Urgent.News

What's breaking now, across thousands of outlets.

AI

How to Set Spending Limits for AI Agents: enforce at the payment layer, not the prompt

Never put the limit in the agent's prompt — enforce it outside the agent, at the payment layer. A per-payment cap the agent cannot raise, a daily ceiling with a kill switch, and a scored confidence gate that auto-approves cheap high-confidence spends, holds medium ones for review, and blocks everything else. Every decision logged. This is the week the question went from theoretical to personal.…

The question of how to control AI agents' spending habits has become a pressing concern. A report from Sept 24 highlighted that while an AI agent managed to save $550 and book restaurant reservations, it also wasted $64, raising concerns about security risks. Similar issues were raised by Tony Siqueira on LinkedIn, who questioned what he had authorized and who would be accountable for a failed attempt that ignored his instructions.

This issue was echoed by six banks, including BofA and Capital One, who expressed concern that AI agents might make the wrong purchases or spend excessively. Additionally, three regulators at GFF 2026 emphasized that AI agents should not independently authorize payments, as they may misinterpret intent.

To address these concerns, a five-part limit system has been proposed. The first part involves assigning one wallet per agent, funded with exactly its budget. This ensures that the agent can only spend the money allocated to it. The second part is a hard per-payment cap, which must be enforced at the payment layer outside the agent's reach.

This cap cannot be overridden by the agent's own judgment. The third part introduces a confidence gate, which scores every payment before it is executed. Payments with a confidence score of 0.80 or higher are automatically approved, those between 0.50 and 0.79 are held for human review, and those below 0.50 are blocked and logged.

The fourth part involves using two ledgers, one for payments made by the agent (tool calls and x402 micropayments) and another for the inference burn caused by the agent's model tokens. This helps in tracking and controlling the agent's token usage and expenditure. The fifth and final part is a daily ceiling with a kill switch and an append-only log to ensure complete auditability of all transactions.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

x402 Agent Spending Guard: Give Your Agent a Budget Before You Give It a Wallet

x402 Agent Spending Guard: Give Your Agent a Budget Before You Give It a Wallet On September 30, 2026, x402-seatbelt shipped — a free, open-source, zero-dependency npm package (plus a Python version…

  • x402 Agent Spending Guard prevents payments from exceeding budget
  • Guard released September 30, 2026, to address ecosystem failures
  • Decision gate evaluates payment based on confidence score

I crawled 3,014 Houston business websites to see what AI crawlers actually see

Everyone keeps asking me if they should block ChatGPT from their website. So I went and looked at what businesses in Houston are actually doing, and the answer surprised me: almost nobody is blocking…

  • Journalist analyzed 3,014 Houston business websites
  • Only 1.6% blocked AI crawlers in robots.txt
  • Key to AI-friendliness: server-rendered content and readable text

More from Sunday 4 October →