AI Dispatch
The wirewireAug 25, 2026

Stripe's Agentic Commerce Protocol lets AI agents spend user funds; company discloses no liability cover for agent transactions

Stripe processed $1.9 trillion in payments in 2025 and now lets AI agents earn and spend funds on a user's behalf through its agent toolkit and Agentic Commerce Protocol; its site publishes extensive general security controls but no insurance, liability cap or indemnification specific to agent-initiated transactions.

Stripe has built an "agent toolkit" that "allows your agents to help you earn and spend funds, expanding their capabilities," according to the company's site reviewed by AI Dispatch, and supports the "Agentic Commerce Protocol (ACP)" for what it calls agentic commerce. The company processed "1.9T in payments volume" in 2025 and handles "500M+ API requests per day," its site states.

Stripe publishes extensive general security and governance disclosures. Customers "can also view audit logs of important account changes and activity in your security history," and the company says "Code changes are recorded in an immutable, tamper-evident log." Stripe's site says it has been "certified us to PCI Service Provider Level 1" and that "Actions within the most sensitive areas of the infrastructure need a human review." Card and bank data sit in what the company calls its Card Data Vault, in "an isolated Amazon Web Services (AWS) environment" that "A dedicated team manages," per the site. Stripe also says it hires "industry-leading security companies to perform third-party scans of our systems" and that its own security teams run "penetration tests and red team exercises" against its infrastructure.

None of that disclosure is specific to the agent toolkit or the Agentic Commerce Protocol. Stripe's site publishes no insurance coverage, liability cap, indemnification terms, coverage limits or settlement mechanism for transactions an AI agent initiates on a user's behalf — all of those fields register as no public information available in AI Dispatch's index, most recently checked Aug. 25.

The absence matters because of what the agent toolkit is built to do: let software, rather than a person, authorize the movement of money. Stripe's general security posture — audit logging, PCI certification, third-party penetration testing — is unusually well documented compared with most vendors AI Dispatch has reviewed. None of it answers what the index's trust-gap rubric scores separately under insurance_indemnity and outcome_settlement: who is liable, and on what terms, when an autonomous agent using Stripe's rails spends money it should not have.

Entries in this piece 1

Published index entries backed by the same source documents this piece cites.

Sources 11

  1. The agent toolkit allows your agents to help you earn and spend funds, expanding their capabilities.
    stripe.com · checked Aug 14, 2026
  2. Agentic Commerce Protocol (ACP)
    stripe.com · checked Aug 6, 2026
  3. 1.9T in payments volume processed in 2025
    stripe.com · checked Aug 6, 2026
  4. 500M+ API requests per day
    stripe.com · checked Aug 6, 2026
  5. You can also view audit logs of important account changes and activity in your security history
    stripe.com · checked Aug 14, 2026
  6. Code changes are recorded in an immutable, tamper-evident log.
    stripe.com · checked Aug 14, 2026
  7. certified us to PCI Service Provider Level 1
    stripe.com · checked Aug 14, 2026
  8. Actions within the most sensitive areas of the infrastructure need a human review.
    stripe.com · checked Aug 14, 2026
  9. A dedicated team manages our CDV in an isolated Amazon Web Services (AWS) environment
    stripe.com · checked Aug 21, 2026
  10. We hire industry-leading security companies to perform third-party scans of our systems
    stripe.com · checked Aug 14, 2026
  11. Our security teams test our infrastructure regularly by scanning for vulnerabilities and conducting penetration tests and red team exercises.
    stripe.com · checked Aug 21, 2026