Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

Fintech iconFintechOctober 4, 2026

HIFI raises $37M for tokenized money infrastructure

HIFI raises $37M for tokenized money infrastructure
StablecoinsPayment Processing+3
Fintech iconFintechOctober 3, 2026

Pivot57 launches Africa's first institutional intelligence platform

Pivot57 launches Africa's first institutional intelligence platform
Africa TechInstitutional Finance+3
SaaS iconSaaSAugust 1, 2026

Agon Emerges from Stealth with $30M to Train AI for Drone Defense

Agon Emerges from Stealth with $30M to Train AI for Drone Defense
Defense TechAi+3
Healthtech & Biotech iconHealthtech & BiotechAugust 1, 2026

CipherX Launches World's First Painless Microneedle Tattoo System

CipherX Launches World's First Painless Microneedle Tattoo System
BiotechMedical Devices+2
Fintech iconFintech
August 1, 2026
Ai AgentsPayment ProcessingAi Access ControlAutonomous SystemsFintech

The Race to Prove AI Agents Have Permission to Spend Your Money

As autonomous AI agents gain payment capabilities, startups and payment giants are rushing to build authorization proof systems that verify machines are authorized to make purchases.

The Race to Prove AI Agents Have Permission to Spend Your Money

Here's a question that keeps payment executives up at night: When an AI agent decides to buy something on your behalf, how does anyone actually know it had permission?

Not long ago, that was a theoretical problem for standards committees and PhD theses. Not anymore. As autonomous systems gain the ability to execute payments—booking flights, negotiating subscriptions, purchasing API calls in bulk—a quiet but urgent race has erupted to build the infrastructure that can prove, cryptographically and irrevocably, that the machine was authorized to spend your money.

Over the past year, payment giants and scrappy startups alike have been developing what the industry calls "authorization proof systems," each attempting to solve the same fundamental riddle: how to verify that an agent's transaction actually reflects a human's intent before value changes hands.

The stakes are higher than they might seem.

Beyond the Tap and Click

The challenge sounds almost trivial at first. Traditional payments rest on a simple assumption: a human is present at the point of transaction, tapping a card, clicking "buy now," entering a password. AI agents shatter that model entirely. They operate autonomously, sometimes making hundreds of micro-decisions in minutes—negotiating prices with other agents, purchasing compute credits, booking services—all without pausing for approval on each individual move.

"The shift to agentic commerce requires a new kind of proof," notes documentation from IETF working groups that spent much of early this year formalizing what they call "authorization evidence standards." "Beyond ephemeral OAuth tokens or short-lived session credentials, we need durable, signed records that bind a principal, a policy, and a specific action request."

That binding—principal to agent, agent to policy, policy to action—is what these new systems attempt to create. Without it, payments become a black box where accountability vanishes. With it, every transaction carries a verifiable chain of custody. In theory, anyway.

An Open Standard Takes Shape

On June 25, a company called Proof launched something it calls x401, billing it as "the open protocol for verifying the authority behind AI agents." The protocol introduces signed, requestable proof of who authorized an agent's action, complete with Model Context Protocol server demos and command-line tools for developers who want to tinker.

x401 arrived just as Google was donating its Agent Payments Protocol—AP2, in industry shorthand—along with a "Verifiable Intent" framework to the FIDO Alliance in May. (Google had originally announced AP2 last September.) The protocol uses verifiable credentials and mandate structures to establish that an agent is operating within bounds set by its principal. The FIDO donation signals something of an industry bet: that authorization proof needs open standards, not a patchwork of proprietary silos.

By July, the IETF had two relevant Internet-Drafts in circulation. One describes "Authorization-Evidence Records" that persist beyond those ephemeral tokens everyone's used to. The other, with the acronym-heavy name OASNT—Attested Action Authorization Tokens—proposes signed objects that bind the exact action, disclosure text, and optional one-time fingerprints. Both drafts make the case for cryptographic proof over systems that run on trust alone.

Whether the standards bodies can keep pace with the market is another question.

Payment Giants Retrofit the Rails

Digital illustration for article section "Payment Giants Retrofit the Rails" in "The Race to Prove AI Agents Have Permission to Spend Your Money" - A minimalist, isometric pixel art illustration of a sleek, modern automated payment terminal seamles...

Mastercard moved early. In April of last year, it unveiled Agent Pay, emphasizing controls at three stages: pre-transaction, during, and post. By June of this year, Mastercard had expanded the program into "Agent Pay for Machines," adding interoperability features that span from traditional card networks all the way to stablecoins—a range that would have seemed improbable just a few years ago. A partnership with PayPal, announced last October, brought Agent Pay into mainstream digital wallets.

Visa took a different path. Its Trusted Agent Protocol, announced earlier this year, focuses more on the merchant side: acceptance and agent verification. On July 2, Visa disclosed that live agentic transactions were already happening in Europe and highlighted an agent directory designed to help merchants recognize verified agents. During a January earnings call, Visa referenced ongoing interoperability work with Google on agent protocols, though details remained scarce.

Both networks face essentially the same technical puzzle: how to retrofit existing payment infrastructure—designed for human-initiated swipes and clicks—to handle autonomous, policy-governed agent requests. Authorization proof systems are the bridge. Or at least, that's the bet.

The Startup Layer Builds Fast

Smaller players have been building authorization infrastructure from different angles, sometimes with more agility than their corporate counterparts. AgentPay, documented as of mid-July, explicitly claims to remove "payment authorization and settlement proof" problems through features like AgentPassport—a trust and attestation layer—and adapters for OpenAI and LangChain. A May 27 demo post showed x402 challenge-response flows for paid APIs, positioning AgentPay as a settlement layer with pre-execution authorization checks baked in.

KYA Protocol published version 0.1 of its "Agent Approval Protocol" on March 18, positioning itself as the authorization layer for AI-driven payments. Clearing Systems advertises what it calls a "trust layer for agentic commerce execution," complete with consent proof and audit-ready receipts. Duvera built a gateway that evaluates policy, signs capability tokens, and persists audit logs—creating what the company describes as a verifiable "proof chain."

Even identity and access management platforms are scrambling to adapt. In June, Ory launched "Agent Security," an IAM control plane designed to sit at the agent harness level and enforce authorization before any tool gets dispatched. A month later, PlainID announced its policy-based access control platform now governs both human and AI agent access at runtime—already in use, they claim, by Fortune 500 customers.

The proliferation of solutions suggests the market hasn't settled on a winner. Or perhaps it never will.

A Pattern Emerges: Dual-Proof Architecture

What's emerging across these disparate systems is something like consensus on architecture, if not on implementation. Call it a dual-proof model.

First, mandate proof before execution: a cryptographically signed assertion that binds the principal, agent identity, policy parameters, request hash, and context. Second, settlement proof after execution: an immutable receipt with payment references and finality markers.

This architecture shows up in Google's AP2, with its verifiable credentials. It appears in Proof's x401, with signed authority records. And it's been debated extensively in developer forums—Reddit and Hacker News threads from May through July have dissected spending mandate layers, cryptographic authorization modules, and MCP guardrails with signed receipts. The separation of concerns is deliberate: mandate proof before signing, settlement proof after.

Academic work is converging on similar patterns, though perhaps more slowly. A March preprint titled "Before the Tool Call" formalizes pre-tool-call authorization layers. A July paper introduces what it calls "cryptographically verifiable authorization"—CVA—for agents, emphasizing principal binding, request binding, policy binding, and replay resistance. The language is dense, but the intent is clear enough.

Why This Actually Matters

Digital illustration for article section "Why This Actually Matters" in "The Race to Prove AI Agents Have Permission to Spend Your Money" - A sleek, conceptual representation of delegated authorization and autonomous decision-making in mode...

McKinsey's March report on agentic commerce framed delegated authorization as the linchpin for scaling AI-driven transactions. Without clear proof systems, the report argues, identity, risk, and compliance layers simply can't adapt to autonomous decision-making. An April note from the IMF echoed the theme, discussing mandate-based authorization models and operational considerations for agent-initiated transactions. When the IMF starts paying attention, you know regulators aren't far behind.

Visa's February whitepaper put it more plainly: trust and standards are prerequisites for scaling agentic AI in commerce. Authorization proof is how that trust becomes something you can measure, audit, enforce.

The infrastructure remains fragmentary. Multiple protocols, overlapping standards, competing platforms—all attempting to define what "proof" means in this context. There's no clear winner yet, no single standard that everyone's rallying behind. But the direction, at least, seems clear.

Authorization proof is no longer a research problem confined to academic papers and working group meetings. It's a product requirement. And the race to build it—messy, competitive, perhaps more urgent than most people realize—is already well underway.

More stories

  • HIFI raises $37M for tokenized money infrastructure
  • Pivot57 launches Africa's first institutional intelligence platform
  • Agon Emerges from Stealth with $30M to Train AI for Drone Defense
  • CipherX Launches World's First Painless Microneedle Tattoo System
  • OneDosh Raises $4M Pre-Seed to Scale Stablecoin Remittance App
  • Unverified: Skit.ai Funding Claim Raises Questions on AI Startup News
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.