Expressible, Advisory, or Unenforceable: A Conformance Analysis of Delegated Financial Authority in Deployed Agent-Payment Protocols
Payment networks and model providers deployed agent-authorization infrastructure at speed during 2025 and 2026: signed mandates, agent-bound tokens, and machine-payable settlement rails, each promising that an autonomous agent transacts only within authority its principal granted. This paper asks a prior question to whether agents obey such authority: whether the deployed protocols can express it at all. We define an authorization envelope of eight fields drawn from the delegated-authority literature and from the control primitives of existing payment rails, comprising a per-transaction ceiling, a cumulative ceiling, a merchant set, a category set, required product attributes, a validity window, a substitution policy and an amount-valued confirmation threshold. We then code eight deployed agent-payment protocols against these fields using an auditable document-analysis protocol, classifying each field as expressible, advisory or absent according to whether a typed schema field exists and whether any identified party validates it. Three fields are unsupported almost everywhere: substitution policy, general product attributes, and the confirmation threshold. Cumulative ceilings are enforceable only where some party accumulates state across transactions, which five of the ten schemes examined do and the remainder do not. Most consequentially, virtual-card controls already enforce cumulative caps and merchant-category scope, and open-banking variable recurring payments enforce cumulative caps, that the new agent protocols omit, so agent authorization is in specific respects a regression against rails that preceded it. We release the coding protocol and evidence table, and retain version-pinned specification snapshots for audit.