惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Cloudflare Blog
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
人人都是产品经理
人人都是产品经理
V
V2EX
爱范儿
爱范儿
PCI Perspectives
PCI Perspectives
T
Troy Hunt's Blog
Stack Overflow Blog
Stack Overflow Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
SecWiki News
SecWiki News
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
The Hacker News
The Hacker News
小众软件
小众软件
雷峰网
雷峰网
D
Docker
NISL@THU
NISL@THU
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
腾讯CDC
B
Blog RSS Feed
C
CERT Recently Published Vulnerability Notes
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
U
Unit 42
有赞技术团队
有赞技术团队
P
Palo Alto Networks Blog
G
GRAHAM CLULEY
T
The Exploit Database - CXSecurity.com
T
Tailwind CSS Blog
S
Security @ Cisco Blogs
量子位
I
InfoQ
Application and Cybersecurity Blog
Application and Cybersecurity Blog
大猫的无限游戏
大猫的无限游戏
Schneier on Security
Schneier on Security
Help Net Security
Help Net Security
Latest news
Latest news
The Register - Security
The Register - Security
S
Securelist
W
WeLiveSecurity
A
Arctic Wolf
Security Latest
Security Latest
AWS News Blog
AWS News Blog
L
LINUX DO - 热门话题
S
Secure Thoughts
T
Tenable Blog
Know Your Adversary
Know Your Adversary
月光博客
月光博客
M
MIT News - Artificial intelligence

Cloud Security Alliance

SearchLeak: Copilot Data Exfiltration Exploited | CSA Zero-Trust AI Governance for Multi-Agent Systems | CSA Dangling CNAMEs: Hidden Cloud Risk | CSA Mythos and the Future of Cybersecurity | CSA AI-Driven Cloud Risk: Defenders Lose Ground | CSA Financial Services Industry Shifts from AI Adoption to | CSA CSAI Foundation Announces RiskRubric V2 as the Next Key | CSA RiskRubric Updates: AI Risk Assessment | CSA Over 80% of Organizations that Miss 24-Hour Patch Window Report | CSA ORCHIDEAS & MAESTRO: Secure AI Design | CSA Top 6 Claude Security Risks to Watch | CSA Cloud Cost Optimization in 2026 | CSA HIPAA Rule Overhaul in 2026 | CSA AI-Driven Exploits Outsmart Detection | CSA MCP Risks CISOs Should Prepare For | CSA AI Governance for Trust and Compliance | CSA MTTP: Patch Cycles Too Slow | CSA Cloud Security Evolution: Security Teams Lead | CSA Misconfigurations Break Customer Trust in Apps | CSA Taming Shadow AI: C-Suite Strategies | CSA Agentic AI Threats: Five Powers | CSA AIUC-1: Agentic AI Governance | CSA 2026 Threat Report for CISOs | CSA Securing AI in AWS: Runtime Detection & Response | CSA SLMs, LLMs, and the DSPM Difference | CSA OT Security Timeline: Mythos and Patch Pace | CSA Blast Radius and Cloud Threat Detection | CSA State of AI Cybersecurity 2026: 92% Concerned | CSA AI in MDR for Franchise & Multi-Location Ops | CSA AI Regulation: Identity and Authorization Gap | CSA MITRE ATT&CK for Cloud: Detection Coverage Guide | CSA Shadow AI Agents: The Insider Threat | CSA Medical Device Breaches Reveal Cloud Security Gaps | CSA AISMM: AI Security Maturity Model for Cloud | CSA Globee® Awards for Artificial Intelligence (AI) Honors Cloud | CSA Patching Smarter for Mythos Security | CSA SDP v3: Identity-First Zero Trust for AI | CSA AI-Ready Security Documents Beyond STIX, OSCAL, and SARIF | CSA Penetration Testing for ISO 42001 & Trust | CSA AI Agent Posture: Data-First Security Guardrails | CSA AI Agents Go Beyond Output: Enterprise Security | CSA AI Agent Security Starts with Scope Control | CSA Identity Spoofing vs. Identity Abuse | CSA AARM: Securing the Agentic Runtime | CSA Securing the Agentic Control Plane | CSA CSAI Foundation Announces Key Milestones to Secure the Agentic | CSA Catastrophic AI Risk Controls | CSA Cloud to AI: Building Secure Programs | CSA Identity in AI Era: Zero Trust's First Pillar | CSA SDLC Visibility: Securing Multi-Cloud Development Lifecycles | CSA Cloud Risk: Top 3 Threats & AI Tools | CSA AI Agent Identity Is Solved Backwards | CSA 8 Truths About Cloud Privilege Risk | CSA AI Governance: Mature Programs | CSA Agent Access Management: Data-First Security | CSA Glasswing: AI-Driven Security for Safer Software | CSA Runtime Security: Detection & Real-Time Cloud | CSA Identity as the OS for AI Security | CSA Cloud Misconfigurations Drive Attacks at Scale | CSA Sensing AI Behavior with the WBSC Probe Library | CSA An Actionable Guide to GDPR Compliance for Startups | CSA Cloud Security LIVE 2026: AI Risk & Trust | CSA Shadow AI Agents: Enterprise Governance | CSA Rethinking Non-Human Identity Security | CSA New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments More Than Half of Organizations Experience AI Agent Scope | CSA SANS Institute, Cloud Security Alliance, [un]prompted, and OWASP | CSA AI Agents Are Talking: Are You Listening? | CSA Software Supply Chain Security Needs an Upgrade Choosing the Right AI Standard: 7-Point Guide | CSA Audience-Driven Authorization for AI Agents | CSA A CISO's Guide to Cloud Security Architecture | CSA Who’s Behind That Action? The AI Agent Identity Crisis SSCF Adoption for SaaS Security | CSA Mythos and the Vulnpocalypse: Cloud Defenses | CSA AI Security Risks and Data Visibility | CSA From Compliance to Credibility with CAIQ/CCM | CSA The State of Cybersecurity in the Finance Sector: Six Trends to Watch EU AI Act Compliance with prEN 18286 & ISO 42001 | CSA AI Security in the Cloud: Exposure Management | CSA Rethinking Incident Response as Engineering System | CSA Defense Depends on the Creator: AI Security | CSA ATF: Zero Trust for AI Agents | CSA Cybersecurity Needs a New Data Architecture | CSA CSA STAR v4.1 Updates for Cloud Security | CSA Unstructured Data Surges as Enterprises Struggle to Maintain | CSA SC Media Names Cloud Security Alliance’s Trusted AI Safety | CSA Exposed AWS Key Leads to Full Account Takeover | CSA Post-Quantum Cloud Migration for CSA Members | CSA AI Identity Security Compliance Checklist | CSA The Agentic Trust Deficit: MCP's Authentication Vacuum | CSA More Than Two-Thirds of Organizations Cannot Clearly Distinguish | CSA AI Cybersecurity 2026: Insights from 1,500 Leaders | CSA Three-Body Security: Data, AI & Identity | CSA IAM as Safety for AI-Controlled Systems | CSA Kubernetes Cost Savings and Security Debt | CSA Code to Cloud Security: Unified Exposure Management | CSA Retail Misconfigurations Attackers Exploit | CSA Rethinking Authorization for the Age of Agentic AI | CSA Enterprise AI: Guardrails to Governance | CSA
Agentic Payments in Financial Services | CSA
2026-06-09 · via Cloud Security Alliance

Imagine telling an AI assistant: “Find me the best flight to Chicago next Thursday. Book a hotel within walking distance of the conference center, stay under my travel budget, and use my rewards points if it makes sense.”Cover of The State of Cloud and AI for Financial Services 2026

Now imagine that assistant not only making recommendations, but actually completing the purchases on your behalf. No extra approvals, switching between apps, or manually entering payment information.

That is the emerging reality of agentic payments.

AI agents are quickly evolving from passive assistants into systems capable of taking action. They can compare products, interact with vendors, negotiate prices, invoke APIs, and execute financial transactions with no human involvement. For financial institutions, this represents a major shift in how digital commerce may operate over the next decade.

CSA and Anjuna’s new State of Cloud and AI for Financial Services 2026 survey report examines this shift. Eighty-five percent of respondents believe AI agents will “initiate and execute payment transactions” on behalf of consumers. Even more telling, 65% believe this shift will require “an entirely new model for authorization.”

These findings highlight how modern payment systems are built around the assumption that a human is directly present when money moves. Agentic AI changes that assumption entirely. How will financial institutions prove that an autonomous transaction was legitimate, authorized, bounded, and auditable?

Below, explore why agentic payments represent more than just another AI use case. Learn why they signal a fundamental shift in how financial institutions need to think about identity, trust, and security. As AI agents move into operational and transactional roles, financial institutions need to rethink how they secure financial decision-making. They need to do this before autonomous commerce becomes mainstream.

AI Agents Are Moving From Assistance to Action

The report shows that AI agents are no longer a future-state concept. Sixty-two percent of respondents say their organization is using AI agents. These agents are already appearing across customer service, IT operations, back-office automation, fraud detection, AML compliance, personalized advice, credit underwriting, and trading.

Not all agents are equally autonomous. Some operate as task-oriented bots. Others are more capable systems that can reason across context, use tools, and act with limited human intervention.

Fifty-five percent of organizations using agents operate under “limited autonomy,” where AI systems perform tasks with active human oversight. Another 33% allow “conditional autonomy,” where AI acts by itself in low-risk scenarios under defined guardrails. Five percent have already granted “high autonomy,” allowing AI to operate by itself for critical actions.

That 5% may sound small, but in financial services it is strategically significant. The industry has already crossed from AI assistance to AI action. Payments are the next obvious frontier.

Why Existing Authorization Models Fall Short

Today’s payment authorization models generally rely on proof that a person approved a transaction at a specific moment. Even when organizations heavily automate the process behind the scenes, the trust anchor is still human intent. The account holder clicked, tapped, confirmed, or authenticated.

Agentic payments introduce a delegated software actor. The user may ask that actor to perform a broad objective. Think “book the cheapest refundable flight under $600” or “renew this subscription if the price has not increased.”

The consumer may not be present when the final transaction occurs. The agent may compare options, interact with merchants, invoke APIs, negotiate terms, and execute payment within pre-approved limits.

This creates difficult questions for banks, card networks, fintechs, merchants, and regulators:

  1. is the identity behind the transaction: the consumer, the agent, the merchant, or the platform operating the agent?
  2. exactly did the user authorize: a specific payment, a category of purchases, a merchant, or a task outcome?
  3. long does delegated authority last?
  4. the consumer revoke authority instantly?
  5. logs prove the agent acted within its mandate?
  6. should fraud monitoring distinguish between legitimate agent behavior and automated abuse?

The report frames this as a need for “a new trust anchor before agentic commerce can possibly scale.” Without a defensible authorization model, agentic payments risk becoming either too constrained or too permissive.

The Security Problem Is Also a Data Problem

The report’s broader AI risk findings help explain why you cannot treat authorization as a payments-only issue. Respondents identified “leakage of sensitive data” as the top financial services AI security concern at 61%. The report notes that this leakage may arise from “prompts, files, chat history or other means.”

Agentic payments tightly connect authorization and data protection. An agent may need access to account balances, invoices, loyalty accounts, shipping details, personal preferences, and merchant credentials. It may also use retrieval-augmented generation connectors or external tools to complete a task. Every connection expands the control surface.

That's why excessive/weak permissions for AI-powered tools, cited by 33% of respondents, is such an important signal. Twenty-seven percent cited unauthorized access or exfiltration through RAG connectors or retrieval tools. Nineteen percent cited credential or secret exposure through API keys, tokens, system prompts, and plugins.

So an agent that can pay can also expose data, misuse credentials, or call the wrong tool if you haven't tightly scoped its permissions. Financial institutions should not think of agentic payments as a standalone innovation project. They should treat it as an identity, authorization, data governance, monitoring, and incident response challenge.

What “Good” Could Look Like

The report points toward several practical control themes. Treat agent identity as a first-class identity and access management object. Do not treat it as an invisible extension of a user account or application. That means verifiable credentials, scoped permissions, time-bounded authority, behavioral monitoring, auditable action logs, and automated credential rotation.

For payments, this could translate into authorization policies that are machine-enforceable and understandable to consumers. Higher-risk actions could require step-up approval. Unusual behavior could trigger revocation or fraud review. Every action should be attributable to the human or organizational principal on whose behalf the agent acted.

Financial institutions will also need stronger observability. Twenty percent of respondents reported AI-related incidents, while another 21% were unsure whether such incidents had occurred. If institutions cannot see what agents are doing, they cannot reliably investigate, report, or learn from failures.

Trust Remains the Business Model

The report closes with this: “In financial services, trust remains the business model.” Agentic payments will test that trust in new ways.

Consumers will want convenience, merchants will want conversion, and AI platforms will want reach. Financial institutions will need to ensure that autonomous transactions are secure, authorized, explainable, and compliant.

Agentic payments are a new operating model for delegated financial action. The organizations that prepare now will be better positioned to support innovation without losing control. Invest in agent-aware identity governance, data controls at the point of AI interaction, and retrieval-layer authorization.

The future of payments may be agent-driven. The future of trust will still depend on governance.

Check Out the Full Report

Agentic payments are only one piece of a much larger transformation happening across financial services. The full survey report explores how cloud infrastructure, AI adoption, governance, identity management, and third-party risk are converging.

Beyond payments, the report dives into:

  • 61% of respondents see sensitive data leakage as the top AI risk
  • financial institutions are approaching AI agent autonomy and governance
  • growing challenge of non-human identities and machine credentials
  • rise of AI-specific security tooling such as AI Security Posture Management (AISPM)
  • third-party and supply chain risk remain the industry’s top cloud concern
  • regulations like DORA and the EU AI Act are reshaping operational expectations
  • recommendations for financial institutions, cloud providers, and regulators

Additionally, the report captures the reality that many security teams are already experiencing firsthand: AI adoption is moving faster than governance maturity. Financial institutions are no longer debating whether AI belongs in operations. They are trying to determine how to deploy it safely, monitor it effectively, and maintain trust as autonomy increases.

If your organization is exploring AI agents, modern cloud, or new financial services risks, check out the full report. It provides a valuable benchmark for where the industry stands today and where it appears to be heading next.