π Hello, super humans! Somewhere in Copenhagen, an AI agent booked and paid for a coffee tasting session this week without anyone typing a password, approving a prompt, or even being in the room. That is either the most boring headline of the year or the first real look at what “the agent economy” means once actual money changes hands. We think it is the second one, so let’s get into it.
π° Quick Signals
- π§ AI: Elon Musk says xAI’s Colossus 2 could run more than 1.2 million Nvidia GB200 and GB300 chips by year end, roughly double today’s count, if chip supply cooperates.
- π€ Robotics: Amazon is investing $100 million in a new Indiana manufacturing facility to build hardware for its fulfillment and robotics operations across North America.
- π» Programming: A widely shared security argument says agent guardrails need to move inside the harness that executes an agent’s actions, since a blocked route is just a problem for an agent to route around.
- β‘ Electronics: Raspberry Pi boards are refusing to boot when they detect non-factory RAM, and the maker community is split on whether that is counterfeit-protection or a bricked-board own goal.
- π‘ Telecom: Lumen launched a bandwidth plan built for AI agents rather than people, betting that non-human traffic now makes up more than half the internet.
The Big Story: An AI agent just used your Mastercard, and nobody typed a password
Every “agentic commerce” pitch so far has been a demo. This week one of them processed a real payment, on a real bank’s real infrastructure, for a real customer, with no human clicking “confirm” at the moment of purchase.
What happened: Danske Bank and Mastercard completed Denmark’s first AI-agent payment on September 21, when a consumer’s AI assistant booked and paid for a coffee-tasting session on Mastercard’s Priceless.com experiences platform. The customer told the agent what they wanted; the agent found the listing, booked it, and paid with a Danske Bank-issued Mastercard, without the customer approving that specific purchase in the moment. PayOS orchestrated the transaction on the agent side, and it ran on Danske Bank’s live card-issuing systems, the same rails serving its 3.7 million retail customers, not a sandbox.
The details: The mechanism doing the work is Mastercard Agent Pay, which extends Mastercard’s existing tokenization network, the same one behind Apple Pay and Google Pay, with what it calls Agentic Tokens. An Agentic Token binds three things at once: a specific agent’s cryptographic identity, a specific consent policy the consumer set in advance (spend limit, allowed merchant categories, an expiry date), and a specific merchant scope. The raw card number never reaches the agent or the merchant, only the token does. Mastercard Payment Passkeys, built on the same FIDO2 and WebAuthn standards already used for passwordless logins, let the network confirm the agent is acting inside that pre-authorized scope without a real-time approval prompt. At checkout, the token passes through a certified processor exactly like a normal network token, and Mastercard’s authorization stack validates the policy and behavioral signals before it clears, which means most merchants need zero integration work to accept an agent’s purchase.
sequenceDiagram
participant C as Consumer
participant B as Danske Bank (issuer)
participant A as AI agent (PayOS)
participant M as Mastercard network
participant S as Merchant (Priceless.com)
C->>B: Enroll card, set policy (limit, categories, expiry)
B->>M: Bind Agentic Token to agent identity plus policy
C->>A: Book us a coffee tasting
A->>S: Find listing, start checkout
A->>M: Present Agentic Token, passkey-signed
M->>M: Check policy match and behavioral signals
M->>B: Authorize within pre-set limits
B-->>S: Payment settles
Note over C,M: No password, no per-purchase prompt: the policy was the approval
Mastercard is not alone at this layer: Visa’s Trusted Agent Protocol does the same job under different branding, and Google’s AP2 sits one level up as a settlement-agnostic envelope that can wrap either network’s tokens, or a stablecoin rail, depending on who is paying whom. The realistic shape of 2026 agentic commerce looks like a split stack: card rails for consumer purchases like this one, stablecoin rails for the machine-to-machine, agent-to-agent payments that never need a human in the loop at all.
Important
Our take: The interesting failure mode here is not “the agent bought the wrong thing,” it is “the policy was wrong from the start” and nobody notices for weeks, because there is no per-purchase prompt left to catch it. If you are building anything that touches Agent Pay, AP2, or a competing protocol, spend as much design effort on the consent-policy UI as you spend on the checkout flow itself; spend limits and merchant categories are coarse tools. FTC chair Andrew Ferguson said this same week that liability for what an agent does still sits with the developer and the business deploying it, not the agent, which is the right default and means “the agent did it” will not be a defense anyone gets to use. Test your policy boundaries like you would test auth, not like you would test a feature flag.
ποΈ More News
π§ AI
- Pope Leo XIV opened his France visit warning that unchecked AI risks building a “paradise of machines” that leaves humans behind, adding a religious voice to the AI-safety debate.
- The White House reportedly asked OpenAI and Anthropic to delay giving two new models to UK AI Security Institute testers pending its own security review, straining an alliance built on shared model access.
- UCLA Health is leading a $25 million, five-year federal effort with Mayo Clinic and the University of Wisconsin to test AI tools for Alzheimer’s and dementia diagnosis and care.
- Chinese cities are handing AI film studios free rent, living stipends, and compute vouchers, racing to turn short-form AI video into a subsidized local industry.
- FTC chair Andrew Ferguson said developers and the businesses deploying AI agents keep the legal liability for what those agents do, pushing back on any framing of agents as independent actors.
- OpenAI is reportedly set to preview GPT-6 Cyber, its fourth security-focused model of the year, alongside a dedicated cybersecurity product, at its September 29 DevDay.
- Alibaba’s Qwen team released Qwen3.8-Omni-Flash, a sparse mixture-of-experts model with a 1 million token context window that natively handles text, audio, and video in one pass.
- Warp raised $85 million and launched Warp 2.0, pitching itself as an “AI Head of HR” that runs payroll, benefits, and onboarding as programmable agents instead of chat replies.
π€ Robotics
- General Robotics is betting that robots need composable, task-specific skills rather than one giant foundation-model “brain,” arguing modular intelligence adapts faster across different hardware.
- CNH says labor shortages and rising costs are pushing more farmers toward autonomous and semi-autonomous equipment just to hold productivity steady.
- Scaling robotaxis from a handful of cities to thousands means solving unglamorous logistics first: fast, local vehicle-servicing infrastructure that does not exist yet at that scale.
π» Programming
- DHH’s Rails World 2026 keynote argued the coding-agent inflection already happened: 37signals has gone “pencils down” on handwritten code as its default way of working.
- git-bug shipped a distributed, offline-first bug tracker that stores issues, comments, and history inside the Git repo itself, syncing over an ordinary git push.
- Stanford’s DSPy hit version 3.4.0, the framework for programming rather than prompting language models, with a fresh round of async and optimizer improvements.
β‘ Electronics
- Delta Electronics unveiled integrated 800-VDC power and cooling for AI factories, folding two separate infrastructure problems into one designed system.
- STMicroelectronics says its SiC-based Interport platform reaches 400 kW in essentially the same footprint as prior designs, at better than 98.5% efficiency.
- Microchip added energy monitoring to its 48V power system lineup, extending visibility into the mid-voltage distribution racks AI data centers increasingly run on.
π‘ Telecom
- CTIA and USTelecom won partial relief from a proposed broadband router ban, trimming one item off carriers’ regulatory-compliance list.
- Vecima posted record sales and picked up more virtual-CMTS deals, riding cable operators’ push to move headend hardware into software.
- Vocus will build a 4,000-kilometer ducted fiber route connecting Brisbane and Darwin, adding a second inland path across Australia.
- Early 6G standards talk is raising more questions than it answers about how carriers actually migrate off 5G, rather than just running both at once.
π¨βπ» Code Corner
Today’s Big Story runs on a policy check happening somewhere inside Mastercard’s network before an Agentic Token is allowed to clear. Here is the toy version of that check: three gates, all of which have to pass before a machine gets to spend a human’s money.
"""Toy version of an Agentic Token policy check at authorization time."""
from dataclasses import dataclass
from datetime import date
@dataclass
class AgentPolicy:
max_amount: float
allowed_categories: set[str]
expires: date
def authorize(policy: AgentPolicy, amount: float, category: str, today: date) -> bool:
if today > policy.expires:
return False # consent window closed; no fallback to "ask the user"
if amount > policy.max_amount:
return False # over budget, reject even if everything else checks out
if category not in policy.allowed_categories:
return False # agent wandered outside its lane
return True
policy = AgentPolicy(
max_amount=75.00,
allowed_categories={"dining", "experiences"},
expires=date(2026, 12, 31),
)
print(authorize(policy, amount=42.00, category="experiences", today=date(2026, 9, 27))) # True
print(authorize(policy, amount=42.00, category="electronics", today=date(2026, 9, 27))) # False, wrong category
Tip
Real agentic-payment networks add a fourth check this snippet skips: behavioral signals, the same fraud-scoring models issuers already run on human-swiped cards, applied to agent transactions too. A policy that looks airtight on paper still gets backstopped by whether the transaction pattern looks like the agent, or like someone who stole the agent’s token.
π§° Toolbox
- CLI-Anything: turns desktop software like Blender, GIMP, LibreOffice, and OBS into an agent-native CLI with one command, so agents get a real interface instead of clicking around a GUI.
- jevmem: writes a living project-memory file from your Claude Code, Cursor, or Codex sessions, keeping decisions, constraints, and open bugs around after the agent’s context resets.
- wafer.space: a budget silicon-fabrication service that got its own custom microprocessor designed, taped out, and running this week, for anyone who wants a chip instead of a board.
- Docker Cloud Sandboxes: lets an agent start work in a free local sandbox and move it to the cloud with one command when a job needs more horsepower or a hundred parallel tasks.
π οΈ Build of the Week (rotating)
Pocket Tank: a pocket-sized digital aquarium where the fish are steered by a large language model small enough to fit on the microcontroller in your hand.
- Difficulty: Intermediate
- Parts: ESP32-S3, 1.8-inch AMOLED touchscreen, a custom LLM distilled down to run on-device, 3D-printed enclosure
- Why we like it: the swimming animation is ordinary rendering code, but a genuinely condensed LLM decides what each fish wants to do next based on tank conditions, with no cloud call involved. It is a fun toy, and also a real answer to how small an agent can get before it stops being useful.
π From the Blog
- Turning Pixels Into Something the AI Can Eat: the third episode in the video-analytics series, on what happens to a frame once the camera and the network are done with it and it is the model’s turn.
- Building Your First Neuron From Scratch: weights, bias, and activation worked through by hand instead of imported from a framework, good background if today’s agent-policy code scratched an itch.
- The Network Behind the Cameras: the unglamorous plumbing that moves pixels across a network fast enough that nothing chokes.
π The Bot Saysβ¦
DHH opened Rails World 2026 by declaring “pencils down” on handwritten code at 37signals: roughly 3% of this year’s Ruby was typed by a human, agents produced about 150,000 lines in August alone, and he says that is 60 times his own old annual average. Somewhere, a keyboard is filing for unemployment. Watch the keynote if you want to see a man make peace with that in real time.
That’s all for today! Reply and tell us: if your own bank rolled out agent payments tomorrow, what spend limit would you actually set?

