At the AGI Playground 2026 conference, Airwallex's Chief Revenue Officer, Wu Kai, introduced the concept of an AI-native financial operating system, arguing that the ultimate destination for agents is not a smarter conversational interface, but an execution system capable of truly managing enterprise funds.Article author and source: GeekPark
The lights on the main stage at Gardens by the Bay in Singapore illuminate for AGI Playground 2026. Below, more than 50 global VCs and hundreds of AI builders sit, eagerly anticipating the next phase of Agent development.
Everyone is asking a question:
How far are we from automated delivery when agents move from conversation to execution?
At the roundtable, Wu Kai, Chief Revenue Officer at Airwallex, offered a perspective different from most. Rather than focusing on model capabilities or user interfaces, he directly framed the issue within finance—the most stringent domain. He believes AI will not only change how software is used, but also how businesses are built and operated: “We are building the foundational execution capabilities for AI-native enterprise finance and commerce.”
This means the endgame for an Agent is not a smarter conversational interface, but an execution system that can truly operate enterprise finances. In Airwallex’s narrative, this system is summarized as an “AI-native financial operating system.” Around this operating system, the company sees two clear opportunities: Autonomous Finance on the business operations side, and Agentic Commerce on the payments and checkout side.
Wu Kai believes the market has reached a critical turning point; as agent-based commerce grows, consumers will authorize their agents to compare prices, select products, and place orders, making agent-to-agent payment systems the future trend.
01 Trustworthiness is the ticket to officially launching an Agent.
Over the past year, agents have nearly become the stars of demo competitions: in demonstration videos, they can connect an entire business workflow within minutes; but in actual implementation, many companies have found that while the demos are impressive, real-world deployment is difficult. Wu Kai has defined a clear standard for “deployment,” believing that true deployment means “not just being able to demonstrate, but being trusted and capable of repeatedly completing production tasks.”
Breaking down this standard reveals five dimensions: adoption rate, reliability, measurable business outcomes, auditability, and a clear fallback path—meaning model quality is just the starting point, not the end goal. Wu Kai particularly emphasized the uniqueness of financial scenarios: “In finance, an Agent is only truly live when it can operate within the company’s real-world approval, compliance, and risk control frameworks.”
This means that an Agent cannot simply be an external intelligent assistant—it must be embedded within the company’s existing approval workflows, compliance rules, and risk control systems. In Airwallex’s practice, Agents excel at handling tasks that were previously performed manually, are highly repetitive, and require minimal human judgment—such as financial operations, reconciliation processes, report preparation, and business workflows that involve sequential search, comparison, and execution.
On the contrary, the weakest tasks for Agent currently are those where it's difficult to obtain complete context—such as designing entirely new products or making complex strategic decisions, which require substantial domain expertise and implicit information from interpersonal communication; Agent is still unable to handle these effectively at this stage.
This clear understanding of capability boundaries ultimately translates into product design.
The recently launched T:0 and Airi target two distinct scenarios. T:0 is an AI-native financial platform designed to autonomously run end-to-end financial functions such as bookkeeping, forecasting, and reporting—essentially serving as a self-operating finance department from day one. Airi began as a one-click checkout wallet, but strategically, it also serves as the trust and credential layer for Agentic Commerce, enabling users to store payment details once and enjoy seamless transactions across participating merchants, while laying the foundation for AI agents to execute delegated payments.
As scenarios and technologies continue to evolve, Wu Kai believes the time is now ripe to launch these two products. On the financial side, customers are tired of fragmented tools, spreadsheets, reconciliation tasks, and repeated handoffs; on the commercial side, the rise of agent-based commerce means wallets and payment layers must evolve, as agents need to help users discover, compare, and purchase goods—requiring a secure payment method that does not expose customers’ card credentials.
The reason AirCloudPay has the confidence to undertake this is largely due to the foundation built over the past decade: its long-term investments in payments, fund management, and regulatory infrastructure enable it to layer intelligent execution on top of real financial channels.
02 Can be delegated for execution, but maintain control
When the Agent begins handling funds, the most practical and core issue becomes the real-world question of "how to design the authorization chain," because the Agent is spending the user's money—who is authorizing? Who is executing? And who is accountable for the outcome? If these questions cannot be clearly answered, even the most intelligent Agent will struggle to enter production.
Wu Kai made an important distinction on-site: enterprises need "authorized delegation," not "transfer of control."
In Airwallex's products, the AI assistant 'Kai' has the same permissions as the user and is subject to the same account roles, permission rules, eligibility criteria, and workflow controls. The entire flow is understood as a delegation relationship of 'User → Agent → downstream Airwallex services,' rather than the user transferring full control to the Agent.
Along this chain, the product team provided very specific boundary designs: Kai can assist with retrieving information, guiding setup, and completing certain actions within policy allowances; however, for any actions involving fund transfers or fees, the product must clearly state what Kai is about to do and require user confirmation before proceeding. For more sensitive scenarios, the correct model is escalation for approval and human review, not silent execution.
Wu Kai summarized this principle in one sentence: “Agents can execute, but humans and organizations still define the mission, boundaries, and responsibility framework.” He believes that increased autonomy must be accompanied by enhanced governance. Over time, agents may take on more workflows, but they will not assume ultimate responsibility.
This same philosophy is embedded in the design of AgentOS. AgentOS connects Agents to production accounts, but by default includes OAuth scopes, guardrails, and prohibits fund outflows. In other words, Agents are not given a blank check, but rather an authorized card with spending limits, usage restrictions, and audit trails.
Wu Kai believes that an ideal long-term model should be an OAuth-based delegation chain capable of verifying who the subject is, which agent is performing the action, and when elevated confirmation is required for sensitive operations. The practical boundaries can be summarized into five elements: user permissions, restricted scope, explicit confirmation when risk increases, full auditability, and the ability to escalate to human handling when confidence or authorization is insufficient.
03 The financial ecosystem determines the upper limit of Agent.
If the authorization chain addresses the question of "what an Agent can do," then "context" determines "how well an Agent can do it."
At the roundtable, Wu Kai also shared a insight repeatedly validated by Airwallex, stating, "In an enterprise environment, context is not something that should be 'added on' at the end—enterprises must first build or acquire systems capable of generating clean, structured financial context."
Behind this statement is Airwallex’s strategic logic behind its acquisitions. Acquisitions such as OpenPay and Leapfin are not merely about adding product features, but about integrating more billing, revenue, reconciliation, and accounting data models into a single ecosystem, enabling Agent to take actions based on a more complete and reliable business picture.
Wu Kai explained why context is so critical in financial scenarios—enterprise context is not merely more data, but rather information dispersed throughout the entire funding lifecycle, such as how revenue is generated, how payments are routed, how transactions are reconciled, and how accounts are closed. If this data is scattered across different systems, the Agent is like a navigator with a blindfold—aware of the direction but unable to see the road conditions.
Based on these practices, Wu Kai concludes, "The best enterprise agents will be built on integrated financial systems, not isolated Copilots attached to fragmented data silos."
This is also the moat built by Airwallex over a decade of infrastructure development. A decade of payment, fund management, and regulatory infrastructure is not just a collection of licenses and channels—it is a foundation that provides Agents with a complete, structured financial context. Without this foundation, even the most powerful models can only perform fragmented analysis.
04 Agent Finance Implementation: Building a Hierarchical and Controllable Fund Security System
Faced with the industry-wide challenges of securing funds under autonomous agent operations and difficulty quantifying real-world enterprise outcomes, Wu Kai provides a practical and forward-looking comprehensive solution, establishing a clear roadmap for deploying AI agents in finance.
Finance is a field with zero tolerance for risk; granting open agents access to fund operations simultaneously amplifies both opportunities and hazards—a challenge faced by the entire industry. Wu Kai proposes three foundational principles: “full user control, tiered authorization of operations, and end-to-end traceability”—balancing automation efficiency with fund security.
He categorizes agent operations into two scenarios—irreversible and reversible—to establish differentiated control logic: For irreversible operations such as fund transfers, salary disbursements, and vendor payments, where funds cannot be reversed, agents can only initiate requests, while final decision-making authority remains firmly with the user, supporting diverse authorization modes such as batch approvals; for reversible operations like bookkeeping and journal entry recording, automation permissions are relaxed to reduce frequent manual intervention and slow down business flow.
To strengthen risk mitigation, AirCloudPay implements a comprehensive operational traceability mechanism, ensuring every action by the intelligent agent is fully logged. Users can review all change histories and undo reversible actions with a single click. In the long term, a closed-loop error feedback system will be established, enabling the intelligent agent to autonomously learn from past mistakes and prevent the recurrence of similar risks.
In C-end agent e-commerce transaction scenarios, the definition of rights and responsibilities is more complex. Wu Kai has clearly established the industry’s unified baseline for rights and responsibilities: user-initiated authorization is a prerequisite for transaction validity; in cases of chargebacks or fraud disputes, final liability rests with the cardholder. Airwallex is collaborating with card networks to develop standardized dispute resolution protocols for agent-based payments, addressing compliance gaps in the next generation of autonomous transactions.
As the industry rushes to deploy agents, companies are generally uncertain about how to evaluate whether an agent is successful or delivers real business value. Wu Kai proposes evaluating frameworks based on two dimensions: the completeness of the business loop and whether model intelligence is the bottleneck. He also categorizes existing agents into three types, clearly distinguishing their levels of commercial potential.
The first category consists of ideal benchmark applications: business processes that can achieve 100% execution closure, with all bottlenecks stemming solely from model reasoning capabilities; AI code generation is a typical example, and the industry is actively seeking such disruptive products.
The second category consists of automation tool-based products, including Airwallex’s intelligent agents for finance and e-commerce: these models have no capability gaps and can enable end-to-end business processes. Wu Kai emphasized that there is a world of difference between 90% and 100% automation—so long as the final step in the process still relies on human intervention, overall adoption and efficiency will be severely limited. Once full end-to-end automation is achieved, enterprise adoption rates will experience a qualitative leap. Meanwhile, intelligent agents enable more frequent corporate decision-making: while traditional finance relies on monthly reviews, today’s systems can monitor metrics daily or even hourly to continuously optimize processes—this is also a core focus of intelligent agent finance development.
The third category is AI-assisted Copilot: it cannot form a complete business loop, with the core bottleneck lying in model intelligence—financial irreversible fund transfers being a typical example. Such products must retain human review processes, with AI only performing auxiliary data analysis tasks; they offer basic value but have far less commercial potential than the first two categories.
*Header image source: AGI Playground 2026
