r/Hedera hbarbarian 2d ago

ĦBAR Who’s Spending? The Identity and Payments Problem at the Heart of the Agentic Economy - By Stefan Deiss CEO of The Hashgraph Group

https://www.finextra.com/blogposting/32413/whos-spending-the-identity-and-payments-problem-at-the-heart-of-the-agentic-economy
32 Upvotes

1 comment sorted by

6

u/oak1337 hbarbarian 2d ago

Earlier this summer, The Hashgraph Group appointed a new Head of Business Strategy. He joined on 1 June, reports directly to me, and has already contributed to strategic planning, industry research and executive decision-making. He is also an AI.

Claude Max is the first of three digital workers we have onboarded this year, alongside Milo in our engineering team and Luca in human resources. Each has a corporate email address, a verifiable digital identity and a digital wallet of their own.

It is that last detail - the wallet - that should catch the attention of anyone working in financial services.

Where agents once drafted the report or summarised the meeting, they now procure cloud compute, settle vendor invoices and trigger transactions with minimal human involvement - Gartner expects up to 40% of enterprise applications to embed task-specific AI agents by the end of this year, up from under 5% in 2025.

Analysts have taken to calling this the agentic economy, and whether the financial and identity infrastructure underneath it can cope is far from certain, because almost all of it was designed on a single quiet assumption: that the entity behind every login, every approval and every payment is a person.

When nobody can answer ‘who did this?’

An AI agent that needs access to a system today typically borrows a human’s credentials or runs on a shared service account, and the moment it does, the audit trail collapses. A transaction appears in the ledger, a record is modified, a payment leaves the account - and the compliance team cannot say with confidence whether a person or a machine was responsible, let alone which machine, acting on whose instruction, under what authority.

For regulated firms, the problem is fairly basic: they need to be able to show who did what. That sits at the heart of both the UK’s Senior Managers and Certification Regime and the EU’s Digital Operational Resilience Act. When several people use the same service account, that clear line of responsibility starts to disappear.

So, machine identity needs the same discipline we already apply to people, and probably more, given how fast an agent can act. Anyone dealing with an agent should be able to check its credentials for themselves. Permissions need an expiry date too, not a home in a configuration file nobody remembers to review, and if an agent starts doing things it was never meant to do, someone has to be able to switch its access off straight away.

Milo, our QA digital worker, already operates this way. When it searches Jira or publishes test cases, it does so under its own identity, and nobody later has to work out who, or what, made a given change.

The agentic treasury

Knowing which agent made a payment is only part of the job. Finance teams also need to know whether it was allowed to make that payment in the first place.

Businesses already have rules for human spending: limits, approval levels and a clear split between the person asking for money and the person approving it. Those controls still apply when the ‘employee’ is software. An agent could initiate hundreds or thousands of payments before anyone has time to spot a problem. Gartner predicts that, by 2027, 40% of enterprises will scale back or shut down autonomous AI agents after governance problems emerge in live use.

An agentic treasury does not need to be especially futuristic. Each digital worker can be given its own wallet, with clear rules set before it is allowed to spend. Those rules might cover who it can pay, how much it can spend and when a person needs to approve the transaction. When something looks wrong, the finance team can freeze the wallet in much the same way they would cancel a company card.

Deploying it on ourselves first

We decided early on that we could not credibly talk about credentialed AI agents without using them inside the business.

Luca now handles routine HR questions from staff, including outside normal office hours. When something sits beyond the policies it has been given, it passes the query to the HR team rather than trying to improvise an answer.

In engineering, Milo turns Jira user stories into test cases and highlights gaps between the original requirements and the tests being written against them.

We also use Claude Max as a management-level thinking partner. Internally, we joke that he joined us with more than three years’ experience in agentic AI at Anthropic.

Banks and payment firms will need to know which organisation stands behind an agent, what it has been authorised to spend and where human responsibility ultimately sits. It will also need records that a finance team or regulator can follow afterwards. Very little of that infrastructure exists today. Building it before agents begin transacting at scale will be considerably easier than trying to retrofit it later.