FinAgentHub
← Archive
Issue No. 0096 min read

Four countries, one question: who's accountable when your agent moves money?

The US, UK, EU, and Singapore are answering it differently — and none of them agree yet.

Every issue so far has looked at one piece of the agent-and-money puzzle at a time — identity, tiers, tools. This week, zoom out: four different regulators are actively writing the rules for agentic finance right now, and they're not converging on the same answer.

This week in the agent economy

  • Danske Bank and Mastercard completed what they're calling Denmark's first agentic AI payment — an AI agent initiating a transaction inside a live, regulated banking relationship. What it means for you: add this to Santander's live agent payment from last month. A second major European bank has now crossed the same line, in the same bounded, pre-authorized way. This is starting to look like a pattern, not an outlier.
  • At Fortune's Leaders Forum in Macau, Ant Digital Technologies president Zhuoqun Bian told financial-industry attendees that "know your agent" is now the compliance challenge the industry has to solve next, alongside know-your-customer. What it means for you: this is the same KYA framing this newsletter introduced two months ago, now coming from inside one of Asia's largest fintech groups on a global stage — a sign the vocabulary is converging, even if the rules aren't yet.

The deep dive: four countries, one question

Every regulator asking about agentic finance is really asking one question — when an agent acts, who's accountable — and each has landed somewhere different so far.

  • United States. No agent-specific rulebook. A banking industry group has told Congress that consumers, not banks, may bear liability for their agent's mistakes under existing electronic-transfer law that predates agents entirely. Untested and unsettled.
  • United Kingdom. The FCA has opened a formal consultation asking whether agentic AI should be allowed to analyze, initiate, approve, and execute payments — and what authentication and liability rules would need to change first. Still a question, not yet an answer.
  • European Union. The AI Act's high-risk provisions are enforceable now, requiring disclosure and human oversight for higher-risk systems — but liability for a specific bad transaction still runs through each member state's existing consumer-protection law, not a single EU-wide agent rule.
  • Singapore. The furthest along: MAS published a framework, built with Mastercard, Visa, HSBC, and JPMorgan Chase, that requires checking an agent's identity, permissions, and risk limits *before* it executes a payment, not after. The closest thing to a real answer any of the four have produced.

What this means if you're not in any of these countries' regulatory conversations

You're not exempt from the outcome, even if you never read a consultation document. Card networks and major banks build one set of rails, not four — whatever Singapore's MAS framework or the EU's oversight rules end up requiring will likely show up in the tools you use, regardless of where you live, because vendors rarely maintain a lighter-touch version for smaller markets.

The practical takeaway hasn't changed since issue one: until one of these four converges into something closer to a real standard, "bounded" is the only stance that works everywhere at once.

— FinAgentHub

This web version has the subscriber-only Tool Corner and Reader Question sections removed. Subscribers get those in the original email, two weeks before this page goes up.

Get the next issue two weeks early.