Visa and Dunamu, the parent company of South Korean crypto exchange Upbit, are exploring stablecoin payments, remittances and AI commerce. The initiative is early: Open Standard’s proposed OUSD is among several projects under review, according to CoinTelegraph.

That limited description does not establish a product launch, transaction volume or deployment timetable. It does, however, put two increasingly connected technologies on the same agenda. Stablecoins can give software a programmable way to transfer value, while AI systems can decide when and where to initiate those transfers.

The combination sounds straightforward until an automated payment reaches a regulated intermediary.

A wallet address can identify where funds came from, but it does not necessarily reveal which person, company or software agent authorized the transaction. It may not show the commercial purpose of the payment, the agent’s spending mandate or who is accountable when the transaction violates a policy.

Those are not peripheral compliance questions. They are part of the payment architecture.

If AI commerce moves beyond demonstrations, the decisive infrastructure may not be a faster blockchain or another stablecoin. It may be an identity and authorization layer that lets payment providers distinguish legitimate machine activity from compromised automation, sanctions exposure and transaction spam.

Programmability creates an attribution problem

Traditional payment systems already process large volumes of automated activity. Businesses use scheduled bank transfers, card-on-file billing and software-driven treasury systems. Those systems generally operate through identifiable corporate accounts, contractual relationships and established mechanisms for disputes and fraud controls.

An autonomous or semi-autonomous AI agent complicates that model.

The agent could discover a service, negotiate a price and initiate payment with limited human involvement. In a stablecoin-based system, it could also transact continuously and across borders without waiting for banking hours. That capability may be useful for remittances, software services and machine-to-machine commerce.

But a blockchain records the movement of an asset, not the complete authority behind the movement.

A receiving business may see a wallet, token and transaction hash. It still needs to know whether the agent represents a real customer, whether the customer approved that category of purchase, and whether the payment complies with the receiver’s own obligations.

The sending side faces a similar problem. A company may permit an agent to buy computing capacity but not financial products. It may authorize payments to approved vendors while prohibiting transfers to newly created addresses. It may impose geographic, time-based or transaction-level restrictions.

Encoding those distinctions requires more than giving software access to a wallet.

Low-value transactions are not automatically low-risk

A separate incident involving Kraken illustrates why payment systems cannot rely on transaction size alone.

CoinDesk reported that Kraken users were briefly locked out after the exchange received nearly 12,000 low-value transactions associated with a flood of sanctioned crypto activity. The available source context does not establish the full technical mechanism or Kraken’s detailed response, but the event highlights an important operational issue: small incoming transfers can still trigger large compliance and availability consequences.

That matters for AI commerce because machines can generate transactions at a scale humans generally do not.

A poorly configured agent could produce thousands of repetitive payments. An attacker could deliberately send small transfers to addresses associated with businesses or intermediaries. Automated systems could also divide activity into many low-value transactions because their objective is continuous settlement rather than traditional invoice processing.

In each case, the nominal value of an individual payment says little about the operational burden it creates.

An intermediary may need to screen the originating address, evaluate sanctions exposure and decide whether the recipient’s account should remain available. When those controls operate at account level, unwanted incoming funds can affect more than the transaction itself.

The result is a basic mismatch: blockchains often allow anyone to send assets to a public address, while regulated service providers are expected to understand and control the activity around customer accounts.

AI-driven transaction volume could widen that mismatch.

A wallet address cannot carry the whole trust model

A workable AI-commerce system needs to separate several identities that are easy to collapse into one wallet.

First is the principal: the person or business ultimately responsible for the payment. Second is the agent: the software making or recommending the purchase. Third is the operator or vendor providing that agent. Fourth is the wallet or account through which settlement occurs.

Those parties may not be the same entity.

That distinction becomes important when something goes wrong. If an agent makes an unauthorized purchase, the payment provider needs to determine whether the agent exceeded its mandate, a credential was compromised or the principal’s policy permitted the transaction. If a merchant receives problematic funds, it needs a way to assess the counterparty without treating every machine-generated payment as anonymous traffic.

This does not mean every commercial detail should be published onchain. Public disclosure could expose customer behavior and business relationships. A more plausible architecture would combine blockchain settlement with selective, verifiable information presented to the relevant payment provider or merchant.

At minimum, an AI payment request may need to communicate:

- The accountable person or organization behind the agent - The specific agent or software instance initiating the request - The scope and duration of its payment authority - The permitted asset, merchant and transaction category - The applicable spending and frequency limits - A reference connecting payment to an order or service - A mechanism for suspending the agent without disabling unrelated accounts

The precise implementation remains open. The important point is that transaction authorization and asset custody are different functions. Possession of a signing key proves the ability to produce a valid signature. It does not prove that a particular purchase was permitted under the owner’s business rules.

Payment networks will care about control, not autonomy branding

Visa and Dunamu’s decision to place AI commerce alongside stablecoin payments is notable because payment networks operate around acceptance, risk management and accountability—not merely asset transfer.

For merchants and small businesses, that means the useful question is not whether an AI agent can send a stablecoin. That capability already follows from giving software access to signing infrastructure. The harder question is whether businesses can accept such payments without losing the controls they rely on in conventional commerce.

An operational system must address false positives as well as illicit activity. If compliance tools respond to suspicious low-value transfers by restricting an entire account, legitimate businesses may face interruptions caused by transactions they did not request. If automated screening is too permissive, machine-scale activity can amplify exposure before a human intervenes.

Identity will not solve every issue. Known entities can still act improperly, credentials can be stolen and authorized agents can malfunction. But attributable authority gives service providers a better basis for limiting the blast radius.

Instead of treating every transaction from one wallet as equivalent, systems could evaluate which agent initiated it and under what mandate. Instead of freezing a company’s broader payment activity, a provider could potentially suspend one credential or authorization path.

That is a meaningful infrastructure improvement even if settlement still occurs through familiar stablecoin rails.

What businesses should watch next

Because the Visa-Dunamu work is described as an exploration, readers should resist treating it as evidence that AI-driven stablecoin commerce has reached production.

The next credible signals would concern operating design rather than branding. Businesses should look for details about who holds funds, how an agent receives authority, what information accompanies a payment and how merchants handle unauthorized or sanctioned activity.

They should also look for clarity on failure handling. A system designed for machine commerce needs a defined response when an agent pays the wrong recipient, generates duplicate transactions or receives unsolicited problematic funds. Faster settlement does not remove those scenarios; it can reduce the time available to contain them.

Stablecoins can make money easier for software to move. AI can make payment decisions easier to automate. Neither technology, by itself, establishes who authorized a transaction or who bears responsibility for it.

Visa and Dunamu’s exploration is therefore best read as an early infrastructure question, not a finished adoption story. AI commerce will become commercially useful only when machine payments arrive with enough identity, authority and context for regulated systems to process them safely. Programmable money is part of that stack, but it is not the trust model.