Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

AI Agents Can Pay. Can They Prove They Had Permission?

Дата публикации: 03-08-2026 11:13:39

AI agents can make payments, but can they prove consent? Explore mandates, fraud controls, accountability and trust in the rise of agentic commerce.

Основное содержимое страницы с новостью.

Agentic commerce has moved quickly. A year ago, much of the discussion was theoretical. Now payment networks, banks, and technology platforms are building systems that allow AI agents to search, select, and pay for products on a customer’s behalf.

Getting an agent to complete a payment is only the first step. To scale, everyone involved needs to know who authorised it, what it was allowed to do, whether it stayed within those limits, and who is responsible when something goes wrong. Until those questions can be answered consistently, agentic commerce is likely to remain confined to familiar retailers and tightly defined use cases.

What Visa’s Move Changes

Visa’s Intelligent Commerce Connect is a significant development. It gives AI agents a route through established payment infrastructure and adds controls around tokenisation, authentication, identity, and spending.

An agent-led payment needs to look different from stolen credentials or automated fraud. Providers need to know that an authorised agent initiated it on a legitimate instruction.

Visa and other payment companies are building these classifications into their systems – but they will need to make sure that merchants, banks, providers, and regulators interpret them consistently. An authenticated agent may still buy the wrong product, at the wrong price, or in a market the customer did not approve. A transaction can be technically valid and still fall outside what the customer intended.

The customer’s instruction, therefore, needs to be as clear and portable as the payment credential itself.

The Missing Layer is a Verifiable Payment Mandate

Every agent-led payment needs to answer two questions: is the transaction financially valid, and was the agent allowed to make it?

Payment systems are already good at answering the first. They can check credentials, balances, authentication signals, and risk. The second question has not yet been solved.

A customer might ask an agent to find the cheapest direct flight to New York, reorder household essentials, or pay an invoice below a set amount. Each instruction has limits, even when they are not expressed in technical terms.

Those limits need to become a mandate that systems can read and the parties involved can verify. It could cover spending, approved merchants, product categories, currencies, markets, time periods, and when human approval is required. It must also be possible to pause or withdraw the agent’s authority quickly.

This cannot be reduced to a consent box shown when a customer first activates the service. Permissions must remain visible and changeable.

A customer may allow an agent to spend £500 on flights without giving it open-ended access to their payment details. They may also block overseas purchases or require approval before a subscription is created. Those settings give the parties involved the context to assess the transaction properly.

Fraud Controls Need to Understand Intent

Fraud systems are designed to spot unusual behaviour, but unusual does not always mean fraudulent.

An agent making several purchases in a short period could be carrying out a legitimate procurement task. It could also have been compromised or moved beyond the authority it was given. A valid payment credential will not tell you which is true.

Fraud controls will need to assess the agent’s identity, the customer’s instruction, and the circumstances of the purchase together. Without that context, providers may block legitimate activity or treat abnormal behaviour as acceptable simply because the agent has already been authenticated.

The mandate should therefore travel with the transaction in a form that relevant participants can interpret. It should show what the agent was asked to do, what limits applied, and whether any required approval was obtained. That record would also be essential if the transaction were later disputed.

Accountability Cannot Be Worked Out Afterwards

When a normal card payment goes wrong, consumers generally know where to begin. They contact the merchant, their bank, or the payment provider and follow an established dispute process. Agentic payments add another party to the chain.

If an agent buys the wrong product, misunderstands an instruction, chooses a fraudulent merchant, or acts outside its limits, responsibility may sit with the agent provider, the merchant, the payment provider, the customer, or more than one of them.

The industry needs to settle those questions before disputes become common. Each transaction should record who issued the instruction, which agent acted, what permissions applied, and where responsibility passed between parties. Authorised participants need enough evidence to resolve fraud, settlement, and consumer-protection questions without exposing the customer’s private data more widely.

What Consumer Trust Actually Requires

Consumers do not need to understand every model, protocol, or payment layer.  But, they do need to know what the agent can do.

They should be able to see its permissions, approve higher-risk purchases, review what it has bought, and stop it immediately. They also need a straightforward route to redress when the outcome is wrong.

The questions consumers will ask are simple: what did I authorise, what did the agent do, can I reverse it, and who will put it right?

A polished demonstration will not answer those questions. Trust will come from fraud controls, authentication, refunds, disputes, and clear responsibility. These protections let consumers use cards without understanding the infrastructure beneath them. Agentic commerce needs the same confidence, with more precise controls over delegated authority.

There is also a competition issue. Consumers may be willing to let an agent shop with a major retailer while remaining wary of an unfamiliar merchant. Unless smaller businesses can be made verifiably safe within agent-led transactions, the technology could strengthen the position of the largest platforms rather than open the market.

The aim should be to make unfamiliar merchants easier to assess, not merely easier to reach.

Cross-Border Payments Will Be the Real Test

We have started to see that agents can reach checkout in familiar, domestic transactions. Cross-border payments will show whether the wider system can cope with more complicated transactions.

Cross-border commerce introduces complexity via different currencies, payment methods, fraud expectations, consumer-protection rules, and settlement arrangements. The customer’s instruction must remain clear as the payment moves between them. An agent authorised to make a domestic purchase may not have permission to accept conversion charges, use another payment method, or transact under another jurisdiction’s rules. Those decisions should not be left to assumption.

Anyone working in cross-border payments already sees how differently transactions are routed, screened, authenticated, and settled between markets. Agents will move across that fragmentation quickly and with less direct human scrutiny. That makes automation more useful, but also raises the cost of a poorly defined instruction.

The agent must be able to judge whether the payment method, currency, jurisdiction, and commercial terms remain within the authority it was given. Cross-border transactions will show whether agentic payments have become dependable infrastructure or remain a collection of controlled integrations.

B2B May Provide the First Repeatable Model

Consumer shopping is the most visible form of agentic commerce, but B2B procurement may be an earlier proving ground.

Business purchasing already uses approved suppliers, fixed budgets, documented policies, and established approval chains. An agent might reorder below a set value, pay an invoice that matches a purchase order, or seek approval when costs fall outside agreed terms. Procurement systems remain fragmented, but these clearer boundaries make authority easier to define and offer a practical setting in which the model can be tested.

Bounded Autonomy, Not Maximum Autonomy

Visa’s announcement will be one of many as agentic payments enter wider commercial use. The companies that succeed will be those that can prove the authority and context behind each transaction and deal clearly with failures when they happen.

The immediate priority should be making delegated authority portable, transactions auditable, and redress straightforward. Consumers will trust agents when they can act independently without crossing boundaries that people can set, understand, and enforce. Greater autonomy will follow.

Wolf Ruzicka, Chief Commercial Officer at Unlimit.

Wolf Ruzicka is Chief Commercial Officer and CEO, North America at Unlimit, where he leads global commercial strategy and helps clients unlock growth through AI-driven solutions. A technology executive with more than 25 years’ experience, he has built and scaled businesses, led successful acquisitions and advised organisations including Microsoft, Mercedes-Benz and Lufthansa. He is also an entrepreneur, investor, board adviser, technology mentor and author of AI Driven.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Silicon AI For Your Business Podcast: Autonomous Money: Are We Ready to Let AI Spend for Us?06.3215-06-2026
2United States: Legal Accountability for AI Agents01001-07-2026
3 AI Agents Need Their Own IDs; How Should Companies Manage AI Agent Identities and Access? 07.8329-09-2026
4AI Agents Teamed Up to Cheat at Blackjack. Their Collusion Is Getting Harder to Spot014.2223-09-2026
5Trump’s AI Accord: Can Voluntary Self-Regulation and Independent Audits Protect Against Frontier AI Risks?015.2606-10-2026
6Autonomous AI Agents: Architecture and Risk Mitigation06.9410-09-2026
7Silicon In Focus Podcast: AI Agents Enter the Enterprise: From Chatbots to Autonomous Digital Workers06.3103-08-2026
8Understanding Agentic AI: A Deep Dive into Autonomous AI Agents07.7103-08-2026
9Agentizing Privacy Preferences without Privatizing Data Protection Policy07.7204-06-2026
10Could AI really take over the internet? Here's what experts say.07.228-09-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 5.74. Источник: www.silicon.co.uk.