The next transaction won't be a card or a phone. It will be an AI agent acting on a mandate, initiating a payment, comparing prices, completing a checkout. The network sits in the middle of that transaction and owns the question no model provider can answer: is this agent authorized, on whose mandate, and at what scope?
A payments or treasury agent inside an issuer initiates a transfer on a customer's behalf. Who signed the mandate? Is the agent in profile? Was this authorized, or injected?
Operator, Claude, or a scripted agent hits a merchant checkout or API. Human, declared agent, or impersonator? Does its mandate match what it is trying to buy?
BladeRun is not in the settlement path. It is the verification and governance layer that wraps the agent transaction, checking the mandate on the way out, attributing the agent on the rail, and scoring the call when it lands at the merchant.
Four capabilities a network needs to make agentic commerce safe, and to monetize it, that no foundation-model provider will build for you.
Cryptographically verify the agent's authority to act: AP2 payment mandates, RFC 9421 signed requests, network tokens, or enterprise agent IDs (Okta, Ping, Entra). Standards-agnostic by design, a verifier, not an issuer. We check whatever credential the agent presents and reward valid ones with a trusted lane.
Know which agent, on whose mandate, at what volume. The attribution layer agentic commerce needs, for fraud, for chargeback evidence, and for metering. You cannot price or meter agent traffic without knowing whose call it is. This is also how a bank complies with the Section 1033 access boundary.
One governance plane on both sides: inspect, score, and enforce on the issuing side (the bank's outbound agent) and the acquiring side (the agent hitting the merchant). One event shape, one audit surface across the whole transaction, and a sub-60-second kill switch if an agent goes out of profile mid-flow.
Verified agent signal, the mandate, the prompt origin, the tool call, flows into the fraud and decisioning platforms and models you already run. The runtime agent context those engines never had. BladeRun produces the signal; it does not replace the engine. Additive, not competitive.
InAuth started at the bank, expanded to the merchant, and integrated with the risk engine, and across the card networks it became infrastructure. American Express acquired it in 2016. BladeRun is the same channel model on a new surface, by the same founders. The agent-trust layer is at the 2011 stage of that curve.
Govern the agents the issuer runs, outbound to any model, inbound from any caller. The same wedge that started InAuth.
Verify agents arriving at checkout and on public APIs, declared, undeclared, or impersonating. BladeRun.js on the surfaces you already run.
Feed verified agent signal into the fraud and risk engines you already run. The integration that turned device trust into infrastructure, repeated for agents.
OpenAI will not govern Anthropic's agents. No issuer governs an acquirer's traffic. They are competitors. The agent transaction needs a verification layer that is provider-agnostic and network-aligned, one that sits above every model and attributes every agent, with evidence the network owns. Structurally, that is a network's role to occupy, not a model vendor's.
One policy plane across OpenAI, Anthropic, Azure, Bedrock, Gemini, and self-hosted. Add a provider tomorrow; the trust posture does not change. No model vendor will govern another's traffic. Only an independent layer can.
Every verified agent transaction is logged immutably to storage you control, not a model provider's cloud. The attribution and audit trail the network keeps, regardless of which model the agent called.
The overstep verdict and signed evidence, inline at authorization, neutral across every network.
One inline call before you score, a deterministic verified-agent verdict as an input to your decision.
Accept legitimate agent orders and stop the ones that overstep, without touching your checkout.
A working session with the founders, the agent transaction mapped against your rails, your standards, and your risk stack. No slides. No procurement. Just the architecture you would actually deploy.