Inspiration

AI agents are rapidly moving beyond answering questions to taking real-world actions — purchasing products, booking services, subscribing to software, and spending money on behalf of users.

But giving an autonomous AI agent direct and unrestricted access to a payment API creates a serious security problem. An AI can make a wrong decision, misunderstand an instruction, or be manipulated — and the result could be a real financial loss.

We asked:

How can we give AI the ability to act autonomously without giving it unrestricted control over someone's money?

That question inspired PayGuard AI.

PayGuard AI acts as a safety and policy layer between autonomous AI agents and payment infrastructure. Our goal is to make autonomous commerce not only intelligent, but also safe, explainable, and controllable.


What it does

PayGuard AI evaluates every autonomous payment before money moves.

Instead of allowing an AI agent to directly call PayPal, the agent first sends its payment intent through PayGuard AI.

The transaction passes through three layers:

1. AI Risk Intelligence

PayGuard analyzes transaction information such as:

  • Transaction amount
  • Merchant
  • Purchase category
  • Risk indicators
  • Transaction context

It generates a risk score, risk level, and explanation for the decision.

2. Policy Enforcement

The risk assessment is combined with user-defined financial guardrails, including:

  • Maximum autonomous transaction limit
  • Daily spending limit
  • Monthly spending limit
  • New merchant protection
  • High-risk transaction blocking
  • Human approval requirements

This ensures that the AI cannot define or bypass its own financial boundaries.

3. Secure Execution

If the transaction passes the risk and policy checks, PayGuard allows it to proceed through the PayPal Sandbox Orders API.

If the transaction is suspicious or violates a policy, it is blocked or sent for human approval.

Every transaction produces an explainable audit trail showing the risk assessment, policies evaluated, final decision, and payment status.

The core workflow is:

AI Intent → Risk Analysis → Policy Engine → Human Approval (if required) → PayPal Execution


How we built it

We designed PayGuard AI as a modular fintech security platform with a clear separation between the Decision Layer and the Payment Execution Layer.

Frontend

The frontend was built using:

  • HTML5
  • CSS3
  • JavaScript
  • Font Awesome

We created a premium fintech-style interface with:

  • AI Agent Simulator
  • Real-time risk analysis
  • Risk score visualization
  • Financial policy controls
  • Transaction dashboard
  • Audit logs
  • Payment execution status
  • Explainable AI decisions

We focused heavily on making complex AI security decisions understandable to users.

Backend

The backend uses Python and Flask to provide APIs for:

  • AI transaction analysis
  • Policy management
  • Transaction history
  • PayPal order creation
  • PayPal payment capture

AI Risk Engine

The risk engine converts transaction context into a structured decision containing:

  • Risk score
  • Risk level
  • Decision
  • Reasoning
  • Policy evaluation

This makes the AI decision explainable instead of treating it as a black box.

PayPal Integration

We integrated the PayPal Sandbox REST API as the payment execution layer.

Once PayGuard determines that a transaction is safe and within policy, it can create and capture the corresponding PayPal order.

This demonstrates that PayGuard is not simply a visual prototype — the safety layer is positioned directly in the payment flow.


Challenges we ran into

One of our biggest challenges was deciding when an AI should be trusted to act autonomously and when it should be stopped.

Financial decisions require a much higher level of reliability than ordinary AI responses.

We had to design rules for situations such as:

  • High-value transactions
  • Unknown merchants
  • Suspicious transaction patterns
  • Policy violations
  • Transactions requiring human approval

Another major challenge was Explainable AI.

Simply displaying "TRANSACTION BLOCKED" is not enough. Users need to understand why their transaction was stopped.

We therefore designed the interface to connect the final decision with the underlying risk signals and policy violations.

We also had to carefully coordinate AI analysis, policy validation, and PayPal execution while maintaining a clean separation of responsibilities.


Accomplishments that we're proud of

Our biggest accomplishment is building a complete AI-to-payment safety pipeline instead of creating another AI chatbot or payment interface.

We successfully separate:

Decision Layer → PayGuard AI

from

Execution Layer → PayPal

This creates an important security principle:

AI can request a payment, but AI should never have unrestricted authority to execute one.

We are also proud of the product experience.

Instead of presenting technical security information as raw logs, PayGuard transforms it into a clear fintech interface where users can understand:

  • What the AI wants to purchase
  • How risky the transaction is
  • Which policies were evaluated
  • Why it was approved or blocked
  • Whether human approval is required
  • What happened during payment execution

This combination of AI, financial policy, human oversight, and PayPal execution is what makes PayGuard AI unique.


What we learned

Building PayGuard AI taught us that AI safety becomes much more important when AI can interact with real-world systems.

We learned how to work with the PayPal Developer Platform and Orders API, design payment workflows, and build a middleware layer around financial actions.

More importantly, we learned that AI safety is not only a machine-learning problem.

It requires a combination of:

AI + Policy + Security + Human Oversight + User Experience

We also learned the importance of separating intent from execution.

An AI agent should be able to say:

"I want to make this purchase."

without automatically receiving permission to say:

"I have permission to spend the money."

PayGuard provides that missing safety boundary.


What's next for PayGuard_AI

We envision PayGuard AI becoming a broader security infrastructure layer for agentic commerce.

Future versions could include:

  • Real-time LLM-based purchase intent analysis
  • Receipt and invoice understanding
  • Merchant reputation intelligence
  • Behavioral anomaly detection
  • Adaptive spending policies
  • Multi-agent approval workflows
  • Independent AI auditor agents
  • Organization-level financial controls
  • Multi-user approval systems
  • Semantic analysis of purchase intent

For example, one AI agent could propose a purchase while a separate Auditor AI evaluates whether the purchase is legitimate, necessary, and within policy.

Our long-term vision is simple:

AI agents should be able to act autonomously without ever receiving unchecked access to financial power.

PayGuard AI is the safety layer designed to make that future possible.

Built With

Share this project:

Updates

posted an update —

We are so excited to officially share PayGuard_AI with the community for the PayPal AI Hackathon!

As AI agents get smarter and begin making purchases on our behalf, traditional payment systems only ask, "Can this payment be processed?" We realized we needed a system that asks, "Should this payment happen?"

What we've built: We’ve successfully integrated the PayPal Sandbox API with Google Gemini to create a 3-step intelligent transaction gateway. Before any money moves, Gemini acts as an autonomous auditor to evaluate the transaction against custom risk rules and policy checks.

If the AI detects high risk (like an unusual purchase category or a suspicious amount), it blocks or flags the transaction for human review. If it's safe, the PayPal API captures the order instantly!

Tech Stack:

AI: Google Generative AI (Gemini) Payments: PayPal REST API Backend: Python / Flask Frontend: Vanilla JS / HTML / CSS Database: MySQL

Log in or sign up for Devpost to join the conversation.

Submission history