Can an AI Agent Spend Your Money?
An agent with a card has exactly that card's authority, and no separate permission layer underneath. Where spending power leaks in, and the controls that hold.
Can an AI Agent Spend Your Money?
Yes, if you give it a payment credential, and the question that matters is not whether it can but what stops it at the point it goes wrong. An agent with a card number has exactly the authority that card has. There is no separate agent permission layer sitting underneath, and the recovery routes people assume exist mostly do not.
The three ways agents end up with spending power
Route | How it happens | Blast radius |
|---|---|---|
Stored card in a browser session | The agent drives a browser that is already logged in and autofilled | Everything that account can buy, with no per-purchase check |
API key to a provider | Cloud, ads or inference accounts billed on usage | Uncapped by default; the bill arrives monthly |
Company card pasted into a prompt or config | Someone wanted a quick result | The full card limit, and the number is now in a log somewhere |
The second one causes the most actual damage, because nobody thinks of it as spending. An agent in a retry loop against a metered API is spending money at machine speed, and the first signal is an invoice at the end of the month.
Why chargebacks are a weak safety net
The instinct is that a bad charge can be reversed. That is much less true here. A transaction you authorised, on a card you provided, through software you chose to run, is not obviously fraud from the issuer's perspective. It looks like a purchase you regret. Consumer protections are built around someone else using your card, not around your own automation using it as instructed.
Metered API spend is worse still, because there is no discrete transaction to dispute. You consumed the service. The invoice is accurate.
The controls that actually hold
Controls that sit between the agent and the money work. Controls that depend on the agent behaving do not.
Use a virtual card with a hard limit, per agent and ideally per task. If the limit is 50, the worst case is 50.
Set hard spend caps at the provider, not soft alerts. An alert tells you after; a cap stops it.
Give the agent its own account with its own budget, never a credential shared with a human.
Require confirmation above a threshold, and make the confirmation happen outside the agent's own loop so it cannot approve itself.
Alert on rate, not just total. Twenty small charges in a minute is the signature of a loop, and the total may still look fine.
The fourth point is the one teams get subtly wrong. A confirmation step the agent can satisfy by generating the approval text is not a control, it is a formality. What human in the loop actually requires goes into why the approval has to live outside the loop being approved.
Authority is not the same as capability
Separately from whether the agent can move money, there is the question of whether its purchases bind you legally. Those come apart: an agent can absolutely execute a payment it had no authority to commit you to. We looked at that side in whether an agent can sign a contract for you, and the practical upshot is that a dispute about authority is slow and expensive, while a spend cap is instant and free.
A reasonable default for a small team
If you are experimenting with agents that touch anything billable, the setup that costs you an hour and removes most of the risk is: one virtual card per agent with a low monthly limit, provider-side hard caps on every metered service, no shared credentials, and an alert on charge frequency. None of that requires you to predict how the agent will misbehave, which is the property you want, because you will not predict it.
Narrowing what the agent can reach at all is the other half of the same job, and it generalises beyond payments: see sandboxing an agent's access. For where this sits among the other things worth worrying about, the wider AI risk picture has the map.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


