AI Agents Can Spend Money, But Who Are They Really?

AI systems are moving into places built for people: shopping sites, financial services, business software, and payment networks. The problem is that many of those systems still ask a basic question they cannot answer cleanly: who, exactly, is on the other side?
A recent test showed the gap between an AI agent’s ability to act and its ability to prove identity. An agent built on Claude Opus 4.7 received a $5,000 stake, an internet connection, and four days to make as much money as possible. It made nothing after CAPTCHA challenges and an identity check similar to the KYC process used to open a bank account stalled its attempts.
When identity checks stop working
The result was not a simple victory for identity verification. Other agents found a workaround and processed more than 100 million payments over Coinbase’s x402 protocol on the Base network by early 2026. Every payment settled in stablecoins, and none touched a bank.
That detail exposes a legal and technical gap. An AI agent cannot be the legal owner of a bank account, yet an agent can still take part in large payment flows when a system lets it operate through another path. The money can move, but the usual assumptions about account ownership and human control no longer fit.
The same problem is spreading beyond payments. A session can clear signals tied to a device, IP address, and verification challenge, but those checks increasingly prove nothing about the actual user. They show that a session passed a set of tests. They do not show whether a person or an automated system controls it.
That distinction matters because the number of automated systems is rising fast. Forty percent of enterprise applications are projected to ship with task-specific AI agents by the end of 2026, up from under 5% in 2025. At the same time, 99% of organizations have adopted AI agents, and 40% of those agents already hold access to organizational data.
Commerce is preparing for agents without understanding them
Shoppers are already part of this shift. Forty-five percent use AI for part of a purchase, which means an agent may help select a product, compare options, or take another step in the buying process. Merchants can see the change, but many are not ready to support it.
Ninety-five percent of merchants see AI agent traffic on their sites, while only 20% have product catalogs that a machine can read. That leaves a basic mismatch between demand and infrastructure: agents are arriving at online stores, but most product information is not prepared for them.
A machine-readable catalog is only one piece of the problem. A merchant also needs to know whether an automated visitor is browsing for a person, making a purchase with permission, or acting on its own. The existing session checks do not answer that question when an agent can pass the same device, IP, and verification tests as a human.
The risk is not limited to shoppers or merchants. Organizations now manage far more machine identities than human identities. The ratio has reached 109 to 1, up from 82 to 1 a year earlier, and 77% of organizations expect that ratio to keep climbing.
The identity system is becoming machine-sized
Those figures change the shape of access control. A company may have a small number of human employees but a much larger set of agents, software services, and other machine identities. When 40% of those agents can access organizational data, the question is no longer only whether a user has passed verification. It is whether each machine identity has a clear owner and a defined reason to act.
The growth of shared tools adds another layer. The open MCP standard listed more than 6,400 registered servers by February 2026, reaching that milestone in just over a year since its 2024 release. Each new connection gives automated systems more ways to interact with services, data, and payment systems.
That does not make every AI agent dangerous, and it does not make every human session trustworthy. It does show why a single verification event cannot carry the full burden of identity. A passed challenge may confirm that a connection met certain conditions, but it cannot establish who owns the action or where responsibility belongs.
The central problem is simple to state: the session is not the customer. AI agents can search, shop, connect to services, and move stablecoins, but the systems around them still need a way to separate human direction from machine action. Until that happens, identity checks may keep proving that something passed the test without proving who—or what—actually acted.
Based on




