Audit trails tracking artificial intelligence agents’ actions on behalf of human consumers will be critical for agentic commerce to function and grow, financial technology executives said at a recent panel on agentic AI risks.
Retail and payments players are trying to develop “a common dialogue” around AI payment protocols and how to assign liability for agentic transactions, said Raisa Sheynberg, Mastercard’s vice president of government affairs and policy.
She spoke Friday as part of a panel discussion on agentic AI called “Risk Management for Autonomous Financial Agents.” The panel convened at the Philadelphia Federal Reserve Bank’s 10th annual fintech conference.
“A lot of our answer is going to lie in trying to attach a cryptographic proof of exactly what the agent did on your behalf, so that we can ultimately trace it back to what you hoped to achieve through your shopping journey,” Sheynberg said, referencing a typical consumer.
A range of payments players from Stripe to Google to the FIDO Alliance, along with the three largest U.S. card networks, are working to coalesce around technical standards for agent transactions that will work across the industry. It’s unclear how quickly that technical work will progress or when bot-powered commerce grows into a significant portion of online sales.
Agentic payments may drive between $3 trillion and $5 trillion in global consumer commerce by 2030, according to the consulting firm McKinsey.
Merchants and others in the payment ecosystem will find it problematic if they lack insights into their interactions with AI agents, said Austin Campbell, CEO of Zero Knowledge Group, a New York-based consulting firm that focuses on crypto and blockchain.
“You’re probably making a terrible mistake if you don’t have some sort of disclosable audit trail for what an agent did,” said Campbell, who is also an adjunct professor at New York University Stern School of Business.
Others on the panel included Rachel Anderika, global head of operations for Anchorage Digital, a bank specializing in digital assets; Ari Redbord, global head of policy at TRM Labs, a digital risk management firm; and Brendan Woodbury, Amazon’s senior manager of payments policy.
The panel also touched on efforts by the Trump administration to adopt a more aggressive posture toward cyberfraud actors based abroad. Efforts to enlist the private sector to combat international fraud organizations have gained new urgency, with two recent developments in Washington, Redbord said.
An August “presidential memorandum” from the White House would authorize U.S. corporations to target foreign fraud organizations but only under close supervision by U.S. agencies, Redbord noted.
Americans lost about $21 billion to “cyber-enabled crime” last year, with 73% of adults reporting that they have experienced some type of online scam or attack, according to a White House fact sheet on its cybercrime initiative.
Meanwhile, two bills introduced in Congress in July would give the president authority to issue “letters of marque and reprisal” for U.S. companies to strike foreign cyberfraud actors.
Sen. Mike Lee, a Utah Republican, and Rep. Tim Burchett, a Tennessee Republican, introduced the Cyber Letters of Marque and Reprisal Act in the Senate and House. The bill aims “to punish, deter, and prevent acts of aggression and depredation and other malign acts committed by foreigners against Americans through cyber-enabled means.”
“Our legislation allows American digital privateers to raid cartels, cybercriminals, and foreign adversaries, disrupting their operations and seizing their assets,” Lee said in a press release.
Campbell said the U.S. has “been pretty restrained about using any of our kinetic warfare capabilities,” predicting that is likely to change as Washington officials consider ways to more aggressively tackle foreign cyber threats.
“If you mess with Google or Meta and they can mess with you back, the threat landscape is very different from a game-theory perspective,” Campbell said, adding that if a fraud perpetrator gets “a drone-like mounted bomb” through a window, it “really changes the calculus on what you’ve achieved.”
Redbord, a former Treasury Department official and assistant U.S. Attorney, described Lee’s legislation as a means of “going after pirates in cyberspace the same way we’ve gone after pirates in the high seas throughout our history.”
“This is not what we prepped at lunch,” Mastercard’s Sheynberg quipped in response.