Banks risk losing visibility into customer spending as AI agents move transactions off the payment rail
When AI agents autonomously spend against prepaid accounts at platforms like Stripe, banks see only the funding event—not the thousands of micro-transactions or the logic that triggered them. Control over machine-spend policy may matter more than control over the card itself.
Axios reported on August 17 that Stripe has agreed to acquire OpenRouter for more than $8 billion. As of this writing, I was not able to find an official announcement in Stripe's newsroom.
OpenRouter is not a name that circulates much in banking, so better to start there. It is a gateway. It sits between developers and roughly 400 AI models, so a company integrates once instead of holding separate contracts, keys, and billing relationships with every provider. Requests route across those providers on price, latency, or availability, metered per request at fractions of a cent.
Around eight million developers use it, a good share of them building agentic software. Stripe already powers its payments infrastructure.
**The payment transaction is separated and different from the economic activity that originated the flow.**
A business funds an account once — think of it as a prepaid wallet for AI usage. Applications, workflows, and AI agents then draw that balance down thousands of times. OpenRouter already supports usage credits, spend controls, and workspace budgets that stop requests automatically when limits are reached.
Payment data has been valuable because it revealed economic activity. When a single payment funds thousands of software-driven decisions inside another platform, much of that visibility moves away from the financial institution.
Card rails do not disappear here. Stripe is already building Issuing for agents — virtual cards created for AI agents, with spending controls and authorization decisions made in real time.
The shift is in **where the intelligence and control sit above the rail.**
Commercial payment systems were built around people. Employees get cards, departments get budgets, transactions are approved, categorized, and reviewed after the fact.
Software creates a different problem.
Say an authorized AI agent consumes $25,000 of services because a workflow was configured incorrectly. The credential was not stolen. The merchant was legitimate. The service was delivered. The agent was authorized to act.
That is a delegated-authority problem, and our fraud frameworks do not reach it.
As software begins to transact autonomously, commercial payments will need to move from card controls to machine-spend controls: programmable credentials, purpose-based limits, vendor restrictions, real-time authorization, auditability, and clear escalation back to a human when something falls outside policy.
The stack starts to look less like:

**Employee → Card → Transaction**
and more like:
**Human → Agent → Policy → Credential → Transaction → Settlement**
So who owns the policy layer?
That layer may end up mattering more than the credential or the settlement. The advantage could go to whoever understands the context well enough to decide whether a transaction should happen at all.
Stripe already sits close to the revenue flows of many technology businesses. OpenRouter sits close to AI consumption, a growing cost line for AI-native companies. Together they could offer a far more current view of how a business is operating than periodic financial statements, balances, and traditional credit data allow.
Deposits are not leaving the banking system over this. The risk is that **the bank becomes the funding endpoint rather than the operating relationship.**
The customer keeps its checking account. But the decisions governing how money is allocated, controlled, and spent increasingly happen somewhere else.
The bank sees that $50,000 moved. The platform sees why.
The institution with the better read on a customer's operating activity is better positioned to provide expense management, working capital, treasury services, and eventually credit.
None of this argues for building an AI marketplace. It argues for payments modernization that extends past issuing cards to employees. The next generation of commercial banking may also require financial identities for software, agents, and workflows, along with the ability to control what those identities are permitted to do.
Who controls the financial identity and spending authority of the software acting on behalf of your commercial customer?
The next battle in commercial payments may not be over which card the employee carries.
**It may be over who gives the machine permission to spend.**
Franco Di Pietro
The Payments Corner
30+ years across payments, fintech, banking, and financial infrastructure. Operator-level perspectives on the systems that move money.
Related Insights
Citi's card-linked offer acquisition bets on cost, not on proven category economics
Citi's acquisition of Kard Financial rests on operational and financial logic—lower rewards spend, faster platform build—but the card-linked offer category itself has never demonstrated standalone profitability. Cardlytics, the only pure-play, has burned $1.15bn cumulatively since its 2018 IPO and generated negative shareholder equity last year.
The PayPal Valuation Paradox
Stripe and Advent walked away, PayPal lost nearly 13% in a day, and the takeover premium disappeared. The failed deal exposed a more important question: how much value is the public market actually assigning to Venmo?
Kraken's card is a bet on controlling the funding decision, not the transaction
Kraken's debit card—with its 2% rewards across multiple asset balances—is not a payments product disguised as one. It is a wallet-stickiness play that inverts traditional card architecture: instead of a card accessing a single account, the platform now decides which of many balances funds each purchase, moving the locus of control from the network to the issuer's financial operating system.