What's new

Trust, Risk and Money: Interview With t54 CEO Chandler Fang on AI Agents That Spend

O

Olayimika Oyebanji

Guest
As AI agents move beyond recommendations and begin executing real financial transactions, questions of trust, liability and security are becoming harder to ignore. Who carries the risk when an autonomous system spends money incorrectly? How much access should software have to wallets and payment credentials? And what safeguards will be required before people feel comfortable letting agents transact without constant human approval?

In this interview with Olayimika Oyebanji, t54 CEO Chandler Fang discusses the practical challenges of building financial rails for autonomous agents, the early signals of demand, and what needs to change before AI systems can be trusted with real money.

As AI agents move from recommending purchases to actually making them, what are the biggest trust issues consumers and businesses need to think about?​


I would say the biggest shift is that agents are moving from giving advice to actually moving money, which raises the stakes pretty quickly. You need to know which agent is acting, who authorized it, what it is allowed to buy and how much it can spend.

There also needs to be a clear record when something goes wrong. We’ve always believed trust, permissions and accountability matter more than simply making agents smarter. Financial autonomy only works if the risk around that autonomy is contained.

How comfortable are people realistically going to be giving autonomous software access to their money, wallets or payment credentials?​


I don’t think most people will be comfortable handing an AI agent unrestricted access to their bank account or crypto wallet, and frankly, they shouldn’t have to. The better model is giving the agent controlled spending power without exposing the user’s underlying funds or credentials. That’s part of the thinking behind Claw Credit. An agent can transact within defined limits, while the user’s money stays protected. If agentic payments require people to surrender financial control, mainstream adoption is going to be difficult.

Who should carry the financial risk when an agentic transaction goes wrong: the user, the agent provider, the merchant or the payment provider?​


The risk probably can’t sit entirely with one party. It depends on why the transaction failed. A merchant shouldn’t necessarily be responsible for an agent behaving badly, but users also shouldn’t carry unlimited liability for software mistakes.

Payment providers and agent developers will need clear rules around authorization, disputes and fraud. The bigger point is that risk needs to be contained before the transaction happens. Spending limits, permissions and credit structures can reduce the damage rather than trying to fix everything afterward.

Within a credit card network, determining who bears the risk if something goes wrong is a process called the liability shift. The interesting part now is that AI agents (or agent developers) may become a counterparty within this entire agent network. This is an open but very innovative discussion happening within the credit card industry: how do we consider how much risk different parties bear, especially given there are potential new counterparties entering this ecosystem?

Could giving AI agents direct access to bank accounts or crypto wallets create an entirely new category of financial fraud and security risk?​


Absolutely. Giving autonomous software unrestricted access to a wallet or bank account creates a pretty obvious attack surface. An attacker no longer necessarily needs to steal the money directly; they could manipulate the agent into spending it for them.

That’s why I think the industry needs to move away from the idea that autonomy means unlimited financial access. Agents should operate inside tightly defined permissions and spending limits. The goal is to give software enough freedom to work without putting the user’s entire financial account at risk.

How serious is the threat of prompt injection when AI agents have the ability to spend real money?​


Prompt injection becomes much more serious once an agent can spend money. If an attacker can manipulate what an agent sees or how it interprets instructions, they may be able to influence a real financial transaction. At that point, it’s not just an AI reliability problem; it becomes a payments security problem. You need safeguards outside the model itself.

Identity, permissions, transaction limits and policy controls should determine what an agent can actually do, even if somebody successfully manipulates what the model thinks it should do.

What kinds of spending limits, permissions and identity checks will be needed before people trust agents to transact without approving every payment?​


I don't believe a spending limit is the right approach eventually. You cannot rule-base an AI agent, just like you cannot rule-base your kids by telling them when or where to spend your money, right?

The correct way to think about this problem is: what is the framework for handling disputes and chargebacks, making sure that when something goes wrong, there is a proper procedure to protect the interests of consumers?

Meanwhile, we need to make sure that on a real-time basis, when transactions are going through the network, we perform risk assessment on agent identity, the purpose and intent of the transactions, and the merchant's credibility.

Basically, give users a worry-free experience instead of pushing this burden onto them by having them set up credit limits. At a high level, a spending limit is useful to create a stopgap, but it won't offer actual risk protection for agent behavior at all.

Credit cards helped build consumer confidence through limits, fraud protection and chargebacks. Do AI agents need a similar financial safety net?​


I think that basic idea translates really well. Credit cards became useful partly because consumers didn’t have to expose their entire bank balance every time they bought something. There were limits and protections around the transaction. Agents need something similar.

Rather than giving software unrestricted access to your wallet, you can give it controlled spending capacity and contain the downside. If we want people to delegate payments to software, protection has to be built into the experience from day one.

With over 135,000 AI agents applying for credit lines through Claw Credit , what does that suggest about demand for payment infrastructure designed specifically for autonomous agents?​


For us, 135,000 applications is a pretty strong signal that agents are starting to need financial infrastructure of their own.

Agents increasingly have to buy data, APIs, compute and other services to complete tasks, and stopping to ask a human to fund every small payment defeats a lot of the point of autonomy. The interesting part isn’t just the number, though. It shows payments are becoming a real bottleneck as agents move from experimentation into economic activity.

What does underwriting an AI agent actually involve, and how is that different from assessing a human borrower?​


Underwriting an agent is different because you’re not looking at salary, employment history or a traditional credit score. You’re looking at the agent itself: its identity, transaction behavior, repayment history and potentially the environment it operates within.

Agents can start with relatively small limits and build greater capacity through responsible behavior. That creates something resembling a credit history for software. The interesting part is that risk assessment can become continuous, so an agent’s financial permissions can change as its behavior changes over time.

If AI agents eventually make more financial transactions than humans directly, what needs to happen between now and then for people to actually trust them with their money?​


We need to stop thinking that smarter models automatically create trustworthy financial agents. They don’t. Before agents can transact at massive scale, we need reliable identity, clear permissions, controlled access to money, strong security and an audit trail showing exactly what happened.

We’re already seeing the transaction volume grow, so this isn’t really a theoretical problem anymore. My view has always been that trust will become the limiting factor. If we solve that layer properly, people can delegate more financial activity without giving up financial control.
 

Thread statistics

Created
Olayimika Oyebanji,
Replies
0
Views
2
Back
Top