Industry Guide

What are agentic payments? [The enterprise guide to AI-driven payment infrastructure]

Agentic payments use AI agents to execute payments under user-defined mandates. Learn how the model works and what enterprises need to know.

On This Page

Key Takeaways

  • Agentic payments occur when an AI agent makes a payment on behalf of a user, acting on a mandate that specifies the approved merchants, spending limits, and other conditions the agent must operate within.
  • Tokenization is what makes agentic payments possible, enabling users to issue agents a token scoped to the parameters of their mandate rather than granting access to their actual payment credentials.
  • Agentic commerce describes the full buying process an AI agent handles autonomously, while agentic payments refer specifically to the moment the agent moves money.
  • Emerging protocols, including MCP, ACP, UCP, and AP2; established identity standards; and Visa and Mastercard’s agent payment initiatives are defining how AI agents connect to systems, exchange context, securely authenticate, prove authorization, and transact across platforms and payment rails.
  • Securing agentic payments depends on verifying each agent’s identity, scoping its tokenized credentials to the mandate, and keeping a tamper-resistant record of everything it was authorized to do.

What are agentic payments?

Agentic payments refer to when an AI agent makes a payment on behalf of a user, acting on a mandate the user has defined in advance. That mandate specifies the rules, intent, and constraints the agent must operate within, such as approved merchants, spending limits, and the conditions under which the agent is authorized to transact. Using tokenized credentials and cards, the agent completes the payment without the user having to initiate or approve each transaction individually.

The mandate is what sets agentic payments apart from traditional payments automation. A scheduled recurring payment executes the same transaction on a fixed cadence. An agentic mandate gives the agent the flexibility to act when conditions align with the user’s criteria rather than on a fixed trigger, making judgment calls within the boundaries the user established rather than following a predetermined script.

Large language models (LLMs) and reasoning models enable AI agents to interpret mandate parameters and apply them to novel scenarios. The Model Context Protocol (MCP)1 is one example of an open-source, cross-platform standard that enables agents to interact with external systems, including payment systems, merchant application programming interfaces (APIs), and banking infrastructure through a standardized interface.

Widespread adoption of real-time payment rails means agents can execute and settle transactions quickly enough for autonomous purchasing workflows to function as end users expect. Without that speed, autonomous workflows would stall waiting for settlement to clear, especially in cross-border and B2B payment scenarios, where conventional rails can take days to complete transactions. Real-time rails enable agents to confirm whether transactions succeeded within seconds and proceed to their next action, with no human monitoring the process in between.

What is tokenization?

Tokenization replaces a user’s sensitive payment credentials, such as card numbers and bank account details, with a unique, random string of characters or symbols, known as a token. Tokens can be used to initiate payments without exposing the user’s account information. With agentic payments, each token is scoped to specific parameters: a merchant, a spending limit, a payment method, or a time window. The token cannot be used outside those parameters.

Tokenization is what makes agentic payments possible because, rather than grant an AI agent access to their actual payment credentials, the user issues a token, which the agent then uses to transact.

agentic payments routing
ACI Worldwide’s Payments Intelligence platform enhances payment security, analytics, and fraud detection for financial institutions.

What is the difference between agentic payments vs. agentic commerce?

Agentic commerce refers to the entire process by which an AI agent autonomously makes a purchase on behalf of a consumer or a business, while an agentic payment is just one step within that process, specifically, the moment the AI agent follows the user’s mandate to move money and complete the transaction.

agentic commerce request

Why is it important for merchants to support agentic payments?

Merchants that don’t support agentic payments risk losing agent-driven sales to competitors that do.

With agentic commerce, AI agents evaluate merchants based on criteria that an end user has set, such as price, delivery times, product specifications, and brand preferences. If an agent selects a merchant but encounters friction during checkout — or, worse, the transaction fails — the agent moves on to the next merchant that meets those criteria. The original merchant doesn’t get a second chance at the sale and, in most cases, doesn’t even realize the sale was lost. This can become a revenue problem as transaction volumes increase.

Merchants whose infrastructure can handle agentic transactions are better positioned to capture and keep agent-driven sales. Each successful transaction builds agent trust signals over time, strengthening repeat conversion and customer lifetime value.

How does AI-powered routing support agentic payments?


AI-powered routing supports agentic payments by giving each transaction its best chance of being authorized the moment it’s submitted.

When a human initiates a payment and the transaction fails, they can retry, select a different payment method, or choose a different merchant. When an AI agent executes a payment on a user’s mandate, none of those fallbacks apply. The transaction either clears on the first attempt or the purchase doesn’t happen.

This dynamic makes routing accuracy more consequential in an agentic payments context compared to conventional payment flows. It also makes payments orchestration critical: Merchants need dynamic routing across providers and rails to maximize first-attempt authorization for agent-initiated transactions.

Agentic transactions also carry additional context that routing infrastructure needs to handle correctly. Each transaction is linked to a mandate ID and executed using tokenized credentials. That context needs to flow through the authorization chain so that issuers and networks can verify agent identity and validate that the transaction falls within the parameters the user established. Routing infrastructure that can’t pass that mandate metadata through to the right endpoints creates authorization failures regardless of how well the underlying credentials are structured.

AI-powered routing addresses these challenges. Rather than evaluate transactions against a static ruleset, routing agents factor in the mandate context for each transaction. They then select payment service providers (PSPs), acquirers, and payment rails that recognize agent-initiated transactions and can process tokenized credentials correctly. If a PSP consistently fails to authorize agent-initiated transactions on a specific corridor, the routing agent incorporates that into future decisions without waiting for a human to update the underlying rules.

agentic payments meaning
Young woman sitting on the sofa in the living room, managing online banking with mobile app on smartphone. Transferring money, paying bills, checking balance.

What fraud risks do agentic payments introduce?

Agentic payments introduce two main fraud risks: compromised agents, and fraudulent storefronts made to exploit how agents select merchants. Because an AI agent has standing authority to transact on a user’s behalf, any attacker who gains control of that agent can run through a series of purchases before anyone detects a problem. A scammer can also create a convincing-looking storefront that meets all of an agent’s criteria and trick that agent into transacting with an illegitimate seller.

Both are harder to catch than a single fraudulent charge because they unfold gradually across a sequence of transactions. For this reason, agentic payments require fraud to move from a one-time transaction decision to one of continuous trust, validating agent identity, mandate scope, and behavior across a stream of activity.

How do agentic payments support treasury and foreign exchange (FX) management?

Agentic payment support treasury and FX management by enabling organizations to encode their treasury policies directly into their payment mandates, so treasury agents make currency and rail decisions within a defined set of rules.

For organizations managing payments across multiple currencies, treasury decisions and payment execution are inseparable. The timing of a cross-border payment affects FX exposure, and rail selection affects settlement speed and cost. In conventional treasury operations, those decisions involve manual workflows that can’t respond quickly enough to market conditions that shift by the hour.

Rather than a human reviewing each international payment before execution, a treasury agent operates within rules the organization has defined, including FX thresholds, approved payment rails, working capital targets, and supplier payment terms, and executes accordingly. When an FX rate crosses a threshold specified in the mandate, the agent acts. When a payment corridor offers a more cost-effective rail for a given transaction, the agent selects it. The organization’s treasury policy is enforced at the moment of execution rather than reviewed after the fact.

How does agentic AI affect chargeback and dispute management?

Agentic payments introduce the risk of a consumer not recognizing a charge their agent placed on their behalf, which could lead them to file a dispute against a transaction that was technically authorized, complicating dispute management. To resolve these disputes, merchants must be able to prove what actually happened.

Only merchants and PSPs that can produce the following evidence can defend agent-initiated chargebacks at the submission stage:

  • The mandate that authorized the agent to act
  • The agent identity that executed the transaction
  • A tamper-resistant record showing that what the agent did fell within the boundaries the user established

This makes audit trail architecture a vital part of agentic payments infrastructure. Protocols such as the Agent Payments Protocol (AP2)2 address this by cryptographically binding each agent-initiated transaction to the mandate that authorized it, creating a machine-verifiable record that survives dispute adjudication.

Card networks are building complementary frameworks. For example, Visa’s Dispute Recovery Manager3 automates representment for merchants and applies win-prediction scoring to maximize recovery, while network-level tools surface transaction context to resolve cardholder confusion before a formal dispute is filed.

Are agentic payments secure?

Yes, agentic payments are secure because they use mandates to ensure that AI do exactly what users authorized them to do. By defining what agents can do in advance, organizations establish security boundaries before a transaction even occurs.

  • Agent identity verification: Each agent must have a verifiable identity linked to the user’s mandate. The FIDO Alliance is actively developing standards4 for trusted AI agent interactions, and card networks require agents to be registered and verified before they can initiate transactions. Unregistered agents are blocked at authorization, and fraud systems that validate these identity signals during the transaction can catch agents that have been compromised or spoofed.
  • Tokenized credentials: Tokenization captures a consent token that stores the user’s signed mandate, an intent token that defines spending limits and purchase categories, and a payments token that represents the underlying card credentials. Together, these produce a record of what was authorized and executed. 
  • Delegated authorization: The user authenticates once when granting the agent permission to transact. The agent then acts within those parameters without requiring transaction-level cardholder authentication at each purchase.
  • Real-time approval workflows: Transactions that approach or exceed defined risk thresholds trigger human review before proceeding, which keeps oversight part of the payments flow.
  • Spending controls and merchant restrictions: Transactions that fall outside the mandate’s parameters, such as an unauthorized merchant or an amount that exceeds the spending cap, fail at the fraud and authentication layers before they can reach settlement, regardless of whether underlying credentials are valid.
  • Verifiable intent: Every agentic transaction generates a tamper-resistant record that links the agent’s action back to the mandate that authorized it, which supports regulatory reporting and audit requirements.
  • Continuous risk evaluation: Because agents can execute transactions repeatedly and autonomously, fraud detection needs to evaluate risk across the full stream of agent activity. Patterns that appear innocuous in isolation can indicate manipulation or compromise when viewed across a sequence of transactions.
  • Network-level fraud scoring for agent-initiated transactions: Card networks5 and processors are building agent-presence signals into their fraud scoring models, so authorization flows can apply risk controls specific to agent-initiated transactions instead of models calibrated for human behavior.

What emerging protocols are shaping agentic payments?

There are several protocols shaping agentic payments, including the Model Context Protocol (MCP), the Agentic Commerce Protocol (ACP), the Universal Commerce Protocol (UCP), and the agent payment frameworks from Visa and Mastercard.

They vary in focus: Some are general-purpose standards that connect AI agents to external systems of all kinds, while others are designed specifically for commerce and payment flows. For merchants, these protocols dictate how AI agents interact with product discovery, checkout, authorization, and settlement, as well as what your payments stack must support to remain compatible as adoption scales

Model Context Protocol (MCP)

Model Context Protocol (MCP)

Developed by Anthropic, MCP is the first major open standard for connecting AI models to external systems.

MCP:

  • Standardizes data and tool access: MCP defines a common protocol that enables AI clients to connect to files, databases, APIs, and services without custom integrations or model‑specific adapters, reducing integration complexity.
  • Secures interactions through clear separation of roles: MCP servers expose only approved capabilities, ensuring the AI host accesses internal systems in a controlled, permissioned way.
  • Scales connectivity with modular, independent servers: Each MCP server can be built and maintained separately, enabling organizations to easily add new data sources without modifying the AI client.

As the foundational connectivity layer, MCP complements all other emerging protocols by enabling agents to access the data, tools, and context those commerce‑specific protocols depend on.

Agentic Commerce Protocol (ACP) (OpenAI and Stripe)

Agentic Commerce Protocol (ACP) (OpenAI and Stripe)

An open-source protocol developed by OpenAI and Stripe, ACP makes online checkouts agent-ready by focusing on the checkout and merchant interaction layer. It is optimized for chat‑to‑buy workflows within the ChatGPT ecosystem.

ACP:

  • Supports agent-driven checkout and payment flows via APIs: ACP lets AI agents discover products, place orders, and initiate payments programmatically through a merchant’s existing commerce stack via APIs.
  • Keeps merchants in control: Merchants retain merchant‑of‑record status and define pricing, policies, and fulfillment via authenticated ACP endpoints.
  • Is platform-agnostic: ACP works with any commerce backend or payment processor. Stripe’s Shared Payment Token is the first widely available implementation compatible with the ACP Delegate Payment specification, with more to be added.

Common use cases for ACP include automated procurement, consumer shopping assistance, and service micropayments.

Universal Commerce Protocol (UCP)

Universal Commerce Protocol (UCP)

UCP is an open‑source standard developed by Google in collaboration with Shopify and major retailers such as Etsy, Wayfair, and Target, along with other industry partners. It was made to power the AI agent-driven commerce lifecycle and optimize search-to-buy journeys.

UCP:

  • Keeps merchants in control: Merchants retain merchant‑of‑record status and define pricing, fulfillment, and capabilities across all authenticated ACP endpoints.
  • Covers the full commerce stack: UCP standardizes the entire agentic commerce flow, enabling agents to discover products, negotiate capabilities, build carts, and handle checkout and orders.
  • Supports flexible payments: UCP’s modular payment handlers support a wide range of payment methods and providers, with optional integration of the Agent Payments Protocol (AP2) for standardized agent‑initiated payments.

Visa and Mastercard’s new rules for agentic payments

Agentic commerce is a major behavioral shift, and card networks are already designing rules to govern it. Merchants should expect new frameworks covering:

  • Tokenization controls for agent-driven transactions
  • AI-specific spending caps tied to customer mandates
  • Enhanced strong customer authentication (SCA) for agent-originated payments
  • Mandate revocation rules defining how and when users can retract agent permissions
  • New liability and chargeback models separating agent-initiated from customer-initiated transactions
  • Agent identity attributes to authenticate legitimate digital shoppers

Mastercard collaborated with Google on the UCP to reinforce how shared, interoperable standards are essential to provide intuitive and scalable agentic commerce experiences.

In 2025, Visa launched the Trusted Agent Protocol6 to give merchants a standardized way to verify legitimate AI shopping agents and distinguish them from bots. Visa Intelligent Commerce7 is also introducing AI-ready tokenization, authentication, and fraud‑screening tools to ensure agents can transact using Visa credentials with the same security guarantees as human buyers.

Most merchants will need to support more than one of these protocols, as the ability to integrate, route, and govern agent-initiated traffic across multiple standards becomes a baseline requirement.

How can merchants support agentic payments?

To support agentic payments, merchants need infrastructure that can authenticate agents, validate mandates, and reliably complete transactions on the first attempt. Key capabilities include:

  • Protocol integration: MCP, ACP, UCP, AP2, Visa Intelligent Commerce, and Mastercard Agent Pay each define how agents authenticate, initiate transactions, and communicate with merchant systems. They also establish rules for which agents can participate and under what terms.
  • Agent verification: Merchants require systems that register and verify agents before they transact, such as Visa’s Trusted Agent Protocol and Mastercard’s Agent Pay Acceptance Framework.
  • Fraud and risk management: Agent verification confirms identity at registration, but merchants also need fraud systems that assess the risk of each agent-initiated transaction as it occurs. Because agents behave like bots, conventional fraud rules would decline most agent-initiated transactions by default, so merchants need a way to route these through fraud logic built specifically for agent activity.
  • Token and access controls: Merchants need fine-grained controls over how tokenized credentials are used, including spending caps, permitted transaction types, and time-bound permissions that expire automatically.
  • Revocation capability: Agents can execute multiple transactions before anomalous behavior is detected. Merchants need the ability to revoke agent access immediately when something goes wrong.

How does accepting agentic payments prepare merchants for the future?

Accepting agentic payments prepares merchants for the future by giving them the data and infrastructure they’ll need as this channel matures.

Agentic payments and agentic commerce are still in their infancy, but they won’t be for long. Early adopters have the opportunity to access transaction data on agent-specific purchasing behavior, including how agents select merchants, what fraud profiles look like on agent-initiated transactions, and how different mandate structures affect conversion. That data will enable merchants to refine their token controls, fraud rules, and protocol integrations.

Industry experts have already drawn comparisons8 between agentic payments and the early days of eCommerce. As with eCommerce, the merchants that establish support for agentic payments early on will be in a position to capture value and rebuild their payments infrastructure on their own terms.

agentic payment orchestration

What is the future of agentic payments?

The core agentic payments model already works; its future depends on the infrastructure around it catching up, from the legal framework to agent identity standards and protocols. Over the next few years, these developments will determine how the category grows:

  • The legal and regulatory framework will settle. Mandate-based authorization is currently untested in courts and before regulators. The next two to three years will produce the case law, scheme rules, and regulatory guidance that determine what mandates can and cannot authorize, and where liability sits when something goes wrong.
  • Mandates will get more sophisticated. Today’s mandates are relatively simple, covering spending caps, approved merchants, and time windows. The next generation will support more complex conditional logic, multi-step goal-based execution, and dynamic re-authorization. AP2’s mandate structure already illustrates the direction, with cart mandates, intent mandates, and payment mandates each capturing different layers of user authorization.
  • Know Your Agent (KYA) will become standard infrastructure. Traditional Know Your Customer (KYC) frameworks were designed to verify human account holders. Agentic payments require a parallel framework for verifying AI agents, linking them to the consumer or legal entity on whose behalf they act, and establishing what they’re authorized to do. The FIDO Alliance, card networks, and regulators are all working on this, and over time KYA verification will become as routine as KYC.
  • Use cases will expand beyond consumer purchasing and B2B procurement. Current live use cases focus on consumer checkout and supplier payments. Bill payments, investment management, tax operations, machine-to-machine micropayments,[DE1]  and treasury workflows are the logical next domains for mandate-based execution, particularly as the identity, audit trail, and dispute infrastructure develops further.
  • Agent-to-agent transactions will emerge as a distinct category. Today agents transact with merchants and PSPs. The next phase introduces agents transacting with other agents, with procurement agents negotiating with supplier agents and treasury agents transacting with banking agents. This will require its own protocol, identity, and settlement infrastructure.

How does ACI Worldwide support agentic payments?

The ACI Payments Orchestration Platform gives enterprises the infrastructure they need to operate as agentic payments mature. ACI’s fraud models are engineered to distinguish trustworthy agents from malicious bots; its orchestration layer handles agent-initiated transactions across payment rails, geographies, and channels; and its compliance and governance workflows are designed to keep pace with the regulatory and protocol changes the agentic payments era will continue to produce.

As agentic payment standards continue to evolve, ACI handles the integration work, ensuring agent-initiated payments move through existing payments, fraud, and settlement infrastructure securely and without disruption to broader payment operations.

Prepare for the future of AI-powered payments — schedule a consultation with our merchants team today.