The assurance gap in agentic finance

Autonomous software agents that hold funds and settle payments without a human in the loop stopped being a thesis somewhere around the middle of last year. The rails exist. Coinbase and Cloudflare put payment into the HTTP request itself; Google built a protocol whose central object is a signed mandate and handed it to the FIDO Alliance; Visa and Mastercard extended network tokenization to agent-initiated flows. Governance of x402 sits under the Linux Foundation with a membership that reads like a roll call of the payments establishment. Brian Armstrong gave the category a name in July — AiFi — and the name stuck faster than the infrastructure settled.

The numbers are more interesting than the headlines suggest. Public trackers put cumulative x402 settlement around 157 million transactions by July 2026, across seven chains, moving roughly $41 million. That is an average under thirty cents. Those totals should be held loosely. For the same thirty-day window, x402.org reports around $24 million, Allium around $3 million, and Artemis $1.6 million. An order of magnitude, entirely down to methodology. Monthly volume peaked late in 2025 and contracted hard afterwards — on one chain, weekly transactions fell more than ninety percent between late December and early February. And Artemis, filtering for wallets repeatedly transacting with themselves, classified roughly 48 percent of x402 transactions and 81 percent of transferred value as non-organic as of December 2025. An adoption curve built from those counts is measuring something other than institutional adoption, in both directions.

What is actually durable shows up elsewhere. The protocol has been absorbed natively into Google’s AP2, Cloudflare’s agent runtime, Stripe, and AWS Bedrock. The card networks joined the foundation. That is what a protocol becoming infrastructure looks like, and it has nothing to do with last month’s transaction count.

The official sector has moved faster than most people noticed. Singapore’s IMDA published a governance framework for agentic AI. IOSCO finalized a supervisory toolkit for AI in capital markets that extends explicitly to agentic techniques. The IMF published a note in April proposing a three-layer separation of intent, authorization, and settlement. The Financial Stability Board consulted on twelve sound practices in June, with a final report due in October. Read together, they state the requirement with increasing precision.

They leave the same thing unaddressed. Every one of them specifies what an institution must achieve without naming the artifact that evidences it. A model risk head who accepts all of it still has no answer to the question a supervisor will actually ask: show me, from your records, who authorized this transaction, under what policy, through what chain of delegation, and whether it was inside its envelope.

That gap is what the paper is about. Safety-critical engineering solved this shape of problem fifty years ago — not by making software perfect, but by making trust in it examinable: rigor scaled to consequence, claims stated explicitly and backed by evidence, behavioral envelopes enforced by something the system cannot reconfigure, and records good enough to reconstruct what happened afterwards. Assurance for Agentic Finance translates that discipline to software that transacts, and includes a graph-native reference model small enough to be examined and specific enough to be used as an acceptance test.

It is published here today. What follows in this journal will be the working notes around it — where the framework meets real deployments, what the FSB’s final report changes, and the parts I got wrong.

Download the paper

Writing on this site is produced through an agentic AI process directed and reviewed by Robert Jeffs, who is accountable for its content.