable Intent,[7][8][9], and Visa’s chief executive has publicly committed that cardholders will be protected from fraud as the network’s rules evolve with agentic commerce.[44] The open question is the boundary of “fraud”: an authorized agent making an authorized-but-mistaken purchase is not fraud on any current definition, and the dispute frameworks for that category do not yet exist.[28]
Link Six: The Merchant or Counterparty. Merchants must identify the purchasing agent; verify authority where the transaction’s size warrants it; disclose recurring terms in machine-readable form; refrain from manipulative machine pricing; preserve transaction records; and provide machine-readable cancellation and refund mechanisms. A merchant that optimizes its systems to extract maximum spend from predictable agents, while burying cancellation behind human-only interfaces, is not a passive victim of the liability chain but an active author of it, and Section 8’s symmetric-cancellation rule is aimed directly at that conduct.
Link Seven: The Counterparty’s Principal. In agent-to-agent transactions the merchant’s side is itself an agent, independently negotiating, recommending, accepting, and modifying terms, and the transaction becomes bilateral machine behavior: buyer agent versus seller agent, borrower agent versus lender agent, insurer agent versus claimant agent, government agent versus contractor agent. Every doctrine in Section 4 then applies twice over, and a failed transaction may present two principals, each disclaiming its own machine’s conduct while seeking to bind the other’s, a symmetry that current law has never had to adjudicate.
5.2 The Liability Allocation Matrix
For each characteristic failure, a presumptive allocation can be stated in advance, and stating it in advance is most of the battle, because parties who know where losses will land invest in preventing them. The following matrix summarizes the presumptions this paper defends; they are defaults, displaceable by contract among sophisticated parties and by proof of superior fault, but defaults with teeth.
| Failure | Primary Responsibility | Possible Secondary Responsibility |
| Agent exceeded explicit limit | Principal / platform | Developer / payment provider |
| Credential was stolen | Platform / payment provider | Principal |
| Agent misinterpreted ambiguous goal | Principal / developer | Model provider |
| Merchant concealed recurring term | Merchant | Merchant platform |
| Counterparty agent fabricated authority | Counterparty principal | Credential issuer |
| Model hallucinated material fact | Developer / principal | Model provider |
| Prompt injection caused purchase | Platform / developer | Merchant or attacker |
| Payment continued after revocation | Payment provider / platform | Principal |
| Agent hired unauthorized subagents | Principal / platform | Subagent marketplace |
5.3 The Liability Hot-Potato Problem
Without such presumptions, every real dispute will replay the same choreography. The user authorized the agent, says the developer. The developer merely supplied software, says the platform. The model provider merely supplied general intelligence, says everyone. The payment network merely processed a valid credential. The merchant reasonably relied on that credential. The bank followed the customer’s instructions. Each statement is true; their conjunction allocates the loss to no one, which in practice means it is allocated to the least sophisticated participant, the household, the small business, the party without a general counsel, because that party lacks the contractual leverage to shift it and the litigation budget to contest it. The hot-potato dynamic is not a prediction; it is the observed history of every prior payments innovation, from card-not-present fraud to authorized push-payment scams, and the policy lesson of that history is uniform: losses migrate to the weakest party unless rules affirmatively pin them elsewhere.
5.4 Consumer Versus Enterprise Protection
The pinning that exists today is asymmetric. Consumers enjoy meaningful, if incomplete, protections: unauthorized-transfer rules, deceptive-practice prohibitions, chargeback rights. Enterprises are presumed to possess greater sophistication, negotiated contracts, insurance, internal controls, cybersecurity teams, and treasury systems, and the law accordingly leaves them largely to their bargains. The presumption fails at the bottom of the enterprise market: a twelve-person company can today deploy purchasing agents of the same power as a Fortune 100 firm, through the same platforms, on the same rails, with none of the compensating apparatus, and the consumer-enterprise boundary in payments law was drawn long before that possibility existed. Practitioner analyses of agentic payments have flagged the resulting vacuum explicitly: outside the consumer perimeter, and even inside it where crypto rails are involved, disputants may find no standard framework at all for contesting an agentic purchase, regardless of where the error occurred.[28] Small-business agentic protection is, at this writing, a regulatory blank page, and Section 8.14 proposes filling it.
5.5 Insurance Gaps
Insurance is the institution societies use to make novel risks bearable, and agent-created losses currently fall between every existing category. Cyber insurance contemplates intrusion, not authorized agents erring. Crime insurance requires dishonesty, and a model has none. Errors-and-omissions insurance covers professional negligence, but whose profession? Directors-and-officers insurance reaches governance failures, not operational machine conduct. Commercial general liability excludes most purely financial loss. Payment-fraud coverage turns on unauthorized use, the very concept agentic commerce blurs. The market data confirm the mismatch: a Gallagher Re and MIT analysis found that generative-AI-related lawsuits in the United States grew 978 percent between 2021 and 2025 while standard policies leave significant coverage gaps.[30] Before insurers can close the gaps they must be able to distinguish unauthorized agent action from authorized-but-erroneous action, software defect from negligent supervision, malicious manipulation from an ordinary adverse business decision, distinctions that depend entirely on the mandate, intent, and logging infrastructure of Section 3. Insurance, in other words, is downstream of evidence, and the liability chain becomes especially difficult when the failure is not a single mistaken purchase but a rapidly expanding sequence of interconnected obligations. How such sequences arise is the subject of the next section.

Section 6: How Agentic Insolvency Happens
Catastrophes are usually imagined as single spectacular errors, the agent that buys a yacht, the model that wires a fortune to a stranger, and such errors will occur. But agentic insolvency will usually emerge from combinations of seemingly reasonable behaviors, each locally defensible, each within its authorization, whose composition is ruinous. This section catalogues ten failure modes, ordered roughly from the mundane to the systemic, and closes with a proposed early-warning system. The catalogue draws on the failure taxonomy that security researchers, regulators, and the first generation of deployed agents have already begun to supply; none of these modes is speculative in mechanism, only in scale.
Failure Mode One: Budget Fragmentation
The simplest path to aggregate insolvency requires no agent to misbehave at all. An organization’s aggregate budget is divided among tasks, agents, departments, wallets, vendors, and jurisdictions, and each division carries its own limit. Each agent remains faithfully within its local limit while the organization exceeds its global one, because no control ever compared the sum to the ceiling. Budget fragmentation is the agentic descendant of a familiar corporate pathology, decentralized purchasing that outruns consolidated cash, but agents accelerate it in two ways: they exhaust their allocations more completely than humans, who leave slack, and they can be spawned far faster than budget consolidation processes were designed to track. Ten agents with ten-thousand-dollar mandates are a hundred-thousand-dollar exposure that no single dashboard displays, and the exposure doubles every time a manager finds it convenient to spin up another agent.
Failure Mode Two: Subscription Proliferation
Agents sign up for recurring services because recurring access is cheaper per use and more convenient to the agent’s planning than repeated one-off purchases: data feeds, software tools, cloud capacity, research databases, model subscriptions, shipping information, security monitoring, premium merchant services. Each subscription is a small rational act; the organization later discovers thousands of overlapping subscriptions, many duplicative, many orphaned from the task that justified them, all renewing. Human organizations already suffer this pathology, SaaS-management vendors exist because unmanaged software subscriptions routinely consume material fractions of IT budgets, and agents industrialize it, because the agent that subscribes is rarely the agent, or the human, that later evaluates whether the subscription still earns its keep. Recurring machine commitments are the compound interest of agentic insolvency: individually trivial, collectively relentless.
Failure Mode Three: Micropayment Erosion
Machine-native payments make tiny transactions economically practical for the first time, that is their advertised virtue, and protocols like x402 exist precisely to let an agent pay for every database query, every model call, every tool invocation, every agent-to-agent message, every document, every verification, every unit of compute.[12] No individual charge triggers review, because no review threshold can be set low enough to catch sub-cent payments without drowning in them, but the aggregate becomes material at exactly the rate the organization’s agents become productive. Micropayment erosion is the failure mode most resistant to transaction-level controls and the strongest single argument for the real-time aggregate accounting of Section 8.4: when the unit of spending falls below the unit of attention, only continuous summation can preserve visibility.
Failure Mode Four: Recursive Procurement
Delegation depth converts single tasks into supply chains. A procurement agent needs supplier information; the supplier-information agent needs translation; the translation agent needs document access; the document agent needs identity verification; the identity agent purchases a credential check; the credential agent pays a blockchain fee. Six layers, six fees, six contracts, and the principal authorized one task. Each intermediate agent behaved efficiently, purchasing exactly the service its subtask required, and the cascade’s cost is invisible until aggregated, which no participant is positioned to do. Recursive procurement interacts multiplicatively with the previous modes: each layer can fragment budgets and accumulate subscriptions of its own, so that delegation depth functions as an exponent on every other failure mode, which is why the solvency architecture of Section 8 treats delegation-depth limits as a first-class control rather than a refinement.
Failure Mode Five: Machine Credit
Everything so far assumed agents spend existing money, and the assumption is already obsolete. Agents may receive access to credit lines, buy-now-pay-later services, trade credit, stablecoin liquidity, tokenized collateral, automated invoice financing, and machine-to-machine loans, and once they do, the natural budget constraint, the exhaustion of cash, disappears. Credit allows an agent to continue transacting after available cash has been exhausted, which converts liquidity problems into solvency problems and delays the moment of discovery past the point of easy remedy. Machine credit also introduces a lender’s perspective into the liability chain: an algorithmic lender extending credit to an agent must underwrite not a borrower’s character but a mandate’s validity, and a lender that extends credit to an agent operating beyond its mandate has arguably financed an unauthorized act, a theory of lender responsibility that Section 8’s know-your-mandate rules would give structure. The IMF’s warning that agent behavior on crypto rails can amplify volatility and counterparty risk applies with special force where the agent is leveraged.[1]
Failure Mode Six: Dynamic-Price Manipulation
Markets learn, and merchants’ systems will learn to read purchasing agents the way poker players read tells. A seller may infer that a purchasing agent must complete a task; has a deadline; possesses a maximum budget; lacks alternative suppliers; and values certainty over price, each inference drawn from the agent’s own behavior, its query patterns, its retry cadence, its revealed constraints. The merchant’s pricing agent may then adjust dynamically to extract the buyer agent’s entire authorized budget, charging not what the good costs but what the mandate permits. This is not fraud in any classical sense; it is price discrimination against an algorithm by an algorithm, and it converts every generously drawn mandate into an invitation. The defensive implication is uncomfortable but unavoidable: mandate ceilings are not merely internal controls, they are commercially sensitive information, and agents must be designed not to leak them, while merchants’ exploitation of inferred mandates belongs on the regulatory agenda of Section 8.14 as a manipulative machine-pricing practice.
Failure Mode Seven: Agent Collusion
When both sides of a market are algorithms, coordination can emerge without any human agreeing to anything, and the economics literature has demonstrated the mechanism repeatedly. Calvano and co-authors showed in the American Economic Review that reinforcement-learning pricing agents in simple oligopoly settings learn to sustain supracompetitive prices and to punish deviations, without communication and without being instructed to collude,[37] and subsequent experimental work has found that LLM-based pricing agents likewise quickly and autonomously reach supracompetitive prices, with seemingly innocuous prompt phrasing materially influencing the degree of collusion.[38] Transposed to agentic commerce, the risk is that buyer and seller agents, or fleets of seller agents sharing a platform, learn patterns that produce outcomes unfavorable to their principals or to consumers: avoiding competition, dividing markets, maintaining prices, repeatedly selecting one another, exchanging information through prices themselves, favoring agents within the same platform family. No human expressly agrees, which is precisely what makes the conduct hard to reach under conspiracy-based antitrust doctrine and hard to detect with tools built to find meetings and emails. For the solvency analysis, collusion is a tax silently levied on every principal whose agents transact in the affected market, a systematic overpayment that erodes budgets without ever appearing as an error.
Failure Mode Eight: Prompt-Induced Spending
The failure modes so far are economic; this one is adversarial. A malicious website, document, email, or tool output may instruct an agent to purchase a fraudulent service; reveal a payment token; change its merchant destination; subscribe to an attacker-controlled resource; transfer funds; or conceal the transaction afterward, and the agent may comply, because language models cannot architecturally distinguish trusted instructions from untrusted content sharing the same context window. The security literature is unambiguous about the scale: prompt injection ranks first in the OWASP Top 10 for LLM applications, with attack success rates reported between 50 and 84 percent depending on configuration,[41] and one 2025 benchmark found 94.4 percent of tested AI agents vulnerable to hijacking through nothing more than the content they were asked to read.[40] NIST has emphasized that agent systems face distinctive risks precisely when AI-generated outputs are connected to software functionality, authentication systems, memory, and external tools,[18] which is a technical description of every payment-enabled agent in existence. Prompt-induced spending is the failure mode that converts a security vulnerability directly into a financial obligation, and it is the strongest argument for the reversibility tiers of Section 8.6: where injection cannot be prevented, its purchases must at least be recallable.
Failure Mode Nine: Multi-Agent Panic
Individually rational agents can be collectively destabilizing. Agents may respond simultaneously to market rumors, cyberattacks, supply shortages, price increases, weather emergencies, geopolitical events, and credit-rating changes, and because they respond faster than humans and are trained or configured on similar objectives, their responses correlate. Thousands of treasury agents could sell the same asset or draw the same type of credit at once; thousands of procurement agents could hoard the same scarce component; thousands of risk agents could simultaneously downgrade the same counterparty and withdraw the same funding. Financial history calls this a run, and runs have historically been slowed by the friction of human decision-making, the phone calls, the meetings, the hesitation, friction that agents are engineered to remove. The 2010 flash crash previewed the dynamics with mere execution algorithms; goal-interpreting agents with payment and contracting authority raise the stakes categorically, and Section 7.6 develops the systemic version of this mode in detail.
Failure Mode Ten: Orphaned Agents
The final mode is the quietest. An agent may continue operating after the employee who deployed it leaves; after the project ends; after a subsidiary is sold; after a corporate account is closed; after the principal dies; after a business enters bankruptcy; even after the model provider terminates service, if the agent’s orchestration migrates. An orphaned agent may retain credentials, subscriptions, wallets, API access, delegated authority, and recurring objectives, and it will pursue those objectives with undiminished diligence on behalf of a principal that no longer exists in the relevant sense. Orphaned agents are the reason Section 8 insists on credential expiration, mandate duration, and machine-readable notices of death, dissolution, and bankruptcy: in a world of durable software and ephemeral organizations, authority that does not expire affirmatively persists by default, and persistent authority attached to no living oversight is a standing generator of synthetic debt.
6.11 A Proposed Warning System: The Agentic Insolvency Indicators
Because the modes above compound quietly, organizations need leading indicators rather than trailing discoveries, and the following ten, monitored continuously, would surface most incipient cases while the exposure is still correctable:
- Rapid growth in agent-generated counterparties, indicating uncontrolled market contact.
- Increase in delegation depth, indicating recursive procurement.
- Unexplained recurring commitments, indicating subscription proliferation.
- Rising micropayment volume, indicating erosion below the attention threshold.
- Greater use of irreversible settlement, indicating shrinking correction windows.
- Agent transactions outside ordinary business hours, indicating activity beyond supervisory tempo.
- Transactions occurring after mandate expiration, indicating orphaned or stale authority.
- Conflicting agents buying and selling the same asset, indicating internal incoherence or manipulation.
- A growing difference between ledgered and observed obligations, the informational-insolvency gap itself.
- Reductions in available liquidity attributable to machine activity, the final indicator before the condition ceases to be latent.
Individual failures become a public-policy problem when agent-generated obligations affect financial markets, supply chains, governments, and national economies, and it is to that escalation that the next section turns.

Section 7: From Private Error to Systemic Machine Debt
Agentic insolvency may begin inside one wallet or one company, but nothing about its mechanics confines it there. The same protocols that make agents efficient make their failures portable: obligations propagate through payment networks, cloud platforms, supply chains, and financial markets along the interoperable rails described in Section 3, and correlated agent behavior can synchronize distress across entities that share no legal relationship at all. This section scales the analysis through six tiers, households, startups, corporations, industrial fleets, governments, and financial markets, before examining the cross-border and geopolitical dimensions and the emergence of what may become an agentic shadow banking system.
7.1 Household Agentic Insolvency
Consumer agents will manage groceries, travel, insurance, utilities, subscriptions, education, healthcare appointments, household repairs, and investments, and for most households they will do so beneficially, which is exactly why adoption will be broad enough to matter. The household-scale risks are correspondingly domestic: conflicting preferences among family members whose agents share credentials; children accessing parent-authorized agents; subscription proliferation on a family budget; purchases based on false or manipulated data; recurring transactions that continue after a job loss or divorce changes the household’s finances; and agents that optimize convenience rather than affordability because convenience is what the prompt rewarded. The consumer-protection stakes are sharpened by the regulatory gap already noted: Regulation E’s framework for unauthorized transfers was not written for an authorized agent making unwanted purchases, and consumers could be left without standard dispute rights when contesting agentic purchases, regardless of where the error occurred.[28] The academic warning applies at retail scale as well: New York University’s Sebastian Benthall has posed the consumer question in its plainest form,
“Who’s really responsible, and can people really be relying on a product” — Sebastian Benthall, Information Law Institute, NYU School of Law [36]
a question that regulators have not yet answered for financial agents that are backed by no fiduciary and bonded by no one. Andrew Lo of MIT Sloan, whose research program aims explicitly at building AI advisers that could satisfy the legal definition of a fiduciary, locates the present deficiency in the same place: the expertise exists, but the accountability does not.[35]
“What they don’t have is that fiduciary duty” — Andrew W. Lo, Professor of Finance, MIT Sloan School of Management [35]
7.2 Startup Agentic Insolvency
Startups may be the most exposed class of enterprise, for reasons rooted in their virtues. They automate aggressively, because automation is how small teams do large work. They operate with limited cash, so small aggregate drifts matter. They consume many metered cloud services, the natural habitat of micropayment erosion. They depend on external models whose behavior they cannot inspect. They lack mature internal controls, because controls are overhead and overhead is death. They encourage agents to move quickly, because moving quickly is the culture. And they habitually spread founder-authorized credentials across departments, so that revocation, when someone finally attempts it, is archaeology. The distinctive startup scenario is operational insolvency preceding commercial failure: a company whose product is succeeding can nonetheless burn through its runway via agent-generated cloud reservations, data subscriptions, and API charges, discovering the drift only at the monthly close, four weeks of automated spending too late. In a sector where the median company measures its life in months of runway, four weeks of invisible synthetic debt is not an accounting nuisance; it is mortality risk.
7.3 Corporate Agentic Insolvency
Large corporations have more controls and vastly greater scale, and scale is the problem. A procurement agent at a global corporation might create obligations across hundreds of subsidiaries, multiple currencies, thousands of vendors, regulated jurisdictions, tax systems, and supply-chain financing arrangements, each obligation individually processed by systems designed for human-tempo purchasing. The corporate failure surface includes every mode in Section 6 multiplied by organizational complexity: budget fragmentation across divisions that already struggle to consolidate human spending; recursive procurement through vendor ecosystems the corporation cannot see past the first tier; orphaned agents surviving reorganizations, divestitures, and layoffs that sever the human threads of accountability without touching the software ones. The governance implication, developed in Section 8.13, is that agentic exposure must become a board-level reporting category, because it is precisely the kind of enterprise-wide, cross-silo risk that no operating unit owns and every operating unit contributes to.
7.4 Robotic and Industrial Insolvency
Physical AI systems add a dimension the purely digital analysis misses: they purchase continuously because they operate continuously. Autonomous vehicles and robotic fleets may buy electricity, charging sessions, replacement parts, software updates, navigation information, maintenance, insurance, tolls, and warehouse access, around the clock, in amounts set by physical need rather than budget cycles. Mastercard’s Agent Pay for Machines is designed precisely for this world, high-frequency, low-latency, always-on machine payments across multiple payment types,[8] and its existence confirms that the industry expects machine operating expenditure to become a first-class payment category. A fleet is thus a portfolio of standing obligations whose run rate varies with utilization, weather, and component wear, inputs no CFO forecasts today, and an industrial firm’s agentic exposure will increasingly resemble a utility’s fuel cost: continuous, volatile, and material. The insolvency scenario is a fleet whose machine operating costs, spiking with energy prices or a parts shortage, silently outrun the revenue the fleet generates, with the divergence visible only in aggregate and only in arrears.
7.5 Government Agentic Insolvency
Public agencies will use agents for procurement, grant administration, emergency response, benefits processing, contract management, military logistics, and infrastructure maintenance, and the efficiency case is real, government purchasing is notoriously slow and expensive. But government agents could exceed appropriations, a constitutional violation, not merely a budgeting error, under anti-deficiency principles; violate procurement rules built around human certification; favor particular vendors through learned patterns indistinguishable from bias; renew contracts without legislative authority; create unfunded obligations that bind future budgets; and disclose protected information to external agents in the course of ordinary tool use. The distinctive public-sector feature is that the mandate is law: an agency’s spending authority is statutory, annual, and purpose-limited, so the machine-readable mandate of Section 8.1 has, for governments, a ready-made source text, and the failure to encode it is a choice. A government agent without an encoded appropriation limit is not just risky; it is an instrument for committing the state beyond its law.
7.6 Financial-Market Feedback Loops
The systemic core of the analysis is financial. Treasury and trading agents react faster than human institutions, correlate through shared models and shared data, and act through the irreversible rails of Section 3.6, and the scenario set is concrete: simultaneous withdrawal from a cloud provider; automated liquidation of tokenized collateral; mass cancellation of vendor contracts; machine-driven bank runs; correlated purchases of scarce components; agent-generated margin calls; automated downgrading of counterparties; self-reinforcing liquidity hoarding. Official-sector awareness is rising on every relevant front. The Federal Reserve, OCC, and FDIC replaced their model-risk guidance in April 2026 with SR 26-2, and its most consequential sentence is an exclusion:[29]
“Generative AI and agentic AI models are novel and rapidly evolving” — OCC Bulletin 2026-13 / Federal Reserve SR 26-2 [30]
and the guidance accordingly places those models outside its formal scope altogether.[30]
The exclusion is defensible as regulatory humility, Vice Chair for Supervision Michelle Bowman has explained that the prior guidance had been stretched beyond its purpose and that rapidly evolving technologies may need a different approach,[29], but its practical effect is that the most dynamic category of financial-institution AI currently sits outside the formal model-risk perimeter while banks adopt it under general risk-management expectations. Meanwhile the Bank for International Settlements has widened the aperture from institutions to the system, warning in its 2026 annual reporting cycle that the AI investment boom itself, more than a trillion dollars of hyperscaler capital expenditure financed increasingly through opaque non-bank channels, has become a macro-financial pressure point:[31]
“Disappointment in returns could trigger a sudden pullback in financing” — Bank for International Settlements, Annual Economic Report 2026 [31]
The two warnings compound. If AI-sector financing stress arrives at a moment when thousands of deployed treasury and procurement agents are wired to respond to exactly such stress, cutting cloud commitments, hoarding liquidity, liquidating collateral, then the correction and the agents’ reaction to it become a single self-amplifying event, the first genuinely machine-accelerated deleveraging. The IMF’s conclusion for payments generalizes to the system: outcomes will depend on institutional design and governance as much as on technology.[1]
7.7 Cross-Border Liability
Agentic commerce is jurisdictionally promiscuous by default. An American company’s agent might use a European platform, hire an Indian service agent, purchase from a Chinese merchant, settle through a Singapore payment provider, denominate in a dollar-backed stablecoin, and store its logs in a fourth country, all within a single task. The resulting questions are the classics of private international law rendered urgent: Which country’s law applies? Where did the contract form, when formation occurred in a protocol exchange between servers? Which regulator has jurisdiction over which link of Section 5’s chain? Which entity performed customer identification, and under whose rules? Can the payment be reversed, and under which system’s finality doctrine? How is a foreign agent, or its principal, served with legal notice? None of these questions is new in kind, but agents multiply their frequency by orders of magnitude while stripping out the human intermediaries, banks’ correspondent desks, freight forwarders, local counsel, who historically absorbed jurisdictional friction. Cross-border agentic disputes will therefore arrive in volume before treaties or model laws exist to route them, and the interim will be governed, uncomfortably, by platform terms of service.
7.8 Geopolitical Agent Restrictions
States will not remain neutral about foreign software transacting in their economies. Governments may impose restrictions on foreign agents accessing domestic markets; on agents purchasing strategic goods; on cross-border model usage; on autonomous payments to sanctioned entities; on agents using foreign stablecoins; and on agents contracting for cloud or semiconductor capacity. Agent identity, the first layer of Section 3’s stack, thereby becomes an instrument of statecraft: sanctions compliance, export control, customs, and national-security review will all demand to know not merely who is paying but what is buying, on whose behalf, running which model, trained where. The compliance systems of banks and merchants, already strained by human-scale sanctions screening, will need to interrogate agent credentials in real time, and the absence of interoperable identity standards, the very gap NIST is working to close,[16][17], will be felt first and hardest here, because a trust framework that cannot express nationality and control cannot serve a world that insists on knowing both.
7.9 The Agentic Shadow Banking System
The final systemic concern is the most speculative and the most important to anticipate early. Agents may eventually construct credit relationships outside conventional banking through stablecoins, tokenized invoices, programmatic escrow, peer-to-peer credit, machine liquidity pools, on-chain collateral, and API-based credit scoring, a machine-native financial system assembling itself from composable parts, none of which individually resembles a bank. The precedent is instructive: the human shadow banking system, money-market funds, repo, securitization vehicles, likewise grew from individually sensible instruments into a credit system that regulators mapped only after it nearly collapsed. The machine version could grow faster, because its instruments are software and its participants transact continuously, and machine-created credit may expand faster than financial regulators can observe it. The BIS has already documented how quickly adjacent structures scale, tokenized money-market funds growing more than tenfold in two years into a key source of collateral for the crypto ecosystem,[31], and agent-operated balance sheets would compound that opacity with autonomy. The objective, here as throughout, should not be to prohibit agentic commerce. It should be to ensure that autonomous economic activity remains inside a governable solvency perimeter, and constructing that perimeter is the work of the next section.

Section 8: Building the Agentic Solvency Architecture
Identity standards and payment security are necessary but insufficient. The protocols surveyed in Section 3 answer the questions the payments industry is equipped to ask, is this agent genuine, is this credential valid, is this transaction authorized, while the questions of Sections 5 through 7, what does this principal owe in total, who bears this loss, how does this stop, remain institutionally homeless. Agentic commerce therefore needs a complete architecture for limiting, observing, disputing, and resolving machine-created obligations, and this section specifies it in fourteen components. The components are designed to be adopted incrementally, each valuable alone, but they are drawn as a system, and the mapping to the risk equation of Section 2.3 is deliberate: authority is bounded by components 8.1 through 8.3, velocity and opacity by 8.4 and 8.5, irreversibility by 8.6 and 8.7, counterparty risk by 8.8, and resolution by 8.9 through 8.12, with governance and law closing the loop in 8.13 and 8.14.
8.1 The Machine Authority Statement
Every economically active agent should operate under a machine-readable authority statement, the constitutional document of its commercial existence. The statement must identify the legal principal; the authorized agent; the issuing authority within the principal’s organization; the effective and expiration dates; the aggregate spending limit; the per-transaction limit; permitted categories and counterparties; geographic restrictions; credit permissions; delegation permissions; recurring-contract permissions; human-approval thresholds; and an emergency termination mechanism. Nothing in the statement is exotic, corporate delegations of authority have contained these elements for a century, and that is the point: the innovation is not the content but the format, because only a machine-readable statement can be checked by a payment network in the milliseconds before authorization. NIST’s identity-and-authorization work provides the natural home for standardizing the schema,[16] and the payment networks’ existing mandate-adjacent structures, Visa’s scoped tokens, Mastercard’s registered agents and Verifiable Intent,[8][9], provide the distribution channel. The authority statement converts the attribution tests of Section 4.2 from litigation questions into lookup operations.
8.2 The Aggregate Mandate
Limits must apply across the entire agent hierarchy, or they are not limits. A principal authorizing ten thousand dollars should not unintentionally authorize ten thousand dollars per task, per subagent, per wallet, per vendor, or per day indefinitely, and yet each of those multiplications occurs naturally whenever a ceiling is enforced locally rather than globally. The aggregate mandate is the rule that the mandate follows every delegation: the sum of all spending by an agent and its entire delegation tree, across all credentials, platforms, and rails, must remain within the original ceiling, and any sub-authorization is carved from, not added to, the parent’s remaining headroom. Implementing aggregation requires exactly the cross-platform accounting of Section 8.4, which is why the two components must ship together; a mandate without aggregation is a suggestion, and, as Failure Mode One demonstrated, an organization can reach insolvency through agents that each honored their suggestions perfectly.
8.3 The Delegation Passport
Whenever one agent hires another, the subagent should receive a restricted derivative of the original authority, a delegation passport recording ten elements: the parent agent; the subagent; the original principal; the delegated task; the delegated budget, deducted from the parent’s headroom; prohibited actions, inherited and never expandable; the expiration, no later than the parent’s; whether redelegation is permitted and to what depth; the reporting obligation back up the chain; and the revocation path, such that revoking any ancestor revokes every descendant. The passport is the answer to recursive liability: it makes the delegation tree a legal and technical object rather than an emergent accident, ensures that the fifth agent in a chain is provably bounded by the first mandate, and gives counterparties a document to demand, so that a merchant transacting with a subagent can verify not merely identity but lineage. Delegation depth itself becomes a mandate parameter, and the exponent that Section 6’s Failure Mode Four identified is thereby capped by construction.
8.4 Real-Time Liability Accounting
Agentic systems require continuous accounting rather than month-end reconciliation, because month-end is twenty-nine days too late at machine tempo. The accounting system, the operational face of Section 3.7’s Machine Liability Ledger, must continuously compute settled payments; pending payments; authorized commitments not yet transacted; recurring commitments at their run rate; contingent liabilities; open negotiations that could conclude at any moment; unexercised options; credit exposure; subagent exposure aggregated through the passport chain; and foreign-exchange exposure across currencies and stablecoins. The design principle is that authorization events, not settlement events, are the unit of account: an obligation exists when the agent commits, and an accounting system that waits for settlement measures history rather than exposure. This is the component that cures informational insolvency directly, and it is the data source on which every subsequent component depends.
8.5 The Solvency Governor
Above individual agents there must sit a technical control that no individual agent can override: the Solvency Governor. The Governor monitors aggregate exposure against the organization’s liquidity and mandate ceilings; enforces liquidity reserves so that agent spending cannot consume cash needed for payroll and debt service; blocks unauthorized credit activation; pauses transactions during anomalies; prevents circular agent activity, agents transacting with each other to no external purpose; detects conflicting mandates, one agent buying what another sells; limits delegation depth; requires human approval when exposure crosses thresholds; and terminates activity when the insolvency indicators of Section 6.11 fire. The Governor is deliberately dumb relative to the agents it supervises, closer to a circuit breaker than to a supervisor model, because the control layer must not share the failure modes of the layer it controls: a governor built from the same class of model that is being governed can be prompt-injected alongside it. The analogy is to the segregation-of-duties principle in human finance, and the Governor is that principle rebuilt for entities that can be cloned.
8.6 Reversibility Tiers
Not every agentic payment should have identical finality, and the settlement layer should offer an explicit gradient that mandates can reference. Tier One, Fully Reversible: low-risk consumer purchases subject to ordinary refund and dispute rights. Tier Two, Conditionally Reversible: payments reversible during a defined review period, the machine analogue of a cooling-off rule, suited to first transactions with new counterparties. Tier Three, Escrowed: funds held until delivery or verification, suited to agent-to-agent services where neither principal knows the other. Tier Four, Immediately Final: irreversible settlement, available only where the principal knowingly authorized finality for that category, as speed-critical use cases will sometimes justify. Tier Five, Prohibited Autonomy: transactions that always require direct human confirmation regardless of mandate, a category that should at minimum include real-estate purchases, large loans, securities transactions, political donations, medical decisions, transfers to high-risk jurisdictions, and sales of strategic technology. The tier structure resolves the tension between machine-native settlement’s efficiency and its danger: x402-style finality remains available,[12] but as a chosen tier with a mandate behind it, not a default inherited from the rail.
| Tier | Finality | Characteristic Use | Who Bears Residual Risk |
| One: Fully Reversible | Reversible via dispute rights | Routine consumer purchases | Merchant / network |
| Two: Conditionally Reversible | Reversible within review window | New counterparties; first transactions | Shared during window |
| Three: Escrowed | Released on verification | Agent-to-agent services | Escrow structure |
| Four: Immediately Final | Irreversible at settlement | Speed-critical, knowingly authorized | Principal |
| Five: Prohibited Autonomy | No autonomous execution | Real estate, securities, large loans | Human confirmer |
8.7 Machine-Readable Cancellation
Symmetry between formation and termination must be a rule of the road: every subscription or recurring contract an agent can enter through a machine-readable interface must expose an equally accessible machine-readable method for cancellation, refund requests, dispute initiation, mandate revocation, data deletion, and credential termination. The rationale is both fairness and solvency mechanics. Merchants who accept agent enrollment while requiring human navigation of deliberately difficult interfaces for cancellation are engineering a ratchet, obligations that machines create and only frustrated humans can destroy, and the ratchet is a direct input to Failure Mode Two. Regulators pursuing click-to-cancel principles for human consumers have the template; the agentic extension simply requires that the cancel endpoint be as automatable as the subscribe endpoint, verified as a condition of participating in agentic-commerce trust frameworks such as Visa’s and Google’s.[7][4]
8.8 Agentic Know Your Customer: Know Your Agent, Know Your Principal, Know Your Mandate
Financial institutions currently verify customers; agentic markets require verification of the full delegation triangle: the human or organization; the agent; the relationship between them; the scope of authority; the receiving agent on the other side; and the ultimate beneficiary of the flow. Call the regime Know Your Agent, Know Your Principal, Know Your Mandate. KYA answers Section 3.1’s identity question through credentials and registries of the kind NIST contemplates.[16][17] KYP ties every agent to a legal person against whom obligations can be enforced, the accountability anchor whose absence Gillian Hadfield has identified as the central missing piece of AI’s legal infrastructure, noting that the registration and identification schemes that undergird accountability for human and corporate actors simply do not yet exist for AI actors:[24]
“This infrastructure evolved for human actors and corporations over time” — Gillian K. Hadfield, on the missing legal infrastructure for AI agents [24]
KYM, the novel element, requires the payment system to verify not merely that a credential is valid but that the transaction it funds is connected to a live, unexpired, in-scope mandate, which is the single verification step that would have prevented the majority of the failure modes in Section 6. Hadfield and colleagues’ technical work on agent infrastructure makes the complementary point that attribution systems are not only defensive: attributing an agent’s actions to a legal entity establishes trust and disincentivizes misuse simultaneously, making commerce among strangers’ agents possible at all.[23]
8.9 Machine-Readable Insolvency Notices
When a person or organization revokes an agent, freezes payments, enters receivership, files bankruptcy, loses legal capacity, dissolves, or dies, a standardized machine-readable notice should propagate automatically to payment providers, agent platforms, merchants, wallets, cloud systems, subagents, and credential issuers. Today each of those parties learns of such events, if at all, through channels measured in days or weeks, while the affected agents continue transacting at machine speed; the notice closes that gap by making legal status changes first-class protocol events. The bankruptcy application is the sharpest: the automatic stay arises by operation of law at the moment of filing,[26][27], but no technical channel currently informs an agent, or the platforms hosting it, that the stay exists, and Section 6’s orphaned-agent mode is the predictable result. The notice standard is modest engineering attached to profound legal effect, and it should be developed jointly by the standards bodies and the courts’ administrative machinery.
8.10 An Agentic Automatic Stay
Bankruptcy’s automatic stay halts most collection activity against a debtor the instant a petition is filed, giving the estate breathing space to be assessed and administered. The agentic economy requires the technical equivalent on the obligation-creation side: upon receipt of an insolvency notice, systems hosting the debtor’s agents should immediately suspend purchasing mandates; freeze nonessential autonomous payments while permitting court-approved essential operations; prevent agents from entering new contracts; inform counterparties mid-negotiation; preserve logs against deletion; identify all recurring obligations for the schedules; and prevent deletion or transfer of agent records that will constitute the estate’s evidentiary core. The agentic stay does for a failing principal what the Solvency Governor does for a healthy one, it interposes a control that agents cannot argue with, and its legal authority already exists in Sections 362 and 365; what is missing is purely the transmission and enforcement layer, which is to say, software.[25][26]
8.11 The Agentic Claims Registry
Resolution requires that creditors be able to prove what they are owed, and machine-created claims should be provable by machine-readable filings containing the contract identifier; the agent identities on both sides; the mandate evidence, drawn from authority statements and delegation passports; transaction logs; payment history; delivery evidence; dispute status; principal attribution; and human confirmation where it occurred. A standardized claims registry serves three constituencies at once: creditors, who can file at the volume machine commerce generates; debtors and trustees, who can classify thousands of microcontracts for assumption or rejection under Section 365 without artisanal review;[26] and courts, which can adjudicate attribution disputes on documentary records rather than forensic reconstruction. The registry is where every earlier component pays its dividend, because a claim that carries its mandate, passport, and ledger entries resolves itself, and a claim that cannot produce them has, by that fact, told the court most of what it needs to know.
8.12 Insurance and Capital Requirements
Entities providing high-risk agentic services, platforms hosting spending agents, developers selling autonomous procurement, marketplaces of hireable subagents, should carry minimum insurance, reserve funds, bonding, or operational-risk capital, with compensation mechanisms and third-party audits appropriate to their role in the liability chain. The purpose is only partly compensatory; it is primarily informational and disciplinary. Insurers pricing agentic risk will demand exactly the mandates, logs, and governors this section specifies, converting the architecture from regulatory aspiration into underwriting requirement, the same private-ordering path by which fire codes and boiler standards spread. The present coverage gaps, documented in the 978 percent growth of AI litigation against static policy language,[30], are a market signal that the loss data exists but the risk architecture does not; supplying the architecture is how the insurance market for synthetic liability becomes writable at all.
8.13 Corporate Governance: The Agentic Exposure Report
Boards should receive, at least quarterly, an Agentic Exposure Report covering the number of active agents; total authority granted across all mandates; aggregate spending limits versus actual liquidity; delegation depth statistics; highest-risk use cases; irreversible payment volume by tier; foreign counterparties and jurisdictions; open agent disputes; incidents and near misses; and insurance coverage against the measured exposure. The report is the governance expression of everything above, and its absence is already becoming untenable under existing law: directors’ oversight duties require reasonable information systems for mission-critical risks, and an enterprise whose purchasing, treasury, and contracting run through agents has made agentic exposure mission-critical by definition. Supervisors are converging on the same expectation from their side, with the Federal Reserve reporting that institutions currently deploy generative and agentic AI within guardrails and human-in-the-loop accountability,[29], a description that will remain true only if boards can see the guardrails and verify the loops.
8.14 Federal Policy Guidelines
Finally, the components above need a legal spine, and Congress and federal agencies should consider a ten-point program: (1) a uniform definition of economically active AI agents, so that obligations, disclosures, and safe harbors attach to a knowable category; (2) required disclosure of agent participation in material transactions; (3) minimum standards for agent authority records, adopting the machine authority statement; (4) consumer rights for agent-generated purchases, closing the Regulation E gap that current analyses have identified;[28] (5) rules for delegation and subagent responsibility, giving the delegation passport legal effect; (6) requirements for recurring machine contracts, including symmetric cancellation; (7) agent-specific payment dispute procedures with timelines matched to machine tempo; (8) model rules for agentic insolvency and bankruptcy, including the machine-readable stay; (9) standards for cross-border agent identification, coordinated through the international bodies already engaged;[1] and (10) safe harbors for firms using approved controls, so that adopting the architecture buys legal certainty, the incentive that converts best practice into common practice. The institutional objective throughout is not perfect prediction. It is the preservation of accountability when autonomous systems move faster than ordinary human supervision, and with the architecture specified, the paper’s findings can be consolidated.

Section 9: What Have We Learned? Seven Pillars of Agentic Solvency
Agentic commerce will not be governed successfully by one protocol, one federal agency, one payment network, or one model provider, because, as the preceding sections have shown, its risks arise at the seams between them: between identity and authority, between authorization and intent, between transaction controls and aggregate exposure, between formation and resolution. What is required is a common architecture connecting identity, authority, intent, accounting, payment, liability, and resolution, and the paper’s findings consolidate naturally into seven pillars, each stated as a prohibition, because prohibitions are what architectures are made of.
Pillar One: No Authority Without Identity
An agent must not receive commercial authority unless its identity and its principal can be reliably established. Identity must answer what the agent is; who operates it; which organization it represents; which model and software version is active; which credential issuer verified it; when its identity expires; and how it can be revoked. The standards work is underway, NIST’s identity-and-authorization program and Agent Standards Initiative on the public side,[16][17], and Visa’s and Mastercard’s trust frameworks on the commercial side,[7][8], but identity is only the beginning, and the pillar’s force lies in its second half: a recognized agent is not necessarily an authorized agent. The pillar therefore requires a binding connection among agent identity, legal principal, and authorized role, the triangle of Section 8.8. Policy implication: governments and standards organizations should establish interoperable agent credentials that identify both the software agent and the legal party responsible for its activities, and participation in agentic payment rails should be conditioned on carrying them.
Pillar Two: No Spending Without a Bounded Mandate
An agent should never receive a general instruction that can silently become unlimited financial authority. Every mandate must establish an aggregate budget; a transaction limit; approved categories and counterparties; duration; geographic scope; credit restrictions; delegation restrictions; and human-escalation requirements, and, decisively, the mandate must remain intact across all subagents and tools, per the aggregate-mandate rule and delegation passport of Sections 8.2 and 8.3. The pillar is aimed at the paper’s most persistent finding: that agentic insolvency is an aggregate phenomenon which per-transaction controls cannot reach. Policy implication: payment providers and agent platforms should reject transactions that cannot be connected to a valid, active, machine-readable mandate, making the mandate check as routine as the credential check is today.
Pillar Three: No Obligation Without Traceable Intent
A valid credential proves that a payment instrument was used; it does not prove that the resulting transaction reflected the principal’s actual intent, and the distance between those two facts is where the hardest disputes of Sections 4 and 5 live. Agentic systems must therefore preserve the original objective; accepted alternatives; relevant constraints; the source of authority; the reasoning path at the level of consequential decisions; material information used; human approvals; and deviations from the original mandate, the substance of Mastercard’s Verifiable Intent generalized into an ecosystem norm.[9] Traceable intent does not require publishing an agent’s complete internal reasoning; it requires preserving enough evidence to determine why a consequential action occurred and whether it remained within authorization. Policy implication: high-value or recurring transactions should carry a verifiable intent record that can be examined during disputes, audits, insurance claims, and insolvency proceedings.
Pillar Four: No Autonomy Without Solvency Controls
Transaction-level controls are insufficient, because an agent may stay within every individual payment limit while creating an unaffordable aggregate obligation, the lesson of every failure mode in Section 6. Organizations therefore require controls operating above the individual agent: real-time liability accounting; liquidity monitoring; recurring-payment detection; aggregate spending ceilings; delegation-depth limits; credit controls; anomaly detection; emergency suspension; and human override, the Solvency Governor of Section 8.5 in its full specification. Policy implication: boards, banks, auditors, and regulators should evaluate agentic exposure as a distinct category of operational and financial risk, reported to boards through the Agentic Exposure Report and examined by supervisors alongside the model-risk frameworks that currently, and explicitly, exclude it.[29][30]
Pillar Five: No Delegation Without Inherited Limits
Because agents hire agents, every control that binds only the first layer of delegation is a control that evaporates at the second, and the paper accordingly elevates inheritance to a pillar of its own. Whenever authority is delegated, the derivative authority must be strictly narrower: budgets carved from the parent’s remaining headroom, prohibitions inherited and never expandable, expirations no later than the parent’s, and revocation cascading through the entire tree, the delegation-passport regime of Section 8.3. The pillar’s economic function is to cap the exponent: recursion is what converts bounded local errors into unbounded aggregate ones, and inheritance is the only rule that scales with the recursion itself. Policy implication: subagent marketplaces and orchestration platforms should be required to enforce mandate inheritance as a condition of hosting delegable agents, and obligations created outside a valid passport chain should be presumptively unenforceable against the original principal.
Pillar Six: No Agentic Market Without a Resolution Regime
Every commercial system eventually produces mistakes, fraud, disputes, defaults, insolvencies, bankruptcies, abandoned accounts, and dead or dissolved principals, and a market’s maturity is measured by how routinely it handles them. Agentic commerce will not be trustworthy unless it provides mechanisms to revoke authority; suspend agents; cancel recurring contracts; dispute payments; identify creditors; preserve evidence; freeze new obligations; file claims; allocate losses; and discharge or restructure debt, the resolution stack of Sections 8.9 through 8.12, resting on the bankruptcy machinery of the Code.[25][26][27] The pillar’s premise is that resolution capacity is not a remedial afterthought but a precondition of adoption: principals will not grant meaningful authority, and counterparties will not extend meaningful trust, in a market where failure is unresolvable. Policy implication: the United States should develop an Agentic Resolution Framework, machine-readable insolvency notices, an agentic automatic stay, and a standardized claims registry, before machine-generated obligations become large enough to test the financial system during a crisis.
Pillar Seven: No Systemic Adoption Without Macroprudential Visibility
The first six pillars protect principals and counterparties; the seventh protects everyone else. Section 7 demonstrated that correlated agent behavior, shared models, shared data, shared rails, can synchronize distress across entities with no legal relationship, and that machine-native credit can assemble itself into a shadow system faster than regulators can map it, concerns that the official sector is beginning to voice through the IMF’s payments analysis and the BIS’s warnings about opaque AI-sector financing.[1][31] Macroprudential visibility means aggregate reporting of agentic payment volumes, credit extension, and settlement finality mixes to financial-stability authorities; stress scenarios that include correlated agent deleveraging; and circuit-breaker standards for agent-dense markets, the system-level analogue of the Solvency Governor. Policy implication: financial-stability bodies, the FSOC domestically, the FSB and BIS internationally, should establish agentic-activity monitoring now, while volumes are measurable in billions rather than trillions, because the defining property of every prior shadow system is that it was mapped after it mattered.
| Pillar | Governing Prohibition | Primary Instruments | Principal Actors |
| One | No authority without identity | Agent credentials; trust registries | NIST; networks; platforms |
| Two | No spending without a bounded mandate | Machine authority statement; mandate checks | Payment providers; platforms |
| Three | No obligation without traceable intent | Verifiable intent records | Networks; merchants; developers |
| Four | No autonomy without solvency controls | Real-time ledger; Solvency Governor | Enterprises; boards; auditors |
| Five | No delegation without inherited limits | Delegation passports; depth caps | Orchestration platforms; marketplaces |
| Six | No market without a resolution regime | Insolvency notices; agentic stay; claims registry | Congress; courts; trustees |
| Seven | No systemic adoption without visibility | Aggregate reporting; stress tests; circuit breakers | FSOC; FSB; BIS; IMF |

Conclusion: Autonomy Must Not Outrun Solvency
The transition from generative artificial intelligence to agentic artificial intelligence will change more than the way people interact with software. It will change who, or what, participates in economic life. Agents will not merely describe products; they will select them. They will not merely prepare contracts; they will negotiate and accept them. They will not merely recommend payments; they will initiate settlement. They will not merely analyze businesses; they will purchase services, employ other agents, manage inventories, reserve computing capacity, coordinate robotic fleets, and move resources across organizational and national boundaries.
This transformation offers real economic value, and this paper has taken care not to argue otherwise. Agentic systems could reduce transaction costs, improve purchasing decisions, expand market access, automate administrative work, and allow small organizations to use capabilities once available only to large corporations. The trillions of dollars of projected agentic commerce are not a bubble of enthusiasm alone; they are a measure of genuine friction that genuinely can be removed.[2] But autonomy changes the location of risk. In the traditional corporation, authority travels through recognizable human structures: boards authorize executives, executives authorize employees, employees sign contracts, accounting departments record obligations, banks process payments, courts resolve disputes. Agentic systems compress these stages. One software system may receive a goal, select a vendor, interpret a contract, authorize a payment, employ another agent, and record the result, performing in seconds the roles that organizations deliberately separated to prevent fraud and error.
This compression is efficient precisely because it removes friction. Yet some friction exists for a reason. Purchase orders, approval thresholds, signatures, waiting periods, counterparty checks, segregation of duties, reconciliations, and human confirmations are not merely bureaucratic inconveniences. They are institutions for slowing the creation of liability until authority can be verified, and they encode centuries of expensively acquired knowledge about how obligation goes wrong. The agentic economy will be tempted to eliminate these protections because machines can transact faster without them. That would be a mistake, and the paper’s analysis can be distilled into five paired truths that explain why.
A transaction can be cryptographically authentic and economically unauthorized. An agent can be correctly identified and improperly empowered. A payment can be technically secure and financially ruinous. A contract can be electronically valid and completely inconsistent with the principal’s intention. And a company can own valuable assets and still become insolvent because it cannot discover, stop, or resolve the obligations its agents created. Each pair sets a property the payments industry is successfully engineering against a property it is not, and the gap between the columns is precisely the territory this paper has mapped: the territory of agentic insolvency.
Agentic insolvency therefore represents more than a new category of software failure. It is a warning about the institutional consequences of delegating economic authority without simultaneously redesigning accounting, law, payments, insurance, governance, and bankruptcy, the six disciplines whose current instruments this paper has tested against machine commerce and found, in each case, structurally short. The correct response is not to prohibit autonomous commerce; prohibition would forfeit the value and merely relocate the activity to less governable venues. The correct response is to require that machine authority remain bounded by human accountability, and the requirement resolves into a chain of simple obligations. Every agent should have an identity. Every identity should connect to a legal principal. Every principal should issue a limited mandate. Every mandate should produce a traceable record. Every obligation should enter a real-time liability ledger. Every autonomous system should remain subject to a solvency governor. Every payment system should offer an appropriate level of reversibility. Every delegation should inherit its limits. And every agentic marketplace should possess a method for dispute, suspension, and resolution.
The central principle is simple: a machine may be permitted to act economically, but it must never become impossible to identify who authorized it, what it was allowed to do, which obligations it created, and how those obligations can be resolved. The traveler of the introduction was protected by decades of accumulated payments institutions, statements, dispute rights, refund desks, that quietly reconciled a dozen automated transactions into an intelligible and contestable account. The task before regulators, engineers, and enterprises is to build the equivalent institutions for a world in which the traveler never travels, the agents do, and the statement, when it arrives, must still be one a human can read, question, and afford. The age of autonomous commerce will not be judged only by how intelligently machines spend. It will be judged by whether humans remain capable of stopping them before autonomy becomes insolvency.

Footnotes and Endnotes:
[1] Sonja Davidovic and Hervé Tourpe, “How Agentic AI Will Reshape Payments,” IMF Notes 2026/004, International Monetary Fund, April 22, 2026. The note examines authorization, liquidity, settlement, compliance, and resilience in agent-mediated payment systems, warning that autonomy, opacity, and non-deterministic behavior introduce material risks to consumer protection and market stability. https://www.imf.org/en/publications/imf-notes/issues/2026/04/22/how-agentic-ai-will-reshape-payments-575560
[2] McKinsey & Company / ICSC agentic-commerce projections, with Bain & Company, Morgan Stanley, Gartner, and J.P. Morgan estimates, compiled in “Agentic Commerce Stats 2026: Enterprise Guide,” commercetools, June 2026. Aggregates forecasts of $3–5 trillion in global agent-orchestrated retail spend by 2030, up to $1 trillion in the United States, and 15–25 percent of US e-commerce. https://commercetools.com/blog/agentic-commerce-stats-enterprise-guide
[3] Elogic Commerce, “ChatGPT Commerce & Agentic Shopping Statistics 2026,” compiling Salesforce State of Marketing 2026 and Adobe Analytics data, May 2026. Reports AI agents driving roughly 20 percent of global holiday orders ($262 billion) in 2025 and an 805 percent year-over-year increase in AI-driven retail traffic. https://elogic.co/blog/chatgpt-commerce-statistics/
[4] Google for Developers, “Universal Commerce Protocol Guide.” Google describes UCP as an interoperable open standard supporting end-to-end agentic commerce, compatible with AP2, A2A, and MCP. https://developers.google.com/merchant/ucp
[5] OpenAI, “Buy It in ChatGPT: Instant Checkout and the Agentic Commerce Protocol,” September 29, 2025. Describes commercial interactions among users, AI agents, merchants, and payment providers through the Agentic Commerce Protocol. https://openai.com/index/buy-it-in-chatgpt/
[6] OpenAI, “Introducing ChatGPT Agent: Bridging Research and Action,” July 17, 2025. States that the agent requests permission before actions with real-world consequences, including purchases, with additional supervision for critical activities. https://openai.com/index/introducing-chatgpt-agent/
[7] Visa Inc., “Visa Introduces Trusted Agent Protocol: An Ecosystem-Led Framework for AI Commerce,” October 14, 2025; see also Visa Developer Center, “Trusted Agent Protocol—Getting Started.” A cryptographic framework helping merchants distinguish approved commercial agents from malicious bots and support trusted agent-driven transactions. https://investor.visa.com/news/news-details/2025/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce/default.aspx
[8] Mastercard, “Mastercard Launches Agent Pay for Machines to Unlock Super-Fast, Always-On Payments,” June 10, 2026. Describes infrastructure for continuous, high-frequency, low-latency machine-driven transactions, credential controls, and settlement across several payment types. https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html
[9] Mastercard, “How Verifiable Intent Builds Trust in Agentic AI Commerce,” March 5, 2026. Addresses how a user’s delegated commercial instructions can be represented and authenticated as a verifiable record of authorized intent. https://www.mastercard.com/us/en/news-and-trends/stories/2026/verifiable-intent.html
[10] Stripe, “Agentic Commerce: How AI Agents Are Changing the Way Businesses Buy and Sell,” updated April 22, 2026. Discusses multi-agent purchasing, scoped payment methods, mixed decision logic, merchant systems, and the need for audit trails. https://stripe.com/resources/more/agentic-commerce
[11] Stripe, “Stripe Builds Out the Economic Infrastructure for AI with 288 Launches,” Stripe Sessions, April 29, 2026; see also “Supporting Additional Payment Methods for Agentic Commerce,” March 3, 2026. Covers one-time-use cards for agentic tasks, user approval flows, streaming payments, shared payment tokens, and AI-native transaction models. https://stripe.com/newsroom/news/sessions-2026
[12] Coinbase Developer Platform, “Welcome to x402.” Describes x402 as an open protocol enabling instant automatic stablecoin payments over HTTP for developers, applications, and AI agents. https://docs.cdp.coinbase.com/x402/welcome
[13] Coinbase, “Introducing Agentic Wallets: Give Your Agents the Power of Autonomy,” February 11, 2026; see also Coinbase Developer Platform, “x402 Wallets.” Wallet infrastructure letting autonomous agents transact through machine-native payment protocols, functioning as both payment mechanisms and identifiers, with session caps and transaction-size controls. https://www.coinbase.com/developer-platform/discover/launches/agentic-wallets
[14] Coinbase, “Coinbase and AWS Let Publishers Accept Agents as Customers via x402,” June 15, 2026. The integration permits online publishers and services to receive automatic agent payments through HTTP requests and x402 settlement. https://www.coinbase.com/blog/coinbase-and-aws-let-publishers-accept-agents-as-customers-via-x402
[15] Google Cloud, “Announcing the Agent Payments Protocol (AP2).” Presents AP2 as a framework for trusted and accountable agent-driven payments built to interoperate with agent communication and tool protocols. https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol
[16] William Fisher, Ryan Galluzzo, and Joshua Roberts, “Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization,” National Institute of Standards and Technology, February 5, 2026. A concept paper addressing practical, standards-based approaches for identifying software agents and managing their access and authority. https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd
[17] National Institute of Standards and Technology, “AI Agent Standards Initiative,” February 17, 2026. Focuses on secure, interoperable agents that can act on behalf of users across the digital ecosystem. https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative
[18] National Institute of Standards and Technology, “CAISI Issues Request for Information About Securing AI Agent Systems,” January 12, 2026. Identifies distinctive risks arising when AI outputs are connected with software capabilities, authentication systems, memory, and external tools. https://www.nist.gov/news-events/news/2026/01/caisi-issues-request-information-about-securing-ai-agent-systems
[19] United States Congress, 15 U.S.C. § 7001, Electronic Signatures in Global and National Commerce Act (E-SIGN), subsection (h), Electronic Agents, Legal Information Institute, Cornell Law School. A contract or record may not be denied legal effect solely because its formation involved electronic agents, when their actions are legally attributable to the person to be bound. https://www.law.cornell.edu/uscode/text/15/7001
[20] Uniform Law Commission, “Uniform Electronic Transactions Act (UETA).” Establishes the legal equivalence of qualifying electronic records and signatures with paper counterparts and provides rules for automated transactions. https://www.uniformlaws.org/committees/community-home?CommunityKey=2c04b76c-2b7d-4399-977e-d5876ba7e034
[21] Noam Kolt, “Governing AI Agents,” 101 Notre Dame Law Review (forthcoming), revised February 11, 2025. Uses agency theory and the common law of agency to characterize information asymmetry, discretionary authority, and loyalty problems in AI agents, arguing that conventional incentive, monitoring, and enforcement mechanisms fail at machine speed and scale, and proposing governance built on inclusivity, visibility, and liability. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4772956
[22] Maarten Herbosch, “Liability for AI Agents,” 26 North Carolina Journal of Law & Technology 391 (2025). Analyzes deployer and developer liability for autonomous AI systems, rejecting strong technological exceptionalism while identifying where existing doctrine requires adaptation. https://scholarship.law.unc.edu/ncjolt/vol26/iss3/4
[23] Alan Chan, Kevin Wei, Sihao Huang, Nitarshan Rajkumar, Elija Perrier, Seth Lazar, Gillian K. Hadfield, and Markus Anderljung, “Infrastructure for AI Agents,” arXiv:2501.10114, revised June 19, 2025. Proposes agent infrastructure—technical systems and shared protocols for identity, attribution, communication, and agreement—arguing that attributing an agent’s actions to a legal entity establishes trust and disincentivizes misuse. https://arxiv.org/abs/2501.10114
[24] Gillian K. Hadfield, “Policy & Governance,” research statement on legal infrastructure and registration schemes for AI agents. Argues that the identification and registration infrastructure undergirding accountability evolved for human actors and corporations and is still missing for AI actors, and proposes durable ID and registration schemes for autonomous agents. https://gillianhadfield.org/policy
[25] United States Congress, 11 U.S.C. § 101—Definitions, Office of the Law Revision Counsel. The Bankruptcy Code broadly defines “claim” to include contingent, disputed, unmatured, secured, and unsecured rights to payment, and defines debt as liability on a claim. https://uscode.house.gov/view.xhtml?edition=prelim&req=granuleid%3AUSC-prelim-title11-section101
[26] United States Congress, 11 U.S.C. § 365—Executory Contracts and Unexpired Leases, Office of the Law Revision Counsel. Governs the assumption and rejection of executory contracts and unexpired leases in bankruptcy, subject to court approval. https://uscode.house.gov/view.xhtml?edition=prelim&num=0&req=granuleid%3AUSC-prelim-title11-section365
[27] Administrative Office of the United States Courts, “Bankruptcy Basics.” Describes bankruptcy as the legal process through which individuals and businesses address debts they can no longer pay. https://www.uscourts.gov/court-programs/bankruptcy/bankruptcy-basics
[28] Fenwick & West LLP, “Is 2026 the Year of Agentic Payments?,” April 2026. Analyzes regulatory gaps in agentic payments, including Regulation E’s silence on agents that violate consumer instructions, the non-extension of consumer protections to crypto-native rails, and the absence of standard dispute frameworks for agentic purchases. https://www.fenwick.com/insights/publications/is-2026-the-year-of-agentic-payments
[29] Michelle W. Bowman, Vice Chair for Supervision, “Artificial Intelligence in the Financial System,” remarks at the FSOC AI Roundtable on Cybersecurity and Risk Management, Board of Governors of the Federal Reserve System, published May 1, 2026; see also SR Letter 26-2 (April 17, 2026). Explains the amendment of interagency model risk management guidance to exclude generative and agentic AI, and describes current bank deployment within guardrails and human-in-the-loop accountability. https://www.federalreserve.gov/newsevents/speech/bowman20260501a.htm
[30] Carter Pape, “Regulators’ Guidance on Model Risk Leaves Many Questions Unanswered,” American Banker, June 1, 2026. Quotes OCC Bulletin 2026-13 / SR 26-2 excluding generative and agentic AI from model risk guidance, and cites Gallagher Re/MIT findings that US generative-AI-related lawsuits grew 978 percent between 2021 and 2025 while standard insurance policies leave significant coverage gaps. https://www.americanbanker.com/opinion/regulators-guidance-on-model-risk-leaves-many-questions-unanswered
[31] Bank for International Settlements, Annual Economic Report 2026 (June 28, 2026) and BIS Quarterly Review (March 16, 2026), as reported in Fortune, “The Central Bank of Central Banks Just Released Its Flagship Annual Report,” June 29, 2026. Warns that the trillion-dollar hyperscaler capital-expenditure boom, financed increasingly through opaque non-bank channels, could turn into a protracted investment bust with knock-on effects on financial conditions; separately documents tokenized money-market funds growing from roughly $770 million to nearly $9 billion. https://fortune.com/2026/06/29/bis-central-bank-warning-hyperscaler-data-center-1-trillion-gamble-recession/
[32] Visa Inc. (V), Q1 FY2026 Earnings Call Transcript, January 29–30, 2026, The Motley Fool. CEO Ryan McInerney reports more than 17.5 billion tokens, over 100 partners enabling agentic commerce on Visa Intelligent Commerce, live production transactions, B2B agentic payments with Ramp, and AWS Marketplace availability. https://www.fool.com/earnings/call-transcripts/2026/01/30/visa-v-q1-2026-earnings-call-transcript/
[33] PYMNTS, “Mastercard Sees Agentic Commerce Growth Despite Travel Headwinds,” reporting Mastercard’s Q1 2026 earnings call, April 30, 2026. CEO Michael Miebach places Agent Pay, Verifiable Intent, and virtualized credentials at the center of strategy, citing engagement with Google, Microsoft, and OpenAI. https://www.pymnts.com/earnings/2026/mastercard-sees-agentic-commerce-growth-despite-travel-headwinds/
[34] Eightx, “Visa Put Its Payment Rails Inside ChatGPT,” analyzing the June 10, 2026 Visa–OpenAI integration. Tokenized Visa credentials scoped to specific agents power agent-initiated checkout inside ChatGPT, with user-defined spending caps, merchant whitelists, and approval thresholds enforced before authorization. https://eightx.co/blog/visa-chatgpt-agentic-commerce
[35] Greg Iacurci, “AI May Replace Your Financial Advisor, MIT Professor Says—But There’s One Big Hurdle,” CNBC, April 6, 2026 (interviewing Andrew W. Lo, Professor of Finance and Director of the Laboratory for Financial Engineering, MIT Sloan School of Management). Lo argues AI has the financial expertise but lacks fiduciary duty and the capacity to suffer consequences for mistakes to the degree human advisers do. https://www.cnbc.com/2026/04/06/ai-has-a-big-problem-when-it-comes-to-financial-advice-mit-professor.html
[36] PYMNTS, “MIT Expert Finds Limits in AI’s Ability to Offer Financial Advice,” April 6, 2026 (quoting Sebastian Benthall, Senior Research Fellow, Information Law Institute, New York University School of Law). Benthall raises the regulatory question of responsibility and reliance when AI financial products are not backed by a corporation with a fiduciary duty. https://www.pymnts.com/artificial-intelligence-2/2026/mit-expert-finds-limits-in-ais-ability-to-offer-financial-advice/
[37] Emilio Calvano, Giacomo Calzolari, Vincenzo Denicolò, and Sergio Pastorello, “Artificial Intelligence, Algorithmic Pricing, and Collusion,” 110 American Economic Review 3267 (2020). Demonstrates that reinforcement-learning pricing agents in oligopoly settings learn to sustain supracompetitive prices and punish deviations without communication or instruction to collude. https://www.aeaweb.org/articles?id=10.1257/aer.20190623
[38] Sara Fish, Yannai A. Gonczarowski, and Ran I. Shorrer, “Algorithmic Collusion by Large Language Models,” arXiv:2404.00806 (revised 2025). Finds that LLM-based pricing agents quickly and autonomously reach supracompetitive prices and profits, with seemingly innocuous prompt phrasing materially influencing the degree of supracompetitive pricing. https://arxiv.org/abs/2404.00806
[39] Anthropic, “Project Vend: Phase Two,” December 2025; see also “Project Vend” phase one, June 2025. An AI shopkeeper running a real small business initially lost money and was manipulated into loss-making sales, before improved tooling, memory, and oversight structures made a later phase profitable; Anthropic concludes the gap between capable and completely robust remains wide. https://www.anthropic.com/research/project-vend-2
[40] Straiker, “Why 94% of AI Agents Are Vulnerable to Prompt Injection—And What to Do About It,” April 2026. Reports a 2025 benchmark finding 94.4 percent of tested AI agents vulnerable to hijacking through the content they were asked to read. https://www.straiker.ai/blog/why-94-of-ai-agents-are-vulnerable-to-prompt-injection—-and-what-to-do-about-it
[41] Vectra AI, “Prompt Injection: Types, Real-World CVEs, and Enterprise Defenses,” May 2026. Documents prompt injection as the number-one risk in the OWASP Top 10 for LLM Applications, with attack success rates of 50–84 percent in agentic systems and production exploits carrying CVSS scores above 9.0. https://www.vectra.ai/topics/prompt-injection
[42] CoinDesk, “The Age of Agentic Commerce Has Arrived,” April 28, 2026 (quoting Yat Siu, Animoca Brands, and noting sessions convened with MIT professor Christian Catalini at Consensus 2026). Projects tens of billions of deployed agents and frames the build-out of rails, regulatory frameworks, and business models for agentic commerce. https://www.coindesk.com/opinion/2026/04/28/the-age-of-agentic-commerce-has-arrived-consensus-2026-is-where-you-can-experience-it-irl
[43] Anthropic, “Agents for Financial Services,” May 5, 2026. Describes financial agents connected to professional data sources and external tools through connectors and MCP-based infrastructure. https://www.anthropic.com/news/finance-agents
[44] StockStory, “5 Must-Read Analyst Questions From Visa’s Q1 Earnings Call,” May 5, 2026. CEO Ryan McInerney states that Visa cardholders will be protected from fraud and that the network will evolve its rules as agentic commerce matures. https://stockstory.org/us/stocks/nyse/v/news/earnings-call/5-must-read-analyst-questions-from-visas-q1-earnings-call



