4 Sources
[1]
Regulating payments when it's AI agents spending the money
The future of trusted transactions will depend on understanding intent, authority and context alongside established rigorous identity checks. A small business owner asks an AI assistant to manage a simple task: review outstanding invoices, check which suppliers need to be paid, and prepare the next set of payments. The assistant scans emails, compares due dates, and prepares recommendations for approval. For the business owner, this could remove hours of repetitive work. But for the financial institution processing those payments, it changes the nature of trust. A payment may still come from a legitimate account, but the decision behind it may have been shaped, prepared or initiated by software acting on someone's behalf. This creates a significant challenge for financial services. It's no longer enough to simply understand who or what is behind a transaction; institutions now need to be able to discern whether the action reflects genuine human or business intent. This challenge becomes particularly important in payments. The International Monetary Fund has described agentic AI as a development that could move payments from human-initiated instructions towards agent-mediated decisions. Payments are not just another automated workflow. When money moves, the consequences are immediate and can be difficult to reverse. Financial systems have long been built around the assumption that a payment instruction can be linked to a person, business or institution with clear authority to act. Agentic AI complicates that assumption by adding another layer between the human and the transaction. This does not mean AI agents should be kept away from financial activity. Used carefully, they could help people and businesses manage routine financial tasks with less friction. But the more useful these systems become, the more important it will be to define the conditions under which they can act. The question is not whether AI agents should be used in finance, but how institutions can support their use without weakening accountability. In 2026, Santander and Mastercard demonstrated Europe's first live payment executed by an AI agent within a regulated banking environment. The transaction was completed using pre-authorised customer permissions, tokenized credentials and existing banking controls, illustrating that autonomous agents can operate within established regulatory and security frameworks rather than outside them. Similar initiatives announced by BBVA with Visa and Nordea with Mastercard suggest that financial institutions are increasingly exploring how AI agents can act on behalf of customers while maintaining the governance, authentication and auditability expected of regulated financial services. An agent that can act quickly across several systems can also make mistakes quickly. It may be able to be manipulated through false information, compromised instructions or fraudulent requests that appear legitimate. In a payments environment, the difference between helpful automation and harmful activity may come down to whether institutions can understand intent, authority and context before money moves. Today, many financial controls focus on identity. Who is the customer? Is the account legitimate? Does the transaction match expected behaviour? These questions will remain essential, but they may no longer be enough. If an AI agent is acting on behalf of a person or business, institutions will also need to understand whether the action reflects a genuine instruction, whether it sits within the agent's permitted role and whether there is enough evidence to explain why the transaction happened. This is where trust in agentic finance will need to be designed carefully. Stronger authentication will matter, but so will clearer audit trails. Financial institutions will need to know when an AI agent was involved, what it was authorized to do and whether its action can be traced back to a legitimate human or business decision. Explainability will also become more important. If a transaction is blocked, delayed or flagged for review, customers and compliance teams need to understand why. If a suspicious transaction is approved, institutions need to understand what signals were missed. Black-box decision-making is uncomfortable in any regulated environment, but in financial services, where decisions can affect people's access to money, markets and essential services, it becomes a direct trust issue. There is also a human dimension inside financial institutions. Compliance and fraud teams are already working under pressure from faster payments, rising alert volumes, and more sophisticated criminal behaviour. Agentic AI could help them identify patterns, summarise cases and prioritize risk. But it should support human judgement, rather than replace it. Regulation is evolving alongside these technological advances. In the UK, the Competition and Markets Authority has published guidance making clear that organizations remain accountable for the actions of AI agents acting on their behalf. Across Europe, the EU AI Act reinforces requirements around transparency, human oversight, governance and record-keeping for higher-risk AI systems. Together, these developments point towards an emerging model of autonomous compliance, where AI agents are expected to operate within robust governance and audit frameworks. The World Economic Forum's AI Playbook for Financial Services argues that trust, governance and human oversight are becoming critical tests as financial institutions move from experimentation to scaled AI adoption. Agentic AI will make those tests more demanding. It will require institutions to define where autonomy is acceptable, where human approval is still needed and how responsibility is recorded when software acts on someone's behalf. The future of trusted transactions will not depend only on knowing who someone is. It will also depend on understanding what they intended, what their AI agent was allowed to do and whether the action can be explained after the event. As AI agents become more involved in economic activity, financial trust will need to evolve with them. The task ahead is not to slow down progress, but to make sure that as AI begins to act, the financial system can still answer one of its most important questions: should this transaction be trusted?
[2]
AI Agents Need Rules Before They Can Run Payments | PYMNTS.com
Moving from manual work and processes to copilots and then to agents means a sea change in how work gets done. Now businesses can assign real responsibility to systems that can execute tasks, make decisions and operate across enterprise workflows. The promise is powerful, but the risk is real. For most companies, the challenge is no longer whether to adopt artificial intelligence (AI), but how to do so without losing control of key workflows, key decisions and creating additional risk on the whole business. In finance, that tension is especially clear. AI has already proven its value in analysis, forecasting and reporting. But the real opportunity sits in processes like collections, payment screening and workflow, cash application and risk management. These are the workflows that directly impact cash flow, working capital and managing financial risk. They are also the areas where autonomy is hardest to scale, because the cost of errors is so high. What separates early experimentation from an agentic enterprise is governance. Assigning work to agents and agentic workflows requires clear rules, defined decision rights and full visibility into how and why actions are taken. Without that, AI becomes another layer of risk rather than a source of value. This is where many organizations are learning that autonomy and agentic AI is harder to implement than expected. This is less because the models are insufficient -- though they are improving all the time -- but because enterprise systems, data, and controls were not built to support the shift to AI. The path forward, then, is controlled autonomy rather than full autonomy. Leading organizations are embedding AI directly into workflows, rather than layering the technology on top of core processes. In this model, agents do not operate independently, but within defined processes that are guided by policies, thresholds and approvals set by the business. Every action is traceable, auditable and aligned to financial controls. This shifts AI from an insight-delivering tool to something that can effectively execute the work that must be done. In this scenario, AI can impact the metrics that matter. We see this progression clearly through the CFO AI Maturity Model. Most organizations start with assistive AI, where technology helps individuals complete tasks more efficiently. From there, workflows become more automated but still require human intervention at key points. The next phase introduces agentic execution, where systems can resolve exceptions, take actions and operate within defined guardrails. Ultimately, the goal is outcome-driven finance, where AI continuously optimizes key metrics like cash flow, risk exposure and operational efficiency. At each stage, the role of the human employee changes. The focus shifts from doing the day-to-day work to defining the rules, monitoring outcomes and controlling performance. Finance functions should think of this as elevating the roles employees play, rather than removing people from the process. The companies making progress are not chasing autonomy for its own sake, to check a box or to send out a splashy press release. These businesses are redesigning workflows starting with high-value use cases and scaling incrementally. They are connecting data across systems, embedding AI where decisions are made, and ensuring that governance is built into workflows from the start. The agentic enterprise will not be defined by how much work AI can get done. Instead, it will be defined by how much confidence organizations can place in AI to achieve desired outcomes without increasing risk.
[3]
Agentic Payments Start With the Right Foundation | PYMNTS.com
As artificial intelligence moves from copilots to agents, the opportunity to evolve how businesses function is becoming more practical and immediate. Enterprises are starting to apply AI to real workflows where speed, accuracy and consistency matter. The bigger question is not simply what AI can do, it is what business foundation AI is being built upon. AI agents have begun to autonomously execute defined work across systems and decision points. But in enterprises, agents do not become valuable in isolation. They become valuable when connected to trusted data, strong technology, established workflows and clear governance. At Boost, we do not view AI as something being applied to a blank slate. We view it as an accelerator of foundational capabilities that already exist: years of proprietary payments data, deep B2B payments expertise, established customer and partner relationships and a best-in-class technology platform built around complex enterprise payment workflows. That foundation is what makes AI more powerful. Agentic AI grounded in proprietary data and domain knowledge can help validate information, flag exceptions and support better decisions. In the payments industry, that context is critical. Understanding how enterprise buyers, suppliers, issuers and processors interact is not something that can be recreated through generic automation alone. Our business is already seeing this transition take shape. AI is being applied in areas such as payments processing, quality control, product design and development, client onboarding and customer service, where agents can help reduce manual effort and improve operational consistency. More importantly, agents will help us build more intelligent customer-facing solutions and experiences over time. But agentic AI also requires discipline. Thoughtful design and planning are necessary ingredients to properly build an agentic enterprise. In payments, speed only matters if accuracy, control and trust are preserved. There is very little room for ambiguity and no room for error. That is why the future of enterprise AI cannot be unrestricted autonomy. It has to include intelligent orchestration. In practice, AI can automate frontline processing, with another AI-enabled layer established to validate the output. Human quality control can remain in place to address issues that require judgment. The goal is not to remove people from the process, but to give them better systems, deeper insight and more technical leverage. This is where many companies will find that autonomy is harder to scale than expected. The challenge is not always the model itself, but instead the enterprise context around the model. AI needs reliable data, mature workflows and business rules that reflect how the company operates. The agentic enterprise will be defined by companies that combine AI with proprietary assets, operational expertise and disciplined governance to generate business outcomes that could not be achieved by humans alone. For customers, the impact should be tangible: faster support, smoother onboarding, stronger knowledge access, more engaging solutions and payment experiences that feel less fragmented. AI will not replace the foundation of a strong enterprise; it will amplify it. The companies best positioned for the agentic future are the ones starting with something unique to build upon.
[4]
Thredd's McCarthy Says Payments Will Govern the Agentic Enterprise | PYMNTS.com
The interesting question about the agentic enterprise is not whether agents can act. They clearly can. It's whether enterprises can scale that action safely -- and the evidence so far is that autonomy is harder to scale than the demos suggest. The bottleneck is not intelligence. It's permission, control and proof. Businesses are putting policies and governance in place to safely scale generative AI across their enterprise. At Thredd, green shoots of innovation are sprouting daily, leveraging agentic capabilities for fraud, credit, sales, billing automation and client servicing. But we see the challenge, and equally the opportunity, for agentic experiences more acutely on the payment side, where an agent recommending a purchase, not all that interesting, becomes useful when it's trusted to initiate and complete a payment. At that moment the question stops being "can the agent pay?" and becomes "what is this agent permitted to do, on whose authority, under what limits, and how is that permission proven, monitored and revoked in the milliseconds an authorization takes?" That's a payments problem before it's an AI problem, and payments has a head start most people underestimate. At every technology inflection point during my career -- eCommerce, mobile commerce, the launch of Apple Pay, cryptocurrency -- someone predicted the end of cards, and yet each time the trust infrastructure proved far harder to replicate than the rails were to reinvent. Tokenization, scheme rules, dispute and chargeback rights, issuers that underwrite risk and bind consumers to credentials -- these aren't legacy baggage. They're the exact controls agentic commerce needs, and they already exist. But raw materials aren't readiness, and this is where the conversation gets too casual. A network token already carries merchant and category restrictions and can be revoked providing a real head start, not an answer on its own. The new work is binding a verifiable mandate to that credential which is essentially a cryptographic proof of what the consumer authorized their agent to do, and then surfacing, at authorization, a signal that an agent rather than a human initiated the transaction, so the issuer can decide in real time rather than discover it after the fact. Visa and Mastercard are standardizing this through Intelligent Commerce and Agent Pay respectively; we monitor and, in some cases, build those frameworks while staying deliberately neutral on the merchant-side protocols, so our clients, issuers and program managers, are insulated from bets that haven't been resolved. It's also why a connection standard, on its own, doesn't solve this. Protocols like MCP matter because they standardize how agents plug into systems. They don't answer who authorized this agent, what the consumer actually intended, whether the behavior is anomalous or who is liable when it's disputed. Those are issuer-layer questions, and they don't get easier by stacking another protocol on top of them. Liability is the one the industry hasn't fully answered, and the one I'd tell any enterprise to watch. Fraud detection is being retuned for a new class of automated behavior. The old question was, "is this the genuine customer?" The emerging one is, "is this still what the customer authorized the agent to do?" That's necessary but not sufficient. The harder case is the agent that behaves exactly as mandated and the cardholder disputes anyway. Today's chargeback rules were never written for a third party acting on standing instructions. My view is that verifiable intent, proven at authorization, must become the basis for reallocating that liability -- and the issuers who can prove intent will be the ones who can actually underwrite agentic commerce, not merely permit it. For a card issuer, the point of sale is the tip of the agentic iceberg. Strip away the consumer experience and the work of card issuing is repetitive, rules-based, operational work. Things like reconciling settlement files, onboarding and screening customers, assembling dispute evidence, servicing cardholders and producing regulatory reports represent high-headcount work that has scaled almost linearly with volume. That's exactly the shape of tasks agents are good at, and where costs can actually be stripped out of businesses: an agent that reconciles a file and escalates only the genuine inconsistencies, or triages an onboarding case, breaks the link between growth and headcount that has constrained this industry for years. Programmable payments extend the same logic to money movement itself where value that moves on conditions and rules set in line with the transaction rather than preset instructions configured at the program level, with an agent orchestrating inside guardrails set by the customer. An agent reconciling a ledger, or releasing a payment on a rule, needs exactly what an agent at checkout needs: defined permission, proof of what it was authorized to do, an audit trail and the ability to revoke it the moment something looks wrong. Solve that governance problem once and you apply it across the operation; that's the compounding advantage, and why the trust layer is worth owning. It's also where discipline matters most, because the back office is where autonomy is easiest to justify and hardest to trust. A silent reconciliation error doesn't announce itself, it compounds. Those who capture these savings will be the ones who put escalation thresholds, manual review thresholds and provable authority in place first -- taking cost out rather than trading labor cost for risk. The agentic enterprise won't be defined by how much autonomy it hands to AI, but by how well it governs that autonomy where liability shifts and value is created. The winners won't just have smarter agents. They'll have agent-ready infrastructure beneath them, verifiable intent underwriting it, and partners willing to absorb that complexity so they can move quickly.
Share
Copy Link
AI agents are moving from copilots to autonomous executors in payments, but financial institutions face critical challenges around trust, authentication and liability. Early implementations by Santander and Mastercard demonstrate feasibility, yet experts warn that governance frameworks must precede widespread adoption to prevent fraud and maintain accountability.

AI agents are shifting from assistive tools to autonomous executors capable of managing payments without constant human oversight. Financial institutions now face a fundamental question: how to enable AI agents executing financial transactions while maintaining the trust infrastructure that underpins global commerce
1
. The International Monetary Fund describes agentic AI as moving payments from human-initiated instructions toward agent-mediated decisions, fundamentally changing how financial institutions verify authority and intent1
.In 2026, Santander and Mastercard demonstrated Europe's first live payment executed by an AI agent within a regulated banking environment, using pre-authorized customer permissions, tokenized credentials and existing banking controls
1
. Similar initiatives announced by BBVA with Visa and Nordea with Mastercard signal that agentic payments are transitioning from theoretical possibility to operational reality1
.What separates early experimentation from sustainable agentic AI systems is governance. Assigning work to AI agents in enterprise workflows requires clear rules, defined decision rights and complete visibility into how actions are taken
2
. Organizations implementing AI in payments processing, collections, payment screening and risk management discover that controlled autonomy outperforms unrestricted autonomy2
.Leading organizations embed AI agents in finance directly into workflows rather than layering technology on top of existing processes. In this model, AI agents operate within defined processes guided by policies, thresholds and approvals set by the business, ensuring every action remains traceable and auditable
2
. The CFO AI Maturity Model illustrates this progression: organizations start with assistive AI, advance to automated workflows requiring human intervention, then introduce agentic execution where systems resolve exceptions within guardrails, ultimately reaching outcome-driven finance where AI continuously optimizes cash flow and risk exposure2
.Traditional financial controls focus on identity verification: confirming the customer, validating the account and checking whether transactions match expected behavior. These questions remain essential but insufficient when AI agents act on behalf of people or businesses
1
. Financial institutions must now understand whether actions reflect genuine instructions, whether they sit within the agent's permitted role and whether sufficient evidence explains why transactions occurred1
.Trust in agentic commerce requires binding verifiable mandates to credentials—essentially cryptographic proof of what consumers authorized their agents to do—then surfacing signals at authorization that an agent rather than a human initiated the transaction
4
. Visa and Mastercard are standardizing this through Intelligent Commerce and Agent Pay respectively, creating frameworks that allow issuers to decide in real time rather than discover agent involvement after the fact4
.Fraud prevention systems are being retuned for automated behavior. The traditional question "is this the genuine customer?" evolves into "is this still what the customer authorized the agent to do?"
4
. The harder case involves agents behaving exactly as mandated while cardholders dispute transactions anyway. Current chargeback rules were never written for third parties acting on standing instructions4
.Verifiable intent, proven at authorization, must become the basis for reallocating liability. Card issuers who can prove intent will be positioned to actually underwrite agentic commerce rather than merely permit it
4
. Explainability becomes critical—if transactions are blocked or flagged, customers and compliance teams need to understand why, and if suspicious transactions are approved, institutions need to understand what signals were missed1
.Related Stories
AI agents become valuable when connected to trusted data, strong technology, established workflows and clear governance
3
. Agentic AI grounded in proprietary payments data and domain knowledge can validate information, flag exceptions and support better decisions—context that cannot be recreated through generic automation alone3
.Companies are applying AI in payments processing, quality control, product design, client onboarding and customer service, where agents reduce manual effort and improve operational consistency
3
. At Thredd, agentic capabilities are being leveraged for fraud detection, credit decisions, sales, billing automation and client servicing4
. The goal is not removing people from processes but giving them better systems, deeper insight and more technical leverage3
.At every technology inflection point—eCommerce, mobile commerce, Apple Pay, cryptocurrency—predictions of card infrastructure obsolescence proved premature. Tokenization, scheme rules, dispute and chargeback rights, and issuers that underwrite risk represent controls that agentic commerce needs, and they already exist
4
. Network tokens already carry merchant and category restrictions and can be revoked, providing a foundation rather than a complete answer4
.Beyond consumer-facing payments, card issuing involves repetitive, rules-based operational work: reconciling settlement files, onboarding customers, assembling dispute evidence, servicing cardholders and producing regulatory reports. These tasks represent exactly the shape of work AI agents handle effectively, where costs can be stripped out by breaking the link between growth and headcount
4
. Programmable payments extend this logic to money movement itself, where value moves on conditions and rules set in line with transactions rather than preset instructions4
.The path forward requires intelligent orchestration rather than unrestricted autonomy. AI can automate frontline processing with another AI-enabled layer validating output, while human quality control addresses issues requiring judgment
3
. Companies making progress are not chasing autonomy for its own sake but redesigning workflows starting with high-value use cases and scaling incrementally, connecting data across systems and ensuring governance is built into workflows from the start2
. The agentic enterprise will be defined by confidence organizations can place in AI to achieve desired outcomes without increasing risk2
.Summarized by
Navi