A mandate skips the hard check
A signed mandate shows that a human approved a scope at some point. It says nothing about whether this payment, right now, fits your exposure limits, your counterparty appetite and current market conditions.
Institutional AI platform
A2Ai checks and records what an AI agent does before it moves money. It works with the payment protocols and settlement networks you already use, and runs inside your own network.
Originating in agentic AI research with Oxford researchers.
Adjusted stablecoin transaction volume in 2025, compounding at roughly 80% a year since 2020
Agent coordination and payment protocols launched since 2024. None of them decides whether an agent should pay
Where approval, agent identity and eligibility are decided, with no common standard
Sources: Visa Onchain Analytics and Allium; Nacha; RWA.xyz, 2025–26.
The problem
Seven protocols now handle how agents coordinate, pay and prove they were authorised. None of them answers the question you have to answer before any of this touches a balance sheet.
A signed mandate shows that a human approved a scope at some point. It says nothing about whether this payment, right now, fits your exposure limits, your counterparty appetite and current market conditions.
Identity, AML and eligibility checks happen off-chain, in custom systems, differently at every institution. There is no common way to establish what an agent is, who it acts for and how much authority it has.
An on-chain record shows that a transfer happened and is final. It does not show what the agent knew, why it acted, which rule allowed it or what would have stopped it. Supervisors ask for that.
Until someone owns the approval step, this stays a demo.
The economics of machine-to-machine payment are good, and the rails are being built by firms with far more capital than us. The gap is the off-chain layer: something has to decide whether an agent may pay, hold it to the limits behind that decision, and produce a record a regulator, an auditor or a client will accept.
In practice
The agent takes the instruction, works out how to settle it, prices the currency leg, runs the checks, sends the payment and reconciles it. A person is involved only where a rule says so.
It resolves the counterparty and the rail, prices the currency leg across venues, sends the payment and confirms both sides.
Mandate scope, exposure, liquidity, slippage and dual control are checked in code. The agent cannot override a failed check.
Inputs, sources, policy version and every check result are captured while the work happens, and can be replayed against changed rules.
Where we fit
Agents and digital assets are converging in four places. In each one, something has to decide what the agent is allowed to do and keep a record of why it did it.
Stablecoins, tokenized RWAs and native assets as instruments an agent can hold and move
Wallet operations, issuance and custody controls, and settlement across every ledger you run. You do not have to pick one network.
MCP and A2A for coordination; x402, ACP, MPP, AP2 and TAP for payment and authorisation
Our agent runs the payment and applies your checks before it executes. Support for the agentic payment protocols is in build, so the same checks will apply when agents transact beyond your perimeter.
Eligibility, AML and transfer restrictions assessed off-chain, with results passed on-chain
We run those checks in code and keep the evidence, so the off-chain half of the workflow can be audited too.
Standardised claims on capacity, priced, pledged as collateral and settled programmatically
Valuation, exposure and collateral handled by the same risk engine that already covers portfolios, credit and real assets. It becomes one more asset class.
How it works
The architecture that came out of the research. It settles on whatever ledger you already run, and connects to your systems today through the API and the agent console.
Plans the work, calls tools and records each step
Mandate, limits, screening and dual control checked in code
Pricing, exposure and counterparty assessment before capital moves
Resolves the rail, prices FX, sends and confirms both legs
Inputs, model versions and decisions, reproducible on demand
We don't build settlement networks, and we don't ask you to bet on which one wins. We run the payment on the rails you already have — and the protocol layer is next.
The suite
The control layer sits on a working institutional platform. That is what lets an agent price an instrument, assess a counterparty and size an exposure before it acts.
Agent control
Decides whether an agent may pay, and keeps the record afterwards.
Digital assets
Issuance, custody and cross-ledger settlement, with checks applied before anything executes.
Risk and valuation
The pricing and exposure engine an agent calls before committing capital, across tokenized and traditional holdings.
Market intelligence
Research depth, so an agent has a view it has worked out before it acts.
One core. One deployment. You install once and get every module. Adding the next domain is a configuration and a data connector.
Origin
A2Ai started as a research collaboration with Oxford researchers on large-scale agentic systems. We tested it on a demanding case: the full research and risk process of a hedge fund.
The question
Screening, fundamental analysis, portfolio construction, stress testing and attribution — the whole job. The test was whether a professional could use the output as it came, without redoing it.
The result
The system held up under load. The runtime, the controls and the evidence layer turned out to apply to any domain. Only the data and the rules changed.
What followed
Banking risk came first, then tokenization and cross-ledger settlement. Once the agents were executing instead of recommending, the control layer became the most important part of the system.
We started with the controls, then added settlement.
Most teams in agentic payments started with a rail and are adding governance to it now. We started with agents doing regulated work, where the governance was the hard part from day one. Settlement came later, built on top of those controls.
A first engagement
With the evidence pack it produces.
What we propose
One workflow in a sandbox, run end to end by the agent: instruction, rail, currency leg, checks, payment and record. We can build the protocol integration you care about as part of it.
What we need
A workflow worth automating, the rules that govern it today, and a test environment. Nothing in production, and no commitment to any protocol or network.
What you get
A working control layer over that workflow, and an audit pack showing every decision the agent made and every rule that held it. You keep both, whatever you decide next.
Consortia and protocol teams will build the rails.
The approval layer has to sit with the institution.
Inside your network, under your own rules. That is what we build, and it is running today.
Talk to us