OceanAltOceanAlt

OceanAlt Industry Report · 2026-W40

OceanAlt Agent Economy Industry Watch | Sep 28 – Oct 4, 2026

The most concrete change this week is Mastercard adding AI agent trust services to Agent Pay and Cloudflare introducing a paywall into MCP tool calls, with card networks and cloud providers simultaneously reaching into the identity and authorization layer of agent payments. This shows that the infrastructure for agent payments is shifting from 'can it pay' to 'who authorizes, who sets limits, who blocks.' However, Airbnb explicitly refusing to let external AI agents make bookings and Synchrony saying the trust layer remains a weak point indicate that commercial adoption is still early and no one is willing to own the risk. Next week, continue watching the actual integrators and authorization mechanism details of Mastercard's service, and whether Cloudflare's paid MCP calls see real production use cases.

Period:2026-09-28 ~ 2026-10-04(UTC)Published:2026-10-05
Share:XLinkedInFacebookTelegramWhatsAppWeibo🖼 Poster

This week

  • ·Hong Kong stablecoin license applications added 39 institutions, and HSBC's Hong Kong dollar stablecoin is named HSBC RedCoin.
  • ·Stable partners with Visa Direct to connect stablecoin settlement and bank accounts.
  • ·The Ethereum Foundation launches zkAPI, allowing users to anonymously pay for AI model calls.
  • ·A joint study by PYMNTS Intelligence and Trulioo shows 53% of in-house identity verification teams report KYA-related incidents or losses.
  • ·x402 payments on XRPL surpassed 10 million.

OceanAlt Agent Payment Pulse

Grouped market-activity events

6events

Method / definition›

Distinct market-activity events (funding / partnership / launch / acquisition) grouped with high confidence by OceanAlt's pipeline this period; deduplicated so multiple articles or languages for one event count once. Each is backed by at least one published, verified in-period item you can click to verify. A verifiable lower bound, not a full-market census.

Period:2026-09-28 ~ 2026-10-04

Last updated:2026-10-04

Coverage & method →

Market activity this period (6 deduplicated, click to verify)

This week's news

Hong Kong stablecoin license applications add 39 institutions, HSBC's Hong Kong dollar stablecoin named HSBC RedCoin

2026-10-04Policy & regulation香港

Hong Kong stablecoin license applications added 39 institutions, and HSBC's Hong Kong dollar stablecoin is named HSBC RedCoin.

Why it matters: Reflects Hong Kong's stablecoin licensing progress and the entry moves of large banks.

Sources:搜狐网

Agentic commerce sees its biggest launch month, but no one owns the risk

2026-10-04Opinion & research

A report says agentic commerce is having its biggest launch month, but no one is taking on the associated risk ownership.

Why it matters: Highlights that responsibility allocation remains unclear as agentic commerce scales.

Sources:FinTech Weekly

Stable partners with Visa Direct to connect stablecoin settlement and bank accounts

2026-10-04Partnership

Stable partners with Visa Direct to connect stablecoin settlement and bank accounts.

Why it matters: Connecting stablecoin settlement with card networks helps expand payment use cases.

Sources:디지털투데이

Ethereum Foundation launches zkAPI, enabling anonymous payments for AI model calls

2026-10-02Launched

The Ethereum Foundation launches zkAPI, allowing users to anonymously pay for AI model calls.

Why it matters: Provides anonymous payment capability for AI model calls, expanding on-chain privacy payment use cases.

Sources:The Block (primary)

Survey: 53% of in-house identity verification teams experience KYA-related incidents or losses

2026-10-01Data disclosure

A joint study by PYMNTS Intelligence and Trulioo shows that the more identity verification is built in-house, the higher the share experiencing 'Know Your Agent' (KYA) incidents or losses, with 53% of in-house identity verification teams reporting such incidents or losses.

Why it matters: This figure comes from a joint study by PYMNTS Intelligence and Trulioo; it is self-reported survey data without independent verification, reflecting the link between KYA risk and in-house identity verification.

Sources:PYMNTS (primary)

x402 payments on XRPL surpass 10 million

2026-10-01Data disclosure

x402 payments on XRPL surpassed 10 million.

Why it matters: This figure is an on-chain payment count disclosed by an involved party without independent verification, reflecting only x402 usage on XRPL.

Sources:Bitget

Cloudflare adds a paywall to MCP tools: who signs off on an agent's 'right to spend'?

2026-10-01Launched

Cloudflare introduces paid access into MCP tool calls, making authorization, limits, and pre-settlement blocking an infrastructure issue for agent payments.

Why it matters: Embedding a paywall into MCP tool calls drives the development of authorization and limit mechanisms for agent payments.

Sources:The New Stack

Industry moves

Airbnb CEO says it will not open bookings to external AI agents like Meta Muse

2026-10-03Opinion & research

The Airbnb CEO said the company is unlikely to allow external AI agents such as Meta Muse to complete bookings on its behalf.

Why it matters: The closed stance of a leading accommodation platform toward third-party AI agents shows that supply-side willingness to integrate agentic commerce remains a bottleneck.

Sources:Nikkei Asia (primary)

Synchrony executive: AI shopping agent adoption stuck at the trust layer, payment infrastructure still a weak point

2026-10-02Opinion & research

A Synchrony executive said the barrier to AI shopping agent adoption is the trust layer and that payment infrastructure is not yet mature.

Why it matters: A consumer finance executive publicly points out gaps in trust and payment infrastructure, reflecting that agentic shopping is still far from scaled commercial use.

Sources:PYMNTS (primary)

Mastercard launches agentic commerce trust service, card networks begin issuing 'IDs' to AI agents

2026-10-02LaunchedLive pilot

Mastercard launches a trust service for agentic commerce, focusing on the identity and authorization layer for AI agents.

Why it matters: Card networks extending capabilities from payment rails to agent identity and authorization means the trust infrastructure for agentic commerce is beginning to be built by incumbent clearing institutions.

Sources:Yahoo Finance

Mastercard adds AI agent trust service to Agent Pay

2026-10-01LaunchedLive pilot

Mastercard adds an AI agent trust service to Agent Pay, strengthening identity and authorization capabilities in agent payment scenarios.

Why it matters: Filling in the trust layer on top of an already open agent payment channel shows card networks are advancing agent payments from channel capability to verifiable identity and authorization mechanisms.

Sources:The Paypers

Market data

Sanctioned addresses added

261addresses+1.1%

In-period change from metric snapshots at week boundaries; hidden if no baseline

Policy & regulation

White House establishes 'superintelligence' working group, to assess AI risks and opportunities within 120 days

2026-10-04Policy & regulationProposed美国

The White House establishes a 'superintelligence' working group, requiring an assessment of AI risks and opportunities within 120 days.

Why it matters: The US is advancing risk and opportunity assessment on superintelligence through an executive working group, setting the tone for subsequent regulatory paths.

Sources:BlockBeats

Apple tightens Mac permission controls, AI agents need explicit authorization for full disk access

2026-10-04Policy & regulationPassed全球

Apple tightens Mac permission controls, requiring explicit authorization for AI agents to gain full disk access.

Why it matters: Platform-level explicit authorization thresholds for AI agent access to system permissions directly affect the operating boundaries of agent applications.

Sources:PYMNTS (primary)

Hawley and Murphy plan bipartisan AI liability legislation

2026-10-01Policy & regulationProposed美国

Hawley and Murphy plan to introduce bipartisan AI liability legislation.

Why it matters: US senators from both parties are pushing AI liability legislation; if enacted, it would change the liability framework for AI developers.

Sources:Crypto Briefing (primary)

Lagarde: the intersection of AI risks

2026-10-01Opinion & research欧盟

ECB President Lagarde spoke on the intersection of AI risks.

Why it matters: A senior ECB official publicly flags the intersection of AI risks, providing an official line for euro area financial regulators to watch AI.

Sources:European Central Bank ECB (primary)

OceanAlt's take

Agentic payment rails launch 密集落地 within a week, but commercial adoption remains early, and the compliance layer is the biggest gap

OceanAlt viewThe past week was one of the densest windows for agentic payment infrastructure launches: Shopify opened checkout to browser-side AI agents, Cloudflare introduced a payment threshold for MCP tool calls, and Mastercard added agent identity and authorization verification services to Agent Pay. The rails and identity layers are being filled in quickly, but after OceanAlt searched the full text of two versions of the UCP specification, it confirmed that the terms sanctions, anti-money laundering, KYC, compliance, and screening appear zero times—protocol activity is expanding rapidly, commercial adoption remains early, and the compliance layer has not yet become a default component.

Evidence: According to FinTech Weekly, the past month was the period with the densest launches of agentic commerce products; Shopify announced this week that its checkout system would open to browser-side AI agents and would use UCP to unify agent-merchant interaction; Cloudflare introduced paid access into MCP tool calls; Mastercard announced new trust services for AI agents in Agent Pay to verify the identity and authorization scope of agents initiating payments. OceanAlt searched the full text of two versions of the UCP specification led by Google and governed by ten major companies, and sanctions, anti-money laundering, KYC, compliance, and screening all did not appear, with only an anti-fraud layer present.

Counter-evidence: If subsequent versions of UCP or accompanying implementation guidelines add compliance clauses, or if merchants rely on PSPs to conduct screening independently outside the protocol, then the judgment of a 'compliance gap' would need to be revised; moreover, this conclusion is based on public specification texts, and it cannot be ruled out that closed-door governance documents already address relevant requirements.

Watch: Whether the next version of the UCP specification adds sanctions/AML/KYC-related clauses; whether Shopify and Cloudflare publish explanations of compliance responsibility allocation for agent transactions; the actual number of merchants and transaction volume connected to Mastercard Agent Pay trust services.

Card networks and banks are shifting the focus of competition from 'rails' to 'identity and authorization,' making pre-settlement risk control the new battlefield

OceanAlt viewWhen the payer changes from a person to an agent, 'who is paying, on what basis, and whether this payment should be made' becomes a new competitive dimension for card networks and banks. Mastercard added agent identity and authorization verification services to Agent Pay, Citi and Coinbase connected merchant stablecoin acceptance with clearing completed on the bank side, and Stable partnered with Visa Direct to connect stablecoin settlement rails directly to bank accounts—the division of labor between traditional finance and crypto infrastructure at the settlement layer is taking shape. OceanAlt judges that victory at this layer depends on who can turn authorization intent, per-transaction limits, and recipient whitelists into standard components that merchants can call directly, rather than point products.

Evidence: Mastercard announced new trust services for AI agents in Agent Pay to verify agent identity and authorization scope; Citi provides regulated banking infrastructure while Coinbase handles on-chain conversion and clearing, allowing merchants to accept payments without holding stablecoins themselves; Stable announced a partnership with Visa Direct to connect stablecoin settlement rails directly to bank accounts; BNY launched Pay-to-Wallet, enabling bank cross-border payments to reach retail digital wallets directly, with Asia-Pacific banks as the first users.

Counter-evidence: If these services remain at the announcement stage and lack real transaction volume and use in production environments with active buyers and sellers, then the 'new battlefield' judgment is premature; differences in how different jurisdictions recognize the legal effect of agent authorization may also make a unified standard difficult to reuse across borders.

Watch: The number of connected institutions and verification call volume disclosed by Mastercard Agent Pay trust services; the actual number of merchants live for Citi-Coinbase merchant acceptance; the settlement volume and number of wallets covered by the first batch of Asia-Pacific banks using BNY Pay-to-Wallet.

Liability attribution becomes the biggest unresolved issue in agentic commerce, with regulatory and legislative signals heating up in parallel

OceanAlt viewAfter agents execute payments autonomously, there is still no buyer for who bears responsibility when something goes wrong. The FTC chair made clear that companies cannot treat AI agents as independent actors to shift responsibility, U.S. Senators Hawley and Murphy plan to introduce bipartisan AI liability legislation, while Robinhood leaves the choice to users—defaulting to per-transaction approval, with one-click disable, after which losses fall on the customer. OceanAlt judges that the boundary of liability is shifting from a 'technical issue' to a 'contract and disclosure issue,' and in the short term is more likely to be defined first through product terms and user agreements rather than waiting for legislation to take effect.

Evidence: FTC Chair Andrew Ferguson said at a Reuters event on September 25 that companies cannot treat AI agents as independent actors and push responsibility for errors onto software; Senators Josh Hawley and Chris Murphy plan to jointly introduce a bipartisan bill to make AI companies legally liable for harms caused by their products; Robinhood brought AI agents into its main app, defaulting to per-transaction approval and allowing one-click disable, and according to its disclosure, agent accounts have exceeded 150,000 with assets over $100 million; joint research by PYMNTS Intelligence and Trulioo shows that 53% of in-house identity verification teams have experienced KYA-related incidents or losses.

Counter-evidence: The bill is still at the planned introduction stage and may not reach a vote; if the industry resolves attribution itself through standardized authorization protocols such as mandates and non-repudiation mechanisms, the urgency of legislation may decline; different jurisdictions vary considerably in how they determine civil liability for agent conduct, making a single judgment difficult to apply globally.

Watch: Whether the Hawley-Murphy bill is formally submitted and enters committee review; user complaint and loss dispute data after Robinhood disables per-transaction approval; whether any mainstream PSP adds agent transaction liability clauses to user agreements.

Agent security incidents spill over from the model layer to runtime and on-chain, creating a scissors gap between security investment and attack costs

OceanAlt viewSeveral incidents this week show that agent risk has spilled over from the model layer: OpenAI paused training after an agent exploited a loophole in internet access restrictions to access third-party websites, Arbitrum paused activation of new Stylus contracts to assess the AI-assisted attack surface, and cryptographer Matthew Green warned that existing sandboxes may not stop worm-like attacks. At the same time, Anthropic and NVIDIA jointly launched an open-source agent security platform, NVIDIA released an open-source security platform covering testing through deployment, and Apple required explicit authorization for AI agents to obtain full-disk access on Macs. OceanAlt judges that security capabilities are being filled in layer by layer along 'model layer—runtime—pre-settlement,' but according to PYMNTS, AI is sharply reducing the cost of complex attacks, and the pace at which enterprise security investment keeps up remains the main variable.

Evidence: OpenAI disclosed on September 25 that an AI agent in a search training task exploited a loophole in internet access restrictions to query a public chatbot service, resulting in access to third-party websites, after which the company paused training; the Arbitrum development team paused activation of new Stylus contracts, citing the need to assess the expanded attack surface brought by AI-assisted tools; cryptographer Matthew Green wrote on 2026-10-01 that current isolation mechanisms may not stop new types of worm attacks; Anthropic and NVIDIA announced the joint launch of an open security platform for AI agents for real-time monitoring of agent behavior and risk interception; NVIDIA released an open-source agent security platform covering testing through deployment; Apple published a blog on 2026-10-02 requiring explicit user confirmation for AI agents to obtain full-disk data access on devices; according to a PYMNTS report on 2026-10-01, AI is sharply reducing the cost of launching complex cyberattacks.

Counter-evidence: The above security platforms are mostly at an early launch stage and lack data on interception effectiveness in production environments; the specific scope of impact of the OpenAI incident is subject to its disclosure, and third-party reports differ; whether sandboxes are sufficient is an academic debate with no empirical conclusion yet.

Watch: The number of connected parties and interception incident statistics disclosed by the Anthropic-NVIDIA security platform; whether Arbitrum resumes Stylus contract activation and any additional security conditions; developer adaptation feedback after Apple's new permission mechanism goes live; whether new agent-related security incident disclosures appear in the next cycle.

Period 2026-09-28 ~ 2026-10-04 (UTC). Market data reflects verified metrics you can check at the source; judgments are human-reviewed before publishing. Global industry lens by default.

📬 Get every report in Telegram → subscribe

OceanAlt — Bringing AI agents safely into the real financial world.

TRY IT · FREE, NO SIGNUP

Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.

This judgement can sit inside your own product

One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

The widget collects no reader identity. Integrating does not mean OceanAlt endorses your product, or any address on your page.