iCentric Insights Insight

Agent-to-Agent Purchasing: The Settlement Gap Nobody Is Solving

AI agents can initiate purchases in milliseconds, but existing clearing cycles create liability windows that current protocols simply aren't built to handle.

October 5, 2026
Agentic CommercePayments InfrastructureAI Strategy
Agent-to-Agent Purchasing: The Settlement Gap Nobody Is Solving

Visa and Stripe have both made significant moves into agentic payment infrastructure in recent months. Visa's AI agent payment framework and Stripe's tooling for autonomous transactions have generated considerable excitement — and understandably so. The prospect of AI agents procuring services, managing supplier relationships, and executing multi-step purchasing workflows without human sign-off represents a genuine step change in operational efficiency. But beneath the announcements, a more fundamental problem is going quietly unaddressed: not whether AI agents can authenticate to make a purchase, but what happens in the hours and days after they do.

The payments industry has largely framed agentic commerce as an identity and authorisation challenge — how do you verify that an AI agent has the delegated authority to spend on behalf of an organisation? That is a real problem, and progress is being made. What is receiving far less attention is settlement finality. When an agent initiates a transaction in milliseconds, that transaction still enters the same clearing infrastructure built for human-paced commerce — infrastructure that operates on T+1 or T+2 cycles and leaves open liability windows that existing protocols were never designed to govern for fully autonomous, high-frequency activity.

Why Settlement Finality Is the Harder Problem

In traditional commerce, the gap between authorisation and settlement is largely invisible to buyers and sellers because humans are not operating at the speed where it matters. A marketing manager who approves a SaaS subscription on Monday and sees the debit clear on Wednesday has no particular exposure in that window. But an AI agent executing hundreds of procurement decisions per day — dynamically selecting suppliers, triggering API-based service consumption, or managing real-time inventory purchasing — creates a fundamentally different risk profile across that same window.

Consider a scenario where an agentic system procures cloud compute capacity from multiple vendors simultaneously, optimising for price and availability at the moment of decision. Each transaction is authorised instantly. But if one vendor's service fails to deliver and the agent initiates a reversal, that reversal must navigate a clearing cycle that was designed for periodic batch settlement, not real-time autonomous correction. The liability for the outstanding value sits somewhere — with the merchant, the acquirer, or the issuing organisation — and current frameworks offer no clear assignment. Multiply this across an enterprise running several agent workflows simultaneously and the aggregate liability exposure becomes material.

What the Existing Infrastructure Actually Handles

Card network rails — even with their modern real-time authorisation capabilities — are fundamentally asynchronous at the settlement layer. Faster Payments in the UK provides near-instant settlement for push payments, but it was designed for discrete, human-initiated transactions and lacks the programmatic dispute resolution primitives that agentic commerce will require. Open Banking provides better API access and cleaner data flows, but settlement finality under the current Variable Recurring Payments framework still depends on human-readable consent models that map poorly to agent delegation hierarchies.

Stripe's recent infrastructure developments acknowledge this tension by building tooling that allows agents to operate within pre-approved spending mandates — essentially constraining the problem rather than solving it. Visa's framework similarly focuses on credentialing the agent as an authorised actor. Both approaches reduce the probability of problematic transactions, but they do not resolve what happens when a problematic transaction occurs and settlement is already in motion. The honest assessment is that the industry is building the front-end of agentic commerce competently while deferring the back-end liability question.

The Governance Gap for UK Organisations

For UK organisations subject to FCA oversight, internal audit requirements, or contractual obligations around procurement controls, this gap has concrete compliance implications. Delegating purchasing authority to an AI agent is not inherently problematic — organisations have long used automated systems for procurement within defined parameters. The issue is that existing governance frameworks assume a human is reachable to ratify, reverse, or account for a decision within a commercially meaningful timeframe. When settlement is pending across a T+2 window and the agent has already moved on to its next decision, that assumption breaks down.

Treasury and finance teams at organisations piloting agentic workflows will need to think carefully about how agent-initiated transactions are classified on the balance sheet during the settlement window, how disputes are logged and attributed for audit purposes, and what the organisation's liability position is if an agent transacts with a counterparty that subsequently becomes insolvent before settlement completes. None of these questions have clean answers under current UK commercial law or FCA guidance, and neither Visa nor Stripe's current frameworks bring them closer to resolution. Legal and compliance teams should be engaged well before agentic purchasing moves beyond controlled pilots.

Emerging Approaches Worth Watching

There are genuine technical pathways towards better settlement finality for agentic transactions, though none are production-ready at enterprise scale. Programmable settlement layers — whether built on distributed ledger infrastructure or as extensions to existing real-time gross settlement systems — could in principle allow agent-initiated transactions to carry embedded settlement conditions: funds move only when both delivery confirmation and payment instruction are cryptographically linked. Several central banks, including the Bank of England, are exploring wholesale CBDC architectures that could eventually support this kind of conditional finality. The timelines are long, but the direction is relevant.

In the nearer term, some organisations are experimenting with escrow-based agent payment flows, where agentic transactions are routed through a holding layer that releases funds only on confirmed fulfilment. This reintroduces latency — which partly defeats the efficiency case for agentic commerce — but it provides a governed settlement boundary that current rails cannot. For high-value or high-frequency agent purchasing, this trade-off may be worth making until the infrastructure catches up.

The organisations that will benefit most from agentic purchasing are those that move deliberately rather than quickly. The authentication and authorisation layer is maturing fast — within the next few years, credentialing an AI agent to transact on your behalf will likely be a solved problem. The settlement and liability layer is not on the same trajectory. Senior decision-makers considering agentic commerce pilots should be asking their payment providers, legal teams, and technology partners one question that is currently going underasked: who holds the liability between authorisation and settlement, and under what conditions does it transfer? If that question does not have a documented answer, the pilot is not ready for production.

At iCentric, we work with organisations navigating exactly this kind of infrastructure complexity — where the commercial opportunity is genuine but the operational and legal scaffolding needs to be built alongside it. If your organisation is scoping agentic workflows that include purchasing decisions, we would welcome a conversation about how to structure that capability responsibly from the outset.

What does 'settlement finality' actually mean in the context of AI agent transactions?

Settlement finality refers to the point at which a payment is irrevocably complete and funds have definitively transferred between parties. In agentic commerce, the concern is that AI agents authorise transactions instantly but the actual movement of funds through clearing infrastructure — typically T+1 or T+2 — creates a window where the transaction is committed but not yet final, leaving open questions about who bears liability if something goes wrong in that interval.

Does Faster Payments in the UK solve the settlement finality problem for AI agents?

Faster Payments provides near-instant settlement for push payments, which does close the settlement gap for qualifying transactions. However, it was designed for discrete, human-initiated transfers and lacks the programmatic dispute resolution and agent delegation primitives that autonomous purchasing at scale requires. It also does not cover the full range of payment types agents would need to use, including card-based procurement and variable recurring payments.

What is the difference between Visa's AI agent framework and solving the settlement problem?

Visa's AI agent payment framework focuses primarily on credentialing and authorisation — establishing that an AI agent has legitimate, delegated authority to initiate a transaction on behalf of an organisation. This is meaningful progress on the identity layer, but it does not alter the underlying clearing and settlement infrastructure. A credentialed agent still transacts through the same T+1 or T+2 settlement cycles, leaving the liability window unaddressed.

How should a UK finance team classify agent-initiated transactions that are authorised but not yet settled?

This is currently an open accounting question without definitive regulatory guidance specific to agentic transactions. In practice, organisations should treat pending agent-initiated transactions similarly to other authorised-but-unsettled items — as contingent obligations — but should work with their auditors to establish a documented classification policy before scaling agentic purchasing, particularly where transaction volumes are high enough to create material aggregate exposure.

Are there any regulatory obligations under FCA rules specific to AI agent purchasing?

The FCA has not yet issued rules specifically governing AI agent purchasing authority, but existing obligations around transaction monitoring, record-keeping, and audit trails apply regardless of whether a human or an automated system initiates a transaction. Organisations regulated by the FCA should ensure their agent workflows produce complete, attributable audit records and that their governance frameworks explicitly address delegated purchasing authority to automated systems.

What is an escrow-based agent payment flow and when does it make sense?

An escrow-based approach routes agent-initiated payments through an intermediate holding layer, releasing funds to the merchant only once a delivery or fulfilment condition is confirmed. This effectively creates a programmatic settlement boundary that standard card rails cannot provide. It reintroduces some latency, making it less suitable for high-frequency, low-value transactions, but it is a viable governance mechanism for high-value or high-risk agent procurement where liability clarity is essential.

Could blockchain or distributed ledger technology solve the settlement finality problem for agentic transactions?

Programmable settlement layers, including those built on distributed ledger infrastructure, could theoretically support conditional finality — where funds transfer only when both a payment instruction and a fulfilment confirmation are cryptographically linked. However, no such solution is currently production-ready at enterprise scale for mainstream commerce. Wholesale CBDC initiatives, including work by the Bank of England, are exploring related architectures, but practical deployment remains some years away.

How do spending mandates — as used by Stripe's agentic tooling — help, and where do they fall short?

Pre-approved spending mandates constrain the scope of what an agent can purchase, reducing the probability of unauthorised or erroneous transactions. They are a sensible risk management layer. Their limitation is that they are a preventive control, not a remedial one — they do not resolve what happens once a transaction within the approved mandate has been initiated and is in the settlement pipeline but needs to be reversed or disputed.

What contractual protections should organisations seek from payment providers when deploying agentic purchasing?

Organisations should seek explicit contractual clarity on liability assignment during the settlement window, defined dispute resolution procedures that accommodate programmatic — rather than human-initiated — reversal requests, and SLA commitments around settlement timing. It is also worth establishing in writing how the provider will handle scenarios where an agent initiates a transaction with a counterparty that becomes insolvent before settlement completes, as standard merchant agreements often do not address this adequately.

At what scale of agent transaction volume does the settlement liability gap become a material business risk?

There is no universal threshold, but the aggregate outstanding value across the settlement window is the key metric to monitor. An organisation running dozens of agent transactions daily at low individual values may carry a manageable exposure. An organisation using agents for high-value supplier procurement or dynamic cloud resource purchasing could accumulate material unsettled obligations very quickly. Finance teams should model the worst-case aggregate exposure under their specific agent workflows before signing off on production deployment.

Agentic Commerce Payments Infrastructure AI Strategy

Get in touch today

Book a call at a time to suit you, or fill out our enquiry form or get in touch using the contact details below

iCentric
October 2026
MONTUEWEDTHUFRISATSUN

How long do you need?

What time works best?

Showing times for 9 October 2026

No slots available for this date