Can You Trust an AI Agent to Buy Things for You?
Stripe is building the trust and fraud infrastructure that lets AI agents spend money on your behalf. Here's how it works and where it breaks.

What’s the actual answer?
Not for everything, and not yet for anything expensive. AI agents can already be trusted with small, bounded purchases (a coffee order, a subscription renewal within a set budget) because companies like Stripe have built identity, payment, and fraud infrastructure specifically for agents acting on a person’s behalf. Trusting an agent to buy a couch or sign up for a new subscription unsupervised is a different, harder problem that the infrastructure hasn’t fully solved yet.
TL;DR
- Stripe is building payment infrastructure for agents as economic actors, not just for the businesses that sell to them, treating agents as buyers who need their own identity and trust signals.
- Stripe’s consumer wallet Link, used by roughly 300 million consumers, has expanded from a checkout tool into something agents can spend through on a person’s behalf, tying purchases back to a verified identity.
- Most serious fraud against AI companies happens before checkout, not during it, which is why Stripe had to rebuild fraud detection around account and usage behavior instead of just transaction scoring.
- The new target for fraudsters is tokens, not money, since inference is expensive and free trials or usage credits have become valuable enough to steal outright.
- Stripe’s work with Cursor showed the shift firsthand, when free-trial abuse and unpaid overages exposed a gap that transaction-level fraud tools like Radar weren’t built to catch.
- Cross-network data lets Stripe flag risky accounts before they transact, because a large share of AI companies and dev platforms run their payments through the same infrastructure, making bad actors visible across services.
- Agent negotiation behavior could quietly erode consumer surplus, since agents can haggle indefinitely in a way no human shopper would, which changes the economics of online selling.
Remy doesn't build the plumbing. It inherits it.
Other agents wire up auth, databases, models, and integrations from scratch every time you ask them to build something.
Remy ships with all of it from MindStudio — so every cycle goes into the app you actually want.
Why does buying and selling need to change for AI agents?
Most people already use AI agents daily without thinking of them as economic actors. They draft emails, summarize documents, or assemble a presentation. What they don’t yet do, for most people, is spend money unsupervised.
That’s starting to shift. Stripe executive Emily Glassberg Sasson, who leads data and agent infrastructure at the company, describes a period of sharp inflection in AI-driven commerce. New business incorporations through Stripe’s Atlas platform were doubling year over year. Overall new business signups on Stripe were up 50% year on year. And crucially, newer cohorts of businesses were monetizing faster than prior ones, with the 2026 cohort monetizing about 50% more on a median basis than the cohort before it.
One detail stands out as a signal of agents acting as actual users of infrastructure, not just topics of conversation: Stripe’s command-line interface, which had existed quietly for roughly seven years with a small niche developer base, suddenly spiked in usage with no product changes on Stripe’s end. The explanation was that coding agents had started finding and using it directly. Agents were no longer just helping humans use software. They were becoming users of financial infrastructure themselves.
That change forces a new question. If agents are going to act as buyers, and businesses are going to sell to agents instead of just humans, who vouches for either side?
How does Stripe let an AI agent spend money on your behalf?
Stripe’s answer runs largely through Link, its consumer wallet product. Link began as a checkout tool used by around 300 million consumers to save payment details and speed up purchases. It has since become something closer to a wallet that agents can draw from when spending for a person.
The identity layer matters here. When a purchase runs through Link, the buyer’s identity stays attached to the transaction, so the seller on the other end isn’t dealing with an anonymous automated process. Stripe layers trust and abuse controls on top of that connection, giving both sides something to check against: the person authorizing the agent’s spending gets protections and controls, and the business receiving the sale gets access to many of the same fraud and trust signals Stripe has historically used to vet individual human buyers.
That’s the mechanism behind the coffee-purchase example: a bounded, low-stakes, verifiable transaction where identity, budget, and merchant trust all line up. It’s a much smaller problem than letting an agent independently choose and purchase a couch, or commit you to a new recurring subscription, where the stakes and the potential for a bad decision are higher and the guardrails are thinner.
Why is most agent fraud happening before checkout?
This is one of the more counterintuitive points to come out of Stripe’s work with AI companies. Traditional fraud prevention, including Stripe’s own Radar product, was built around scoring individual transactions: is this specific payment likely to be fraudulent. That model assumes the valuable thing being protected is the transaction itself.
Seven tools to build an app. Or just Remy.
Editor, preview, AI agents, deploy — all in one tab. Nothing to install.
For AI companies, the valuable thing is often something else entirely: compute. Sasson describes tokens as “not yet a currency” but already a very valuable asset, and fraudsters have adapted accordingly. Instead of stealing money at the point of purchase, they’re stealing free trial credits, spinning up disposable accounts, or racking up usage they never intend to pay for. None of that shows up as a fraudulent transaction, because there often isn’t a transaction at all until the fraud has already happened.
Cursor, the AI coding tool, ran into exactly this problem. According to Sasson, Cursor’s team told Stripe that Radar was “world class” but wasn’t solving their actual problem, because the abuse was happening pre-transaction: fraudulent signups harvesting free credits, or usage that accumulated without ever converting to a paid bill. For a traditional SaaS company, this kind of abuse would barely register, since the marginal cost of serving another free user is close to zero. For an AI company running expensive inference, unpaid usage is a direct financial hit.
How did Stripe fix this for AI companies?
The shift Stripe made was moving from scoring transactions to scoring accounts and behavior before a transaction ever occurs. Instead of asking “is this payment suspicious,” the new approach asks “is this account likely to be abusive,” evaluated at the moment of signup, at the start of a free trial, or as usage starts climbing toward an overage.
What made this possible at speed was Stripe’s cross-network visibility. Stripe processes a very large share of global payment volume overall, but more relevant here is its concentration inside the AI economy specifically: Sasson cites Stripe’s presence across a large majority of the Forbes AI 50 list, plus deep integration with AI-adjacent developer platforms like Vercel, Replit, and Manus. Because so many AI companies and the tools built on top of them run through the same payment infrastructure, Stripe can spot when the same bad actor is hitting multiple services, something no single company could see on its own.
For Cursor, this reportedly went from problem statement to a working API in days, without a formal product spec, because Stripe had the underlying network data already and just needed to expose it in a new way. That capability then scaled out to other AI companies, most of which now use Stripe not just for payments but for billing, tax, revenue recognition, and fraud detection together, because they want a single real-time view of who’s buying, who’s churning, who has credit risk, and who’s likely committing fraud.
Is trusting an AI agent with money actually a good idea right now?
It depends heavily on scope. The infrastructure described here supports narrow, budgeted, identity-linked purchases reasonably well: an agent buying a coffee, managing a small recurring cost, or operating within a hard spending limit tied to your verified identity through something like Link. That’s a bounded problem with existing fraud and identity tooling wrapped around it.
- ✕a coding agent
- ✕no-code
- ✕vibe coding
- ✕a faster Cursor
The one that tells the coding agents what to build.
It’s a different story for higher-stakes or judgment-heavy purchases, like a big-ticket item or a new subscription commitment. Those require the agent to make a qualitative decision, not just execute an authorized transaction, and that’s a much less mature part of the trust stack. There’s also a subtler risk worth watching: agents can negotiate relentlessly in a way humans don’t bother to, going back and forth indefinitely to get a better price. That behavior could shift bargaining dynamics between buyers and sellers online in ways that erode the kind of pricing slack (consumer surplus) that currently benefits shoppers who don’t have the patience to haggle forever.
Frequently Asked Questions
What is Stripe Link and how does it relate to AI agents?
Link is Stripe’s consumer payment wallet, used by roughly 300 million people to store payment details for faster checkout. It has expanded to support agents spending on a person’s behalf, keeping the buyer’s identity attached to the purchase so sellers know who is ultimately behind the transaction.
Why do fraudsters target AI tokens instead of money?
Inference and compute costs are expensive for AI companies, making usage credits and free-trial tokens valuable assets in their own right. Fraudsters exploit this by creating accounts to harvest free credits or run up usage they never pay for, rather than attacking payment transactions directly.
How is fraud detection different for AI companies compared to traditional software?
Traditional fraud tools score individual transactions for suspicious activity. AI companies need to catch abuse earlier, at signup or during free trial usage, because the damage (stolen compute) often happens before any transaction takes place.
Can an AI agent safely buy expensive items on its own?
Not reliably yet. Current trust infrastructure supports small, budgeted, identity-verified purchases well, but higher-stakes decisions like big purchases or new subscription commitments require more judgment than current agent-safety tooling reliably provides.
What role does cross-network data play in stopping agent-related fraud?
Because many AI companies and developer platforms process payments through the same infrastructure, patterns of abuse can be spotted across multiple services at once, rather than being invisible until they cause damage at each company individually.
