Urgent.News

What's breaking now, across thousands of outlets.

AI

Fed’s Waller Says AI Shopping Changes What Banks Need to Authenticate

The first rule of online payments is to prove that the person trying to pay is allowed to do so. Artificial intelligence is forcing banks and payments networks to add another layer. Federal Reserve Gov. Christopher Waller said Tuesday (Sept. 29) that agentic commerce changes the authentication problem because an AI system may be acting […] The post Fed’s Waller Says AI Shopping Changes What Banks…

Fed’s Waller Says AI Shopping Changes What Banks Need to Authenticate

Federal Reserve Governor Christopher Waller highlighted Tuesday that AI-driven commerce introduces fresh challenges for banks and payment systems in terms of authentication. In his Sibos speech, Waller emphasized the need to prove an AI system's authority to execute payments on behalf of consumers or businesses, rather than just assisting them. This shift in authentication requirements could prove to be a critical infrastructure hurdle for agentic commerce.

Visa, Mastercard, and PayPal have already begun developing technologies enabling software agents to participate in shopping and payment processes. However, the banks assessing these transactions may require more than just a valid payment credential. They may also need proof that the consumer or company has explicitly authorized that specific agent to act within predefined limits.

This situation could give rise to a novel payment object: a machine-readable record of delegated authority, akin to a digital power of attorney. This record could specify the authorized agent, the scope of transactions, the payment method, and the authority's validity period.

Several industry entities are already progressing towards this direction. For instance, Visa's Intelligent Commerce technology can link payment credentials to a specific agent and enforce controls ensuring purchases align with the user's instructions. Mastercard's Agent Pay system includes registered agents and "verifiable intent," intended to validate user consent before an agent acts.

Waller did not propose a uniform standard but identified three primary challenges: authentication, liability, and fraud. Existing fraud systems are tailored around human behavior and may need to be adapted for software agents. Additionally, Waller pointed to the necessity of technical standards that could capture the intended transaction and how agents carry out those instructions.

The stakes may be particularly high in business-to-business (B2B) payments. B2B transactions are often governed by rules such as approved suppliers and budget limits, making them more suitable for agents. These agents could potentially negotiate terms and select payment strategies to optimize working capital. However, the increased transaction values also amplify the financial risk should an agent transgress its authority or make an error.

Moreover, B2B payments often involve multiple payment methods such as ACH, wires, instant payments, and cards. An autonomous purchasing agent might eventually need to choose among these methods based on factors like cost, speed, liquidity, or supplier preference. Thus, agents could make microtransactions for AI model queries, price feeds, and API calls before completing a purchase.

Mastercard is currently developing Agent Pay for Machines, which addresses high-speed machine-to-machine transactions. This development transforms payment orchestration into an AI decision problem.

The unresolved issue is determining who should manage the authority accompanying the payment. Banks might anchor this authority to customer identity and account permissions. Payment networks could incorporate it into tokens and authorization standards. Alternatively, AI platforms or merchants could devise their own versions. Waller noted that market participants are already working on both platform-specific and interoperable standards for registering agents, recording approvals, and transferring credentials across commerce systems.

Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pymnts.com →

More in AI

I built CyberMira: An AI-Powered Cybersecurity Assistant Grounded in Sanity

This is a submission for the Sanity Challenge, Path One: Ship an Agent That Queries Real Content What I Built Cybersecurity questions often have answers scattered across standards, vulnerability…

  • CyberMira is an AI-powered cybersecurity assistant for developers.
  • Retrieves targeted cybersecurity information from curated knowledge base.
  • Separates structured knowledge retrieval from answer generation.

Anthropic's Sonnet 5.5 release is about cost-per-task, not peak performance

Anthropic released Claude Sonnet 5.5 this week, and the main takeaway isn't a new state-of-the-art benchmark. The real story is the focus on cost-per-task for the bulk of everyday engineering work.

  • Anthropic releases Claude Sonnet 5.5 focusing on cost-efficiency
  • New model 30% faster and cheaper than Sonnet 5 for common tasks
  • Outperforms Sonnet 5 by 30% in agentic coding, 70.6% on Terminal-Bench 4.0

Adding AI to a Security Toolkit: Start With Your Own Scripts

Open your shell history before you open a course catalog. The jq filters, the grep -v chains against Zeek logs, the PowerShell one-liners you paste into a ticket every week: that is your toolkit.

  • Start with existing scripts like jq filters and PowerShell one-liners before adding AI.
  • Enhance existing pipelines (threshold adjustment, obfuscated script decoding, LLM features) with AI.
  • Train team on data paths and manual attacks to effectively use LLM in security pipelines.

More from Wednesday 30 September →