Signals
Real developments, as we find them.
Short, one-line notes on the agent economy — posted through the week, not batched. Every Sunday, whichever ones mattered most get folded into the newsletter's full roundup, with more context.
Get the Sunday roundup in your inbox.
The UK's FCA opened a consultation on modernizing payment-services regulation, asking directly whether agentic AI should be allowed to analyze, initiate, approve, and execute payments.
The identity and liability questions this newsletter keeps raising — who's accountable when an agent acts — are now formally on a regulator's desk in the UK, joining Singapore's MAS and the EU AI Act. The rules are still being written, in more than one place at once.
A US banking industry group told Congress that consumers, not banks, may bear liability for mistakes their AI agents make — an unresolved question under existing electronic-transfer law.
This is the flip side of the identity story: even once an agent is verified, it's still an open question who eats the cost when it gets something wrong. Worth knowing before treating any "bounded" limit as risk-free.
Singapore's central bank (MAS) published a framework requiring banks to check an AI agent's identity, permissions, and risk limits before it executes a payment — not after.
This is the KYA idea from two issues ago, formalized into an actual regulatory framework, built with Mastercard, Visa, HSBC, and JPMorgan Chase among others. Worth watching as a preview of where US rules may eventually land.
Santander and Mastercard ran Europe's first live agent-executed payment inside a regulated bank.
It used pre-authorized permissions and tokenized credentials, not unsupervised access — the first real-world case of a bank crossing this line, and still a bounded one.
Plaid partnered with AI agent platform Sierra to move beyond sharing your account data toward agents that can act on it.
Plaid's connections power a huge share of the budgeting and banking apps freelancers already use — this is a sign those same tools are being wired for agent action, not just agent visibility.
Visa announced plans to acquire BioCatch, a behavioral-biometrics company, to strengthen fraud and identity verification.
Another layer in the identity story from two weeks ago — behavioral patterns like how you type or move a mouse may become part of how a network tells you apart from your agent, or from an imposter.
The EU AI Act's high-risk provisions became enforceable, including disclosure and human-oversight rules.
If a finance tool you use also serves EU customers, expect more disclosure banners and review-before-send prompts to show up on your account too — vendors rarely ship two versions.
"Know Your Agent" is being treated as its own discipline in 2026, distinct from Know Your Customer.
If a tool can't show you which of your account's actions were the agent's and which were yours, it's behind on identity, not just features.
Mastercard's Agent Pay ties every agent transaction back to a KYC'd human via a cryptographic agent ID.
The card networks are building the identity layer first — this isn't something you configure yourself yet, but it's the direction bank and fintech tools will plug into.
Payment startup Natural raised $30 million to build transaction rails built specifically for AI agents.
Even here, a human still has to approve the actual payment — today's card and ACH rails weren't built for a machine to authorize a transaction on its own.
Payouts.com launched role-based agents for solo operators — accounts payable, collections, and treasury, no bookkeeper required.
Worth watching as a category: a vendor building for the freelancer/small-agency case first, not enterprise first.