Your Customer May Soon Be an AI Agent: Is Your Payments Risk Framework Ready?

For decades, payments companies have built their risk frameworks around a relatively straightforward assumption: behind every transaction is a person or a business making a decision to buy something.

Agentic commerce is beginning to challenge that assumption.  Artificial intelligence is moving beyond recommending products, comparing prices, or answering customer questions. Increasingly, AI agents are being designed to act on behalf of consumers. These agents are negotiating terms and ultimately initiating payments.

The payments industry is already preparing for this transition. EMVCo recently released a draft framework for card-based agentic payments focused in part on establishing consumer intent and delegated authority. The FIDO Alliance is similarly developing standards for trusted agent interactions, recognizing that traditional authentication and authorization models were designed for direct human interaction rather than transactions initiated by software acting for a person.

For Payment Facilitators, financial institutions, fintechs, merchants, and embedded-payment providers, this raises an important question:

Is your existing payments risk framework equipped to evaluate a transaction when the customer making the purchase may actually be an AI agent?

Identity Is No Longer Enough.  Payments risk programs have traditionally placed significant emphasis on identifying the parties involved in a transaction.  The common questions are:

·       Who is the merchant?

·       Who is the customer?

·       Who owns the business?

·       Who has authority to conduct the transaction?

Agentic commerce introduces another participant into that chain: the agent.

Payment providers may eventually need to distinguish between a legitimate authorized agent, an automated purchasing application, a conventional bot, and malicious software.  The transaction may look technically valid while the underlying authority to conduct it is not.

Authorization Takes on a New Meaning

Today, authorization generally means determining whether a payment credential can be used to complete a particular transaction.  Agentic commerce adds another dimension: Did the customer authorize the AI agent to make this particular decision?

Consider a consumer who instructs an AI assistant:  “Find me a nonstop flight to Chicago next Tuesday for less than $500.”  The consumer has established parameters, but the agent may select the airline, departure time, seat, fare category, and perhaps additional services.  What exactly has the consumer authorized?  The same issue becomes even more complicated in commercial payments.

A business might authorize an agent to reorder inventory whenever supplies fall below a certain level, provided the price stays within an approved range. That agent could potentially initiate hundreds or thousands of transactions over time.

The payment industry therefore may need to think about authorization not simply as approval of a transaction, but as evidence of delegated authority, defined limits, and verifiable intent.

Mastercard, for example, recently described an agentic-commerce trust framework built around identity, intent, controls, trusted execution, and intelligence—illustrating how significantly the concept of payment authorization could expand in an agent-driven environment.

Fraud Controls Will Need Different Signals

Fraud prevention also becomes more complicated when legitimate customers and malicious actors both use automation.  Traditional fraud models examine indicators such as transaction velocity, device information, geography, historical purchasing patterns, account behavior, and merchant characteristics.  But what happens when an authorized AI agent legitimately executes transactions at machine speed?

Activity that once appeared suspicious like rapid purchases, automated interactions, unusual hours, or repeated attempts might become completely normal.  At the same time, compromised or malicious agents could potentially conduct fraudulent activity much faster than a human attacker.  Risk models therefore may need additional signals.

Payment companies could increasingly need to understand:

  • Which agent initiated the transaction

  • Who authorized that agent

  • What purchasing authority it was given

  • Whether the transaction falls within those parameters

  • Whether the agent's behavior has changed

  • Whether unusual activity requires intervention

The challenge will be distinguishing legitimate automation from malicious automation without introducing so much friction that the benefits of agentic commerce disappear.

Disputes Could Become More Complicated

Agentic commerce could also create difficult questions around disputes and chargebacks.  Suppose an AI agent purchases exactly what a consumer technically authorized, but the consumer later argues that it was not what they intended.  Did the issuer or payment provider have enough information to determine that the purchase was agent initiated?

The answers will depend upon evolving network rules, technologies, contractual arrangements, and applicable regulations. But payment providers should recognize now that transaction evidence may become increasingly important.

The industry may need new ways to demonstrate not only that a credential was authenticated, but that an authorized agent acted within the scope established by the customer.

PayFacs Should Pay Particular Attention

Payment Facilitators and embedded-payments providers sit at an especially important point in this evolution.  Their merchants may begin accepting agent-initiated transactions before the PayFac itself develop formal policies addressing them.  That makes merchant onboarding and ongoing monitoring critical.

A PayFac may eventually need to understand whether a merchant actively supports agentic commerce, what technologies are involved, whether transaction patterns differ from traditional ecommerce, and whether existing fraud and dispute controls remain appropriate.

Sponsor banks are likely to ask similar questions.  As agentic commerce grows, oversight discussions may move beyond “What controls do you have for ecommerce?” toward more specific questions about how agent-initiated transactions are identified, authenticated, monitored, and documented.  Waiting until those questions appear on a sponsor-bank examination request is not an ideal strategy.

Start With the Existing Risk Framework

Payment companies do not necessarily need an entirely new risk program for AI commerce today.  They do need to determine where their current controls depend upon assumptions that agentic commerce may invalidate.  Start by reviewing several fundamental areas:

·       Can your systems recognize when an agent rather than a person is initiating activity?

·       Can you establish that the person or business authorized the agent—and understand the boundaries of that authority?

·       Will existing velocity and behavioral rules mistakenly flag legitimate automated activity or overlook malicious automation?

·       Do you know which merchants are enabling agent-based purchasing?

·       What evidence would demonstrate that an agent acted within the customer's instructions?

·       Who within the organization owns agentic-commerce risk?

The Time to Prepare Is Before Volume Arrives

Agentic payments are still developing, and industry standards are continuing to evolve. But major payment networks and standards organizations are already building infrastructure and frameworks around them. Visa has described AI agents beginning to transact for both individuals and businesses, while Mastercard is developing capabilities specifically designed for agent-driven payments.  Payments companies therefore should not wait for agentic transactions to represent a significant percentage of volume before examining the risks. 

 

At RPY Innovations, we help Payment Facilitators, financial institutions, fintechs, and payments companies evaluate emerging payment models through the practical lens of risk, compliance, operations, technology, and sponsor-bank oversight.

 

Next
Next

AML Program Effectiveness: What Payment Facilitators and Sponsor Banks Need to Demonstrate