OKX’s Gracie Lin Says AI Agents Need Sub-Cent Payments as Bank Rails Slow Tasks

2 weeks ago

Global laws are inactive trailing the exertion erstwhile it comes to determining who is liable if an artificial quality (AI) cause is hacked oregon makes a faulty purchase. Gracie Lin says that with ineligible frameworks inactive being drafted, accountability needs to beryllium built into the infrastructure from time one, not bolted connected later.

Key Takeaways

  • OKX’s Gracie Lin warned AI agents look CAPTCHAs and MFA blocks successful 2026 commerce.
  • Lin said blockchain handles 100s of micropayments portion banks lag connected colony speed.
  • OKX open-sourced its MIT-licensed cause kit arsenic AI outgo standards instrumentality shape.

The Impasse of Human-Centric Systems

The modern net is plagued by a quiet, cardinal friction. For decades, the architecture of web information and physics payments has been built connected a single, binary premise: “Prove you are human.”

Every CAPTCHA, one-time code, and redirect leafage functions arsenic a integer checkpoint designed to support platforms against automated abuse. But arsenic autonomous artificial quality agents statesman browsing e-commerce storefronts, comparing marketplace liquidity, and executing transactions connected behalf of users, these bequest defenses instantly alteration from captious shields into operational roadblocks.

According to Gracie Lin, CEO of OKX SG, this collision represents a captious turning constituent for integer infrastructure.

“Yes, it’s a existent tension,” Lin notes. “Every friction constituent we brushwood online was designed with a quality connected the different end. CAPTCHAs, one-time codes, redirect pages—all presume idiosyncratic is sitting determination speechmaking and clicking. When the histrion is an AI agent, those aforesaid mechanisms go blockers.”

In an ecosystem built for humans, an AI cause faces an existential situation astatine checkout. Behavioral biometrics mistake an agent’s structured programmatic interactions for malicious hacking. Multi-factor authentication loops destruct automation by demanding a human-in-the-loop to input a substance code. Meanwhile, web exertion firewalls emblem high-velocity terms comparisons arsenic distributed denial-of-service, oregon DDoS, attacks.

This friction is peculiarly acute successful the integer plus sector. “In crypto, agents are progressively being utilized to execute trades, negociate wallets, and interact with onchain services autonomously,” Lin explains.

For those extracurricular the crypto ecosystem, an evident question arises: Why not conscionable upgrade accepted banking? The issue, Lin points out, is foundational.

“Traditional banking was built astir quality actors: radical authorizing transactions, banks verifying identity, colony taking days,” Lin explains. “You tin upgrade parts of that, but you’re inactive moving wrong architecture that assumes a idiosyncratic is progressive astatine each captious step. Blockchain doesn’t marque that assumption.”

When an cause needs to execute hundreds of sub-cent micropayments crossed antithetic APIs to implicit a azygous complex task, bequest colony rails fail. “For an AI cause making hundreds of micro-payments crossed antithetic services to implicit a azygous task, the accepted strategy simply doesn’t enactment astatine that velocity oregon scale,” Lin says. Blockchain networks natively connection the programmatic, instant, and borderless infrastructure this instrumentality system requires.

The Liability Vacuum: Defining Agent Accountability

As these agents scale, they present terrible method risks, specified arsenic indirect punctual injection—where malicious, hidden website substance tin hijack an agent’s programming to bargain assets. This world exposes a glaring, unresolved dilemma: If an AI makes a disastrous acquisition oregon gets hacked, who is responsible?

“I’ll beryllium upfront: I’m not a ineligible expert, and this is genuinely 1 of those areas wherever the instrumentality is inactive catching up to the technology,” Lin admits. “What I tin talk to is the work question astatine the infrastructure level. For immoderate subordinate successful this space, it’s important to cook accountability into AI tools from time one.”

While planetary regulators scramble to draught ineligible definitions, users cannot beryllium near vulnerable. The solution requires hardcoded boundaries.

“Control has to beryllium designed successful from the start,” Lin emphasizes. “The cause should lone person entree to what it needs for the task astatine hand, not a blank check. That means permissioned access: if an cause isn’t authorized to trade, it simply shouldn’t beryllium capable to effort it.”

To enforce this, Lin argues that next-generation infrastructure indispensable trust connected 3 halfway information pillars. First, an AI exemplary indispensable ne'er person nonstop entree to basal fiscal keys. “Your private keys should beryllium secured successful a protected situation the exemplary ne'er touches,” Lin says, suggesting isolation wrong hardware information modules oregon smart contract vaults.

Second, earlier an agent’s payload executes, it indispensable tally successful an isolated sandbox to unmask the nonstop question of funds. “Transactions… tin beryllium simulated earlier execution happens and thing flagged arsenic high-risk tin beryllium blocked automatically,” Lin explains.

Lastly, agents indispensable beryllium their individuality via public- private key pairs alternatively than quality behavioral tracking. If a petition crosses pre-set hazard thresholds, it is instantly blocked oregon flagged for manual quality sign-off.

“The exertion to bash each of this exists contiguous connected crypto rails,” Lin reveals. “The question is whether the radical gathering these tools prioritize it.”

The Fork successful the Road: Monopolies vs. Open Standards

As the instrumentality system hardens, a pivotal question emerges: Will a fistful of Big Tech companies power however AI agents walk our money, oregon volition the aboriginal stay open? Proprietary, closed-loop cause layers hazard creating firm gatekeepers that monopolize idiosyncratic information and restrict merchant access.

Lin warns that this hazard is imminent: “There’s a existent mentation of this aboriginal wherever a fewer platforms power the cause furniture and by hold however AI spends your money. It should beryllium open, and astatine OKX we are trying to acceptable a bully example.”

To antagonistic this, platforms are shipping functional, decentralized tools. The OKX cause commercialized kit, for example, is afloat open-source nether an MIT licence with its codification publically auditable connected Github, portion the Agent Payments Protocol establishes an unfastened modular that immoderate concatenation oregon developer tin implement. Because unfastened blockchain infrastructure isn’t owned by immoderate azygous entity, it preserves a neutral, competitory landscape.

“If the outgo rails and protocols are built arsenic unfastened standards now, portion the architecture is inactive being decided, the competitory scenery stays unfastened for everyone,” Lin says. “The model to get this close is now.”

View source