2026-07-31
AI agents can now move money via x402, Stripe Agentic, wire APIs, and USDC. Here's the 10-rule runtime policy pack that keeps them survivable under PSD3, Reg-E, and OFAC.
Load-bearing stat: 97% of agent-payment incidents in 2026 auditor postmortems trace to one of three missing controls: no per-agent daily cap, no 2-of-N on high-value flows, or no allowlist on destination addresses.
Read → 2026-06-29
If your AI agents touch cardholder data or move money, here's the concrete PCI-DSS v4.0 and SOC 2 Type II checklist with policy enforcement at the tool-call layer.
Load-bearing stat: PCI-DSS v4.0 Req 10 (logging) + Req 8 (access control) + SOC 2 CC6.1/CC7.2/CC8.1 cover ~80% of what a fintech AI agent compliance review will ask for.
Read → 2026-06-29
AI agents in healthcare touch PHI in 8 different ways. Here are the 7 HIPAA requirements that map directly to the agent's tool-call layer, with concrete controls.
Load-bearing stat: HIPAA Security Rule §164.312 has 5 implementation specs; only 2 are 'required' but 3 'addressable' specs become 'required' the moment your agent automates PHI access.
Read → 2026-06-29
AI agents moving USDC and other stablecoins need three guardrails: FATF Travel Rule compliance, 2-of-N approval for high-value transfers, and treasury wallet allowlists.
Load-bearing stat: FATF Recommendation 16 (Travel Rule) requires originator + beneficiary info on every VASP-to-VASP transfer over $1,000. AI agents moving USDC need this enforced at the tool-call layer.
Read →