AI agents are already performing on-chain transactions completely autonomously. Between May 2025 and April 2026, approximately $73 million was settled in over 176 transactions via blockchain rails.
The capability for agentic transactions already exists, but governance and security efforts haven’t kept pace. An agentic economy without a proper security and control layer in place introduces systemic risks to the system and all of its participants.
How Agentic Payments Differ
Traditional payment systems and governance are built for human-driven transactions. These transactions are executed more slowly and have the advantage of traditional payment rails, such as bank accounts, credit cards, and identity checks.
AI agents, on the other hand, perform near-instant transactions and lack access to the same payment rails. Instead, they rely on blockchain networks, settling transactions using stablecoins within milliseconds and at costs below $0.001.
The New Rails of Agentic Payments
Agentic payments have widespread appeal, which has resulted in many organizations developing new infrastructure, including:
- x402 Protocol: Coinbase launched the open x402 protocol in May 2022, which used the long-unused HTTP 402 Payment Required error code to allow stablecoin payments for web requests. Cloudflare cofounded the x402 Foundation with Coinbase to standardize the protocol and its usage.
- Coinbase Agentic Wallets: Coinbase also created blockchain wallets specifically designed to support autonomous AI agents. Features include session caps, operation allowlists, transaction limits, multi-party approvals, and detailed audit logs.
- ERC-8004: This standard created verifiable on-chain identities for AI agents. The standard was introduced as an EIP in August 2025 and later adopted by BNB Chain as well.
In addition to this, other players, including Stripe, MoonPay, and others, have embraced the use of stablecoins for settlement by AI agents. These allow HTTP protocols to support payments and blockchains to support clearance.
Top Risks of the Agentic Ecosystem
The agentic ecosystem has numerous potential benefits, but it also creates risks. Some of the most significant security and compliance gaps in the agentic economy include:
- Identity and Impersonation: While there is work being done in the space, spoofing of trusted AI agents is still a major threat. Agents that claim to be authorized by users may be impossible to differentiate from legitimate ones without real-time intent analysis.
- Delegated Authority Abuse: Users grant AI agents permission to perform certain acts within defined boundaries. This runs the risk that legitimate agents may be tricked or coerced into taking undesirable actions, such as updating payment methods, profile data, or security settings without authorization.
- Expanded Attack Surface: Autonomous AI agents introduce various risks to the business, such as data exfiltration or tool misuse. Agentic payments create new risks, adding financial threats to the agentic attack surface.
- Obsolete Fraud Models: Traditional fraud models are based on human behavioral patterns. These models are no longer effective when autonomous agents can perform transactions.
- Regulatory and Liability Gaps: Like fraud models, most financial and consumer protection laws are based on the patterns of human-driven transactions. These laws don’t effectively cover agentic payments, requiring updated regulations, such as Know Your Agent (KYA) laws rather than the traditional Know Your Customer (KYC) ones.
The agentic economy is already up and running, with many transactions being performed on-chain each day. However, scalability, security, and widespread adoption require closing these and other security gaps.
Key Elements of an Agentic Economy Control Layer
The agentic economy is well-established and continually growing, making a control layer vitally important. Some of the most critical pieces of a security and governance layer for the agentic economy include:
- Agent Identity Infrastructure: A lack of strong agentic identity infrastructure is one of the biggest risks of the agentic economy; impersonation undermines trust in legitimate agents and enables fraud. Agents should have verifiable, on-chain identities that are tied to real-world identities and revocable in real time.
- Agent-Friendly Authorization Policies: Agents are delegated a great deal of power and authority, making limits essential. The agentic economy needs a framework for defining consent and authorizations so that policies can be attached to transactions that detail who authorized the payment, the associated conditions, and whether an agent remained within the defined scope.
- Continuous Transaction Monitoring: Autonomous AI agents can perform payments near-instantaneously, meaning that a rogue or malicious agent can do significant damage in seconds. Managing this risk requires continuous transaction monitoring, using AI-based fraud detection algorithms that consider permissions, context, real-time signals, and machine behavioral systems to identify potential fraud.
- Audit Trails: AI agents can autonomously decide to execute payments, which becomes problematic if these payments are unauthorized or fraudulent. Effective risk management within the agentic economy requires immutable audit trails that are more accessible and usable than those provided natively by blockchain infrastructure.
- Threat Prevention and Mitigation: With near-instant, irreversible on-chain transactions, prevention is essential to managing the threats associated with agentic payments. Key elements of a mitigation strategy include strong authentication, scoped authorization, and secure API governance.
In the history of the web, capabilities have historically run ahead of the associated security and governance controls. Like TCP/IP predated TLS, Web3 and the agentic economy have the ability but lack the required limits and defenses.
Building the Control Layer for the Agentic Economy
The agentic economy is rapidly expanding. New rails allow agents to perform rapid, on-chain payments at scale. These also introduce significant risks to the business, ranging from rogue agents performing unauthorized payments to malicious agents impersonating legitimate, trusted ones.
The next stage in the evolution of the agentic economy is building the control layer that manages these risks. The technology stack is mature enough that top threats are easily identifiable; however, the necessary security controls and laws don’t yet exist.
Organizations building the agentic economy require expertise in security, Web3, and AI and its associated risks. Halborn offers advisory services with deep expertise in these areas, offering guidance and support to teams building at any stage of the software development lifecycle. To learn more about how to enter the agentic economy while implementing security best practices and controls, get in touch with Halborn.
