If you try automating bots to do KYC for debit cards what you'll be doing is basically looking like a money launderer and get all your accounts shut down.
Let’s say for a minute this is a failure of my imagination. Does each sub agent really need to be able to independently transact?
Besides, you're already effectively giving agents money (tokens aren't free, and agents decide when to stop consuming new ones), this is just more explicit :)
KYC is probably particularly important in this space and it should be easily traceable to a human.
Do we need KYC for reloadable cards under a certain dollar amount though? I don't think so. We need a new tier of regulation to account for the fact that a lot of online transactions occur which do not fit a 'gift card' model but do not feel as comfortable with a 'forever identity' attached (for instance music subscriptions, recurring application payments, perhaps donations). A prepaid debit card with a limit of $500 or $1000, maybe, that anyone can get, like the old GreenDot cards but with a lower threshold and the ability to set a pin.
Basically as much as someone might carry around in cash, or a week or so of what someone might make at a 'not high wage' job.
Not everyone wants a bank account, or an account at a place that is not a bank account, and often people with those want an alternative to just cash.
We should not be so willing to sacrifice our possible pseudoanonymity; have we learned nothing from ad serving?
The existing "credit card" infrastructure is not designed to compete with that.
Now some actors like Paypal could have come up with an HTTP 402 standard and implementation 25 years ago but they never did. I am not sure why.
On-chain transactions are still not free. x402 isn't settled in batches or rolled up anywhere AFAIK, so large volumes of tiny payments are still not cost-effective. Facilitators such as Coinbase only subsidize transactions up to a point: https://docs.cdp.coinbase.com/x402/core-concepts/facilitator
There are ways around this, but with tradeoffs.