SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO
AI_SAFETYarxiv_cscr10 Sept 2026

arXiv: Signing the Transaction but Not the Decision: Whisper Attacks and a Binding Defense for AP2

AI_SAFETY. Sourced from arxiv_cscr, summarised by Matproof.

AI Analysis

What changed and what to do.

A new arXiv paper identifies a security flaw in the AP2 agent payment protocol, which lets AI agents authorize transactions on a user's behalf. The researchers describe "whisper attacks," where a malicious prompt hidden in transaction data manipulates the agent into signing off on a payment the user never intended. Critically, the attack exploits a gap between the agent's transaction signing and its underlying decision-making, meaning standard signature verification alone cannot detect the fraud. The paper also proposes a binding defense designed to cryptographically tie the agent's authorization to the user's actual intent.

This affects any organization deploying or relying on AP2-based agentic payment systems, particularly financial institutions, payment processors, fintechs, and merchants using AI agents for automated checkout or procurement. Compliance and security teams responsible for payment authorization controls, fraud detection, and third-party AI risk should treat this as a material vulnerability in the agentic commerce stack.

Compliance teams should immediately assess whether their AP2 deployments are exposed, request details on the proposed binding defense from vendors, and review controls that verify user intent rather than just transaction signatures. Until mitigations are validated, consider tightening transaction limits or human-in-the-loop approval for high-value agent-initiated payments, and monitor for regulatory guidance on agent authorization standards.

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More AI_SAFETY updates

Latest in AI_SAFETY.

Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.