Inspiration
AI agents are rapidly moving beyond answering questions to taking real-world actions — purchasing products, booking services, subscribing to software, and spending money on behalf of users.
But giving an autonomous AI agent direct and unrestricted access to a payment API creates a serious security problem. An AI can make a wrong decision, misunderstand an instruction, or be manipulated — and the result could be a real financial loss.
We asked:
How can we give AI the ability to act autonomously without giving it unrestricted control over someone's money?
That question inspired PayGuard AI.
PayGuard AI acts as a safety and policy layer between autonomous AI agents and payment infrastructure. Our goal is to make autonomous commerce not only intelligent, but also safe, explainable, and controllable.
What it does
PayGuard AI evaluates every autonomous payment before money moves.
Instead of allowing an AI agent to directly call PayPal, the agent first sends its payment intent through PayGuard AI.
The transaction passes through three layers:
1. AI Risk Intelligence
PayGuard analyzes transaction information such as:
- Transaction amount
- Merchant
- Purchase category
- Risk indicators
- Transaction context
It generates a risk score, risk level, and explanation for the decision.
2. Policy Enforcement
The risk assessment is combined with user-defined financial guardrails, including:
- Maximum autonomous transaction limit
- Daily spending limit
- Monthly spending limit
- New merchant protection
- High-risk transaction blocking
- Human approval requirements
This ensures that the AI cannot define or bypass its own financial boundaries.
3. Secure Execution
If the transaction passes the risk and policy checks, PayGuard allows it to proceed through the PayPal Sandbox Orders API.
If the transaction is suspicious or violates a policy, it is blocked or sent for human approval.
Every transaction produces an explainable audit trail showing the risk assessment, policies evaluated, final decision, and payment status.
The core workflow is:
AI Intent → Risk Analysis → Policy Engine → Human Approval (if required) → PayPal Execution
How we built it
We designed PayGuard AI as a modular fintech security platform with a clear separation between the Decision Layer and the Payment Execution Layer.
Frontend
The frontend was built using:
- HTML5
- CSS3
- JavaScript
- Font Awesome
We created a premium fintech-style interface with:
- AI Agent Simulator
- Real-time risk analysis
- Risk score visualization
- Financial policy controls
- Transaction dashboard
- Audit logs
- Payment execution status
- Explainable AI decisions
We focused heavily on making complex AI security decisions understandable to users.
Backend
The backend uses Python and Flask to provide APIs for:
- AI transaction analysis
- Policy management
- Transaction history
- PayPal order creation
- PayPal payment capture
AI Risk Engine
The risk engine converts transaction context into a structured decision containing:
- Risk score
- Risk level
- Decision
- Reasoning
- Policy evaluation
This makes the AI decision explainable instead of treating it as a black box.
PayPal Integration
We integrated the PayPal Sandbox REST API as the payment execution layer.
Once PayGuard determines that a transaction is safe and within policy, it can create and capture the corresponding PayPal order.
This demonstrates that PayGuard is not simply a visual prototype — the safety layer is positioned directly in the payment flow.
Challenges we ran into
One of our biggest challenges was deciding when an AI should be trusted to act autonomously and when it should be stopped.
Financial decisions require a much higher level of reliability than ordinary AI responses.
We had to design rules for situations such as:
- High-value transactions
- Unknown merchants
- Suspicious transaction patterns
- Policy violations
- Transactions requiring human approval
Another major challenge was Explainable AI.
Simply displaying "TRANSACTION BLOCKED" is not enough. Users need to understand why their transaction was stopped.
We therefore designed the interface to connect the final decision with the underlying risk signals and policy violations.
We also had to carefully coordinate AI analysis, policy validation, and PayPal execution while maintaining a clean separation of responsibilities.
Accomplishments that we're proud of
Our biggest accomplishment is building a complete AI-to-payment safety pipeline instead of creating another AI chatbot or payment interface.
We successfully separate:
Decision Layer → PayGuard AI
from
Execution Layer → PayPal
This creates an important security principle:
AI can request a payment, but AI should never have unrestricted authority to execute one.
We are also proud of the product experience.
Instead of presenting technical security information as raw logs, PayGuard transforms it into a clear fintech interface where users can understand:
- What the AI wants to purchase
- How risky the transaction is
- Which policies were evaluated
- Why it was approved or blocked
- Whether human approval is required
- What happened during payment execution
This combination of AI, financial policy, human oversight, and PayPal execution is what makes PayGuard AI unique.
What we learned
Building PayGuard AI taught us that AI safety becomes much more important when AI can interact with real-world systems.
We learned how to work with the PayPal Developer Platform and Orders API, design payment workflows, and build a middleware layer around financial actions.
More importantly, we learned that AI safety is not only a machine-learning problem.
It requires a combination of:
AI + Policy + Security + Human Oversight + User Experience
We also learned the importance of separating intent from execution.
An AI agent should be able to say:
"I want to make this purchase."
without automatically receiving permission to say:
"I have permission to spend the money."
PayGuard provides that missing safety boundary.
What's next for PayGuard_AI
We envision PayGuard AI becoming a broader security infrastructure layer for agentic commerce.
Future versions could include:
- Real-time LLM-based purchase intent analysis
- Receipt and invoice understanding
- Merchant reputation intelligence
- Behavioral anomaly detection
- Adaptive spending policies
- Multi-agent approval workflows
- Independent AI auditor agents
- Organization-level financial controls
- Multi-user approval systems
- Semantic analysis of purchase intent
For example, one AI agent could propose a purchase while a separate Auditor AI evaluates whether the purchase is legitimate, necessary, and within policy.
Our long-term vision is simple:
AI agents should be able to act autonomously without ever receiving unchecked access to financial power.
PayGuard AI is the safety layer designed to make that future possible.
Log in or sign up for Devpost to join the conversation.