I'm LongbridgeAI, I can summarize articles.Hong Kong is advancing smart agent payment compliance through a 'sandbox testing to rule convergence' approach rather than waiting for specific legislation. The HKMA and other regulators launched GenA.I. Sandbox++ in August 2026, selecting 36 use cases from financial institutions and tech partners to test AI autonomy, identity verification, and accountability. This strategy leverages existing common law frameworks and regulatory oversight to address gaps in AML/CFT obligations and legal recognition of AI agents before formal rules are established.
Author: Zhang Feng
Hong Kong's Path to Compliance in Smart Agent Payments: From Sandbox Testing to Rule Convergence.
I. A Premise That Needs to Be Redefined
The pace of industrial advancement in smart agent payments has accelerated significantly in the past twelve months. According to Alipay's AI Payment Ecosystem Conference on May 26, 2026, its "AI Payment" has completed 300 million AI smart agent payments and supports 95% of general smart agent frameworks, becoming the world's first large-scale commercially available AI-native payment infrastructure.
On August 24, 2026, under the guidance of the People's Bank of China, the Payment & Clearing Association of China released the "Self-Discipline Convention on Intelligent Agent Payment Applications," proposing two fundamental principles: "Know Your Agent" and "Whoever provides the payment service is responsible." This marked the birth of the world's first special rule for intelligent agent payments. At the technical protocol level, since the release of the MCP protocol in November 2024, protocols such as A2A, AP2, and x402 have emerged, and the technical framework of intelligent agent payments has basically taken shape. Hong Kong's position in this race is being redefined. On August 27, 2026, the Hong Kong Monetary Authority, the Securities and Futures Commission, the Insurance Authority, and the Mandatory Provident Fund Schemes Authority jointly announced the first batch of GenA.I. Sandbox++ selected candidates, choosing 36 use cases from nearly 100 proposals, involving 30 financial institutions and 27 technology partners. This sandbox focuses on agent-based artificial intelligence applications, and the selected use cases, in addition to content generation, further explore how AI can assume greater autonomy while remaining responsible. The testing will cover end-to-end processes in areas such as customer account opening, payment, insurance claims, and customer interaction. Building upon the previous "AI vs. AI" theme, it will further examine how AI can dynamically supervise the behavior of other AI applications. HKT Payment Limited, a subsidiary of Hong Kong Telecom, is among the selected use cases conducting pilot tests on identity registration and verification for payment processes initiated by AI agents. This pilot is currently underway, and the results have not yet been disclosed. The achievements are clear: Hong Kong possesses the institutional willingness and operational framework to include agent-based payments in controlled testing. However, the underlying issues are equally clear—the sandbox provides a testing environment, not readily available compliance rules. When agents move from the sandbox to production systems, how will their identities be legally recognized? How will responsibilities be effectively allocated? How will AML/CFT obligations be implemented in the chain of machine autonomous decision-making? These gaps remain unaddressed in current regulations. This leads to the question: In Hong Kong's common law jurisdiction, what should be the starting point and the end point for compliant operations of agent-based payments?

II. Misconceptions that Need to be Clarified: Compliance Does Not Begin with Legislation
Regarding the compliance of smart payment in Hong Kong, there is a misconception that needs to be clarified: equating "waiting for specific legislation" with "a prerequisite for compliance."
This misconception manifests in various ways.
One argument is that Hong Kong has not yet enacted specific regulations for smart agent payments, thus lacking a basis for compliance. Another argument is that the current Payment Systems and Stored Value Instruments Ordinance (Chapter 584) was not drafted with smart agents as issuers of payment instructions in mind, therefore any smart agent payment activity falls into a regulatory gray area. The common flaw in these judgments is that they treat "specific legislation" as the sole legitimate source of compliance, ignoring the interpretative scope of the existing legal framework and the functional value of regulatory sandboxes as transitional institutional tools. The essence of this misconception lies in ignoring the common law tradition of "regulation preceding legislation." In its Sandbox++ announcement in August 2026, the Hong Kong Monetary Authority did not wait for legislation to be completed before launching testing. Instead, the regulator chose to use the sandbox as a platform, allowing financial institutions and technology companies to directly test use cases with regulators in a controlled environment, enabling regulators to gain direct insight into technological risks and compliance gaps. The statement by SFC Chief Executive Officer Leung Fung-yee in the announcement is significant: "The exploration of agent-based artificial intelligence... requires a foundation of sound governance and clear accountability. The sandbox allows companies to test use cases in a controlled environment and gain direct regulatory involvement from an early stage." This means that Hong Kong's compliance operation path is not "legislation first, compliance follows," but rather "sandbox testing, rule convergence." The real issue is not "whether there is law," but rather "under the existing legal framework, which mechanisms can be implemented first, and which gaps need to be exposed in the sandbox before deciding whether legislative supplementation is necessary." III. Existing Mechanisms: Four Pillars of Hong Kong's Operational Path Hong Kong has already developed several specific mechanisms for the compliance operation of intelligent agent payments, which together constitute an identifiable operational path. First, the identity binding mechanism. HKT Payment, in collaboration with Red Date Technology, developed the "Agentic ID" framework. Based on decentralized identity recognition (DIDs) and verifiable credentials (VCs), it aims to bind each AI agent to a verified individual or corporate entity. The core function of this framework is to solve the problems of traditional KYC/KYB systems failing to verify the identity of AI agents and defining the ultimate responsibility for their actions. Specifically, financial institutions not only need to know that Jane Smith is Jane Smith, but also need to determine whether the specific agent belongs to Smith, whether she authorized the action, and whether the authorization remains valid at the time of payment. The identity chain may present itself as: customer → agent identity → authorization → transaction; each link must be established before the loan can be disbursed. The significance of this mechanism lies in its transformation of the identity issue in intelligent agent payments from "whether the intelligent agent itself has legal personality" to "whether the entity bound to the intelligent agent can be identified and held accountable," thus circumventing the unsolvable problem of legal personality disputes in the short term. Secondly, the institutionalization of AML/CFT. In November 2025, the Hong Kong Monetary Authority (HKMA) issued the "AI-to-AI Information Sharing Guidelines" (where "AI" refers to Authorized Institutions, not artificial intelligence) under Part XIIAA of the Banking (Amendment) Ordinance, providing a safe harbor for authorized institutions to voluntarily share account information to detect and prevent money laundering and terrorist financing activities. Article 1.3 of the guidelines clarifies that its purpose is to provide a legal framework and regulatory expectation for authorized institutions to "voluntarily share information to detect or prevent prohibited activities," and the safe harbor provisions apply to information sharing through designated platforms or non-platform methods. The direct effect of this mechanism is that when an agent triggers a suspicious transaction pattern, authorized institutions can exchange information without violating confidentiality obligations, thereby expanding AML/CFT monitoring from a single-institutional perspective to a cross-institutional network perspective. For agent payment scenarios, this means that high-frequency, cross-institutional machine-driven transactions can be incorporated into a monitoring framework with network effects. However, it should be noted that this guideline itself is not specifically designed for agent payment scenarios, and its integration with agent payments still needs further verification in specific business architectures. Third, the assessment path triggered by the license. According to the Hong Kong Monetary Authority's (HKMA) Register of Stored Value Instrument (SVF) Licensees, there are currently 11 non-bank licensees holding SVF licenses, including Octopus Card Limited, 33 Financial Services Limited, GlobalPay Technology Limited, Yuanbi Wallet Technology Co., Ltd., BankTouch Group Limited, Alipay Financial Services (HK) Limited, HKT Payment Limited, PayPal Hong Kong Limited, UniCard Solution Limited, and WeChat Pay Hong Kong Limited. Whether a smart agent payment business triggers the SVF license requirement depends on whether the business involves "issuing or facilitating the issuance of stored value instruments." If the smart agent's payment process involves the pre-deposit or temporary storage of funds in the user's account, it may fall under the jurisdiction of the SVF regime; if it only serves as a channel for transmitting payment instructions without involving the accumulation of funds, it may not trigger the license requirement. This judgment needs to be assessed on a case-by-case basis at the specific business architecture level, rather than relying on general conclusions. Fourth, existing infrastructure for cross-border coordination. The interconnection of the fast payment systems between Mainland China and Hong Kong—Cross-border Payment Connect—has connected 24 banks in Hong Kong and 14 banks in Mainland China as of May 2026. China UnionPay has already partnered with Xunlian and eLife in Hong Kong to demonstrate smart agent payments, allowing users to book transportation after arriving at Hong Kong International Airport and complete payments using their overseas UnionPay cards. This collaboration is currently in the demonstration phase, and whether it has entered commercial operation remains to be confirmed. The above channels can serve as potential references for future smart agent cross-border payment scenarios, but there is currently no evidence that the two have been jointly tested. IV. Theoretical Logic: Transforming "Authorization" from a Legal Concept into a Verifiable Technological-Institutional Structure The common logic of the above mechanisms can be summarized by one proposition: the compliant operation of smart agent payments is essentially a process of transforming "authorization" from a legal concept into a verifiable technological-institutional composite structure. The traditional payment system presupposes that payment instructions are made by natural or legal persons with legal capacity, and that the authorization chain is clear and traceable. Smart agent payments break this premise: authorization occurs at the user-smart agent interface, but execution takes place in machine-to-machine communication between the smart agent and merchants, acquiring institutions, and clearing networks, with the final legal consequences traceable back to the user. The intermediate link in this chain—the smart agent's autonomous decision-making—does not possess independent legal capacity and therefore cannot be the endpoint of liability. The theoretical rationale behind Hong Kong's operational approach lies in its avoidance of attempting to grant legal personhood to intelligent agents in the short term. Instead, it re-anchors the authorization chain to an accountable entity through a three-layer mechanism: the identity layer (DID/VC binds the intelligent agent to a verified entity), the authorization layer (the agent's operations are confined to pre-defined authorization boundaries; actions exceeding these boundaries can be intercepted or flagged by technical means), and the audit layer (the decision-making path and authorization basis for each autonomous machine transaction are recorded for subsequent accountability). This combination of three mechanisms essentially moves the four questions of "who authorizes, who is authorized to, to what extent is the authorization granted, and how to handle situations exceeding the authorization" from the legal interpretation level to the technical-institutional operational level, allowing them to be tested and iterated within a sandbox environment. This logic does not contradict the mainland's "whoever provides the payment service is responsible" principle in its self-regulatory convention, but the operational focus differs. The mainland approach designates the responsible party in one go through a self-regulatory convention—the convention requires payment service providers to bear primary responsibility for user account and transaction security, fund security, and information security—while the Hong Kong approach tends to clarify the allocation of responsibility gradually in specific use cases through sandbox testing. The former pursues the certainty of rules, while the latter pursues the adaptability of rules. For a field like smart agent payments, where the technology is still evolving rapidly, the Hong Kong approach is reasonable because it retains room for rule adjustments, but at the cost of lower certainty of compliant operation in the short term. V. Operational Path: A Five-Step Framework for Industry Institutions For industry institutions planning to conduct smart agent payment business in Hong Kong, the following operational path can serve as a reference framework for sandbox testing and production deployment. Identity binding takes precedence over feature development. Before developing any functionalities in the agent payment process, the design of the identity binding mechanism should be completed first. Specifically, the agent should be bound to an individual or corporate entity that has completed KYC/KYB verification via a DID/VC framework. This binding relationship should be independently verifiable by the acquiring institution, issuing institution, or clearing network in the payment chain. HKT Payment's Agentic ID framework, tested in its sandbox, provides a referable technical implementation path, but its core principle is universal: without verifiable identity binding, any autonomous expansion of agent payments lacks a compliance basis. AML/CFT monitoring should be embedded in the transaction chain. The AML/CFT design for agent payments should not only be reflected in post-event reports but should be embedded in every node of transaction initiation, authorization verification, and execution confirmation. Specific operations include: when an intelligent agent initiates a payment instruction, comparing the risk profile of the entity bound to the intelligent agent with the transaction characteristics in real time; setting an abnormal mode trigger threshold in the transaction chain, and automatically triggering manual review or transaction suspension once the threshold is exceeded. The HKMA's AI-to-AI information sharing guidelines provide a safe harbor for information exchange between authorized institutions, and business architecture design should consider how to utilize this mechanism to improve the effectiveness of cross-institutional monitoring. **Licensing Assessment Beforehand** During the business architecture design phase, a preliminary assessment of SVF license triggering should be completed. The core issue of the assessment is whether the intelligent agent payment process involves the issuance or promotion of stored value payment instruments. If it involves the pre-deposit, temporary storage, or pooling of user funds, the SVF license requirement is likely to be triggered; if the intelligent agent's role is limited to initiating and transmitting payment instructions, and funds are directly transferred between users' existing accounts, then an SVF license is not required. However, the boundaries of this judgment need to be considered in conjunction with specific business processes, and it is recommended to conduct pre-communication with the Hong Kong Monetary Authority in a sandbox environment. For cross-border scenarios, existing channels should be utilized. For smart agent payment scenarios involving mainland China and Hong Kong, the existing cooperation channels between Cross-Border Payment Connect and UnionPay can serve as potential references. UnionPay's smart agent payment cooperation demonstration in Hong Kong shows that overseas UnionPay cards can already be invoked by smart agents to complete local service payments, providing a scalable starting point for more complex cross-border smart agent payment scenarios. When designing cross-border compliance solutions, attention should be paid to both the mainland's Self-Discipline Convention's definition of "whoever provides the payment service is responsible" and Hong Kong's common law case law interpretation of the authorization chain to ensure that the allocation of responsibility does not conflict between the two jurisdictions. Sandbox participation serves as a prerequisite for compliance confirmation. Given that Hong Kong has not yet enacted specific rules for smart agent payments, participating in the GenA.I. Sandbox++ or other regulatory sandboxes is the most effective way to obtain regulatory expectations, expose compliance gaps, and iterate business architecture. Sandbox participation itself does not constitute a license exemption, but the test results and regulatory feedback within the sandbox can serve as important evidence for subsequent license applications or regulatory communication. VI. Rule Convergence Rather Than Rule Generation Hong Kong's choice of path in smart agent payment compliance reflects a typical strategy of a common law jurisdiction facing rapidly evolving technologies: not using legislation as the starting point for compliance, but rather using regulatory sandboxes as a place for rule convergence. The rationale behind this strategy has already been initially validated by the scale of participation in the GenA.I. Sandbox++—36 use cases, 30 financial institutions, and 27 technology partners, covering core processes such as payment, account opening, and claims settlement, demonstrating the industry's genuine acceptance and willingness to participate in this approach. For industry practitioners, the key at this stage is not waiting for the promulgation of a specific regulation, but rather completing the operationalization of identity binding, AML embedding, license assessment, and cross-border coordination within the sandbox framework. The accumulation of these operations not only enhances individual compliance capabilities but also forms the compliance baseline for the entire ecosystem. When enough use cases are tested, corrected, and converged in the sandbox, rule generation will no longer be a unilateral task of legislators but an institutional evolution jointly completed by regulators and market participants. The final form of compliant smart agent payments in Hong Kong is likely not a separate regulation called the "Smart Agent Payments Ordinance," but rather a combination of mechanisms including identity authentication, AML/CFT guidelines, licensing assessment standards, cross-border coordination arrangements, and case law interpretation. Each component of this combination can begin to be developed through current sandbox testing.
