Skip to content
Open access

Expressible, Advisory, or Unenforceable: A Conformance Analysis of Delegated Financial Authority in Deployed Agent-Payment Protocols

2026 · Journal of Artificial Intelligence and Emerging Technologies · 0 citations

TL;DR

This paper defines an authorization envelope of eight fields drawn from the delegated-authority literature and from the control primitives of existing payment rails, comprising a per-transaction ceiling, a cumulative ceiling, a merchant set, a category set, required product attributes, a validity window, a substitution policy and an amount-valued confirmation threshold.

Abstract

Payment networks and model providers deployed agent-authorization infrastructure at speed during 2025 and 2026: signed mandates, agent-bound tokens, and machine-payable settlement rails, each promising that an autonomous agent transacts only within authority its principal granted. This paper asks a prior question to whether agents obey such authority: whether the deployed protocols can express it at all. We define an authorization envelope of eight fields drawn from the delegated-authority literature and from the control primitives of existing payment rails, comprising a per-transaction ceiling, a cumulative ceiling, a merchant set, a category set, required product attributes, a validity window, a substitution policy and an amount-valued confirmation threshold. We then code eight deployed agent-payment protocols against these fields using an auditable document-analysis protocol, classifying each field as expressible, advisory or absent according to whether a typed schema field exists and whether any identified party validates it. Three fields are unsupported almost everywhere: substitution policy, general product attributes, and the confirmation threshold. Cumulative ceilings are enforceable only where some party accumulates state across transactions, which five of the ten schemes examined do and the remainder do not. Most consequentially, virtual-card controls already enforce cumulative caps and merchant-category scope, and open-banking variable recurring payments enforce cumulative caps, that the new agent protocols omit, so agent authorization is in specific respects a regression against rails that preceded it. We release the coding protocol and evidence table, and retain version-pinned specification snapshots for audit.

Read PDF

Similar papers

#artificial intelligence Preprint Aug 2026

A Formal Analysis of Agent Payment Protocols

This work formalizes four representative agent payment protocols: x402, MPP, ACP, and AP2 in Tamarin, and constructs source-grounded models that capture each protocol's roles, state, trust assumptions, and lifecycle transitions.

Ke Jiang, Mo-Han Yu, Yuan-Yi-Chun-Min-Chieh Chang et al. · 0 citations
Preprint Sep 2026

Runtime Authorization for Resources Acquired by AI Agents

A provenance-bounded runtime authorization architecture that quarantines acquired outputs, resolves their actual capabilities from authenticated provider evidence through a versioned resolver, and activates them only through a current activation transaction that checks the resolved manifest, provenance, epochs, and a d...

Gen-Liang Zhu, Chu Wang Accentrust, Georgia Institute of Technology et al. · 0 citations
Preprint Aug 2026

Mandato: Protocol-Level Enforcement of Digitally Signed Mandates on AI Agent Actions with Cryptographically Chained Audit Trails

This work presents Mandato, a governance proxy that enforces digitally signed mandates on agent actions at the protocol level, and gives the mandate model and its decision semantics, the reference architecture as an MCP-transparent proxy with separated decision and enforcement points, and a mapping of the mechanism ont...

Giovanni Racioppi · 2 citations
#artificial intelligence Preprint Aug 2026

Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems

It is argued that agent security must be evaluated under an untrusted-model assumption: a correct system is one in which a fully prompt-injected agent still cannot exceed the authority explicitly delegated to it, and an authorization broker is implemented that closes the gap.

Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi · 0 citations
#artificial intelligence Preprint Sep 2026

NostrAgent: A Decentralized Identity and Delegation Architecture for Sovereign Agentic Systems

Autonomous AI agents increasingly act across organizational boundaries on behalf of human operators: they invoke third-party services, delegate subtasks to other agents, and pay for metered resources. Deploying such agents safely requires five capabilities that today live in separate systems: persistent identity, scope...

Oliver Aleksander Larsen, M. T. Moghaddam · 0 citations
Preprint Aug 2026

InterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents

The emerging Internet of Agents enables LLM-powered agents to discover peers, invoke tools, and delegate tasks across organizational boundaries. Existing protocols increasingly define how agents exchange messages, but not how an agent proves its identity, authorization, advertised capabilities, or accountability after...

Zhen-Hua Zou, Sheng Guo, Qiu-Yang Zhan et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.