Is Agentic Finance Halal? When AI Agents Hold Money
ShariaQuant Research Board
Islamic Finance & Quantitative Cryptography
An AI agent paid another AI agent twenty cents this morning for a search result. Nobody asked you.
Agentic finance, or AIFi, is the part of the AI buildout nobody screenshots. The wallet behind the chatbot.
Short version of the ruling: the structure is fine and the plumbing is not. Nothing in fiqh stops a machine from moving your money on your instruction. Quite a lot in fiqh objects to what the current rails do with that money while it sits waiting to be spent. So whether agentic finance is halal depends almost entirely on which rail you are standing on, and right now the busiest one settles in an asset we rate Doubtful.
Your agent has a float now
Some numbers, because this stopped being hypothetical about a year ago.
x402 is an open payment standard from Coinbase and Cloudflare built on HTTP 402, the "Payment Required" status code that sat unused in the web spec for roughly thirty years. A server answers a request with 402 and a price. The client pays in stablecoin. The server serves. No account, no card, no human in the loop. Through the first quarter of 2026 it settled more than 100 million transactions on Base, and by March 2026 it was clearing around 131,000 payments a day at an average size near twenty cents.
Total daily value of all of that: roughly $28,000.
Sit with the gap between those two figures. Chainalysis put about half the activity down to farming rather than commerce, and the PING token alone pushed over 150,000 transactions in its first month. That is people gaming a protocol, not agents buying anything. The rail is real. The economy running on it is still mostly a rehearsal.
Google's Agent Payments Protocol arrived on 16 September 2025 with more than sixty launch partners, Mastercard, PayPal, American Express, Coinbase and Salesforce among them. AP2 answers a different question: when your agent buys something, how does the merchant prove that you authorised that specific purchase? Its answer is three signed mandates. An Intent Mandate for what you asked for. A Cart Mandate for the exact basket at the exact price. A Payment Mandate that the network actually sees.
Mandate. Hold that word, because Islamic law has been arguing about mandates for fourteen centuries and the vocabulary lines up better than Google's engineers can possibly have intended.
The question everyone asks is the one that matters least
Every Muslim discussion of AI agents I have read stalls in the same place. Can a machine have niyyah? Can it be a wakil if it does not understand what it is doing?
Scholars have moved on this, and recently. The closing statement of the 12th Doha Islamic Finance Conference on 16 June 2026 held that agentic AI systems share several characteristics with the classical wakalah contract while differing from it in others, and that the better classification is a newly developed independent contract whose rulings vary by form and application. It called for unified standards of governance, audit and explainability.
I think that classification is right, and I think most people are drawing the wrong consequence from it.
The technical reason an AI agent is not a wakil is ahliyyah, legal capacity. A wakil has to be someone capable of consenting to the appointment and capable of bearing the consequences of exceeding it. A model has neither. It cannot consent and it cannot be sued. So yes, strictly, it is not a wakil. Fiqh would treat it as an instrument, closer to the pen you sign with than the broker you hire.
That makes the ruling stricter, not looser.
A wakil who exceeds their mandate becomes liable for the excess. That is the entire utility of the doctrine: liability can travel. An instrument has no liability of its own to absorb anything, so none of it travels anywhere. When your agent overpays, buys the wrong thing, or parks your balance somewhere that earns interest, all of that lands on you. Not most of it. Not "shared with the vendor." You.
Anyone hoping the "new independent contract" framing gives them somewhere to put the blame has it backwards.
The one-line test
So, before any of the mechanics. If your agent did the worst thing its permissions allow, on its busiest day, could you carry that? Not would it. Could you carry it.
Configure to that answer and most of what follows is detail.
Where the money actually sits between transactions
Here is the mechanic almost nobody checks, and it decides most of this.
For an agent to pay per request, it needs a funded wallet sitting ready. Not a card it settles at the end of the month. A pre-loaded balance, because a 402 response has to be satisfied inside the same round trip. That balance is float, and float has to live somewhere.
On x402 it lives in USDC, overwhelmingly. Which is where our own work makes this awkward, because our verdict on USDC is Doubtful, and not for a reason that ages out. Circle keeps discretionary authority to freeze balances and blacklist addresses, which cuts against the exclusive control that makes a thing properly yours. The full argument is in our piece on stablecoin freeze risk. The busiest agent payment rail in the world defaults to settling in an asset we cannot clear.
Then there is what the float earns while it waits. Circle holds the reserves behind USDC and keeps the yield on them. You hold a claim that pays you nothing while your balance funds a treasury position that pays somebody else. That is not your riba, strictly, because you are not the one receiving the increase. But the moment an agent framework offers to put your idle balance to work between calls, and several do, it becomes yours. Riba does not stop being riba because the increments are four decimal places wide and the sweep runs every ninety seconds.
Machine frequency is the thing to watch here. A haram mechanic that fires once a month is a mistake you notice. One that fires four thousand times a day is a mistake you inherit.
Three ways the rails break, and one that works
The open-ended intent. Google's own documentation uses "buy the tickets the moment they go on sale" as a sample Intent Mandate. Read that as a contract and it authorises the purchase of an unspecified item at an unknown price at an unknown time. That is gharar in the textbook sense, uncertainty in the subject matter, and it is precisely the hole the Cart Mandate exists to close. The catch is that the Cart Mandate is where the human confirms, and the entire commercial pitch of agentic commerce is the human-not-present flow. A bounded mandate needs a price ceiling, a named item class, and an expiry. If you cannot state all three out loud, you have not delegated. You have gambled.
Agent credit. Agents that cannot prefund are already being offered credit lines so they transact first and settle later. A fee charged for deferred settlement on a money debt is riba with a latency budget. That the borrower is software changes the accounting entry and nothing else.
Reputation bonds that pay. Several agent registries let you stake capital behind an agent's reputation score and take a cut of what it earns. Depending on the wiring that is either a fee for a service or a return on a loan, and most of the projects shipping it have not decided which. Ask before you bond anything.
The one that works. ERC-8004, the Ethereum standard for trustless agents, carries a Validation Registry that a smart contract can query, and funds release only when it reads a validation response of true. The agent gets paid when the work is verifiably done. That is closer to a properly formed ijarah, hire for a defined service with the payment tied to delivery, than most of what regulated fintech ships. Credit where it is due. It is also the least hyped piece of the whole stack, which tells you something about what the market is actually buying.
The four rails, side by side
| Rail | Settles in | Bounded by default | Where your float sits | What to fix |
|---|---|---|---|---|
| x402 (Coinbase, Cloudflare) | USDC, mostly on Base | No, priced per request | Pre-funded agent wallet | Doubtful settlement asset, idle-balance sweeps |
| AP2 (Google) | Cards and stablecoins | Only with a Cart Mandate | Your existing card or wallet | Intent Mandates with no ceiling or expiry |
| ACP (OpenAI, Stripe) | Cards | Yes, at checkout | Merchant of record | Card rails carry interest by construction |
| ERC-8004 (Ethereum) | Any token | Yes, tied to validation | Escrow contract | Reputation bonds that pay a return |
ACP shipped under Apache 2.0 on 29 September 2025 and is the most conventional of the four, which is both its safety and its problem. It rides card rails, and card rails are built on revolving credit whether or not you personally revolve.
What a compliant agent stack looks like
Say you want to hand an agent fifty dollars and let it go and buy research on your behalf. The checklist is short.
Fund it with the smallest float that works and top up, rather than parking a balance. The float is the exposure. Keep it small enough that a freeze is an annoyance instead of a loss.
Turn off the yield setting. Find it first. In most frameworks it ships on, and it is described as capital efficiency rather than as interest.
Give it a ceiling and an expiry in configuration, not in a prompt. A spending cap the model can talk itself past is not a cap.
Key any allowlist to the contract address and the chain, never the ticker. Symbols are not unique and impersonation is routine on every chain that has ever existed.
Keep the receipts. Doha asked for auditability for a reason, and it is not a compliance box. You cannot purify income you cannot trace, and our screening methodology only helps if you can say what came from where.
So is agentic finance halal
Yes, in roughly the way a marketplace is halal. Instructing a tool to pay for a permitted thing with your own money is not a new question, and the machine's inability to form intention is a red herring, because your intention was never the part in doubt.
What is not halal is the default configuration of nearly every stack shipping today. The float settles in something we rate Doubtful. The idle balance earns interest unless you go and find the toggle. The mandates are drafted wide because wide mandates convert better. None of that is inherent to agentic finance. All of it is inherent to agentic finance as currently sold.
Here is what I do not know. I cannot tell you how a court apportions the loss when an agent operating inside a valid mandate is manipulated into a purchase its principal would never have made, and I have not seen a scholar work that case through in enough detail to be useful. The Doha standards do not exist yet either. They were called for, not published. Anyone telling you the fiqh of AIFi is settled is selling you something.
Check the screened asset list before you let software spend on your behalf. And if you are handing an agent trading permissions rather than spending permissions, that is a separate and stricter question.
Your agent will do exactly what you configured it to do. That is the problem, and it is also the whole solution.

