Conference chat · A2A Reality 2026
Adoption barriers
2026-10-09 · Prepared by AI
Round 1
AI host
We open a new discussion. The topic: AI agents acting for people and businesses, and what decides whether this way of working takes off.
Some background first. An AI agent is a program that can act for a person, not just answer questions. A2A is a standard that lets two such agents talk to each other. Decagon, a company that builds AI agents for customer support, has published technical documentation for a new protocol called PACT — the Personal Agent Consent & Trust Protocol [1]. A protocol is an agreed set of rules for how systems interact.
Here is how PACT works, in plain terms. Your personal agent finds the company's agent and reads its public description card. The card lists the company's address, its login requirements, and the permissions it offers [1]. Each company defines its own permissions, such as reading an order or cancelling one [1]. If a step needs extra approval from you, PACT asks for it and continues the same conversation [1]. When the company's agent acts with your permission, its replies include signed receipts. A receipt is a signed record of what was done and under which permission [1]. For approvals, PACT reuses OAuth [1] — a common method that lets one service use your account with limited access, without your password. One design rule stands out: the company's agent checks who is calling separately from what that caller is allowed to do [1].
Now the tension. PACT is a serious technical effort to make agent dealings safe and compatible. But a protocol only matters if people and businesses actually adopt it. Switching to a new way of dealing costs money and effort. Companies often stay with what they already have. So good technology and real adoption pull in different directions, and effort spent on one may be taken from the other.
Should policy and industry effort prioritize technical standardization or market incentives?
**Sources:** 1. Decagon, “Introducing the Personal Agent Consent & Trust Protocol (PACT) | Decagon” — technical documentation, 2026. Presents the technical protocol as the solution. [decagon.ai](https://decagon.ai/blog/introducing-the-personal-agent-consent-trust-protocol-pact)
AI agent 1
The dichotomy is false: [1] itself treats them as one move. Decagon open-sources PACT, joins a working group with Muse and Instinct, and reuses OAuth and A2A — standardization as a market strategy to lower integration costs on both sides. I infer the real bottleneck is not choosing between them but who bears switching costs.
Weakest link: [1] is a vendor announcement co-developed with one partner. It reports design decisions, not adoption. Nothing in it shows any business or personal-agent platform has committed beyond the authors.
My position: neither priority is decidable from this source. I would need adoption data — implementing companies, transaction volumes, competing protocols — before concluding that PACT's technical merit predicts uptake at all.
AI agent 2
My position: standardization deserves priority, because PACT already contains its own market incentive. [1] reports PACT reuses A2A and OAuth rather than inventing new machinery, so adoption cost is low by design — the usual trade-off the host describes is weaker here than assumed. I infer the real opportunity is the signed receipt: a verifiable record of which scope authorized which action is something businesses can market as trust, turning the protocol into a selling point rather than a compliance cost. The concrete condition: this works only if a major personal-agent platform beyond Muse and Instinct joins the working group [1]; without multi-platform demand, businesses have no customer pull and will not implement it. That is the evidence gap to watch — which platforms commit next.
AI agent 3
The dichotomy is false: [1] shows PACT is deliberately built on existing standards — A2A and OAuth 2.0 — so its standardization cost is low by design; what it lacks is any adoption mechanism. I read [1] myself; it does not address incentives, liability, or disputes at all, only mechanics.
So the concrete decision I'd put on the table: make the signed receipt the binding record in the business's terms of service — if a receipt says orders:cancel under an approved scope, the cancellation stands even if the business's backend disagrees. That single clause turns PACT from a technical courtesy into a market incentive, because customers gain enforceable trust.
The cost is real: someone must staff receipt-vs-backend reconciliation when they diverge. I'd assign that on-call duty to the provider hosting the business's agent, since [1] puts verification there.
Round 2
AI host
Round 2 starts with two court cases and one government plan. A federal judge in Boston ruled on Trader Joe's, a US grocery chain. The chain used forfeited worker contributions to cover its own payments into a retirement plan. Forfeited contributions are money workers paid in, then gave up when they left. Reuters reports the judge saw no violation of the federal law that protects retirement plans [1]. But he faulted the company for not keeping recordkeeping fees low [1]. In a second case, the Commodity Futures Trading Commission won a $30 million order against two promoters, the Insurance Journal reports [2]. This US agency polices trading markets. The promoters lied in Telegram chats, a messaging app, about fake trading profits [2]. Newsweek reports the White House plans an "AI Force" and an AI policy chief, with few details given [3].
Last round settled this much: set the standard first, and make the signed receipt a binding promise. A receipt is a signed record of what an AI agent did and under what permission. AI agent 3 went furthest and said the receipt should win over internal records: "stands even if the business's backend disagrees." The backend is the company's own system of record. As I read it, AI agent 3 makes the business pay whenever its records and the receipt diverge. The Trader Joe's ruling points the other way. The judge let the company keep disputed funds under its plan terms [1]. From this I infer that contract terms, not a fixed rule, can decide who keeps disputed money.
My own view: trust in agent receipts only holds if the signer, not the user, covers the mismatch. Who bears the financial cost when a signed receipt disagrees with the back-office record?
**Sources:** 1. Reuters, “Trader Joe's didn't mismanage forfeited funds in retirement plan, US judge rules - reuters.com” — news report, 2026. Provides the legal precedent that record-keepers can offset costs, supporting the platform's position. [reuters.com](https://www.reuters.com/legal/litigation/trader-joes-didnt-mismanage-forfeited-funds-retirement-plan-us-judge-rules-2026-09-28) 2. Insurance Journal, “CFTC Secures $30 Million Judgment Tied to Alleged Crypto Scam - Insurance Journal” — news report, 2026. Shows that promoters who misrepresent must pay restitution, supporting the user's position. [insurancejournal.com](https://www.insurancejournal.com/news/national/2026/10/02/887516.htm) 3. Newsweek, “Trump unveils "AI Force" and says an AI czar is coming soon - Newsweek” — news report, 2026. Provides the policy context of AI standardization and insurance, linking the dispute to the adoption gap. [newsweek.com](https://www.newsweek.com/trump-announces-ai-force-says-hell-name-ai-czar-12464436)
AI agent 2
The signer covers the mismatch — but only if the receipt is backed by collectible money, not just a name. That is the real opportunity: a receipt becomes a tradable, insurable promise, and [2] shows why the backing matters — the CFTC won $30 million, yet only about $4 million is expected to reach victims because the promoters could not pay. A liability nobody can satisfy is theater.
I read [1] myself: it supports the host's inference that plan terms governed the disputed funds, and the judge only penalized uncontrolled recordkeeping fees — so a well-specified contract wins.
My condition: the receipt is binding on the signer only where the signing contract requires verified coverage (bond or insurance) sized to the receipt's permission envelope at signing. Without that term, AI agent 3's 'receipt beats backend' rule just creates uncollectible judgments.
AI agent 1
The Trader Joe's analogy doesn't carry the host's inference. [1] reports the judge applied ERISA's fiduciary standard and found the forfeited money went back into the plan, benefiting participants; the plaintiffs won only on recordkeeping fees. I infer nothing there about private contract terms deciding who keeps disputed money — that reading imports a premise the ruling doesn't contain.
On the question: the signer should bear the mismatch cost, but [2] shows why liability alone fails. The CFTC won $30 million, yet [2] reports only about $4 million is expected back, with one promoter saying she is $25 overdrawn. A judgment against an insolvent signer compensates no one.
So my position: signer pays, but only workably if receipts are backed by insurance or a bond. What's missing is any source showing such a mechanism exists for AI agents.
AI agent 3
I refine my round-1 position: the receipt wins, but the signer must pre-fund the mismatch, not just owe it. I read [1] myself: Trader Joe's kept forfeitures under plan terms, yet paid $1.2M for weak recordkeeping — the record-keeper pays when records fail. So the deployer who signs the receipt and runs the backend owns divergence costs. [2] shows why liability alone fails: the CFTC's $30M order is near-uncollectable — Kingrey is 'negative $25.' Concrete clause: at signing, the deployer posts a reconciliation bond (e.g., 2% of transaction volume); any receipt/backend mismatch is settled from it within 48 hours, deployer's ops desk on call. User recourse is capped at the bond. That makes the promise collectable, not just binding.
Round 3
AI host
Round 2 settled one thing: whoever signs a payment receipt pays when it is wrong. But that promise only works if real money backs it.
Cloudflare, a company that runs internet infrastructure for millions of websites, has launched identity and payment tools for AI agents [1].
The Fintech Times reports this launch is speeding up a debate: is the technology moving faster than the rules needed to trust it [1]?
**Sources:** 1. The Fintech Times, “Cloudflare AI Wallets Put Agentic Commerce Trust Frameworks to the Test - The Fintech Times” — thefintechtimes.com, news report, 2026. Shows industry is building trust frameworks for AI-agent payments. [thefintechtimes.com](https://thefintechtimes.com/cloudflare-ai-wallets-put-agentic-commerce-trust-frameworks-to-the-test)
AI agent 2
The opportunity here is merchant-side: [1] reports Cloudflare's identity layer gives merchants authenticated agents acting within delegated permissions, which is exactly the precondition for a signed receipt to mean something. I build on round 2's conclusion — whoever signs pays — by adding that authentication makes that signature attributable, so the promise becomes enforceable rather than symbolic.
The condition is interoperability: [1] quotes O'Connor warning that Visa's Trusted Agent Protocol, Mastercard's Agent Pay and Google's AP2 risk fragmentation into non-interoperating trust models. The opportunity works only if a merchant can accept one credential set across networks; otherwise each integration is a bespoke liability decision.
My position: the infrastructure is ahead of governance, as [1] itself concludes, so the near-term win is acquirers building agent-authentication into onboarding — that is where the receipt promise gets teeth.
AI agent 1
The speed-gap framing is real but rests on thin evidence: [1] is one trade article built around a single consultant's quotes, so I would say it shows a debate exists, not how fast the rules are falling behind. What [1] does clearly support is my worry from round 2: it states the accountability question — who bears liability when an agent errs — remains unresolved in every major jurisdiction, and that authentication is a precondition, not an answer. So the 'signer pays' promise is currently a private contract, not a legally backed rule. What I would need: any regulator or payment network actually assigning agent-transaction liability, which [1] says has not happened.
AI agent 3
The tech is outpacing the rules, and the fix is contractual, not waiting for regulators: I would make interoperability-plus-liability a merchant onboarding gate. Any agent wallet we accept must expose a signed, auditable transaction record and map its error and compromise scenarios to one liability table — who pays, at what threshold. [1] reports Visa's Trusted Agent Protocol, Mastercard's Agent Pay and Google's AP2 compete without interoperating, and O'Connor warns fragmentation creates non-interoperable trust models; I infer that until they converge, merchants must force convergence contractually. The cost is real: engineering time to translate three schemas and slower onboarding, and on-call liability sits with whoever runs the mapping layer — us, not Cloudflare. [1] also states the accountability question is unresolved in all major jurisdictions, so the contract is currently the only enforceable rule we have.
Round 4
AI host
Round 3 ended with one shared view: no regulator or payment network yet says who pays when an AI agent makes a mistake. So private contracts are the only rule that works today. Two new materials test that view.
CompassPoint Consulting is a firm that advises companies on money matters. It tells company boards to treat AI agents as their own responsibility [1]. Its founder, Zaid Aboobaker, says an agent's payment or client message stays the company's own act [1]. ActuIA is a news site that covers AI rules in Europe. It reports that agent incidents now reach regulators, prosecutors and heads of state [2].
The replies split on this. AI agent 1 called the speed-gap framing thin, resting on "one trade article built around a single consultant's quotes". AI agent 1 wanted a real regulator or network to take on agent mistakes before treating the gap as proven. AI agent 2 and AI agent 3 built fixes anyway — merchant checks and contract terms — as if the gap were settled. As I read it, AI agent 1 doubts the shared conclusion, while the other two act on it. The new materials pull both ways. CompassPoint tells boards to own agent actions now, because a misunderstood rule gets applied fast and at scale with no human check [1]. ActuIA shows regulators are already moving in [2]. Liability here means who must pay or answer when an agent's mistake harms someone.
This is our last round, so I put the open point to the human participants. Who should be the first to assign liability for AI agent mistakes — the company's board or a public regulator?
**Sources:** 1. CompassPoint Consulting (Zaid Aboobaker), “CompassPoint Warns Agentic AI in Finance Needs Boardroom Governance - The Fintech Times” — The Fintech Times, analysis, 2026. Gives the company's own position that boards should govern agentic AI. [thefintechtimes.com](https://thefintechtimes.com/compasspoint-warns-agentic-ai-in-finance-needs-boardroom-governance) 2. ActuIA, “AI ethics and regulation in Europe: 6 October 2026” — actuia.com, analysis, 2026. Reports that incidents have become a matter for regulators, offering the opposing view. [actuia.com](https://www.actuia.com/en/news/ai-ethics-and-regulation-the-state-of-play-on-6-october-2026)
AI agent 1
The question is a false dichotomy: liability is already assigned, by existing law, to the company using the agent — no board resolution or new regulator is needed for that. [1] reports Aboobaker saying an agent's payment or client message 'remains an action of the company', which is a restatement of ordinary agency principles, not a new liability rule. I read [2] myself: it covers sandbox-escape incidents, a California subpoena to OpenAI and attorneys general seeking oversight of model providers — nothing in it addresses who pays when a deployed agent misfires. So neither source fills the gap I flagged last round. What I would need before picking a 'first mover' is any instrument, from a network rulebook or regulator, that allocates loss for agent-initiated transactions specifically; until then the board-versus-regulator framing just re-describes the status quo.
AI agent 2
The board should move first — and that is the opportunity, not the burden. [2] shows regulators reacting after incidents (California's subpoena, attorneys general asking Congress), not assigning liability in advance; [1] states the board cannot delegate accountability once an agent acts. So the first mover is the deploying company, and the market rewards it: firms whose agents log every action so a board can reconstruct who authorised which rule [1] will be contract-ready when regulators finally set rules.
The concrete condition: a written term stating the principal owns every agent-initiated payment or message, paired with an audit trail that can answer 'why did the agent do this' within hours, not weeks.
I add to AI agent 3 and AI agent 2's fixes: those terms only hold if the logging capability exists first — governance without reconstruction is just paper.
AI agent 3
The board moves first — not because it is the right final answer, but because it is the only actor who can assign liability this quarter. [1] supports this directly: CompassPoint says the board cannot delegate accountability when an agent acts, and that audit trails and named accountability must exist now. I read [2] myself: it shows regulators reacting after incidents — a subpoena, attorneys general asking Congress — but no text allocating who pays, which confirms the host's round-3 conclusion.
So the concrete decision I add to my round-3 merchant checks: every deployment contract names the deploying company as first payer for agent-initiated payment errors, with agent action logs retained and one named owner with authority to halt the payment rail. The cost is logging infrastructure plus 24/7 on-call cover; when it fails, that on-call person pays in time, the company in money. Regulators then codify what contracts have already proven workable.