NextFin News - A sitting Federal Reserve governor has publicly framed agentic commerce as a technology that "could significantly reshape commerce and payments if adoption scales," while leaving open the question that will decide how fast it arrives: who is on the hook when an autonomous software agent makes the wrong purchase. In a speech delivered Tuesday at Sibos 2026 in Miami, Governor Christopher J. Waller stopped short of proposing rules, but he signaled that the central bank is already convening the firms building the infrastructure — card networks, banks, and technology platforms — to shape the standards before the market hardens. The remarks are the clearest sign yet that payments regulators are treating AI-driven transactions as an emerging issue for the safety and integrity of the payments system, not a distant hypothetical.
The Speech: Two Models, One Sharp Warning
Waller's remarks, titled "Payments in the Age of AI Agents," built on a speech he gave at the same conference a year earlier, when he discussed how a range of emerging technologies could shape the next frontier in global payments. This time he narrowed the focus to the state of artificial intelligence in payments and raised questions about how the technology could change the way payment systems operate. He opened by noting that within the financial sector, the payments industry has long been at the forefront of using AI to improve operations — deploying machine learning to combat fraud and adopting large language models early for reconciliation tasks. The new frontier is AI agents that can plan and execute multistep processes and transact autonomously.
At the center of the speech were two models of agentic commerce. In the agent-assisted model, a buyer uses an AI agent primarily for product search and discovery, but the buyer remains in control: they make the decisions and handle the payment. In the agent-delegated model, a buyer grants authority to an AI agent to shop and make payments on their behalf. The buyer may specify some constraints and set up guardrails, but the agent operates autonomously — for example, giving an agent access to a pre-funded virtual card with instructions to shop for groceries online based on past purchases.
Market participants broadly agree that agentic commerce is in an early phase, Waller said, but the delegated model drew his most pointed language. The biggest barrier to scaling agentic commerce, particularly the agent-delegated model, is building sufficient trust among buyers and sellers, and three concrete challenges stand out: authentication, liability, and fraud.
"Liability in this context comes down to a pretty simple question: Who is on the hook if an agent makes the wrong purchase?"
Waller noted that current e-commerce liability frameworks — including network rules, consumer protection standards, and other regulations — could potentially be adapted for agentic commerce, but there may also be an opportunity to test and refine new approaches. He also warned that existing fraud detection and prevention systems, calibrated to human behavior, may not translate well to agents, and that fraud models and rules will need to be recalibrated to account for agent payment patterns.
The speech also documented the Fed's own engagement. At the beginning of the summer, Waller hosted an industry roundtable at the Federal Reserve focused on agentic commerce, and the participant list for the May 26, 2026 meeting reads like a map of who is building the infrastructure: Adyen, Amazon, Amazon Web Services, Centime, Cloudflare, Coinbase, Cross River Bank, Fiserv, Forte Fintech, Google, Lead Bank, Mastercard, Paze, Plaid, Shopify, Skyfire, Stripe, Taktile, and Visa, alongside Federal Reserve governors and Reserve Bank presidents.
The Liability Gap Is the Real Story
The most consequential part of Waller's speech was not the technology description but the question he posed about liability. Today's card-payment system rests on a fraud-liability model that assumes a human cardholder: the bank can alert the customer, the customer can dispute a transaction, and rules allocate losses between issuers, merchants, and networks. An autonomous agent breaks that assumption. If an agent is tricked into sending money to a fraudster, or if its credentials are stolen, who is liable — the consumer who delegated authority, the bank that provided account access, the agent developer, or the merchant that accepted the transaction?
Waller did not answer that question. He framed it as something the industry must consider, and that silence is itself a signal. Regulators typically move slowly; when a governor raises a liability question in a public speech, it usually means the issue has moved from the research division to the policy agenda. The risk for the industry is that uncertainty itself becomes a brake on adoption: banks may restrict agent access to accounts until the loss-allocation rules are clear. Consumer-to-business transactions are seen as the first wave of agentic commerce, with agent-assisted use cases preceding more autonomous, agent-delegated ones, precisely because the delegated model introduces higher risks of unintended purchases and requires a more extensive buildout of trust mechanisms and guardrails.
The authentication paradigm shifts as well. As Waller put it, the question moves from proving that a buyer is an authorized payer to proving that an agent has the authority to pay on the buyer's behalf — and capturing that will require new authentication approaches. Technical standards could be designed to give everyone a better understanding of what the buyer intended and how their agent carried it out, reducing the ambiguities that complicate many transaction disputes today.
Private Infrastructure Is Already Building
While the Fed is still asking questions, the private sector is already building the rails. Google announced the Agent Payments Protocol, known as AP2, in September 2025 — an open standard built on signed mandates that record exactly what a human authorized an agent to buy. More than 60 launch partners joined, including PayPal, Mastercard, American Express, Adyen, Coinbase, Salesforce, and Shopify. AP2 introduces signed mandates — a Checkout Mandate and a linked Payment Mandate — carried as verifiable digital credentials, and it treats stablecoin rails as first-class citizens alongside cards and bank transfers.
The card networks moved in parallel. Mastercard unveiled Agent Pay in April 2025, built around agentic tokens that extend its tokenization service to AI agents. Visa introduced new AI commerce capabilities at the end of April 2025 and followed with its Trusted Agent Protocol in October 2025, which has since evolved into a broader Intelligent Commerce program. The two networks agree on the problem — AI agents need a credentialed way to transact on a cardholder's behalf — but they diverge on how identity, tokenization, and merchant trust are wired. Mastercard's model centers on cardholder-defined mandates bound to a token at provisioning; Visa's approach leans toward per-transaction signed intent, with the agent acting within an authorized scope.
That divergence matters because whoever defines the mandate envelope effectively defines where liability attaches. If the signed mandate becomes the legal record of consent, the protocol layer — not the rail — becomes the locus of control. Waller's speech can be read as a bid to make sure the public sector has a seat at that table. His closing line called for "a proactive approach that balances innovation with the safety, integrity, and stability that underpin trust in payments." That is regulatory language for: do not let the standard harden before we have weighed in.
Cross-Border Efficiency Is the Easier Win
Waller was more confident about AI's role in cross-border payments than in agentic commerce. Combating illicit finance is one of the clearest examples of where AI can drive efficiency and security gains, particularly in cross-border payments where threat actors can exploit the seams between jurisdictions. Large language models have contextual awareness that can "greatly improve the accuracy of sanctions screening and anti-money-laundering systems," and research has demonstrated that they can significantly reduce false-positive alerts for illicit activity. Waller cited Federal Reserve research by Jeffrey Allen and Max Hatfield on fuzzy matching in sanctions screening. His expectation is measured: given the velocity of modern payment systems, LLMs will augment, rather than replace, faster, more traditional anomaly detection methods.
He also flagged the cybersecurity asymmetry that keeps payment operators awake. "Threat actors need to exploit only one key vulnerability, whereas payment system operators and service providers need to defend a large attack surface," he said. AI can support cyber threat detection and exposure management, and can help develop more secure software and catch vulnerabilities before they are introduced. But the asymmetry is precisely why the industry must move deliberately to leverage AI in strengthening the safety of trusted payment systems.
On routing, foreign-exchange conversion, and liquidity management, Waller saw a natural fit. Payment routing involves finding the path that best balances cost, speed, and reliability, and cross-border providers must decide when and where to convert currency and whether to net offsetting flows. If presented with the right data and criteria, AI agents have the potential to excel at solving these complex optimization problems — back-office efficiency gains that are real, but not transformative in the way agent-delegated commerce could be.
Cyclical Hype, Structural Shift
The honest read of this moment separates the hype cycle from the regime shift. The hype is cyclical: industry forecasts of agentic commerce reaching hundreds of billions or even trillions of dollars by 2030 rest on adoption curves that have not yet materialized. AI-referred sessions remain a very small fraction of total e-commerce traffic, and usage is concentrated early in the customer journey — product comparison rather than checkout. Generative AI referral traffic to U.S. retail websites surged in mid-2025, but from a tiny base. The slope looks dramatic; the base does not.
The regime shift is structural and independent of the adoption curve. Once payment initiation moves from a human at a keyboard to software acting under delegated authority, the fraud, liability, identity, and settlement layers of the payments system must be rebuilt. That does not revert when the hype cools. The question is not whether the direction changes; it is whether the transition is smooth or punctuated by losses that force regulatory intervention.
The strongest counter-thesis is that agentic commerce stalls before it reaches the delegated stage. Consumers may never become comfortable handing spending authority to software; merchants may refuse to accept agent transactions without guaranteed settlement; and the liability question may remain unresolved, leaving agents permanently confined to assisted search rather than delegated payment. Waller himself frames these as open questions rather than settled outcomes, and the authentication and fraud-recalibration problems he identifies are genuine technical hurdles, not mere regulatory friction.
But that counter-thesis has a falsifying signal. If agent-delegated transactions remain below roughly 1 percent of e-commerce volume by the end of 2027 and no major bank or network has published an agent-liability framework, the "reshape" thesis is wrong for this cycle. The signal to watch is not the next protocol announcement; it is the first high-profile unauthorized agent transaction that forces a loss-allocation decision. That case, more than any speech, will set the market's expectations.
What Comes Next
In the short term, the beneficiaries of a shift toward agent-delegated commerce are the firms that control the consent and identity layer — the mandate protocols, the credential vaults, the authentication standards. Standards bodies and the major networks are already working on agentic trust, and the Fed's roundtable suggests regulators intend to be part of that conversation. The exposed parties are the banks and payment service providers that hold the liability today but may not control the agent interface tomorrow.
In the medium term, three developments will tell the story: whether Visa and Mastercard publish agent-transaction liability rules, whether AP2-style signed mandates become the default consent record, and whether fraud models recalibrated for agent payment patterns begin to appear in production. In the long term, the structural question is whether the payments industry can agree on a liability framework before adoption scales — or whether a crisis writes the rules for them.
Waller's own falsifying signal, in effect, is adoption itself. If agent-delegated commerce never moves beyond the assisted stage and no liability framework emerges, his language will have overstated the near-term risk. But the direction of travel is clear. The payments industry is being asked to build guardrails for a mode of transacting that does not yet exist at scale — and to do it before the first major loss forces the issue.
The payments system was built for humans who can be alerted and can dispute. It was not built for software that can spend on your behalf while you sleep — and the liability rules for that world do not exist yet.
更多独家洞察尽在 nextfin.ai.

