Most financial rules were written for a human who can confirm or dispute a payment. A human can be asked what they intended, can notice something unusual, and can stop. Software agents do none of these things in the same way. They act continuously, within limits, and without a memory of a conversation in a regulator's file. That mismatch is the regulator's dilemma, and it is not solved by stricter rules alone.

The assumption built into current rules

Existing frameworks assume a person behind each transaction: someone who can confirm a payment, dispute one, and explain intent after the fact. When an agent initiates operations at machine speed, the dispute window, the question of intent, and the audit trail all need to be reconstructed from somewhere else.

What an agent unit looks like

SUPA's agentic model answers this with five layers inside each unit:

  1. An identified principal — the person or company legally standing behind every operation.
  2. A revocable agent identity — an agent owns nothing and is never anonymous.
  3. Policy — limits, approved counterparties and approval thresholds applied below the model, where the agent cannot argue with it.
  4. Partner rails — accounts, FX, payments, cards and acquiring behind one interface.
  5. A ledger with evidence — every operation traceable to principal, agent and policy version.

What changes for supervision

Two things follow. First, an over-limit operation becomes a human approval request instead of a rejection, which gives a named person a moment to decide. Second, because every operation is attributed to a principal and a policy version, supervision can ask "who and under what rule" rather than "which script".

The dilemma does not disappear. It becomes documentable — and documentation is what turns an unfamiliar actor into one a supervisor can assess on the usual terms: who is behind it, what it may do, and where the record lives.

This article is general information, not legal, tax or financial advice.

In short

  • Current rules assume a human who can confirm or dispute a payment.
  • Agents act continuously and are never anonymous and never owners.
  • Policy sits below the model; over-limit operations become approval requests.
  • The ledger ties every operation to principal, agent and policy version.

Explore the agent layer at /ai/.