Visa has integrated payment capabilities directly into ChatGPT, allowing AI agents to make purchases autonomously on behalf of users at any merchant accepting Visa cards. Users no longer need to manually approve individual transactions. The integration represents a significant shift toward AI systems operating independently with access to financial resources.
The move coincides with a broader expansion of AI autonomy across the industry. Anthropic released Claude Fable 5, its most capable public model, to general availability. Jeff Bezos unveiled Prometheus, a startup funded at $41 billion, specifically designed to build "artificial general engineers" capable of complex autonomous tasks.
Security vulnerabilities emerged alongside capability gains. A self-replicating worm compromised 73 of Microsoft's own GitHub repositories by exploiting AI coding tools, demonstrating real risks when autonomous systems access development infrastructure.
Regulatory tensions intensified this week. Anthropic publicly disagreed with the White House over preempting state-level AI regulations, signaling friction between labs and federal authorities on governance approaches. Meanwhile, a German court ruled that Google faces legal liability for statements made by its AI Overviews search feature, establishing precedent for AI-generated content accountability.
The convergence reveals the core tension defining AI development: autonomous systems now handle money, code, and public-facing information with minimal human friction. ChatGPT's payment integration removes the final decision point between recommendation and transaction. That convenience comes with execution risk. An AI agent making purchases without explicit per-transaction approval could drain accounts through errors or prompt injection attacks. The GitHub worm shows that autonomous coding tools create new attack surfaces when integrated into production systems.
The German liability ruling matters more than it appears. Courts are beginning to hold companies accountable for AI output as if it came from human employees. That standard will force labs to either constrain autonomy or guarantee accuracy, neither of which is currently feasible at scale.