Markets Closed
Global Markets
S&P 500 7,443.28 ▼ -0.2% DOW 51,839.26 ▼ -0.6% NASDAQ 25,508.07 ▼ -0.0% RUSSELL 2K 2,942.43 ▼ -0.7% VIX 18.65 ▼ -0.6% GOLD 4,048.5 ▲ +1.0% CRUDE OIL 82.24 ▼ -1.2% EUR/USD 1.14 ▼ -0.1% BTC 65,480 ▲ +1.1% ETH 1,924.89 ▲ +2.6%
Fintech

AI payment agents need controls at checkout, Meridian founder says

Scott Lee argues that delegated authority for AI agents does not by itself prove that a final payment still matches a customer’s intent.

Rafael Ortiz

By Rafael Ortiz · Fintech Correspondent

· 3 min read

AI agents can reach checkout with valid credentials while still triggering a payment that differs from the customer’s mandate, according to Scott Lee, founder of Meridian Verity Group. In an opinion published on Finextra, Lee said banks, payment service providers and commerce platforms need controls that evaluate the precise economic effect of an automated purchase at the point it is about to be committed.

Lee used a hypothetical purchase to illustrate the risk: a customer authorises an AI agent to buy one laptop from a named seller, on an approved marketplace, for no more than £1,500, with delivery to a London office. By checkout, the agent may still have a verified identity, a valid delegation credential and a usable payment credential, while the seller, amount, add-on terms or delivery destination have changed.

The issue, Lee argued, is that identity, delegated authority and payment protocols answer different questions. They can confirm who is acting, what authority was granted, and how an instruction will be sent and settled. They do not necessarily confirm that the final transaction still conforms to the customer’s permission at the last point before money moves or an order is placed.

From permission to acceptance

Lee proposed a control layer he called “Action Acceptance”, enforced through an “Acceptance Plane”. In his formulation, the system that will create the economic effect should decide whether the exact transaction is acceptable, using the evidence produced by identity systems, policy tools, fraud controls, agent frameworks and payment networks.

For a purchase, Lee said the final action should be represented in a deterministic form. That representation could include the actor, merchant or payee, amount and currency, cart or line-item digest, recurring terms, delivery or beneficiary destination, policy version, validity window, nonce or idempotency key, and the external consequence that will be recorded.

The accepting system would then return one of three outcomes: accept, hold or refuse. Lee defined a hold as the appropriate state when required evidence is missing, stale, incomplete or disputed. He said a hold should carry a reason code, identify the missing dependency, assign an owner, set an expiry and define retry or escalation rules.

Why logs may not be enough

Lee also warned that an agent’s planning process may rely on facts that do not reach the payment service at the time of execution. A model may read the customer instruction, mandate, merchant record, cart, risk status and policy, then submit only the write parameters needed to make the payment. In that case, the facts that justified the payment may be available later in transcripts or logs, while absent from the commit path itself.

To address that gap, Lee said the service that owns the economic effect should define the mandatory dependencies for each protected action. Those dependencies may require exact matches, such as a specific payee or cart digest, or predicate checks, such as confirming that the total remains within an approved limit.

Lee said the strongest design is for the target system to validate required conditions and commit the effect within the same atomic boundary. Where that is unavailable, he said reservation or saga-based designs can reduce risk, although they carry different guarantees.

The governance implications are likely to draw attention as agentic commerce expands. Lee noted that EU AI Act obligations are taking effect and that the PSD3 and Payment Services Regulation package is moving toward formal adoption, creating sharper scrutiny of fraud controls, liability and reconstructable evidence. He said decision records should preserve the action digest, authority reference, policy version, dependencies checked, evidence versions, replay state, outcome and reason code.

This story draws on original reporting from Finextra Research.

More from Fintech

All Fintech →