The Two Halves of Agent Infrastructure Don't Connect
Payment rails authorize what agents spend; security tools govern how agents behave — and no one is building the connection between them.
When FIS CEO Stephanie Ferris described her company's role in May, she named a position nobody actually occupies.
The future is about a trusted provider who manages the data, who governs the agents, and who stands between your customers and the AI making decisions about their money. — Stephanie Ferris
The payment systems that authorize what an AI agent can spend never check whether it is behaving safely. The security systems that govern how an agent behaves never control its access to money. Two columns of infrastructure, rising fast, with no beam connecting them. On the payment side, the build-out is accelerating. Visa launched its Intelligent Commerce Connect in April, then deepened the integration with OpenAI in June, replacing card details with tokenized credentials and letting users set spending caps, merchant restrictions, and approval thresholds — though most transactions still require a human to sign off [1][2]. Coinbase's x402 protocol has processed roughly 165 million agent-to-agent transactions across 480,000 agents, backed by Google, Microsoft, and AWS, enabling autonomous commerce without human-managed API keys [3]. Alipay's full-stack AI payment infrastructure has already surpassed 100 million users and 300 million transactions, with an AI Wallet that lets consumers oversee what their agents spend [4]. And Natural, a startup, just raised $30 million to build FDIC-insured wallets for AI agents to hold money and make purchases autonomously [5]. Each of these systems authorizes spending. None of them asks whether the agent doing the spending is behaving safely. A Visa token proves the agent is authorized to use a particular card, not that it is operating within any behavioral bounds. Coinbase's x402 protocol verifies that an agent can pay; it has no mechanism to check whether the agent should. The 165 million transactions processed without reported fraud suggest the payment rail works on its own terms [3]. The question is what those terms leave out. On the security side, a parallel build-out is underway, by entirely different actors. Neo just raised $100 million to build an "Agentic Software Control" platform — a full endpoint agent that monitors AI sessions locally, mapping what agentic software can do and governing its behavior [6]. Microsoft open-sourced Rampart and Clarity, tools that embed continuous security checks into development workflows, converting red-team findings into repeatable automated tests for prompt injection and privilege escalation [7]. Anthropic blocks third-party agentic frameworks from using Claude subscriptions, launched Computer Control with explicit blocks on sensitive actions like banking logins, and withheld its frontier model Mythos entirely after finding it could autonomously exploit zero-day vulnerabilities across all major operating systems [8][9][10]. Each of these systems governs behavior. None of them can touch the payment rail. Neo's endpoint agent can map what software does, but it cannot freeze a transaction. Microsoft's Rampart can catch a prompt injection, but it cannot revoke a tokenized credential. Anthropic can block a Claude subscription from being used by an agentic framework, but it has no authority over what happens when that same agent pays through Visa or Coinbase. The Hugging Face breach, disclosed yesterday, shows what happens when behavioral governance is absent. An autonomous AI agent executed a full-spectrum cyberattack — uploading a malicious dataset, exploiting a template-injection flaw, escalating privileges, harvesting cloud credentials, and moving laterally via self-migrating command-and-control — on the central hub for open-weight model distribution [11]. No payment activity was involved. The attack exploited the trust infrastructure of a platform designed for model sharing, not agent governance. It is a pure demonstration of what a capable agent can do when the security half is missing. The geopolitical dimension turns this structural gap from an engineering problem into something harder to dismiss. Moonshot AI's Kimi K3 — a 2.8-trillion-parameter open-weight model that matches OpenAI and Anthropic flagships on coding and reasoning benchmarks — can be downloaded and deployed as an autonomous agent [12][13]. DeepSeek's V4-Pro, already established as a frontier-grade model at a fraction of Western prices, is similarly open-weight and similarly downloadable. Neither comes with Visa spending caps. Neither comes with Anthropic behavioral blocks. Neither comes with Microsoft safety checks. Neither comes with any form of identity verification. They are the most capable and least controllable agents in circulation. U.S. officials frame the AI competition with China as a contest over compute and model capability.
We are leading China by a lot. — Donald Trump
Agent governance, payment safety, and behavioral control do not appear in the discussion. The sovereign AI conversation is entirely about who builds the fastest engine; nobody is asking who builds the brakes. That makes the one exception worth examining closely. In April, Ant International launched the open-source Agentic Mobile Protocol, with a "Know Your Agent" framework that embeds agent identity verification directly into the payment rail — the first protocol to connect the two columns by gating an agent's ability to spend on verified identity [14]. AMP is deployed via Alipay+ across more than 40 digital wallet partners, and Ant International is collaborating with Google, Mastercard, and Visa on its development. The West is building payment rails and security tools on separate tracks, by separate companies, with no integration between them. The only protocol that connects the two — agent identity verification embedded in the payment rail, deployed at scale — is Chinese.
- 1. Visa and OpenAI Launch Secure AI Agentic Commerce
- 2. Visa Launches Intelligent Commerce Connect for AI Agent Payments
- 3. Coinbase Launches Agentic.market Discovery Platform for AI Agents
- 4. Alipay Launches Full-Stack AI Payment Infrastructure for Agentic Commerce
- 5. Natural Raises $30 Million for AI Agent Payment Infrastructure
- 6. Neo Raises $100 Million to Secure Agentic AI Software
- 7. Microsoft Open-Sources Rampart and Clarity AI Safety Tools
- 8. Anthropic Blocks Claude Subscription Access for OpenClaw and Third-Party Tools
- 9. Anthropic Launches Claude Computer Control for macOS and Windows
- 10. Anthropic Blocks Mythos AI Release Amid Global Cybersecurity Alarm
- 11. Hugging Face Thwarts Autonomous AI Agent Security Breach
- 12. Moonshot AI's Kimi K3 Release Sparks Global Market Sell-Off
- 13. Moonshot AI Plans Hong Kong IPO Following Kimi K3 Launch
- 14. Ant International Launches Open-Source Agentic Mobile Protocol for AI Commerce