Payments

Machine Payments Need Machine-Speed Controls

Blackrock Research
June 30, 2026
4 min read

Machine Payments Need Machine-Speed Controls

Payments between software agents are likely to be smaller, faster and more connected than familiar card purchases. Mastercard’s Agent Pay for Machines announcement describes transactions worth fractions of a cent and chains executed continuously at machine speed, with more than 30 early supporters. The opportunity is real, but so is a new risk shape: a harmless unit price can become a material loss through velocity and recursion.

What the evidence shows

Most payment controls assume a person initiates a purchase, sees a price and experiences some friction. Machine commerce removes those natural pauses. An agent may buy compute, data, identity checks or delivery from another service, which itself buys an input from a third service. Thousands of individually valid decisions can form one economically irrational chain.

The rail is adapting. Mastercard is positioning card and tokenized payment capabilities for programmatic, always-on service exchange. The AP2 specification and FIDO’s description of agentic payment trust focus on delegated authority and verifiable authorization. Those are necessary foundations. They do not by themselves decide whether a particular series of authorized purchases is worth its total cost.

That requires a budget and policy layer close to execution. Human approval for every microtransaction would eliminate the benefit. Unlimited pre-authorization would convert a software loop into an open wallet.

The operating consequence

Machine-payment economics are nonlinear. A $0.001 data call looks negligible, but retries, nested agents and adversarial prompts can multiply it. The relevant exposure is not transaction value alone. It includes frequency, cumulative spend, number of counterparties, depth of delegation and concentration in a short interval. Source

Disputes may also be difficult. A traditional receipt describes one purchase. A machine workflow needs a trace linking the initial objective to every downstream call and payment. Without that lineage, finance cannot allocate cost, engineering cannot diagnose waste and risk teams cannot distinguish abuse from a poorly designed loop.

Pricing strategy changes for sellers too. A per-call price invites volume but creates bill shock if buyers cannot predict consumption. Subscriptions cap buyer uncertainty but may subsidize heavy agents. Hybrid commitments, quotas and clearing intervals may emerge.

What operators should do now

Issue task-scoped payment credentials. Bind each credential to an initiating job, allowed merchant categories or counterparties, maximum unit price, cumulative budget, time window and permitted delegation depth. Expire it when the job ends.

Implement velocity controls at several horizons: per second for runaway loops, per hour for abnormal bursts and per job for economic discipline. Use circuit breakers that stop both calls and payments, then preserve state for diagnosis.

Require a machine-readable receipt containing the service purchased, input reference, unit price, quantity, parent task and result status. Reconcile failed or duplicated service calls automatically. Do not rely on a monthly statement to reveal a recursive error.

For pricing, expose estimates before execution and update the forecast as the agent’s plan changes. Let buyers set soft alerts below hard stops. Measure useful output per dollar, not transaction count.

Design controls around dependency chains, not just individual merchants. A service may be trustworthy on its own while calling several paid tools downstream. The initiating organization needs a consolidated view of total exposure and a rule for how much authority each delegated service can pass onward. Unbounded delegation is an economic vulnerability even when every credential is valid.

Run failure drills before raising limits. Simulate retry storms, duplicate calls, compromised suppliers and incorrect unit pricing. Confirm that circuit breakers halt new spend, preserve evidence and notify the accountable owner quickly enough to matter. A control that produces a clean report the next morning is too slow for machine-speed loss.

Finance and engineering should reconcile from the same event record. Give every paid call a stable identifier and connect reversals, retries and downstream charges to it. That shared lineage makes cost allocation possible and helps distinguish genuine demand from a malfunction. Controls must operate before exposure compounds.

The decision

Machine payments can make digital services composable in ways subscriptions and invoices cannot. They will scale only if economic authority travels with technical authority. The right primitive is not simply “agent can pay.” It is “agent can pay this much, for this purpose, along this chain, until this condition changes.”