Stablecoins and tokenized assets are changing what wallets can hold, and AI agents will change what wallets can do. The legal architecture must now catch up.
By Edwin Mata, CEO and Co-Founder of Brickken
Most conversations about digital wallets still begin with convenience: one place for cards, accounts, credentials and digital assets. With these changes, that’s no longer the most important part of the story.
We still picture the wallet as the product we see on a phone. In practice, it is moving behind the interface. Today, it has become the point from which a person or institution can identify itself, hold money and assets, access financial services and give instructions across several rails.

Stablecoins and tokenized deposits make value available in programmable environments. Tokenized securities and funds can bring transfer restrictions, distributions and settlement into the same operating layer. Once an AI agent is added, the user may no longer press every button personally as the agent can compare options, prepare an instruction and, within defined limits, execute it.
As a lawyer, I find the word “autonomous” less useful than “authorized.” Finance has always relied on people and systems acting for somebody else. The difficult question is actually whether the software had authority to do that specific thing, on those terms, at that time.
That question is already practical. The Bank for International Settlements has described tokenized money and assets operating through programmable workflows. Europe is implementing a digital identity wallet framework. Google’s Agent Payments Protocol uses signed mandates to evidence user instructions, and in March Santander and Mastercard reported a live AI agent payment conducted within predefined permissions and limits.[1-4]
The wallet is where identity, assets, and delegated authority meet.
Consider a corporate treasury agent instructed to keep surplus cash available within 90 days. It places EUR 500,000 into an instrument that produces a positive return but cannot be redeemed for six months. The transaction made money and still breached the mandate. An agent might equally make a permitted investment that falls in value. That may be a bad financial result without being an unauthorized act.
Outcome is therefore a poor test of authority. A loss does not prove that the system acted improperly, and a profit does not cure an action taken outside the powers granted to it. The first issue should be whether the agent remained within its mandate.
The law already has tools for automated action. UNCITRAL’s Model Law on Automated Contracting provides a framework for legally recognizing automation and AI in contract formation and performance.[5] It does not turn software into a legal person or remove the need to attribute an instruction to the person or institution behind it.
At the institutional level, a mandate has to be more precise than “optimize returns.” It should identify the principal, permitted systems, eligible assets, approved counterparties, jurisdictions, purpose and duration. It should also set transaction and exposure limits, liquidity thresholds and the actions requiring a second signature or human approval.
Draft ERC-8226, the Regulated Agent Mandate proposal, offers one technical model. RAMS allows a verified principal to delegate authority to an agent subject to a defined scope, duration, asset, permitted actions and financial caps. It also provides for compliance checks, revocation, freezing and execution records.[6]
RAMS is a draft proposal, not a complete legal answer. An on-chain mandate cannot determine whether an officer could bind a company, an investment complied with fiduciary duties or a regulated service was lawfully provided. It can make important parts of the delegation machine-readable and enforceable when a transaction is attempted. That is better than discovering the limits afterwards.
The wallet metaphor can be misleading in another way. A wallet generally controls keys or credentials. It does not, by itself, establish legal ownership of the asset displayed.
A stablecoin is not automatically a bank deposit, legal tender or settled cash. The holder’s rights depend on the issuer, reserve arrangements, redemption terms and applicable law. The same is true of a tokenized security or fund interest. Its legal effect comes from governing documents, the relevant register, transfer rules and the surrounding legal system. The UNIDROIT Principles on Digital Assets and Private Law address this separation between control, transfer, custody and proprietary rights.[7]
An agent choosing between assets needs more than a ticker and price. It needs reliable information about what the asset represents, who issued it, who may hold it, which restrictions apply, how valuation and redemption work, what backs it and which record controls the legal position.
This is the role of a regulated asset claims layer, or RACS. Draft ERC-8320, the Regulated Asset Claim proposal, sets out a registry for signed, versioned and role-controlled claims concerning identity, valuation, terms, compliance, backing, events and risk.[8] A claim can show who made an assertion, under what authority, in which version and whether it changed. It does not prove that the assertion is true.
RACS and RAMS answer different questions. RACS helps a machine understand what an asset claims to be. RAMS helps determine what an agent is permitted to do with it. A constrained agent can still make a poor decision if the asset information is unreliable, while excellent asset data is of limited value if the agent’s authority is vague.
There will rarely be a single party called “the AI” behind an agentic transaction. The chain may include the principal, wallet provider, agent developer, identity service, bank, custodian, execution venue and data providers. Liability will depend on the obligation each party assumed and the control that failed.
Where the agent acted within a valid mandate, the principal may bear the economic consequence, subject to duties owed by advisers, regulated firms and service providers. Where the agent ignored a limit, used an unapproved venue or continued after revocation, attention moves to the authorization architecture. A compromised credential raises security and custody questions. A missed sanctions or investor eligibility check remains attributable to the party required to perform it. Incorrect asset information directs attention to whoever supplied or validated it.
Europe illustrates why no single regulation will resolve every case. MiCA addresses parts of the crypto-asset and stablecoin layer. DORA governs operational resilience for regulated financial entities. The AI Act allocates obligations for specified AI systems and their providers or deployers.[9-11] Agency, contract, payments, securities, anti-money-laundering, consumer and data-protection law will continue to operate around them.
By the time lawyers ask why an agent acted, the most important evidence should already exist. The record should show who granted the authority, which mandate applied, the credentials used, the policy and asset information considered, the compliance checks performed, any approval obtained, the instruction signed and the result.
This is not the same as retaining every model calculation. Nor is it enough to ask the model afterwards why it acted. A generated explanation may be useful, but it is not proof of authorization. The evidence must come from the systems that granted, checked and executed the mandate.
Financial-crime obligations attach to the activity, not to whether a human or software initiated it. FATF’s 2026 targeted update continues to identify implementation gaps involving virtual assets, the Travel Rule, stablecoins and unhosted wallets.[12] Agents may increase speed and volume. They do not reduce the need to identify relevant parties, apply risk-based controls and preserve an auditable trail.
The next wallet race will not be won by adding one more asset icon. The more important capability will be translating human and institutional intent into authority that is narrow, revocable and provable.
Agentic finance does not require software to become a legal person. It requires a better interface between law and technology. Software may act, but the authority behind that action must remain explicit, limited and attributable. Such systems will not eliminate responsibility. They will make it harder for responsibility to disappear.
References
- Bank for International Settlements, Annual Economic Report 2026, Chapter III: Anchoring trust in money: innovation beyond stablecoins.
- European Commission, European Digital Identity Regulation.
- Google Cloud, Powering AI commerce with the Agent Payments Protocol.
- Mastercard, Santander and Mastercard complete Europe’s first live end-to-end payment executed by an AI agent.
- UNCITRAL, Model Law on Automated Contracting, 2024.
- Ethereum Improvement Proposals, Draft ERC-8226: Regulated Agent Mandate.
- UNIDROIT, Principles on Digital Assets and Private Law.
- Ethereum Improvement Proposals, Draft ERC-8320: Regulated Asset Claim.
- Regulation (EU) 2023/1114 on markets in crypto-assets, MiCA.
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, DORA.
- Regulation (EU) 2024/1689 laying down harmonized rules on artificial intelligence, AI Act.
- FATF, Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs, 2026.


