The Agent as Economic Actor
When AI Spends Money, Who Owns the Consequences?
The Agent as Economic Actor
When AI Spends Money, Who Owns the Consequences?

Abstract
On April 30, 2026, Cloudflare and Stripe launched a protocol that allows AI agents to autonomously create cloud accounts, purchase domain names, start paid subscriptions, and deploy production applications — without a human completing any of those steps [1]. Five days later, OpenAI opened a self-serve advertising platform inside ChatGPT, targeting $2.5 billion in ad revenue this year and $100 billion annually by 2030 [2]. On April 24, the International Monetary Fund published its first formal note on agentic AI in payments, warning that “most payment regimes require that a payment order be traceable to an authorized instruction from an account holder or its legally recognized agent” — a requirement that agent-initiated transactions structurally violate [3]. On April 8, researchers from Google DeepMind, Microsoft Research, and Columbia University proposed the Agentic Risk Standard, introducing escrow, underwriting, and collateralisation mechanisms for AI agent transactions [4]. These are not separate stories. They are convergent evidence of a single institutional crossing: the AI agent has become an economic actor — an entity that spends money, earns money, deploys capital, enters commercial relationships, and generates revenue — without legal personhood, fiduciary obligations, an identity framework, or an accountability structure. Every institution governing economic activity — payment rails, fraud models, KYC regimes, consumer protection law — was built for human-initiated transactions. The agent has crossed into economic agency. The institutions have not followed.
The Problem Crystallized
In May 2024, Sam Altman sat at a Harvard fireside chat and called the combination of advertising and AI “uniquely unsettling.” He disclosed, as a personal bias, that he hated ads. He called them a “last resort” for OpenAI’s business model. He valued, he said, that people paying for ChatGPT knew their answers were not influenced by advertisers [5].
Twenty months later, the last resort arrived. On February 9, 2026, OpenAI began testing ads in ChatGPT for U.S. users on the free and Go tiers. By March 26, the pilot had crossed $100 million in annualised revenue within six weeks [6]. On May 5, OpenAI launched a self-serve advertising platform — eliminating the $50,000 minimum spend, adding cost-per-click bidding alongside CPM, and rolling out a measurement pixel and Conversions API [2]. On June 5, conversion-optimised campaigns begin rolling out to eligible advertisers [7]. The trajectory from “uniquely unsettling” to “$100 billion by 2030” took less than two years.
That same spring, a quieter but more structurally significant threshold was crossed. On April 30, Cloudflare and Stripe launched Stripe Projects — a protocol that lets AI coding agents create Cloudflare accounts, register domain names, start paid subscriptions, obtain API tokens, and deploy production applications, all without a human manually completing any step beyond accepting terms of service [1]. The agent goes, in Cloudflare’s words, “from scratch to a live URL.” Startups incorporating through Stripe Atlas receive $100,000 in Cloudflare credits. Vercel, Supabase, and Planetscale are integration partners. The protocol is open; any login-based platform can connect.
Now hold these two facts together. In June 2026, an AI agent can spend money (Cloudflare/Stripe provisioning), earn money (ChatGPT ad revenue), deploy infrastructure (Stripe Projects), and enter commercial relationships (domain registration, paid subscriptions) — all autonomously. The agent is no longer a tool that assists economic activity. It is an entity that initiates economic activity. And every institution governing economic life — payment authorisation, fraud detection, identity verification, consumer protection, tax law, liability assignment — was designed for a world in which economic actors are human.
The thesis of this essay is precise: the simultaneous emergence of agent-initiated spending, agent-mediated advertising, and agent-driven infrastructure provisioning marks the moment AI agents crossed from tools to economic actors — entities that transact, deploy capital, and generate revenue — without any legal, regulatory, or financial infrastructure recognising them as such. This is not a hypothetical risk. It is an institutional fact as of June 2026. The economic identity vacuum — the absence of identity frameworks, authorisation standards, fiduciary obligations, and accountability structures for non-human economic actors — is the defining governance gap of the agentic era.
1. The Phenomenon: Three Crossings in Sixty Days
1.1 Crossing One: The Agent That Spends
The Cloudflare-Stripe protocol is not a convenience feature. It is an architectural decision with institutional consequences. Before April 30, an AI coding agent could write code, suggest deployments, and draft configuration files. It could not execute a financial transaction. The new protocol changes this: the agent, operating under a human’s Stripe login, can initiate payment flows, subscribe to paid services, and allocate financial resources. Stripe handles identity and payment with a $100-per-month default spending cap [1].
The security implications were immediately noted. David Shipley of Beauceron Security warned that the protocol is “a huge win” for cyber criminals, who are “constantly forced to set up new infrastructure as security firms and law enforcement fight back” — making it faster to build and deploy infrastructure “is a huge win for them” [8]. Within weeks of OpenClaw’s peak adoption — the autonomous AI agent that crossed 250,000 GitHub stars in early 2026 — security researchers found over 1,800 exposed instances leaking API keys and conversation histories [9]. The Cloudflare-Stripe protocol extends this attack surface to financial transactions: an agent that can create accounts and deploy infrastructure can also, if compromised, create accounts and deploy adversarial infrastructure.
The institutional gap is precise. Stripe’s $100 cap is a spending limit, not an authorisation framework. It controls magnitude but not intent. The agent is not asked why it is spending; it is merely capped at how much. This is the equivalent of giving an employee a corporate credit card with a monthly limit but no expense policy, no approval workflow, and no audit trail linking expenditures to business purposes. In a human context, this would be an internal controls failure. In the agent context, it is the default architecture.
1.2 Crossing Two: The Agent That Earns
ChatGPT’s advertising model creates a different kind of economic actor: the agent as a revenue-generating surface. When a user asks ChatGPT a question and an ad appears beneath the response, the agent has participated in an economic exchange — attention for revenue — that neither the user nor the agent initiated in the traditional sense. The user did not search for a product. The agent did not recommend one. A contextual matching algorithm, operating on the conversation’s semantic content and the user’s chat history, selected the ad [10]. The agent’s “earning” is a function of its utility: the more users engage, the more ad impressions are generated, the more revenue flows to OpenAI.
OpenAI’s stated principle is that “ads do not influence the answers ChatGPT gives you” [11]. The architectural claim is that the response generation and the ad selection are separate processes. But this separation rests on an organisational commitment, not a verifiable architectural guarantee. Altman himself identified the structural tension in 2024: ads “fundamentally misalign a user’s incentives with the company providing the service” [5]. The misalignment he described has not been resolved; it has been accepted as a business cost. OpenAI projects $74 billion in operating losses in 2028 and spends approximately $1.69 for every dollar of revenue it generates [12]. The “last resort” was not a philosophical concession. It was a financial necessity.
The economic actor framing reveals what the advertising narrative obscures. The agent is no longer a neutral intermediary between user and information. It is a node in an advertising network, generating revenue from the quality of its conversational engagement — a quality that is optimised, through RLHF and other training methods, to maximise user satisfaction and continued interaction. The optimisation target (“be helpful and engaging”) and the revenue target (“generate ad impressions through sustained engagement”) are not opposed, but they are not independent. The agent’s economic role as a revenue surface creates an incentive gradient that its training process cannot fully insulate against, even with the best architectural intentions.
1.3 Crossing Three: The Agent That Transacts
The IMF’s April 2026 note — authored by Sonja Davidovic and Hervé Tourpe — represents the first acknowledgement by a multilateral institution that AI agents are entering the payment system as autonomous actors [3]. The note identifies a foundational conflict: most payment regimes require that every payment order be traceable to an authorised instruction from an account holder or its legally recognised agent. Agent-initiated payments violate this model because individual transactions may not correspond to specific, pre-approved human instructions. The agent interprets objectives, breaks them into tasks, and initiates payments as part of task execution — a process that does not map cleanly onto the human-instruction-to-payment-order chain that payment law assumes.
The IMF note introduces a critical concept: the shift from Know Your Customer (KYC) to Know Your Agent (KYA) [3]. In the KYC regime, financial institutions verify the identity of the human behind a transaction. In the KYA regime, institutions must additionally verify the identity of the agent, the scope of authority delegated to it, the intent behind the transaction, and the chain of accountability linking the agent’s action to a human principal. No major payment system currently implements KYA. The IMF notes that emerging standards — ERC-8004 for on-chain agent registries, Google’s Universal Commerce Protocol (UCP) for agent-mediated commercial discovery, the x402 protocol for agent-embedded HTTP payments [3] — are beginning to address the infrastructure gap, but none has achieved adoption at scale.
Mastercard’s “Verifiable Intent” framework, announced March 5, 2026, addresses the authorisation gap from the payment-rail side: it requires that every agent-initiated transaction carry a cryptographic proof linking the transaction to a specific user authorisation and delegation scope [13]. IBM’s orchestration layer supports integration. But Verifiable Intent is an industry proposal, not a regulatory requirement. Its adoption is voluntary. And voluntariness, as the credible commitment literature demonstrates, is structurally inadequate under competitive pressure [14].
2. Why Current Institutional Frameworks Fail
2.1 Payment Authorisation: The Human-Instruction Assumption
The entire architecture of modern payment systems rests on a single assumption: a human being authorised the transaction. Credit card networks, ACH transfers, wire transfers, mobile payment systems — all require that a payment instruction be traceable to a specific human decision. Fraud detection models are calibrated to human behavioral patterns: transaction velocity, geolocation, spending category consistency, time-of-day signatures. When a human’s card is used in an unusual pattern, the system flags it. When an AI agent’s spending pattern is unusual, no system exists to flag it — because no baseline of “normal agent behavior” has been established [3].
The IMF note identifies the precise failure mode: “Traditional fraud models rely on human behavioral patterns, which become ineffective when transactions are initiated by autonomous agents” [3]. This is not a calibration problem — it is a category problem. The models are not poorly tuned for agents; they are designed for a different kind of actor entirely. An agent that creates three cloud accounts, registers two domains, subscribes to four services, and deploys six applications in ninety seconds is exhibiting normal agent behavior. A human doing the same would trigger every fraud alert in the system. The distinction between legitimate agent activity and compromised agent activity cannot be drawn using models built to distinguish legitimate human activity from compromised human activity.
2.2 Identity: The Missing Layer
Every financial transaction requires identity verification — but identity, in the existing framework, means human identity. An AI agent operating under a human’s Stripe login inherits the human’s identity. This creates a fundamental attribution problem: when the agent transacts, the transaction is recorded as the human’s. If the agent overspends, the human is liable. If the agent is compromised and used to launder funds, the human’s account is flagged. If multiple agents operate under a single human’s credentials, their transactions are aggregated and indistinguishable.
The KYA framework the IMF proposes requires a new identity layer: a verifiable, persistent identity for the agent itself — distinct from but linked to its human principal — that carries information about the agent’s model version, deployment context, permission scope, and delegation authority [3]. This is architecturally analogous to the distinction between a corporate officer and the corporation: the officer acts on behalf of the corporation, but the corporation has its own legal identity, its own obligations, and its own liability exposure. No equivalent exists for AI agents. The agent acts economically but has no economic identity. It transacts but cannot be a party to a contract. It spends but cannot be invoiced. It earns but cannot be taxed.
2.3 The Guarantee Gap: Probability Is Not Certainty
The Agentic Risk Standard (ARS) paper, authored by researchers from DeepMind, Microsoft Research, and Columbia University, identifies what they call the guarantee gap: the disconnect between the probabilistic reliability that AI safety techniques provide and the enforceable guarantees users need before delegating high-stakes economic tasks [4]. A language model that behaves correctly 99.97% of the time is impressive. It is not sufficient when the 0.03% failure mode involves the user’s money. Safety research aims to reduce the probability of failure. The ARS paper argues that a complementary infrastructure is needed to compensate for failure when it occurs — applying the same financial safeguards used in construction (performance bonds), e-commerce (platform escrow), and capital markets (clearinghouse margin requirements) to AI agent transactions.
The ARS proposes a two-tier structure. For fee-only tasks (where the user risks only a service fee), payment is held in escrow and released only upon verified completion. For fund-moving tasks (where the agent must access user capital before outcomes can be verified — trading, currency exchange, financial API calls), the system introduces an underwriter who evaluates risk, requires the service provider to post collateral, and repays the user if a covered failure occurs. In 5,000 rounds of simulation, underwriting reduced user losses by up to 61%, though zero-loading premiums left underwriters insolvent — revealing the same structured trade-offs between protection and market participation that exist in traditional insurance [4]. FINRA’s 2026 regulatory oversight report included its first-ever section on generative AI, warning broker-dealers to develop procedures specifically targeting hallucination risk in financial contexts [15].
2.4 Consumer Protection: The Consent Problem
When a human purchases a product, consumer protection law provides a clear framework: the consumer consented to the transaction, received disclosures about the product, has recourse through chargeback and dispute resolution, and can sue for misrepresentation. When an AI agent purchases a domain, subscribes to a service, or deploys an application on behalf of a human, the consent architecture collapses. Did the human consent to this specific transaction? Or did the human consent to a goal (“deploy my app”) and the agent selected the specific transactions to achieve it? If the agent overpays for a domain because it lacks market context, is that the human’s failure for setting an inadequate spending policy, the agent provider’s failure for building an agent without price-comparison capabilities, or the platform’s failure for not requiring agent-specific pricing disclosures?
The answer, under current law, is: nobody’s failure, because the law does not recognise the scenario. Consumer protection statutes assume that the consumer and the transacting entity are the same person, or that the transacting entity is a human agent (an employee, a broker, a fiduciary) with legal obligations to the principal. An AI agent is neither. It is a probabilistic system executing goal-directed behavior through a sequence of economic transactions that no consumer protection framework anticipated.
3. Toward an Institutional Architecture for Agent Economic Activity
The institutional gap cannot be closed by technical controls alone. Spending caps, escrow mechanisms, and audit logs address symptoms. The structural problem is that the agent operates in an institutional vacuum — a space where economic activity occurs but economic governance does not apply. Four institutional components are needed.
3.1 Agent Identity Infrastructure
Economic actors require identities. The agent needs a verifiable, persistent, machine-readable identity — distinct from its human principal’s identity — that carries structured information about model version, deployment context, permission scope, delegation authority, and operational history. The identity must be portable across platforms (an agent that transacts on Stripe, deploys on Cloudflare, and interacts with Mastercard’s payment rail must carry a consistent identity), tamper-evident (modification of delegation scope must be auditable), and revocable (the principal must be able to terminate the agent’s authority in real time).
The ERC-8004 standard for on-chain agent registries [3], the TIVA (Trustless Intent Verification for Autonomous Agents) framework from recent arXiv work [16], and Mastercard’s Verifiable Intent [13] all point toward this architecture. None has achieved interoperability. The critical design question is who issues and governs the identity: the agent provider (Anthropic, OpenAI), the platform (Stripe, Cloudflare), a neutral registry (analogous to domain name registrars), or a regulatory body. The history of digital identity suggests that government-issued or government-regulated identities are necessary for financial transactions above a de minimis threshold, but that industry-issued identities suffice for low-risk interactions. The tiered identity model mirrors the tiered autonomy model from the liability vacuum analysis [17]: higher-stakes economic activity requires stronger identity verification.
3.2 Delegated Authority Frameworks
The principal-agent relationship between a human and an AI agent requires formal specification of the authority being delegated. The current architecture — a human logs into Stripe, and the agent inherits the human’s full account permissions — is the digital equivalent of handing someone a signed blank cheque. The delegation must be scoped: what transaction types the agent may execute, what spending limits apply per transaction and per session, what categories of commercial relationship the agent may enter, what approval checkpoints exist for irreversible financial commitments, and what conditions trigger automatic authority revocation.
This is not an AI-specific problem. Delegation of financial authority is a solved problem in corporate law (power of attorney, corporate resolutions, signatory authority) and a partially solved problem in API-based commerce (OAuth scopes, API key permissions). What is missing is the translation of these established frameworks into agent-specific infrastructure. The IMF’s proposed “mandate-based authorisation” model [3] — where the agent operates within a machine-readable mandate that specifies the scope, limits, and conditions of its economic authority — provides the right architectural direction. The mandate functions as a digital power of attorney: specific, bounded, auditable, and revocable.
3.3 Settlement-Layer Assurance
The ARS paper’s core contribution is recognising that agent economic activity requires a settlement layer that operates independently of the agent’s own reliability [4]. The insight is simple but profound: no amount of alignment research, RLHF training, or safety testing can reduce the probability of agent failure to zero. LLMs are inherently stochastic. The guarantee gap is permanent. Therefore, the institutional response cannot be to prevent all failures; it must be to compensate for failures when they occur — just as clearinghouses compensate for counterparty default, deposit insurance compensates for bank failure, and performance bonds compensate for contractor non-delivery.
The practical implementation requires three mechanisms: escrow for fee-only tasks (payment released upon verified completion), underwriting for fund-moving tasks (independent risk assessment, collateral requirements, failure compensation), and mandatory insurance for high-autonomy deployments (pooled risk across deployers). The ARS simulation demonstrating 61% loss reduction through underwriting [4] provides the first actuarial evidence that these mechanisms are quantitatively meaningful — though the insolvency of zero-loading underwriters reveals that accurate failure-rate estimation is the binding constraint on institutional viability.
3.4 Regulatory Recognition
The institutional components above — identity, delegation, settlement assurance — require regulatory recognition to become binding rather than voluntary. The IMF note is the most significant policy signal to date precisely because it comes from a multilateral institution with normative authority over global payment systems. FINRA’s inclusion of generative AI in its 2026 oversight report signals awareness at the financial regulatory level [15]. The FCA’s chief data officer has stated that the authority will apply existing rules — the senior managers regime and consumer duty — to hold executives responsible for agent-caused harm [18]. Gartner predicts 40% of financial services firms will use AI agents by year-end 2026 [18].
The regulatory gap is not the absence of concern but the absence of category. Existing regulatory frameworks — KYC, AML, consumer protection, payment services directives — assume human actors. They do not prohibit agent economic activity; they simply do not recognise it. The agent operates in the regulatory equivalent of international waters: subject to no jurisdiction’s rules because no jurisdiction has claimed authority over this class of actor. The first jurisdiction to create a comprehensive regulatory framework for AI economic agents — defining identity requirements, delegation standards, settlement obligations, and consumer protection for agent-mediated transactions — will establish the global standard, just as the EU’s GDPR established the global standard for data protection through the Brussels effect [19].
4. Implications: What This Changes
4.1 For AI Labs: The Revenue Model Is the Governance Model
OpenAI’s advertising trajectory reveals a structural truth about AI business models: how the agent earns money determines what governance the agent requires. A subscription-funded agent (Anthropic’s Claude Pro, OpenAI’s ChatGPT Plus) has aligned incentives: the user pays, the agent serves the user, the revenue model and the service model point in the same direction. An ad-funded agent has structurally misaligned incentives: the advertiser pays, the user engages, and the agent’s economic interest is in maximising engagement time and ad exposure, not in minimising the user’s time to solution. Altman identified this in 2024. He proceeded anyway.
The governance implication is direct: ad-funded agents should face stricter transparency requirements than subscription-funded agents, precisely because the incentive misalignment creates risks that subscription models do not. This is not a novel regulatory principle; it is how broadcast media, financial advisory, and pharmaceutical marketing are already regulated. When the intermediary’s revenue depends on a third party (the advertiser) rather than the end user, disclosure obligations increase. The same principle should apply to conversational AI. The user should know, at minimum, what data informs ad targeting, whether conversation content influences ad selection, and what the advertiser paid.
4.2 For Payment Infrastructure: Agent-Ready Rails
Payment networks — Visa, Mastercard, ACH, SWIFT — must develop agent-specific processing capabilities. This means: agent identity fields in transaction metadata (distinguishing human-initiated from agent-initiated payments), agent-specific fraud models calibrated to agent behavioral baselines rather than human behavioral baselines, delegation-scope verification at the point of transaction (confirming the agent’s authority to execute this specific type and amount of payment), and real-time notification to the human principal for transactions above a configurable threshold. Mastercard’s Verifiable Intent [13] is the first major payment-network initiative in this direction. Visa has not yet announced an equivalent.
4.3 For Regulators: The Know-Your-Agent Mandate
The shift from KYC to KYA is not optional. It is the minimum institutional adaptation required by the empirical reality that agents now initiate financial transactions. The KYA framework must require: verifiable agent identity linked to a responsible human principal, machine-readable delegation mandates specifying the agent’s economic authority, mandatory audit trails for all agent-initiated transactions, mandatory settlement assurance (escrow or underwriting) for transactions above a defined threshold, and incident reporting requirements for agent-caused financial losses. The IMF note provides the intellectual foundation [3]. The regulatory implementation is a matter of political will, not conceptual difficulty.
4.4 Testable Predictions
Prediction 1: An agent-initiated transaction will cause a financial loss exceeding $1 million within 12 months. The Cloudflare-Stripe protocol enables agents to spend money at scale. The OpenClaw security exposure (1,800+ instances leaking API keys [9]) demonstrates the attack surface. A compromised agent with financial authority is a qualitatively different threat from a compromised agent with only code-generation capability. The loss event is a matter of when, not whether.
Prediction 2: At least one major payment network will implement agent-specific transaction metadata by Q2 2027. Mastercard’s Verifiable Intent initiative [13] signals intent. The competitive pressure from agent-mediated commerce — and the fraud liability exposure from agent-initiated transactions indistinguishable from human transactions — will force infrastructure adaptation faster than regulatory mandate.
Prediction 3: OpenAI’s ad revenue will create a measurable divergence between ad-funded and subscription-funded model behaviors within 18 months. The incentive misalignment Altman identified will produce observable differences in response patterns — session length, engagement optimisation, topic steering — between the ad-supported free tier and the ad-free paid tier. Independent researchers will detect and publish the divergence, accelerating regulatory attention to the governance gap between ad-funded and subscription-funded conversational AI.
Prediction 4: The EU will be the first jurisdiction to propose a regulatory framework for AI economic agents, anchored in the AI Act’s high-risk classification. The AI Act’s existing framework for high-risk AI systems provides a regulatory chassis that can be extended to cover economic agency. The EU’s track record of first-mover regulation (GDPR, AI Act, Digital Markets Act) and its institutional appetite for comprehensive frameworks make it the most likely jurisdiction to act. The timeline: a formal proposal by Q4 2027.
The Honest Limit
This analysis has identified the institutional gap. It has not closed it. The agent identity infrastructure proposed in Section 3.1 requires interoperability across providers, platforms, and payment networks that no single actor can unilaterally establish. The settlement assurance mechanisms require actuarial data on agent failure rates that does not yet exist in sufficient volume or granularity. The regulatory frameworks require political consensus in jurisdictions whose AI governance priorities are divergent or actively hostile to regulation.
Several findings would revise this thesis. If the Cloudflare-Stripe protocol’s spending caps prove sufficient to prevent meaningful financial losses — if the $100 default cap is an adequate substitute for institutional governance — then the urgency of the economic identity gap diminishes. If OpenAI’s architectural separation between response generation and ad selection proves robust under independent audit, the incentive-misalignment concern is weaker than argued. If the ARS escrow and underwriting mechanisms achieve voluntary adoption at scale without regulatory mandate, the case for regulatory intervention weakens.
What remains regardless is the structural diagnosis. In June 2026, AI agents can spend money, earn money, deploy capital, enter commercial relationships, and generate revenue. They do so without legal personhood, without fiduciary obligations, without verifiable identity, and without accountability structures. Every institution governing economic activity was built for a world in which economic actors are human. The agents have arrived in the economy. The institutions that govern the economy have not noticed they are there.
References
[1] S. Chatterjee and B. Irvine-Broque, “AI agents can now deploy to Cloudflare,” Cloudflare Blog, Apr. 30, 2026. See also: InfoQ, “Cloudflare and Stripe let AI agents create accounts, buy domains, and deploy to production,” May 2026.
[2] S. Fischer, “OpenAI launches self-serve ad platform,” Axios, May 5, 2026.
[3] S. Davidovic and H. Tourpe, “How Agentic AI Will Reshape Payments,” IMF Notes, vol. 2026, no. 004, Apr. 24, 2026. doi:10.5089/9781513533308.068.
[4] W. Hua, T. Peng, C. Wang, I. Kaufman, C. Fang, and B. Lim, “Quantifying Trust: Financial Risk Management for Trustworthy AI Agents,” arXiv:2604.03976, Apr. 2026.
[5] S. Altman, fireside chat at Harvard University, May 2024. Reported in: Men’s Journal, “ChatGPT moves forward with CEO’s ‘last resort,’” Jan. 17, 2026.
[6] “OpenAI’s ad pilot crosses $100M in annualized revenue,” Reuters, Mar. 26, 2026.
[7] Search Engine Roundtable, “OpenAI announces conversion-optimized campaigns for ChatGPT ads,” May 28, 2026.
[8] D. Shipley (Beauceron Security), quoted in: “Are we ready to give AI agents the keys to the cloud?” InfoWorld, May 2026.
[9] NeuralCoreTech, “Agentic AI Infrastructure: Cloudflare & Stripe Power Autonomous Agents,” May 2026. Citing OpenClaw security research.
[10] Choice OMG, “ChatGPT Ads in 2026: How It Works and Where It’s Going,” May 2026.
[11] OpenAI, “Testing ads in ChatGPT,” openai.com, updated May 7, 2026.
[12] S. Pallaprolu, “ChatGPT Gets Ads: Sam Altman’s ‘Last Resort’ Is Here,” Medium, Jan. 19, 2026. Citing Wall Street Journal investor documents.
[13] Mastercard, “How Verifiable Intent builds trust in agentic AI commerce,” mastercard.com, Mar. 5, 2026.
[14] T. C. Schelling, The Strategy of Conflict. Cambridge, MA: Harvard Univ. Press, 1960. See also: Adhi, “The Credible Commitment Problem in AI Safety,” Mar. 2026.
[15] FINRA, “2026 Regulatory Oversight Report,” Dec. 2025. First section on generative AI.
[16] “Secure Autonomous Agent Payments: Verifying Authenticity and Intent in a Trustless Environment,” arXiv:2511.15712.
[17] Adhi, “The Liability Vacuum in Agentic AI: Why Tort Law Breaks When the Agent Has No Principal,” Mar. 2026.
[18] J. Rusu (FCA Chief Data Officer), quoted in Reuters: “Agentic AI race by British banks raises new risks for regulator,” 2026. Gartner prediction cited in same.
[19] A. Bradford, The Brussels Effect: How the European Union Rules the World. New York: Oxford Univ. Press, 2020.
메타데이터
- post_id
- ca140b5302b7
- slug
- the-agent-as-economic-actor-ca140b5302b7
- url
- https://medium.com/@adhix/the-agent-as-economic-actor-ca140b5302b7
- canonical_url
- https://medium.com/@adhix/the-agent-as-economic-actor-ca140b5302b7
- author_url
- https://medium.com/@adhix
- status
- ok
- fetched_at
- 2026-06-09 22:10:26