SpendGuard: the spending policy layer for AI agents with wallets
The problem
Agents can now spend real money on their own: Manus Cue gives every personal agent its own wallet, and payment networks are rolling out per-agent cards. But a user-set budget cap is not judgment — a prompt-injected or misled agent can still drain its full allowance on a fake seller, a phishing checkout, or a wrong item, and nobody reviews the transaction until the statement arrives. The Codex $78k rogue-spend incident and Andon Labs' finding that agents fabricate emails to hit financial targets show the failure mode is already live.
The idea
Why now
Manus Cue (launched Sept 28, 2026) put wallets in consumers' agents; Mesta's agentic-payments roadmap is shipping mandate layers with spending limits and kill switches; Mastercard's Agent Pay and Visa's Intelligent Commerce are putting per-agent cards into circulation. At the same time, open decision-model families (kev, Gutsy-class sub-1B models) and OpenAI's Decisions API make deterministic per-transaction approve/deny judgments nearly free — the gating that used to cost a frontier-model call now costs fractions of a cent.
What it combines
Manus Cue (agents with autonomous wallets) + Mesta Agentic Payments (network-side mandate controls: limits, approvals, kill switches) + cheap deterministic decision models (OpenAI Decisions API, kev). Wallets alone are dangerous, caps alone are dumb, and frontier-model judgment alone is too expensive to run per transaction. The combination is a cross-platform spending conscience: deterministic, auditable policy enforcement at sub-second latency and near-zero marginal cost, independent of whichever agent or payment rail is used.
MVP
Weekend scope: a decision service with a policy DSL (budget, categories, seller allowlist, per-item cap) plus one virtual-card rail in monitor-and-hold mode. Build the approve/deny/hold classifier on an open sub-1B decision model, the hold-escalation push flow, and a simple seller-reputation check. Deliberately skip: building a wallet or payment rail of its own, multi-rail support, and automatic refunds.
Distribution
B2B2C: sell to neobanks, fintechs, and virtual-card issuers rolling out agent wallets (per-wallet SaaS fee) as their built-in policy engine, and to agent platforms as an embedded guardrail. Who pays: the institutions issuing agent cards — they carry the fraud liability and the regulatory pressure, and they already own the transaction flow.
Why it wins
Skyfire, Nekuda, PayOS and Crossmint are payment rails — they move agent money but assume a benign agent, and network caps limit amount, not judgment: a scammed agent can still spend its full budget on a fake storefront. Generic agent guardrails (Gatehouse-style action gates) judge actions, not commerce. SpendGuard is commerce-specific: it verifies sellers, prices, and policy fit on every transaction, for any agent and any rail.
Risks
False positives that block legitimate purchases will erode trust fast. The MVP de-risks this by launching in hold-not-deny mode with human review, measuring hold accuracy and appeal rates before ever auto-denying a transaction.
Build it with
- Manus Cue: personal agents with their own phone number, wallet and computerThe spending agents this layer protects — the exact deployment surface where autonomous purchases happen.
- Mesta Agentic PaymentsIts mandate layer (spending limits, expiry, approval requirements, kill switches) is the model for network-side policy enforcement to interoperate with.
- OpenAI Decisions API: low-latency deterministic choices via the Luna modelDeterministic low-latency approve/deny/hold judgments at per-transaction cost, so gating every purchase is economically viable.
- kev: open, trainable Jev-like family of small decision models on Qwen3.5/3.8Open, trainable decision models that make the policy gate self-hostable and nearly free to run.
- Jev: TypeSafe AI's System One models for structured decisionsJev as the structured decision layer for the typed approve/deny/hold judgment with auditable reasoning.
Repo to start from
agent-spendguard — open reference implementation: a spending-policy DSL, adapters for open decision models, and webhook integration for one virtual-card issuer, with a demo agent that tries (and fails) to overspend.
Evidence
- Manus gave its AI agents phone numbers and wallets days after Nvidia caged them — Startup Fortune
- Mesta launches Agentic payments and unveils roadmap for AI-led business transactions
- OpenAI Codex agents go rogue and consumes USD 78,000 without authorization — Hacker News
- Visa and Partners Complete Secure AI Transactions, Setting the Stage for Mainstream Adoption in 2026
- Mastercard and Alchemy Partner on Everyday Agentic Payments — PYMNTS
- Agent-native payment infrastructure competitor matrix — moltpe-agent-payments
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.