More than one well-funded team in agentic payments is making the same bet right now: a unified stack, built from scratch, hub-and-spoke, where external rails feed in until the network is dense enough to settle natively on one ledger. It is a coherent strategy, and an honest one. It also has a hidden assumption baked into it, and the assumption is doing most of the work.
The assumption is that the rails an agent needs to reach are, eventually, the kind of thing a private ledger can absorb. For cards and ACH, that is roughly true, they are private infrastructure already, owned by companies that can be routed around or partnered with over time. For most of the rest of the world's payment volume, it is not true, and no amount of scale changes that.
Most of the world's payment volume does not move through rails a private company can eventually own. It moves through rails a central bank already owns.
The rails outside the card networks are not spokes waiting to be absorbed
Pix is not a payment company's API that a bigger ledger could someday route around. It is Brazil's central bank infrastructure, real-time, free, and mandatory for every regulated institution in the country to support. SPEI is the same shape in Mexico. UPI is the same shape in India, at a volume that dwarfs anything card-based.
This is not a maturity gap, the kind a good enough product closes over time. It is jurisdiction. No amount of network density lets a private ledger become the settlement layer for a sovereign instant-payment scheme a central bank built and mandates by law. The hub-and-spoke model works exactly as well as it is supposed to, for exactly the rails that are structurally spokes: cards, ACH, the fragmented private infrastructure of one country. It does not generalize to the rest of the map, and the rest of the map is most of the world's transaction volume.
We made a version of this argument before, about a narrower case: x402's power was never the coin, it was the shape of the handshake, and that shape works on Pix without anyone's ledger absorbing anything. The same logic applies one level up. If the winning primitive is a single ledger, LatAm, India, and most of the rest of the world are permanently excluded from the winner's map. If the winning primitive is an authorization that travels, with the same guarantees, across whichever rail an agent lands on, the map has no edge.
A promise is not the same as proof
The easy answer to "who is liable if the agent gets it wrong" is a promise: trust the platform to have honored the instruction, and trust it to admit when it did not. In a market this early, that is a reasonable place to start. It will not scale to the volume this category is chasing.
The alternative is not a better promise. It is removing the need for one. Every debit we settle is scoped to a mandate the account holder signed: an amount cap, a merchant or category allowlist, an expiry, revocable at any time. Every settlement seals a hash-chained receipt binding that mandate to the payment to the delivery it paid for. Liability is not something we assert after the fact. It is something anyone, the account holder, the merchant, a regulator, can verify after the fact, without calling us to ask what happened.
The identity question does not need a philosophical answer
Every serious agent-payments company eventually runs into the same open question. Tie an agent's identity to a stable identifier bound to its operator's legal identity, the way most of the category does today, and there is no clean answer to what happens when the code changes. At what point does a patched, retrained, or rewritten agent become a different entity? Nobody has a good answer, because the question itself is the wrong shape.
Do not try to decide whether the agent is still "the same agent" after it was updated. Anchor identity to the mandate, not to the software. Each mandate is its own signed, scoped credential: this authority, this cap, this allowlist, this expiry, cryptographically bound to the account holder who granted it. Whatever code is executing on the other end, the only question that matters at settlement time is whether this specific authorization is still valid. The agent can be rewritten daily. The mandate either still holds or it does not.
You do not need to know what an agent is to know what it is allowed to spend.
Where this actually points
The agentic-payments market will not resolve into one company's ledger. Not for lack of ambition anywhere in the category, but because the rails that carry most of the world's money are not for sale, are not for absorbing, and are not going to become anyone's spoke. Brazil's central bank is not going to route Pix through a private ledger, and neither is Mexico's, or India's, or anyone else's. That is not a temporary market inefficiency. It is the permanent shape of a world with more than one government in it.
The layer that wins is the one whose authorization means the same thing everywhere it lands: on a card, on Pix, on a stablecoin, on whatever ships next. Not by building all of it, by governing the spend on top of it, with a receipt that survives the question of which rail actually moved the money. We are building that layer LatAm-first, on purpose, because it is the part of the map every unified-stack bet skips, and it is not a rounding error.
The rails will stay plural. The authorization does not have to.
Fabiano Cruz is co-founder of CodeSpar. Read the companion piece, One Authorization, Any Rail.