Who decides what an AI agent may spend?
Agents can already buy things. The unresolved question is not whether they can transact — it is how a person or a firm grants one bounded authority, how that authority is checked before money moves, and what evidence exists afterwards. Four groups are answering that question at once: payment networks, standards bodies, AI platforms and regulators. They use the same words to mean different things.
The emerging stack has identity protocols, payment credentials, commerce protocols and payment rails, and they are being built quickly and well. What it does not yet have is a general-purpose authority layer: something that decides whether this particular action, at this moment, is within the authority a person actually granted. That is the layer mnd8t is building, and the reason this reference exists.
Everything here is a record of what exists, sourced to primary documents wherever one exists, with our own reading clearly marked as such. It is updated as the field moves.
Start here
The Agentic Authority Stack
The Agentic Authority Stack is a six-layer model for how an AI agent moves from delegated permission to completed financial action: authority, identity, credential, rail, commerce and governance.
Everything on this site is organised against these six layers. Read the stack from the bottom: each layer assumes the one beneath it has been answered, and most confusion in this field comes from an argument about one layer being conducted in the vocabulary of another. It is a lens, not a standard — use it, argue with it, or cite it against us.
The card networks have built parts of credential and rail. ACP and UCP have taken commerce. Trusted Agent Protocol and Web Bot Auth have taken identity. FIDO now holds the standards work spanning identity, credential and authority. Regulators are defining governance. The base of the stack — whether a specific proposed action is within the authority a principal granted — is where the work is chartered but not yet delivered. FIDO now holds the standards effort spanning identity, credential and authority, and no broadly adopted architecture yet provides the full lifecycle of dynamic, stateful delegated authority. Every layer above assumes that lifecycle exists.
The Agentic Authority Stack is version 1.0, published 8 September 2026. Quote it, adapt it, or place a technology in it — attribution to mnd8t.com/intelligence#agentic-authority-stack is all we ask. The version number moves when a layer is added, removed, or its question changes, so a citation stays checkable.
Where the decision sits
An authority decision happens between the agent forming an intention and anything moving money. The execution boundary is the part worth noticing: mnd8t decides and proves, and never holds funds, keys or payment credentials.
Latest in the tracker
- 8 September 2026Meta launches Muse, a personal agent that buys, with Stripe Link as the credential
- August 2026Mastercard publishes a Signals report on trust in agentic commerce
- 16 July 2026Ramp ships spend controls for AI token consumption
- 14 July 2026HM Treasury consults on modernising payment services regulation
Analyses
How this is written
- Primary sources. Every factual claim links to the specification, press release, standards body or draft that states it. Secondary coverage is used only where no primary source exists, and is labelled.
- Opinion is marked. Where we are reading rather than reporting, it appears under an mnd8t assessment heading and nowhere else.
- No competitor scoring. mnd8t is a policy engine, and most of what is described here is not a substitute for one. Where something genuinely overlaps with what we build, the analysis says so plainly rather than grading it.
- Corrections welcome. If something here is wrong or out of date, write to hello@mnd8t.com and it will be fixed and dated.
The authority layer
Identity tells you who the agent is. Credentials tell you what it can present. Commerce protocols let it transact, and payment rails move the money. None of those decides whether this specific action is within the authority the principal intended to grant — and a credential minted at issuance cannot, because the answer depends on state it cannot see: the budget already consumed, this counterparty's history, whether a person would have wanted to be asked.
mnd8t exists for that decision. A proposed payment is evaluated against a live, versioned mandate and answered approve, reject or escalate before any money moves — deterministically, with a rule-by-rule trace and no model in the decision path. You or your regulated provider execute; mnd8t proves what was authorised.