
Agentic Authority: China's AI Commerce
China's agentic AI already pays at scale. The hard part is authority: who lets an AI agent spend, and who answers when it's wrong. One market solved it via escrow rails.
China's agentic AI already pays at scale. The hard part is authority: who lets an AI agent spend, up to what limit, and who answers when it's wrong. One market solved it first because of how its payment rails were built.
China's agentic AI is moving real money right now, at a scale most of the West is still announcing. Alipay processed more than 120 million AI Pay transactions in a single week in February 2026, and by late May that had crossed 300 million agent payments, across 95 percent of the mainstream agent frameworks (Xinhua, 26 May 2026). So capability is settled, and the thing that isn't is authority: who lets an AI agent spend, up to what amount, and what happens when it gets the order wrong.
120M+
That's a design problem, and it's why agentic payments is measured in years, not months. Most of what looks like an AI agent paying is a model making a suggestion and a person tapping approve. A few thin slices are genuinely hands-off. Full autonomy over real money is a long way off.
Capability was never the hard part
The model, the API, the token. Capability is close to solved and getting cheaper by the quarter. JD.com built a whole protocol for AI agents that pay. Amazon's "Buy for Me" AI agent completes a purchase on an outside site while the buyer watches. What everyone races on is capability. What nobody races on is permission, because permission isn't a feature. It's a decision.
Authority is a ladder, and the market shipped it independently
I've been writing about the step-up in autonomy as the Agentic Authority Escalation Model: capability first, then permission, and permission escalates in steps. A higher step only works if the design is more explicit about who is accountable. It sits alongside the Seven Dimensions framework I build on.
In June 2026, JD.com shipped the Agent Autonomous Payment Protocol, an L0 to L5 scale taken from autonomous driving. L0 is a person confirming every payment; L5 is the AI agent paying on its own. The run that matters is L3 and L4, where an agent can initiate inside a boundary a person set.

That's the strongest kind of validation: not that a framework reads well, but that it lands on the same shape when someone builds it independently.
The architectural reason one set of rails took it sooner
This isn't cultural, and it isn't a superiority story. It's structural.
Chinese marketplaces were built on escrow-style settlement. Money goes to a middle account, the seller ships, the buyer confirms the goods, and only then does the money release. There's a built-in step where a second party authorizes the final move. Add a delegated AI agent and that step already has a slot. The AI agent can act; the cash stays held until a condition clears.
Card rails are capture-then-settle. The money moves, and a dispute becomes a chargeback after the fact. No built-in hold where a conditional authorizer sits. Add an AI agent to a card rail and either you build that hold in, or you let it act on a standing mandate and hope the limits hold.
That's the mechanical reason the agent-payment slice widened in one place first, and it has nothing to do with who trusts the machine more. The trust sits in the settlement design. If you want an AI agent moving money, the question isn't how to make it trustworthy. It's how to make the release conditional, keep a second key, and leave a human signature on the move that matters.
For a leader deciding whether to push agentic AI into an operation, or an investor sizing the risk, three things.
- 1Authority is a boundary you design, not a benefit a strong model hands you. Set it, log it, make the budget a hard stop.
- 2Expect the failures to be integration and legacy systems, not the model.
- 3When a move is consequential and irreversible, keep a hold, a reversal window, and a human sign-off.

Authority, systems, reversibility. Those three are the test for whether an agentic deployment holds up or ships a headline and quietly stalls.
The same question in creator commerce
This isn't really a payments story. It's the authority question wherever a system makes a consequential call. In creator commerce, the consequential call is which creator to back and how much to commit.
I built a decision engine for that. TikSense measures a creator's ability to convert sales on a specific product. The number buyers assume matters, engagement, wasn't the number that mattered. A creator at 2 percent engagement on content-driven content is a different instrument from a creator at 2 percent on product content. Same number, opposite meaning. So the engine had to judge them on something else, and the decision that cost money, whether to back the creator, stayed with the operator.
Same shape. The system decides, the person authorizes the move that spends.
And it's the same thing the Seven Dimensions of Enterprise AI names. Governance & Containment is drawing the boundary. Human Judgment is the checkpoint. Calibration is knowing when the system is confident enough to act and when it should hand back to a person.
The AI agent can pay, and the capability was never the hard part. What's hard is deciding how much an AI agent is allowed to move, on what authority, and who answers when it moves it wrong. The deployments that hold up will be the ones that treated permission as something you design rather than something you bolt on at the end.
This lives wherever you already are, Substack, X, or LinkedIn, drawn from building TikSense.