Field Dispatch

Payments

Money used to be a medium of exchange. It is becoming a permission system. The shift is incremental. Each step is reasonable on its own terms. Aggregated, the steps have the property that an entity's ability to transact, to spend its own…

2026-08-02 20 min read Dispatches
Companion to Quiet Autocomplete

Money used to be a medium of exchange. It is becoming a permission system.

The shift is incremental. Each step is reasonable on its own terms. Aggregated, the steps have the property that an entity’s ability to transact, to spend its own legally-acquired funds on a legal purchase from a willing seller, is conditional on a sequence of automated approvals running against an aggregate of databases the transacting entity has no ability to inspect, audit, or appeal.

In the United States, FedNow, the Federal Reserve’s instant-payment system, went live in mid-2023. By 2026, its ScamClassifier component, a machine-learning model trained on payment-pattern data across participating banks, was making real-time approval decisions on individual transfers above a configurable threshold. The threshold varied by participating bank. The decisions were not, in any documented case, reviewable by the transacting party in real time. A blocked transfer simply did not go through. The receiving party’s bank account showed no deposit. The sending party’s bank account showed no debit. The party that had attempted to send money was told, by the originating bank’s app, that “your transfer could not be completed at this time. Please try again later.”

No debit, no deposit, no appeal. “Could not be completed at this time” is the modern excommunication, delivered as an error message.

The Consumer Financial Protection Bureau (CFPB) issued a Circular in 2023, Circular 2023-03, clarifying that the Equal Credit Opportunity Act applies to AI-driven lending decisions, and that lenders using AI models for lending decisions must be prepared to produce an “adverse-action notice” explaining the reason for any denial. The Circular was clear. The Circular was actionable.

Compliance, as of May 2026, was uneven. The major U.S. lenders had, by various means, taken positions: some had front-loaded the AI decision into a “pre-screening” step that was characterized as not formally a denial; some had developed adverse-action notices that complied with the letter of the Circular while disclosing essentially nothing about the model’s reasoning; some had simply not bothered.

The Consumer Financial Protection Bureau, in March 2025, was reorganized under the second Trump administration. Its capacity to enforce its own Circulars was reduced to a fraction of its 2024 level. Compliance, by mid-2026, was, in operational terms, voluntary.

This is the precondition for everything that follows. The rule exists. The rule is clear. The rule is, as a practical matter, not enforced. The decisions go on being made, in milliseconds, by models nobody is required to explain.


Consider a day.

The day belongs to no one in particular. Which is the point. It is the day of a person with a job, a bank account, a phone, and no criminal record, in the United States, in 2026. The person does nothing unusual. The person breaks no law, evades no tax, attends no protest, sends no money to a sanctioned entity, and at no point during the day is informed that a decision has been made about them. By the time the person goes to bed, somewhere between six and a dozen automated systems will have evaluated whether the person may spend the person’s own money, and the person will be aware of approximately none of it.

The day begins with coffee.

The coffee is four dollars and fifty cents, paid by tapping a phone against a terminal. The payment routes through an instant-transfer rail — the kind that settles in seconds, around the clock, that did not exist for retail consumers a decade ago. FedNow went live in July 2023 with thirty-five participating institutions, including JPMorgan Chase and Wells Fargo. It moves existing money between existing bank accounts very fast.

Before the four-fifty leaves the person’s account, a model has looked at it. The Fed added its ScamClassifier model to FedNow’s fraud flow in 2025 and began piloting a network-intelligence tool that lets banks pre-check a receiver account before a transaction is submitted. A coffee at a coffee shop the person buys coffee at most mornings is the easiest possible call. The model approves it in the time it takes the terminal to chirp. The person notices nothing, because nothing is the correct thing to notice. The system worked. The coffee was bought.

The person commutes by ride-share. The fare is paid inside the app; the person never sees a terminal. What the person also never sees is the other half of the transaction: the part where the platform’s pricing and dispatch systems decide what the driver earns, routed through the gig platform’s own algorithmic layer. Two AI-mediated decisions, one trip: the rider’s fare and the driver’s pay, set by software that neither party can inspect. The rider gets to work. The driver gets a number. Neither was consulted.

At lunch the person uses a card the employer issued. It is a single-purpose instrument, the kind that has quietly proliferated in corporate expense management: it works at the office cafeteria and nowhere else. Geo-fenced and merchant-category-restricted, it is, in the technical vocabulary of the field, programmable. The money on it carries rules. It can be spent on the approved category, at the approved place, and the card is declined everywhere else, not by a human decision but because the instrument itself will not permit the transaction.

It is the whole architecture in miniature, sitting in a wallet, and nobody thinks of it as sinister, because it is not. It is an expense card. But the distinction the central banks draw — between programmable payments, where the transfer mechanism has rules and the money itself is neutral, and programmable money, where the currency itself carries the constraints — has already collapsed at the level of the cafeteria card. The Federal Reserve’s own research draws the line cleanly: “Programmable money is self-contained, carrying both the programming logic and the value.” The employer’s lunch card is not, technically, money carrying its own logic. But the person experiences it as money that can only buy lunch. The reader cannot tell the difference, and for the purposes of the day, there is none.

The pharmacy is next.

The person has a prescription to fill. The insurance card is swiped. In the milliseconds before the price appears, a formulary system has checked whether the medication is covered, at what tier, with what prior-authorization requirement, against the person’s plan. This is a model deciding, in real time, what the person will pay for a drug a physician has already prescribed, and, in the cases where the answer is not covered, whether the person fills the prescription at all. The person does not see the model. The person sees a number at the register, and the number is either affordable or it is not.

The afternoon’s groceries are bought with a benefits card by the person ahead in line, which the person notices only because the line is slow. The card is an Electronic Benefit Transfer card, the modern delivery mechanism for the Supplemental Nutrition Assistance Program: food stamps, in the older language. The card, too, is programmable in the cafeteria sense: it buys food and not the categories the program excludes, eligibility checked at the point of sale. This is not a hypothetical and not a future. It is the oldest deployed instance of programmable spending in the United States, running for decades, uncontroversial, and almost nobody calls it a control grid, because it is administered as a benefit and the rules are published.

That, again, is the architecture’s defense, and it is a real defense. The IMF’s deputy managing director, Bo Li, described the feature set plainly at the IMF–World Bank Annual Meeting in October 2022: a programmable currency “can allow government agencies and private sector players to program, to create smart contracts, to allow targeted policy functions. For example, welfare payment; for example, consumption coupons; for example, food stamps.” He was not warning. He was listing benefits. By programming the currency, he continued, “those money can be precisely targeted for what kind of people can own and what kind of use this money can be utilized, for example for food.”

The benevolent reading of that sentence is the food-stamp reading: the money goes to the people who need it, for the thing they need it for, and the leakage that plagues unrestricted cash transfer is engineered out. China, under its fifteenth Five-Year Plan, has built precisely this at national scale, coding agricultural subsidies in its digital yuan so the grants can be spent only on approved categories such as seeds or fertilizer. One set of early-2026 reports put the resulting reduction in administrative leakage at roughly twenty-two percent, a figure that traces to a single cluster of secondary outlets rather than an audited evaluation, and is best read as a claim about the design’s promise rather than a verified outcome. The capability, in any case, is not speculative. It works. It is, by one entirely coherent set of values, good government.

The less benevolent reading is the one the same officials supply, in the same speeches, without prompting. Cornell’s Eswar Prasad, who advises both the IMF and the World Economic Forum, told the WEF’s Tianjin meeting in June 2023 that programmability opens “a potentially darker world where the government decides that units of central bank money can be used to purchase some things, but not other things that it deems less desirable like say ammunition, or drugs, or pornography, or something of the sort.” He also described currency “with expiry dates” as a feature: spend it by the deadline or the units expire. China has in fact tested it, sending fifty billion digital yuan to low-income households with a thirty-day usage window and watching ninety-four percent of it spent in the first week.

The same feature. The food-stamp version and the ammunition-and-pornography version are the same feature, described by the same kind of person, at the same kind of conference. The difference is entirely in who draws the approved-category list, and whether the person whose money it is gets a vote.

The person at the end of the long grocery line gets no vote. The person never did.


It is evening, and the person buys gas.

The debit card is swiped at a pump in a town the person does not usually buy gas in, because the day’s errands ran long. The transaction is, to a fraud model trained on the person’s pattern, mildly anomalous: a new merchant, a new location, after dark. The FedNow ScamClassifier, or the issuing bank’s own equivalent, weighs the anomaly against everything else it knows: the amount is small, the merchant is a gas station, the card has been used normally all day. It approves. Had the model decided the other way, the pump would simply have declined the card. The person would have stood in the cold reading the words transaction declined, with no way to know whether the cause was fraud detection, a bank-side error, or a balance the person had miscounted. The decline is the same regardless of cause. The system does not distinguish, to the person, between we think this is fraud and we have decided you may not.

That indistinguishability is the load-bearing fact of the chapter. There is, by design, no human in the loop at the speed the transaction happens. The CFPB’s 2023 Circular requires an adverse-action notice with a real reason: eventually, on request, in the mail, for the lending decisions it covers. It does not require, and cannot deliver, an explanation at the pump, in the cold, at the moment the card is refused.

The day ends with a gift.

It is a family member’s birthday, abroad, and the person sends a small amount of money across a border through an app. This transfer travels the longest gauntlet of the day. Cross-border value movement runs through anti-money-laundering and counter-financing-of-terrorism screening — sanctions lists, pattern models, jurisdiction flags — and the screening is increasingly automated and increasingly built directly into the payment architecture itself. The Bank for International Settlements’ Project Agorá, launched in April 2024 with the participation of the central banks of the G7 and beyond, is an experimental platform for cross-border tokenized payments that combines central-bank money and commercial-bank deposits with AI-screening hooks for sanctions, AML, and fraud built into the architecture, with reporting due in the first half of 2026.

The person’s birthday gift clears. Of course it clears: it is a small, legible, explicable transfer between two named individuals who are related. But it clears because a model decided it was clean, and the same model, presented with a transfer that tripped a pattern it had been trained to distrust, would have held or rejected it with the same silence the gas pump used. The person would have learned of the problem the way everyone learns of these problems: not from a notice but from an absence. The money would not have arrived. The relative would not have a deposit. The person would have a screen reading your transfer could not be completed at this time.

That sentence — your transfer could not be completed at this time — is the voice of the system. It is the only thing the system ever says. It said it about the coffee, except the coffee went through, so it said nothing. It would have said it about the gas. It did not need to say it about the gift. But it is the sentence in the chamber, and the person has heard it before, on a day when something failed, and could not get a human being on a phone to tell them why.

The person authorized none of these checks. The person consented to most of them only in the sense that everyone consents to everything by clicking agree on a document no one reads. The person is unaware of all but one or two of them, and the one or two the person is aware of, the person experiences as friction, not as governance. The transfers succeeded or they did not. The person’s ability to spend the person’s own legally-held money, on legal purchases, from willing sellers, was conditional all day on a sequence of automated approvals running against databases the person cannot inspect, audit, or appeal. And the person had a completely ordinary, completely uneventful day.

The permission system is already installed. It did not arrive by decree. It arrived by integration, one reasonable component at a time, each justified on its own terms, each declining to call itself what it collectively is.


The reason it does not feel like a control grid is that it does not yet behave like one for the ordinary person. The fraud model approves the gas. The formulary covers the drug. The cross-border screen clears the gift. The system’s daily output, for the compliant, is yes, and a yes delivered in milliseconds feels like service, not surveillance. You only meet the architecture when it says no, and most people, most days, never do.

But the people who have met it know exactly what it is, and their experiences are the chapter’s other half: the documented cases where the silent infrastructure was pointed at someone deliberately, and the yes became a no with no court, no notice, and no appeal.

The clearest proof of concept is Canadian. In February 2022, the Canadian government invoked the Emergencies Act to end the Freedom Convoy protests. Under the emergency financial measures, the RCMP provided lists of names to financial institutions, and the banks froze at least two hundred fifty-seven accounts — personal, business, and mutual-fund holdings — plus a number of cryptocurrency wallets, totaling roughly seven point eight million Canadian dollars. No court orders were required. The banks acted on police direction, against names supplied on what later filings characterized as “bare belief,” without any standard of reasonable grounds or reasonable suspicion.

Two years later, the Federal Court ruled the invocation “unreasonable and ultra vires”: that there was no national emergency justifying it, and that the financial measures constituted unreasonable search and seizure in violation of Charter rights. In January 2026 the Federal Court of Appeal upheld that ruling, finding that “as disturbing and disruptive as the blockades and the ‘Freedom Convoy’ protests in Ottawa could be, they fell well short of a threat to national security.” The government has appealed to the Supreme Court of Canada.

The legal vindication is real. It is also beside the point of this chapter. The courts found the freeze unlawful. The freeze still happened, in days, faster than any legal process could run, and the money was inaccessible while it mattered. The lesson is that you do not need a programmable currency to freeze someone’s money. The existing banking infrastructure — banks, payment processors, exchanges — already complies when a government invokes emergency powers. The control grid is the relationship between the state and the financial intermediaries, and that relationship is fully operational. A programmable currency would only make the freezing faster, more granular, and automated: no phone call to a compliance officer required.

It is not only governments that operate the kill switch, and it is not only emergencies that trip it. The private layer has its own record. When five major financial institutions — Bank of America, Visa, Mastercard, PayPal, and Western Union — imposed a blockade on a publisher within ten days of a 2010 document release, no criminal charges had been filed; the blockade destroyed roughly ninety-five percent of the organization’s revenue years before any indictment. When a bank closed a British politician’s account in 2023, an internal dossier later obtained by the customer showed the real reason was that his “publicly-stated views” were “not compatible” with the bank’s “values”: a judgment rendered by a reputational-risk committee, with no legal process, no appeal, and, when the press asked, a lie about the cause.

The reputational-risk committee is not an improvisation. It is the visible end of a documented supervisory doctrine, and the doctrine has been written down. Davis Wright Tremaine, in an analysis published through NYU Law’s compliance forum in December 2024, described how the category does its work. Reputational risk, the firm noted, “is present in every facet of banking,” and because bank regulators “list themselves as among the ‘stakeholders’” whose views define it, any finding of it is “by definition” nearly indisputable. The finding is administered out of public view. There is no notice, no standard of proof, and no party with standing to contest it, because the category is constructed so that the regulator who raises the concern is also the authority who certifies it.

That is the operating manual for everything else in this chapter. The Freedom Convoy freeze needed an emergency declaration; the WikiLeaks blockade needed a sufficiently unpopular publisher; the Coutts dossier needed forty pages of a customer’s “publicly-stated views.” The reputational-risk doctrine needs none of these. It needs only a supervisory whisper that an account, an industry, or a customer carries a risk no bank can disprove. The risk is defined as the regulator’s own perception of it. In the United States the paper trail is now primary. The House Financial Services Committee’s debanking report, released November 30, 2025, defines the move in the supervisor’s own grammar — an account closed because its holder “is subjectively determined to pose a financial, legal, or reputational risk” — and the Committee majority characterizes the pattern as “Operation Choke Point 2.0,” its hearing titled, as a question rather than a finding, “Coincidence or Coordinated?”

It is managed exclusion without a formal CBDC. The country rejected the central-bank version, the version that announces itself and asks. The reputational-risk doctrine does neither. It produces the outcome a programmable currency would produce — an account that may no longer transact — through a determination nobody is required to write down, defend, or attribute to a decision-maker who can be named. The kill switch does not need new money. It needs only a risk category that justifies itself, a supervisor empowered to invoke it, and a bank that would rather close one account than become the next one. The exclusion happens. No one decided it in any form a court could review. It autocompleted.

These are the same architecture as the person’s ordinary day, with the polarity reversed. The fraud model that silently approves the gas is the same kind of automated gate that, pointed at a designated account, silently declines everything. The difference between the convenience and the kill switch is not the technology. It is the contents of one list — the approved list, or the frozen list — and who gets to write it. The person whose ordinary day ran smoothly and the publisher whose revenue evaporated were standing in front of the same machine. One of them was on a list.


So the honest question is whether the architecture is inevitable. The honest answer is no. And the proof that it is not inevitable is also the proof of where the trajectory points.

The United States killed the central-bank version outright. In January 2025, an executive order prohibited federal agencies from establishing, issuing, or promoting a central-bank digital currency, terminated the existing initiatives, and revoked the prior order that had directed research into a digital dollar. In July 2025 the House passed the Anti-CBDC Surveillance State Act, attached to the must-pass defense authorization. Sitting Federal Reserve governors had already said, on the record, that they could find no satisfactory case for a CBDC; one warned specifically of “the risk that a CBDC would provide not only a window into, but potentially an impediment to, the freedom Americans enjoy in choosing how money and resources are used and invested.” The opposition was one of the few genuinely bipartisan alignments in American politics, uniting libertarians, progressive civil-liberties organizations, cryptocurrency advocates, and small-government conservatives.

And yet, the chapter has just walked an American through an entire day of programmable, automated, model-gated spending without a CBDC anywhere in it. FedNow is not a CBDC. The Fed says so explicitly, and the Fed is correct. It is a payment rail, not a new form of money, and it cannot, by itself, impose a spending restriction. But the rail carries the ScamClassifier. The cafeteria card carries the geo-fence. The benefits card carries the category list. The formulary carries the coverage decision. The cross-border screen carries the sanctions model. The control did not need the currency. The control was assembled out of components that are each individually legal, individually reasonable, individually not-a-CBDC, and that collectively deliver the feature set the central bankers described, without anyone having to pass the law the country united to reject.

The other proof that the architecture is not inevitable is that, where it has been imposed as a deliberate, top-down currency, people have refused it.

Nigeria launched the eNaira in October 2021: Africa’s first central-bank digital currency, the second in the world. Adoption was half of one percent a year after launch. The International Monetary Fund reported in May 2023 that ninety-eight and a half percent of eNaira wallets had never been used, and described adoption as “disappointingly low.”

When the government tried to force adoption — redesigning the high-denomination naira notes in late 2022 with a hard February 2023 deadline, explicitly to push citizens toward the digital alternative — it pulled the old cash out of circulation faster than it could supply replacements. By March 2023 only about forty percent of the old notes had come back, while the central bank had minted eNaira equal to roughly nine-hundredths of one percent of the cash supply. The result was a nationwide cash shortage. The lines outside banks turned into protests. The protests turned into riots. ATMs were burned. And even at the height of the shortage, Nigerians still would not adopt the eNaira, preferring bank-transfer apps and, increasingly, cryptocurrency. Nigeria has one of the highest crypto-adoption rates in the world.

By August 2024 the central bank admitted the eNaira had failed to gain widespread acceptance. By 2025 it had formed a task force exploring an official stablecoin instead, conceding that the central-bank-digital-currency model, in Nigeria, was dead. Across the Caribbean, the same pattern: the Bahamas’ Sand Dollar, the world’s first CBDC, sat at three-tenths of one percent of currency in circulation while cash use went up twenty percent; the Kansas City Fed’s own analysis of the region concluded that the technology was never the bottleneck. The demand was.

The top-down version — announce a digital currency, declare it legal tender, force adoption — fails. People can see it coming, and they refuse it, and they riot if they have to. The eNaira is the proof that the architecture is not inevitable. A population that is asked, plainly, whether it wants its money turned into a permission system can say no, and Nigeria’s did.

But nobody asked the person in the ordinary American day. The permission system arrived in that day without a launch, without a deadline, without a name on the ballot: assembled from a fraud classifier, an expense card, a benefits card, a formulary, and a cross-border screen, each of which the person agreed to one click at a time, none of which announced itself as the thing it was joining. The eNaira failed because it asked. The American version did not ask. It autocompleted.

The architecture is not inevitable. The trajectory is.

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.