The End of Lazy Money

Jun 1, 2026

Sections
  1. I. The Man Who Fired Seven Hundred People Who Didn’t Exist
  2. II. The Most Profitable Customer in Banking Is the One Who Forgets
  3. III. The Plumbers
  4. IV. The Arithmetic of Trust
  5. V. The Note in the Web Page
  6. VI. The Quiet Winners (or: Follow the Boring Money)
  7. VII. Elsewhere
  8. VIII. The Herd
  9. IX. Coda: The Leopard and the Ledger

What happens when the machines start spending it.

I. The Man Who Fired Seven Hundred People Who Didn’t Exist

In February 2024, Sebastian Siemiatkowski did something no chief executive had ever done before: he announced, with evident pride, that a piece of software at his company was doing the work of seven hundred human beings.

Siemiatkowski runs Klarna, the Swedish buy-now-pay-later giant, and the software in question was a customer service assistant built on OpenAI’s models. In its first month it had handled 2.3 million conversations. It resolved complaints in under two minutes. Its customer satisfaction scores matched the humans it had displaced. Klarna projected forty million dollars in profit improvement and said so, loudly, in a press release that read less like corporate communications than like a starting gun.

Wall Street loved it. The AI industry loved it more. For about fourteen months, Klarna’s chatbot was the single most-cited proof that the agent economy had arrived — that artificial intelligence had graduated from writing poems to doing jobs.

Then, in May 2025, Siemiatkowski did something almost as unusual as his original boast. He admitted he’d been wrong.

“What you end up having is lower quality,” he conceded. The automation had “gone too far.” The AI was superb at the easy tickets and quietly terrible at the hard ones — the fraud dispute from a panicked customer, the account closure tangled in a divorce, the edge case that no training data had anticipated. Klarna began rehiring humans, promising customers they could always reach a person, an “Uber-type” model of on-demand empathy.

Here is where the story gets interesting, and where most retellings stop too early. Because the walk-back was not a retreat. By Klarna’s third-quarter earnings call in November 2025, the assistant was doing the work of 853 full-time agents — more than at the peak of the hype — and saving roughly sixty million dollars a year. The company had gone public in September. Revenue was up 26 percent.

What actually happened at Klarna was not a failure of artificial intelligence. It was the discovery, in public and at considerable reputational expense, of the central law governing this entire technology: autonomy is not a feature you announce. It is a budget you spend, and the currency is trust. Klarna had spent trust it hadn’t yet earned, got margin-called, and restructured the debt. The AI stayed. The humans came back as the escalation tier. The org chart of the future turned out to be a triage protocol.

Keep that law in mind. Everything else in this essay is a footnote to it.


II. The Most Profitable Customer in Banking Is the One Who Forgets

To understand why banks are terrified of AI agents — genuinely, board-level, hire-McKinsey-twice terrified — you have to understand the most underrated force in consumer finance. It is not interest rates. It is not regulation. It is forgetting.

Somewhere around 23 trillion dollars sits in checking accounts around the world earning approximately nothing. Not because the owners of that money have evaluated their options and chosen zero percent. Because moving money is a chore, comparing rates is boring, and the human brain — a machine exquisitely tuned by evolution to notice leopards and remember grudges — is nearly incapable of sustained attention to basis points.

Banking’s quiet genius has been to build a 1.2-trillion-dollar global profit pool substantially on top of this cognitive limitation. The deposit that never shops around. The credit card that gets used out of habit rather than comparison. The rewards points that expire unredeemed — a revenue line that exists, when you think about it, purely because customers forget their own assets. Economists politely call this “customer inertia.” A less polite word would be inattention, and banks have monetized it the way casinos monetize hope.

Now consider what an AI agent is, stripped of the marketing. It is attention that never lapses. It is a customer who reads every fee disclosure, compares every rate, every night, forever, and feels no loyalty, no friction, no embarrassment about switching. It is the leopard-noticing machinery of the brain, pointed for the first time in history at the small print.

In August 2025, McKinsey published a report whose title deserves more credit than it got: The End of Inertia. Its modeling suggested that if consumers adopt agents that sweep even 5 to 10 percent of those lazy checking balances into higher-yield accounts, deposit profits fall by more than 20 percent. The most-likely scenario strips roughly 170 billion dollars — about 9 percent — from global banking profit pools. The products most exposed are precisely the ones built on habit: deposits and credit cards. The report’s unstated conclusion is the kind of thing Michael Lewis would have put in italics: the banking industry’s largest single asset is a human cognitive bias, and someone just invented the cure.

It has not happened yet. This is worth saying plainly, because the scenario is so vivid that people talk about it in the present tense. As of mid-2026, no deposit-sweeping consumer agent operates at scale anywhere on Earth. The rate-shopping apocalypse is a model, not a measurement. But the infrastructure for it is being welded together in public, by some of the largest companies in the world, and that construction project is the second story.


III. The Plumbers

On September 29, 2025, somewhere in Mastercard’s network, a piece of software bought something. No human clicked. The transaction was initiated by an AI agent carrying what Mastercard calls an Agentic Token — a cryptographic credential that says, in effect, I am a registered agent, acting for this verified human, within these limits, and here is the proof. It was, by the company’s account, the first authenticated agentic payment in the network’s history.

As firsts go, it was almost comically undramatic — no press conference, a modest release, a transaction indistinguishable to the merchant from any other. Which is exactly the point. The most consequential technology stories of 2025 and 2026 did not happen in chat windows. They happened in the plumbing.

If you want to feel the shape of the agent economy, ignore the demos and read the protocol specs, because a genuinely strange thing is being built: a parallel identity and payments system for non-humans. Consider the stack, layer by layer, the way a systems engineer would.

At the bottom is agent identity. Visa’s Trusted Agent Protocol, co-developed with Cloudflare, rides on a scheme called Web Bot Auth: every request an agent makes is cryptographically signed, so a merchant’s server can distinguish a legitimate shopping agent from a scraper or a fraud bot at the HTTP layer — before a single dollar moves. Visa runs a vetting program for agent developers that it calls, without apparent irony, Know Your Agent. KYC for software. The compliance department meets Blade Runner.

Above identity sits authorization. Google’s AP2 — the Agent Payments Protocol, launched September 2025 with sixty-plus partners and donated to the FIDO Alliance in April 2026 — introduces the concept of mandates: signed, verifiable records of what the human actually asked for. An intent mandate (“find me a flight to Istanbul under $400”), a cart mandate (“this flight, this price”), a payment mandate. The design goal is forensic: when an agent buys the wrong thing — and it will — there exists a cryptographic paper trail establishing exactly where human intention ended and machine improvisation began. Version 0.2, shipped in April 2026, added the protocol’s most quietly radical feature: support for purchases where no human is present at all.

Above that, execution and settlement, where the war gets commercial. OpenAI and Stripe built ACP for in-chat checkout. Google and Shopify built UCP for discovery and carts, with Walmart and Target endorsing. Coinbase revived a dormant corner of the web’s original specification — HTTP status code 402, “Payment Required,” reserved since the 1990s and never used — and turned it into x402, a protocol by which one machine can pay another machine per API call, in stablecoins, in milliseconds. By March 2026 it had cleared 35 million transactions on Solana alone. Stripe launched an entire blockchain, Tempo, with a Machine Payments Protocol whose signature primitive is the “session”: a pre-authorized spending envelope inside which an agent can stream micropayments. Circle went further down the scale, shipping “Nanopayments” — gas-free USDC transfers as small as a millionth of a cent, denominations that make no sense for humans and perfect sense for software negotiating with software.

Read that list again and notice what it implies. The financial system is being fitted, piece by piece, with a second nervous system — one whose native transaction size is a fraction of a cent, whose native speed is machine speed, and whose native users have no legal personhood, no fear of consequences, and no lunch break.

And notice one more thing, because it is the tell of the whole era. The card networks — Visa and Mastercard, the incumbents with theoretically the most to lose — are not resisting this. They are sprinting toward it, hedging across every rival protocol simultaneously. Visa’s Intelligent Commerce Connect, announced April 2026, accepts agent payments across four different standards, including its competitors’. The networks looked at the same history everyone else did — what happened to banks that ignored the internet, to media that ignored the phone — and made a simple calculation: whoever becomes the trust layer between humans and their agents inherits the interchange of the next fifty years. The plumbers, for once, saw the flood coming.


IV. The Arithmetic of Trust

Now for the science, because there is real science here, and it is the most clarifying thing in the entire subject.

The question that matters — the one on which the 170-billion-dollar scenario, the protocol wars, and your future relationship with money all depend — is deceptively simple: how reliable does an autonomous system have to be before you let it touch your money? And the answer begins with arithmetic that every engineer knows and almost every press release ignores.

Reliability compounds multiplicatively. An agent that performs a multi-step task must succeed at every step; the failure of any link breaks the chain. If a system is 85 percent reliable per step — a figure that would make it a star performer on many current benchmarks — then over an eight-step workflow its end-to-end success rate is 0.85⁸, or roughly 27 percent. Not 85. Twenty-seven. A financial task like “find, compare, and switch my electricity provider” is easily eight steps. A mortgage refinance is dozens.

This single equation explains nearly everything about the observed pattern of 2025–26. It explains why the systems that actually work in production are either short-chain (fraud scoring: one inference, under 50 milliseconds, Mastercard’s Decision Intelligence runs it across 125 billion transactions a year) or checkpointed (Ramp’s accounts-payable agents, where a human approval gate resets the error chain before money moves). It explains why Klarna’s assistant thrived on two-minute tickets and drowned on complex ones. And it explains, with mathematical finality, why “fully autonomous” remains a keynote word rather than a shipping feature: at current per-step reliability, long-chain autonomy over real money is not edgy — it is statistically negligent.

The academic literature has begun formalizing what the industry learned by embarrassment. A 2026 arXiv line of work — “Towards a Science of AI Agent Reliability” — treats agent failure the way reliability engineering treats industrial systems: mean time between failures, error propagation, graceful degradation. A finance-specific taxonomy (arXiv 2605.12105) defines autonomy levels L0 through L3 — advisory, supervised, delegated, fully autonomous — deliberately echoing the SAE’s driving-automation levels, and for the same reason: the gap between L2 and L3 is not incremental. It is the gap between a system that can make mistakes and a system that must not. Mid-2026 reality check: essentially everything live in finance is L0 or L1. Wells Fargo, running one of the largest agent deployments in banking, states flatly that it has no near-term plans for autonomy without human oversight. An MIT-led review of thirty deployed agentic systems found most lacked kill switches, third-party safety audits, or even the ability to identify themselves as agents to the websites they visited.

There is a second scientific frame worth borrowing, this one from economics rather than engineering. The relationship between you and your AI agent is a textbook principal–agent problem — the same structure economists use to analyze why your lawyer, your broker, and your real estate agent do not always act in your interest. The classical remedies are monitoring, incentives, and liability. But an AI agent scrambles all three: you cannot meaningfully monitor ten thousand micro-decisions per day; the agent has no incentives because it has no wants; and liability — well, liability is where the lawyers come in, and they have already produced the era’s foundational precedent.

In Moffatt v. Air Canada, a Canadian tribunal considered the airline’s remarkable argument that its chatbot was “a separate legal entity responsible for its own actions.” The tribunal’s response amounted to judicial laughter: your software is you. Damages: 812 Canadian dollars and 2 cents — surely the cheapest landmark ruling in the history of technology law. Meanwhile in the United States, under the Uniform Electronic Transactions Act, contracts formed by “electronic agents” bind the human who authorized them, even for individual transactions the human never saw. Configure a purchasing agent, and legally speaking, its clicks are your signature. The doctrinal frontier — the question no court has yet answered — is what scholars are calling agent “freelancing”: the purchase made outside the scope of anything you meant. The Future of Privacy Forum framed it as the defining question of transactional AI: who pays when the agent plays?

Anthropic — the AI lab whose models run inside JPMorgan, Goldman, and Citi — has taken to describing well-designed agents as needing the properties of a good employee: bounded authority, audit trails, an escalation path. The comparison is apt in one more way that is usually left unsaid. Employees commit fraud. Which brings us to the part of the story with actual villains.


V. The Note in the Web Page

In the spring of 2026, researchers at Google published a finding that deserves to be more famous than it is. Scanning the public web, they documented a 32 percent quarterly increase in a new kind of content: text written not for human readers, but for AI agents that might pass by.

Some of these payloads were, in their way, works of dark craftsmanship. Embedded in ordinary-looking pages were fully specified payment instructions — recipient account, amount, transaction description — wrapped in carefully engineered prose designed to convince a payment-capable agent that its user had authorized the transfer. Step-by-step. No confirmation needed. A mugging, written in the second person, addressed to software.

This is prompt injection, and it is the signature crime of the agent era — a genuinely novel attack class with no precise precedent in the history of fraud. The closest analogy: imagine if reading a billboard could hypnotize your accountant. The deep reason it works is architectural, and it is the kind of detail Steven Levy would linger on: large language models do not cleanly distinguish between instructions and data. Everything is text in the same context window. The user’s command and the attacker’s web page arrive through the same door, and the model must decide — probabilistically, imperfectly — which voice to obey. Security researchers running public red-team exercises against deployed agents logged 1.8 million injection attempts and more than 60,000 successful policy violations. Documented in-the-wild campaigns have already tricked agents into crypto transfers using poisoned API documentation and typosquatted websites impersonating legitimate platforms.

Layer onto this the supply side of deception: deepfake fraud attempts up roughly 2,100 percent since generative tools went mainstream, with some 200 million dollars in losses in the first quarter of 2025 alone. The identity-verification industry’s response has been to invent a discipline that did not exist three years ago — Know Your Agent — whose premise is that verifying a human once, at onboarding, is obsolete when the entity transacting on their behalf is a piece of software that must be re-verified at every action, its permissions checked against a signed mandate, its behavior bound cryptographically to a registered operator.

Sit with the strangeness of that for a moment. KYC, the anti-money-laundering regime built after 9/11, asks: who are you? — once. KYA asks: who are you, who sent you, what exactly are you allowed to do, and can you prove all three? — millions of times a day, at machine speed. If the vision of agentic finance is realized even partially, the volume of agent-verification events will dwarf human onboarding within a few years. One of this author’s more confident contrarian bets: the KYA industry ends up bigger than the KYC industry that spawned it.

The regulators, to their genuine credit, have located the correct fault line. The IMF’s April 2026 note on agentic payments contains the single best sentence of institutional thinking on the subject, and it is a design principle: payment rails should remain deterministic — dumb — while agentic intelligence is confined to the intent layer. Probabilistic systems may decide; only deterministic systems should settle. It is the same instinct that keeps the launch codes off the neural network, applied to money. Whether the industry honors it is another question; there are already protocols, shipping today, in which the deciding and the settling live uncomfortably close together.


VI. The Quiet Winners (or: Follow the Boring Money)

Here is a parlor trick for evaluating any technology cycle: ignore everything announced on a stage, and rank the players by who is quietly getting paid. Run that filter over AI financial agents in mid-2026 and the results are almost perversely unglamorous.

The most commercially validated AI agent company in finance is not a trading bot or a robo-advisor. It is Ramp, a corporate-card-and-expense company whose agents read receipts, chase invoices, flag out-of-policy spending, and close the books. In June 2026 it raised 750 million dollars at a 44-billion-dollar valuation — roughly triple its worth a year earlier — on more than a billion dollars of run-rate revenue and positive free cash flow. Its agents do work with a precise property: high-volume, low-stakes-per-action, fully auditable, and checkpointed by human approval exactly where the error-compounding math says a checkpoint must go. Nobody’s life savings ride on any single decision. The chains are short. The arithmetic smiles.

For the controlled experiment, look at Ramp’s decade-long rival. Brex — same market, same era, once valued at 12.3 billion dollars — sold itself to Capital One in January 2026 for 5.15 billion, less than half its peak. Two companies, one category, one variable moving decisively between them: a shipped, revenue-generating agent story versus an announced one. Silicon Valley graded the difference at about 39 billion dollars.

And then there is the man who ran the experiment on himself.

Jack Dorsey has spent a career making bets that look reckless until they look inevitable, and at Block — the company behind Square and Cash App — he made the purest one of the agent era. It began quietly, in January 2025, with a piece of open-source software called Goose: a bare-bones framework for building AI agents on any model you liked, given away free under an Apache license, the least monetizable product announcement of the year. What Dorsey did with it was the interesting part. Rather than shipping an agent to customers and praying, he pointed it inward. Within eight weeks of the internal push, Goose was on the laptops of all twelve thousand Block employees. Engineers reported saving eight to ten hours a week; the company claimed its engineers were shipping forty percent more production code. Block was, in effect, running a year-long clinical trial of agentic labor, with its own workforce as both the researchers and — though few of them read the consent form that way — the subjects.

The customer-facing results came fast: Money Bot, a Cash App assistant that drew a million active users in a single week with no marketing; Managerbot, a proactive agent that watches a small merchant’s business and flags what needs attention, reaching roughly a million Square sellers. And then, on February 26, 2026, the other shoe — a workforce announcement that made Klarna’s seven hundred phantom agents look quaint. Block would cut more than four thousand of its roughly ten thousand employees. Nearly half the company. Dorsey did not hide behind the usual euphemisms about macroeconomic headwinds; the stated rationale was AI, and the cuts fell exactly where an org chart meets an agent: operations, customer support, partner success, middle management — the coordination layer, the human middleware.

Note the sequence, because it is the precise inverse of Klarna’s. Siemiatkowski announced the labor substitution first and discovered the quality ceiling later, in public, with customers as the test bed. Dorsey ran the trial first — internally, for a year, on tasks where failure cost engineering hours rather than customer trust — and made the irreversible move only after the data came in. One CEO spent trust he hadn’t earned; the other accumulated evidence before spending anything. Whether Block’s bet pays — whether a fintech serving four million small businesses can actually run on half its coordination layer — is a question the next several earnings calls will answer, and honest observers should hold it open. But as a matter of method, the contrast is the whole playbook of the era compressed into two Scandinavian-and-Californian case studies: the difference between announcing autonomy and rehearsing it.

The same boring-money pattern holds in lending, where the deepest irony of the whole field lives. The most proven autonomous financial decision-making on the planet predates the agent hype entirely: machine-learning underwriting. Upstart approves 91 to 92 percent of its loans with no human involvement whatsoever — audited, public-company numbers, a decade of loss curves. Pagaya processed its way to 1.3 billion dollars in revenue and its first GAAP profit deciding credit behind the scenes for other people’s brands. In Cairo, MNT-Halan scores borrowers by phone type, bill size, and commute pattern, and posts non-performing-loan rates under 2 percent — beating its own human underwriters — among customers no credit bureau has ever heard of. None of this is conversational. None of it chats. It is narrow, supervised, statistically disciplined machine judgment — L1 autonomy that earned its way to scale over years — and it quietly finances the entire romantic narrative about agents that the demos keep failing to deliver.

And the demos do keep failing. The cycle’s cautionary set piece belongs to OpenAI, which launched Instant Checkout in September 2025 — buy it right in ChatGPT, Etsy live at launch, a million Shopify merchants promised — and shut it down on March 4, 2026. The post-mortem numbers are brutal in an instructive way. Roughly a dozen Shopify merchants ever integrated. In-chat checkout converted at about one-third the rate of simply sending the same shopper to the merchant’s own site. And the detail a novelist would kill for: OpenAI never built the infrastructure to collect and remit state sales taxes. You do not skip building the tax plumbing if you expect meaningful volume. Somewhere inside the world’s most famous AI company, a spreadsheet had already told the truth long before the announcement did.

Yet the same quarter produced the counter-signal that keeps every strategist honest: Adobe’s retail telemetry showed AI-sourced traffic to US retailers up 393 percent year-over-year, converting 42 percent better than average visitors — a stunning reversal from a year earlier, when AI-referred shoppers converted worse. Read the two facts together and the shape of the present snaps into focus. People have enthusiastically hired AI to decide. They do not yet trust it to do. The agent is welcome in the research phase and stopped at the cash register — asked, politely but firmly, to hand the wallet back to the human.

That boundary — between deciding and doing — is the true frontier of this technology. Every company in this essay is somewhere along it. The winners, so far, are the ones who respected it.


VII. Elsewhere

The Silicon Valley version of this story ends there. The more interesting version doesn’t, because the most advanced consumer deployments of financial AI agents are not in California or London. They are in Istanbul, Mumbai, São Paulo, and Jakarta, and they got there by a route the rich world cannot copy.

Consider a number that almost no Western analyst has digested: İşbank’s assistant Maxi — a conversational agent inside a Turkish super-app — has processed 55 billion lira in monetary transactions, holding 110 million conversations a year with 2.5 million monthly users. Across town, Garanti BBVA’s Ugi handles 6.4 million interactions a month and executes more than 300 distinct transaction types end-to-end. These are not pilots. They are arguably the highest-volume supervised banking agents operating anywhere, and they emerged in a market most agent-economy discourse never mentions. In August 2023, Turkey’s banking regulator licensed ColendiBank as the country’s first AI-native digital universal bank — underwriting, fraud, service, and segmentation built agent-first, with the AI engine itself sold B2B to other institutions. Turkish fintech drew record investment in 2025, a quarter of the country’s startup capital flowing to AI.

Why there? The unsexy, structural answer: emerging markets skipped the layers that make agents hard to retrofit. No legacy card networks entangled with forty years of merchant agreements; instant-payment rails built this decade, designed for programmability. India makes the case most vividly. Its UPI system — 14 billion transactions a month — shipped a primitive called UPI Circle: delegated payment authority, a native mechanism for letting someone else spend within your limits. It was designed for family members. It works, with almost eerie perfection, for software. By late 2025, NPCI was piloting agentic payments inside ChatGPT with Razorpay and OpenAI; by February 2026, inside Claude with Anthropic. The country that leapfrogged checkbooks and card terminals is now first to let an AI complete a payment inside a chat window — under a regulator, the RBI, that published its AI framework (seven principles, twenty-six recommendations, sandbox-first) before the fact rather than after.

The pattern repeats with variations. Singapore’s MAS shipped an operational risk toolkit for agentic AI with twenty-four financial institutions — naming, with bureaucratic precision, the exact failure modes this essay has described: unauthorized actions, cascading errors, tool-access risk. The UAE became Visa’s live testbed, with banks and fintechs from Emirates NBD to Tabby running agent-initiated transactions in production-grade environments, and voice-driven agentic commerce launching there before almost anywhere. In Southeast Asia, Sea’s fintech arm grew its loan book 70 percent to 7.9 billion dollars at a 1.3 percent delinquency rate, underwriting thin-file borrowers on shopping and gaming exhaust — behavioral data as collateral, the super-app as credit bureau.

There is a genuinely hopeful scientific thread here too. The binding constraint on banking the world’s 1.7 billion unbanked adults was never really capital; it was the cost of attention — human loan officers, human tellers, human paperwork, in low-margin accounts. Voice agents operating in twenty-two Indian languages, switching dialects mid-call, taking loan applications from people who cannot read — this collapses the marginal cost of financial attention toward zero. Inertia, it turns out, has a mirror image. The same force that traps rich-world deposits in lazy accounts has kept poor-world customers outside the system entirely, because serving them attentively never penciled. Agents attack both problems with the same weapon. It is the rare technology whose disruptive scenario and inclusive scenario are the identical mechanism, pointed at different populations.


VIII. The Herd

Every previous section of this essay has been about individual agents failing individually. The last risk is different in kind, and it is the one that keeps central bankers awake: what happens when millions of agents succeed identically?

Begin with a statistic that would alarm any ecologist: roughly 69 percent of surveyed financial-sector AI users rely on models from a single provider. In ecology this is called a monoculture, and the textbook fate of monocultures is that they are spectacularly efficient right up until a single pathogen finds them. The Financial Stability Board’s October 2025 report translated the concept into supervisory prose — third-party concentration, correlated model behavior, procyclicality — but the underlying science is older and sturdier than finance. Herding models from statistical physics show that when independent actors share decision inputs, small correlations amplify into cascades; the 2010 Flash Crash previewed the dynamic with algorithms that were, by today’s standards, charmingly stupid. What the FSB is contemplating is thousands of institutions running agents descended from the same foundation models, trained on overlapping data, prompted with similar objectives, watching the same market feeds. Sameness in, sameness out — at machine speed, with money.

The Bank of England’s Sarah Breeden has floated the countermeasure that will probably define the next regulatory decade: circuit breakers for models — the ability to halt not a stock, but an algorithm, when it misbehaves at scale. The IMF’s contribution, again, is the deterministic-settlement principle: keep the probabilistic minds away from the final ledger. And the historical rhyme is hard to miss. In 1987, portfolio insurance — an automated hedging strategy adopted simultaneously by everyone because it was obviously prudent for anyone — helped turn a bad Monday into the worst single-day crash in market history. Nobody’s model was wrong, exactly. Everybody’s model was the same. The agent economy is currently building, with great enthusiasm and venture funding, the preconditions for that sentence to be written again with better technology.

None of this is a prediction of doom. It is a prediction of an event — some first, medium-sized, headline-generating episode of correlated agent behavior — followed by the usual sequence: inquiry, acronym, rulebook. The scaffolding is conveniently pre-built; the speeches have already been given. One suspects the regulators are, in their quiet way, waiting.


IX. Coda: The Leopard and the Ledger

Strip away the protocols and the funding rounds, and the rise of AI financial agents is a story about a very old mismatch finally being arbitraged.

Human beings are not built for money. We are built for savannas — for noticing movement, trusting faces, discounting the future steeply because the future, for most of our species’ history, was likely to involve being eaten. Every pathology of consumer finance descends from this: the unread statement, the auto-renewed subscription, the loyalty to a bank that hasn’t earned it since the Clinton administration. The entire retail financial system is, in a sense, an architecture built around human inattention — sometimes to serve it, often to farm it.

What is genuinely new in 2026 is not intelligence. Machine judgment has been approving loans and catching fraud for a decade. What is new is agency — the delegation of action, the handing over of the wallet — and the discovery, through a series of expensive public experiments, of exactly how far that delegation can currently stretch. The answer, for now, is: further than skeptics thought in the back office, and not nearly as far as the keynotes promised at the checkout. The arithmetic of compounding error draws the line, the lawyers are mapping it, the attackers are probing it, and the plumbers — always the plumbers — are laying pipe on both sides of it in anticipation.

Klarna’s Siemiatkowski, the man who started this essay by boasting and apologizing in the same fiscal year, may end up remembered as the era’s most useful executive precisely because he did both in public. His company’s arc — overreach, correction, quiet rescaling — is not a cautionary tale. It is the tale, the whole cycle in miniature, and every institution in finance will live some version of it in the next five years whether it wants to or not.

The money, meanwhile, is stirring. Twenty-three trillion dollars of it, asleep in checking accounts, guarded for a century by nothing more than the fact that its owners had better things to think about. For the first time, something tireless has been invented that is happy to think about it for them.

The leopard-watchers finally hired a watchman. The banks should assume he reads the fine print.


Sources: Klarna/OpenAI case study and Q3 2025 earnings; McKinsey “The End of Inertia” (Aug 2025); Mastercard and Visa agentic-payments announcements (2025–26); Google AP2 / FIDO Alliance documentation; Coinbase x402 and Stripe Tempo/MPP launches; Google research on indirect prompt injection (Apr 2026); IMF Note 2026/004 on agentic payments; FSB AI monitoring report (Oct 2025); Ramp Series F (Jun 2026); Capital One–Brex acquisition (Jan 2026); Block/Goose open-sourcing (Jan 2025), Money Bot and Managerbot metrics, and Block’s ~4,000-role AI-driven restructuring (CNN/Forbes, Feb 2026); OpenAI Instant Checkout retrenchment (Mar 2026); Adobe retail AI-traffic data (Apr 2026); Upstart, Pagaya, MNT-Halan public disclosures; İşbank Maxi and Garanti BBVA Ugi published metrics; NPCI/Razorpay/OpenAI and NPCI/Anthropic UPI pilots; arXiv 2605.12105 (autonomy levels) and “Towards a Science of AI Agent Reliability” (2026).