should an ai agent keep its spending authority after a software update?
this is going to become a real question as agents start controlling meaningful budgets. say a company deploys an agent and authorizes it to spend up to $10,000 per month. the wallet is scoped, policies are defined, and the agent runs for a while without issue.
then the agent changes; a new model is deployed. its system prompt is updated. new tools are added. its planning logic changes. perhaps a new sub-agent is introduced into the workflow. from the payment system's perspective, very little may have changed. the same wallet still holds the same key and the same spending policy. from a governance perspective, quite a lot has changed. the software deciding when and where to spend the money is now different.
this distinction is starting to show up in standards work. a recent IETF draft on attested payment authorization argues that authenticating a key does not establish that the software using that key is the software that was originally reviewed and approved.
that suggests an interesting direction for agent wallets. spending authority could eventually be bound to a specific agent deployment: its identity, policy, software version and approved runtime. material changes to the agent could trigger re-attestation or a new authorization. we already treat software changes as security events. once software can spend money autonomously, some of them may need to become financial authorization events too.