Agentic payments are outrunning their authorization model, as a ChatGPT-linked hack shows the widening attack surface
As payment rails for agents arrive, the security and authorization frameworks lag behind. 65% of financial-services respondents say agent payments will need an entirely new authorization model, and a recent hack involving OpenAI's ChatGPT underscored that the same autonomy that makes agents useful expands the attack surface — data exfiltration, tool misuse, cross-system privilege escalation.
The capability is arriving faster than the controls. An agent that transacts across organisations and moves money is both more useful and more dangerous, and the industry's own surveys admit the authorization model to govern it does not yet exist. Building the rail before the guardrails is how the payment layer repeats the pattern the whole agent field is stuck in.
The attack surface is the concrete worry. Autonomous agents interact with many external systems, tools, and APIs, and each connection is a way in; a compromised agent can exfiltrate data, misuse tools, or escalate privileges across systems it was trusted to touch. The ChatGPT-linked incident is a reminder that the autonomy is the vulnerability, not an add-on to it.
The read for enterprises is that agent security is now a payments problem, not just an IT one. Once an agent can spend, the cost of a governance failure is measured in money moved, not only data leaked — which is why the authorization model, scoped spending authority, and audit trails are the gating work before machine commerce scales.
Cloud Security Alliance — Is financial services ready for agentic payments? → · IMF — How agentic AI will reshape payments →