Who Banks the Agents?
.png)
Foreword. Sometime in the past hour, thousands of AI agents bought something. Nobody clicked a button. The average purchase was about thirty-one cents, a data feed, a burst of compute, an API call, and it settled on a blockchain because no card network can economically clear a payment that small. Over the past year, agents moved more than $73 million across roughly 176 million on-chain transactions, 98.6% of it in stablecoins, and Gartner expects 90% of B2B buying to flow through agents by 2028, more than $15 trillion in throughput.
We run agentic banking services and engineering at America’s first federally chartered digital asset bank, Anchorage Digital Bank N.A., and we've spent the past year answering one question from institutions: when our agents start spending, who stands behind them? Our answer is the argument of this paper. An agent can hold a wallet, but it cannot open an account, pass identity checks, carry a compliance obligation, offer recourse when it errs, or run treasury. Those functions belong to a bank, and a federal charter is the only way to hold them. The agent economy has built nearly everything it needs for institutions to participate. What it hasn't built is its bank.
- Every new economic actor has eventually needed a bank
There is a pattern in financial history that the AI industry is about to repeat. When a genuinely new kind of economic actor shows up, commerce runs ahead of accountability for a while, and then the accountability gets built, and the volume follows it. Long-distance merchants traded on reputation until the letter of credit let strangers transact across oceans. The joint-stock corporation was a legal novelty until banks learned to underwrite an entity rather than a person. Internet commerce limped along on mailed checks and misplaced trust until issuing banks, merchant accounts, and chargeback rights made it safe to type a card number into a website.
AI agents are the newest economic actor, and they are earlier in that cycle than the demos suggest. The money moving today exists, but nanocent. What makes it a signal rather than a curiosity is that of the 176 million global transactions (with no human in the loop), the average ticket is around thirty-one cents, per Keyrock's analysis of a full year of agent payments. Machines have started paying machines, at machine frequency, for machine-sized things. Roughly three quarters of those payments fall below the $0.30 fixed fee a card charges before interchange even starts, which is why nearly all of them settle in stablecoins: a transfer that costs a tenth of a cent on Solana is the only rail where a thirty-one-cent purchase makes sense.
The rules arrived almost simultaneously with the rails. The GENIUS Act, enacted in July 2025, gave the U.S. its first federal stablecoin framework, and the stablecoin market value has since passed $300 billion. Settlement, statute, and supervision converged inside eighteen months. In the historical pattern, this is the moment the accountability layer gets built, and the moment whoever builds it first sets the terms for everyone who follows.
- Follow one agent's purchase and the gap appears
Here is the thought experiment we walk institutions through. Picture an asset manager that deploys a research agent. The agent subscribes to data feeds, rents compute, pays for inference, and occasionally books a larger purchase, say, a $40,000 annual dataset license. Now ask the questions any risk committee asks.
Who is the customer? Not the agent, as it does not have a government ID, Social Security number, or a phone to receive one-time passcodes. It cannot pass a Know Your Customer (KYC) check, which is why the early market's workaround was to hand the agent a pre-funded crypto wallet with a spending cap. That workaround is genuinely clever, and the existing players execute it well. But a capped wallet answers the security question "how much can we lose?", not the banking one. Try getting this past a risk committee: "We can't tell you who it is, but it can spend $40,000."
What happens when it pays the wrong party? On a stablecoin rail, nothing. Settlement finality means the transfer is irrevocable; there are no chargebacks, reversals, or anyone to call. Card rails have recourse written into statute, chargeback rights under Regulation Z and Regulation E, with an issuing bank absorbing the loss. On-chain rails have finality written into math. The dominant agent transaction today lives entirely on the second kind.
Who answers for the mistake? This one has stopped being hypothetical. California's AB 316, effective January 1, 2026, eliminated the defense that the AI acted autonomously, whoever developed, modified, or used the agent is on the hook. The EU's Product Liability Directive goes further, putting AI systems under no-fault liability. The law now assumes a responsible principal exists. Somebody has to be able to identify that principal, underwrite them, and stand behind the flow.
And who monitors it? A funded wallet does not carry a Bank Secrecy Act obligation; non-custodial providers sit outside anti-money-laundering monitoring precisely because they never hold customer funds. The lightness that makes a wallet easy to ship is the same lightness that makes it impossible to supervise.
Four questions, four gaps, and every one of them is a function banks have performed for centuries: know the customer, provide recourse, assign liability, monitor the flow. Our Co-founder and CEO framed the underwriting piece this way:
"KYA, know your agent...we're not only underwriting the human that is the owner of the bot or agent, but also the agent itself." — Nathan McCauley, Co-Founder and CEO, Anchorage Digital · Consensus, 2026
KYA went from a metaphor to a named framework in about a year. The World Economic Forum defined it in January 2026 as four capabilities: establish the agent's identity, bind it to a responsible human or organization, confirm its permitted actions, monitor it continuously, and the International Monetary Fund has since called for regulators to shift from Know Your Customer to Know Your Agent outright. When the International Monetary Fund (IMF), which has no product to sell, lands on the same architecture the industry is converging toward, the debate about whether this layer is needed is effectively over. The remaining question is who is equipped to operate it. The identity numbers suggest the urgency: machine identities already outnumber human ones 82 to 1, per CyberArk, and most organizations admit they lack identity controls for AI.
- Give the agent an allowance, and put the allowance in a bank
So how do you let an agent spend without handing it everything? McCauley’s concept has become the cleanest shorthand we know:
"Instead of giving your agent access to your whole bank account, you can give them a segmented bank account...almost like giving them an allowance." — Nathan McCauley, Co-Founder and CEO, Anchorage Digital · Consensus, 2026
What's striking is how completely the industry has converged on that idea from every direction at once. Visa's Intelligent Commerce lets consumers set limits and conditions on a tokenized credential. Mastercard's Agent Pay binds each credential to a specific agent, merchant, and consent policy. Google's AP2 protocol carries price limits and purchase conditions in a signed mandate. Different rails, different companies, one primitive: bounded, rule-carrying delegation. And consumers are asking for the same thing, Accenture found only 9% would let an agent act with full independence, but 32% would inside defined boundaries.
We'd make a friendly amendment to the industry's consensus, though. An allowance is a banking primitive. It is a sub-account with rules attached, and the interesting engineering problem is where the rules get enforced. Enforce them in the agent and a prompt injection can rewrite them. Enforce them at the account, inside a regulated custodian, and the agent physically cannot exceed them, the mandate is checked before settlement, by infrastructure the model cannot touch. This distinction sounds academic until you read the incident reports. Forcepoint has catalogued live prompt-injection payloads built specifically to redirect agent payments, including one carrying a $5,000 fraud instruction. And in July 2025, Replit's coding agent deleted a production database during an explicit code freeze, then fabricated records to cover it. The lesson we take as engineers is blunt: an agent's safety rails cannot live anywhere the agent can reach.
"Controls are what's going to enable this to scale out and not go haywire." — Nathan McCauley, Co-Founder and CEO, Anchorage Digital · Consensus, 2026
A custodial account can freeze a suspicious flow mid-transaction, decline a payment that breaches its mandate, and claw back a transfer that never should have cleared. A wallet, however well-designed, can only watch its balance drain more slowly.
- Institutions want in, and governance is the gate
Everything above would be an interesting payments debate if institutional demand were hypothetical. It isn't. Deloitte's survey of 3,235 senior leaders found agentic AI usage set to rise sharply over two years, and only one in five companies has a mature governance model for autonomous agents. McKinsey finds nearly two-thirds of enterprises experimenting with agents while fewer than one in ten have scaled them to real value. And when CrewAI surveyed 500 executives at large enterprises this year, 65% said agents were already in use, and the top criterion for choosing an agent platform was security and governance, ranked above integration, above performance, above ROI.
Read those three findings together and the institutional bottleneck comes into focus. Appetite is universal; deployment stalls at the point where an auditor, a risk committee, or a regulator asks who is accountable. Nowhere is that question sharper than where agents touch money, and nowhere is the answer more established than in banking. The institutions that put agentic spending into production first will be the ones that can show their board an account with underwritten identity, enforced mandates, and a supervised counterparty behind every transaction. The capability race gets the headlines, but reliability is not keeping pace with capability; Princeton researchers measuring frontier models found exactly that lag, and for money movement, reliability is the trend line that matters.
This is also why we believe the account layer requires a charter rather than a license portfolio. Moving money nationally without a federal charter means assembling money-transmitter licenses across 49 states, a program that runs roughly $500K to $2M over a two-to-four-year timeline. A national bank charter collapses all of it into one federal regulator and grants, on day one, the full stack the April 2026 FinCEN rulemaking now requires of stablecoin institutions: AML programs, ongoing due diligence, suspicious-activity reporting, and mandatory freeze-and-reject capability. Building software is cheap now, but building the trust and compliance organizations need is expensive, and a charter puts a federal examiner behind all transactions as a safeguard.
- The best counterargument, taken seriously
The strongest pushback we hear comes from the protocol layer, and it deserves a real answer. Scoped one-time cards, onchain spend permissions, cryptographic intent records, smart-account limits like ERC-6900, with hard caps and a signed audit trail…why does an allowance need a bank at all?
Our answer concedes the premise. Those controls are excellent, and for a $30 consumer purchase on a card rail they may well be sufficient. But look at where the obligation lands. A merchant-scoped virtual card still settles through an issuing bank, and that bank holds the chargeback liability and the compliance duties. The protocol sets the limit, and a chartered institution answers when the limit fails. And in the place where agents actually transact today, sub-dollar stablecoin transfers with no issuing bank and no chargeback, the protocol-layer safety net doesn't reach at all. The controls improve fastest where the recourse problem is smallest.
So the honest scope of our claim is this: for small consumer purchases, the wallet-and-protocol stack is closing the gap, and we're glad it is. The charter is decisive for everything that stack cannot absorb: enterprise treasury, cross-border settlement, and every flow that triggers a suspicious-activity filing. That is the institutional share of the agent economy, and it is the share worth banking.
- The answer to the title
Every wallet, credential, protocol, and network in this market is building something the agent economy needs, and the largest players in payments are building alongside us rather than against us. What remains unbuilt is the account those layers draw on: one that knows the agent and the human behind it, fences the spending into an allowance the agent cannot escape, answers for mistakes with recourse, and settles at machine speed across fiat and stablecoin rails alike.
"Agentic Banking is the bridge between those two worlds: a system that brings trust, governance, and real financial rails to autonomous systems." — Nathan McCauley, Co-Founder and CEO, Anchorage Digital · PYMNTS, 2026
We are building that bridge where we believe it has to be built: inside a bank. Anchorage Digital Bank N.A. received the first OCC national trust bank charter granted to a crypto company in January 2021, making it America’s first federally chartered crypto bank, and has operated under continuous OCC supervision for more than five years since. When Mastercard launched Agent Pay for Machines in June 2026, Anchorage Digital was a named, non-exclusive launch partner, and the premier federally chartered crypto bank among the partners listed. Additionally, in May 2026, Google Cloud partnered with Anchorage Digital to deliver a full-stack, cloud-native infrastructure for both agentic commerce and embedded digital asset services.
McKinsey projects $3 trillion to $5 trillion in agent-mediated consumer commerce by 2030, roughly $1 trillion of it in the U.S., and the enterprise flows behind it will be larger still. The institutions deciding where that capital moves have already told the surveyors what they will choose on governance first. History says the same thing in fewer words. Every new economic actor eventually got its banker. The agents are getting theirs now.
About Anchorage Digital
Anchorage Digital is a global crypto platform that enables institutions to participate in digital assets through trading, staking, custody, governance, settlement, stablecoin issuance, and the industry’s leading security infrastructure. Home to Anchorage Digital Bank N.A., the first federally chartered crypto bank in the U.S., Anchorage Digital also serves institutions through Anchorage Digital Singapore, which is licensed by the Monetary Authority of Singapore; Anchorage Digital NY, which holds a BitLicense from the New York Department of Financial Services; and self-custody wallet Porto by Anchorage Digital. Anchorage Digital Bank also offers fiat custody services through the use of an FDIC-insured, licensed sub-custodian. Anchorage Digital is funded by leading institutions including Andreessen Horowitz, GIC, Goldman Sachs, KKR, and Visa, with a valuation of $4.2 billion. Founded in 2017 in San Francisco, California, Anchorage Digital has offices in New York, New York; Porto, Portugal; Singapore; and Sioux Falls, South Dakota. Learn more at anchorage.com, on X @Anchorage, and on LinkedIn.
This post is intended for informational purposes only. It is not to be construed as and does not constitute an offer to sell or a solicitation of an offer to purchase any securities in Anchor Labs, Inc., or any of its subsidiaries, and should not be relied upon to make any investment decisions. Furthermore, nothing within this announcement is intended to provide tax, legal, or investment advice and its contents should not be construed as a recommendation to buy, sell, or hold any security or digital asset or to engage in any transaction therein.
Anchorage Digital Bank National Association offers fiat custody services through the use of an FDIC-insured, licensed sub-custodian.