SOUTH+BRIDGE
AI AI-translated

Who Presses the Pay Button

When AI agents start swiping cards, the real question isn't model performance. It's who delegates the authority and who bears the responsibility. Veto rights, spending limits, and audit logs become the primary components of the next payment rail.

Between 0 and 1 · June 6, 2026 · 4 min read

AI Summary

As AI agents begin autonomously booking hotels, renewing subscriptions, and reordering parts, the author argues that the true challenge is not intelligence but the architecture of trust and authorization—who delegates, and who is accountable. The article calls for an open, standards-based infrastructure stack built around veto rights, spending caps, and audit logs, warning that ceding these to a single platform is trading away user control for convenience. Korea, and Busan in particular, are identified as uniquely positioned to lead in defining delegation standards, given the country's dense experience in gaming economies and fintech identity verification.

Who Presses the Pay Button

Agents book hotels, renew subscriptions, and reorder parts. People read this as 'AI has gotten smarter.' That's the wrong reading. The real event is that the hand pressing the pay button has changed.

Until now, payment has rested on one assumption: that the one who presses and the one who is responsible are the same person. The hand that swiped the card and the person who received the bill were identical. Agents quietly break that assumption.

So the signals of 2026 must be read not from the screen but from the structure of authorization. It is a question of delegation. When I tell an agent to 'go grocery shopping,' what exactly have I delegated? A one-time errand or an indefinite mandate? Up to 50,000 won or with no ceiling? Without those boundaries, delegation becomes a blank check.

People who see Web3 only in terms of coins and exchanges will lose the thread here. To them, on-chain is a speculation arena. But what agent payments require is not a price—it is rules. Nailing down in code who can do what, and to what extent.

There was an era when trust was handed over to human conscience or corporate terms of service. Automating that trust through protocols—that is what I see as the essence of Web3. Coins are the foam floating on top; the infrastructure is the rail laid beneath.

When agents become economic actors, four things are needed simultaneously. Identity: whose delegation does this agent carry? Reputation: has it kept its promises in the past? Payment: how does it settle value? Settlement: if a dispute arises, who do you go back to?

Solving these in isolation creates another platform prison—a structure where one company controls identity, payment, and reputation alike. That is why they must be bundled as a stack. Stablecoins carry value; standards like x402 attach payment to a single HTTP request; efforts like ERC-8004 inscribe agent identity and reputation on-chain; and tokenization layers on proof of asset ownership.

The key point is that the primary components of this rail are not speed or fees—they are veto rights, spending limits, and audit logs. Can a human stop the process at any time? Is there a ceiling on an agent's expenditures? Can you trace after the fact who bought what and why? Agent payments without these three are not convenient—they are dangerous.

US Big Tech is already eyeing this space. Major payment networks are moving to layer agent payments on top of their own rails, and cloud providers are bundling models and wallets together. The Ethereum ecosystem counters with the neutrality of open standards—the promise of a rail that requires no one's permission.

A strong counterargument arises here: 'No standards needed—if one Big Tech company handles everything, it's fast and convenient.' That sounds right. But the heart of delegation is revocability. If one company controls identity, reputation, and settlement, it is that company that interprets the authority you gave your agent. You hand over your veto in exchange for convenience. A neutral protocol may be slower, but it keeps that authority in the user's hands.

This is where Korea runs into a wall. Our payment system was designed around real-name verification and simplified payment apps—one person, one phone, one identity check. But an agent is not a person. At the NICE or KCB identity verification screen, an agent comes to a full stop. Our identity infrastructure does not yet recognize a delegated automated actor.

That collision is not a weakness—it is an opportunity. Korea has built a density of experience in content payments, in-game economies, and simple payment infrastructure that the world envies. Games have already run virtual economies; fintech has industrialized identity verification. Few places hold as much real-world operational data as Korea when it comes to standardizing the identity and spending limits of delegated actors.

Look at Busan. Gaming and fintech talent share the same city. The standard for proving who an agent is delegated by and how much it is authorized to spend need not emerge from the headquarters of a major payment network—it can come first from a testing ground like this. Whether we become users or designers of that standard comes down to the choices made now.

That is why the priorities must be reversed. Building smarter agents first and attaching trust later is the wrong sequence. Intelligence without authorization is a runaway train; automation without accountability is an accident waiting to happen.

In an era when AI agents are pressing the pay button, what must be designed first is not model performance—it is veto rights, spending limits, and audit logs: the standards of trust. If the hand pressing the pay button has changed, first design the hand that can stop it.

This article was automatically translated from the Korean original by AI. For the authoritative version, read it in Korean.

한국어 원문 읽기 →