Yesterday's brief said the rulebook would arrive unfinished. It did. US regulators reached the GENIUS Act's one-year rulemaking deadline on 18 July without issuing the final rules the framework needs, and the day after, nothing about the timetable at the far end has changed. Meanwhile the rail the rules are meant to cover keeps consolidating, and the part nobody has built yet is what happens when an agent buys the wrong thing.

The rules did not land, and the clock at the other end kept running

Regulators hit the 18 July deadline without final regulations to implement the federal stablecoin framework, leaving the core proposals unfinished [1]. Comments on the joint customer-identification rule stay open until 21 August, and an FDIC anti-money-laundering proposal runs until 4 August, which means the text that decides who may issue and under what identity checks is still being argued after the date it was due [1].

Missing the deadline did not buy anyone extra time

The delay does not push back the law's 18 January 2027 effective date, so every week of rulemaking that runs over comes straight out of the implementation window on the other side [1]. The statute itself set the one-year mandate for six agencies, so the compression is a matter of arithmetic rather than interpretation [2]. Issuers now have to build toward requirements whose final wording they will read late, against a date that has not moved.

The rail the rules will govern is still consolidating

On 14 July the Linux Foundation launched the x402 Foundation with 40 founding members to steward the HTTP-based protocol for autonomous payments, covering the card networks, the processors, cloud, stablecoin issuers, and several chains at once [3]. Visa, Mastercard, Stripe, and AWS are among them, which puts direct commercial rivals inside one governance body for the plumbing [4]. The protocol has already moved about 75 million transactions worth roughly 24 million dollars in a month, averaging 32 cents apiece [3].

The dispute layer is the piece nobody finished

Card networks have activated agent payments this year, but the machinery for handling a contested agent purchase has not caught up, and no jurisdiction has yet enacted regulation aimed specifically at autonomous purchasing [5]. Disputes on agent-initiated transactions are running at roughly 2.4 times the rate of comparable card-not-present transactions, and the mix is different: fewer straight fraud claims, more "did not authorise" and "not as described" [5]. Merchants carry that liability today without the evidence trail needed to defend it [6].

Read from the rails

The interesting number this week is not the missed deadline. It is 2.4 times. A dispute rate that shape is not a fraud problem, it is an evidence problem, and the two get treated very differently by anyone who has sat through a chargeback review. Fraud you can score. "I did not authorise that" you can only answer with a record: what the agent was permitted to do, what it was asked to do, what it actually did, and when. If that record does not exist at the moment of the transaction, it does not exist at all, because you cannot reconstruct intent after the fact.

Ten years in payments operations taught me that disputes are where the design flaws in a rail finally show up in writing. So the question I would put to anyone shipping agent checkout now is narrow and boring. Does every agent-initiated payment carry a stored authorisation scope, a timestamp, and something that ties the instruction back to a human decision? If yes, you can argue a case. If no, you will lose them one at a time until your ratios drift toward scheme thresholds, and no final rule published in October will retroactively give you the logs.

A rail without a dispute record is not a payment system. It is a series of transactions you cannot explain later.

Building in agentic commerce or payments?

This is the intersection I work in. Book thirty minutes and we will scope the build worth doing.

Book an AI consultation