EU AI Act Article 26 · ready day one

Your agents spend.
Your APIs earn.
All of it governed.

See every agent decision before it spends. Approve what matters. Hand a regulator the trace.

Protocols backed by

StripeCoinbaseVisaMasterCardShopifyLightning LabsTempo

These companies co-author or back the open protocols Custena implements - not Custena customers.

The governance gap

Your agents are spending.
Nobody can see or stop it.

The new agent payment protocols (x402, MPP, L402) handle the transaction. They carry no context, no controls, and no compliance evidence. The operational layer that enterprises actually need does not exist yet.

No visibility into what agents spend

Agents move money across x402, MPP, L402, and fiat. Raw transaction logs show amounts, not context. The CFO question - why did the agent buy this - has no answer anywhere in the stack.

No controls before the money leaves

Today's protocols only confirm a payment was valid. They carry no per-agent spending caps, no approval workflows for large calls, no kill switches. Nothing stops an agent from over-spending or buying from the wrong vendor.

EU AI Act Article 26 requires all of this

From August 2, 2026, Article 26 deployer obligations require human oversight, continuous monitoring, and log retention for autonomous AI systems - including the financial transactions they make. Fines reach 3% of global turnover.

Real-time policy
Spend caps, allow-lists, per-agent budgets - enforced before the call leaves the building.
ops-agent · daily spend cap$340 / $500 today
GET finance-api/forecast · $0.04ALLOWED
POST payroll-api/run · $1200OVER CAP

How it works

Your agent hits a paywall. Custena decides.

A policy gate sits between every agent and every outbound payment. Requests flow through in milliseconds when they stay within policy. Anything outside the rules pauses for human review - then continues.

Connect
Govern
Approve
Audit

Connect

Your agents call any API or MCP server, Custena-integrated or third-party. No per-protocol wallet setup; governance applies to every call.

Govern

Every request hits the policy gate: per-agent budgets, vendor allow-lists, category limits, and duplicate detection evaluated in real time.

Approve

Spends above a threshold ping the right human in Slack with full context. One click approves or denies - the agent waits for the decision.

Audit

Every transaction lands in the unified ledger: agent identity, endpoint, amount, reasoning, approver, and policy - ready for a regulator audit.

What Custena does

The building blocks of governed agent spending

Four capabilities, one platform. Each one maps to an Article 26 deployer obligation - and to a CFO or compliance team question that current protocol tooling cannot answer.

Real-time policy
Spend caps, allow-lists, per-agent budgets - enforced before the call leaves the building.
ops-agent · daily spend cap$340 / $500 today
GET finance-api/forecast · $0.04ALLOWED
POST payroll-api/run · $1200OVER CAP
Human approvals where it matters
Anything over the line gets a card - Slack, dashboard or API. Workflows wait; nothing leaks.

ops-agent wants to spend $1,200.00

payroll-api/run · over the $500 daily cap

Slack · dashboard · API
Every protocol, one integration
x402, MPP, L402 and fiat - agents pay outbound, your APIs earn inbound, on all of them.
x402
MPP
L402
fiat
one ledger
// same call, any rail
POST /proxy/acme/finance-api/forecast
paid via x402 (Base) · settled · span logged
Article 26 audit evidence
Every decision - allowed or halted - writes a span with the reasoning attached. Export it for a regulator.
research-agent · GET market-data/quote
within budget
ALLOWED
ops-agent · POST payroll-api/run
1200 > cap 500 -> human approval
HALT
approved by alice@acme.io
$1,200.00 · settled
SETTLED

EU AI Act Article 26 · Compliance

Compliant by default. From day one.

Article 26 enforcement begins August 2, 2026. Deployer obligations cover human oversight, continuous monitoring, and 6-month-plus log retention. Non-compliance carries fines up to 3% of global annual turnover under Article 99(4). Custena ships all three obligations on day one.

Human oversight

Art. 26(2)

Per-agent budgets, real-time approval workflows, and instant kill switches. Every spending decision your agents make can require sign-off before it executes.

Immutable audit trail

Art. 26(6)

Every transaction cryptographically logged with agent identity, endpoint, cost, timestamp, protocol, and the full reasoning chain. Retained 6 months or more. Exportable evidence for regulators, auditors, and disputes.

Continuous monitoring

Art. 26(5)

Real-time anomaly detection on agent spending. Drift alerts fire the moment behavior diverges from policy - before it becomes a compliance event.

Cryptographic receipts

Verifiable Intent

Machine-readable receipts prove each payment was authorized by a human principal - compatible with Mastercard Verifiable Intent (open-sourced March 2026).

Deadline: August 2, 2026. Deployers of high-risk AI systems must be able to show human oversight, continuous monitoring logs, and a 6-month-plus audit trail on demand. Custena ships the complete evidence package, not just a checkbox.

Two-sided platform

Built for both sides

Sellers monetize any MCP server or API in minutes. Buyers govern every dollar their agents spend - with the audit evidence to prove it.

For enterprise buyers

Govern what your agents pay for.

Deploy spending AI agents safely. Real-time policy enforcement, human approvals where it matters, and EU AI Act Article 26 audit evidence on every transaction.

  • See every dollar your agents spend

    One unified ledger across x402, MPP, L402, and fiat.

  • Per-agent budgets and approval workflows

    Set daily or monthly caps. Route high-value calls to a human.

  • EU AI Act Article 26 audit evidence

    Cryptographically logged, 6-month retention, exportable on demand.

  • Instant kill switches

    Revoke any agent's spending access in one click.

For MCP and API sellers

Monetize in 2 minutes.

Register any URL, set your price, and start earning from AI agents. No code changes needed. Every protocol, one integration, settlement via Stripe Connect.

  • Register any URL - REST, MCP, GraphQL

    No code changes required. Custena proxies and handles auth.

  • Accept x402, MPP, L402, and fiat

    Every paying agent, on every protocol, through one integration.

  • Real-time revenue dashboard

    Per-endpoint call volumes, revenue, and conversion in one view.

  • Stripe Connect settlement

    Payouts to your bank account. EU-regulated fiat rails included.

Both sides on one ledger. See pricing

Pricing

Transaction fees to start. Enterprise governance plans when it matters.

Start free for 60 days. Pay a small percentage on what your agents spend or what your APIs earn. Enterprise governance plans for compliance teams with EU AI Act Article 26 evidence requirements.

Free trial
60 days 0% fees
  • All protocols
  • Full governance
  • No card required
Pay-as-you-go
0.4% per transaction
  • Sellers and buyers
  • No monthly minimum
  • Unlimited endpoints
Enterprise governance
Custom From €500/mo
  • Article 26 evidence pack
  • Slack approvals + HITL
  • Dedicated EU support
See full pricingNo credit card required to start

Get started today

Agents that pay. APIs that earn.
All of it governed.

Start free for 60 days. No crypto wallet required. EU AI Act Article 26 compliance evidence on every transaction from day one.