Highlights
- AI agents are moving beyond recommending products to actually completing purchases within limits that users set.
- Visa, Mastercard, Google, OpenAI and Stripe have all launched frameworks or protocols for agent initiated payments.
- Tokenized credentials allow agents to pay without ever seeing your real card number.
- Spending mandates let users control amounts, merchant categories and approval rules.
- New fraud threats such as prompt injection and fake storefronts target AI buyers instead of humans.
- Liability and chargeback rules have not fully caught up with AI shoppers.
- Merchants may soon need to optimize for AI agents the same way they optimize for search engines today.
- Transparency, human checkpoints and instant kill switches will decide which platforms earn trust.
From “Click to Buy” to “Ask to Buy”
Imagine it is Sunday evening and your AI assistant notices you are almost out of coffee. It checks three stores, finds your favorite beans on sale, confirms the delivery window fits your schedule, and pays. You never open an app. You simply receive a short note: “Coffee reordered, $18.40, arriving Tuesday.”
This scenario is quickly becoming reality. Payments are shifting from human initiated to agent initiated transactions, and that shift breaks a basic assumption the payments industry was built on: that a person is sitting at the checkout. When the buyer is software acting on your instructions, everything from authentication to fraud detection to dispute resolution has to be rethought.
What Are Agentic Payments?
Agentic payments are transactions started and completed by an AI agent on behalf of a person or business, within boundaries that the person defines. The agent can search for options, compare prices, make a decision and pay, all as part of a single task.
How They Differ From Autopay and Subscriptions
We already live with plenty of payment automation. Streaming subscriptions renew monthly, utility bills are paid through autopay, and robo advisors rebalance portfolios. The difference is that those systems follow fixed rules, while an agent pursues a goal. Autopay pays the same bill every month. An agent told to “keep my household stocked for under $300 a month” decides what to buy, where to buy it and when.
The Four Levels of Autonomy
Not every agent needs full control. Most products sit somewhere on this spectrum:
- Suggest: the agent recommends and you buy.
- Confirm: the agent prepares the cart and you approve with one tap.
- Act within a budget: the agent buys freely under preset limits.
- Fully autonomous: the agent manages spending toward a goal with minimal oversight.
Consumers will likely start at levels one and two, while businesses with clear procurement policies may move to level three much faster.
How Agentic Payments Work Behind the Scenes
Delegated Credentials and Spending Mandates
The central challenge is simple: how do you let software pay without handing over your card number? The answer is tokenization. Mastercard’s approach, for example, links a tokenized card credential to one specific agent, a defined merchant scope and a consent policy, so an AI assistant can finish checkout without ever holding the actual card number. If a token leaks, it is useless outside those boundaries. For a refresher on how tokenization and encryption already protect everyday transactions, see our analysis of how payment gateways are evolving.
On top of the token sits a spending mandate. In Visa’s newest agentic partnership, transactions are designed to run inside clear user permissions and controls such as spending caps, merchant categories and mandatory approvals, backed by tokenized credentials, real time authorization and fraud monitoring.
The Frameworks Powering Agent Commerce
The industry moved fast. Mastercard announced Agent Pay in April 2025, launching with Microsoft, IBM and Braintree as partners, and Visa introduced its Intelligent Commerce program that same month, opening its rails to developers building agents that search, recommend and pay for consumers. Google followed in September 2025 with AP2, an open standard backed by more than 60 launch partners including Mastercard, PayPal, Coinbase and American Express. In 2026, Google released a second version of AP2 and handed it to the FIDO Alliance, placing its governance in a neutral body with the same lineage as passkeys. Then at its Payments Forum in June 2026, Visa announced a strategic collaboration with OpenAI to support secure payments within agentic commerce.
| Framework | Led By | Launched | Role in the Payments Stack | Key Trust Mechanism |
|---|---|---|---|---|
| Mastercard Agent Pay | Mastercard | April 2025 | Network level credentials for verified AI agents | Agentic Tokens limited to a specific agent, merchant scope and consent policy |
| Visa Intelligent Commerce | Visa | April 2025, expanded with OpenAI in June 2026 | Connects AI agents directly to the Visa network | Tokenized credentials, real time authorization, user set spending limits and approvals |
| Agent Payments Protocol (AP2) | Google, now governed through the FIDO Alliance | September 2025 | Open, payment method neutral protocol that proves user consent | Cryptographically signed mandates recording what the user wanted and what the agent selected |
| Agentic Commerce Protocol (ACP) | OpenAI and Stripe | 2025, still evolving | Checkout handshake between a buyer’s agent and a merchant | Structured, machine readable checkout that merchants can verify |
These standards are not really rivals. ACP manages the checkout itself while AP2 proves that the shopper authorized the spending, so a complete agentic purchase can rely on both, with card networks providing acceptance on top. We The Flywheel
Real World Use Cases
For Consumers
Travel is an early favorite: an agent books a flight, watches for price drops and rebooks automatically. Other practical examples include grocery restocking, finding and cancelling forgotten subscriptions, and negotiating bills for internet or insurance.
For Businesses
Companies may benefit even sooner. Procurement agents can reorder supplies when inventory runs low, pay approved vendor invoices on schedule, and monitor cloud and software spending to cut waste. Treasury agents can move idle cash between accounts to avoid fees or capture better interest rates.
The Big Questions: Risk, Trust and Liability
Who Pays When an Agent Makes a Mistake?
Suppose your agent books a nonrefundable hotel for the wrong weekend. Was the instruction unclear, did the agent misread it, or did the merchant display misleading information? Traditional chargeback rules revolve around one question: did the cardholder authorize this payment? With agents, the honest answer is often “yes, but not this way.” Signed mandates help by creating an evidence trail showing exactly what was approved.
A New Generation of Fraud
Fraudsters are adapting. Prompt injection hides instructions inside web pages to trick an agent into buying something else or paying a different account. Fake storefronts can be designed specifically to attract agents, and stolen agent credentials could allow rapid, automated spending. The wider threat is growing too: Deloitte’s Center for Financial Services projects that generative AI could push US fraud losses to $40 billion by 2027.
Regulatory Gaps
Consumer protection laws and card network dispute rules were written with human buyers in mind. Regulators have yet to clearly define how existing protections apply when a person delegates a purchase to software, which leaves early adopters in a gray zone.
What It Means for Banks, Merchants and Fintechs
Banks and card issuers have a chance to launch new products, such as agent specific cards with programmable limits and clear activity dashboards. Digital banks with strong apps and open APIs are especially well placed, as our FintechZoom.com Banking guide to digital banking explains.
Merchants face a new kind of visibility challenge. If agents choose where to shop, clean product data, accurate pricing and fast APIs become as important as a beautiful website. “Agent optimization” could become the next SEO, and brand loyalty will be harder to win when a machine compares every option instantly.
Fintech startups can build the missing layers: agent identity verification, spend controls, fraud detection built for machine behavior, and dispute evidence tools.
Consumers gain convenience but risk losing visibility into where their money goes, which makes trust features essential.
Designing for Trust
The platforms that succeed will make delegation feel safe. Best practices include:
- Transparent logs that show what the agent bought, from whom and why.
- Human checkpoints for high value or unusual purchases.
- Instant kill switches that revoke agent credentials with one tap.
- Plain language limits that users can understand and adjust easily.
- Clear receipts that separate agent purchases from manual ones.
What Comes Next
Over the next two to three years, expect agent to agent commerce, where your buying agent negotiates directly with a merchant’s selling agent. Standards for agent identity and consent will likely consolidate, and regulators will start issuing guidance while the first legal disputes test who is liable.
Progress will not be perfectly smooth. OpenAI’s earlier effort to bring agentic checkout into ChatGPT was scaled back, and the Visa partnership did not include a full launch date, participating merchants or details of the checkout experience. Early bumps like these are normal for a technology still finding its shape.
Conclusion
Agentic payments are less about artificial intelligence and more about redesigning trust in transactions. The technology to let agents pay safely already exists in tokens, mandates and open protocols. The real test is whether consumers and businesses feel confident handing over control. The winners will be the companies that make delegation feel as safe as paying yourself.
Would you let an AI agent spend your money? Share your view in the comments and follow FintechZoom.com for the rest of our series on the trends shaping financial technology.
Summary Keys
- Agentic payments are purchases completed by AI agents within limits set by users.
- Tokenized credentials and spending mandates keep real card numbers hidden and control what agents can buy.
- Major frameworks include Mastercard Agent Pay, Visa Intelligent Commerce, Google’s AP2 and the Agentic Commerce Protocol from OpenAI and Stripe.
- Key risks include prompt injection, fake merchants, unclear liability and outdated dispute rules.
- Merchants will need clean data and strong APIs to be chosen by AI agents.
- Transparency, human approvals and instant revocation are the foundations of trust.
FAQs
They can be, when built on tokenized credentials, clear spending limits and human approval for larger purchases. The safest approach is to start with low value tasks, review activity logs regularly and choose platforms that let you revoke agent access instantly.
This is still being settled. Responsibility may fall on the user, the agent provider, the merchant or the card issuer depending on what was authorized. Signed mandates and detailed logs are becoming the main evidence used to resolve these disputes, so keep records and check your provider’s terms.
Usually not. Most frameworks work with your existing card or bank account by creating a token specifically for the agent. Your real card details stay protected, and the token only works within the limits you approve.

