Programmable money promises that a payment can carry conditions: who may receive it, under what circumstances, up to what amount. When an AI agent is the one executing payments, those conditions stop being a convenience and become a control. The question is where the conditions live, and whether the agent can argue with them.
Conditions belong below the model
The design choice that matters most is placement. In SUPA's agent model, policy — limits, approved counterparties and approval thresholds — is applied below the model, where the agent cannot argue with it. An agent may decide how to route an operation; it does not get to renegotiate the boundary of what it is allowed to do. If an operation exceeds its limits, it becomes a human approval request rather than a rejection, so the decision goes to a person rather than vanishing.
The agent unit, in five layers
- An identified principal: the person or company legally standing behind every operation.
- A revocable agent identity: the agent owns nothing and is never anonymous.
- Policy: limits, approved counterparties and approval thresholds, applied below the model.
- Partner rails: accounts, FX, payments, cards and acquiring behind one interface.
- A ledger with evidence: every operation traceable to principal, agent and policy version.
Those layers are what make programmable money safe to delegate. The conditions are not suggestions in a prompt; they are constraints the agent cannot reach.
What stays human
Validation happens once per operation, in a single compliance function: reliance confirmation, sanctions screening, agent mandate, client-profile fit and network anomaly signals. Where an operation crosses a threshold, a person decides. Routing — by cost, settlement time, reliability and regulatory fit — can remain automated, because it works inside a boundary that a human has already set.
In short
- Programmable conditions should sit below the model, not inside it.
- An agent identity should be revocable and never anonymous.
- Limits, counterparties and thresholds belong in policy.
- Over-limit operations should escalate to a human.
- Every operation should be traceable to a principal and a policy version.
For the agent route, see /ai/