← All posts

When your AI agent paid on your behalf, did you notice something?

Why agentic payments need identity: a trust layer that lets AI agents prove who authorized a transaction (without exposing personal data).

AIbillions teamSep 29, 20266 min read

Think about the last time you were in a restaurant and you wanted to pay. You take out your credit card and you hand it to a waiter. You know who has it, and if something goes wrong you know whose name to say. Agentic payments ask you to skip that last part: you give an AI agent access to your card, it spends, and the restaurant owner sees a payment - but from whom?

How do you verify who authorized the payment? Did the agent have permission to pay for you? Can the payment actually be traced and revoked? American Express (Amex) published a protection for exactly this problem in April 2026, and its own documentation says the standard it depends on is still being written.

American Express admits it cannot protect you

Luke Gebb, Executive Vice President and Head of Global Innovation at American Express, announced it will protect eligible customers from charges caused by AI agent error:

As commerce becomes more agent-powered, trust becomes the defining factor. Our goal is to ensure that when an agent acts on a Card Member’s behalf, the identities of both the human and the agent are authenticated and intent is clear – so that every Amex-enabled transaction reflects the backing and seamless experience that define our brand. That’s why we’re introducing Amex Agent Purchase Protection, an industry-first commitment to protect Card Members from registered agent error…

But there is a catch, and it is on their website.

The protection applies only when an Amex-registered agent sends them "the customer's authenticated purchase intent." And a few lines further down, Amex writes that "Agent Registration and Cart Context specifications are still under development."

So when Amex says the agent must be registered with them, the cardholder's purchase intent must be authenticated by them, and their implementation to protect you is unfinished, that is a card network saying in public that it cannot protect anyone in an agentic transaction unless it knows who is acting.

Which means: Amex’s protection is not real yet.

The price you pay when an order by an AI agent goes wrong!

In an ordinary dispute there is a trail: a name at the bank and an authorization record. Somebody is accountable and you can reach them.

In an agentic transaction with no verified identity, neither exists. The charge happens. Nobody can show who approved it.

You have nobody to call.

And nobody can reliably tell a trusted agent apart from something pretending to be it:

  • DataDome counted more than 16 million requests in two months this year impersonating a single company's agent.
  • The World Economic Forum (WEF) reported that, in the next two to ten years, misinformation and disinformation will be the most severe technological global threat.
  • The second most severe threat to humanity will be adverse outcomes of AI technologies, according to WEF.

There are two answers on the table for how to fix that. Both are bad.

Two bad choices (and a third option below)

Option A:

  • Every merchant demands the full identity of every customer and every agent before a transaction clears.
  • Total surveillance.
  • Every checkout becomes a KYC event.
  • Customers hate it.
  • Conversion drops through the floor.

Option B:

  • Agents stay anonymous.
  • Nobody is accountable, and whoever ships the product carries the risk.
  • Chargeback rates climb and fraud teams burn out.

Both are being presented as the only choices, but there is a third one.

Third good choice: an agent proves one thing that matters in the moment, nothing else

You need to prove you are over 18? You prove only that. Not your name, not your address, not your mother's maiden name.

The system checks the age, confirms it, and forgets the interaction immediately.

That is the whole requirement:

  • one confirmation (older than 18, yes or no?)
  • proved at the moment of the transaction
  • then forgotten.

Our CEO, Evin McMullen, says:

We can enable our armies of digital butlers and multi-agent workflows, to prove they are acting on behalf of us, on behalf of me, Evin, an American citizen over the age of 18 who has passed KYC. That means my agent can interact on my behalf in compliant spaces or in spaces that are regulated, and he can prove that I'm a safe actor to engage with.

The same principle applies to agents:

  • The agent proves it is authorized to spend on behalf of a real, verified human.
  • The other side gets enough assurance to ship.
  • The private data never moves.

An environment with little trust is dangerous

The internet was built to connect computers, not to verify the humans and agents operating through them. But without verification, we are stepping into an increasingly dangerous, trust-poor environment.

If we want to continue to enjoy the benefits and efficiencies enabled by large language model tools like Claude, Gemini, and ChatGPT, we need to introduce a layer of trust that is missing from the internet today. That means we need to be able to tell who or what we are interacting with and who or what they are acting on behalf of.

AI agents are the largest unidentified population on the internet

Every other actor in a card transaction has a file somewhere.

  • The cardholder has a name at the bank.
  • The merchant has an acquirer.
  • The network sits in the middle and can trace either one.

Agents have none of that…

They can initiate payments, and no registry says which human stands behind which agent. Amex is building one for its own network. It is still under development. Until something like it exists across every network rather than one, an agent is an actor with spending power and no file.

It is not safe, compliant, or scalable for agents to make payments if you do not know who you are paying.

You do not know whether it is acting for a real person or for a thousand fake ones.

Every AI agent should be able to prove three things:

  • It is acting on behalf of a real, accountable human
  • That human gave it permission to act
  • If something goes wrong, someone can trace it back and revoke it

The internet that works the other way around

Right now, using the internet is work. You open Google. You type. You scroll through pages of results. You click. You read. You decide. You do it again.

Turn it around. You say what you want. Your agents go find it, compare the options and handle the boring part. You get the result. That is the trade worth making, and it only works if the thing spending your money can prove it is yours.

Somebody still has to drive

Builders get so excited about what is under the hood that they forget about the driver.

Our CEO, Evin McMullen, says:

Our colleagues in the web3 development space get so excited by the novelty of the technology inside their engine that they forget a human being is supposed to be able to drive this car without needing to have spent thousands of hours understanding how the internal combustion works.

Accordingly, nobody should need to understand an identity protocol to trust agentic payments at a checkout. Amex shipped its developer kit in April 2026 and its registration standard is still open. Whatever fills that gap becomes the default for agentic commerce, and defaults are hard to unpick later.

What we are building at Billions Network

  • A way to prove you are human. Online, instantly, without handing over your life story.
  • A way for an AI agent to prove it belongs to a specific person, so the other side of the transaction knows who authorized it.
  • Live now: more than 12,000 verified AI agents and more than 2.5 million verified users. Built by the founders of Disco, Hermez and Polygon. Backed by Coinbase Ventures and Polychain.

The goal is simple: you never fill out a form again, and identity becomes something you carry, not something websites hold. You prove what you need to prove, nothing more, and the system forgets you when it is done.

What happens next

Agents are already buying. Contracts and larger sums are next.

When they do, somebody needs to know who is behind the wheel.

That is the internet we are building. One where machines work for humans, and a trust layer makes sure everyone knows whose work it is.

Prove you are one of the humans. Tap your passport to your phone and see what being verified feels like: https://billions.network

Adapted from Evin McMullen's conversation with Zara Nalir and Kim Currier for Decentraland’s Career Mondays series. Evin McMullen is CEO and co-founder of Billions Network, the Human and AI network. Backed by Coinbase Ventures and Polychain, Billions Network provides identity for humans and trust for AI agents across more than 2.5 million verified users and 12,000+ verified AI agents.

Get this in your inbox

Product news, agent-commerce research and the occasional deep dive.