On February 7, 2025, Washington Post columnist Geoffrey Fowler let OpenAI’s Operator agent manage a week of his errands. It bought him a dozen eggs for $31.43 — and it did that without the final confirmation step OpenAI had built into the product specifically to prevent unconfirmed purchases. Nobody lost real money over eggs. But eighteen months later, three of the biggest names in payments have each shipped infrastructure built around exactly that failure: an agent doing something with your money that you didn’t explicitly sign off on, one step before it happens.
Three companies, three different bets
Google went first, announcing the Agent Payments Protocol (AP2) on September 16-17, 2025, with more than sixty launch partners — PayPal, Mastercard, American Express, Coinbase, Salesforce among them. AP2’s idea is a pair of cryptographically signed mandates: an Intent Mandate captures what the user actually authorized (“book a flight under $400, economy, next Tuesday”), and a Cart Mandate is generated at the moment of purchase, tying the specific transaction back to that authorization. The signature doesn’t prove the purchase is a good idea. It proves a real user authorized this class of purchase, and the agent isn’t freelancing.
Visa didn’t join AP2. It built its own thing instead — the Trusted Agent Protocol, announced October 14, 2025 with Cloudflare and a list of processors and merchants. TAP takes a different angle: instead of mandates about intent, it signs the agent’s traffic itself, using HTTP Message Signatures (RFC 9421) built on the emerging Web Bot Auth standard, with Ed25519 keys checked against a Visa-run directory. The problem TAP is solving is upstream of AP2’s — it’s not “was this specific purchase authorized,” it’s “is this actually a legitimate commerce agent knocking on the merchant’s door, or a scraper wearing an agent’s clothes.”
Mastercard shipped first of the three, on April 29, 2025, with Agent Pay — Agentic Tokens that bind a payment credential to a specific agent identity with per-session and per-merchant limits baked in. PayPal joined that ecosystem later, in a separate deal announced October 27, 2025. And in June 2026 Mastercard added Agent Pay for Machines, extending the same idea to agent-to-agent payments small enough to matter only in aggregate — API calls, compute time, data queries priced in fractions of a cent.
Then, on April 28, 2026, FIDO Alliance stepped in to stop this from calcifying into three incompatible standards nobody outside their own ecosystem can use. It formed two working groups: Agentic Authentication, chaired by CVS Health, Google, and OpenAI, and Payments, chaired jointly by Mastercard and Visa — drawing on both AP2 and Mastercard’s own Verifiable Intent work. Read between the lines and that’s an admission: none of the three companies wanted to concede the standards fight outright, so the compromise is a shared committee that borrows pieces of everyone’s homework.
The paper that tested whether any of this actually holds
Here’s the part that made me want to write this post instead of just filing it under “interesting industry news.” A team of researchers — Yedidel Louck, Amit Dvir, and Ariel Stulman — published a paper in September 2026 with a title that’s doing a lot of work: “Signing the Transaction but Not the Decision: Whisper Attacks and a Binding Defense for AP2.” Their point, in one line: a cryptographic signature proves the final transaction was authorized. It says nothing about whether the reasoning that led an agent to construct that transaction was manipulated first.
They built three attack types — Vault Whisper, Branded Whisper, Selection Whisper — that quietly tilt what an agent thinks it’s buying before the mandate ever gets signed, and tested them across models. The spread is the whole story: on their price-manipulation attack, Gemini 3.1 Pro-Preview fell for it 100% of the time, Gemini 2.5 Pro 93.8%, Gemini 3.1 Flash-Lite 73.3%, GPT-5.5 41.1%. Claude Opus-5 held at 1.2%. Same attack, same target, an 80-plus-point spread depending entirely on which model is doing the reasoning behind the signature.
That’s the uncomfortable bit these payment rails don’t advertise. AP2, TAP, and Agent Pay all solve the “was this authorized” problem elegantly. None of them touch “was the model tricked into wanting the wrong thing before it asked for authorization.” The signature is downstream of the decision, not a check on it.
What I’d actually implement if I were building this
If you’re wiring agent checkout into a product today, three things matter more than picking the trendiest protocol. Scope every mandate to the narrowest thing that satisfies the task — an Intent Mandate for “a coffee subscription under $20/month” is a different risk than one for “manage my grocery spending,” even if both are technically one signature. Put a hard, non-negotiable ceiling on transaction size that lives outside the agent’s own context, the same lesson the last post’s OpenClaw incident taught the hard way — a number a crashed session can’t quietly forget. And treat the reasoning step before mandate signing as the actual attack surface, not the signature itself; the Whisper Attacks paper is basically a live demonstration that everyone secured the notary and left the front door open.
None of these three companies is wrong to build what they built. I just wouldn’t tell a client the problem is solved because their agent now signs its receipts.