The Big Picture
Agentic payments are payments in which an AI agent can act on behalf of a person or business – potentially choosing what to buy, when to buy it, from whom, and how to pay, within permissions and limits set by the user. The technology is moving beyond theory: payment networks, banks, and technology companies are already testing or running agentic transactions in real payment environments.
But the biggest change isn’t that AI can move money. It’s that we may start trusting AI to decide when our money should move.
Think about the last thing you bought online.
- You searched for it.
- You compared the options.
- You chose one.
- You clicked “BUY”.
- You authorized the payment.
- You were the decision-maker.
Now imagine saying:
“Find me the best flight to London next month. Keep it under $800, no more than one stop, and book it if you find one that fits.”
- The AI searches.
- It compares.
- It interprets your preferences.
- It chooses.
- And, if you’ve given it the authority, it pays.
You never clicked Buy.
Your AI did!
That sounds futuristic.
But parts of that future are already being built, and suddenly, the most interesting question about AI and money isn’t: “Can AI make a payment?”
BUT
“How much of my financial decision-making am I willing to give it?”
By the End of This Article, You’ll Know:
- What are agentic payments?
- How are agentic payments different from normal digital payments?
- Can AI agents already make real payments?
- How does an AI agent get permission to spend money?
- Would people actually trust AI with their payments?
- What happens when AI makes a decision you didn’t expect?
- Why are Visa, Mastercard, Google, banks, and fintech companies building agentic-payment infrastructure?
- Could AI agents change who controls the customer relationship in commerce?
And perhaps the most uncomfortable question:
Would you let an AI buy something for you without asking first?
1. Agentic Payments Aren’t Just Automated Payments

“Agentic payments” sounds like something designed for a conference room.
The idea is actually pretty simple.
Think about three ways a payment can happen.
1. You make the decision
- You find a product.
- You choose it.
- You click Buy.
- You authorize the payment.
- You are in control.
2. Software follows a rule
You set up a monthly subscription. Every month, the system charges you automatically.
The decision was made in advance.
3. An AI agent makes a decision
You tell it:
“Keep my office stocked with printer paper. Don’t spend more than $100 per order.”
The AI could check inventory, compare suppliers, consider price and delivery time, choose a supplier, and place the order.
The decision is made at the time of the transaction.
That last part is what makes it different.
McKinsey’s 2026 Global Payments Report draws a useful line between ordinary automation and genuinely agentic payments: traditional automated payments execute decisions that were fixed in advance, while an agentic transaction can involve an agent selecting important parameters – such as the counterparty, amount, or timing – at runtime.
Federal Reserve Governor Christopher Waller offers an equally useful distinction.
He describes agent-assisted commerce, where the consumer remains in control, and agent-delegated commerce, where the consumer gives an AI agent authority to shop and make payments on their behalf.
So, the progression looks something like:
AI recommends → AI assists → AI acts → AI pays.
And that leads to the most important idea in this article: The important change isn’t automation. It’s delegation. You are delegating part of a financial decision to software.
2. From “Click Buy” to “Let AI Handle It”
Let’s make this less technical; suppose you’re going to Dubai.
You ask an AI:
“Find me a good hotel under $200.”
It searches and recommends three.
You choose one and book it; that’s AI-assisted shopping.
Now change the instruction:
“Find the best hotel under $200, within two miles of downtown, with free cancellation. Book it if you find one that fits.”
Now the AI has a job to complete.
It has to search, compare, interpret your preferences, check availability, and choose among alternatives.
If you have authorized it to do so, it can then complete the purchase.
That’s much closer to agentic commerce.
And the payment is where the story changes.
Because recommending a $200 hotel is one thing.
Spending $200 on your behalf is another.
This is why agentic payments are really about authority.
At what point does an assistant stop being an assistant and become a financial decision-maker?
The Federal Reserve is already asking versions of that question, including what standards agents need for identity, consent, and payment credentials, and how much friction should remain when an agent is authorized to transact.
The old payment question was:
“Did the customer authorize this transaction?”
The emerging question is more complicated:
“Did the agent correctly understand what the customer authorized?”
That difference may define the next era of digital payments.
3. This Isn’t Science Fiction: AI Agents Are Already Making Real Payments
Here’s the part that may surprise you.
Agentic payments have already moved into real payment environments.
In March 2026, Santander and Mastercard announced a live end-to-end payment executed by an AI agent within a regulated banking framework. The transaction used Mastercard Agent Pay and Santander’s live payment infrastructure, with predefined limits and permissions. It was conducted in a controlled environment rather than launched as unrestricted consumer banking.
Then, in June, Worldline, ING and Mastercard announced Europe’s first end-to-end agentic payment transaction in production. In that case, an AI agent helped select a purchase and completed the transaction after the consumer gave explicit approval.
That distinction is important.
AI is already entering payment rails – but mass autonomous spending is not here yet.
Visa’s research has also found AI agents beginning to book travel, reorder inventory, query data services, and purchase computing resources.
Google is building standards around the problem.
Its Agent Payments Protocol (AP2) was donated to the FIDO Alliance in April 2026, and its updated specification introduced “Human Not Present” transactions, allowing an agent to execute certain payments autonomously based on pre-authorized instructions. Google also highlighted Verifiable Intent, designed to create an auditable record of what a user authorized an agent to do.
Stripe is building another piece of the infrastructure.
Its Shared Payment Tokens allow agents to initiate payments with customer permission without exposing the underlying payment credentials.
And Mastercard is thinking even further ahead.
Its Agent Pay for Machines initiative is designed for AI agents and machines to transact continuously, including payments worth fractions of a cent. The idea is that software could eventually pay other software for services such as data, computing, APIs, or digital resources.
Mastercard’s Chief AI and Data Officer Greg Ulrich has described an even more radical possibility:
“AI agents may even outnumber people.”
That sounds extreme.
But consider what it means.
If software agents become participants in the economy, they don’t just need intelligence.
They need money-moving infrastructure.
4. What Happens When AI Gets Permission to Spend Your Money?

This is where the technology gets personal.
Giving an AI permission to pay doesn’t necessarily mean handing it your credit-card number.
Modern agentic-payment systems are increasingly being designed around:
identity + authorization + limits + tokenization + monitoring.
Imagine telling your AI:
“Buy this for me. Don’t spend more than $50.”
The payment system could potentially issue the agent a restricted credential rather than exposing your underlying card details.
Stripe’s Shared Payment Tokens are designed around precisely this concept: agents can initiate payments using customer-approved methods without exposing the underlying payment credentials.
Visa is also building agentic payment infrastructure around tokenization, controls, and trusted agent identity.
Google’s AP2 takes another approach to the same fundamental problem: How do we prove what the human actually authorized?
A simple way to understand the architecture is:
Intent → Authorization → Payment
Intent
What do you want?
“Find me the cheapest reasonable flight to London.”
Authorization
What is the agent allowed to do?
Maximum $800.
Economy class.
One checked bag.
No overnight layover.
Payment
The agent makes its decision, and the payment system executes the transaction within those boundaries.
Sounds straightforward.
Until you ask:
What does “cheapest reasonable flight” mean?
The cheapest ticket?
The cheapest ticket including baggage?
The shortest journey?
The best combination of price and convenience?
What if the AI chooses a $720 flight that arrives at 2 a.m., while you would happily have paid $760 for the flight arriving at 6 p.m.?
The AI may not have made a technical mistake.
It may have followed your instruction exactly.
You simply didn’t realize how much information was missing from your instruction.
That is a much deeper problem than “AI sometimes makes mistakes.”
It is the problem of human intent versus machine interpretation.
And that is why the IMF and Federal Reserve have emphasized the tension between adaptive, probabilistic AI systems and payment systems that require precise authorization and finality.
5. Would You Actually Trust AI With Your Wallet?

Now forget the technology for a moment.
Imagine someone tells you:
“This AI is really good at finding cheap flights.”
You might happily use it.
Now they tell you:
“It can also spend $2,000 of your money without asking you.”
Suddenly, the conversation changes.
That’s the trust gap.
Visa’s 2026 Trust Index found that only 23% of U.S. consumers surveyed said they trusted generative AI to handle payment transactions on their behalf.
But when Visa was named as the company handling the AI-powered transaction, that figure rose to 61%. The survey was conducted for Visa by Harris Poll among U.S. consumers.
That tells us something important.
People may be increasingly comfortable using AI.
They are not automatically comfortable giving AI financial authority.
Visa’s Chief Product and Strategy Officer Jack Forestell put the issue bluntly:
“The challenge is making agentic commerce secure, permissioned, and reliable enough to scale.”
Mastercard’s Chief Digital Officer Pablo Fourez frames the same problem even more directly:
“When AI starts buying for you, trust becomes the product.”
That may be one of the most important lines in the entire agentic-payments story.
Because consumers will want answers to very ordinary questions:
- How much can my AI spend?
- Can I set a daily or transaction limit?
- Can I block certain merchants?
- Can I require approval above $100?
- Can I revoke permission immediately?
- Will I receive a notification?
- Can I see why the AI chose something?
- What happens if it gets hacked?
- Who pays if it makes a mistake?
Convenience gets people interested.
Control gets them comfortable.
6. What If AI Follows Your Instructions – And You Still Regret the Purchase?

Here’s the more interesting problem.
Imagine you tell your AI: “Book me the cheapest flight to London”, It finds one.
It saves you $150, but the flight leaves from an airport two hours away. It has a 17-hour journey and the ticket is non-refundable, you arrive at 2 a.m.
Did the AI make a mistake?
Maybe not.
It may have done exactly what you asked, the problem was that what you said wasn’t everything you meant.
This is where agentic payments become fundamentally different from ordinary automation.
A recurring payment doesn’t need to understand you.
It simply follows the rule.
An AI agent has to interpret you.
And interpretation creates ambiguity.
Mastercard’s Verifiable Intent initiative was created around this exact problem. Its Chief Digital Officer Pablo Fourez asks:
“How do we know an agent is doing exactly what we asked – and nothing more?”
That question becomes critical once real money is involved.
And then there is the security problem.
An AI shopping agent could encounter:
- fraudulent merchants,
- misleading product information,
- fake discounts,
- manipulated reviews,
- malicious websites,
- prompt injection,
- compromised credentials,
- instructions designed to alter the agent’s behavior.
Today’s fraudster may try to trick you.
Tomorrow’s fraudster may try to trick your agent.
That changes the security battlefield.
It also creates a difficult liability question:
If the AI technically followed its mandate but misunderstood your intent, who is responsible?
- The consumer?
- The AI provider?
- The merchant?
- The bank?
- The payment network?
The answer will depend on the circumstances, contracts, and regulation – and the industry is still working out the rules.
That’s why Waller says the agentic-payments ecosystem needs to balance innovation with the safety, integrity, and stability that underpin trust in payments.
7. Why Are Visa, Mastercard, Google and Banks Racing Into Agentic Payments?

Because this isn’t just a new way to pay.
It could change who controls commerce.
Today, the journey usually looks like:
You → Search → Website → Product → Checkout → Payment
An agentic journey could look more like:
You → AI Agent → Product → Payment
- The AI may discover the product.
- The AI may compare it.
- The AI may choose the merchant.
- The AI may choose the payment method.
- And the AI may initiate the transaction.
That means the AI agent could become the new front door to commerce.
And payment companies clearly see the stakes.
Visa describes agentic commerce as potentially the biggest shift it has seen in payment technology in more than two decades. Its Chief Product and Strategy Officer Jack Forestell wrote that the “agentic web” could be the most important shift in payment technology since the early days of digital commerce.
Mastercard is building Agent Pay, trusted-agent frameworks, and machine-to-machine payment capabilities.
Google is developing open protocols for agent-led payments.
Stripe is building payment primitives that let agents transact without exposing underlying payment credentials.
Banks and payment processors are already testing live transactions.
And McKinsey’s 2026 Global Payments Report suggests the economic stakes could be substantial.
Its baseline scenario estimates that agentic AI could put roughly $75 billion of global payments revenue at risk by 2030, while an aggressive adoption scenario could push that exposure to about $160 billion. McKinsey also estimates up to $110 billion in annual operational productivity opportunity from generative and agentic AI.
But there’s an important catch.
The $75 billion is not the size of the agentic-payments market.
It is an estimate of existing payments revenue that could be exposed to changing economics.
And that’s arguably more interesting.
Because if an AI agent constantly compares merchants, payment methods, fees, rewards, and financial products, it could change where value flows through the payment’s ecosystem.
McKinsey describes this as a shift away from the visible checkout interface toward a deeper “control layer” involving machine identity, consent, dynamic routing, and policy guardrails.
That leads to a much bigger business question:
If AI chooses what you buy, which company actually owns the customer relationship?
- The merchant?
- The bank?
- The card network?
- The payment processor?
- The AI platform?
- Or whoever controls the agent?
That could be the real battle behind agentic commerce.
So, Should You Let AI Spend Your Money?
There is no universal answer yet.
And that’s precisely why this technology is so interesting.
The pieces are already appearing:
- AI can search.
- AI can compare.
- AI can make decisions.
- AI can initiate transactions.
- Payment systems can restrict and authenticate those transactions.
- Real agentic payments have already been demonstrated.
But widespread consumer adoption depends on something harder than technical capability:
Trust!
The industry knows it.
Visa’s research says trust is a key barrier.
Mastercard is building frameworks around identity, intent, controls, trusted execution and intelligence.
The Federal Reserve is examining the implications for payment systems and authorization.
And businesses are already preparing.
PayPal’s 2026 Agentic Commerce Pulse Report, based on research involving 498 U.S. merchants, found that 52% of large enterprises said they had integrated AI tools into regular operations, while 95% of large enterprises expected payment providers to play a leading or supportive role in agentic commerce. PayPal also identified data security as the top investment barrier. These are survey findings, not a measure of the entire economy.
So, the likely path isn’t:
- AI suddenly takes over your bank account.
- It’s much more gradual.
- First, AI helps you find something.
- Then it helps you compare it.
- Then it helps you choose it.
- Then it asks permission to buy it.
- Then, for certain purchases, you might simply tell it: “Handle it.”
That last step is the real transformation.
Because your AI is no longer merely helping you shop.
It has become a delegated financial actor.
The Bigger Question: Who Becomes Your Financial Gatekeeper?
The first internet changed where we shop.
Mobile changed how we shop.
Agentic AI could change who does the shopping.
And once the shopper is software, the payment system has to answer a fundamentally different question:
How much financial authority are we willing to give a machine?
The future could eventually look like:
You → Your AI Agent → Merchant → Payment
And, for machine-to-machine services:
AI Agent → Another AI Agent → Service → Payment
Mastercard is already building infrastructure for this second possibility, including machine-to-machine transactions and micropayments.
Imagine an AI running a small business.
- It notices inventory is low.
- It searches for suppliers.
- It compares prices.
- It negotiates.
- It checks the company’s budget.
- It places the order.
- It pays.
- It schedules delivery.
- It records the expense.
No human touches the transaction.
That isn’t simply a better checkout.
It’s a different economic architecture, and that’s why agentic payments deserve attention.
The real revolution may not be that AI can move money; it may be that we start trusting AI to decide when money should move.
So perhaps the most important question isn’t:
“Can AI spend my money?”
It increasingly can.
The better question is:
“How much authority should AI have over my money?”
Because once the answer changes, the way we shop – and the way money moves through the economy – could change with it.
Final Thought
Imagine someone asking you a few years from now:
“Why are you still choosing the product and clicking Buy yourself?”
It might sound as strange as manually typing a card number today but there’s an important difference.
- When AI writes your email, a bad sentence is annoying.
- When AI chooses your purchase, real money moves.
That is why agentic payments could become one of the most consequential – and controversial – parts of the AI revolution.
The future of payments may not simply be about making checkout faster; it may be about making checkout disappear, and when that happens, the biggest question won’t be whether AI can pay.
It will be whether we trust it enough to decide when we should.
Frequently Asked Questions
What are agentic payments?
Agentic payments are transactions in which an AI agent can act on behalf of a person or business to make payment-related decisions and potentially complete transactions within permissions, limits, or instructions set by the user or organization.
How are agentic payments different from normal digital payments?
In a normal digital payment, the person usually chooses what to buy and authorizes the transaction. In an agentic payment, an AI agent can make some purchasing decisions and potentially execute the transaction on the user’s behalf.
What is the difference between agentic payments and automated payments?
Automated payments usually follow rules established in advance, such as a recurring subscription. Agentic payments involve an AI agent making dynamic decisions at runtime within boundaries set by the user.
Can AI agents make real payments today?
Yes. Controlled and production agentic-payment transactions have already been demonstrated by companies including Santander, Mastercard, Worldline and ING. However, widespread autonomous consumer payments remain at an early stage.
Can an AI agent access my credit-card number?
It does not necessarily need to. Agentic-payment systems can use tokenized or permissioned credentials so an agent can initiate a payment without receiving the underlying card credentials.
Is it safe to let an AI agent spend money?
Safety depends on the controls around the agent. Spending limits, tokenization, authentication, monitoring, identity verification and revocable permissions can reduce risk, but fraud, manipulation, cybersecurity attacks and incorrect decisions remain important concerns.
What happens if an AI agent makes a payment mistake?
Responsibility can depend on what the user authorized, how the agent behaved, the merchant’s role, the payment provider and applicable laws or contracts. Clear liability and dispute frameworks are still developing as agentic payments expand.
What is agentic commerce?
Agentic commerce is commerce in which AI agents can discover products, compare options, make purchasing decisions and potentially complete transactions on behalf of users or businesses.
What is Google’s Agent Payments Protocol?
Google’s Agent Payments Protocol, or AP2, is an open protocol designed to help AI agents conduct secure payments. Google donated AP2 to the FIDO Alliance in 2026 and introduced support for autonomous “Human Not Present” payments based on pre-authorized instructions.
What are Visa and Mastercard doing with agentic payments?
Visa is developing Intelligent Commerce and other infrastructure for agent-led transactions, including tokenization and trusted-agent capabilities. Mastercard is developing Agent Pay, agent trust frameworks and machine-to-machine payment capabilities.
Will AI agents replace traditional payment systems?
Probably not in the near term. A more likely outcome is that AI agents become a new decision-making layer above existing banks, payment networks, wallets and settlement infrastructure.
Will AI agents eventually buy things without asking me?
They may, for transactions covered by permissions you have already granted. Google’s AP2 framework, for example, explicitly supports certain autonomous transactions based on pre-authorized instructions. But widespread adoption will depend on consumer trust, security, regulation, liability and how much financial authority people are willing to delegate.






