Podcast episodes

Episode 42: Economies of machines — tokenization for agentic autonomous finance

We are entering the era of agentic autonomous finance, where AI agents are transitioning from simple digital assistants to active financial participants. As these agents begin to negotiate, transact and manage complex workflows independently, the financial system faces a critical shift in how it handles identity, trust and control. Traditional credential-based models and manual approval chains are no longer sufficient for the high-velocity, machine-to-machine (M2M) commerce of the future.

This panel brings together global leaders in payments, banking and autonomous systems to explore the "next frontier" of finance. We will discuss how tokenized assets, cryptographic trust and agent-aware payment rails will build the secure foundation required for machines to safely participate in the economy and how Canadian institutions and regulators can prepare for this autonomous shift.

Guests:

  • Aviva Klein, Independent Consultant

  • Nate Soffio, Head, Reusable & Agentic Identity Products, Prove

  • David Tax, Senior Manager, Payments Strategy & Innovation, TD Bank Group

  • Mike Ward, CEO, Mica

Moderator:

  • Michelle Beyo, CEO & Founder, Finavator

Share icon
 

ABOUT THE PAYPOD

The PayPod is Payments Canada’s multi-episode podcast which explores the trends and topics influencing payments in Canada and around the world. Hear Elizabeth Dempsey, Manager, Event Strategy and Engagement at Payments Canada and host of The PayPod, interview leading experts and respected thought leaders about the changing payment landscape, the needs of Canadians and the future of modern payments.

WHERE TO LISTEN

 

Spotify logo
Apple podcast logo

 

 

 

 

 

Transcript of the recording

Elizabeth (Liz) Dempsey:
Welcome back to The SUMMIT Summer Series, a special presentation by The PayPod, the podcast from Payments Canada that explores the trends and topics influencing payments in Canada and around the world.

I'm your host, Liz Dempsey.

Today, we are bringing you a panel from the breakout stages at The 2026 SUMMIT on agentic finance. The session, entitled, "Economies of machines: tokenization for agentic autonomous finance” talks about the new era we are entering, where AI agents are transitioning from simple digital assistants to active financial participants. 

But as these agents begin to negotiate, transact and manage complex workflows independently, our financial system faces a critical shift in how it handles identity, trust and control.

In this episode, we join moderator Michelle Beyo from Finavator, as she guides an expert panel featuring consultant Aviva Klein, Nate Soffio from Prove, David Tax from TD Bank Group and Mike Ward from Mica. 

Together, they explore how tokenized assets, cryptographic trust and agent-aware payment rails will build the secure foundation for machines to safely participate in the economy and how Canadian institutions and regulators can prepare for this autonomous shift.

Enjoy the conversation. Here’s Michelle Beyo!

Michelle Beyo
Thank you for joining us this afternoon. Really excited about this panel because I really think we need to dig into Agentic finance. It's coming at us faster than we can breathe. I've definitely been in the ecosystem through many innovations. I was actually in online shopping in two thousand and seven when one to three per cent of people were shopping online. And I remember people being nervous to shop online or at least fully shop online, they might put something on hold, but they would still go pick it up in store. And I think of this shift, the first time I heard of Agentic Finance was at Money 2020 last June on a prep call in April. And we were talking about trust being the new currency. And someone on the call said agentic finance. And I said, sorry, I'm pretty. I've met a lot of conferences. I'm pretty attuned to what's happening, but it's coming at us like from that moment to where we are today. In the last six weeks alone, the amount of updates and news across the ecosystem from Amex, all the way to Worldpay and back to Plaid. And like anthropic, I think there's just so much to take in that I'm happy that we're sitting here to digest and give some insight to what's truly happening in agentic finance, what's real, what's hype and what do we need to focus on to get there properly? 

Because I do think whether we are there right now or we are running there, we all need to work together to get there properly to ensure consumers are protected and getting the innovation part of this whole ecosystem play. 

So I think when we're thinking about the transactions, what are the transactions going to be? And how are we going to ensure trust liability and consumer protection. So a lot to cover in an hour. I always love to kick off my panels by having my panelists introduce themselves so that you can get to know them a little bit. We have a very different perspective across this, this group of panelists. And I'd love it if you, when you introduce yourself, tell us the one thing that has you believing that agentic finance or agentic commerce is coming or is here. And I'll start with you, Nate. 

Nate Soffio:
Hi, everyone. Thanks for coming out. Nate Soffio. I head up new product development at a company called Prove based in New York. I'm focusing my efforts specifically on reusable identity and identity ecosystems, which also includes how we do authentication authorization and verification for agentic payments. 

So a lot of my day to day is either spent with some of the working groups and standards groups that are tackling these things or otherwise building stuff that solves some of the problems that we're going to tackle or try to tackle today. I joined Prove at the beginning of twenty twenty five when they bought my company, Portable, which was an identity wallet company that I had pushed out into market starting in 2022. As for what has got me excited. Well, I haven't really been able to make a lot of purchases yet, but I think one thing I am keeping my eye on is the fact that contributors to the standards, bodies and working groups are moving way faster than I've seen them move before. So as an example, there's two new Fido working groups that have spun up both within the past quarter. One is a technical working group for payments, agentic payments specifically. And now there's a kind of a flip side of the coin working group as well for agentic authentication and agentic authorization specifically. 

Now, it's one thing to say Fido has spun up a bunch of new working groups. They do that all the time. That's fine. The thing that's got me particularly excited to answer your question, Michelle, is the cooperation we're seeing in these working groups across payments. So the rails, the PSPs, the card networks, traditional authentication and identity identity verification providers like prove and also the large, large companies responsible for internet infrastructure like Cloudflare. All three of those types of companies are taking part in both of these groups, because we realized we can't just kind of transpose one to one human frameworks for trust onto agents. We have to think about the payment, the identity and the internet pathing all at the same time. And that's a pretty big thing to realize this early in the game. 

Michelle Beyo:
I love that that's your takeaway, because I do think Fido has been a part of so many different working groups, but the fact that everyone's at the table having the discussion is so important for us to get there. Thank you for sharing that, Nate. Aviva?

Aviva Klein:
Thank you Michel. So my name is Aviva Klein. I'm an independent consultant. I have many years of experience working at the intersection of emerging technology payments and safety and security. I work with my clients to bring innovative and safe and secure payment solutions to market. It's pretty straightforward. My last role was the VP of Payments at Constellation Software, where I built a number of payment programs and really helped midsize businesses become more efficient in the back office. And prior to that, I had a very long and exciting career at Mastercard, working in all sorts of different areas across commercial payments, digital payments, safety and security, cybersecurity and everything in between. 

For me, when you asked like, what kind of agentic finance is happening now? What are you seeing similar with Nate? I'm not seeing a lot, that's for sure. I think we know intellectually that there is, you know, agents working at the infrastructure layer from a fraud perspective. I personally haven't interacted with any agentic finance, but just sort of reading, you know, as we all do around this industry. I think, you know, what I'm really seeing the most of is really in the commercial space. And a lot of these spend management platforms who are, you know, going through the procure to pay cycle and really, you know, not just automating it, but taking control of that and going everywhere, you know, doing everything from approving the invoice to creating the batch. So yeah, that's, that's, those were my thoughts, my early thoughts. 

Michelle Beyo:
I love that. So identity, cybersecurity. Off to the banker. 

David Tax:
David, the token banker on the, on the panel here. And it's funny because I still think of myself as a non-banker. So, my background was doing a PhD in electrical engineering. So I was at MIT building high power microwave devices for fusion energy. Took a little detour to consulting and then somehow ended up in a bank. And again, still think of myself as the outsider, but as of what? Last month or six weeks ago, it's been ten years at TD. So I guess I am the token banker now. I'm part of the furniture. 

So for me, I think you see that it's there, you see that it works or, you know, I think everyone kind of understands when you use AI tools like what's possible here. I think for me, a similar experience, but one of my favorites was one of our executives at TD was, you know, committed to, I'm going to go and do an agentic transaction. And so she said to herself, I'm going to buy a case of cold pressed juice. And 10 cases showed up at her door. So I think what I take away is, you know, again, I think we all see the path to agentic transactions, agentic finance, agentic commerce. I think what that highlighted to me is that the challenges are not theoretical, the challenges are real. And that's why we're here today, and that's why working groups are being stood up, because there's real problems to solve, and they need to be solved collectively. 

Michelle Beyo:
I love that. Thanks for the background. Over to you, Mike. 

Mike Ward
Mike Ward I am born and raised up here, but I live stateside right now. We launched a company down there called Mica. And what we have done, our thesis is that in fintech, in transactional activity today, the innovation that has been happening is always a layer on top of a layer that has sitting on top of older infrastructure. And, you know, ultimately, you know, there is limitations to that innovation. There is obviously things that create challenges and fraud and other things that may happen. But if you can go to the core, if you can go to the infrastructure itself, the network level And upgrade that, that could bring a lot more change into the industry. So that's what we have built. We've built a brand new network and that's going live stateside and activity going on in South America and over in Europe right now. We'd love to be doing stuff up here as well. 

So for us, agentic is a big part of our channel and use case that we work on. So we have been seeing this less, you know, myself going online, even though I try all the time on the different cloud or chat or Gemini to be making a transaction, making a purchase. But inside of ecosystems like the bigger networks or the Googles or Perplexity where we are in Austin, Texas, you know, we're able to test those things and start to see. And I think this key topic for all the things that we've said so far, but it's moving fast and everyone's trying to solve or be a part of it quickly, which has a obviously a pro to that because you want to be a part of the game and this is happening, but we're seeing a lot of red flags as well because it's happening fast. 

And so I think there's a good discussion to be had of, of where is this going to go and how safely will it be put out in the marketplace? So excited to be here. 

Michelle Beyo:
Yeah. And I think we have to start at the base layer, right? When I think about Agentic, I know that we, being within the payment ecosystem, have to rely on KYC, know your customer, right, to ensure the human is the human making the purchase. How ready are we to trust an agent to be KYA’d and then binded to the identity of the person to ensure that there isn't a foreign actor attempting to get into play here? And I think the question is, are we ready to trust agentic agents? Is the answer yes? No. And if so, if not, why? I'm going to go backwards on this one, Mike. 

Mike Ward:
Yeah. Look, I think in some way people are pretty trusting of a lot of different platforms out there today to make transactions, right? There are aggregators that you go in and say, hey, I want a vacation. I want to stay at this hotel. I want to rent from this car company, this airline. Right? And they start to go put their credentials and data out there. And, you know, there's technology making such transactional activity happen. 

So I think it's not a big leap for people to go. Then put it into a well-designed dashboard, you know, inside of a Claude or a Gemini. I think if there's quick fraud or quick, you know, noise in a negative way, people may be a little bit slower or hesitant to it, but I don't envision that this is going to take a long time for the flywheel to get going. I do believe it is our view that the flywheel will get going with more simpler transactions. I'm probably not going to give it a permission for a $5000 summer vacation with the family and go book everything, but to make sure that there's toilet paper on the front doorstep tomorrow morning and a few other items. Yeah, I believe that type of transaction will start to happen quite quickly. 

Michelle Beyo:
I love that. And then to come to you, David, just thinking about the bank, you guys have high regulatory mandates on how you validate that the consumer is the consumer. How how do you validate that the agent is the agent attached to the consumer? 

David Tax:
Well, I think yeah. So I mean, to your question, we're still in a not yet, like trust is, is hard to gain and easily lost. And so, um, I think, you know, with where we are at today, that experience is going to be too uneven for people to, um, to really scale yet. Some of these building blocks need to be in place. And that's what will really drive the potential success of these things in the mid and long term. But I think I'd agree with, with what Mike said, right? It starts out with with simpler transactions and it really the one thing that it comes down to in this space is intent, right? Like what is the intent? And so we're still in this world where an intent is not, book me a three day trip to Miami. The intent is buy this specific SKU from this merchant. And there's a human in the loop. We could abstract that maybe to your point, we could bind identities and that human could be out of the loop because we know it's them or their intent is clear. 

But that's really where this has to go. And so longer term, yes, you're going to get to those vaguer, broader intents where ideally the model truly knows you, right? What do you like? What kind of shopper are you? Are you value oriented? Are you just cheap? You know, it's these types of things that it's going to have to really act on your behalf without a specific instruction. And so that part will take a little longer. That trust will need to be built up. And that's where you go from a single item to being confident that it will book something and do that. And like you said, there's going to be a lot of building blocks over the next few years that get put in place where that scale or that trust is really at scale. 

Mike Ward:
Let me just use a quick example. I don't know, again, how many of you guys are dialing in and trying to purchase something today, but I think trust could also happen pretty quickly in that if I was to put in, I need a pair of black Nike running shoes right into Google up pops obviously that list of where I could start to purchase all those shoes from, right? If I put that into any of those agents today, it will go, well, what do you use in the shoes for? Is it trail running? Is it indoor, the gym? Is it this? And it starts to guide me and think about things that maybe I wasn't thinking about. So now all of a sudden I'm going, well, that's kind of smart. Oh, actually, yeah, I need them for indoor, you know, working out I need okay, now it starts to give me better guidance and insight. 

So all of a sudden it's doing something very different than just my general search. And whether you call that trust or just that education starts to happen. You have to go, that's that's interesting. Right? And I think this is going to happen much quicker than we expect. 

Michelle Beyo:
Yeah. It's getting to know us better than we might know ourselves or maybe our significant others. Um, Aviva coming from cybersecurity and looking at this are we ready for bots to be trusted? 

Aviva Klein:
I think, you know, just to build on the other speakers, I think it really depends on what the task is that the agent is being asked to do. I think these simpler, much more narrow use cases. I think we'll get there faster. You know, other types of use cases like improve my cash flow. That's a very broad mandate. And I'm not I don't think we're there yet. I think that there, you know, if I look at the Canadian banks and sort of what they're investing in terms of agentic AI, it's really at the infrastructure layer and we're not really seeing it at the presentation layer. Like Canadians are not able to, at least I haven't seen it. If anyone else has, let me know. But you're not able to interact with an agent at. I'm just going to pick on TD because I can see the lanyard. And so I think there's a lot that needs to be worked out. There are a lot of really scary risks that need to be worked out. Cybersecurity risks, systemic risks. I mean, you could, you know, imagine a malicious bot that, you know, creates a run on a bank. How do, how do the banks handle that? 

And I think, I think the banks are still working through a lot of the risk and the liability before they let the cat out of the bag. 

Michelle Beyo:
I think that's a fair statement. And then coming from identity, um, thinking about this binding, right? Like maybe we're not there yet, but KYC, KYA in some type of validation that this is my bot. It's not some foreign actor pretending to be my bot. And how do we make sure they were binded at the same time with consent? 

Nate Soffio:
It's tricky. You know, the stuff that we see today in a Gemini or a Claude. You know, there's some smoke tests, if you will, for search and discovery. Is it a better Google? Well we'll see. But, you know, I think it's easy to get sort of discovery killed right now in these LLMs. Okay, I'm looking for Adidas Sambas because reason. I'm not going to. Most embeddings for instance, are not to a point yet of technical sophistication where I can just buy it right then and there in the chat. There's some POCs, there's some pilots, fine. And those aren't without their hazards, but I'm still like clicking out and going to do my fulfillment on adidas.com or something like that. 

Zooming out though, there are two real cardinal issues that are worth bringing up from the identity perspective. The first is just how we insert an identity into like a commerce transaction flow or a set of interactions. It is called binding. That's kind of the commonly understood term. And I think the interesting thing here is all of the protocols that have been fairly recently published, whether you're looking at Visa Tap, verifiable intent for Mastercard, AP2 such and so on and so forth. They all kind of have an identity shaped hole. Now this makes sense if you think about the payment providers or payment infrastructure providers who are kind of global by default. They're not in a position to make specific territorial claims about how to do identity here or there or there. They just have parking spots. So the question then becomes what companies can go fill those parking spots and what are the mechanisms in place to, say, cryptographically bind an identity to a specific agent or agent runtime or a specific task or a specific chain of events. So it's problem space one is just get the identity in there in a way that the AI can understand and in air quotes. 

The second problem is more about systemic risk. And, you know, the common way I describe this to other people is, great, we can expose an identity to an agent, and you can figure out what their ways to expose authentication, authorization and identity, but you haven't solved for how you actually give the agent a permission slip to go do a thing. And the thing can take four flavours. So if you want to walk out here with a framework, there's four flavours on one axis. You have human present and human not present. So in the chat, am I doing the thing or am I telling the agent to go do a thing and then buy it and I can walk away, get on with my life? So that's the first part. 

Other access is, is the interaction open ended or close ended? So open ended would be I giving you a five thousand dollars budget? Go figure out my vacation to Vancouver or something closed ended would be watch these tickets on Priceline and buy them the second they go under two hundred bucks, something like that. The permission slip structure, the consent layer, the audit trail, if you will, has to be different for those four things. You know, the human has to be kept in the loop in certain scenarios as well. So I think long story short, while, you know, there's been decades of work being done for authentication and authorization and IDV and KYC and normal human land, there's a long list of net new things that need to be built. So those things can actually be transplanted into how agents are going to be doing interactions, because the stuff we're seeing right now is not going to be the stuff we're going to be seeing twelve months from now or 24 months from now. 

Michelle Beyo:
Yeah, we're like at the precipice of something, right? We're all talking about it. But it's not a nine year discussion to maybe get there. This is like this is happening on a global scale. And it, it's looking like we need to figure out how this rail of agentic commerce is going to run. And as we talk about like, what are the current hurdles for this agentic rail to run? And, um, when we're looking at that, what's going to be the payment method that is utilized? Like I come from prepaid. So I like, are you going to box it with a prepaid card? Is it going to be to your core credential and we're going to protect those somehow from being overutilized. Is it going to be a stablecoin because it's programmable? And I have so many questions, so I could only come to two to two of you on this. So I'm going to start with David and then come over to you, Nate. 

David Tax:
Yeah. So it's going to depend a lot on what you're trying to do. Right? So I do think still existing rails are largely going to persist on these. But there's definitely opportunity for complementary new rails, so I think if we look at the traditional. So. Especially the commerce transactions, you know, the card networks are quickly trying to build that baseline of trust. And, you know, we talked about, again, those identity pieces, it doesn't look a lot different than e-commerce, tokenization and the things that you're already trying to do, right? It's about how do I make sure that the customer is the customer? The customer is behind this transaction. This is what they want it to do, that I can authenticate them appropriately. And so, you know, whether it's visa intelligent commerce, Mastercard, agent pay, their goal is really to, to bring that same level of trust on e-commerce into this world. Right. And so I think that's, that's going to be the first thing, you know.

To your, to your second point, I think there's a couple of things here, and this is where it gets a little bit more interesting. So I always have the view. Innovation is always about timing. Like we can come and talk about trends or real-time payments. Nine years ago or whatever it was, and it's always a timing thing, right? You're going to be right within some time frame. But we're obviously caring about things in this kind of maybe short to mid-term that are going to be more impactful. 

And so I think the first thing is if you think about having AI and agents doing things, one of the biggest barriers to the adoption of something new is just inertia, consumer behavior and habit. Right? As in businesses getting workflows, you know, hey, please use EFTs, don't send a check or do whatever, right? People are persistent in that. And so if agents are actually the ones acting, it kind of changes that, that mental math or that potential time frame and acceleration on a new rail, because I don't need each individual in this room to do it. I just need them to adopt a technology that can say this is a better tool. And you already have the account numbers. You have, you know, for maybe real-time payments, whatever it is, to be able to do that. 

The second piece, like I said, around stablecoin, tokenized deposits or some sort of DLT blockchain. I think again, there's kind of that timing thing of when we were looking at those initially 10 years ago, project Jasper, the Bank of Canada, 10 years ago, people, it wasn't quite mature. People didn't understand it. The value wasn't as clear. Whereas you see, if you saw the keynotes, you know, the banks in the UK, they're tokenized deposit platform and central banks pursuing things like Project Agora. You know, the pieces are coming together where tokenized rails, tokenized money can move. And so I think that's definitely going to be a potential use case for things like micropayments. To your point, back in the day it was prepaid. It was stored value. You no longer need to rely on that closed loop system in order to enable that. I'd say the only caveat I'd put on that is, does the programmability matter as much if the agents themselves can be the programming? So do they need a programmable rail or do they just need something cheap and instant and atomically settled, which again, might be the same features or the same rail or the same payment asset? But I think those are the kinds of things that we'll think about. 

So there's going to be new use cases and these new rails. And I think, you know, for us in the industry, it's, you know, that framework that you have is how long something will take to, to adopt as more and more things get, you know, AI agentic automation, you know, those curves will quickly accelerate and ramp up. And so we need to be more quick and nimble on our feet to adapt to that. 

Michelle Beyo:
Yeah, I really love that you broke it down so deep to tokenized assets as well. And kind of brought it to what is going to be the fastest, easiest way for this agent to be able to, to move in this new world. So to bring it to you, Nate. Round it out for us in the sense of what's missing to get us there. 

Nate Soffio:
I've got a naive answer and then an answer that's a little bit more about where we think incentives are going to align from an ecosystem view. 

So the naive answer is all these payment methods are going to be available inside agentic ecommerce a genetic interactions. You know, if any of us have bought anything ever on Amazon, Shopify, etc. it's a, it's button salad, right? Pay with Shop, pay with PayPal, pay with Venmo, so on and so forth. We should expect the same stuff at a very cursory level inside agentic experiences. UX is TBD on that. 

The two things that get a little bit weirder now that you have a person on one end and maybe a merchant or a relying party on the other, and then some weird spaghetti in the middle involving an LLM runtime, some code, maybe the merchants code, etc. Two things are very different than how we generally understand payments in commerce to work today. The first is something that David already mentioned is optimization is going to look different, right? 

And this is going to kind of insidiously involve, well, how much information are we as consumers willing to give to the LLMs around our payment methods and payment preferences? Do we expose our shopping history to the LLMs for like memory in a project? Things like that. There's an argument to be made that the more we do that, you know, consent bleed notwithstanding, the more the agent can be optimized for what we want. Oh, if I'm booking travel, it'll use this card. Oh, if I’m sending money overseas, it'll use, you know, Felix which uses stables, stuff like that. It'll just kind of know what to do to introduce the least friction. Great. Cool. 

The flip side of this, though, is agentic payments of really any sort can't really succeed without identity being tied into it, which is kind of why we're all on the stage to begin with. It's different from like a 3DS or something, which is kind of like post hoc authentication and authorization. What that means then is we get into these weird discussions around liability shift, new types of interchange, stuff like that. So as much as it's easy to say, oh, just there'll be buttons on a page and consumers have preference because of inertia or, oh, the LLM will optimize for me. 

We also have this third sort of force in the room where there might be safer rails than other rails, and they may cost us differently or they may cost merchants differently if we have assurance or chargeback protection, say, baked in. We don't know what that's going to look like yet, but we should expect a world where all three of these things are going to be probably stepping on each other's toes. 

Michelle Beyo:
I definitely see that. And and my next question is about programmable trust, because I think we're starting to see that there isn't a global standard. There's no ISO standard for agentic commerce. We haven't got there yet, but oh, do we need to, at least from a guidepost perspective. And Amex just came out with we'll take on the liability of the agent. They're the first in the ecosystem to do that. But Aviva and Mike I wanted to get your perspective. Do we need regulation? Do we need a standard? What do we need to kind of ensure that we get there together and not just one player wins because they got there first with something trustworthy? And I'll start with you, Aviva. 

Aviva Klein:
I think we definitely need interoperability. I mean these agents are going to be crawling all over this, you know digital landscape. And they in order for it to truly function, it is going to have to cross, whether it's like geographical borders or organizational borders. And so you do need to position and be ready for interoperability. But I think it also kind of comes down to some common standard that we all by we, I mean, the players in the ecosystem sort of all sort of agree on whether that's an ISO standard or an EMV code standard. And Nate touched on it a little bit, but it's about, you know, having these agents be properly authenticated, not just the agent, but also the user who's, you know, establishing a relationship with the agent. 

Consent is going to be super important and not just one time, but continuously throughout the mandate of the agent. And, you know, some mandates are going to be really, really narrow. Like I need a pair of black shoes. Another are going to be optimized my cash flow. And agents, I think, just want to please us, right? They just want to do what we ask them to do. And they will uncover every single stone in order to please its user. And that really, I think, shifts consent and shifts the direction. It could shift the direction of the agent through a series of smaller micro decisions where what you started, what you consented for originally is actually not necessarily what the agent is even doing anymore. So you can bring this parallel of the card networks if you think about tapping, right. Every fourth tap, you have to shove your card in and put your pin in. It's like a re authentication so that there are checks and balances in the system. So I think that there is common standards and interoperability are going to be super important, particularly as I said around authentication and consent. I think also sort of how you bind the agent and what's the, what's the boundary setting look like in terms of what an agent can and can't do, and how does that get cryptographically created and stored? I think the audit trail is going to be super, super important. So what did the agent do? And not just what, but why did the agent do it? It is going to be super important in retrospect to look back. If you have a god forbid moment where you're not on the happy path anymore and you know, you ordered a pair of shoes and there's five hundred pairs of shoes. So I think the, the auditing is going to be super important. Um, I think revocability is going to be super important, the ability for the human to stop. And I think also this idea of like having the human in the loop, you know, we get stepped up all the time. 

So how do we continue to step up in the age of AI when we are going to start giving these agents these very broad mandates? It will start with a pair of shoes or a toilet paper, and it will very quickly go to manage my cash flow or improve my cash flow. So I think those are some of the elements that are going to be required to think through. 

Michelle Beyo:
Yeah, we still have a ways to go, but wow, are we running. Mike, what do we need? Like I know the US, like everyone's running at different paces, but considering the Silicon Valley and like most LLMS living in the US, like what is needed and I know the US does not love regulation. Is it a standard that gives some clarity? Like, what do you think we need to get there? 

Mike Ward:
I think it could be a standard. I think it's also who's in the mix, right. I think Visa and Mastercard are obviously a great companies, big companies. I think they're trying to, you know, square peg, round hole some stuff because of what they are actually available to do today. Right. And trying to make it work. And I think there's a lot of nervousness around that because that still doesn't protect the consumer like it could or doesn't control the agent. Maybe like it should - not just because I'm sitting beside David and he's bigger than me, but I believe the banks need to be a lot more involved. You know, that's ultimately in our position. The consumer trust the most right is usually their financial institution. Right? 

And so if we just break it down to a simple transaction today, if I was to do a transaction and something was not right with it, who would I call? Am I calling Perplexity? Am I calling Claude? Probably not. Do I know who the underlying merchant is? Right. Did it carry my loyalty and all my information over to connect that with me and Walmart that I made the purchase from? Probably calling them, right? And they're going, well, I wasn't even involved. Right? I had no connectivity. I had no, you know, and I believe if the issuer was a lot more involved in this activity, right, in both the KYC elements of it, maybe not responsible for KYA, but KYT right? For, you know, being able to sign off or step up authentication, you know, signing off on. Yes, I authorize them to go and make that transaction. And that is right. You know, receipts where the receipts are going to sit. 

Like just if you think about this, you know, I believe the bank can play a very key role, which puts a lot of security and kind of management in this. And my nervousness so far is, I think at least stateside, I'll pick on them for a second. You know, they're in the conversation, but they're not necessarily taking a position like they could. There's a lot of hands in the middle here. And if we can remove some of those hands and just go, hey, that is probably who the consumer is going to call and who trusts the most. Let them be a lot more involved in this than they are today. 

Michelle Beyo:
Yeah. And I think it brings me to the question, like, I’ve liked touching new technologies for many years. I like to figure out what's happening and try to work with it. But when I think of an agent, I have maybe five credit cards, some for business, some for personal. But that's how I manage my payment ecosystem. When I think of agents, I don't want more than a couple agents, and I want to know who they are, who was, who were they built by, and how do I revoke them? Um, so who do we think the agents are going to be? Because I don't know that I trust the LLM to be my agent because what trust have they built with me so far? And what visibility like I don't trust them with my data to be the overarching player to protect me. So who do you think the agent, like a trusted agent, is going to come from? Is it like a big corporation? Is it an LLM? Is it a bank? Is it a payment providing organization? Is it all of the above? And like how as consumers? Are we going to manage and protect them so that my daughter doesn't have four agents and my son has a couple agents and they're all tapped to my credit card. So how are we going to manage this? And Nate, you come from digital identity. So I'm coming over to you first. Who do you trust? 

Nate Soffio:
Oh, that's a question! 

Michelle Beyo:
It was not on the prep list, I apologize. It just came to me.

Nate Soffio:
The seat is getting hotter the longer I sit here. So this is sort of architecturally very difficult. You know, I think one thing I'd want to dispel is that like an agent necessarily has things innately. It may be easier to think about an agent as sort of a container for stuff. Now, having said that, if you're in Perplexity or Claude or something, and you're using agents in there, those agents will have some of their own identity in big air quotes because it comes from what's called an agent publisher. So you're using a Claude agent, you're using a Gemini agent, you're using a such and such agent or if you're on a merchant site and they're built on AWS, then great. It's an AWS route 53 based agent. Point is it's a container. You have a human, you have the agent, you might have a merchant agent, you might have a merchant. It's one thing to say that, okay, the person is a real person. They're authenticated, but it becomes a sort of four party model. I hope for folks out there, four party models sound familiar? Because that's like one thing that does still hold for agentic interaction. You have the person, you have the relying party on the other end, you have the agent, and then you have this other kind of weird object, which is the scope, like what is supposed to be done in this interaction between person and merchant or person and relying party. 

So two things follow from this. The first, in my, at least in my opinion, it's easier to think about agentic interactions if you think of everything as peer to peer, no matter who's on either end of the pipe. What this means then, is people always have to authenticate to do an action and the relying party and the agent in the middle. Even if it's like an LLM agent, everyone's got to authenticate to everyone else. It's just a big authentication party because there can't be blind trust between all these parties, because now you have all these middlemen. It's not me going into 7-Eleven and buying a Slurpee, and there's no middleman. There's agents, there's the LLMs, there's the merchant agents, stuff like that. So everything has to be authenticated. So that's a framework. As for the deeper question of, well, what is it like to get the stuff of a real human into the interaction. You have attributes and you have keys. And so this is a lot of the work I do at Prove stems from this. Verified attributes can be your name, your shipping address, some personalization information. It can be an ID-linked payment token for a card, something like that. 

And then there's keys. Now normally we think about keys. We think about authentication, public private, key pairs, things like that. An agent world keys become really important because it allows the verified identity to apply digital signatures to all of these events and all these middleman things that happen. So to Aviva's point, how do we prove that this chain of events actually happened and the telephone game didn't go totally sideways? If you have a trustworthy person with the right attributes and keys that have signed off on the series of events and the trust travels, you can now end up with an audit log, dispute resolution, recourse frameworks, because you've got an end to end. But solving that is a very, very tall order because we have different types of actors in this ecosystem that need to agree to these sorts of paradigms. And then we need identity and auth companies to figure out how they get involved in payments if they haven't previously. So needless to say, there's a ton to coordinate in a very, very short time frame. 

Michelle Beyo:
So who would you trust to be your agent? 

Nate Soffio: 
No one yet. 

Michelle Beyo:
Fair. Anyone have an opinion? I realize multiple companies know a lot about us, and increasingly, LLMs know a lot more about us. But who would you want to give agency to and trust? 

 

Mike Ward:
I think it depends on the level of trust that you're giving. But let's just say most people in the room here think about this very differently than the average person, right? The average person goes to, I even think of my thirteen year old and it's shocking. The buy button does come up now once in a while. Right on Gemini. You can do the buy button from certain merchants, right? And so why does she know Gemini? Because she knows Google, right? Because she's already tapped in. So you know where trust starts to go for the average person potentially is a brand that they've heard of, right first. And I'm not leaning towards that. It will be Gemini over everyone else. But again, Google's recognized by most people out there, so I'm just using that as an example. 

Michelle Beyo:
Yeah. No fair. It's a hard question. I really didn't prep them so well. 

David Tax:
So I think this is where the again, no one no one has the crystal ball. Right. So where we are today, I think, and if we look back twelve months ago, right, like there was this arms race around models, it was like whoever has the biggest model, the best model was going to win. That seems to be less true. What you're seeing is some differentiation, right? Like different things, different models are better at different things. And I tend to believe that's more how this will shape out over time. I think the question is, does it become an app store thing? Do you know, do we become banks or payment companies or merchants become model context protocols within these large couple of large players? Or do people start building custom solutions on top of each one, like you say, this is an agent for shopping and it's some third party, not not first party provider. I think we don't know yet how that plays out, but I think to to where you were going, you know, people will generally align to things that work better, right? So things that are more effective are going to get that. So there's going to be a baseline of brand recognition, name recognition to start or trust whatever it is. But everybody will have their own views. And I think ultimately it comes back to what makes it work better is going to be who knows you the best or who has access to the data. And so when I was thinking through like midnight last night, you know, we're doing this panel, it was just like I was remembering for all of you who were here seven years ago. So back at the Payments Canada Summit 2019. Tim Berners-Lee did a did a keynote, like probably a couple people remember. You know, I get to my point on innovation and timing. So he was coming and pitching this concept where you would hold your data. And so it was like a reimagining of the World Wide Web, where you carried your data with you. And when you access the data or when you went to a website or whatever that would look like in this world, they would not take your data, but they would have access to your data to, to run it. But they wouldn't necessarily store, collect, manage like the large tech companies do. Everything is platforms and centralization today. And so it kind of got me thinking, well, maybe that approach or that technology is better suited to something like an AI or an agentic world where you actually do have your data. So I was saying before, there's your personal attributes. So we have kind of traditional data sources and attributes and things like that based on transaction data and behavioral things like that. But we need things like, you know, well, what is your shoe size? Right? So like, I don't want to have to make you prompt the agent every single time. Like if you wear a Puma nine size nine and a half and you prefer the pink with the black accent, like eventually over time those things should be automatically known. And that regardless if there's another agent that's better for shopping, you should be able to bring all of that context with you to that other provider. And so this kind of goes back to, to Mike's point earlier, like, who are the arbiters of that trust? I mean, sure, banks are definitely well positioned to facilitate that. I mean, this is where again, industry coordination, collaboration still needs to happen. And, you know, I think ultimately standards and all that, it comes down to, you know, who's responsible for what throughout the chain. And, you know, so the standard will make it clear. And then ideally we position those responsibilities or the access to the right information in the right places, like where it's trusted the most secure information to be in the most trusted, safe places. And, you know, kind of snowballed from there. But again, this is where the industry is moving so quickly. Those theoretical or ideal scenarios versus the pace of innovation and activity in the marketplace, it's like, will those things align or will they kind of diverge in their own respect. So again, it just reminded me of that past. And again, maybe that's the way it shapes out. But, you know, perhaps we all have a role to play in, in helping all those types of things along. 

Michelle Beyo:
I love that you mentioned that, and I'm sad I didn't get to see Sir Tim Berners-Lee. I kind of fangirl on his new book called “This Is for Everyone The Missing Element of the the World Wide Web.” And he talks about the solid project and it being a data pod that is only pinged but not taken up. And I think just thinking of that potentially being the agent, not taking the data with them for privacy by design infrastructure and just validating that I am who I say I am without taking my data because I always complain about hotels having my data, because I think they're the least protected place that holds our core data. They have our passport, our name, our address, our birth date and our credit card. And like bad actors, love hotel data. We need to figure out a better way to have an agent, let's say, sign me into a hotel, but without sharing any of my data. If agents were to be a helpful party in protecting our data, or if that was part of their mandate and we only have time for a couple more questions and I'm happy to take an audience question. So if you have one brewing, I've got one more to my audience or to my panelists. I'd love to get one from you. I really two questions. So I'm going to try and direct it to two of you. One, open banking is kind of the underlying data sharing of consent under agentic if done properly. In the way that I look at it, because if I no longer like my LLM, I should be able to data share everything I'd ever learned about me to another agent if we had true open data. We're not there yet, but someone needs to think about that. But if we're doing agentic finance and like I need to have consent for this agent, open banking seems like the natural fit of the consent rail if done properly with, you know, the right API. 

I don't know who wants to jump in on this one because I kind of threw it out there. But I think it's, it's just really interesting. We need the data flow and we need the consent of the agent. 

Nate Soffio:
I will say briefly, um, my old company portable was a member of FDX. We really liked taking part in that because of the accessibility and design standards that they said open banking providers must abide by these so people know what's getting access by whom? For what purpose? Under what conditions? For how long? Full stop with Irrevocability. That's a pretty darn good paradigm. Now, the problem is, if an AI agent or an LLM environment starts consuming all manner of things, some of that I'm just going to share freely, like, yes, I'm a size this and size that, and no one's the custodian of that information except for me. I think getting open banking data in LLMs should still abide by those principles. The question then becomes is will all data get permission for all purposes? Now should it not. In theory, yes. Like, you know, imagine this sort of create like privacy hell, or everyone involved, but it does sort of raise a question of, well, every, every share action should at least have a record of someone saying yes or no to it. 

Michelle Beyo:
I love that. I know it makes it complex. Okay, we don't have a lot of time. I have a Canada question. And Aviva, I was going to come to you just looking at the landscape. Right. We don't really have a major LLM. We do have an LLM in Canada as we look to agentic. How does Canada play a part to not just be taking in other people's innovation but innovating?

Aviva Klein:
That's a good question. I'm not sure if we need a Canadian LLM. If I'm being honest, I think that it's, you know, I think the privacy by design is important with the LLMs that we have and we need to make sure that we're not disclosing that we're sharing the data that we want to share, but we're not inadvertently disclosing things about ourselves that we never wanted to disclose in the first place. 

So, you know, I'm not, I don't know if I don't think Canada needs its own LLMs, I think that the LLMs need to be ready for Canadian traffic and whatever that may look like, whether that's using Canadian backed stablecoins, you know, as an underlying rail. I just don't see a Canadian backed LLM in the future. My own personal opinion. 

Michelle Beyo:
Mike, former Canadian, still Canadian. 

Mike Ward:
Still Canadian. Yeah. I think you make a good point. Maybe there's a version of it. I just, I believe up here has so much more opportunity to put your arms around obviously the ecosystem. Right. And so to have more kind of controlled closed loop opportunity, is greater than a lot of places, right? And so I think to have your own version, to have the four or five banks that really have a good size of the market share up here, your ability to get good standards, good kind of programs out in place, tested and controlled is not like a lot of places, at least not where I live. Right? And so I would hope actually to spin it a bit, the opportunity is to move faster up here. Right? That's the opportunity now that you take advantage of it. Yeah. Because I think knowing that agents might run 23 per cent of commerce right, the next two years, how do we make sure Canada is a part of that? David. Yeah.

David Tax:
Yeah. I mean, so for anyone who's been innovating in Canada for years, you know, we tend to suffer from perfect being the enemy of good because it's easier. You don't have to get six thousand banks. You know, there's a hundred institutions and you get a much everybody. If you hit ten, you pretty much, you know, almost every Canadian will have an account that creates, again, a lot of potential. But then it's like, you know, with great responsibility. And so yeah, we tend to move a little slower than others. I mean, I think there's a couple of things in Canada, you know, we talked before, like you were saying about LLMs. We don't necessarily get the attention from them to build or develop for the Canadian market. Right? And so I think some things that are happening now in as far as Canadian sovereignty and Canada's place on the world stage, these things do help us to be seen and heard on the global scale, to know that this is a market that's really important. I think when it comes to privacy laws, you know, there's some quite good things there as far as how your data is used in the US and then how your data is used in Canada, right. Companies can't just take it and kind of, you know, check a box and do whatever. Right. We have a bit more stricter rules in Canada. I think especially in this agentic space, it's, you know, we've, we've been talking for, for a while now as far as in this current open finance, open data, open banking world, our privacy law is being modernized for digital transactions and digital interactions. And then we're still solving that. And then we're now our privacy laws to your board. Like, are they fit for purpose for an agentic world? Or is it just going to be privacy, compliance, hell and things that don't work or, you know, like the constant check boxes and things like that. And so again, striking that right balance will really be what's important. But I think Canada has a lot to offer. We were where the godfathers of AI come from here. We have great Canadians down south, you know, so innovating down there. And so, you know, I think the opportunities ahead of ourselves if maybe a bit, we can get out of our own way and focus on the kind of really important things. And like I said, not let perfect be the enemy of good. 

Michelle Beyo:
Yeah, I appreciate that. We only have a couple minutes left. I'd love each of you to just maybe share with the audience one thing that you think we're underestimating when it comes to Agentic finance? Mike less than 30s. 

Mike Ward: 
Oh my goodness. I feel like you spun every question different than what we prepped for. 

Michelle Beyo:
You're all ready. All right. I know you all too well. 

Mike Ward:
Look, I think I mean, you were talking about something earlier about, you know, giving it cash flow and stuff like that. I actually maybe smart, maybe stupid. I gave my agent the opportunity to do my taxes prep for my accountant this year. And it was done on a Sunday night, which would have taken me a week, you know, finding everything and all the folders and the different entities and all that stuff. Right. It was fantastic. You know, maybe 95 per cent correct. Right. So I think the power of it, how quickly you can start to use it. Yes, trust is a big thing here, but it's, it's here. And I mean, it's just how quickly are you going to start to adopt it? So I'm just excited about it. 

Michelle Beyo:
I love the hot take. Yeah. Dave. 

David Tax:
So I think again, short term we might be overestimating, you know, how many use cases good enough is good enough for. Right. I think the potential is there, but it's like 95 per cent. We might be overstating that in the short. Classic innovation. But I think that once we can solve those key things, I don't think we need to solve everything to the nth degree. But once those few key building blocks are put into place, I think that's where we underestimate just how quickly it can expand and scale, not just in terms of adoption and transactions, but just the breadth of use cases and problems to solve. 

Michelle Beyo:
Yeah. Fully agree. Aviva? 

Aviva Klein:
We anticipated this question. So when I thought about it again, I sort of looked at it from a Canadian banking lens. And you kind of talked about the spaghetti. And there's a lot of spaghetti and a lot of it is legacy. And so how are the banks going to take all of that legacy hardware and infrastructure and put this really leading generation, like next generation technology on it. I just think it's a little bit incompatible and it's a really heavy lift. I think also the data architecture, like, you know, the data at the banks is not necessarily well structured. It's not all in the cloud. And so you're going to need those things to really function well. I'm going with legacy infrastructure and the underestimated. 

Michelle Beyo: 
Yeah. Underestimated. Nate. 

Nate Soffio:
I think for me parting thoughts is going to sound strange. The AI is the easy part. Like we've just heard from Mike, it can do extraordinary things with like decent accuracy, you know, getting ten cartons of fruit juice instead of one notwithstanding, I think the thing we're radically underestimating sort of backs into what Aviva said is we're not ready for the volume and speed with which things are going to go sideways. You know, so we are underestimating the amount of controls we need to put into place.

Michelle Beyo:
I love that you started with the Fido working group and ended with the complexities ahead of us. So we all need to gather and talk more so we can get there in the right way. Thank you so much to my panelists. If you want to learn more about the future of finance, I somehow wrote a book that's coming out with Wiley this September 22 second on the future of finance, outlining the nine elements of the future of finance and agentic and payment innovation. Definitely being one of them. Thank you to Mike, to David, to Aviva and to Nate, please. Big round of applause. Yeah. It's fun.

Liz Dempsey:
That’s a wrap on this episode of The SUMMIT Summer Series! 

We want to extend a thank you to our expert panel, Aviva Klein, Nate Soffio, David Tax and Mike Ward, as well as our moderator, Michelle Beyo, for sharing their time and insights with us.

We are moving past the era of simple search-and-discovery bots toward autonomous, agentic finance systems capable of executing transactions on our behalf. The technical capability to build these systems is already here. And collaborative efforts will be key in building the framework to govern them.

If you enjoyed this episode, make sure to subscribe to The PayPod wherever you get your podcasts.

We’ve got plenty more conversations coming your way as we continue to highlight the very best insights from The 2026 SUMMIT.

I'm your host, Liz Dempsey. Thanks so much for listening to The PayPod.

Be sure to join us on our next episode.

Keep reading