Visa and Mastercard joining the Agentic Payments Alliance is the industry’s way of admitting that the next payment initiator won’t be a human with a card or a phone. It will be software acting on behalf of a consumer or a business.
For PSPs, this shifts the conversation from “when will AI agents pay?” to “how do we handle liability when they do?”
The current payment flow assumes a human is in the loop. You have authentication, 3DS, device binding, and behavioral biometrics all pointing at one person. An AI agent changes that equation entirely. The agent isn’t the account holder, but it holds the credentials. It isn’t the buyer, but it makes the purchasing decision.
That breaks the fraud model.
When a chargeback occurs because an agent was instructed to find the cheapest flight and it booked a non-refundable fare, who is liable? The consumer who set the parameters? The merchant whose API the agent used? The PSP that processed the transaction? The card scheme that set the rules? Right now, the answer is unclear, and in the absence of clarity, the default will be that the PSP absorbs the loss.
What many PSPs underestimate is that this is not just a technical integration problem. It is a compliance problem. Frederic Yves Michel NOEL highlights that regulators will not wait for case law to develop. They will mandate that PSPs prove they can identify agent-initiated transactions, apply appropriate risk scoring, and ensure consumer consent mechanisms are explicit. If your transaction monitoring cannot distinguish between a human swiping a card and an agent calling an API, you will be non-compliant before the rules are even finalized.
The commercial consequence is equally stark. If you cannot support agentic payments securely, merchants will route around you. They will use PSPs that offer dedicated agent credentials, machine-readable receipts, and reconciliation that matches agent intent rather than just transaction IDs.
I would not look at this as a distant scenario. The schemes are building the standards because their largest merchants are already testing agentic commerce. The infrastructure is being laid now.
For PSPs, the key point is to start mapping your current flow against an agent-initiated transaction today. Where does authentication break? Where does your fraud model fail? Where does liability sit in your terms?
For payment teams already working on this, where is the friction greatest—authenticating the agent, or assigning liability when the agent makes a bad decision?

Comments are closed