Community Discussion · Tracks

AI Wallet Agents: Payments Start Making Decisions for Users

Sister QingSister QingSep 112026/09/11 76 views

I noticed a detail: Alipay advanced AI payments from "payable" to "trustworthy" at the Bund Summit this time, launching an AI Wallet Agent to help individuals manage every AI payment. The news also mentioned VibePay, SkillPay, MachinePay, as well as AI Subscription Purchases, AI Snatching, and AI Booking. Agents are being equipped with an ID card, a wallet, and an authorization ledger.

Over the past four weeks, I've been building agent demos in the AI Lab. After hitting pitfalls, I feel the difficulty lies in boundaries. I had one agent look up info, another summarize, and then let it test a certain API. During the days when I was configuring the API key, I repeatedly asked myself: How much can it spend? Can it touch production accounts? Who bears the charge if the task fails? At the time, I thought machine payments were only suitable for developer tools or internal demos because wallet custody, risk control, and dispute resolution were immature. My thinking has changed now, but not necessarily completely.

Alipay data shows that over the last 5 months, agent-driven purchasing tasks grew 7-fold, and users' average monthly payment frequency grew 3-fold.

In the past, payment was the "cashier action" at the final step of a transaction. Now, it needs to permeate the agent's identity, intent, authorization, execution, and responsibility.

Previously, payment required human confirmation. Now, it might become a person saying, "Book it for me, buy if it's below this price." The agent checks conditions, places orders, and deducts funds itself. Payment thus changes from a beep to a series of records, logged from intent generation through task completion. If the AI Wallet Agent only does bookkeeping, its value is mediocre. To achieve trustworthy payment, it must answer four questions: Who authorized, how much was authorized, did it execute, and who is responsible if something goes wrong.

In my testing, the place where agents most easily cause issues is "buying." Give it a goal, and it might bypass the boundaries you wanted to keep simple in order to achieve that goal. For example, "AI Snatching" sets a target price, which seems clear. But price, inventory, coupons, delivery time, and refund rules all affect whether it's worth buying. If the model only looks at the target price, it easily buys results that fit the numbers but not the human context. "AI Subscription" is the same; ordering goods on a fixed cycle saves hassle, but the other side is continuous deductions. Users think they're authorizing a one-time purchase during setup, but two months later discover it's still auto-renewing.

So I'm particularly concerned with the phrase "one explicit authorization, complete the task as agreed." The Alipay Agent Payment page mentions that users pre-confirm task scope, amount, and validity period; the agent only executes payment when authorization conditions are met, and continuously syncs execution status. This direction is correct. For machine payments to reach ordinary people, it can't rely solely on model intelligence; it needs to be queryable, stoppable, and explainable. Authorizing tasks, amounts, and deadlines item-by-item sounds like drawing a circle around the agent. Inside the circle, it runs; outside, it asks. Status must be queryable anytime to give users an exit for regret. Otherwise, "AI Booking" easily becomes "AI booking behind your back."

However, I'm not that optimistic. Payment platforms have real-name verification, accounts, and risk control—this is their biggest advantage compared to protocols like x402. I previously said machine payment protocols like Paygate are more suitable for developers and internal demos; I still hold half of that judgment. Protocols can solve how machines pay each other, but they can't solve how ordinary people confidently let machines pay for them. The latter requires custody, limits, anomaly alerts, dispute resolution, and merchant-side recognition of agents as legitimate participants. Alipay brought merchants into this too; terms like Agentic Commerce Infrastructure, Treasure Box, Skills, and MCP seem developer-focused, but they are actually turning goods and services into units callable by agents.

Another interesting detail. Alipay partnered with AutoNavi (Gaode) Momentum to apply AI payments to embodied robots; robot dogs can run errands and complete payments according to instructions, netizens jokingly call it "Dog-leg Pay." The payment subject expands from mobile apps to glasses, earphones, and robot dogs, making device identity complex. Iris recognition, voice payment, and robot dog proxy payments reduce screen taps and confirmation dialogs. Convenience and loss of control are often separated by just one authorization page.

I think the focus of future competition is who makes decisions for humans. The AI Wallet Agent could become an entry point, managing money, authorizations, and agent behavior. For individuals, it's like a butler; for merchants, it's like a channel; for platforms, it's like a ledger. The question is, will this butler be too diligent? Before the responsibility chain is established, I'd advise novices to set small authorization amounts, short validity periods, and rigid task scopes, and don't let it touch important accounts yet.

This is certainly not just Alipay's issue. UnionPay is also positioning for new entry points in the AI era, indicating that payment institutions see the same trend: agents are becoming new commercial participants. Previously, humans sought services; now, it might be agents seeking agents. When money flows in between, human intent is compressed into a single instruction, and the risks behind that instruction do not automatically disappear.

From humans using AI, to humans delegating to AI, to AI collaborating with AI.

This sentence flows well, but each step shifts the type of risk. Using AI, errors can be corrected. Delegating to AI, errors may already have incurred costs. AI-to-AI collaboration, errors may happen where you cannot see. Once AI Wallet Agents become widespread, when a user first discovers it acting on its own initiative, the platform should treat it as an incident record, not just a product highlight.

0 replies

?
Ctrl + Enter to reply
No replies yet — be the first to share your thoughts