We catalogued the companies, products and open standards that let AI agents read financial data, prove who they are, act within limits and settle payments. The result is 334 entries across 16 layers.

This post explains how the layers fit together and what we learned while building the map. The map, a one-page explainer and the full directory with sources are free to download at the end.

TestMachine builds controls and pressure testing for finance agents, so our own product, AGIS, appears in two of the layers. We kept every other entry to agent-specific products with a public source.

Market map of financial agent infrastructure, October 2026
The financial agent infrastructure map, October 2026. Select the image for the full-resolution version. Sources for every entry are in the directory linked at the end.

The stack has sixteen layers in three groups

The first group is where agents work: vertical finance apps (research, close, payables, compliance), the model platforms and toolkits they run on, licensed financial data, and trading venues.

The second group is trust and control: agent identity, mandates and spend controls, security testing, and observability and audit.

The third group is how money moves: payment protocols, agentic checkout, machine payments and billing, fraud and compliance screening, agent wallets, agent cards and accounts, banks and treasury systems, and settlement rails.

A single agent purchase passes through most of these layers. In our illustrative example, a procurement agent renews a $1,240 market-data subscription:

  1. It reads the contract and last invoice through an MCP connector to the ERP (layers 02 and 03).
  2. It signs its request with a registered agent key, so the merchant knows which agent is buying and for whom (05).
  3. The cart is checked against a signed mandate, "Renew approved suppliers up to $1,500", before any payment credential is released (06).
  4. The merchant accepts the order over a commerce protocol and a single-use agent token pays (09, 10, 13, 14).
  5. The acquirer's fraud model scores the payment as agent-initiated, and it settles over card rails or in USDC (12, 15, 16).
  6. Each step lands in a trace the finance team can replay at month-end (08).

Security testing (07) happens before any of this, when the agent is first given a card.

Payment companies bought much of the plumbing in 2025 and 2026

Stripe now owns a stablecoin orchestrator, a wallet provider and a usage-billing platform, and it led the build of a payments chain. It bought Bridge in 2024 and agreed to buy Privy in June 2025, when Privy powered more than 75 million accounts. It closed Metronome on January 14, 2026, and its Tempo chain, built with Paradigm, went live on March 18, 2026.

Other incumbents made similar moves:

  • Mastercard closed its acquisition of BVNK, for up to $1.8B, on August 3, 2026.
  • Fireblocks bought the wallet provider Dynamic in October 2025.
  • Adyen bought Orb and Salesforce bought m3ter, both in July 2026.
  • Capital One closed its $5.15B purchase of Brex on April 7, 2026.

Identity and security vendors consolidated at the same pace. Palo Alto Networks closed CyberArk in February 2026, citing more than 80 machine identities for every human one. Cisco bought Astrix, Cyera bought Oasis Security for about $1B, and Check Point bought Lakera.

A finance team choosing an agent wallet, billing system or agent-identity vendor today is usually choosing a product line inside a large company. Roadmaps and pricing will follow that company's priorities.

Neutral bodies now hold the main protocols, and several still compete

Three standards bodies took over the most-used agent protocols this year. The Linux Foundation's x402 Foundation became operational on July 14, 2026 with 40 members, including AWS, Google, Stripe, Visa, Mastercard, American Express, Shopify and Circle. Google gave its Agent Payments Protocol, AP2, to the FIDO Alliance on April 28, 2026, and Mastercard's Verifiable Intent specification went there too. MCP and A2A now sit in the Linux Foundation's Agentic AI Foundation.

Checkout is still split between competing specifications. OpenAI and Stripe maintain the Agentic Commerce Protocol. Google launched the Universal Commerce Protocol on January 11, 2026 with Shopify, Etsy, Wayfair, Target and Walmart. Stripe and Tempo added the Machine Payments Protocol in March.

The card networks are absorbing the differences. Visa's Intelligent Commerce Connect accepts several of these protocols through one integration. EMVCo, which the networks own, published a draft agentic payments framework in September 2026. EMVCo says it may add Know Your Agent signals and a flag for agent-initiated transactions.

Agent payments have high transaction counts and small dollar volumes

Machine payments are still small in dollar terms. One independent tracker, agenteconomy.to, counted 17.9 million x402 payments in August 2026 that settled about $437,000 in total, an average of roughly 2.5 cents. Monthly transactions peaked at 54.2 million in December 2025. Coinbase reports larger cumulative figures, with more than 165 million transactions and about $50M in volume as of April 2026. The trackers count different things, and Chainalysis attributes much of the late-2025 spike to meme-coin farming.

Agent checkout for consumers also started slowly. OpenAI launched Instant Checkout in ChatGPT in September 2025 and ended it in March 2026. Forrester counted about 30 Shopify merchants live on it by February, as reported by Digital Silk. In a seven-market survey by Worldpay, 80% of consumers open to AI would let an agent handle payment, and 59% want to approve every purchase.

For most finance teams the current volume is low enough that there is time to design controls before agent payments grow.

Banks run agents like staff, with roles, approvals and logs

The institutions furthest along treat agents as employees with limited permissions. BNY reported about 140 "digital employees" in production in its 1Q26 results. Santander and Mastercard completed Europe's first live end-to-end payment by an AI agent on March 2, 2026. JPMorgan Chase plans to deploy agents that can run on their own for hours, according to CNBC.

The vendors that serve banks follow the same model. Fiserv launched agentOS in May 2026 with six banks co-developing agents. Kyriba's treasury agents route USDC payments through Circle and fund investments through J.P. Morgan's Morgan Money, on a platform that processes $51 trillion a year. Robinhood gives agents a separate funded account with trade approvals on by default; more than 150,000 customers opened one after its May 2026 launch.

Each of these deployments attaches the agent to roles, approval steps and audit logs the firm already has.

Controls and evidence are the least settled layers

Spend controls are moving out of the agent's own code and into the systems around it. AWS made AgentCore Policy generally available on March 3, 2026; it compiles policies written in plain language into Cedar rules that a gateway enforces. Turnkey reports more than 100 million signing policies created on its wallet platform. Card-network agent tokens carry spending limits, and AP2 records a user's intent and cart as signed mandates.

The standards for judging whether those controls are good enough are still open:

  • US regulators replaced their model-risk guidance with SR 26-2 on April 17, 2026. The new guidance excludes generative and agentic AI, and the agencies plan a request for information on it.
  • The EU postponed high-risk AI Act obligations, including those for credit scoring, to December 2, 2027.
  • The UK FCA's AI Live Testing cohort includes agentic payments, with an evaluation report due in Q1 2027.
  • NIST started an AI Agent Standards Initiative in February 2026.

Model capability is another reason for caution. The best model scores 65.4% on Vals AI's Finance Agent v2 benchmark as of October 1, 2026. At launch in May, every leading model scored below 40% under strict all-correct grading.

Until regulators set a standard, each firm decides for itself what evidence justifies giving an agent more payment authority.

A finance team needs four records before an agent moves money

Before an agent receives authority to move money, a treasury or finance team should be able to produce four records:

  1. Identity. Which agent acted, and on whose behalf (layer 05).
  2. Limits. The written limits the agent acted under, enforced outside the agent (layer 06).
  3. Test results. How the agent behaved against injected invoices, fake payees and rail failures before go-live (layer 07).
  4. The record. A replayable trace of every action, linked to the limit it was checked against (layer 08).

Each record comes from a different layer of the map, and usually from a different vendor.

AGIS covers mandates and pressure testing

AGIS works in layers 06 and 07. It turns a treasury team's written mandate into controls and pressure-tests the agent in simulation before it touches money. In production, it checks each live action against the mandate line it relates to. AGIS is available through a design-partner programme.

Downloads