AI & Compliance
The Firm With the Obligation Is the One Without the Context
In an agent-mediated payment, the bank sees an instruction and the agent platform knows why it exists. Anti-money-laundering duties attach to the party moving the money, which for thirty years has also been the party who decided to move it. Agentic commerce quietly separates those two things.
By Thomas Geater· 4 September 2026 · 8 min read
HM Treasury is currently consulting on modernising the payment services regulatory framework, and it asks, at question 16, whether there are innovations the government should take into account beyond the ones already named. I responded to that consultation this week. This is the part of my answer I think is most underrated, and it has nothing to do with authentication, liability or stablecoins.
An anti-money-laundering obligation attaches to the firm that moves the money. That is the bank, the payment institution, the e-money issuer. It is the party that has to know the customer, understand the purpose of the relationship, monitor the activity for consistency with that understanding, and report what it cannot explain.
For thirty years this has worked because the party moving the money was also downstream of the party who decided to move it, and that party was the customer sitting in front of them. The firm could ask the customer why. It might get a poor answer, but the question had an addressee.
Agentic commerce takes the deciding and puts it somewhere else.
What each party can actually see
Picture the chain in an agent-initiated purchase. The consumer sets an objective and a budget. An AI agent platform interprets that objective, searches, compares, selects a merchant, and produces a payment instruction. The payment firm executes it.
The payment firm sees: payee, amount, currency, timestamp, channel, and whatever reference data rides along. That is the whole evidential universe available to its monitoring estate.
The agent platform sees: what the customer asked for in natural language, the constraints they set, the options considered and rejected, why this merchant was chosen over the others, whether the instruction came from a standing mandate or a fresh request, and — increasingly — the reasoning trace that produced the decision.
One of those parties is regulated for financial crime. It is not the one holding the answers.
Why this is worse than the usual data gap
Compliance people are used to partial visibility. Correspondent banking, payment initiation services, marketplaces and intermediaries have all produced versions of the same complaint: we see the leg, not the journey. The regime’s answer has been to push duties down the chain and to open information-sharing gateways between the firms that hold different pieces.
Neither answer reaches this case, and it is worth being precise about why.
The Money Laundering Regulations require ongoing monitoring — scrutinising transactions to ensure they are consistent with the firm’s knowledge of the customer, their business and their risk profile. That test assumes the firm’s knowledge of the customer is the right frame of reference for the customer’s transactions. Where an agent selects payees inside a mandate the customer set weeks earlier, the transactions are consistent with the agent’s optimisation, not with anything the firm learned at onboarding. The firm is comparing observed activity against a model of a person, and the activity is being generated by a process.
The suspicious activity regime has the same problem in sharper form. A disclosure is an account of why the firm cannot explain what it saw. If the honest answer is that the customer’s software chose this merchant for reasons held on a platform the firm has no relationship with, the narrative does not survive contact with a reviewer. I have written before about what makes a SAR narrative defensible, and every requirement on that list assumes the reporter can describe the conduct. Here the conduct is a decision made elsewhere.
And the sharing gateways do not help, because of who they are drawn around. The direct information-sharing provisions in the Proceeds of Crime Act and, more recently, the Economic Crime and Corporate Transparency Act, run between regulated firms. An AI agent platform is not one. So the party holding the context sits outside the perimeter, outside the reporting duty, and outside the mechanism the sector built specifically for getting context from one institution to another.
The typology this creates
The interesting failure is not a single fraudulent payment. It is correlation.
Suppose an agent platform is manipulated — a poisoned product feed, an injection in merchant-supplied content, a compromised integration, or simply a supplier who has learned how these agents rank. The output is not one anomalous payment. It is a shift in payee selection across the platform’s entire user base, running through dozens of payment firms simultaneously.
Each firm sees a handful of customers paying a merchant they have not paid before, for amounts inside their normal range, at plausible times, under mandates the customers genuinely granted. Nothing scores. Nothing should score, on the evidence any one firm holds.
The pattern exists only at the platform. The platform has no obligation to look for it, no obligation to report it, and no route to tell anybody if it found it.
This is not a hypothetical about superintelligence. It is a straightforward consequence of concentrating payment initiation in a small number of intermediaries, which is exactly what the consultation anticipates happening, and which the United Kingdom has said it wants to lead.
What I am not proposing
I do not think the answer is to authorise agent platforms as payment firms. Most of them are not payment firms in any useful sense, several of the largest are not UK entities, and an authorisation regime aimed at whoever is currently building agents would be obsolete before it commenced. I said as much to the Treasury: I can see the asymmetry clearly and I do not have a settled view on the structure that fixes it. That is an honest position and a more useful one than inventing a regime to sound decisive.
What can be said now is narrower and cheaper.
Flag agent-initiated payments in the message. This is the single most valuable thing available, and its value goes well beyond monitoring. Without a flag, machine-initiated traffic is invisible inside human traffic, which means firms will tune their models to accommodate it without ever having decided to, supervisors cannot measure how much of the payment system is machine-initiated, and nobody can evidence any of the above. A field in a message standard is trivial to require now and expensive to retrofit once volumes are real.
Make the mandate a retained record. If the consent that matters is the mandate rather than the transaction, then the mandate — its limits, its date, its scope, its revocation — should be a record somebody is obliged to keep and produce on lawful request. That is a record-keeping duty, which is a familiar instrument, rather than a new perimeter.
Recognise that purpose evidence has moved, and say where it now lives. Whatever the eventual structure, a regime that leaves the only party who knows why a payment happened with no duty to consider it is not going to work by accident.
What to ask inside a firm
Three questions, none of which need a technical background, and all of which are answerable this quarter.
Do our contracts with agent platforms and payment initiation partners give us any right to information about the mandate behind an instruction? Most integration agreements are silent, because nobody drafting them was thinking about a SAR.
If a reviewer asked us to explain why a customer paid a merchant they had never paid before, and the answer is that an agent chose it, what would our narrative actually say? Write the paragraph now, while it is a drafting exercise rather than a deadline.
And do we know which of our customers have delegated payment authority at all? Not in principle, in the data. A firm that cannot count them cannot claim to be monitoring them.
The uncomfortable part of all this is that nothing in it requires anybody to behave badly. The payment firm applies its rules diligently to the evidence it holds. The agent platform optimises for its users exactly as advertised. The customer gets what they asked for. The obligation and the information simply end up in different places, and the gap between them is where the losses will sit.
Regulation has been late to every previous version of that problem. This one has the courtesy of announcing itself in advance.
Written by
Thomas Geater
I write The Typology Files, on financial-crime compliance and what generative and agentic AI are doing to it. BSc Business Management with Finance, University of Brighton. I work independently and take on advisory and writing engagements.