Tell an agent to find you a morning flight with a carry-on and a checked bag for under $350. The instruction feels precise. It has a time preference, a baggage requirement, a price ceiling. Any competent travel agent would know exactly what to do with it.
But that sentence has to become something a payment network can enforce. Visa's developer documentation for agentic payments lists the fields available: a description, an amount with currency, a quantity, a merchant preference, a recurrence indicator, an expiration time. The natural-language request survives in a prompt field, but the controls that decide whether a transaction goes through check the intended merchant and the amount against the authenticated instruction. "Morning" is not a field, and neither is "carry-on and checked bag." Those preferences ride along as text the agent can use while searching. They never become constraints anyone can enforce at the moment money moves.
Visa's agentic payment rules require the agent to use only cardholder-defined purchasing criteria, obtain consent, verify identity, set an expiration. This is careful work. It is also necessarily silent about the preferences a cardholder cannot state in a form the network is able to check.
The IMF's April 2026 note on agentic payments names that boundary directly. It describes an instruction gap: the space that opens when account holders grant broad mandates and agents execute payments without transaction-level instructions. The example given is someone asking an agent to buy the latest book on a topic, at the best price, whenever it becomes available. The agent decides when to search, where to look, and which option counts as best. "Best" is no longer a parameter. It is a judgment, made by the agent, for someone who will see only the result.
The note separates two things that are easy to conflate. Intent is probabilistic: goals are conditional, they shift, they are sometimes unclear to the person holding them. Authorization is deterministic, requiring conditions that can be reproduced and read legally. Something resolves the difference, and the IMF is direct about the risk in that. Agents may optimize for a provider's incentives rather than the user's welfare, or drift from the original objective. The party filling the instruction gap has interests, and the person who supplied the ambiguity usually has no way to audit how it was settled.
Some preferences never make it into the mandate at all. Only from a seller with a decent return policy. Nothing from a manufacturer with a recent safety recall. An agent can weigh these while searching; the payment network cannot enforce them, because it has no mechanism for verifying them. The preference shaped the search and did not survive into the commitment.
A W3C workshop this month surfaced the phrase last reversible moment for the final checkpoint before an agent's action becomes irrevocable. Past that point, what the mandate's fields could not hold is simply not part of what was agreed.
People have delegated decisions to intermediaries for as long as there have been brokers and travel agents, with the same losses each time. What changes is speed, volume, and the disappearance of the moment when someone noticed an ambiguity and asked about it. The gap between what you meant and what the system did doesn't shrink because the system got faster; it becomes harder to find.

