A four-year follow-up to the Banking 4.1 thesis
AI agents can spendmoney. The hard partis proving they hadpermission.
Four years after Banking 4.1, agentic payments are here. The challenge now is not capability, it is authority.
In early 2022, I published two connected predictions about the direction of financial technology in Africa.
In This Decade will be massively and radically different in African Fintech, I argued that progress would not come from one technological silver bullet. It would come from deliberate choices: open and interoperable systems, real-time payments, embedded financial services, and infrastructure that was responsive to the needs of the society using it.
Six weeks later, in Hop on the spaceship and join the Banking 4.1 movement, I described Banking 4.1 as the move from “banking everywhere” to “banking, and transacting everywhere and for everyone.” I expected artificial intelligence, blockchain, cloud infrastructure, data, and embedded finance to become part of how financial products were built and delivered.
Four years later, the direction of those predictions is visible. Financial activity is moving beyond bank branches and dedicated banking interfaces. Payments are becoming embedded inside software, commerce, communication, and automated workflows.
What was less explicit in those essays was the next participant in the transaction: software itself.
AI systems are no longer limited to presenting information or helping a person make a decision. They are beginning to search, compare, negotiate, prepare orders, and initiate purchases on behalf of people and businesses. Agentic payments are therefore a continuation of the Banking 4.1 thesis, but they also expose its next unresolved problem.
If banking and transacting can happen everywhere, how do we preserve human authority when the human is no longer operating every step?
That is the question this follow-up addresses.
For most of the internet’s history, the person choosing a product, approving a purchase, and making a payment was assumed to be present at the same moment.
A click on “Buy” did several jobs at once. It expressed intent. It authorized the merchant. It selected a payment method. It created evidence that the customer had acted.
AI agents separate these actions.
An agent may discover an option today, compare it with alternatives tomorrow, and prepare a payment later. It may act across several merchants, currencies, accounts, and payment systems. The person may be present for some decisions and absent for others.
This changes the central question in digital payments.
The question is no longer only, “Can this transaction be processed?”
It is also, “Who gave this system permission to act, what exactly did they permit, and can every party prove it afterward?”
That is the real infrastructure problem behind agentic payments.
The market is converging on authority
The industry is approaching this problem from different directions, but the underlying pattern is becoming consistent.
Airwallex describes an agentic wallet as three layers: an intent layer where the agent decides, a deterministic policy layer where hard rules are enforced, and a settlement layer where payment executes and is recorded. Its Airi product is a one-click wallet today, with fuller agentic capabilities presented as a roadmap.
Google’s Agent Payments Protocol, or AP2, uses typed mandates to record who approved a purchase, which limits apply, and how the resulting transaction is tied back to the user’s intent.
OpenAI’s Agentic Commerce Protocol keeps merchants in control of orders, payments, fulfillment, returns, and customer relationships. Its delegated payment model uses credentials constrained by amount and expiry rather than giving an agent unrestricted access to a stored card.
Visa’s Trusted Agent Protocol focuses on helping merchants distinguish an authorized agent from an anonymous or malicious bot. Mastercard’s Verifiable Intent links identity, intent, and action into an auditable record that can support fraud reviews and disputes.
These efforts differ in scope. Some address commerce messages, some payment credentials, some agent identity, and some proof of authorization. Yet they point toward the same conclusion:
AI can be probabilistic. Financial authority cannot.
An agent may reason, rank, negotiate, and recommend. The system controlling money must still enforce exact rules.
A capable agent is not necessarily an authorized agent
Suppose someone asks an AI agent:
Find me a flight to Nairobi for less than $650.
The agent may be able to search routes, compare baggage policies, account for departure times, and recommend an itinerary. None of that proves it has permission to pay.
Before money moves, the system still needs answers to several separate questions:
- Which person or business authorized the agent?
- Is the task limited to flights, or can the agent buy anything related to the trip?
- Is $650 a total ceiling or a per-transaction ceiling?
- Which merchants, countries, currencies, and dates are allowed?
- Must the user approve the final itinerary and price?
- What happens if the fare changes, the payment fails, or the airline issues only a partial refund?
A natural-language instruction is useful input. It is not, by itself, a payment control.
Prompts are open to interpretation. Payment policies must be testable. “Find a reasonable flight” may guide an agent’s search, but it cannot replace an exact spend ceiling, an expiry time, a merchant rule, or an approval requirement.
This distinction matters because the risk is not limited to a malicious agent. A legitimate agent can misunderstand a request. A merchant page can contain a hostile instruction. A model can degrade. A price can change between selection and payment. A retry can create a duplicate charge.
The payment system must remain safe even when the model is wrong.
Five requirements for an agentic payment
An agentic payment needs a chain of accountable authority. At minimum, that chain should contain five elements.
1. An accountable principal
Every agent must act for a verified person or organization. “Know Your Agent” can help establish which software process is making a request, but agent identity alone is incomplete. A merchant also needs confidence that the agent is acting for a real principal with the authority to make that purchase.
2. A bounded mandate
The mandate should translate human intent into explicit permissions. It should define the task, spending limit, currency, permitted merchants or categories, duration, and approval conditions.
A mandate is stronger than a chat transcript because it is structured, time-bound, and revocable.
3. Deterministic policy enforcement
The agent should not decide whether it has exceeded its own authority. That decision belongs to a separate policy layer that does not negotiate, infer exceptions, or respond to persuasive text.
If the purchase exceeds the ceiling, falls outside the allowed merchant scope, or arrives after expiry, it should be blocked.
4. A scoped payment credential
Agents should not receive reusable card or account credentials. A payment credential should be limited to the approved merchant, amount, purpose, and time window. Where practical, it should be single-use.
If that credential is exposed, its usefulness outside the approved transaction should be close to zero.
5. A durable record and a recovery path
Payment is not complete when authorization succeeds. The user, merchant, payment provider, and support team need a record of what the agent was asked to do, what it selected, which rules passed, what was paid, and what happened afterward.
The user must also be able to pause or revoke future authority without losing the evidence needed for refunds, disputes, fraud reviews, or support.
Autonomy is a ladder, not a switch
“Agentic” is often treated as another word for fully autonomous. That framing compresses several different product states into one.
An agent can:
- Research and recommend.
- Prepare an order for review.
- Request approval for a specific payment.
- Act within a standing mandate for a narrow, repeatable task.
Each step delegates more authority and requires stronger controls.
The responsible starting point for consequential consumer payments is clear human confirmation before funds move. Greater autonomy should be earned task by task, supported by reliable identity, predictable merchant behavior, low-risk payment instruments, clear dispute rights, and evidence from prior outcomes.
Convenience should not require users to surrender visibility.
Cross-border payments make the problem harder
Much of the agentic commerce discussion starts with a familiar shopper, a familiar card, and a familiar merchant. That is a narrow version of the problem.
For Africans and the diaspora, a single purchase may cross currencies, jurisdictions, payment providers, and regulatory boundaries. A customer may earn in one currency, hold value in another, pay a merchant in a third country, and depend on a payment route whose availability changes by location or customer type.
The agent may be able to find the best product. It still cannot manufacture eligibility, regulatory permission, merchant acceptance, foreign exchange liquidity, or a reliable dispute process.
This means agentic payment infrastructure for cross-border users needs more than a faster checkout.
It must preserve context:
- who the user is;
- what the agent was authorized to do;
- which payment routes were actually available;
- which fees, exchange rates, and restrictions applied;
- which party is responsible when the outcome differs from the instruction.
This is where the opportunity for Africa becomes specific. The continent does not need a thin AI interface placed on top of fragmented payment systems. It needs authority and payment context to remain intact as a transaction moves across them.
An agent can simplify complexity for the user. The underlying system must still account for that complexity precisely.
The interface must make authority visible
Security architecture matters, but users will experience agentic payments through controls and records.
Before delegating a payment task, a person should be able to answer, at a glance:
- What is the agent allowed to do?
- How much can it spend?
- Where can it spend?
- When does its authority end?
- Will it ask before payment?
- How do I stop it?
- Where will I see the receipt?
- What can I do if the result is wrong?
If these answers are hidden inside terms, prompts, or technical logs, the system has not made authority understandable.
At Poza, we summarize this principle as: Delegate the task. Keep the authority.
Our public concept begins with controls people already understand: a defined task, a spending ceiling, merchant scope, an expiry, approval before payment, and a receipt that can be reviewed. These are simple product ideas, but they reflect the deeper requirements emerging across the payment industry.
We are not treating intelligence as permission. We are treating permission as infrastructure.
Agentic payments will succeed when they make financial action easier without making it less accountable. The systems that earn trust will not be the ones that let agents spend most freely. They will be the ones that let people define authority clearly, see it in use, and take it back.
Further reading
- Airwallex: Agentic wallets explained
- Google Developers: Developer’s Guide to AI Agent Protocols
- OpenAI: Instant Checkout and the Agentic Commerce Protocol
- OpenAI Developers: Delegated Payment Spec
- Visa Developer: Trusted Agent Protocol
- Mastercard: How Verifiable Intent builds trust in agentic AI commerce