The Responsible Agentic Payments Framework
When the payer shifts from a human to code, an entire compliance system — built on the assumptions that a person sits behind each transaction and that transactions are slow enough to review — fails at once. RAP is an open, protocol-neutral standard for keeping machine-initiated payments attributable, controllable, auditable and compliant — adoptable on both sides of the Pacific.
Why it exists
Agentic payments (x402 + stablecoins) turn the payer into code, moving at machine speed, micro-value, high-frequency, with no human in the loop. Existing KYC/AML tooling will fail at scale, and regulation has not yet answered. This framework binds to no single protocol or vendor; it is a neutral convening.
Four principles
Accountability-first
Every machine-initiated payment must trace back to an accountable legal entity.
Defense-in-depth
Layered defenses: agent-side firewall, network-layer screening, settlement-layer compliance.
Protocol-neutral
Adapts to x402 / AP2 / Visa Intelligent Commerce / Mastercard Agent Pay — no single-stack lock-in.
Privacy-proportionate
Only the minimum data compliance requires, with clear cross-border boundaries.
Seven pillars
Identity & Attribution · KYA
Know-Your-Agent. Every paying agent binds to an accountable entity, verifiable by counterparties. The foundation of the framework — and the biggest gap at the open, verifiable layer.
- ·Each agent has a unique, verifiable identity (verifiable credentials / on-chain attestations)
- ·Identity is bound to a KYC'd legal entity
- ·Counterparties can verify attribution and mandate validity before the transaction
Mandate & Limits
A human's grant to a machine is a bounded envelope, not a blank cheque.
- ·Explicit mandate scope (purpose, counterparties, time window)
- ·Per-transaction / daily / cumulative limits; block or escalate on breach
- ·Mandates revocable at any time, effective immediately
Controls & Guardrails
A firewall belongs between the agent and its wallet.
- ·Spending-policy engine: allowlists, blocklists, rule-based interception
- ·Resistance to prompt-injection hijacking; anomaly circuit-breakers
- ·Emergency kill-switch + human escalation for high-risk transactions
Screening & AML
AML at machine speed must be upfront, automated and explainable.
- ·Sanctions / mixer / risk-score screening of counterparty addresses (third-party data)
- ·Travel Rule information passing for agent-to-agent transfers
- ·Typology-based continuous monitoring and red-flag alerts
Auditability & Accountability
When something goes wrong, answer: who authorized it, what the machine did, who is responsible.
- ·Immutable, complete transaction and decision logs
- ·Clear accountability chain (entity → mandate → agent → transaction)
- ·Incident response and recourse process
Privacy & Data Governance
Trustworthy is not surveillance; cross-border data needs clear boundaries.
- ·Data minimization
- ·Explicit jurisdictional and cross-border processing rules
- ·Due process and user recourse
Interoperability & Governance
A standard lives or dies by adoption and shared upkeep.
- ·Identity and mandate credential formats interoperable across major protocols
- ·Maintained by a neutral body, open for public comment
- ·Versioned evolution with a traceable changelog
Framework implementation levels
The three tiers below describe which controls are implemented — a checklist for implementers. They are not the same as the L0–L3 grades in the RAP Compliance Rating, which are assessment grades mapped from the seven-pillar weighted score by one threshold rule. See how rating grades are defined →
Agent attributed + basic limits + sanctions screening. Fits small-value, low-risk flows.
Level 1 plus a spending firewall, Travel Rule, full audit and hijack resistance. Fits commercial platforms.
Level 2 plus continuous typology monitoring, human escalation, incident response and third-party audit. For regulated institutions and cross-border settlement.
v1.1 addendum · Bilateral decision clause
In a responsible agent payment, both the payer and the payee decide before settlement, and both decisions are verifiable and leave a trace. The payer side (allow / review / decline) is covered by the seven pillars; this clause adds the payee side.
Pre-settlement conditions met; settle, and carry the decision id with the settlement.
Final, with reason codes. Re-paying does not change the result.
Not final. requested_fields states what is missing; the payer supplies it and gets a second round, at most two; unanswered past 48 hours becomes decline.
The payee itself is not ready: not registered, not live, or downgraded with unresolved disputes. This is where the registry enforcement ladder exits.
- Every status carries evidence (kind / ref / complete_through) that a third party can open and check.
- Decisions come from rules, not model judgement; the reason-code table is public and every code traces to the registry or the rules page.
- A payee's readiness is set by the registry's four-level ladder; we seize nothing and issue no verdict of guilt.
Governance & participation
Convened by a neutral body (to be established in Singapore), reviewed with issuers, protocol teams, platforms, and experts from compliance and law-enforcement backgrounds; open for public comment, versioned. This is a living document; citations and change requests are welcome.
Conflict-of-interest & neutrality statement: RAP is an open standard — any organization may cite, adopt or implement it for free. OceanAlt is RAP's convener and first implementer / assessor, but not the only one. We also offer commercial compliance products built on RAP, making us a stakeholder in the standard. To manage this conflict: (1) RAP's methodology, rating criteria and conflicts of interest are public and reviewable; (2) any rated party has a right-of-reply to contest or correct; (3) ratings are not skewed by commercial relationships. Once RAP reaches adoption milestones, its standard and rating governance will move to a neutral body independent of OceanAlt's commercial products (to be established in Singapore).
How to cite
OceanAlt. "The Responsible Agentic Payments (RAP) Framework, v1.0." 2026. https://oceanalt.com/en/rapHelp build RAP
Are you an issuer, protocol team, platform, or compliance / security practitioner? We invite you to review, cite, or adopt RAP in your product. To see it run, try the live compliance demo in AI Security Lab.

