Monthly · Issue 1 · September 2026

September Stories

Two reports the market published this month — and what they mean for the people who let agents act for them.

Every month we carry the stories that help our customers see the issues that are relevant to the integrity, the security and the quantum readiness of their workflows — told from the official reports, with the numbers exactly as the authors published them, and our reading kept in its own box. The danger is rarely where everyone is looking. It is where nobody has thought to look yet.

We open the dance with two. One measures the step every agent product sells you — and finds it is where the damage gets through. The other measures the rail the whole industry is building on — and finds it nearly empty.
Story 1 · Integrity

The approval step is where the overreach
gets through.

A study published on 27 August 2026 asked a simple question: when an agent proposes something you did not ask for, which kind of control stops it? One hundred and thirteen people with no software background each supervised a simulated working day — eighteen agent actions, seven of them overreach: real actions, outside what the person had actually asked for. Three controls were compared: approve every action yourself, let a model review every action, or write standing rules in advance — “allow”, “ask” or “never” — for each category of consequence.

113
people

Non-technical participants, each supervising an 18-action day with 7 overreach actions.

−20.1
points

Standing rules blocked less overreach than approving each action (95% CI −32.1 to −8.1).

133 / 148
approved by a human

Of the overreach actions that ran under standing rules, 133 ran because a person clicked approve. Fifteen slipped through an “allow” rule.

What the report found

People choose “ask” — then, in the moment, they say yes.

THE RECORD

Given the chance to decide in advance, participants set 114 of their 140 rules to “ask”. Every decision therefore came back to them at run time, in the middle of the day, one prompt after another — and at run time they approved the overreach. The authors call it a gap between preference and commitment: repeatedly choosing “ask” preserves case-by-case choice, but prevents a standing policy from settling anything in advance.

The uncomfortable reading is the plain one. Asked “may the agent do this?” while trying to get through a task, a normal person says yes. That is not a training problem and not a design flaw in one product. It is the shape of human attention, measured.

WHAT IT MEANS FOR YOUR WORKFLOW

Almost every agent product on the market sells the approval step: an inbox of pending actions, a promise to “check with you before sensitive actions”, a confirmation prompt. This study measures that the approval step is where the overreach gets through.

A mandate works the other way round. You state once, calmly, exactly what the agent may do — this amount, this recipient, this data, this window — and every action is checked against it, in the path, in a fraction of a millisecond, with nobody asked in the moment. What matches, runs. What does not, does not — and you hold a signed receipt either way. Your authority is spent once, when you write the mandate; never eighteen times a day under pressure.

Approval is where the overreach gets through — 133 of 148 times, measured. We don’t ask you in the moment. We bind the action to what you already allowed.
The official report

Ting Yan, “Do User-Authored Permission Policies Improve Protection Against AI Agent Overreach?”, arXiv 2608.27443, 27 August 2026 — arxiv.org/abs/2608.27443. All numbers on this page are the author’s; the reading in the shaded box is ours.

Story 2 · Security & payments

The agent-payment rail is almost
empty.

On 9 September 2026 the blockchain-analytics firm TRM Labs published the first rigorous measurement of the most-cited rail for “agents paying for things” — the x402 protocol, on which thousands of merchants had announced checkouts over the summer. They counted every settlement since May 2025, removed the noise, and then asked the only question that matters: how much of this is actually an agent?

198.9M
settlements

USD 52.7 million in total, on three public chains, since May 2025. 99.6% of it in one stablecoin.

~50%
removed as noise

Wallets paying themselves, bulk flows from one or two payers, sellers with fewer than ten buyers — leaving USD 25.6 million of plausible commerce.

0.6–7.5%
attributable to agents

Roughly USD 5,000 to 11,000 a month. The strict test required months of consistent pattern plus a public agent registry.

What the report found

The rail works. The agents are not on it.

THE RECORD

The infrastructure is real and it settles: hundreds of millions of tiny payments, almost all in one stablecoin. But once self-payments and scripted bulk flows are screened out, the share that behaves like an autonomous agent buying something is a rounding error on the headline.

TRM’s conclusion, in their words: “The rail already works. What is needed is accurate registration, counterparty reputation an agent can check on its own, and monitoring built for volume rather than value.” Agentic commerce, they add, requires agentic compliance rather than human-scaled controls.

WHAT IT MEANS FOR YOUR WORKFLOW

Read TRM’s list again — registration, a reputation an agent can verify on its own, monitoring by volume. It describes a receipt: a signed, independently verifiable record of who authorised what, for how much, to whom — without using the word. The rail cannot tell a mandated purchase from a script, so it cannot price it, insure it or refund it correctly. So the serious money stays off it.

That is the quiet reason the rail is empty. Not the technology — the missing object. A mandate the agent carries, and a receipt the rail, the issuer and your auditor can all verify, is what turns “an agent paid” into “an agent paid exactly what it was allowed to”.

The rail is empty because the mandate is missing. 198.9 million settlements, and USD 5–11K a month of it is agents — because nothing on the rail says what the agent was allowed to buy. A receipt does.
The official report

TRM Labs, “Who’s Actually Paying? Measuring AI Agent Payments Onchain”, 9 September 2026 — trmlabs.com/trm-tech-blog/whos-actually-paying-measuring-ai-agent-payments-onchain. All numbers on this page are TRM’s; the reading in the shaded box is ours.

How these stories are chosen

One rule: a primary source, published this month, by people who are not us. We quote their numbers as they printed them and keep our reading in its own box. Each story touches one of the three things that matter to a workflow that delegates to agents — its integrity (did the agent do exactly what it was allowed to?), its security (what could reach it, and what could leave?), and its quantum readiness (will the signatures under it still hold?). Next issue: October.

The mandate and the receipt, for the people in these stories.

WARRANT gives a person or a team a per-action mandate for their agents and a signed receipt for every action — verifiable by anyone, with no account.

See WARRANT The open mandate