Why AI agents need a new kind of trust
When you buy something online today, a person clicks "buy." The payment system trusts that the person behind the card details actually authorized the purchase. That assumption is starting to break down. Visa's Intelligent Commerce, Mastercard's Agent Pay, Google's Agent Payments Protocol (AP2), and Stripe's partnership with ChatGPT already exist. Each lets an AI agent complete a purchase without a person confirming every step.
Once an agent makes the decision instead of a person, the usual paper trail disappears. Three questions go unanswered.
Question | What it means |
|---|---|
Who sent the agent | Does the agent really represent the company it claims to, or has it been spoofed |
What it is allowed to do | Can the agent spend 50 euros or 50,000, buy office supplies or order a new server |
How long that permission lasts | Is the authorization valid for one purchase, or does it stay active indefinitely, a security risk if the agent is compromised |
Without answers to these questions, a payment network only sees that a payment arrived. It has no way to confirm the agent was actually authorized to send it.
What already exists and what is still a proposal
GLEIF (Global Legal Entity Identifier Foundation) published a discussion paper (PDF) on 13 August 2026. The title is "Agentic AI in Payments: Establishing Interoperable Trust and Control." One detail matters here: this is a discussion paper, not a finished standard. GLEIF lists several open questions itself. These include who should issue an agent's mandate, and who should manage limits like spending caps once they go live.
The paper's central idea is the Agent Mandate Credential (AMC). This is a cryptographic proof that links an agent to its organization's verifiable LEI (vLEI) data. It also sets the scope and expiry of the agent's authority. GLEIF is clear the goal is not a brand new identity system for agents. The plan reuses the organizational identity companies already hold.
The paper names four payment protocols it expects this trust model to work alongside. They are Visa's Intelligent Commerce, Mastercard Agent Pay, Google's AP2, and the Stripe and ChatGPT Instant Checkout integration.
Why a plain LEI code is still the essential foundation
The AMC model depends entirely on the organization's underlying LEI data. A company's LEI record can lapse, carry an outdated address, or lose its active status. When that happens, any authorization layer built on top of it rests on a weak foundation. As a Registration Agent (RA), we see this pattern daily. Companies forget to renew an LEI code on time, or leave their record unchanged after a change of ownership. Today that is mainly a compliance issue. Agent authorization models will soon rely on the same LEI data. Once they do, keeping that record accurate becomes part of the trust chain itself. It is no longer just a box regulators ask companies to tick.
Issuing a vLEI credential depends on infrastructure GLEIF requires, called Key Event Receipt Infrastructure (KERI). KERI gives every authorization and key rotation a tamper proof, traceable history. Building and running KERI infrastructure is expensive and technically demanding. It is also exactly what makes the vLEI trust model work at all. For us, that means joining this path once the vLEI ecosystem and demand for it have matured, not before. Right now our contribution stays simple: keeping your existing LEI record accurate and active. That record is the foundation everything else, vLEI included, gets built on later.
If your company's LEI data or registration status needs a check, sort it out now. It is worth doing before frameworks like this see wider use. The same logic already applied to the Agent Name Service for AI agents, a related standard we covered previously.
What this means for your business right now
None of this is mandatory yet. No regulator or payment network has turned the AMC model into a requirement. GLEIF itself says the architecture is still open. An LEI code that stays accurate and current is cheap insurance against that future. This holds whether or not this exact model becomes the one that wins out.
If your company does not have an LEI code yet, we can help you register one. If you already have one, we can check it and renew it before it lapses.
Frequently asked questions
Does my company need an LEI code for AI agents right now? No. This is not mandatory yet. A standard LEI code is simply the foundation that future agent authorization models are likely to depend on.
Will LEI System offer vLEI issuance? We plan to join that path once the vLEI ecosystem and demand for it have matured. The required KERI infrastructure is expensive and technically demanding. We are tracking its progress rather than issuing vLEI credentials ourselves today.
Is the Agent Mandate Credential already in use? No. It is a proposal from a GLEIF discussion paper published in August 2026, not a finished standard or a requirement.
