Solv Labs、Amazon Bedrock AgentCore で監査可能な AI エージェント決済を実現
本文の状態
日本語全文を表示中
詳細モードで約19分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
AWS Machine Learning Blog
Solv Labs は Amazon Bedrock AgentCore payments を活用し、ORACLE と ICME PreFlight の 2 層構造で権限付与とコンプライアンス検証を行う、監査可能な AI エージェント決済。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月12日 23:13
AI深層分析
キーポイント
二層ガバナンス構造の導入
Solv Labs は ORACLE(ポリシーエンジン)と ICME PreFlight(コンプライアンス検証)という二つのレイヤーを組み合わせ、各取引前に権限付与とプライバシー保護された検証を実行する仕組みを構築した。
AWS 技術による完全な監査証跡
AWS Nitro Enclave 内の整合性サービスとリスクエンジンを用いることで、各取引が事前承認され、個別に価格設定され、Coinbase を介してオンチェーン決済されるまでの全過程を4秒以内で記録する。
企業向け実金移動の証明可能性
自律型エージェントによる資金移動において、「動作したか」ではなく「何が起きたかを証明できるか」が問われる状況に対し、特定の行動とそれを許可したポリシーを紐付ける永続的な記録を提供する。
Amazon Bedrock AgentCore payments の新機能
2026 年 5 月に Coinbase や Stripe と提携して導入された同機能は、AI エージェントが Web コンテンツや API を即時にアクセス・決済できる仕組みを提供し、開発者が既存の制御で支出を管理可能にする。
実行時のガバナンスと個別決定の記録
個々の意思決定の実行を記述するレコードを生成し、監査や紛争解決を可能にする。
重要な引用
As a result, every agent payment runs through three core governance components: ORACLE for pre-authorization decisions, an integrity service running in an AWS Nitro Enclave, and a risk engine for per-transaction pricing.
The first time an autonomous agent moves real money on behalf of an enterprise, the question is no longer 'Did it work?' It is 'Can we prove what just happened?'
Amazon introduced Amazon Bedrock AgentCore payments in May 2026, built in partnership with Coinbase and Stripe.
Without that transaction-level binding, operators have no clean way to resolve a dispute, satisfy an auditor, or tell a routine agent action apart from a compromised one.
編集コメントを表示
編集コメント
2026 年という未来の時点での技術導入を想定した記事だが、AI エージェントが自律的に資金を扱う際のガバナンス要件と、それを満たすための具体的なアーキテクチャ(Nitro Enclave やポリシーエンジン)の組み合わせは、実用化に向けた重要な指針となる。特に「証明可能性」を技術的課題として解決するアプローチは、規制対応が必要な企業における AI 導入の障壁を下げる可能性がある。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
この記事は、Solv Labs の Patrick Duffy 氏と ICME Labs の Houman Shadab 氏との共著です。
Solv Labs は、Amazon Bedrock AgentCore Payments を活用した AI エージェントの決済ワークフローを構築しました。この仕組みは、Solv のポリシーエンジンである「ORACLE」と、コンプライアンス検証を行う「ICME PreFlight」の 2 つのレイヤーによって統制されています。AgentCore Payments が決済処理インフラを提供し、ORACLE は各取引前に承認ポリシーを適用します。また、ICME の検証層は AWS の自動推論チェックを拡張することで、プライバシーを保護しつつ移植可能で、独立して検証可能な仕組みを実現しています。これにより、すべての意思決定が個別に確認可能です。
その結果、すべてのエージェント決済は 3 つの主要なガバナンスコンポーネントを経由します。1 つ目は取引前の承認判断を行う「ORACLE」、2 つ目は AWS Nitro Enclave で動作する整合性サービス、そして 3 つ目は取引ごとの価格設定を行うリスクエンジンです。各取引は 4 秒未満で完了し、事前承認からガバナンス処理、Coinbase を介したオンチェーン決済までを一貫して処理します。すべての取引には完全な監査証跡が生成され、これはエージェントワークロードのレイテンシ要件を十分に満たしています。
企業が自律型エージェントに実金移動を任せる初回において、問われるべきは「機能したか」ではなく、「直前の出来事を証明できるか」という点です。この問いに答えるためのインフラが、たった 1 クォーターの間に 4 つ揃いました。それは、Amazon Bedrock AgentCore の支払い機能、AWS Automated Reasoning Checks(自動検証チェック)、トランザクションごとにアテスターとして機能する AWS Nitro Enclaves、そしてエージェントからサービスへの支払いを可能にする x402 支払い規格です。
Amazon は 2026 年 5 月、Coinbase と Stripe との共同開発により「Amazon Bedrock AgentCore payments」を発表しました。これにより、AI エージェントは利用したウェブコンテンツ、API、MCP サーバー、他のエージェントに対して即座にアクセスし、支払いを行うことが可能になります。支出管理には、開発者がすでにエージェント運用で使っている制御機能がそのまま適用されます。
本稿では、Solv Labs と政策検証パートナーの ICME が、AgentCore payments を活用したエージェント支払いワークフローの構築プロセスを解説します。この仕組みでは、すべての取引が実行時にポリシーによって厳格に管理され、AWS Nitro Enclave 内でアテスタ(証明)され、リスクに応じて個別に価格設定され、完全な監査証跡を残すことができます。また、規制環境下でエージェントを運用する企業にとって、このパターンがもたらす可能性についても触れます。
エンタープライズが直面する課題
自律システムがお金を動かすとき、運用者は監査役や取引相手、法務部門に対して、各支払いが承認されたものであり、そのリスクに見合った価格設定がなされ、精査に耐えうる形で記録されていることを証明する必要があります。設定ミスや改ざんを受けたエージェントは、単に間違った回答を返すだけではありません。実際にお金を動かします。難しいのは支払いを実行することではなく、実行後に「そもそもこの支払いは許可されていたのか」を証明することです。
企業チームは常に同じ課題に直面しています。エージェントによる取引が完了した際、その特定の行動を承認したポリシーや満たされた制約、あるいは負ったリスクと結びつける永続的な記録が存在しないのです。モデルカードや SOC 2 レポート、事後レビューはシステムを取り巻く「組織」については記述しますが、個々の意思決定の「実行プロセス」については記述しません。取引レベルでの紐付けがない限り、運用者は紛争を解決したり、監査役の要求に応えたり、通常のエージェント行動と侵害された行動を見分けるための明確な手段を持ちません。
Solv Labs は、既存のシステムに外部インフラを追加するのではなく、エージェントの速度を落とすことなく、すべてのエージェント行動が即座に検証可能で、リスクに応じた価格設定がされ、監査可能な状態であることを実現する必要がありました。
Vision
ビジョンはシンプルです。実行時にすべてのエージェント支払いを管理し、運用者の発言に依存せず、監査役や取引相手、規制当局など多様な関係者が独立して検証できる記録を生成することです。
AgentCore payments を決済オーケストレーション層として、形式化されたポリシー評価のための Automated Reasoning Checks (ARc)、ハードウェアの証明に Nitro Enclaves を活用し、さらに x402 がエージェント決済で広く採用されるようになったことで、ようやく実用段階に入りました。これらが揃ったことで、「管理されたエージェント決済」はもはや研究課題ではなく、現実的な実装選択肢となりました。
アーキテクチャ
このワークフローは、Solv 運営環境内の AgentCore payments、Nitro Enclave 証明機能を備えた ORACLE エンジン、そして外部サービスとして機能する ICME によるポリシーチェックという、それぞれ専門化されたコンポーネントの集合体として動作します。各コンポーネント間の信頼境界を越えるやり取りは、署名付きでハッシュに紐付けられたアーティファクトを通じてのみ行われるため、サービスのデプロイ形態に関わらず、証拠の流れは常に保たれます。このワークフローは Amazon Bedrock AgentCore を基盤としたエージェントに接続され、AgentCore ランタイム上で動作するエージェントや、カスタム実装された AgentCore とも互換性があります。

図 1: システムアーキテクチャ。すべてのエージェント決済は、決済前に事前承認、制約検証、完全性証明、リスク評価という一連の処理を経ます。これらはすべて AgentCore ネイティブの機能です。
各決済は、ガバナンス問題の異なる側面に対応する 5 つの専門コンポーネントを通過します。
ORACLE は事前承認機能です。ORACLE は、実行されるアクションが適用されるポリシーに合致しているかを評価し、資金移動が行われる前に「許可」または「レビューが必要」という判断を返します。これにより、ポリシー違反が発生しても、オペレーターが巻き戻し処理を行う必要がある決済取引が成立してしまうことを防ぎます。
PreFlight は、独立して検証可能なポリシーチェック機能です。ICME の PreFlight は、ORACLE の判断の根拠となるポリシーチェックを提供します。このチェックの結果は、プライバシーを保護する小さな証明データとして生成され、第三者がポリシーやトランザクションのパラメータにアクセスしなくても、その正当性を検証できるようになっています。
AWS Nitro Enclave は、整合性の証明(アテステーション)機能です。Nitro Enclave 内で動作する整合性サービスが、ハードウェアレベルで隔離された環境内で実行記録に署名します。この署名文書は Nitro セキュリティモジュールによって生成され、署名鍵を特定のエンクレーブイメージの測定値(PCR0、および PCR1 と PCR2 も含む)と紐付けます。その結果、検証者は単に「記録がエンクレーブ内で署名された」だけでなく、「Solv Labs が公開した特定のエンクレーブイメージ内でのみ署名が行われたこと」を確認できます。各アクションは暗号学的に証明され、生成元のエンクレーブに紐付けられるため、事後に記録がこっそり書き換えられることを防ぎます。
リスクエンジンでは、各取引に対してリスク乗数が付与されます。この乗数は評価された違反信号から決定論的に計算され、ガバナンス記録には単なる合格・不合格ではなく、リスクに応じた価格が記録されます。この情報は、後続のレビュー優先度の設定や、第三者に移転されるリスクの価格設定に活用されます。
決済処理と決済完了では、AgentCore Payments が各取引を処理する際、セッションごとの支出制限を厳格に適用し、エンドユーザーが承認した予算範囲内で取引が行われるように制御します。その後、Coinbase を介したオンチェーンルーティングを通じて決済が完了します。
これらのコンポーネントは固定された順序で実行されます。ORACLE の判断、その独立して検証可能な証明、ハードウェアの証明、そして取引ごとのリスク価格はいずれも、決済開始前に生成されます。ゲートは絶対的なものであり、「判断がなければ決済も行わない」という原則が適用されます。

図 2:トランザクションシーケンス。ステップ 1〜3 でガバナンス記録が生成され、決済開始前にゲートが「判断なしには決済なし」を強制します。エンドツーエンドのレイテンシは取引あたり 4 秒未満で、ガバナンスによるオーバーヘッドは 1 秒未満です。
ガバナンス層が証明するもの
各管理された決済は、以下の 5 つの要素を結びつけた単一の署名付き証拠レコードを生成します。評価対象となったポリシー、そのチェック結果と独立して検証可能な証明、ハードウェアによる実行記録、取引ごとのリスク価格、そして AgentCore Payments から得られる決済アーティファクトです。
これは、エージェントの根幹にある判断が賢明であったこと、取引相手が破産していないこと、あるいはポリシー自体が正しいことを保証するものではありません。これらは他の決済と同様、運用者の責任です。このシステムが証明するのは、特定の制約条件下で特定のリスク価格に基づき、特定のポリシーに対してこの特定の決済が評価され、その結果として決済が承認されたという事実を、関係者が検証可能な形で示すことです。

図 3:実行ハッシュとポリシーハッシュ、制約結果、ゼロ知識証明の参照先、ハードウェアアテステーションダイジェスト、リスク乗数、オンチェーンアンカーを含む取引ごとの証拠レコード。ハッシュと識別子は例示用のプレースホルダーです。完全なレコードは正規化され、Nitro Enclave 内で Ed25519 で署名された上で、ブロックチェーン上にアンカーされます。
AgentCore Payments がどうガバナンスの隙間を埋めるか
このサービスの3つの特性が、ワークフローを運用上クリーンに保つ要因となっています。
- エージェントシステムにネイティブ。エージェントと同じ AgentCore 環境内で実行されるため、ガバナンス・ワークフローはエージェントのアイデンティティ、ゲートウェイ、観測機能を引き継ぎます。オペレーターは、実際の運用でガバナンスの抜け漏れが発生しやすい「並列する2つの制御平面」を構築する必要がありません。
- インフラレベルでの支出制限。AgentCore Payments は、エージェントやポリシーエンジンが決定することとは独立して、セッションごとの支出上限を強制します。防御は多層構造として組み込まれており、後付けで組み合わせるものではありません。
- 単一の観測面。すべての意思決定、証明、リスク価格、決済は、Amazon Bedrock AgentCore の機能である標準的な「AgentCore Observability」を通じて可視化されます。これは Amazon CloudWatch のログ、メトリクス、トレース上で、エージェントが行う他のすべての活動と一体化して監視可能です。
カスタマー視点:Solv Labs
「このワークフローを構築する前まで、私たちが企業顧客に提供できなかったのは、特定の支払いが許可された理由に対する明確な回答でした。提供できたのは『それを承認した組織』に関する主張だけでした。AgentCore Payments により、その答えを取引自体に移すことができました。すべての支払いには、クリアされたポリシー、署名されたエンクレーブ、第三者が検証できる証明情報が添付されます。証拠は取引と共に移動します。」
— Patrick Duffy, CEO, Solv Labs
カスタマー視点:ICME
「決済判断の検証者が、その判断を下したオペレーター自身ではない場合、ポリシー自体を公開せずにチェックが正しく実行されたことを証明する手段が必要です。ICME は AWS の自動推論チェックにこの機能を追加します。つまり、すべての判断には暗号化された証明が付随し、取引先や規制当局は、1 秒未満でその証明を検証できます。ただし、ポリシーの詳細や取引パラメータが露出することはありません。」
— Houman Shadab、ICME Labs 共同創業者
成果
このワークフローにより、エージェントによる決済トランザクションの決済前に、1 トランザクションごとにハードウェア証明付きで独立して検証可能なガバナンス記録が生成されます。Amazon Bedrock AgentCore payments でこのパターンを採用した企業は、機械速度で決済トランザクションごとに以下の成果を得られます。
- トランザクションにおける実行の検証: 各エージェントアクションは暗号化署名され、Base ネットワーク上の公開アンカーに対して独立して検証可能です。ALLOW および REVIEW の両方の意思決定パスを処理するガバナンス付き決済において、どちらも同じ証拠保証を持ちます。DENY パスは ORACLE エンジンで完全に実装・単体テストされており、設定された制約が違反された場合に署名付きの拒否記録を生成します。
- リスク価格設定: 各トランザクションには決定論的に計算されたリスク乗数が付随するため、ガバナンス記録はトランザクションが負ったリスクに基づいて価格を設定し、すべての決済を同一視しません。このリスク乗数はエンジンの動作点を反映しており、観測される実行が蓄積されるにつれて結果の較正が進みます。
独立した監査可能性:各の意思決定は、Solv Labs と ICME からの参照検証ツールを用いた第三者による検証を想定し、公開ブロックチェーン上に基盤が置かれています。これにより、ポリシーの詳細や取引パラメータ、秘密鍵が露出することなく検証が可能になります。
機械速度でのガバナンス:取引は 4 秒未満で完了します。事前承認、ガバナンス、決済処理、Coinbase を介したオンチェーン決済までの全工程が含まれます。ガバナンス呼び出しの遅延も、取引全体のレイテンシ予算内に収まります。
単一の観測可能なインターフェース:各意思決定、証明、リスク価格はいずれも、オペレーターがエージェントの他の行動に対して Amazon CloudWatch のログ、メトリクス、トレースで利用する「AgentCore Observability」を通じて可視化されます。記録は、それを活用する人々——リスク・コンプライアンス部門、内部監査、外部監査人および取引相手——のために構造化されており、各関係者が個別に検証できます。

図 4:取引ごとの証拠スタック。決済発火前にすべての 4 つのアーティファクトが生成され、一緒に記録されます。監査人、取引相手、規制当局は、オペレーターのポリシー詳細や取引パラメータ、秘密鍵へのアクセスなしに、各要素を独立して検証できます。
これが企業にもたらす可能性
各取引ごとに、実行直後に生成されるクリーンな監査証跡。承認された内容、適用されたポリシー、対象となった制約、リスク価格、署名したエンクレーブ、そしてアンカーリング先がすべて記録されます。
紛争に耐えうる証拠の提示。取引相手が「なぜこの支払いを許可したのか」と問う場合、組織の主張ではなく検証可能なアーティファクトで回答できます。これは規制環境において特に重要です。各取引には証拠保持義務が付随するためです。
エージェント速度でのガバナンス。サブ秒単位のオーバーヘッドにより、企業は制御性と、アジェンティックなワークロードが要求するスループットの両方を獲得します。
例外数に比例して拡大するレビュー作業量。すべての取引には固有の証拠が付帯し、決済前にポリシーゲートを通過するため、レビュー対象は「N 件ごとにサンプリング」から「証拠自体が示す例外の調査」へとシフトします。監督業務の負荷は取引レートではなく、例外発生率に依存して増加します。
既存の予算ラインに収まる管理コスト。AgentCore のネイティブなサーフェス上で動作するため、ライセンスや統合、人員配置を要する並列制御プレーンが存在しません。追加の支払い 1 件に対するガバナンスの限界コストは、AgentCore コール自体が支配し、証明とアンカーリングはその上乗せコストに過ぎません。これは企業がすでに支払っているラインアイテムではなく、新たな項目として計上されるものではありません。
今後のワークロードを支える基盤
同じトランザクションごとの証拠モデルは、本番環境で生成される決済アクションの量と多様性にも対応してスケーラブルです。
結論
Amazon Bedrock AgentCore Payments を ORACLE、PreFlight、AWS Nitro Enclave アテスターと組み合わせることで、Solv Labs は以下のようなガバナンスされたエージェント支払いワークフローを構築しました。すべてのトランザクションは決済実行前にポリシーに基づいて評価され、ハードウェアで証明され、リスクに応じた価格設定が行われ、パブリックブロックチェーンにアンカーされます。
企業にとってこれは、例外数に応じてスケーリングするレビュー作業と、既存の予算項目に収まる管理コストを意味します。また、オペレーターのポリシー詳細、トランザクションパラメータ、秘密鍵へのアクセスがなくても、リスク管理、コンプライアンス、監査部門それぞれが検証可能な監査証跡を提供します。これが、規制環境でスピードと制御のトレードオフなしにエージェント支払いを導入するために必要な条件です。
Amazon Bedrock AgentCore Payments については、AgentCore payments の技術的深掘りや、公式ドキュメントをご覧ください。Solv Labs のガバナンスされたエージェント支払いについては Solv Labs を、ICME の PreFlight については ICME をご参照ください。
著者について

パトリック・ダフィー
パトリックは Solv Labs の CEO です。同社では、ガバナンスされたエージェント決済ワークフローの設計と、取引ごとの証拠モデルを主導しています。このモデルにより、各取引が独立して検証可能になっています。

ハウマン・シャダブ
ハウマンは ICME Labs の共同創業者です。同社はプライバシーを保護する検証レイヤー「PreFlight」の開発元で、AWS の自動推論チェック(Automated Reasoning Checks)を 1 秒未満で独立して検証可能にします。彼は、この暗号学的な厳密性を、企業やコンプライアンスチーム、規制当局が実際に信頼できる監査証跡へと変換することに注力しています。

マドゥ・サムヒタ・ヴァンガラ
マドゥは AWS のグローバル GenAI スペシャリスト ソリューションアーキテクトです。アジェンティック AI の GTM(Go-To-Market)戦略に注力しています。
原文を表示
*This post is co-written with Patrick Duffy from Solv Labs and Houman Shadab from ICME Labs*
Solv Labs built an AI agent-payments workflow using Amazon Bedrock AgentCore payments, a capability of Amazon Bedrock AgentCore, governed by two layers: ORACLE (Solv’s policy engine) and ICME PreFlight for compliance verification. AgentCore payments provides the payment processing infrastructure. ORACLE enforces authorization policies before each transaction. ICME’s verification layer extends AWS Automated Reasoning Checks to make them privacy-preserving, portable, and independently verifiable, with each decision checkable.
As a result, every agent payment runs through three core governance components: ORACLE for pre-authorization decisions, an integrity service running in an AWS Nitro Enclave, and a risk engine for per-transaction pricing. Each transaction completes in under four seconds, covering pre-authorization, governance, and on-chain settlement through Coinbase. Every transaction produces a full audit trail, and that’s well within latency budgets for agentic workloads.
The first time an autonomous agent moves real money on behalf of an enterprise, the question is no longer “Did it work?” It is “Can we prove what just happened?” In a single quarter, four pieces of infrastructure that make that question answerable arrived together: Amazon Bedrock AgentCore payments, AWS Automated Reasoning Checks, AWS Nitro Enclaves used as a per-transaction attester, and the x402 payment standard for agent payments to services.
Amazon introduced Amazon Bedrock AgentCore payments in May 2026, built in partnership with Coinbase and Stripe. It lets AI agents instantly access and pay for what they use, including web content, APIs, MCP servers, and other agents. Spending is governed by the same controls developers already use to operate their agents.
In this post, Solv Labs and policy-verification partner ICME walk through how we built an agent-payments workflow on AgentCore payments where every transaction is governed at execution time, attested inside an AWS Nitro Enclave, risk-priced individually, and fully auditable. We also cover what this pattern unlocks for enterprises running agents in regulated environments.
The enterprise challenge
When an autonomous system moves money, the operator must prove to auditors, counterparties, and legal that each payment was authorized, priced for the risk it carried, and recorded in a way that holds up to scrutiny. A misconfigured or manipulated agent doesn’t only return a bad answer. It moves money. And the hard part isn’t executing the payment. It’s proving, afterward, that the payment was permitted in the first place.
Enterprise teams consistently struggle with the same gap: when an agent transaction completes, there’s no durable record tying that specific action to the policy that authorized it, the constraints it satisfied, or the risk it carried. Model cards, SOC 2 reports, and after-the-fact reviews describe the *organization* around the system. They don’t describe the *execution* of individual decisions. Without that transaction-level binding, operators have no clean way to resolve a dispute, satisfy an auditor, or tell a routine agent action apart from a compromised one.
Solv Labs needed every agent action to be verifiable, risk-priced, and auditable on demand, without slowing agents down or bolting on infrastructure outside the system they already run on.
Vision
The vision is straightforward: govern every agent payment at execution time and produce a record that various parties (auditors, counterparties, regulators) can verify independently without depending on the operator’s word for it.
This became practical only recently, with AgentCore payments as the payment orchestration layer, Automated Reasoning Checks (ARc) for formal policy evaluation, Nitro Enclaves for hardware attestation, and x402 reaching broad adoption for agent payments. Together, they made governed agent payments an implementation choice rather than a research program.
Architecture
The workflow runs as a set of specialized components: AgentCore payments in a Solv-operated environment, the ORACLE engine with its Nitro Enclave attester, and policy checks from ICME as an external service. Components only cross trust boundaries through signed, hash-bound artifacts, so the evidence flow holds regardless of how the services are deployed. The workflow attaches to an agent built on Amazon Bedrock AgentCore and is compatible with agents running on AgentCore runtime or custom AgentCore implementations.

Figure 1: System architecture. Every agent payment passes through pre-authorization, constraint verification, integrity attestation, and risk pricing before settlement, all native to AgentCore
Every payment runs through five specialized components, each addressing a distinct part of the governance problem.
- ORACLE – pre-authorization. ORACLE evaluates the proposed action against the applicable policy and returns an ALLOW or REVIEW determination before values move, so a policy failure doesn’t produce a settled transaction the operator has to unwind.
- PreFlight – independently verifiable policy checks. ICME’s PreFlight provides the policy check underlying ORACLE’s decision. It produces a small, privacy-preserving proof of that check that a third party can verify without access to the policy or the transaction parameters.
- AWS Nitro Enclave – integrity attestation. An integrity service running in a Nitro Enclave signs the execution record inside a hardware-isolated environment. The attestation document, produced by the Nitro Security Module, binds the signing key to the specific enclave image measurements (PCR0, with PCR1 and PCR2 also included). As a result, a verifier can confirm not just that the record was signed inside an enclave, but inside the specific enclave image Solv Labs has published. Each action is therefore cryptographically attested and bound to the enclave that produced it, so the record can’t be silently rewritten after the fact.
- Risk engine – per-transaction pricing. The risk engine attaches a risk multiplier to each transaction, computed deterministically from the assessed violation signal, so the governance record carries a risk price rather than a flat pass. The multiplier informs downstream review prioritization and, where applicable, pricing of risk transferred to a third party.
- Payment processing and settlement. AgentCore payments processes each payment while enforcing per-session spending limits, keeping the transaction within the budget the end user has authorized. Settlement then completes with on-chain routing through Coinbase.
These components run in a fixed order: ORACLE’s decision, its independently verifiable proof, the hardware attestation, and the per-transaction risk price are all produced before settlement is initiated. The gate is absolute: no decision, no settlement.

Figure 2: Transaction sequence. Steps 1–3 produce the governance record before settlement is initiated, and the gate enforces “no decision, no settlement.” End-to-end latency is under four seconds per transaction, with governance overhead under one second
What the governance layer attests
Each governed payment produces a single signed evidence record binding five things: the policy that was evaluated, the policy-check result and its independently verifiable proof, the hardware-attested execution record, the per-transaction risk price, and the settlement artifacts from AgentCore payments.
It doesn’t attest that the agent’s underlying decision was wise, that the counterparty is solvent, or that the policy itself is correct. Those remain the operator’s responsibility, as for other payments. What it *does* attest, in a way parties can verify, is that this specific payment was evaluated against this specific policy under these specific constraints at this specific risk price, and that the result of that evaluation is what authorized settlement.

Figure 3: Per-transaction evidence record containing execution and policy hashes, constraint result, zero-knowledge proof reference, hardware attestation digests, risk multiplier, and on-chain anchor. Hashes and identifiers are illustrative placeholders. The full record is canonicalized, Ed25519-signed inside the Nitro Enclave, and anchored on-chain
How AgentCore payments closes the governance gap
Three properties of the service make the workflow operationally clean:
- Native to the agent system. Running inside the same AgentCore environment as the agent, the governance workflow inherits the agent’s identity, gateway, and observability surfaces. Operators don’t run two parallel control planes, which is the configuration where most governance gaps appear in practice.
- Infrastructure-level spending limits. AgentCore payments enforces per-session spending limits independently of anything the agent or policy engine decides. Defense in depth is built in, not assembled.
- A single observability surface. Every decision, attestation, risk price, and settlement is visible through standard AgentCore Observability, a capability of Amazon Bedrock AgentCore, on Amazon CloudWatch logs, metrics, and traces, alongside everything else the agent does.
Customer perspective: Solv Labs
“Before we built this workflow, the thing we couldn’t give an enterprise was a clean answer to why a specific payment was permitted — only assertions about the organization that authorized it. AgentCore payments let us move that answer to the transaction itself: every payment now carries the policy it cleared, the enclave that signed it, and the proof a third party can check. The evidence travels with the transaction.”
— Patrick Duffy, CEO, Solv Labs
Customer perspective: ICME
“When the verifier of a payment decision isn’t the operator who made it, you need a way to prove the check ran correctly without exposing the policy itself. That’s what ICME adds to AWS Automated Reasoning Checks: every decision comes with a cryptographic proof a counterparty or regulator can verify in under a second without seeing the policy detail or the transaction parameters.”
— Houman Shadab, Co-Founder, ICME Labs
結果
The workflow produces a per-transaction, hardware-attested, independently verifiable governance record before settlement of a payment transaction by an agent. Enterprises adopting this pattern on Amazon Bedrock AgentCore payments get the following, per payment transaction, at machine speed:
- Verifiable execution on transactions: Each agent action is cryptographically signed and independently verifiable against a public anchor on the Base networks. Governed payments processed across both decision paths, ALLOW and REVIEW, and both carry the same evidence guarantee. The DENY path, fully implemented and unit-tested in the ORACLE engine, produces a signed refusal record when configured constraints are violated.
- Risk pricing: Each transaction carries a deterministically computed risk multiplier, so the governance record prices the risk it carried rather than treating every payment as identical. The risk multipliers reflect the engine’s operating point, with outcome calibration accruing as observed executions accumulate.
- Independent auditability: Each governing decision is anchored on a public blockchain, designed for third-party verification using reference verifier tooling from Solv Labs and ICME, without exposing the policy detail, transaction parameters, or private keys.
- Governance at machine speed: Transactions complete in under four seconds, covering pre-authorization, governance, payment processing, and on-chain settlement through Coinbase. Governance-call latency holds within the latency budget of the overall transaction.
- A single, observable surface: Each decision, attestation, and risk price is visible through the same AgentCore Observability on Amazon CloudWatch logs, metrics, and traces operators use for the rest of agent behavior. The record is structured for the people who consume it: Risk and Compliance, Internal Audit, and external auditors and counterparties, each able to verify.

Figure 4: The per-transaction evidence stack. All four artifacts are produced before settlement fires and recorded together, and auditors, counterparties, and regulators can verify each element independently without access to the operator’s policy detail, transaction parameters, or private keys
What this unlocks for enterprises
- A clean audit trail per transaction, produced at the moment of execution rather than reconstructed afterward: what was authorized, under which policy, against which constraints, at what risk price, signed by which enclave, and anchored where.
- Evidence that survives a dispute. When a counterparty, auditor, or regulator asks why a payment was permitted, the answer is a verifiable artifact, not an organizational assertion. This matters most in regulated environments, where evidence-retention obligations attach to each transaction.
- Governance at agent speed. Sub-second governance overhead means enterprises get both control and the throughput agentic workloads require.
- Review effort that scales with exceptions, not volume. Because every transaction carries its own evidence and clears a policy gate before settlement, review shifts from sampling every Nth transaction to investigating the exceptions the evidence itself flags. Oversight work grows with the exception rate, not the transaction rate.
- A control cost that fits the budget line you already own. Running on AgentCore’s native surfaces, there is no parallel control plane to license, integrate, or staff. The marginal cost of governing one more payment is dominated by the AgentCore call itself, with proof and anchoring as marginal cost on top of a line enterprises already pay, not a new line item.
- A foundation for the workloads ahead. The same per-transaction evidence model scales to the volume and diversity of payment actions agentic workloads will generate in production.
まとめ
Using Amazon Bedrock AgentCore payments together with ORACLE, PreFlight and an AWS Nitro Enclave attester, Solv Labs built a governed agent-payments workflow in which every transaction is evaluated against policy, attested in hardware, priced for risk, and anchored to a public blockchain, all before settlement fires. For enterprises, that means review effort that scales with exceptions rather than volume, a control cost that fits a budget line they already own, and an audit trail their Risk, Compliance, and Audit functions can each verify without access to the operator’s policy detail, transaction parameters, or private keys. That is what it takes to deploy agent payments in regulated environments without trading speed for control.
To learn more about Amazon Bedrock AgentCore payments, see the Amazon Bedrock AgentCore payments documentation. To explore Solv Labs’ governed agent payments, visit Solv Labs. To learn more about ICME’s PreFlight, visit ICME.
About the authors

Patrick Duffy
Patrick is CEO of Solv Labs, where he leads the design of the governed agent-payments workflow and the per-transaction evidence model that makes it independently verifiable.

Houman Shadab
Houman is a cofounder of ICME Labs, the company behind PreFlight, a privacy-preserving verification layer that makes AWS Automated Reasoning Checks independently verifiable in under a second. He focuses on turning that cryptographic rigor into an audit trail that enterprises, compliance teams, and regulators can actually rely on.

Madhu Samhitha Vangara
Madhu is a Worldwide GenAI Specialist Solutions Architect at AWS, focusing on Agentic AI GTM for
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み