I have written on agentic governance ad nauseam (Agentic Commerce Economics and Governance, Governance in Payments, Machine to Machine Transactions: How to Resolve Trust and Governance Gaps). While I’m glad to see 3 new groups jump into the effort:
- JPMorganChase. Zack Anderson, chief data and analytics officer for global banking and payments: “everybody’s building for their slice of the pie. … Our view is really that it needs to be universal” (American Banker).
- Six banks. Bank of America, Capital One, Commonwealth Bank of Australia, ASB, ING and NatWest published five principles: transparency, safety, privacy and data, choice and interoperability (Building Trust in Agentic Commerce).
- A new protocol. The Agentic Financial Services Protocol (AFSP) v0.1, a Know Your Agent check for banks, is open for comment through November 16.
There are 2 aspects to these standards: agentic COMMERCE and Agentic Finance (where agents perform banking functions, act on bank data and perform bank like activiteies). Lets start with agentic commerce, here I am skeptical of these standards for three for 3 reasons.
1. Someone Has to Be the Cop
Readers of this blog know my position: trust requires a commercial construct or enforceable law (Understanding eIDAS Impact on Banking and Payments, Why Closed Chains Work Best for Banks). A standard needs a cop with an enforcement mechanism (ie “a stick”). Ask any framework five questions. Who gets to assume a given role? How are they registered? What happens when someone breaks the rules? What is the cost of a violation? Who owns the risk when things go wrong?
The bank paper answers none of them. Its own disclaimer: “Nothing in this paper requires the authors or other industry participants to take any particular action.” AFSP goes further, with an agent registry and certification. But its foundation is “targeted for formation in early 2027,” and until then a single vendor administers the protocol. Certification without liability is a badge, not a rule. Goldman asks the right questions: who owns fraud losses, chargebacks and returns, who bears liability for erroneous purchases, and who governs agent behavior (Eric Sheridan et al., Goldman Sachs, “Entering the Agentic AI Era for the Commerce Landscape,” Sep 2026). Principles do not answer them. Contracts do.
As I wrote in Part 2 – The Power of Bank Networks, card networks unlock the power of banking, the ability to assume risk, across all consumers and businesses. Two of their core functions of card networks are standardized contracts and certification with active enforcement. This “standardization” of commercial terms is far more important than the “easy” standardization of tech. The contract is the cop with a stick. You break the rules you pay the fine or get kicked off.
Networks are not the only commercial construct. Amazon sets rules for its marketplace. Google sets rules for its platform. Third-party networks like Amex, COF/DFS (Capital One and Discover), PayPal, Walmart and Taobao/Alipay can each write and enforce their own (Stripe/Advent – PayPal: My Thoughts). Note that Capital One signed voluntary principles while owning a network that can write binding ones.
Europe is the top offender against this rule of thumb. PSD2 and eIDAS each assumed technology alone would provide governance, and Europe regretted it every time (Europe’s Siege – Digital Sovereignty Strategy, Why eIDAS Will Fail in Banking). Connectivity is not governance.
Technically speaking we can see that Agents will find a way to work with anything they need. How do we hold them accountable for their actions and the value they create? A legal framework would take 20 years. A commercial framework is the only way.
2. Who Pays Sets the Standard
The economics of agentic are far from settled (Agentic Commerce – Inevitable or Unworkable?). Who pays the cost for all this AI? Not checkout. OpenAI walked away from Instant Checkout (Explaining the Death of OpenAI’s Instant Checkout) and Google pulled back from Buy for Me (Google Pulls Back From “Buy For Me”). The first real business model is advertising (Agentic Reality: Advertising).
Whoever pays the freight of AI has the heavy hand on standards. Today that is the merchant (Retail, Roles and Know Your Agent). The merchant stays merchant of record, owns fraud and disputes, and decides which agents it accepts.
Authorization follows the same logic. The entity owning the risk has the biggest say in the credential used to authorize the purchase. Verifiable Intent is just a stupid model here, as it lets the platform construct, hold and sign the mandate. The platform grades its own homework (EMVCo Enters the Intent Wars, Agentic Data Battle: Intent). No party holding the loss will accept that.
Banks would like a say, but they cannot tell consumers “we won’t support you when you buy this way.” Particularly when Amex is live with ACE and its message to cardmembers is that they are covered no matter what (American Express Breaks the Agentic Commerce Deadlock). As VGS put it this week, “American Express may find it easier to approve and provision an agentic token as they are the issuer, while Visa and Mastercard must promote adoption across their wide pool of issuing banks” (Timothy Chiodo, UBS, “Agentic Commerce Developments with VGS,” Oct 5, 2026).
3. Specialists Agents Need Governance, Not Protocols
We are in a period of flux. Big platforms and monolithic agents dominate. Yet the consumer successes are Instinct and Muse, and specialized agents will fill a large role (e.g., a travel specialist or someone you permit with your data). The technology of agent to agent collaboration is not the problem (A2A and AP2 Protocols). The governance around it is:
- Value exchange: measuring the value an agent creates and paying for it
- Permissions and authorization: what the consumer allowed, and who owns the risk
- Data privacy and permission: who sees what, and who consented
Privacy is self-explanatory. Authorization is covered by my many blogs. Value exchange is the hard one. Neither Google nor OpenAI is thrilled at the idea of paying specialized agents (because they want to deliver all the value). Thus, the friction with retailer specialized agents like Walmart’s Sparky. In my view Anthropic is aligned to enabling specialized agent, building for the merchant’s side of the counter (Anthropic’s New Agents: Picking the Right Side of the Counter). Exchanging value starts with measuring it (The Power to Price).
Recommendation for Banks – in Agentic Commerce
Focus on who owns the pricing and the risk. Today that is solidly the merchant. Banks would love a say in standards, but the only place their voice is effective is within the governance of the networks they created.
The biggest threat to banks (w/o bank collaboration) is Stripe, Cloudflare and others capable of setting the governance and value exchange rails for agent-to-agent commerce on X402 and stablecoins (X402 Foundation, MPP (and X402) – Solving the Internet’s “Original Sin”).
My example of the day. At Sessions, Stripe asked me if the networks would drop the fixed component of interchange to enable card payments under $1. Take debit at 120bps + $0.05: the ask is to drop the nickel. On a $0.50 purchase, the nickel is 10% of the ticket. The networks would love to accommodate. The issuers say no. This is just insane. Every payment issuers refuse is a payment that moves to x402.
Agentic Finance is Different
Everything above covers agentic commerce: an agent buying from a merchant. Here the merchant owns the risk, so the merchant sets the terms. Agentic finance is different. When an agent moves money, opens an account, or performs banking or financial planning activities, the bank owns the risk, so the bank should set the rules.
Here the bank is the cop. It knows the customer and is the “throat to choke” for regulators. Bank license confers great responsibility on how activities and services are governed and who can act on an account: authorize users, limits. Anderson made the point for treasury: “It’s pretty easy actually to create an agent that can move money. It’s hard to do it safely.” The controls he describes (limits, maker checker rules, approved counterparties) are “not that different from the controls we have now for humans” (American Banker).
AFSP fits better here. Its first use case is an agent opening a deposit account, a case where the bank does own the risk. That is the right problem. It still needs a cop: a registry with a stick, and a price for the bank’s work.
The rule from commerce still applies: the party owning the risk picks the credential. In finance, that party is the bank. As I argued in Is Know Your Agent (KYA) Really Necessary?, a bank does not need to know the agent. It needs to know what the customer permissioned, and it registers agents against its own terms.
Banks should put their standards effort in Agentic Finance and delegate Agentic Commerce to Networks. In commerce they are a guest. In finance they own the house. The starting point for action is in data access. Consumers need to know which agent they permissioned for which activity for how long. See related blog on Plaid/JPM.