Welcome to The Payment Expert weekly podcast, brought to you by SBC Media. Each week we analyse the news driving the global payments industry forward; the innovation, the infrastructure, and everything that has to happen to make it all possible.
Louis Thompsett (00:01.084)
Hello and welcome back to the payment expert podcast, your source for the latest news insights and analysis on the payments industry. I'm Lewis Tompsett, news editor at payment expert and joining me today, I'm delighted to have David Birch, author, advisor and commentator on digital financial services. David's joining us today to discuss security and safety concerns around agentic transactions as they move from concepts to.
David, thanks very much for joining us today.
Dave (00:34.188)
Thanks for inviting me, I appreciate it.
Louis Thompsett (00:48.7)
down a bit there. Okay.
my vocal warmups today. Hello and welcome back to the payment expert podcast, your source for the latest news insights and analysis on the payments industry. I'm Lewis Tompstett, news editor at payment expert and joining me today I'm delighted to have David Birch, author, advisor and commentator on digital financial services. David's joining us today to discuss the security and safety concerns.
around agentic transactions as they move from concepts to pilots. David, thanks for joining us today.
Dave (01:27.566)
Yeah, thanks for inviting me. It's a great topic.
Louis Thompsett (01:30.12)
It is indeed. And as we've seen across the last year and maybe more, two years perhaps, agentic transactions, they're moving into live pilots and there's growing competition in the space too. For listeners watching this arrive and sort of play out in real time, how would you describe what really changes about security and trust once there's an agent in place rather than a person making a particular purchase?
Dave (01:58.671)
Well, I think there's sort of two ways of looking at that really. So one is, I mean, we haven't actually fixed the problem with people yet. I mean, given that fraud is completely out of control, even without us using AI agents, because we lack a proper digital identity infrastructure. I mean, I hate to keep going back to the same point, but it's true. Nobody knows who anybody is online and without some sort of digital identity infrastructure, it's really hard to make progress there. Although, you know, to be fair, you know, some progress is being made.
Because nobody knows who anybody is, a lot of the security is essentially probabilistic. It's, you know, companies looking, putting scores on things. I does this look a bit like Dave? Is it coming from somewhere where Dave might normally log in from? Is it doing things that Dave might normally do? But those are all substitute for asking, actually, is this Dave? And as we edge towards, you know, the European digital identity wallet and various other things,
mobile driving license, so on. The idea that you can be pinged, who are you? Or actually, more importantly for most transactions, what are you? It's getting a bit closer. So not fixed, but on the way. Now you add into that agents. And I'm kind of from the more bullish end of that spectrum. I think a lot of things in payments are actually quite boring. so, I mean, I know I've annoyed people more than once by saying this.
For normal people it's just not that interesting. So as soon as bots will do it for them they'll cheerfully hand it over. I honestly can't be bothered to think, you know, should I pay for this with my Amex and get these rewards or should I pay with my BA card and get some miles or should I pay with my John Lewis cash back card or you blah blah blah. So just pay for this and that's great. So as soon as I don't have to think about it anymore that's fantastic.
But now when a bot shows up and says, you know, I want to buy this pair of shoes or something for Dave and here's the money. There's a couple of extra questions that are in that loop that need to be resolved. So first of all, who is this agent? I mean, is this a real, you know, Martin Lewis money supermarket agent? Is it a real, you know, whatever, Barclays wealth management agent or what is this? Is it a real, as I suspect it will be for most people.
Dave (04:28.941)
is it a real, you know, take that, you know, personal finance agent or whatever and not a North Korean copy or something that's been tampered with or whatever. So the first question is what is this agent? And we need to figure out a way to solve that. And the second thing is what is this agent allowed to do and who is it allowed to do it on behalf of? And to answer questions like that, again, you need an infrastructure.
We're not going to just build a giant database of all of the agents in the world with all of their, you know, code hashes and what they're allowed to do and who's allowed to use them. It's going to be a much more distributed, much more decentralized world than that. So what that means in practice is when an agent shows up, it has to present, for want of a better word, credentials as to, you know, who it is and what it's allowed to do.
in the sort of early coalescing of standards around this sort of thing, like in Google AP2 and so on, you see W3C verifiable credentials as the standardized mechanism for managing these credentials. And that's great. And the fact that the standards exist and there's a slot in there for them is superb. But of course, you still need the framework. So, you know, the bot can turn up.
show me the certificate that says that, you know what, Barclays said that Dave is allowed to access this account or that product or whatever. But how do you know that that came from Barclays? You you need to be able to check the digital signature and to do that, you need a framework where you get certificates from and all this sort of stuff. So, it sort of conceptually, I think people are beginning to.
beginning to sort of share some sort of basic ideas around this and we can sort of see the outlines but it's a long way from being fixed and the interim solutions that people are using you know if you look at like for example some of the big acquirers what they're doing is sort of basically building a database of agents that their merchants can access but and maybe that's a good idea but it seems kind of an interim solution to me ahead of sort of a more
Dave (06:44.621)
you know, a more comprehensive framework.
Louis Thompsett (06:47.469)
Yeah, I know one of the debates around agents at the minute is around, as we've been talking about, the identity of that agent, you know, are they an extension of a person making a purchase? they an extension of the firm running the payment? Or are they, should they be treated from the, I suppose, the merchant side as almost like another member of the team? And where the liability lands when
Dave (06:55.863)
Yeah.
Louis Thompsett (07:13.797)
things go wrong, let's talk of it. I suppose the onus being on the consumer if they've agreed to use an agent to make a purchase and things go right, where does that liability land?
Dave (07:25.581)
mean, you need to ask a lawyer that question rather than me, but I mean, the way it's worked out so far is if I do something stupid with my bank account and send money to, you know, a fake Brad Pitt or something, then basically it's the bank's fault, not mine, because we've constructed a, you know, we've constructed a model which says the banks have to take responsibility for all of this and probably we'll do the same thing because it's just easy.
Louis Thompsett (07:27.463)
Okay.
Dave (07:52.782)
If you're a politician, you've got people complaining to you about their being ripped off all the time, and you don't understand how anything actually works, then the easiest thing to do is to say, we're making the banks problem, which in this case would be catastrophic, of course. So you said about the first issue you raised, I think is really pertinent issue. I don't mean that in patronising way. think you're right to flag that up as the thing. Is the agent simply you? Is it some software acting on your behalf?
Or is it something independent, which has essentially inherited some rights because you've granted them to it? So, and I can see why the merchant's very unhappy about the first case, which is why they don't like, you see them suing the AI companies because if the AI shows up with my username and password and logs in pretending to be me, maybe that's a way of getting things done. But actually it's kind of suboptimal because.
Louis Thompsett (08:37.286)
Mmm.
Dave (08:48.863)
It's accessing a website that was never designed for agents to use. All of the, you know, all of the money that was spent on that website and advertising and nudging and making these easy for consumers to use is all wasted because the agent just comes in.
Dave (09:08.833)
I mean, I saw some interesting experiments a couple of days ago looking at trying to buy something using sort of Google search, using different agents, quite a bit of itself. And it was very clear that what the agents were basically looking at was much too simple. I mean, they were basically looking at price and that's a race to the bottom for merchants. Like if the agent is gonna go to a bunch of different merchants and just find out whichever one's got the cheapest thing.
Louis Thompsett (09:30.213)
Mm.
Dave (09:38.167)
but doesn't take into account all sorts of other things like maybe I want somewhere where it's easy to return because it's around the corner or maybe I want somewhere where I know they've got better customer service or maybe I want somewhere where I know they deliver on time. don't know whatever else it might be. If it's only about price that's sort of very problematic. So we don't want agents pretending to be people. We want agents being agents and showing that they have the appropriate credentials to.
Louis Thompsett (09:56.262)
Mm.
Dave (10:06.7)
If you want to think of it in terms of like a sort of stack, I think you can think of it as being in three layers. You have a kind of demand layer, which is where you work out the customer's intent and you look at the context, mean, to some extent, history, who the customer is, their loyalty schemes, kind of thing. So you've got this kind of demand.
assembly level and then underneath that you've got the discovery and trust layer. So okay I've established that I want to buy this pair of shoes and that in the past I've always bought echoes and I belong to these loyalty schemes and I've got these points. Then the next layer is to find out who's actually supplying those. Do they have them in stock? Do I trust them? Do they know it's acting on behalf of Dave? Do they know all this sort of thing?
And then the third layer, which is where the payments are, is the kind of executional thing. Okay, now we know that everything is in place, go ahead and do the payment. Now, I I've bored people senseless in the past by making the same point, which is, if you know who everybody is in a transaction, the payments are actually not that complicated. So if we get that trust layer right, not only do we make agentic commerce, know, frictionless.
I don't want be, you know, if I send my agent out to look for some, you know, get me some British Airways, get me a frequent flyer miles flight to New York, I don't want to wake up at two o'clock in the morning to log in and see what British Airways seats are being released a year ahead. That's exactly the sort of boring rubbish I expect an AI agent to do for me. But also when it goes ahead and makes the purchase, I don't want to be woken up at two o'clock in the morning to put my thumb on my phone or whatever. I want it to all be seamless. Now, actually,
I think there are reasons for being optimistic about the security of that if we get the identity infrastructure correct. And the reason for that is that I think agents will be much harder to fool and make mistakes than people are. So, you know, I can make a convincing video of Brad Pitt, I mean, people do, and try and persuade you that I'm Brad Pitt, but my agent doesn't look at, does this look a bit like Brad Pitt? Does this sound a bit like?
Dave (12:31.848)
All of that sort of probabilistic stuff. What my agent says is, is this Brad Pitt's digital signature? Okay, you know, who signed this? Under what authority did they sign it? You know, what's the recourse and that kind of thing. So I think you could argue that an agentic trust layer in place actually makes the whole payment process cheaper and simpler. How we get there is fun and complicated and interesting. And I'm loving seeing this.
Louis Thompsett (12:38.448)
Hmm.
Dave (13:00.766)
evolved just as much as everybody else's. But it could take us to a much better place.
Louis Thompsett (13:07.846)
Sure. suppose one of the stepping stones along that path is standardization as well, where there are so many sort of players in the space pushing ahead with the genetic commerce. There needs to be some sort of probably standardization across the board. Obviously, if different card networks, for example, wants to approach it slightly differently, that's probably fine. But there still needs to be that standardization in place across all.
agentic frameworks essentially for that to go forward. Do you think there are any blockers in that? Obviously there's competition in the early phases, but as the market consolidates maybe in a couple of years time, what elements of standardization do you think really need to be at the heart of any kind of universal model essentially?
Dave (13:58.315)
Well, think, I mean, obviously I tend to think, because I'm a horrible payments nerd and I've done this for a long time. I I tend to think of things in a very kind of structured way. So if you go back to those three layers that I told you about earlier on, we need, we need standardize it. So we need standardization at the demand layer. You know, what are you allowed to know about customers and their history? And, obviously you want customers to be in control of what they.
Louis Thompsett (14:03.34)
Hahaha
Louis Thompsett (14:12.005)
Hmm.
Dave (14:24.884)
you know what they tell the agents or what the agents are allowed to know about and this kind of thing. So we want some kind of standardization up there. At the sort of trust layer we need some kind of standardization which you can see elements of it and outlines of, not quite there yet. And then at the payments layer we need standardization again and actually you know Visa master cut the label said well look you know we're already using tokens I mean not AI tokens but payment tokens.
We're already using tokens. We've already got the systems in place. So why don't we use tokens, which I think is, you know, a good interim solution, even if it's not the long-term solution. Of course you see other things going on. Cause for example, last week you saw the open USD consortium being announced and people looking at maybe using stable coins or, whatever else, but if the interim tokens probably like an okay thing, I think for some of the merchants, they would want to use the enhanced
intelligence of the counterparties to drive better solutions from their point of view. If you're going to check out and the merchant says, I mean you can easily imagine this example, right? I go to check out, I present my premium credit card, the merchant says, please Dave, can you just use any other card except that? I don't want to pay a blended 2.9%, whatever it is for. I'll tell you what, use something else and I'll give you some points.
Louis Thompsett (15:27.673)
Hmm.
Dave (15:54.604)
And so, say, well, how about, I don't know, here's my regular MasterCard, how about that? And they say, okay, well, that's not too bad. If you do that, we'll give you some points. But you know what, actually, if you used your debit card, we'd give you a little bit of a discount. If you use stable coins, we'll give you a little bit of a discount and we'll give you some points, or something like that. That would be very annoying for you and me at Retail Point of Sale to go through this negotiation, even if you had some defaults set in place. But actually, it's...
milliseconds for some AIs to have that conversation. you know, I can see why merchants obviously do get annoyed about essentially funding other people's loyalty points. So they would have a preference for, you know, if your agent could do account to account payment and stable coins and cards and, you know, everything else, then, you know, you could have quite a sophisticated discussion there, which would happen very quickly.
Louis Thompsett (16:52.483)
Yeah, totally. I want to pick up on something you mentioned earlier around KYC and obviously how we're probably not fully sorted that yet. If you look at APP fraud, for example, that's sort of still rampant. And then as you move into the know your agent phase, there's inevitably going to be a new sort of any wave of fraud that comes alongside that. As I suppose, agentic frameworks and agentic commerce moves forward.
What do you think really is needed sort of at source or, you know, in the beginning to try and mitigate as much of that as possible, it's still going to happen in instances.
Dave (17:31.308)
I mean, that's, you know, that is a really, I mean, I was actually having this conversation with somebody yesterday using a real example because I was trying to, do you have an open Claw server? You know, everybody went mad a few months ago, it's certainly open Claw. So I have an Amazon web server running open Claw, which I'm just using for like little experiments and things. But you know, in a specific context, I said, well, okay, how are we going to give that?
Louis Thompsett (17:44.804)
Yeah.
Dave (17:59.884)
agent and identity. Now within Amazon, you know, you could imagine that Amazon could give my agent an identity, which would be no, but like, what would that mean outside Amazon? How would people know, you know, and what would it actually imply, you know, the identification that I would pass outside? So, it's easy to draw a cloud on a whiteboard and say, well, give an agent an identity. But when you drop down one level,
Like how exactly are you going to do this? It gets a bit complicated. And there's a very specific issue, which I'm very reactionary about, which is to some extent giving an agent identity means it has to have access to private keys ultimately. And obviously for a variety of reasons, we prefer to see keys stored in secure hardware, lessons that we've learned from the past.
Louis Thompsett (18:45.764)
Hmm.
Dave (18:56.447)
That kind of means in this context, cloud HSMs, hardware security modules, or some sort of trusted execution environment, and services, remote secure elements as people talk about them. But either way, there's got to be something in the cloud where the agents can store and have access to their keys.
And actually that's really a very... quite how that's going to work out I'm not sure, but because I'm kind of old school and think don't try and do it without secure hardware I think that's the way it's going to go. So you could imagine you've got these keys in secure hardware accessible through the cloud, so your agent can demonstrate its identity essentially by demonstrating it has access to those keys and that would...
Louis Thompsett (19:45.189)
Hmm.
Dave (19:46.399)
That would I think work.
Louis Thompsett (19:49.283)
Yeah, totally. Great stuff again, David. We're nearly out of time, but I suppose I'll leave on this question. know it goes so quickly. I'll leave you on this. If there's one thing you'd like to see sort of entrenched or focus upon perhaps on the identity side, on the kind of anti-fraud side, but before there is any kind of standardization to these agentic commerce models, what's the main takeaway you'd like to...
Dave (19:54.141)
well, that's really interesting questions.
Louis Thompsett (20:19.426)
I suppose, leave our listeners with that that should really be enforced.
Dave (20:22.086)
Well, my current favorite thing is many years ago, I worked on a I was on a working group. It's a long time ago for a financial services passport. And the idea was, because it takes forever for governments to sort these things out, and they might not be interoperable and blah, blah, blah. Wouldn't it kind of just make sense for the banks to have their own ID system and give you
Louis Thompsett (20:31.204)
Hmm.
Dave (20:50.442)
a passport essentially for access to that. So you didn't have to keep showing your gas bill to everybody every time you log into things. And I'm sort of wondering if we don't need to go back to that kind of idea, because although we haven't fixed the ID problem, it's kind of interesting that the pressure to fix it now actually comes from the agentic space. It isn't that banks and the government and retailers all of a sudden change, they'll actually...
we probably actually could use a proper digital identity system instead of muggling through. The pressure to actually do something about it comes from the agentic side. So maybe the thing to think about rather than kind of universal boil the ocean solutions is, you know, couldn't the banks get together and provide some kind of interoperable global solution in this space? And yeah, I think that's kind of what we're thinking about. Maybe it could go alongside OpenUSD.
Louis Thompsett (21:46.082)
Hmm, yeah, it's worth keeping an eye on definitely. Well, David, thank you. Thank you very much for coming and joining us today. Unfortunately, for the listeners, that's all we do have time for though. If you're not already subscribed to the payment expert podcast, please make sure to subscribe wherever you do get your podcasts with plenty more insight and analysis coming over the weeks and months ahead. And for the latest news as it happens, head over to paymentexpert.com. We'll see you all next time.