What Are AI Agent Spending Controls?

AI agent spending controls are the pre-set rules — spending caps, merchant or category allowlists, human-approval thresholds, and transaction-velocity limits — that determine what an autonomous AI agent is allowed to buy, from whom, and up to what amount, without requiring a human to approve each individual purchase.

Every agentic payment protocol and product in this space is, at its core, trying to answer the same question: how do you let an AI agent spend money without giving it a blank check? The mechanisms differ by layer — protocol-level mandates, card-network tokens, or wallet-level policy engines — but the underlying controls repeat across all of them.

Key facts

  • AP2 encodes spending limits into cryptographically signed mandates, not server-side settings. Google's Agent Payments Protocol (AP2) uses an Open Payment Mandate, a Verifiable Digital Credential that captures "the user's constraints on payment (e.g., budget, allowed instruments) for autonomous execution" before a transaction is finalized, and a Closed Payment Mandate that authorizes a specific transaction amount once checkout is finalized, per ap2-protocol.org and the Google Cloud announcement.
  • AP2 distinguishes "human present" from "human not present" transactions, which changes what counts as an approval threshold. In the "Human Not Present" mode introduced in AP2 v0.2, an agent executes a transaction the user pre-authorized (with defined limits) without the user actively present at the moment of purchase, per Google's FIDO Alliance blog post.
  • Card networks are building spending controls directly into agent-specific tokens. Mastercard's Agentic Tokens are described as dynamic digital credentials that "register, verify and recognize agentic transactions," where each transaction an agent makes "does so with the permissions and limits you define, keeping you in full control," per Mastercard's April 29, 2025 announcement.
  • Visa's Trusted Agent Protocol focuses on merchant-side agent verification rather than a consumer-facing spend-cap UI. Its cryptographic signature scheme (built on HTTP Message Signatures, RFC 9421) confirms "a Visa-trusted agent seeks product details or purchases," letting merchants distinguish legitimate shopping agents from bots — a precondition for enforcing any downstream spending rule, per Visa's October 14, 2025 press release.
  • Wallet- and platform-level products implement controls as account settings rather than protocol fields. Skyfire's product page states agents let a user "set spending limits per agent to ensure cost control" and offers "transaction monitoring & analytics" as a separate, developer-facing feature, per skyfire.xyz/product — a simpler, dashboard-driven model compared to AP2's cryptographically signed mandates.
  • Audit trails are a stated design goal, not just a side effect. AP2's own documentation describes producing "a non-repudiable, cryptographic audit trail for every transaction" to support dispute resolution, per ap2-protocol.org. Primary sources reviewed for this article did not specify a standardized revocation mechanism (e.g., how a user cancels a still-valid mandate mid-flight) for AP2, Mastercard Agentic Tokens, or Visa's Trusted Agent Protocol.

How it works

  1. A human (or a business's admin) defines constraints before the agent starts acting: a maximum budget, a list of allowed merchants or categories, an approval threshold above which a human must confirm, and how many transactions the agent can make in a given period.
  2. Those constraints are encoded into whatever mechanism the underlying rail uses — a signed Open Payment Mandate in AP2, an Agentic Token configured with defined permissions and limits in Mastercard's system, or an account-level spending-limit setting in a wallet product like Skyfire's.
  3. When the agent wants to transact, it either presents a Closed Payment Mandate matching the finalized cart (AP2), completes checkout using its scoped Agentic Token (Mastercard), or has the transaction checked against its account-level limit (wallet products).
  4. If the transaction falls within the pre-set bounds, it proceeds without further human input — this is what protocols call a "human not present" transaction. If it falls outside the bounds (over budget, unlisted merchant, over the velocity limit), the system is designed to block it or escalate for a human approval step.
  5. A cryptographic or logged record of the transaction and the mandate/token that authorized it is retained, so a human or business can later audit what the agent did and why it was allowed to.

Comparison of spending-control approaches

AP2 Mandates Card-network agent tokens (Mastercard Agentic Tokens) Wallet/platform-level rules (e.g., Skyfire)
Mechanism Cryptographically signed Verifiable Digital Credentials (Open/Closed Payment Mandate) Dynamic, tokenized payment credentials scoped with defined permissions and limits Account/dashboard settings applied per agent
Where the rule lives Embedded in the signed mandate itself Embedded in the token issued for that agent Stored in the platform's own backend
Human-approval step "Human present" vs. "Human Not Present" modes defined in the protocol Not specified in primary sources reviewed Not specified in primary sources reviewed
Verification point Payment processor/bank checks the mandate signature Card network / issuer checks the token's permissions at authorization Platform checks its own stored limit before allowing a transaction
Governance FIDO Alliance (since April 28, 2026) Mastercard Individual company (Skyfire)
Primary source ap2-protocol.org, Google Cloud blog Mastercard press release skyfire.xyz/product

FAQ

What is a "spending control" for an AI agent? It's any pre-set rule — a budget cap, an allowed-merchant list, a velocity limit, or a human-approval threshold — that bounds what an autonomous agent can pay for before it's allowed to transact.

Is a spending cap the same as a mandate? Not exactly. A mandate (as used in AP2) is the cryptographically signed artifact that contains the spending constraint and proves the user set it; the "cap" is just one field inside that artifact.

Do card networks or protocols support revoking a spending limit mid-transaction? Not specified in the primary sources reviewed for this article. AP2, Mastercard's Agentic Tokens announcement, and Visa's Trusted Agent Protocol materials describe how limits are set and checked, but none of the sources reviewed detail a standardized real-time revocation flow.

What's the difference between "human present" and "human not present" transactions? "Human present" means the user is actively confirming the purchase at the moment it happens. "Human not present," introduced in AP2 v0.2, lets an agent execute a transaction the user pre-authorized earlier, without the user active at the moment of purchase, per Google's FIDO Alliance blog post.

Do spending controls stop all fraud or overspending? No source reviewed claims this. They reduce the risk by constraining what an agent can attempt in the first place and by creating an audit trail, but none of the primary sources describe them as a complete fraud-prevention system on their own.

Are spending controls specific to one protocol? No. Every major approach reviewed here — AP2's mandates, Mastercard's Agentic Tokens, and wallet/platform account settings like Skyfire's — implements some version of a spending control, using different technical mechanisms.

Related terms