AI Insiders covered Stripe’s acquisition of OpenRouter as news when it was announced. AMP, a research and investment publication whose authors hold a financial stake in OpenRouter, argues that most of the commentary since, framed around routing convenience or billing consolidation, missed the actual motive. In a research note on AMP, Anjney Midha and Malika Aubakirova contend Stripe bought the company for one asset: the only cross-model dataset that can secure AI agents holding spending authority.
Midha, the note’s lead author, arranged the company’s earliest venture financing for a16z, and AMP PBC, the publication running this analysis, put its own money in afterward. Midha now sits on OpenRouter’s board. Aubakirova, the piece’s co-author, was involved in the original a16z investment and co-wrote the token study AMP cites as its central evidence. None of that makes the argument wrong, but the source is not a neutral outside analyst.
AMP’s case starts with a reframe of Stripe itself. The company is usually described as a payments processor, but AMP argues its Radar engine, trained daily on adversarial transactions across Stripe’s network, is the more important product. That continuous training loop against live fraud attempts is what AMP says actually differentiates Stripe from any bank or card network.
OpenRouter’s platform handles a claimed 10 trillion-plus tokens daily, spread across roughly 500 models supplied by dozens of vendors, per AMP’s account. The authors say that traffic looks less like a person typing a question and more like an autonomous agent looping through tool calls with its own credentials and spending authority. AMP’s own study of 100 trillion tokens routed through the platform found reasoning models climbed from a sliver of traffic to over half within a year, while average prompt length roughly quadrupled.
An agent that can spend money and call tools is, in AMP’s framing, a counterparty rather than a user. Fraud, misalignment, and a hijacked agent all look identical at the moment they act: a transaction. AMP argues no single lab can see this behavior across models, because each one only observes its own. For open-weight models served by multiple independent providers, no lab observes anything at all. The routing layer, in this reading, is the only place the behavior aggregates.
AMP acknowledges the obvious objection: the deal puts a corpus this rare, an agent behavior record spanning every model on the platform, inside one private company’s walls. The authors answer that Stripe stays neutral on models, since it builds none of its own and rivals no lab directly. That argument is also the weakest link. AMP is asking the market to trust a concentration risk on the word of the same investors who profit from OpenRouter changing hands. The piece names no audit right or outside regulator that would verify it.
For operators building agents on OpenRouter with real spending authority, AMP’s motive theory matters less than what Stripe does next. Watch whether Stripe opens any part of that behavioral data, an audit trail, a shared fraud signal, to third parties, or keeps it proprietary. That decision within the next few quarters will show whether this was ecosystem safety infrastructure or a data acquisition wearing a safety narrative.
The analysis and disclosures above are drawn from a research note by Anjney Midha and Malika Aubakirova published on AMP at amppublic.com/research/openrouter.