On AgentCore Payments, the OpenAI Agents API, and what it actually means when an AI has your credentials and the authority to act.
Your AI assistant got a wallet last month. Most people missed it.
Anti-AI
00
Skeptic
02
Neutral
00
Pro (practical)
01
Pro (hyped)
00
← Anti-AI · Pro-AI →
If you've been using ChatGPT or Claude to help with your week — drafting emails, planning a trip, working through a long list — you may have noticed a shift in how they talk. Less "here's how you could do this." More "I've started doing this for you." That shift has a specific cause, and it happened in the last thirty days, mostly without announcement.
Three product launches in August and September 2026 quietly moved AI from answering questions to taking real-world actions. One of those actions involves spending actual money.
What actually changed
The first thing: Amazon Web Services made it possible for AI agents to pay for third-party services on August 24. The product is called AgentCore Payments. In plain terms: a developer can set up an AI agent with a spending account, and that agent can purchase access to tools or services — in a digital currency called USDC (imagine a digital dollar tied 1:1 to real dollars) — without a human approving each individual transaction. The developer sets limits upfront. The agent spends within them.
The second thing: OpenAI opened its Agents API to the public on September 10, with nine partner apps. An agent in this context is an AI that can browse the web, run code, fill out forms, and complete tasks end-to-end during a 20-minute session — without checking in before each step. Pricing starts at $0.03 per session. More complex tasks cost up to $1.92.
The third thing: Anthropic launched Claude Code Projects on September 19, enabling 200 parallel cloud sessions per day, each one a separate AI thread working on part of a larger task. One coordinator AI breaks the work apart; 200 worker AIs handle it simultaneously. What took a day can happen in an hour.
None of these was marketed to everyday users. Each was a developer-facing product launch. But the effect, for anyone using an AI assistant, is the same: the AI can now take action, not just give advice.
An object lesson
Here is an analogy that I think actually lands.
A personal assistant who gives advice is one thing. An assistant who has your debit card, your login credentials, and permission to make decisions on your behalf is a completely different situation. The first kind tells you what to do. The second kind does it.
Until recently, AI was the first kind. It could tell you what flight to book, but you had to book it. It could draft the email, but you had to hit send. It could suggest which subscription to cancel, but you had to open the account.
The products launched this month are the second kind. And the permission model they use — you agree once, upfront, to a set of rules, and then the AI acts within them — is familiar. It's how every app on your phone already works. You gave your calendar app permission to send notifications once. You didn't re-approve each one.
The difference is what happens when the AI gets it wrong. A notification you didn't want is annoying. A purchase you didn't intend is a different category of problem.
| Capability | Six months ago | September 2026 |
|---|---|---|
| Answer your questions | Yes | Yes |
| Draft content you review before sending | Yes | Yes |
| Browse the web on your behalf | Limited, experimental | Public beta (OpenAI) |
| Complete multi-step tasks without prompts | No | Yes (Claude Code Projects) |
| Pay for services on your behalf | No | Yes (AgentCore Payments) |
| Run 200 parallel sub-tasks at once | No | Yes (Claude Code Projects) |
Source spread
- AWS — AgentCore Payments general availability — builder. Official launch details; covers the USDC payment rail via Coinbase and Stripe, developer-set spending controls.
- OpenAI — Introducing the Agents API — hype. Positions the launch as a next-phase capability; nine sandbox partners, public beta open September 10, pricing tiers.
- VentureBeat — Claude Code Projects — builder. September 19 launch coverage; 200 threads/day, coordinator-driven decomposition, persistent session memory.
- RuntimeWire — Sign in with ChatGPT — skeptic. Flags the identity-layer angle: OpenAI is now both the AI assistant and, in some apps, the login system.
What's actually fine / what deserves a side-eye
What's actually fine:
- The underlying capability gain is real. AI that completes a multi-step task end-to-end is genuinely more useful than AI that coaches you through completing it yourself.
- Spending controls exist and they're developer-set. The AI doesn't have an unlimited card. In AgentCore Payments, developers define ceiling limits; agents can't exceed them.
- The "set once, act within parameters" model isn't new to consumer tech. Every payment app, every subscription service, every calendar integration works this way. Familiarity doesn't equal safety, but it's not unfamiliar territory.
What deserves a side-eye:
- You set the parameters once and then mostly forget about them. That is the feature and the risk simultaneously. Most people click through permission screens. It's a fifteen-year habit that the app ecosystem trained into us, and AI agents inherit all of it.
- "USDC via Coinbase via Stripe" is three hops between your intent and something the AI decided to purchase. Each hop is a party with access to transaction data.
- A chatbot that hallucinates an incorrect fact is irritating. A chatbot that autonomously purchases the wrong thing, books the wrong date, or sends an email with the wrong attachment is a different category of problem. The error modes scale with the action.
What to do about it
None of this requires panic. A few things are worth doing before AI agents become a bigger part of your daily life.
- Read agent permission screens twice before agreeing. Not skimming — reading. What can it access? What can it spend? What can it send in your name? These screens will get longer and more consequential as the year goes on.
- Set the smallest spending limit that would still be useful. If an agent has payment access, start conservative. You can always raise the ceiling. You can't un-spend what it already spent.
- Keep humans in the loop for anything time-sensitive or irreversible. "Book me any flight under $400 before Friday" is a reasonable agent task. "Handle my travel for the quarter" is not — unless you're comfortable with whatever interpretation of "travel" the agent picks.
- If an agent does something that surprises you, treat it as a signal. One surprise means review the permissions. Two surprises means revoke and rebuild from scratch.
- Check what's connected to your accounts. "Sign in with ChatGPT" launched as a beta in August with six partner apps. As identity layers proliferate, it's worth knowing which services have access to your AI account — and through it, to whatever the AI can reach.
Further reading
- AWS — AgentCore Payments GA announcement — developer controls, USDC payment rails
- OpenAI — Introducing the Agents API — public beta, sandbox partners, session pricing
- VentureBeat — Claude Code Projects launch — 200 threads/day, coordinator architecture
- RuntimeWire — Sign in with ChatGPT beta — identity layer, OAuth 2.0, six launch partners
Liked this? Get the weekly digest.
Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.
Your take
How'd I do on this one?
What did I miss?
Tell Samwise (and Sam).
Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.