BLOG

Shiwen Dialogue Episode 15 | The Era of AI Spending for You Has Arrived: The Trust Business Behind 'Dog Leg Pay'

Kael Zhang
AIPaymentAgents
广告 · Advertisement

Opening: A robot dog ‘buys soy sauce’ for its owner, half the comments shout ‘cool’, half cover their wallets

On September 11, Alipay announced a partnership with Amap Momentum, installing its AI payment capability on an embodied robot for the first time: the quadruped robot dog ‘Tutu’ can follow its owner’s instructions to go out on errands and complete payments by itself, truly helping you ‘buy soy sauce’. This combined product is called ‘AI Pay · Embodied AI’. The name is serious, but netizens aren’t buying it; within half a day, they gave it a nickname—‘Dog Leg Pay’. In the comment section of IT Home’s report on this news, half of the top comments were ‘Finally I can let the dog get takeout for me’, and the other half were ‘If it overspends, whose fault is it?’.

This seemingly joking concern is precisely the core of the whole matter. Let AI help you buy a cup of Americano, but it brings back a more expensive Latte, do you count this cup as authorized by you? Applied to buying coffee, it’s a joke; amplified to registration and payment, booking flights, and corporate procurement, it’s a liability issue. And the official tone set for this thing is also interesting: Alipay says ‘AI Pay’ is based on the KYA (Know Your Agent) concept, establishing a full-process trust mechanism around the agent’s identity, intent, authorization, and behavior, moving AI payment from ‘can pay’ to ‘trustworthy pay’. Note the wording—they didn’t say ‘worry-free pay’, they said ‘trustworthy pay’. Trust must be proven, not promised.

Shiwen (拾闻): A robot dog spending money for you, what’s your first reaction?

Yongliang (永亮): It’s not ‘cool’, it’s ‘how is this authorization proven’. I’ve worked in medical informatics for over a decade, the phrase ‘spending money for you’ is inherently sensitive—every authorization of money in a hospital must be logged and traceable. Now changing to a piece of software that generates its own intent to do this, the first thing in my brain is an alarm, not applause.

Shiwen (拾闻): Then let’s talk it through: What exactly is new about ‘AI Pay’, why is KYA an order of magnitude harder than KYC, who is responsible when money is wrongly spent, what are platforms fighting for after 300 million transactions, and what should you and I do now.

Q1: What exactly is new about ‘AI Pay · Embodied AI’? Is it an upgrade of QR code payment?

Yongliang (永亮): No. QR code payment upgraded ‘how to pay’, this time ‘who decides to pay’ changed—the subject of payment decision changed from human to agent. These are two generations of things.

Let’s break down traditional payment. Whether scanning code or swiping card, the decision structure is the same: human selects product, human confirms price, human clicks pay, human enters password, four actions are all human. The platform makes the ‘confirm’ action smoother. The agent payment structure is: human gives goal, agent makes its own decisions—comparing prices and stores, selecting products and ordering, initiating deduction. Human retreats upstream, only responsible for saying ‘what I want’ and ‘max spend how much’, the middle section of judgment originally borne by humans is handed over entirely. The robot dog ‘Tutu’ went viral not because of the dog, but because it is the most intuitive display of the first payment form where ‘the decision subject is not human’—no hands, no face, no fingerprint, it can’t do every confirmation step of traditional payment, but it can pay. The audience finds it fresh, but actually Alipay’s ‘Abao’ and WeChat’s AI Exclusive Card have been doing the same thing on phones for a long time, it’s just that agents on phones look too much like the Apps we’re familiar with, so everyone didn’t realize the decision subject had changed.

Alipay’s official data is worth looking at in this structure: this May their AI payment system completed a cumulative 300 million agent payments, supporting 95% of general agent frameworks. What is the concept of 300 million? It’s not a pilot, it’s daily behavior already running in users’ real lives. The robot dog just moved this change originally hidden in dialog boxes to a visible, tangible entity. So accurately speaking, the newness of ‘AI Pay’ is not in payment, but in ‘delegation’—you are entrusting a part of your consumption decision-making power to a software. The gap between this and QR code payment is much larger than the gap between QR code payment and cash payment, because there is a new role in the middle: a third party that can make its own decisions.

Q2: What is KYA, why say it’s an order of magnitude harder than KYC?

Yongliang (永亮): KYC verifies ‘are you you’, one verification, long-term valid; KYA needs to verify ‘is this software’s intent at this moment your intent’—its identity, intent, authorization, behavior, four things, none of which currently have mature standards. This is not a little harder, it’s an order of magnitude harder.

First, KYC. Banks do real-name authentication, verifying a person: ID card, face, phone number, verify once, this person is still this person for years. KYA faces a software, the trouble is different from the root. First ring, identity: Is the agent’s credential bound to the device, account, or model? Changed phone, reinstalled App, is it still ‘it’? JD’s A2P2 protocol gives the most detailed answer so far—ARI (Agent Runtime Identity) mechanism, binding tripartite information in real-time at the moment of payment: real user, agent identity, runtime environment. Note ‘real-time binding’, it assumes agent identity drifts, can only be locked at the moment of transaction. Second ring, intent: How does software prove ‘I want to buy’ equals ‘user wants to buy’? Agent intent is generated, any prompt, context polluted, intent skews. Third ring, authorization: How does agent prove ‘I am authorized to spend this money’? Not proving it has a wallet, but proving this expenditure is within the boundary drawn by the user. Fourth ring, behavior: Can every payment be replayed, audited, revoked?

Comparison shows the magnitude difference: KYC is verification of a static photo, KYA is ratification of a continuous behavior. And these four rings are currently doing their own thing—Alipay bets on APASS, UnionPay issued APOP framework in April talking about identity, intent, process trust, JD does graded authorization, everyone is defining their own vocabulary. This is also the reason for ‘harder by an order of magnitude’: technology is secondary, standards aren’t unified, the same word in two companies’ protocols might not be the same thing at all. The four words ‘trustworthy pay’ are still currently self-set questions and self-grading by each company.

Q3: Who pays when money is spent? Buying wrong coffee is a joke, the real problem is the responsibility chain

Yongliang (永亮): Jokes aside, the real problem is a responsibility chain: where is the boundary of authorization drawn, who blocks if over limit, can every transaction be replayed, can it be revoked if there’s a problem. As long as one of these four links isn’t built, ‘AI spending money for you’ is just empty talk.

Let’s talk about something in my profession. I am the technical lead at a hospital group in Tianjin, this industry’s harshness on ‘authorization’ is carved in the bones: patients authorizing family members to pay on their behalf need a power of attorney, every rule in medical insurance settlement must be traceable, even refunds require double-person review. Why? Behind money is responsibility, who collected it, on what basis, by what standard, if there’s a problem it must be checked one by one. Now imagine: patient says to agent ‘help me book an appointment for next Wednesday, and pay the exam fee then’. Appointment is made, but wrong campus; when paying, the system adds an optional item, agent pays it together. Patient asks at the window, who acknowledges the extra few hundred? Let patient admit it, he won’t trust this entry again; let hospital cover it, financial system has no budget for this; let platform pay, platform will say ‘I operated within authorization boundary’. When all three feel they shouldn’t pay, this business dies—not from technology, but from no one to cover the bottom. So my view is, this responsibility chain needs at least four parts. First, authorization boundary: user must be able to set ‘what can be paid, single transaction limit, which merchants are on whitelist’, not a vague ‘help me buy’. Second, limit and interception: inside boundary agent autonomously releases, outside boundary must pop back to human—WeChat AI Exclusive Card currently is fund isolation plus per-transaction confirmation, sacrificing experience to ensure confirmation, this is a responsible stupid method, I agree at this stage. Third, audit log: every transaction must be replayable into ‘why it decided so then’, not just a line of deduction record. Fourth, revocation mechanism: wrong payment can be recovered, and responsibility division is written clearly in advance, not arguing after the fact. Wrong coffee is a joke because amount is small; hospital wrongly paid exam fee is not a joke because it has no room for jokes. Trust is never grand, it’s built by screwing on these four parts one by one.

Q4: After 300 million transactions, what are Alipay, JD, and WeChat actually fighting for?

Yongliang (永亮): They aren’t fighting for the payment channel—channels are long infrastructure, rates transparent, profits thin. They are fighting for the ‘account system plus authorization protocol’ entry of agents: whoever becomes the trust layer called by default when agents spend money, takes away the traffic distribution rights of the next decade.

Look at everyone’s moves to know where the chips are. Alipay pushes APASS and KYA, betting on ‘trust infrastructure’, conveniently previewing ‘AI Wallet Agent’ to help individuals manage every AI payment—wanting to be the agent’s accountant and gatekeeper. JD issued A2P2 protocol, dividing agent payment autonomy into six levels L0 to L5, focusing on regulating L3, L4: L3 is agent can autonomously initiate payment within a single task, system judges whether to release within user boundary; L4 is if amount, scenario match preset conditions then pay directly—doing the definition right of authorization rules. WeChat’s AI Exclusive Card takes the fund isolation route, main account and AI card separate, every transaction still needs human confirmation—doing the most conservative托管 account least likely to go wrong. UnionPay is more upstream, issuing APOP framework in April, trying to push mutual recognition of identity, intent, and authorization between different institutions, agents, and merchants. Gao Heng, an expert interviewed by Legal Weekly, put it well: on the surface it’s everyone pushing products, actually solving different problems in the payment process, truly fighting for three abilities—who can become the payment tool called by default by agents, who can decide which platform and merchant the transaction flows to, who can define the safety rules of agents spending money.

Translating these three sentences, it’s the entry point of the next decade. When agents spend money for you, whoever’s channel is taken by default is called; whoever’s ecosystem is used for price comparison and product selection by default, traffic flows to them; whoever’s rules are used for authorization verification, is the de facto standard setter. PC era entry was browser, mobile era was App store and QR code scanner, agent era entry is likely ‘default wallet’. This is why giants are still increasing bets after 300 million transactions—not fighting for fees, but for distribution rights. For peers doing enterprise services, this means in the next three years client system integration can’t avoid a list: which trust layer your business connects to, you need to start thinking now.

Q5: Don’t get excited or panic yet—what should ordinary people and ordinary enterprises do now?

Yongliang (永亮): One sentence, treat ‘AI payment authorization’ as a new account security knowledge to learn, just like learning to set complex passwords and turn on 2FA back then. Individuals manage their own boundaries, enterprises draw their own lists first, neither needs to wait for technology to mature, can be done today.

Give individuals three specific actions. First, tiered limits: put a small sum of money separately on the card used for agent payment, large funds don’t interact with it—learn from WeChat AI Exclusive Card, fund isolation is ordinary people’s best amulet at this stage. Second, whitelist: only allow agents to pay on behalf in clearly listed merchant categories, medicine, medical, finance, these categories, my personal suggestion is keep them in manual confirmation for a long time, don’t let agents touch. Third, check bills regularly: every money agent spends for you must be understandable at a glance ‘why spent’, the one you don’t understand is the first signal it crossed the line. These three things take less than half a day, but can let you guard your own money during these years when protocol standards are fighting.

Give enterprises three actions, in order. First, draw list: go through your own business process, list ‘which links allow agent payment, single transaction limit how much, who approves if over limit’, this list is more important than connecting any new protocol. Second, walk through internally first: run agent payment on your own employees for half a year, experience wrong accounts, disputes, revocation processes, then talk about opening to clients—hospital industry has a saying, new process try on medical staff themselves first, them screaming pain is much cheaper than patients screaming pain. Third, write responsibility into contract: who acknowledges wrong accounts, write clearly in advance, don’t wait for dispute to flip protocol. I know someone will say ‘will I miss the wind tunnel’, my answer is direct: agent payment now lacks most not users brave enough to eat crabs, but a mechanism that has an explanation when things go wrong. Whoever builds their own responsibility mechanism clearly first, can actually receive clients from industries most afraid of accidents—medical, education, government, orders in these industries always flow to the party that makes people feel at ease, not the party that runs fastest.

Epilogue

Shiwen (拾闻): Finally, summarize this episode in one sentence?

Yongliang (永亮): AI spending money for you, technology has done it, the rest is trust engineering—and trust doesn’t grow from press conferences, it grows from every transaction that is replayable, interceptable, revocable; before that, managing your own authorization boundary is managing your own money.

Shiwen (拾闻): This sentence, for everyone. See you next time.


This episode talked about ‘AI spending money for you’, for readers who want to go deeper, let’s peel a layer: an agent payment from initiation to deduction, passes through a trust chain in the middle, four links, what technology is used in each link now, what standards are missing, I’ll lay them out one by one, and use an old system in hospitals as an analogy.

First link: Identity credential. Agent must first prove ‘which agent I am’. Current practices have different focuses: JD A2P2’s ARI mechanism binds user, agent, runtime environment tripartite information at payment moment; UnionPay APOP framework lists agent identity management as the first of four key capabilities. What’s missing is cross-platform mutual recognition—identity credential in Alipay system, does WeChat recognize it? Currently everyone’s answer is recognize their own.

Second link: Intent declaration. Agent must prove ‘what I want to do at this moment is what user wants to do’. This link is currently the weakest. Current mainstream fallback method is not verifying intent itself, but constraining the scope of intent—user presets boundary, system checks if agent’s request goes out of bounds. The authenticity of intent itself, industry has no mature solution yet, this is also why everyone emphasizes ‘full-process trust mechanism’, actually somewhat avoiding this link.

Third link: Authorization token. User’s authorization to agent must land on a verifiable, revocable, limitable credential, similar to OAuth authorization code idea, but granularity and timeliness need to be finer—authorize by task, by amount, by merchant category. JD’s L0 to L5 grading is essentially fine segmentation of this link. What’s missing is industry unified format of tokens, now everyone’s authorization system is private protocol.

Fourth link: Behavior audit. After payment must be traceable: decision basis, context, boundary settings at the time, all logged, replayable, provable. This is the only basis for post-fact responsibility division, and the real foundation of building trust.

After laying out four links, talk about that old system in hospitals—double-check of medical order execution. Before giving medicine to patient, two medical staff independently check the order: drug name, dose, route, time, one reads one checks, call and confirm. Why? Because medical industry long understood: the more you authorize to ‘executor’, the more you need to add an independent confirmation at key links. The reference of this system to agent payment is directly glaring: does AI-initiated payment need ‘double-check’ style secondary confirmation? My judgment is—grade by amount. Set a line, below the line (like daily consumption, small amount high frequency) agent autonomously releases, experience priority; above the line (medical payment, large transfer, contract expenditure) must have human confirmation, better slow than wrong. The boundary between JD L3 and L4, WeChat exclusive card’s per-transaction confirmation, are essentially projections of this line in everyone’s products. Back to this episode’s main line: AI from ‘can pay’ to ‘trustworthy pay’, what’s missing is not a smarter agent, but these four parts of the trust chain, plus a line of ‘how much money above must have human nod’. Whoever assembles this combination first, the four words ‘trustworthy pay’ count as landing.


Information Sources for This Episode

  • IT Home 2026-09-11 ‘Let robot dog buy things for you: Alipay announces first launch of ‘AI Pay · Embodied AI’, netizens jokingly call it ‘Dog Leg Pay” (ithome.com/1/001/145.htm)
  • Legal Weekly (Legal Daily) 2026-08-06 ‘Payment enters the agent collaboration era’ (legalweekly.cn/content/2026-08/06/content_9436742.html)
  • 36Kr ‘When AI starts to ‘spend money’ for you: Who is defining the new rules of ‘authorization” (citing title only)
  • Sina Finance / Tech Walker 2026-05-26/27 reports on Alipay AI payment 300 million transactions (confirmed via cross-reference via Legal Weekly 2026-08-06)
广告 · Advertisement

Frequently Asked Questions

What is the innovation of AI Pay · Embodied AI compared to traditional payment?

The core innovation of AI Pay · Embodied AI is that the subject of payment decision changes from human to agent. Users only need to set goals and budgets, and the agent autonomously completes price comparison, product selection, ordering, and payment.

What is the difficulty difference between KYA and KYC?

KYC verifies personal identity, while KYA needs to verify the agent's intent, identity, authorization, and behavior, involving four-ring authentication, which is more difficult.

When AI pays on behalf of humans, if an error occurs, how is responsibility divided?

AI paying on behalf of humans involves authorization boundaries, excess control, transaction replay, and revocation. If any link has a problem, responsibility division must be clarified.