The Delegation Chain
Europe has built the identity half of agentic commerce ahead of anyone else. The authorization half is still open. Where European payment law and the agentic payment protocols meet, they describe the same boundary from opposite directions.
The boundary the framework already identified
In May I published a framework describing six levels of autonomous buying. I argued that the hardest step is not Level 4 or 5. It is the move from Level 2 to Level 3: the moment a human stops approving each transaction. I called it a governance decision rather than a technology one. I have spent the past weeks reading European payment law alongside the agentic payment protocols, and the two turn out to be describing the exact same boundary from opposite directions.
The chain of who acts on whose behalf
Consider the chain of who acts on whose behalf. A person authenticates and a person buys. A person instructs an agent, the agent prepares, the person still commits. An agent initiates, another agent negotiates, the person still commits. Then the step where the person authorizes upfront and the agent commits alone. Then the chain with no person in it at all. The first three are one situation. The last two are another. Everything that matters in European agentic commerce sits on the line between them.
Five levels of delegation. The red line marks the point at which no human authenticates the specific amount and the specific payee.
Where the EUDI Wallet solves it
For the first three, Europe is close to a solved problem, and the EUDI Wallet is what solves it. By design, it supports all three PSD2 authentication factors and dynamic linking. From late 2027, financial institutions applying strong customer authentication must accept it. The specification work is already published as TS12. A traveler, a patient, a buyer proves who they are once, cryptographically, at assurance level high, and shares only the attributes the transaction requires. The friction that has defined European checkout since PSD2 largely disappears. That is a genuine achievement, and it deserves more attention than it is getting.
Where dynamic linking breaks
The fourth step is where it becomes interesting. Dynamic linking requires the authentication to be uniquely tied to the specific amount and the specific payee. The agentic payment protocols work differently by design: the user signs an intent mandate upfront with a price cap, a time window, and a merchant allowlist, and the agent generates the cart mandate itself when conditions are met. At the moment the amount and the payee become concrete, no human authenticates anything. A price cap is not an amount. An allowlist is not a payee. The wallet solves authentication beautifully, and in doing so makes visible a question it was never designed to answer. Not a flaw in the wallet. A boundary that was always there, now clearly lit.
Three directions worth exploring
I do not think this is unsolvable, and I would rather contribute than complain.
The first direction is to treat the intent mandate itself as the dynamically linked act, with the wallet performing strong customer authentication at mandate signing against the constraint set rather than the final amount. That requires a regulatory view on whether a bounded constraint can stand in for a specific amount, and the European Banking Authority is already developing rulebooks in this area.
The second is to use the wallet to attest the delegation rather than the payment: a qualified electronic attestation that this agent acts for this person within these limits, verifiable by the issuer at authorization time. The wallet already issues attestations of attributes. Delegation is an attribute.
The third is to accept that the fourth step belongs under existing exemptions, low value, recurring, trusted beneficiary, and to build agentic commerce inside those boundaries rather than around them.
Specification versus law
What I would not do is assume the American protocols and the European regulation will simply meet in the middle. One is a specification. The other is law, with liability attached: where strong customer authentication is not applied, the payment service provider carries the loss. Travel distribution is one of the clearest live cases of this, because every booking carries a real person with real identity data and a payment that has to clear.
The week this argument arrived
For completeness, and because the timing is difficult to ignore: we are discussing how much authority to delegate to machines in the same week that OpenAI disclosed that two of its models broke out of a controlled test environment and hacked into another company's production infrastructure in order to cheat on an evaluation. The company called it an unprecedented cyber incident. Anthropic has reported a comparable sandbox escape during safety testing. The models in the OpenAI case were being tested without guardrails limiting cyber capability, and OpenAI's own account is that they were fixated on solving a narrow benchmark. That is not emergent agency. It is a system optimizing exactly what it was told to optimize, with no regard for the boundary it was told to stay inside. Which is precisely the risk profile of an agent holding an intent mandate.
The half that is still open
None of this makes agentic commerce impossible. It does explain why the European instinct to bind authority to a verified human, and to make someone liable when that binding fails, looks less like regulatory caution and more like foresight. Europe has built the identity half of agentic commerce ahead of anyone else. The authorization half is still open. I would like to see that conversation happen between the people writing the protocols and the people writing the rulebooks, before the market decides it by default. The peer-reviewable foundation behind this framework is published on SSRN.
Start the conversation
Whether you are mapping agentic exposure, working through delegation governance, or preparing for the EUDI Wallet acceptance obligation, contraco can help you move before the boundary is decided for you.
Contact us