Human approval for agent payments: the FSB draft and the replies
The Financial Stability Board's draft asks for human approval above a value threshold. Mastercard's reply says per-purchase human review will not scale. Both are now in the public record.
By XAgent Team · 2026-08-14
On August 6 the Financial Stability Board published the 124 public responses to its consultation on responsible AI adoption in finance. Inside that pile is a disagreement worth reading closely, because it is about the control every agentic commerce product currently depends on. The FSB's draft asks for human approval above a value threshold. Mastercard's reply says that will not scale. Both are now on the record, and the final report has not been written.
What the FSB actually proposed
The consultation is "Sound Practices for Responsible Adoption of Artificial Intelligence (AI)", published on 10 June 2026 with comments due 22 July. It is not an agentic-AI consultation — agentic AI is one thread in a broader document, and the FSB is explicit that the practices "are not intended to establish an international standard, to impose a prescriptive approach for responsible AI adoption by financial institutions, nor to influence business decisions in adopting a certain AI technology."
Within that scope, the report names the risk plainly: "This creates a risk of AI agents taking illegal, unethical, or unauthorised actions without human approval or oversight. Overriding, redressing, or remediating these actions can be difficult or impossible for humans."
And it proposes, among additional considerations for agentic AI, "placing controls on AI agents executing financial transactions especially with customers' funds; including human approval or dual authorisation for transactions above a certain value; restricting direct agent access to payment systems."
On identity, the FSB's ask is thin — a single provision: "assigning and documenting individual identifiers to AI agents to facilitate monitoring and identity management."
Mastercard's reply says the human step does not scale
Mastercard's letter takes that directly:
"For financial institutions, a flexible approach to AI oversight is especially important with the expected growth of agentic commerce – where AI agents will be purchasing goods and services on behalf of users – as it may not be scalable and logistically feasible for organizations to implement human review of each individual purchasing decision."
This is not an abstract objection. It is the same finding Anthropic published from its own users, where per-action approval prompts were being approved 97% of the time — a control that had stopped filtering. The regulator is drafting toward a checkpoint; the network operating the rails is saying the checkpoint will be clicked through.
What Mastercard proposes instead is verification before the transaction rather than confirmation during it. It asks the FSB to strengthen guidance on agent credentials, "noting that such credentials should be: (1) cryptographically verifiable; (2) tied to a human or enterprise principal; (3) fully lifecycle managed (from issuance to revocation); and (4) policy-constrained based on the scope of authority for that unique agent."
It also asks for "a 'know your agent' approach to AI agent security, including references to agent registration, measures for cryptographically verifiable identity, provenance, and traceability", and defines the thing being established as "agentic trust (i.e., the confidence that an autonomous AI agent is authorized to act, is acting with legitimate intent, and can be held accountable on behalf of a real human within defined guardrails)."
Read the four-part test again. Cryptographically verifiable, tied to a principal, revocable, and scoped to a specific authority. That is a machine-checkable mandate — the thing that has to be evaluated at the moment of purchase if the human click is not going to do the work.
Visa's letter is more hedged than it is being reported
Visa also filed, and its most-quoted sentence deserves care, because it is easy to sharpen into something Visa did not write.
What Visa wrote: "As AI agents increasingly interact with financial services, payment systems, merchants, and other digital actors, the ability to verify the identity and authority of an agent may become as important as the governance of the underlying AI model itself."
May become as important as. Not "rather than", not "instead of". This is additive and hedged, and any summary that has Visa telling regulators to police the agent's permissions rather than the model is misquoting it.
Visa's sharper argument is elsewhere, and it is about categorisation: "we recommend avoiding any implication that agentic AI systems should automatically be treated as inherently high-risk, as agentic systems exist in a wide spectrum of delegation, and any assessment of risk is also context-dependent on the type of activities it may be authorized to perform."
It also lists what trusted deployment depends on — "strong digital identity, authentication, authorization, accountability, and auditability frameworks" — in a single sentence, as a list rather than a developed position.
Three absences matter, and each is a place where commentary tends to invent things.
Liability. Neither letter allocates responsibility for an agent-initiated payment that goes wrong, and neither does the FSB report. There is no card-network fight over who eats a bad agent purchase, because nobody made the argument in these submissions.
Mandates, by that name. Visa comes closest with a request that the final report recognise "delegated transaction initiation", but the word does not appear and no letter specifies how a spending mandate would be expressed or checked.
Anything adopted. Everything Mastercard proposes is advocacy. Its own framing is that it "should go further" than the FSB's single identifier provision — which is the tell that the four-part credential test is a request, not a rule. Reporting "know your agent" or "agentic trust" as FSB policy would be wrong; those phrases appear nowhere in the FSB's report.
One further caution on timing. The FSB's June announcement said "The final report will be published in October 2026". The August responses page says only that the FSB "expects to publish the final report in the coming months". Treat October as the earlier, firmer statement that has since been softened, not as a confirmed date.
What a merchant should take from this
The regulator and the network agree on more than they disagree about, and the agreement is the useful part: an agent transacting with customer funds needs a verifiable identity, a traceable link to a principal, and constraints on what it may do. They differ on where the check happens — a human confirming a large transaction, or a credential evaluated before one.
Whichever way the final report lands, the merchant-side work is the same and it is not a dialog box. You will need to know which agent is transacting, what it was authorised to do, whether this specific purchase falls inside that, and be able to reconstruct all three afterwards. That is the authorizable pillar, and it is an execution-layer job.
What's next
Watch the final report for whether the value-threshold language survives contact with the responses. If it does, agent purchases above some amount acquire a human step by regulatory expectation, and the design question becomes what that human is shown — a plan they will engage with, or an item they will approve reflexively. If it does not, the credential test moves to the centre and the industry needs an interoperable way to express and check scope.
If your business should be able to identify an arriving agent, check the purchase against what its principal actually permitted, and produce a record either way, list your store on XAgent and let the open execution market run that check.