Agentic payments: when software pays on your behalf

If a piece of software can hold your card details and buy something while you sleep, every rule in payments that assumes a human at the checkout has a gap in it. An agentic payment is one an AI agent initiates for a person within a mandate that person gave it earlier, and the money part is the smallest problem in it.

The hard parts are evidence and blame. Somebody has to prove afterwards what the person actually authorized, and somebody has to pay when the agent bought the wrong thing from the wrong seller.

A smartphone completes an unattended purchase beside the parcel it paid for.

What makes a payment agentic

Automation alone does not. A standing order and a card on file both pay without anyone pressing a button, and neither is agentic, because the amount, the payee and the timing were fixed when the human set them up. An agent is different in that it decides: it picks the product, the seller, the moment and sometimes the payment method, inside limits it was given.

The Bundesbank's monthly report of September 2026 describes exactly that capability, with AI agents able to plan, initiate and manage payments on their own within a given mandate, including the choice of payment method, timing and network without approval for each transaction. That shifts the question every payment rule answers first, which is who authorized this. Finance Loop covers the agents themselves in AI agents in finance.

The protocols being proposed

Three efforts are competing to be the plumbing, and they come from different directions. The Agent Payments Protocol, AP2, was published by Google in September 2025 as an open standard, and Descope's explanation of it records backing from more than 60 organizations across e-commerce and payment processing. The Agentic Commerce Protocol came out of OpenAI's checkout work inside ChatGPT. A third effort from Klarna opens a product catalog to agents.

They answer different questions. AP2 is about proving authorization and apportioning accountability, so it standardizes credentials. The commerce protocols are about getting a cart and a checkout in front of an agent, so they standardize the merchant interface. A merchant will likely have to support more than one, the way it supports several wallets today.

How a mandate is scoped for a machine

AP2 splits the consent into three signed credentials, and the split is the useful idea whatever protocol wins. An intent mandate is what the person signs in advance and carries the rules the agent must stay inside, such as buy tickets for this concert the moment they go on sale and do not exceed 200 dollars. A cart mandate is signed when the person is there and fixes the exact items and the exact price. A payment mandate goes to the network and tells the issuer whether a human was present.

Descope notes that the mandates build on the W3C Verifiable Credentials standard and that a cryptographic signature makes each one tamper-evident, so any modification invalidates it. The design also keeps the card credentials with a credential provider instead of handing them to the agent or the merchant, which is what keeps the agent out of PCI scope. Finance Loop covers that standard in PCI DSS 4.0.

Strong customer authentication with nobody there

This is the open regulatory question in Europe, and it has no settled answer. Freshfields puts the problem directly: authentication assumes a human enters a PIN, gives a biometric or answers a push notification, and an AI agent can do none of those in the conventional sense. The briefing adds the part that matters most, that none of the current rules explicitly contemplates authentication that a non-human initiates.

The candidate answers reuse mechanics that already exist. A time-limited token can attest that the person authenticated earlier when they signed the mandate, which treats the agent's purchase as a later leg of an authenticated session. Or the agent operates on credentials issued through an API to a registered agent identity. Both need a supervisor to accept them, which is why firms are asking for guidance instead of shipping. Finance Loop covers the rules as they stand in strong customer authentication and the coming revision in PSD3.

Liability when the agent pays the wrong payee

Nobody has decided, and the nearest precedent is unflattering for banks. Freshfields draws the analogy to authorized push payment scams, where the sending provider in the United Kingdom has to reimburse the consumer in most cases even when a third party caused the loss, with the cost shared equally between sending and receiving provider up to 85,000 pounds. Applied to agents, the briefing warns the aggregate exposure of payment providers could be large, because an agent authorizes at a speed and scale a person cannot.

The defense an agentic flow offers is the audit trail. A signed intent mandate shows what was permitted, a signed cart mandate shows what was approved, and together they distinguish a payment that exceeded its mandate from one the person asked for and later regretted. Which of those a reimbursement rule will excuse is the commercial question underneath the standards work. Finance Loop covers the scam side in APP fraud.

What supervisors have said so far

They are describing the mechanism before regulating it. The Bundesbank devoted an article in its September 2026 monthly report to how agentic payments work and what they mean for payment traffic, which puts the subject in the central bank's own analytical record. Its reading is that an agent can plan, initiate and manage a payment inside a mandate, and that this differs from existing automation because the agent decides from objectives and available information.

No European authority has issued binding guidance on agent-initiated authentication. Two existing frameworks will reach these flows regardless of whether anything new is written: the payment services rules on consent, authentication and unauthorized transactions, and the AI Act's obligations for the provider and deployer of the system making the decision. A firm building this is designing against two regimes that were drafted without each other in mind. Finance Loop covers the German field in AI in finance in Germany.

What a merchant has to change to sell to an agent

More than a checkout button. The product data has to be readable by a machine that never sees the page, with price, availability, variants and delivery terms in a structured feed instead of rendered HTML. The checkout has to accept a signed mandate as the authorization and return a result an agent can act on.

Then come the parts nobody budgets for. Fraud scoring has to tell an agent apart from a bot, which inverts a decade of blocking anything that is not a browser. Bot defenses have to let the good agents through on a verifiable identity, since a user agent string proves nothing. Returns and disputes need a process for a buyer who was software, and the record of which mandate authorized the purchase has to be kept as long as a dispute can arrive. Finance Loop covers the checkout side in e-commerce payments in Germany.

Which rails will agents actually use?

Cards first, because that is what the protocols were built around and what the dispute machinery already covers. Account-to-account transfer is the cheaper route and the harder one for an agent, since a transfer is final once sent and carries no chargeback to fall back on. Stablecoin settlement appears in agent demonstrations for the same reason it appears in machine-to-machine payments, namely that a small payment can clear without an account relationship, and it carries the same finality problem. Finance Loop covers the alternatives in account-to-account payments and stablecoin settlement.

Can an AI agent legally make a payment in Germany?

Yes, when the payment is authorized by the account holder and the agent acts as a tool for giving that authorization. German and European payment law attaches consent to the payer, not to the device or program that transmits it, so a mandate a person gave is the person's instruction. The unsettled parts are whether the authentication method satisfies the strong customer authentication rules, and who bears the loss when the agent acted outside its mandate. Both are answered today in the contract between the user, the agent's provider and the payment service provider.

Agentic payments and Finance Loop

Finance Loop is the meeting place where the payments track meets the AI work, and agent-initiated payment is the question that belongs to both at once. Finance Loop brings together the payment teams writing mandate and authentication logic, the engineers building the agents, and the legal and supervisory specialists deciding who carries a loss nobody has assigned yet.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.