Before AGI Talk, Clarify How AI Agents Spend Money
This feels a bit like humanoid robots entering factories. First, look at the joint torque density and emergency stop circuits; then see how smart the model is. Agent commercialization has reached this stage too. Whether it can call payments, place orders, or change configurations depends on who authorizes it, what permissions it has, and whether actions are traceable if things go wrong.
At the AI Payment Forum during the Bund Summit on September 11, Ant Group released APASS, a trust infrastructure for agentic commerce based on KYA (Know Your Agent). It revolves around identity registration, continuous verification, intent security, and trusted evidence preservation, answering "Who is the Agent, whom does it represent, what is it allowed to do, and are its behaviors trustworthy?"
I previously discussed Agents sending WeChat messages to each other; the core difficulty lies in verifiable identity authorization and state synchronization. An Agent sending messages, checking orders, or making payments on behalf of a user is different from it merely claiming it can do so. Without key management, even the strongest model is just driving someone else's car with their keys randomly.
The value of APASS seems to be about separating these two issues. The identity chain solves who you are and whom you represent; the behavior chain solves what you did and whether it was permitted. This is especially needed in payment scenarios. Once money leaves, the cost of error is much higher than chat hallucinations.
From an engineering perspective, for this system to land, it must meet at least a few criteria. Authorization needs to be granular down to specific actions and limits, not just a generic "callable" permission. Identity verification must be continuous, not valid for life after one-time registration. Logs must be tamper-proof but shouldn't expose all privacy. Keys need lifecycle management: revocation, rotation, and accountability.
As a moderator for robotics, I view this more through a hardware lens. When humanoid robots eventually enter homes or factories, besides motion control, they will also need to invoke services. For example, if a sensor breaks, it needs to order spare parts, schedule repairs, and request access control. No step here should be left entirely to the model's discretion.
Over the past two weeks, I've been running embodied intelligence simulations, and the most obvious issue is fragile state synchronization. If a task is interrupted and the Agent doesn't know the current permissions, budget, or device status, it might repeat execution. In reality, this could mean duplicate orders, duplicate door openings, or duplicate charges. If APASS works well, it can pull execution actions from the control layer up to an auditable authorization layer.
However, don't overpromise. Many humanoid robot scenarios are still early-stage. Torque density, battery life, force control, and safety redundancy aren't sufficient to support free decision-making yet. If physical emergency stops aren't clean enough, talking about fully automated ordering and payments is easy pie-in-the-sky thinking. APASS looks more like hanging digital-world keys first; the responsibility chain in the physical world still needs to be patched by hardware, insurance, and operations.
Although I haven't seen public spec sheets, my first reaction is whether the interfaces will be heavy. Payments, identity, risk control, and evidence preservation—adding verification at every layer increases latency. In robot control, safety checks often compete for resources with task execution. Calling services via Agents is similar; if every action requires multi-hop verification, high-frequency scenarios might become unusable.
Another issue is cross-platform interoperability. If APASS only works well within the Ant ecosystem, it's more of a payment ecosystem hardening than an industry-wide trust foundation. Future Agents may span WeChat, Alipay, cloud providers, model APIs, and enterprise systems. Whether identities can migrate, authorizations can be revoked, and behavioral evidence can be verified by third parties determines if it's truly infrastructure.
These days, while testing WeChat's Xiao Wei, I'm more cautious about Agents operating on behalf of users. The lighter the entry point, the clearer the backend permissions must be. Behind a chat interface lie payments, files, and device controls. Without fine-grained authorization, risks will be perceived by users as AI acting recklessly, and system safeguards will seem insufficient.
So my judgment on APASS is pragmatic. The direction is right. As Agent commercialization enters deep waters, the trust chain is often the first bottleneck. Whether early adopters are willing to hand over critical actions to it, and whether we can clearly identify who authorized, who executed, who managed risk, and who compensates when problems occur—that's the key.
Next, watch the production ramp-up data. Interface docs, SDKs, case studies, and failure drills are what determine if it's actually usable.
Physix Frontier