Institutional AI platform

Agentic AI shaping innovation in the digital assets space

A2Ai checks and records what an AI agent does before it moves money. It works with the payment protocols and settlement networks you already use, and runs inside your own network.

Originating in agentic AI research with Oxford researchers.

$11T

Adjusted stablecoin transaction volume in 2025, compounding at roughly 80% a year since 2020

7

Agent coordination and payment protocols launched since 2024. None of them decides whether an agent should pay

Off-chain

Where approval, agent identity and eligibility are decided, with no common standard

Sources: Visa Onchain Analytics and Allium; Nacha; RWA.xyz, 2025–26.

The problem

Nobody owns the approval step.

Seven protocols now handle how agents coordinate, pay and prove they were authorised. None of them answers the question you have to answer before any of this touches a balance sheet.

A mandate skips the hard check

A signed mandate shows that a human approved a scope at some point. It says nothing about whether this payment, right now, fits your exposure limits, your counterparty appetite and current market conditions.

Agent identity has no standard

Identity, AML and eligibility checks happen off-chain, in custom systems, differently at every institution. There is no common way to establish what an agent is, who it acts for and how much authority it has.

A settled transaction explains nothing

An on-chain record shows that a transfer happened and is final. It does not show what the agent knew, why it acted, which rule allowed it or what would have stopped it. Supervisors ask for that.

Until someone owns the approval step, this stays a demo.

The economics of machine-to-machine payment are good, and the rails are being built by firms with far more capital than us. The gap is the off-chain layer: something has to decide whether an agent may pay, hold it to the limits behind that decision, and produce a record a regulator, an auditor or a client will accept.

In practice

How a payment runs, end to end.

The agent takes the instruction, works out how to settle it, prices the currency leg, runs the checks, sends the payment and reconciles it. A person is involved only where a rule says so.

  1. Instruction
  2. Rail selected
  3. FX priced
  4. Checks run
  5. Payment sent
  6. Reconciled
Authorisation Gate: the agent's plan, six deterministic policy gates, and one $740,200 payment held for human approval after a payee bank-detail change
The agent's plan, the checks run against it, and one payment held for approval. 13 of 14 payments released autonomously.

The agent runs the payment

It resolves the counterparty and the rail, prices the currency leg across venues, sends the payment and confirms both sides.

Checks run before money moves

Mandate scope, exposure, liquidity, slippage and dual control are checked in code. The agent cannot override a failed check.

The record is built as it runs

Inputs, sources, policy version and every check result are captured while the work happens, and can be replayed against changed rules.

Where we fit

Four areas, and what we add to each.

Agents and digital assets are converging in four places. In each one, something has to decide what the agent is allowed to do and keep a record of why it did it.

Machine-native money

Stablecoins, tokenized RWAs and native assets as instruments an agent can hold and move

Wallet operations, issuance and custody controls, and settlement across every ledger you run. You do not have to pick one network.

Agentic commerce

MCP and A2A for coordination; x402, ACP, MPP, AP2 and TAP for payment and authorisation

Our agent runs the payment and applies your checks before it executes. Support for the agentic payment protocols is in build, so the same checks will apply when agents transact beyond your perimeter.

Tokenized real-world assets

Eligibility, AML and transfer restrictions assessed off-chain, with results passed on-chain

We run those checks in code and keep the evidence, so the off-chain half of the workflow can be audited too.

Compute as an asset class

Standardised claims on capacity, priced, pledged as collateral and settled programmatically

Valuation, exposure and collateral handled by the same risk engine that already covers portfolios, credit and real assets. It becomes one more asset class.

How it works

One control layer, on the rails you already run.

The architecture that came out of the research. It settles on whatever ledger you already run, and connects to your systems today through the API and the agent console.

Reaches it today
Agent consoleDirect APIERP and treasury systemsBank control panel APIs
Protocols · in build
MCPA2Ax402ACPAP2TAP
A2Ai core
Agent runtime

Plans the work, calls tools and records each step

Policy and approval engine

Mandate, limits, screening and dual control checked in code

Risk and valuation

Pricing, exposure and counterparty assessment before capital moves

Payment execution

Resolves the rail, prices FX, sends and confirms both legs

Audit and lineage

Inputs, model versions and decisions, reproducible on demand

Where it settles
Permissioned ledgersPublic networksStablecoin railsTokenized RWA venuesISO 20022 fiatOn-premise

We don't build settlement networks, and we don't ask you to bet on which one wins. We run the payment on the rails you already have — and the protocol layer is next.

The suite

Twelve modules in production today.

The control layer sits on a working institutional platform. That is what lets an agent price an instrument, assess a counterparty and size an exposure before it acts.

Agent control

  • Authorisation and mandate
  • Policy checks in code
  • Dual control and escalation
  • Audit, lineage and replay

Decides whether an agent may pay, and keeps the record afterwards.

Digital assets

  • Tokenization and smart ledger
  • Settlement orchestration
  • Wallet and counterparty risk
  • End-to-end payment execution

Issuance, custody and cross-ledger settlement, with checks applied before anything executes.

Risk and valuation

  • Portfolio construction
  • Stress scenarios and VaR, CVaR
  • Banking and credit risk
  • Exposure across asset classes

The pricing and exposure engine an agent calls before committing capital, across tokenized and traditional holdings.

Market intelligence

  • Equity screening and analysis
  • Fixed income
  • Macro intelligence
  • Earnings intelligence

Research depth, so an agent has a view it has worked out before it acts.

Token registry, transaction feed and wallet portfolio with risk profile
Tokenization and smart ledger. Issuance, transfer and custody with per-wallet exposure and settlement controls.
Custom scenario builder with oil, rate, real estate and FX shocks, and global stress scenarios
Multi-factor stress scenarios. The same engine behind the checks an agent runs before it pays.

One core. One deployment. You install once and get every module. Adding the next domain is a configuration and a data connector.

Origin

It began as an Oxford research project.

A2Ai started as a research collaboration with Oxford researchers on large-scale agentic systems. We tested it on a demanding case: the full research and risk process of a hedge fund.

The question

Could agents do institutional work?

Screening, fundamental analysis, portfolio construction, stress testing and attribution — the whole job. The test was whether a professional could use the output as it came, without redoing it.

The result

The architecture worked anywhere

The system held up under load. The runtime, the controls and the evidence layer turned out to apply to any domain. Only the data and the rules changed.

What followed

Then agents started executing

Banking risk came first, then tokenization and cross-ledger settlement. Once the agents were executing instead of recommending, the control layer became the most important part of the system.

We started with the controls, then added settlement.

Most teams in agentic payments started with a rail and are adding governance to it now. We started with agents doing regulated work, where the governance was the hard part from day one. Settlement came later, built on top of those controls.

A first engagement

One workflow, set up end to end.

With the evidence pack it produces.

What we propose

One workflow in a sandbox, run end to end by the agent: instruction, rail, currency leg, checks, payment and record. We can build the protocol integration you care about as part of it.

What we need

A workflow worth automating, the rules that govern it today, and a test environment. Nothing in production, and no commitment to any protocol or network.

What you get

A working control layer over that workflow, and an audit pack showing every decision the agent made and every rule that held it. You keep both, whatever you decide next.

Consortia and protocol teams will build the rails.
The approval layer has to sit with the institution.

Inside your network, under your own rules. That is what we build, and it is running today.

Talk to us