Authors Ian StaleyIndependent Researcher, Seattle, Washington, United States Abstract Payment networks and model providers deployed agent-authorization infrastructure at speed during 2025 and 2026: signed mandates, agent-bound tokens, and machine-payable settlement rails, each promising that an autonomous agent transacts only within authority its principal granted. This paper asks a prior question to whether agents obey such authority: whether the deployed protocols can express it at all. We define an authorization envelope of eight fields drawn from the delegated-authority literature and from the control primitives of existing payment rails, comprising a per-transaction ceiling, a cumulative ceiling, a merchant set, a category set, required product attributes, a validity window, a substitution policy and an amount-valued confirmation threshold. We then code eight deployed agent-payment protocols against these fields using an auditable document-analysis protocol, classifying each field as expressible, advisory or absent according to whether a typed schema field exists and whether any identified party validates it. Three fields are unsupported almost everywhere: substitution policy, general product attributes, and the confirmation threshold. Cumulative ceilings are enforceable only where some party accumulates state across transactions, which five of the ten schemes examined do and the remainder do not. Most consequentially, virtual-card controls already enforce cumulative caps and merchant-category scope, and open-banking variable recurring payments enforce cumulative caps, that the new agent protocols omit, so agent authorization is in specific respects a regression against rails that preceded it. We release the coding protocol and evidence table, and retain version-pinned specification snapshots for audit. Keywords Agentic payments delegated authority authorization conformance analysis payment protocols AI agents agentic commerce spending controls AI governance standards. Citation of this Article Ian Staley. (2026). Expressible, Advisory, or Unenforceable: A Conformance Analysis of Delegated Financial Authority in Deployed Agent-Payment Protocols. Journal of Artificial Intelligence and Emerging Technologies (JAIET). 3(8), 19-29. Article DOI: https://doi.org/10.47001/JAIET/2026.308003 Licence Copyright (c) 2026 Journal of Artificial Intelligence and Emerging Technologies. This work is licensed under a Creative Commons Attribution Non Commercial 4.0 International Licence. References D. Hardt, Ed., "The OAuth 2.0 authorization framework," RFC 6749, IETF, Oct. 2012.B. Campbell, J. Bradley, N. Sakimura, and D. Tonge, "OAuth 2.0 token exchange," RFC 8693, IETF, Jan. 2020.M. Bartoletti, J. H. Chiang, T. Junttila, A. Lluch-Lafuente, M. Mirelli, and A. Vandin, "Formal analysis of lending pools in decentralized finance," in Proc. ISoLA 2022, LNCS 13703, pp. 335-355, 2022.S. Yao, H. Chen, J. Yang, and K. Narasimhan, "WebShop: Towards scalable real-world web interaction with grounded language agents," arXiv:2207.01206, 2022.M. Thomson and A. Backman, "HTTP message signatures," RFC 9421, IETF, Feb. 2024.European Parliament and Council, "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence," OJ L 2024/1689, 12 Jul. 2024.S. Yao, N. Shinn, P. Razavi, and K. Narasimhan, "tau-bench: A benchmark for tool-agent-user interaction in real-world domains," arXiv:2406.12045, Jun. 2024.E. Debenedetti et al., "AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents," in Proc. NeurIPS 2024 Datasets and Benchmarks Track, arXiv:2406.13352, 2024.I. Levy, B. Wiesel, S. Marreed, A. Oved, A. Yaeli, and S. Shlomov, "ST-WebAgentBench: A benchmark for evaluating safety and trustworthiness in web agents," arXiv:2410.06703, Oct. 2024; accepted, ICLR 2026.Mastercard, "Mastercard Agent Pay," press release, Apr. 2025; and Mastercard Developers, agentic commerce merchant guide, accessed 18 Aug. 2026.Visa, "Visa Intelligent Commerce," developer portal and press materials, May 2025; accessed 18 Aug. 2026.Coinbase, "x402: An open standard for internet-native payments," specification v2 including the exact and upto schemes, May 2025; repository accessed 18 Aug. 2026.W3C, "Verifiable Credentials Data Model v2.0," W3C Recommendation, 2025.I. Nakash, G. Kour, K. Lazar, M. Vetzler, G. Uziel, and A. Anaby-Tavor, "Effective red-teaming of policy-adherent agents," in Proc. 2025 Conf. Empirical Methods in Natural Language Processing (EMNLP), 2025; arXiv:2506.09600, Jun. 2025.M. Bartoletti and E. Lipparini, "A theory of lending protocols in DeFi," arXiv:2506.15295, Jun. 2025.J. Wang et al., "ShoppingBench: A real-world intent-grounded shopping benchmark for LLM-based agents," arXiv:2508.04266, Aug. 2025.Google, "Agent Payments Protocol (AP2)," specification v0.1, 16 Sep. 2025; A2A extension and mandate schemas; accessed 18 Aug. 2026.OpenAI and Stripe, "Agentic Commerce Protocol: Agentic Checkout Specification and Delegated Payment Specification," version 2025-09-29, Sep. 2025; accessed 18 Aug. 2026.Visa, "Trusted Agent Protocol," specification and reference implementation, 14 Oct. 2025; accessed 18 Aug. 2026.M. El Helou et al., "Delegated authorization for agents constrained to semantic task-to-scope matching," arXiv:2510.26702, Oct. 2025.I. Aldasoro and A. Desai, "AI agents for cash management in payment systems," BIS Working Papers No. 1310, Bank for International Settlements, 26 Nov. 2025.FINRA, 2026 FINRA Annual Regulatory Oversight Report, Washington, DC, 9 Dec. 2025.M. Q. Li, B. C. M. Fung, M. Weiss, P. Xiong, K. Al-Hussaeni, and C. Fachkha, "A benchmark for evaluating outcome-driven constraint violations in autonomous AI agents," arXiv:2512.20798, Dec. 2025 (rev. May 2026).Mastercard, "Verifiable Intent," specification v0.1-draft, 18 Feb. 2026; accessed 18 Aug. 2026.Stripe and Tempo, "Machine Payments Protocol," specification and documentation, 18 Mar. 2026; accessed 18 Aug. 2026.Y. Zhang et al., "SoK: Blockchain agent-to-agent payments," arXiv:2604.03733, Apr. 2026.Q. Mao, J. Wang, Y. Liu, L. Zhu, C. Ma, and J. Yan, "SoK: Security of autonomous LLM agents in agentic commerce," arXiv:2604.15367, Apr. 2026.Google, "Agent Payments Protocol v0.2.0 release and Payment Mandate constraint documentation," 28 Apr. 2026, ap2-protocol.org/ap2/payment_mandate/; and FIDO Alliance, "FIDO Alliance to Develop Standards for Trusted AI Agent Interactions," 28 Apr. 2026; accessed 18 Aug. 2026.K. Tallam, "Authorization propagation in multi-agent AI systems: Identity governance as infrastructure," arXiv:2605.05440, May 2026.I. T. Staley, "Regulatory-grade evidence for AI in FinTech: A control-mapped framework and blockchain-anchored architecture for audit replay," Journal of Computational Law and Legal Technology, pp. 1-7, advance online publication 9 May 2026, doi:10.47852/bonviewJCLLT62029281.Z. Li, Q. Wang, and Z. Wang, "Five attacks on x402 agentic payment protocol," arXiv:2605.11781, May 2026.S. Ling, Y. Huang, Y. Du, Y. Chen, Y. Zhou, L. Wu, and C. Wang, "Free-riding the agentic web: A systematic security analysis of x402 payments," arXiv:2605.30998, May 2026.M. U. Safder et al., "FinPersona-Bench: A benchmark for longitudinal psychometric stability of autonomous financial agents," arXiv:2606.31522, Jun. 2026.Z. Ji et al., "Coding agents are guessing: Measuring action-boundary violations in underspecified DevOps instructions," arXiv:2607.02294, Jul. 2026.Linux Foundation, "x402 Foundation launch announcement," 14 Jul. 2026.Q. Wang et al., "When HTTP 402 meets the blockchain: Risks on emerging x402 payments," arXiv:2607.19545, Jul. 2026.I. Staley, "A reference architecture for AI agents on blockchain infrastructure: Identity, policy, payments, and custody as composable primitives," Zenodo, Jul. 2026, doi:10.5281/zenodo.21432152.J. Wu, M. Gong, F. Cheng, and Q. Zhao, "EcoAgent-Bench: Evaluating economic decision-making in budget-constrained LLM agents," arXiv:2608.05519, Aug. 2026.A. Li et al., "ComboShoppingBench: Evaluating LLM agents for budget-constrained basket shopping with coupons," arXiv:2608.09282, Aug. 2026.Marqeta, "Velocity controls and spend controls," developer documentation, accessed 18 Aug. 2026.Checkout.com, "Card controls and velocity limits," developer documentation, accessed 18 Aug. 2026.Open Banking Limited, "Variable Recurring Payments: consent parameters and standards," accessed 18 Aug. 2026.