The Real Problem With AI Spending Money Isn't Whether It Can,It's How Much Authority It Should Have
The question driving agentic commerce has fundamentally shifted. It's no longer "Can artificial intelligence spend money on behalf of users?" but rather "How much spending authority should we grant to AI, and who controls that authority?" This reframing emerged as Rain, a stablecoin-based payments platform, acquired Ansa, a stored-value payment startup, and then launched the Agentic Payments Alliance (APA) to establish shared standards for AI agent-based transactions.
Why Is the Agentic Payments Alliance Different From Other AI Payment Protocols?
The payments industry has become crowded with competing AI agent protocols. Coinbase developed x402, OpenAI and Stripe created ACP (Agentic Commerce Protocol), Stripe and Tempo built MPP, Google launched AP2 and UCP, Visa introduced the Trusted Agent Protocol, and Mastercard released Agent Pay and Agent Pay for Machines. Rather than adding another acronym to this list, the APA takes a different approach: it functions as a working coalition focused on shared research and frameworks instead of a proprietary standard owned by a single company.
The alliance's founding members span the entire payments ecosystem. Traditional card networks like Visa and Mastercard sit alongside payment processors including Fiserv, Shift4, and Lithic. Crypto-native infrastructure partners include Circle, a stablecoin issuer; blockchain networks like Solana and Avalanche; and wallet and key management providers such as Fireblocks and Turnkey. Compliance and risk specialists like Chainalysis and Sardine round out the coalition.
What's notably absent, however, are the major AI platform companies. OpenAI, Google, Anthropic, Amazon, and Microsoft are not seated at the table. This gap matters significantly because these companies ultimately control which AI agents billions of consumers will use. In June, Visa announced a strategic partnership directly with OpenAI to integrate payment credentials into OpenAI's agentic commerce ecosystem, while Google's AP2 has assembled its own coalition including Mastercard, PayPal, and MetaMask.
What Problem Does the Agent Control Layer Actually Solve?
Rain launched its Agent Control Layer in June, introducing a capability that sounds minor but addresses a fundamental challenge in AI-powered payments. The system allows businesses to predefine rules specifying which merchants an agent can spend at, which merchant categories are permitted, maximum transaction amounts, spending frequency limits, and card expiration dates. Critically, these rules are enforced before a transaction occurs, not logged after the fact.
This distinction matters because traditional payment systems rest on an assumption that has held for decades: the person spending the money is the person behind the account. Credit card authentication asks a simple question: "Is the person clicking the Buy button right now you?" Agentic payments must answer a different question entirely: "Is what this software is doing right now still within the scope of what you authorized it to do?"
Consider a real-world scenario. A consumer tells an AI agent on Monday evening: "Help me plan my trip to New York next week. Keep hotel costs under $400 per night, prefer United Airlines for flights, and keep the total trip budget under $2,500." The agent actually places the order on Tuesday afternoon, when the customer isn't even on the checkout page. Traditional payment authentication cannot answer whether the agent's actions align with the original authorization.
How to Implement Spending Controls for AI Agents
Organizations deploying AI agents in financial decision-making can establish guardrails across several dimensions:
- Merchant Restrictions: Define which specific merchants or categories of merchants an agent is permitted to transact with, preventing unauthorized spending at irrelevant vendors.
- Transaction Limits: Set maximum amounts per transaction and daily or weekly spending caps to contain financial exposure from agent decisions.
- Temporal Boundaries: Establish expiration dates for agent spending authority and define windows during which transactions are permitted.
- Pre-Transaction Enforcement: Implement controls that block violations before they occur rather than detecting them after the fact through logs or audits.
- Credential Scoping: Use task-specific payment credentials that are valid only for a single transaction rather than handing raw payment methods to AI systems.
Basis Theory, a member of the APA, pioneered agentic credentialing by allowing users to define parameters such as merchant, amount, and expiration time before an agent generates a credential valid only for that specific task. This approach prevents agents from accessing broader payment authority than necessary.
Why the Ansa Acquisition Reveals Rain's Strategic Direction
Rain's acquisition of Ansa, a stored-value payment startup, appears particularly significant when viewed alongside the APA launch. Stored-value systems, like Starbucks' prepaid card model, function as merchant-controlled wallets where consumers deposit funds upfront and a set of rules governs where the balance can be spent and what rewards can be redeemed. This architecture naturally aligns with the mandate enforcement required for agentic payments.
Rain's broader strategy has become clearer over the past year. The company raised $250 million in a Series C round in January with a $1.95 billion valuation, positioning itself as a payment-native platform combining stablecoin settlement efficiency with traditional card network acceptance. The company disclosed that its active card base grew 30-fold over the past year, and its annualized payment volume increased 38-fold. The Ansa acquisition and APA formation suggest Rain is building infrastructure specifically designed to handle the authorization and identity verification challenges unique to AI agent transactions.
The core insight driving this strategy is straightforward: the payments industry has spent decades optimizing for human cardholders making conscious purchasing decisions. Agentic commerce requires a fundamentally different architecture, one where spending authority is granular, time-bound, and continuously verified against user-defined mandates. Until that infrastructure exists at scale, the question of how much authority to grant AI agents remains largely unanswered.
From our network
How AI Agents Are Starting to Control Your Crypto Wallet: Coinbase's New Autonomous Trading Platform Explained
Coinbase now lets AI agents trade crypto autonomously on your behalf, with spending caps and isolated portfolios as guardrails against runaway losses....
on My Crypto News AIHardware Wallets Meet AI Agents: How Ledger Is Solving Crypto's Biggest Automation Problem
Ledger's open-source Agent Stack forces every AI crypto transaction through a physical hardware button, blocking prompt injection attacks that stole $...
on My Crypto News AI