Six major financial institutions—Bank of America, Capital One, ING, NatWest, ASB Bank, and Commonwealth Bank of Australia—released a joint paper on September 22, 2026, titled "Building Trust in Agentic Commerce." For developers building autonomous agents that move money, this document functions less like policy and more like a mandatory spec sheet. The consensus is clear: if your agent spends, it must prove it.

The Banks' Non-Negotiables

The coalition demands auditable records for every step of the transaction lifecycle, including consumer instructions, authentication, intent, and final outcomes. They explicitly warn against agents that "may buy the wrong thing or spend too much" or fall victim to fraud. The paper insists on disclosure whenever an AI agent is involved in a transaction and requires greater transparency in decision-making logic. While these are framed as principles for policymakers rather than immediate regulations, they represent the loudest demand signal yet from the legacy financial world.

Card Networks Respond With Scope Limits

Mastercard and Visa are already shipping countermeasures. Mastercard’s "Agent Card + Agent Pay" initiative, rolling out with Alchemy, assigns virtual cards to individual agents with network-enforced spend caps and kill switches. Their "Verifiable Intent" records who authorized the agent and what it was instructed to do. Visa takes a different angle with "scoped tokens" in partnership with OpenAI. These tokens bake hard limits at issuance; a grocery token cannot book travel, and a $200 cap cannot clear a $500 charge. The policy lives outside the model, preventing a hallucinating agent from talking its way past financial limits.

Protocol Layers and Live Gates

Google’s Agent Payments Protocol (AP2), backed by Coinbase and over 60 partners, separates the "intent mandate" from the "cart mandate," requiring final approval for specific items. Meanwhile, newer solutions like Veyra offer an independent decision layer on the Arc testnet, signing authorizations bound to one endpoint and one amount. On the ground, ScriptMasterLabs is running a live confidence gate in front of the x402 rail. Tested on September 24, 2026, their system held a 0.05 USDC payment for human review because the agent’s confidence score hit only 0.5, proving that a hunch does not equal authorization.

Key Takeaways

  • Six global banks published a joint framework on September 22, 2026, demanding auditable records for AI-driven transactions.
  • Mastercard and Visa are deploying network-level caps and scoped tokens to prevent agents from exceeding authorized limits.
  • Google’s AP2 protocol separates intent from execution, requiring specific cart mandates for final spending approval.
  • Live implementations like ScriptMasterLabs’ confidence gate are already holding low-confidence transactions for human review.

The Bottom Line

The banks aren't asking nicely anymore; they are defining the rails. If your agent can't prove its intent and stay within its scope, it doesn't get to spend.