The current trajectory of agentic commerce is focused on establishing agent identity before addressing the complexities of payment. We saw this with the retirement of the ACP Instant Checkout in March 2026 and the subsequent shift toward deferred payment models like PAP v0.1. The latest attempts to bridge this gap suggest that the future of agent payments may not rely on traditional card rails at all, but rather on permission-token models that treat budgets as revocable, server-enforced constraints.
Recent demonstrations from Nevermined provide a concrete look at how this functions in practice. In early production tests, three different assistants—Claude, ChatGPT, and LangSmith Fleet—successfully paid five distinct vendors to complete tasks, including fetching live product pages, planning a trip, and producing a company brief, all for a total cost of under four cents and without the use of any pre-arranged API keys. This builds on more complex demonstrations, such as an agent tasked with turning news into a song. Using a 50-cent budget, the assistant autonomously discovered and paid four independent services: Brave for headlines (3.5 cents), Suno for lyrics and audio (15.5 cents), fal.ai for cover art (2.5 cents), and 2s.io for captions (4.5 cents). The total spend was 36 cents, all executed without pre-arranging access with any of the vendors. As the company notes, “Brave, Suno, fal.ai and 2s.io don’t know about each other, and nothing was arranged with any of them in advance. Each one does one thing, and the assistant combines them into a song about today’s news.”
The mechanism here departs from the standard practice of delegating credit card access to an agent. Instead, the agent operates within a defined budget grant. “The assistant never holds a key — it holds five dollars, for a week, spendable only through the Router, revocable in one click,” the documentation explains. This approach addresses the inherent risk of agentic overspending. “Budget works like a prepaid card with a server-enforced limit so the agent cannot overspend,” and the documentation notes, “An agent that spends your money on something it can answer for free is a badly behaved agent.”
This shift is occurring against a backdrop of significant industry friction. A PYMNTS study from September 2026 found that 93% of payment providers believe they should bear the losses from agent purchase errors, while a Product.ai April 2026 report noted that 42% of consumers would not trust AI for purchases over $25. By moving away from card rails, these protocols attempt to bypass the liability issues that plague traditional checkout flows. The demos utilized two distinct settlement layers: the machine payments protocol (MPP) on Tempo and the x402 protocol on Base, demonstrating interoperability across two different blockchains.
However, these demonstrations are currently limited to the company’s own reporting, and there has been no independent confirmation of these results. The self-reported data also highlights the messy reality of early-stage agentic infrastructure. The team noted that async polling costs—such as Suno charging half a cent per status check—can inflate expenses. Furthermore, failed calls still incurred costs of approximately 1.5 cents despite delivering no output, and price volatility remains a factor, with one caption service listed at 1.8 cents but ultimately charging 4.5 cents.
The broader pattern is clear: the industry is moving toward a model where agents pay for specific, discrete tasks rather than maintaining persistent access to a user’s financial accounts. “Your assistant pays for the things it cannot get on its own — live data, specialist APIs, someone else’s work — and does the reasoning itself, for free.” Whether this permission-token model can scale beyond controlled demos remains an open question. For now, the infrastructure is being built to support a world where agents act as autonomous consumers, provided they stay within the strict, revocable boundaries set by their human operators.
