We use cookies

Essential cookies keep the site working. Optional cookies help us understand site traffic and improve Poza. We never include email addresses or form contents. Cookie details

Skip to content
Poza
Product
CardsSpending, with your rules.MoneyYour balances and activity.InvestingExplore what is in development.Ask PozaAssistance. With your approval.
How it works Trust Insights
Join early access
CardsMoneyInvestingAsk Poza
How it worksTrustInsightsCompany
Insights Agentic payments AI agents can spend money. The hard part is proving they had permission.
Core thesis

AI can be probabilistic.
Financial authority cannot.

On this page The market is converging on authorityA capable agent is not necessarily an authorized agentFive requirements for an agentic paymentAutonomy is a ladder, not a switchWhy agentic payments are harder in AfricaThe interface must make authority visibleFurther reading

Share this essay

A four-year follow-up to the Banking 4.1 thesis

Your browser does not support embedded audio.

AI agents can spendmoney. The hard partis proving they hadpermission.

Four years after Banking 4.1, agentic payments are here. The challenge now is not capability, it is authority.

10 min read August 15, 2026 Agentic payments

In early 2022, I published two connected predictions about the direction of financial technology in Africa.

In This Decade will be massively and radically different in African Fintech, I argued that progress would not come from one technological silver bullet. It would come from deliberate choices: open and interoperable systems, real-time payments, embedded financial services, and infrastructure that was responsive to the needs of the society using it.

Six weeks later, in Hop on the spaceship and join the Banking 4.1 movement, I described Banking 4.1 as the move from “banking everywhere” to “banking, and transacting everywhere and for everyone.” I expected artificial intelligence, blockchain, cloud infrastructure, data, and embedded finance to become part of how financial products were built and delivered.

Four years later, the direction of those predictions is visible. Financial activity is moving beyond bank branches and dedicated banking interfaces. Payments are becoming embedded inside software, commerce, communication, and automated workflows.

What was less explicit in those essays was the next participant in the transaction: software itself.

AI systems are no longer limited to presenting information or helping a person make a decision. They are beginning to search, compare, negotiate, prepare orders, and initiate purchases on behalf of people and businesses. Agentic payments are therefore a continuation of the Banking 4.1 thesis, but they also expose its next unresolved problem.

If banking and transacting can happen everywhere, how do we preserve human authority when the human is no longer operating every step?

That is the question this follow-up addresses.

Delegated purchasing is not new.

Long before AI agents, people relied on other people to act on their behalf. A personal secretary might arrange a trip, book flights, reserve accommodation, purchase supplies, and manage the resulting receipts. Travel agents, brokers, household staff, and procurement teams have performed similar roles for generations.

What was scarce was not delegation itself. It was access to capable assistance.

For much of history, having someone continuously available to organize information, coordinate plans, and execute purchases was largely reserved for wealthy individuals and sufficiently large organizations. AI agents could make a version of that assistance available to far more people.

A useful way to think about an agent is therefore as a personal secretary. You give it an objective, provide relevant context, and allow it to complete a series of connected tasks on your behalf.

You might ask it to plan a trip to Nairobi, find a suitable flight and hotel, stay within a total budget, and seek approval before booking anything non-refundable.

A capable secretary would not need instructions for every search, comparison, form, and phone call. They would exercise judgment within the assignment. But their competence would not give them unlimited authority.

Even if you trusted them, you would still define boundaries. You might give them access to a particular account or card, establish a budget, restrict what it could be used for, and identify decisions that required your approval. A more sophisticated secretary might need less procedural guidance, but they would still need to understand the intended outcome and the limits of their mandate.

There is a Shona saying: kuudza mwana hupedzisira.

It means that when you give someone an instruction, you must carry the instruction through to its conclusion. You should not assume that the other person will infer every condition, exception, or consequence that exists only in your mind.

The saying places responsibility on the person giving the instruction as well as the person carrying it out. If an important boundary was never communicated, the resulting mistake cannot be understood only as a failure of execution.

This principle becomes especially important when an instruction grants access to money. “Plan my trip to Nairobi” communicates an objective. It does not, by itself, establish how much may be spent, which payment method may be used, whether the booking must be refundable, or which decisions require further approval.

The agent may determine how to achieve the objective. The payment system must determine whether each proposed action remains within the authority granted by the user.

This is where agentic payments differ from the delegation that payment systems have historically tolerated.

A secretary could use an employer’s card, but the payment network would usually see only that valid card credentials had been presented. It would not necessarily know who had been delegated the task, what they had been asked to accomplish, or whether the resulting purchase remained within their instructions.

Most consumer payment interfaces similarly collapsed several roles into one moment. The person selecting the product, approving the purchase, entering the payment credentials, and receiving the result was generally treated as the same participant.

AI agents separate those roles more visibly and at a much larger scale.

An agent may discover an option today, compare it with alternatives tomorrow, and prepare a payment later. It may act across several merchants, currencies, accounts, and payment systems. The person may be present when establishing the mandate but absent when the agent encounters the transaction that satisfies it.

The secretary analogy also has limits. A human secretary operates within a continuing relationship shaped by professional expectations, social judgment, and personal accountability. An AI agent has no inherent loyalty or independent duty to protect the user. It may misunderstand an instruction, act on incorrect information, or be influenced by hostile content encountered while completing the task.

Its financial authority must therefore exist outside the model.

The central question is no longer only, “Can this transaction be processed?”

It is also, “Did the user give the agent a sufficiently complete mandate, did this action remain within that mandate, and can every party prove it afterward?”

That is the real infrastructure problem behind agentic payments.

The market is converging on authority

The industry is approaching this problem from different directions, but the underlying pattern is becoming consistent.

Airwallex describes an agentic wallet as three layers: an intent layer where the agent decides, a deterministic policy layer where hard rules are enforced, and a settlement layer where payment executes and is recorded. Its Airi product is a one-click wallet today, with fuller agentic capabilities presented as a roadmap.

Google’s Agent Payments Protocol, or AP2, uses typed mandates to record who approved a purchase, which limits apply, and how the resulting transaction is tied back to the user’s intent.

OpenAI’s Agentic Commerce Protocol keeps merchants in control of orders, payments, fulfillment, returns, and customer relationships. Its delegated payment model uses credentials constrained by amount and expiry rather than giving an agent unrestricted access to a stored card.

Visa’s Trusted Agent Protocol focuses on helping merchants distinguish an authorized agent from an anonymous or malicious bot. Mastercard’s Verifiable Intent links identity, intent, and action into an auditable record that can support fraud reviews and disputes.

These efforts differ in scope. Some address commerce messages, some payment credentials, some agent identity, and some proof of authorization. Yet they point toward the same conclusion:

AI can be probabilistic. Financial authority cannot.

An agent may reason, rank, negotiate, and recommend. The system controlling money must still enforce exact rules.

A capable agent is not necessarily an authorized agent

Suppose someone asks an AI agent:

Find me a flight to Nairobi for less than $650.

The agent may be able to search routes, compare baggage policies, account for departure times, and recommend an itinerary. None of that proves it has permission to pay.

Before money moves, the system still needs answers to several separate questions:

  1. Which person or business authorized the agent?
  2. Is the task limited to flights, or can the agent buy anything related to the trip?
  3. Is $650 a total ceiling or a per-transaction ceiling?
  4. Which merchants, countries, currencies, and dates are allowed?
  5. Must the user approve the final itinerary and price?
  6. What happens if the fare changes, the payment fails, or the airline issues only a partial refund?

A natural-language instruction is useful input. It is not, by itself, a payment control.

Prompts are open to interpretation. Payment policies must be testable. “Find a reasonable flight” may guide an agent’s search, but it cannot replace an exact spend ceiling, an expiry time, a merchant rule, or an approval requirement.

This distinction matters because the risk is not limited to a malicious agent. A legitimate agent can misunderstand a request. A merchant page can contain a hostile instruction. A model can degrade. A price can change between selection and payment. A retry can create a duplicate charge.

The payment system must remain safe even when the model is wrong.

A hand-drawn permission ring, policy gate, scoped key, and receipt connected by a reversible orange thread
A payment mandate needs bounded authority, deterministic enforcement, a scoped credential, and a path back to the person who granted permission.

Five requirements for an agentic payment

An agentic payment needs a chain of accountable authority. At minimum, that chain should contain five elements.

1. An accountable principal

Every agent must act for a verified person or organization. “Know Your Agent” can help establish which software process is making a request, but agent identity alone is incomplete. A merchant also needs confidence that the agent is acting for a real principal with the authority to make that purchase.

2. A bounded mandate

The mandate should translate human intent into explicit permissions. It should define the task, spending limit, currency, permitted merchants or categories, duration, and approval conditions.

A mandate is stronger than a chat transcript because it is structured, time-bound, and revocable.

3. Deterministic policy enforcement

The agent should not decide whether it has exceeded its own authority. That decision belongs to a separate policy layer that does not negotiate, infer exceptions, or respond to persuasive text.

If the purchase exceeds the ceiling, falls outside the allowed merchant scope, or arrives after expiry, it should be blocked.

4. A scoped payment credential

Agents should not receive reusable card or account credentials. A payment credential should be limited to the approved merchant, amount, purpose, and time window. Where practical, it should be single-use.

If that credential is exposed, its usefulness outside the approved transaction should be close to zero.

5. A durable record and a recovery path

Payment is not complete when authorization succeeds. The user, merchant, payment provider, and support team need a record of what the agent was asked to do, what it selected, which rules passed, what was paid, and what happened afterward.

The user must also be able to pause or revoke future authority without losing the evidence needed for refunds, disputes, fraud reviews, or support.

Autonomy is a ladder, not a switch

“Agentic” is often treated as another word for fully autonomous. That framing compresses several different product states into one.

An agent can:

  1. Research and recommend.
  2. Prepare an order for review.
  3. Request approval for a specific payment.
  4. Act within a standing mandate for a narrow, repeatable task.

Each step delegates more authority and requires stronger controls.

The responsible starting point for consequential consumer payments is clear human confirmation before funds move. Greater autonomy should be earned task by task, supported by reliable identity, predictable merchant behavior, low-risk payment instruments, clear dispute rights, and evidence from prior outcomes.

Convenience should not require users to surrender visibility.

Why agentic payments are harder in Africa

Agentic payments in Africa are harder because a single transaction may cross currencies, jurisdictions, payment providers, identity systems, and regulatory boundaries before it settles.

Much of the agentic commerce discussion starts with a familiar shopper, a familiar card, and a familiar merchant. That is a narrow version of the problem.

For Africans and the diaspora, a single purchase may cross currencies, jurisdictions, payment providers, and regulatory boundaries. A customer may earn in one currency, hold value in another, pay a merchant in a third country, and depend on a payment route whose availability changes by location or customer type.

The agent may be able to find the best product. It still cannot manufacture eligibility, regulatory permission, merchant acceptance, foreign exchange liquidity, or a reliable dispute process.

This means agentic payment infrastructure for cross-border users needs more than a faster checkout.

It must preserve context:

  • who the user is;
  • what the agent was authorized to do;
  • which payment routes were actually available;
  • which fees, exchange rates, and restrictions applied;
  • which party is responsible when the outcome differs from the instruction.

This is where the opportunity for Africa becomes specific. The continent does not need a thin AI interface placed on top of fragmented payment systems. It needs authority and payment context to remain intact as a transaction moves across them.

An agent can simplify complexity for the user. The underlying system must still account for that complexity precisely.

A hand-drawn verified transaction passing through three policy gates while retaining its authorization seal
Cross-border execution becomes safer when identity and permission context travel with the transaction instead of being reconstructed at every boundary.

The interface must make authority visible

Security architecture matters, but users will experience agentic payments through controls and records.

Before delegating a payment task, a person should be able to answer, at a glance:

  • What is the agent allowed to do?
  • How much can it spend?
  • Where can it spend?
  • When does its authority end?
  • Will it ask before payment?
  • How do I stop it?
  • Where will I see the receipt?
  • What can I do if the result is wrong?

If these answers are hidden inside terms, prompts, or technical logs, the system has not made authority understandable.

At Poza, we summarize this principle as: Delegate the task. Keep the authority.

Our public concept begins with controls people already understand: a defined task, a spending ceiling, merchant scope, an expiry, approval before payment, and a receipt that can be reviewed. These are simple product ideas, but they reflect the deeper requirements emerging across the payment industry.

We are not treating intelligence as permission. We are treating permission as infrastructure.

Agentic payments will succeed when they make financial action easier without making it less accountable. The systems that earn trust will not be the ones that let agents spend most freely. They will be the ones that let people define authority clearly, see it in use, and take it back.

Further reading

  • Airwallex: Agentic wallets explained
  • Google Developers: Developer’s Guide to AI Agent Protocols
  • OpenAI: Instant Checkout and the Agentic Commerce Protocol
  • OpenAI Developers: Delegated Payment Spec
  • Visa Developer: Trusted Agent Protocol
  • Mastercard: How Verifiable Intent builds trust in agentic AI commerce

Poza agent payment features discussed here are concepts in development, not a promise of current availability. Product availability varies by location, eligibility, and programme.

KZ

Written by

Kudzaishe George Zharare

Founder and CEO of Poza
Earlier essays

Authority storyboard

Diagrams following the essay from delegated intent through policy, payment and durable proof.

Systems view
01IdentityVerifiable identity layer 02MandateUser intent and permissions 03SettlementInteroperable rails 04ProofCryptographic assurance
TX 9381KE → NGSETTLED
01IdentityOK
TX 9383ZA → KEPENDING
02MandateOK
Cross-border corridors are systems, not events.
Delegated task · 01

The personal secretary becomes widely available.

TRIP BRIEFNAIROBI
Plan my trip to Nairobi. Find a suitable flight and hotel.
Total budget
≤ $650
Payment method
Travel credential
Booking rule
Refundable only
Final action
Ask before paying
OBJECTIVE RECEIVEDAUTHORITY BOUNDED

Competence can reduce procedural guidance. It does not remove the need for a mandate.

Instruction · 02

Carry the instruction through to its conclusion.

kuudza mwana hupedzisiraShona proverb
  1. 01ObjectivePlan the trip
  2. 02BoundaryStay under $650
  3. 03ExceptionRefundable bookings
  4. 04ConsequenceAsk before payment
INCOMPLETE PROMPTCOMPLETE MANDATE
Role separation · 03

AI separates decisions that payment interfaces once collapsed.

01PRINCIPALDefines the outcome
grants mandate
02AGENTSearches and selects
requests action
03POLICYChecks exact authority
issues scope
04PAYMENTExecutes and records
Capability≠Authority
Market scan · 04

Different protocols are converging on authority.

01AirwallexIntent · policy · settlement
02Google AP2Typed mandates
03OpenAI ACPScoped credentials
04Visa TAPTrusted agent identity
05MastercardVerifiable intent
SHARED CONCLUSIONFinancial authority must be exact.
IDENTITYINTENTPOLICYPROOF
Authorization test · 05

A capable agent is not necessarily authorized.

THE AGENT CAN

Search routes

Compare baggage

Rank departure times

Recommend an itinerary

THE SYSTEM MUST PROVE

Principal verified

Purpose allowed

Total ≤ $650

Final approval present

PROPOSED PAYMENT$612.40AWAITING HUMAN APPROVAL

Natural language guides the search. Deterministic policy controls the money.

Authority chain · 06

Five requirements connect intent to recovery.

  1. 01
    Accountable principalWho granted authority
  2. 02
    Bounded mandateWhat, where and how much
  3. 03
    Policy enforcementExact rules outside the model
  4. 04
    Scoped credentialLimited purpose and lifetime
  5. 05
    Record and recoveryEvidence, revocation and recourse
CHAIN STATUSAll requirementsREQUIRED
Delegation model · 07

Autonomy is a ladder, not a switch.

  1. 04
    Standing mandateNarrow, repeatable task
    MORE AUTHORITY
  2. 03
    Request approvalSpecific payment prepared
  3. 02
    Prepare orderUser reviews the result
  4. 01
    ResearchRecommend only
    LESS AUTHORITY
HUMAN CONFIRMATIONBEFORE FUNDS MOVE
Cross-border context · 08

Permission must survive every boundary.

IDENTITYMANDATEFXELIGIBILITYPROOF
ZAZAR → USD → KESKECONTEXT INTACT
Product principle · 09

The interface must make authority visible.

AGENT TASKACTIVE

Nairobi trip

Spend ceiling
$650 total
Merchant scope
Airlines and hotels
Expires
18 Aug · 18:00
Before payment
Approval required
REVOKE AUTHORITYREVIEW RECEIPTS
Delegate the task.
Keep the authority.
Durable proof · 10

Payment ends with evidence and a recovery path.

PRINCIPALVERIFIED
MANDATEWITHIN SCOPE
POLICYALL RULES PASSED
PAYMENTSETTLED
RECORDREVIEWABLE
RECOVERYAVAILABLE
POZA FIELD NOTEIntelligence can propose an action.
Authority must remain provable.
01 / 11
Systems overview

Built for a borderless future

Move globally. Keep control.

Get early access
Next in this essayThe market is converging on authority Continue reading
Poza

Payment decisions
at the speed of compute.

Product

CardsMoneyInvestingAsk Poza

Poza

How it worksTrustInsightsCompany

Say hello

support@poza.coLinkedInXEarly access

Poza is a financial technology company, not a bank. Financial products are provided through partners where required. Access, currencies, routes, fees and features depend on your country, eligibility and programme. Investing involves risk. Product screens use sample data.

© 2026 Poza
TermsPrivacyGitHub