
The Missing Infrastructure Layer for Enterprise Agentic Payments
April 26, 2026 · Updated August 12, 2026
Download Now

Enterprise AI agents are already initiating payments on behalf of organizations. No shared infrastructure exists to verify whether those organizations actually authorized them to do so. This whitepaper documents that gap across eight live coding experiments run against real payment infrastructure — not simulation — and proposes CLARC, a clearing and authorization registry, as a reference architecture for closing it.
The gap in one sentence
Intent proves what was asked. Authority proves it was allowed. The protocols being built across the agentic commerce stack are solving for intent. The infrastructure to verify authority does not yet exist.
A payment can be valid at every system boundary — the rail, the bank, the receiving chain — while remaining unverifiable at the level of organizational authority. That is not a failure of any single system. It is a missing layer across all of them.
Key terms
- CLARC
- Clearing and Authorization Registry for Agentic Commerce — a neutral infrastructure layer proposed as a reference model. "Clearing" here refers to clearing an agent's authorization status before a transaction executes, analogous to a security clearance, not to the financial clearing process by which payment obligations are netted between institutions. CLARC does not participate in financial clearing.
- Agent-initiated payment
- A financial transaction generated by an AI agent without real-time human involvement at the point of execution.
- Delegation chain
- The multi-step path through which an enterprise's governance structure — board policy, CFO delegation, department approval, procurement system — authorizes a specific AI agent to act.
- Neutral registry
- Shared infrastructure operated independently of any single participant, whose verification records are trusted by all parties because no single party controls it.
What eight live experiments found
The research series ran real transactions against Stripe test mode, the Anthropic API, the Model Context Protocol SDK, and a working CLARC prototype. The findings were consistent across every implementation tested.
- The payment rail is blind to agent identity. An AI agent can complete a payment today that is indistinguishable from a human-initiated one at every receiving node — no standard field carries verified initiator type.
- Multi-agent chains break the authorization model. In a two-agent delegation chain, the executing agent detected a discrepancy in its own authorization record, named it in its reasoning trace, and processed the transaction anyway — because the infrastructure gave it no mechanism to escalate.
- Published protocols stop at the boundary of their scope. MCP enforces spending constraints only when the model's own alignment produces compliance. AP2's enterprise delegation module did not exist as callable code six months after its announcement with 60+ industry partners.
- The receiving chain is correctly blind. A bank statement line looks identical for human and agent-initiated payments — including one carrying a full CLARC credential — because receiving infrastructure was never designed to verify the sender's internal governance.
- Bilateral solutions do not scale. When two enterprises with no prior relationship attempted a transaction, both agents correctly identified they could not prove their authority to each other. The payment executed anyway. The dispute went unresolved and required human escalation.
The agent caught its own authorization gap in its reasoning trace — and processed the transaction anyway. Because the infrastructure gave it nowhere to go.
— Experiment 3, The Agent Economy Research Series
The proof of concept
The same cross-organizational transaction was run twice: once without CLARC, once with it. Without CLARC, both agents escalated to a human and the dispute went unresolved. With CLARC, the paying agent's registration and a pre-transaction credential let the receiving enterprise's AR agent independently verify authority and accept the transaction autonomously — with no prior relationship between the two enterprises. The only difference between the two runs was one CLARC registration.
What's inside
- Why existing payment and ERP infrastructure lacks agent-native authorization controls
- The distinction between agent identity, delegation, and transaction-level authorization
- A clearing and registry model for verifying agent authorization in real time, and what it explicitly does not do
- The economic case for enterprises, paying banks, and receiving banks, with illustrative build-versus-buy comparisons
- A three-phase development roadmap from foundation to network-mandated infrastructure
Who should read this
Enterprise treasury and finance leaders, payment service providers, financial institution risk and compliance teams, and technology partners building agentic commerce capabilities.
Key Concepts
- Clearing and authorization registry
- Agent identity vs. delegation vs. transaction authorization
- Pre-transaction verification
- Real-time verification for financial institutions
- Enterprise agentic payments
- Rail-agnostic governance
Download the white paper
Complete the form below to receive instant access.


