Skip to main content

Your AI agent shouldn’t spend blindly: open standards keep it honest

Clare Schramm
15th September 2026

When OpenClaw broke on to the scene, we got a glimpse of the future: agents working autonomously on our behalf, paying our bills, booking travel, renewing a subscription, purchasing an item we need. Agents working together, without us even in the loop. We observed the stunning conclusion of an agent world: they created their own religion, their own social media, they complained about us humans relentlessly, but the biggest impact might have been to our wallets. Humans experienced huge surprises on their credit card bills due to OpenClaw handling raw API keys and exploiting security vulnerabilities in browser autofill data. There was intense fear and speculation. What would happen if OpenClaw got into a company’s IT system and started making payments on behalf of a business? How would we show accountability and traceability to corporate governance? How do we stop it making payments when it thinks it’s acting in our best interest? The lessons learnt from OpenClaw showed us that autonomy without accountability is a liability, not a feature.

Now for the scary part: many businesses are already exploring agentic payments today. Stripe/OpenAI’s Agentic Commerce Protocol and Google’s AP2 (Agent Payments Protocol) are already live attempts to standardise how agents transact. It appears that many companies with significant stake in the payment ecosystem (namely fintechs and big tech companies) are already proposing their own protocol. In that way, it is reminiscent of early stablecoin initiatives: attempting to corner the entire ecosystem with a single project governed and influenced by a large corporate maintainer. This obviously risks creating walled gardens, which is diametrically opposed to standardisation initiatives underway across payments ecosystems. Those with recent battle scars from ISO20022 implementations would lament the reversal of a trend we saw as a major step forward for interoperability.

From a risk perspective, agentic payments enter into a regulatory grey area. The UK Financial Conduct Authority (FCA), who regulates the financial industry in the UK, and the Prudential Regulatory Authority (PRA), who regulates the banks and insurers, have maintained a pro-innovation and principles-based approach to AI adoption in financial services. They advise that AI does not create a new regulatory category but rather requires financial institutions to show how AI fulfils their existing obligations via a new execution mechanism. Easy in theory, but in practice it bears more questions when it comes to agentic payments. Who instructs the agent, and within what limits? Can you reconstruct the decision chain that an agent made? Who’s accountable when an agent overpays, pays twice, or pays the wrong recipient? Proprietary protocols compound the risk. Existing operational resilience and third-party outsourcing risks become heightened when partnering with one of the small number of proprietary Silicon Valley AI providers who are able to provide LLMs at enterprise-scale to financial institutions. How can a bank or merchant trust and audit a black box they don’t control, multiplied across the various partners and payment rails that they integrate with throughout their business and consumer customer base?

Open standards are the only way to achieve what regulated financial institutions actually need at scale in order to enable agentic payments: inspectable logic, portable audit trails, and no single vendor lock-in on infrastructure. Payments rails in the UK are considered critical national infrastructure, and as such we should consider frameworks that allow those payment rails to be protected and audited in the age of AI. An open source agentic payments protocol needs to have the following components:

  • Specification of the consent model
  • Open and audible transaction logging formats
  • Open reference implementations

The goal of the open source protocol is to provide a standard, auditable way for AI agents to discover payment options, prove the authority to act on someone’s behalf, assess risk, and initiate transactions across banks, wallets, and payment networks. Rather than embedding opaque payment logic in proprietary agent platforms, the protocol would define interoperable standards for identity, consent, spending limits, transaction signing, receipts, and dispute evidence, whilst allowing financial institutions to extend the protocol to their own regulatory controls. An open source agentic payments protocol would give consumers and businesses portability between agents, give banks clearer governance and traceability, and enable innovation without treating trust, security or accountability as proprietary features.

The financial institutions that help shape agentic payments standards now will benefit from influencing how standards treat interoperability, liability allocation, and audit requirements. We issue a call to action to UK fintechs, banks, and insurers to co-author these standards with the regulator to ensure the UK financial sector’s market dynamics are adequately represented, rather than picking a framework developed elsewhere and applying it to the UK payment ecosystem. Open standards aren’t the cautious choice, they’re the only one that scales to the payment ecosystem in the UK.

OpenUK will be looking into agents in financial services at its meet-up on 22 October, and you can join this by signing up.

Scroll to top of the content