10 Sources
[1]
Regulating payments when it's AI agents spending the money
The future of trusted transactions will depend on understanding intent, authority and context alongside established rigorous identity checks. A small business owner asks an AI assistant to manage a simple task: review outstanding invoices, check which suppliers need to be paid, and prepare the next set of payments. The assistant scans emails, compares due dates, and prepares recommendations for approval. For the business owner, this could remove hours of repetitive work. But for the financial institution processing those payments, it changes the nature of trust. A payment may still come from a legitimate account, but the decision behind it may have been shaped, prepared or initiated by software acting on someone's behalf. This creates a significant challenge for financial services. It's no longer enough to simply understand who or what is behind a transaction; institutions now need to be able to discern whether the action reflects genuine human or business intent. This challenge becomes particularly important in payments. The International Monetary Fund has described agentic AI as a development that could move payments from human-initiated instructions towards agent-mediated decisions. Payments are not just another automated workflow. When money moves, the consequences are immediate and can be difficult to reverse. Financial systems have long been built around the assumption that a payment instruction can be linked to a person, business or institution with clear authority to act. Agentic AI complicates that assumption by adding another layer between the human and the transaction. This does not mean AI agents should be kept away from financial activity. Used carefully, they could help people and businesses manage routine financial tasks with less friction. But the more useful these systems become, the more important it will be to define the conditions under which they can act. The question is not whether AI agents should be used in finance, but how institutions can support their use without weakening accountability. In 2026, Santander and Mastercard demonstrated Europe's first live payment executed by an AI agent within a regulated banking environment. The transaction was completed using pre-authorised customer permissions, tokenized credentials and existing banking controls, illustrating that autonomous agents can operate within established regulatory and security frameworks rather than outside them. Similar initiatives announced by BBVA with Visa and Nordea with Mastercard suggest that financial institutions are increasingly exploring how AI agents can act on behalf of customers while maintaining the governance, authentication and auditability expected of regulated financial services. An agent that can act quickly across several systems can also make mistakes quickly. It may be able to be manipulated through false information, compromised instructions or fraudulent requests that appear legitimate. In a payments environment, the difference between helpful automation and harmful activity may come down to whether institutions can understand intent, authority and context before money moves. Today, many financial controls focus on identity. Who is the customer? Is the account legitimate? Does the transaction match expected behaviour? These questions will remain essential, but they may no longer be enough. If an AI agent is acting on behalf of a person or business, institutions will also need to understand whether the action reflects a genuine instruction, whether it sits within the agent's permitted role and whether there is enough evidence to explain why the transaction happened. This is where trust in agentic finance will need to be designed carefully. Stronger authentication will matter, but so will clearer audit trails. Financial institutions will need to know when an AI agent was involved, what it was authorized to do and whether its action can be traced back to a legitimate human or business decision. Explainability will also become more important. If a transaction is blocked, delayed or flagged for review, customers and compliance teams need to understand why. If a suspicious transaction is approved, institutions need to understand what signals were missed. Black-box decision-making is uncomfortable in any regulated environment, but in financial services, where decisions can affect people's access to money, markets and essential services, it becomes a direct trust issue. There is also a human dimension inside financial institutions. Compliance and fraud teams are already working under pressure from faster payments, rising alert volumes, and more sophisticated criminal behaviour. Agentic AI could help them identify patterns, summarise cases and prioritize risk. But it should support human judgement, rather than replace it. Regulation is evolving alongside these technological advances. In the UK, the Competition and Markets Authority has published guidance making clear that organizations remain accountable for the actions of AI agents acting on their behalf. Across Europe, the EU AI Act reinforces requirements around transparency, human oversight, governance and record-keeping for higher-risk AI systems. Together, these developments point towards an emerging model of autonomous compliance, where AI agents are expected to operate within robust governance and audit frameworks. The World Economic Forum's AI Playbook for Financial Services argues that trust, governance and human oversight are becoming critical tests as financial institutions move from experimentation to scaled AI adoption. Agentic AI will make those tests more demanding. It will require institutions to define where autonomy is acceptable, where human approval is still needed and how responsibility is recorded when software acts on someone's behalf. The future of trusted transactions will not depend only on knowing who someone is. It will also depend on understanding what they intended, what their AI agent was allowed to do and whether the action can be explained after the event. As AI agents become more involved in economic activity, financial trust will need to evolve with them. The task ahead is not to slow down progress, but to make sure that as AI begins to act, the financial system can still answer one of its most important questions: should this transaction be trusted?
[2]
Agentic payments will need more than wallets: By Tohid Naeem
Agentic payments are moving from demo territory into infrastructure. Natural's recent raise is a useful signal for the category. The market is beginning to organize around wallets, vaults, cards, merchant acceptance, credit, billing, and direct rail access for AI agents. That matters. Agents need ways to participate in payment flows: holding value, accepting payments, triggering transfers, and interacting with existing rails. But movement is only one side of the problem. The harder institutional question is what happens before and after the payment moves. When an agent initiates or participates in a transaction, a bank, PSP, enterprise, or marketplace will eventually need to answer basic questions: Who was the actor? What authority did it have? What mandate applied? What limits were enforced? Which policy produced the decision? Was the action allowed, denied, or sent for review? What evidence survives for audit, dispute resolution, risk review, or regulatory examination? Those questions are not solved by a wallet alone. A wallet may identify where value is held. A card may provide access to a network. A merchant-acceptance layer may let an agent receive payments. A rail connection may move funds from one place to another. But none of those, by themselves, fully explains why an autonomous or semi-autonomous actor was permitted to act. That is where agentic payments become more than a payments problem. They become a governance problem. The financial system is used to human actors, corporate actors, service providers, delegated users, API credentials, and regulated intermediaries. AI agents do not fit neatly into any one of those categories. They may act on behalf of a person, a business, another system, or a chain of delegated instructions. They may operate across merchants, jurisdictions, workflows, and rails. That creates a control gap. The market will need payment stacks. It will also need a governance layer above those stacks: actor identification, mandate binding, policy evaluation, decision logging, and audit evidence. This distinction matters because the most important question after an agentic transaction may not be "did the payment clear?" It may be: "Why was this action authorized?" The rail moves the money. The governance layer explains why the action was allowed.
[3]
When AI agents start fixing financial systems, trust becomes the real currency
As AI agents move beyond detecting problems to resolving them autonomously, financial institutions face a new challenge: balancing speed with trust. This session explores how agentic AI is transforming operational resilience through compliance-aware automation, explainable decision-making, and governed autonomy, enabling faster incident resolution without compromising regulatory accountability or customer confidence. For the last decade, banks and financial institutions have fought operational risk with the same basic playbook: monitor everything, alert on anomalies, and route the alert to a human who investigates, decides, and fixes it. It has never been fast enough, and honestly, it was never designed to be. It was built for a world where humans were the only ones anyone trusted to touch production financial systems. AI is now breaking that assumption, and most people haven't noticed yet. A modern financial institution runs on tens of thousands of interconnected services, moving billions of transactions a day, under overlapping regulatory regimes: Sarbanes-Oxley Act (SOX), Basel III, Markets in Financial Instruments Directive (MiFID II), and now Europe's Digital Operational Resilience Act (DORA), which gives institutions as little as 30 minutes to detect, escalate, and act on a major incident. Industry data suggests systemically important institutions face a serious operational disruption roughly once a quarter, and the average one takes well over two hours to resolve. In a regulated, always-on financial system, two hours isn't a delay. It's an incident report waiting to be filed. The obvious next question is whether AI can simply watch the dashboards faster than a human. That's the easy prediction, and it happens to be the wrong one. Faster monitoring alone doesn't solve much, because detection was never really the bottleneck. The bottleneck was always what happens after detection: figuring out the actual root cause across dozens of interdependent systems, deciding what to fix, and doing it without accidentally breaching a compliance rule along the way. That's a judgment problem, not a speed problem, and it's exactly the kind of problem a single alerting rule, or a single AI model working alone, was never going to solve well. This is where the real shift is happening. Instead of one large model trying to do everything, the more promising approach looks like a small team of specialised AI agents, each responsible for one part of the job. One agent watches for early signs of trouble across transaction flows, compliance signals, ledger reconciliation, and infrastructure health together, instead of monitoring each in its own silo the way most systems do today. The second agent's only job is root cause analysis, tracing the anomaly back through the system's dependency graph instead of guessing from a single alert. A third proposes the fix. A fourth executes it, but only after a governance layer checks whether the action is even allowed under the regulatory constraints that apply to that system. None of this replaces a human so much as it compresses a two hour, multi team scramble into a single, auditable, machine speed decision loop, with a human still in the loop for anything the system isn't confident, or authorised, to do alone. Early results from this kind of multi agent approach are striking. Incident resolution times drop from over two hours to under half an hour, with roughly two out of every five incidents resolved without any human escalation at all. That's not a small improvement on existing monitoring tools. It's a different category of system, one that doesn't just detect problems but actually resolves a meaningful share of them on its own. And that's precisely where the uncomfortable question begins. An AI agent that can independently diagnose and fix a production issue inside a bank's core systems is also an AI agent that can independently take an action a regulator will one day ask about. Autonomy without compliance built in isn't innovation, it's just a liability with better uptime. The institutions that get this right won't be the ones that deploy AI fastest. They'll be the ones that build autonomy and accountability into the same system, so that every autonomous action is explainable, reversible, and provably within regulatory bounds before it ever executes, not after something has already gone wrong. Who's in the race Their advantage Where they're exposed Core banking & enterprise platforms Already sit inside the regulated environment, with the data and system access needed to act Risk becoming the system that gets fixed, not the system that does the fixing AIOps & observability vendors (Splunk, Dynatrace, Moogsoft type tools) Own detection and correlation today, with deep telemetry access Historically stop at detection; root cause and remediation still route to humans Frontier AI / model providers Increasingly capable of the reasoning root cause diagnosis requires Need deep, trusted integration into regulated infrastructure, which they don't own Systems integrators & consultancies Understand the messy reality of legacy financial infrastructure and compliance mapping Good at implementation, not always at owning an ongoing autonomous system Purpose built agentic resilience platforms Designed from day one around compliance aware autonomy, not bolted on afterwards Have to earn institutional trust with no long incumbency to lean on The financial industry has spent 20 years automating what it could measure: payments, settlements, reporting. What it hasn't automated is the moment something breaks. That always required a human, not because machines couldn't act fast enough, but because nobody trusted a machine to act inside a regulated system without supervision. Agentic AI is the first real challenge to that assumption. It won't be won by whoever builds the fastest agent. It will be won by whoever builds the agent that a regulator, a Chief Financial Officer (CFO), and a customer can all trust to act on its own, and can prove it, every single time.
[4]
i2c CEO Says AI Agents Make Entire Workflows Disappear | PYMNTS.com
I think most companies building agentic AI are answering the wrong question. They ask which model to deploy. The harder question is whether the infrastructure underneath was ever designed to let something act on its own. I've watched AI move through three eras: rule-based systems in the 1980s, machine learning that detected patterns starting around 2010, and now agentic AI -- systems that reason, act autonomously, orchestrate across systems, and learn from every outcome. Generative AI gave us reasoning. Agentic AI adds perception, action and memory. The companies winning in this era aren't necessarily the ones with the most sophisticated artificial intelligence strategy. They're the ones whose architecture was built to support it. An agent can only orchestrate across systems it can see and only act in real time if the underlying platform responds to events as they happen. When AI is layered onto fragmented systems and disconnected data, what looks like an AI initiative quickly becomes a data integration project. We learned this through experience. Decisions we made years ago to build a unified data model across our platform are paying off in ways I didn't fully anticipate. Our fraud systems can read signals across a customer's entire relationship, not just a single transaction type, and learn continuously from outcomes. That foundation allows us to move decisions closer to the transaction itself. The clearest example is fraud management. What once required an analyst review and a call-center process can increasingly be handled within the transaction flow. An anomaly is detected, action is initiated and the customer experience becomes a quick confirmation rather than an embarrassing decline or a lengthy dispute process. That's not automating a step. It's removing the step entirely. As autonomy increases, decision rights shift. Judgments that once belonged to people increasingly belong to systems, with humans positioned to intervene rather than approve every action. Getting that balance right matters. Too much oversight limits the value of autonomy. Too little creates unnecessary risk. That's why governance becomes critical. Permissioning, audit trails and human oversight cannot be afterthoughts. The organizations scaling agentic AI successfully are building those guardrails before they need them, not after an incident exposes the gaps. The build-versus-buy conversation is changing, too. Unless an organization operates at the scale of the largest players in its industry, building proprietary AI infrastructure from scratch is rarely the best use of capital or talent. The better question is which capabilities truly differentiate your business and which have already been solved well by trusted partners. Build where it creates competitive advantage. Partner where it doesn't. What hasn't changed is the discipline required to evaluate any artificial intelligence use case: economic benefit, structured data, real scale and auditability. Agentic AI doesn't lower that bar. It raises the stakes, because these systems aren't just advising anymore. They're acting.
[5]
Beyond the Model: Foundations for Safe, Scalable Agentic AI: By Laurie Schnidman
Conversations about the move away from 'tokenmaxxing' have taken off over the past few weeks, highlighting just how prevalent AI usage has become within businesses. As organisations look for more cost-efficient ways to operate AI at scale, what's become clear is that we have now moved beyond experimentation to full-blown implementation. Within financial services organisations, we're seeing a shift from experimenting with frontier AI to building agentic applications, with businesses exploring just how far agents can go in reasoning, planning, decision making, and - crucially - taking action. Agentic AI's potential is significant; beyond efficiencies, there is potential for faster and smarter decision-making and hyperpersonalised customer experiences at scale. To date, much of the focus has been on the AI models and capabilities, but a more important question is emerging as businesses scale AI at speed: what will it take to build an environment in which agentic AI can operate safely, reliably, and with confidence? The challenge isn't just about deployment. It's about integrating models, data, and systems safely and responsibly across the enterprise so that agents operate in tandem as opposed to isolation. And for financial services businesses, intelligence alone is not enough. In a highly-regulated environment where a misstep can cost firms millions and materially impact consumers, AI systems must be explainable, accountable, and governed in ways that satisfy customers, regulators, boards, and auditors. That's where trusted data becomes the differentiator. As organisations scale agentic systems, scrutiny will shift beyond the model itself to interrogate the data, context, expertise, and governance frameworks that underpin outcomes. The real competitive advantage won't come from sheer volume of data alone, but from its quality, authority, and context. Trusted, true data. Because data is now also action: how organisations encode expertise and establish guardrails. Through semantic layers, governance frameworks, and codified domain knowledge, organisations can better ensure autonomous systems operate within defined boundaries while remaining transparent and compliant. Building this foundation requires collaboration; it relies on interconnected data, shared infrastructure, trusted identity frameworks, and common approaches to risk and governance. Successful architectures and ecosystems will increasingly depend on strong and experienced partners providing both technical capability and operational expertise. Ultimately, the organisations that succeed with agentic AI will not simply be those that move fastest. They will be those that invest the time and resources to build strong foundations, combining trusted data, embedded expertise, and robust governance to create systems that are transparent, reliable, and ready for real-world deployment.
[6]
Agentic Payments Turn Proof Into Competitive Advantage | PYMNTS.com
The inflection in agentic AI won't be defined by what agents can do, since that capability is arriving regardless. It will be defined by which banks can prove what their agents did. The next phase of agentic AI in payments will be shaped by a practical question: "How much work can agents take on without weakening control?" That question guided our development of Vol360i, Volante's agentic AI solution for payments. Banks are ready for artificial intelligence to do more than summarize information or suggest next steps, but they are not asking for unchecked automation or another AI layer that creates more work for operations, risk or compliance. They need agents that can work within the payment flow, act when evidence is strong, escalate when risk is higher and show exactly how each recommendation was made. For financial institutions, there is little to no room for trial and error. A payment cannot be fixed casually after the fact. It touches liquidity and the customer's expectation that money will move as intended. The economics now point the same way. As inference costs fall, running an agent gets cheap, but in payments, the dominant cost is the time spent on investigation and clawback, and the liquidity hit. When intelligence becomes inexpensive, the binding constraint shifts from compute to control, which makes a confidence-based operating model a rational choice. Agents Need to Live in the Workflow A payment workflow is not the kind of process where banks can automate first and clean up the consequences later. That's why it is essential to design true value-adding solutions around agents who act where payment decisions are made. Vol360i is built around four capabilities: Together, these capabilities move banks away from static rules and manual queues. Further, they prepare banks for what comes next: a growing share of payments initiated by agents acting on behalf of humans. The financial institution that can govern agent-initiated payments -- verifying intent, scoring confidence and escalating anomalies -- will strengthen their competitive advantage as the counterparty becomes non-human. Governance Is Non-Negotiable The AI race is also a governance test. Speed only matters if banks can explain and control the decisions that agents make. Governance must shape how agents are designed, tested and monitored from the start. Banks need to understand why an agent made a recommendation and whether a human accepted, changed or rejected it. Each decision should leave a clear record, including the data behind the recommendation and the confidence level assigned to it. That record only means something on infrastructure the bank governs -- deployed in-tenant, with data kept resident and no payment information passing through shared inference. Governed confidence requires governed compute. For DORA-regulated institutions, private AI deployment is what turns the audit trail from a promise into a control. That record is what makes a confidence-based operating model practical. When the evidence is strong and the risk is low, an agent can be allowed to do more. When the risk is higher or the signal is unclear, the system should bring an operator back into the decision. Those responses should then improve the model over time, so autonomy expands based on performance rather than assumptions. Autonomy Must Be Earned Agentic AI will not remove people from payment operations. It will change where their judgment is needed. The real opportunity is to take repetitive repair work off their plates so they can focus on decisions that carry the most risk or customer impact. That shift will not happen all at once, and that is by design. Every reviewed decision that is accepted, changed or rejected trains models and widens the band of what agents can safely do unsupervised. Banks that deploy fastest without that record get speed once. Banks that instrument the loop get compounding autonomy, where trust earned on low-risk repairs funds expansion into higher-risk ones. The moat is not the agent, but the governed track record behind it.
[7]
Visa Says the Agentic Enterprise Starts With Better Controls | PYMNTS.com
Every major technology wave changes how we work. From the printing press to the loom, from the typewriter to the web, new technology requires new ways of working. That's why I see building an agentic enterprise as just as much of an organizational challenge as a technology one. It's a mindset shift that requires us to organize our work in a new way. For instance, as artificial intelligence agents take on more operational responsibilities, employees are increasingly focused on organizing how agents work and guiding decisions based on their specific domain expertise. We're also seeing employees use AI coding assistants like Claude Code or OpenAI's Codex to build new workflows to coordinate actions across agents and create fit-for-purpose solutions that solve challenges in real time. Many of these new tools activate existing data, unlocking fresh insights and business value. The value often comes not from a single breakthrough capability, but from lifting layers of complexity in ways that reduce manual coordination and help us move faster. The best implementations reveal new opportunities that were not visible before, tapping agents to gather information from multiple systems and connect the dots. When it comes to true autonomy, most organizations have a ways to go. And that's a good thing, as there's quite a bit that goes into true agentic autonomy. Success requires embedding trust, transparency and accountability into AI strategies from the outset. Agentic systems need clear guardrails that limit access to an organization's data in a way that protects privacy while still ensuring that teams get the most value from their artificial intelligence tools. Enterprises must also thoughtfully balance agentic autonomy with human oversight. It's not a binary choice, as different workflows require different levels of human involvement. Many tasks will continue to require human judgment, particularly when decisions involve financial risk, regulatory obligations, customer trust or broader business strategy. We also must keep the end goal always in mind: tapping both human and machine capabilities in ways that create smarter decisions, faster execution and stronger business outcomes. That's the true value of the agentic enterprise: the best of both worlds.
[8]
AI Agents Need Rules Before They Can Run Payments | PYMNTS.com
Moving from manual work and processes to copilots and then to agents means a sea change in how work gets done. Now businesses can assign real responsibility to systems that can execute tasks, make decisions and operate across enterprise workflows. The promise is powerful, but the risk is real. For most companies, the challenge is no longer whether to adopt artificial intelligence (AI), but how to do so without losing control of key workflows, key decisions and creating additional risk on the whole business. In finance, that tension is especially clear. AI has already proven its value in analysis, forecasting and reporting. But the real opportunity sits in processes like collections, payment screening and workflow, cash application and risk management. These are the workflows that directly impact cash flow, working capital and managing financial risk. They are also the areas where autonomy is hardest to scale, because the cost of errors is so high. What separates early experimentation from an agentic enterprise is governance. Assigning work to agents and agentic workflows requires clear rules, defined decision rights and full visibility into how and why actions are taken. Without that, AI becomes another layer of risk rather than a source of value. This is where many organizations are learning that autonomy and agentic AI is harder to implement than expected. This is less because the models are insufficient -- though they are improving all the time -- but because enterprise systems, data, and controls were not built to support the shift to AI. The path forward, then, is controlled autonomy rather than full autonomy. Leading organizations are embedding AI directly into workflows, rather than layering the technology on top of core processes. In this model, agents do not operate independently, but within defined processes that are guided by policies, thresholds and approvals set by the business. Every action is traceable, auditable and aligned to financial controls. This shifts AI from an insight-delivering tool to something that can effectively execute the work that must be done. In this scenario, AI can impact the metrics that matter. We see this progression clearly through the CFO AI Maturity Model. Most organizations start with assistive AI, where technology helps individuals complete tasks more efficiently. From there, workflows become more automated but still require human intervention at key points. The next phase introduces agentic execution, where systems can resolve exceptions, take actions and operate within defined guardrails. Ultimately, the goal is outcome-driven finance, where AI continuously optimizes key metrics like cash flow, risk exposure and operational efficiency. At each stage, the role of the human employee changes. The focus shifts from doing the day-to-day work to defining the rules, monitoring outcomes and controlling performance. Finance functions should think of this as elevating the roles employees play, rather than removing people from the process. The companies making progress are not chasing autonomy for its own sake, to check a box or to send out a splashy press release. These businesses are redesigning workflows starting with high-value use cases and scaling incrementally. They are connecting data across systems, embedding AI where decisions are made, and ensuring that governance is built into workflows from the start. The agentic enterprise will not be defined by how much work AI can get done. Instead, it will be defined by how much confidence organizations can place in AI to achieve desired outcomes without increasing risk.
[9]
Agentic Payments Start With the Right Foundation | PYMNTS.com
As artificial intelligence moves from copilots to agents, the opportunity to evolve how businesses function is becoming more practical and immediate. Enterprises are starting to apply AI to real workflows where speed, accuracy and consistency matter. The bigger question is not simply what AI can do, it is what business foundation AI is being built upon. AI agents have begun to autonomously execute defined work across systems and decision points. But in enterprises, agents do not become valuable in isolation. They become valuable when connected to trusted data, strong technology, established workflows and clear governance. At Boost, we do not view AI as something being applied to a blank slate. We view it as an accelerator of foundational capabilities that already exist: years of proprietary payments data, deep B2B payments expertise, established customer and partner relationships and a best-in-class technology platform built around complex enterprise payment workflows. That foundation is what makes AI more powerful. Agentic AI grounded in proprietary data and domain knowledge can help validate information, flag exceptions and support better decisions. In the payments industry, that context is critical. Understanding how enterprise buyers, suppliers, issuers and processors interact is not something that can be recreated through generic automation alone. Our business is already seeing this transition take shape. AI is being applied in areas such as payments processing, quality control, product design and development, client onboarding and customer service, where agents can help reduce manual effort and improve operational consistency. More importantly, agents will help us build more intelligent customer-facing solutions and experiences over time. But agentic AI also requires discipline. Thoughtful design and planning are necessary ingredients to properly build an agentic enterprise. In payments, speed only matters if accuracy, control and trust are preserved. There is very little room for ambiguity and no room for error. That is why the future of enterprise AI cannot be unrestricted autonomy. It has to include intelligent orchestration. In practice, AI can automate frontline processing, with another AI-enabled layer established to validate the output. Human quality control can remain in place to address issues that require judgment. The goal is not to remove people from the process, but to give them better systems, deeper insight and more technical leverage. This is where many companies will find that autonomy is harder to scale than expected. The challenge is not always the model itself, but instead the enterprise context around the model. AI needs reliable data, mature workflows and business rules that reflect how the company operates. The agentic enterprise will be defined by companies that combine AI with proprietary assets, operational expertise and disciplined governance to generate business outcomes that could not be achieved by humans alone. For customers, the impact should be tangible: faster support, smoother onboarding, stronger knowledge access, more engaging solutions and payment experiences that feel less fragmented. AI will not replace the foundation of a strong enterprise; it will amplify it. The companies best positioned for the agentic future are the ones starting with something unique to build upon.
[10]
Thredd's McCarthy Says Payments Will Govern the Agentic Enterprise | PYMNTS.com
The interesting question about the agentic enterprise is not whether agents can act. They clearly can. It's whether enterprises can scale that action safely -- and the evidence so far is that autonomy is harder to scale than the demos suggest. The bottleneck is not intelligence. It's permission, control and proof. Businesses are putting policies and governance in place to safely scale generative AI across their enterprise. At Thredd, green shoots of innovation are sprouting daily, leveraging agentic capabilities for fraud, credit, sales, billing automation and client servicing. But we see the challenge, and equally the opportunity, for agentic experiences more acutely on the payment side, where an agent recommending a purchase, not all that interesting, becomes useful when it's trusted to initiate and complete a payment. At that moment the question stops being "can the agent pay?" and becomes "what is this agent permitted to do, on whose authority, under what limits, and how is that permission proven, monitored and revoked in the milliseconds an authorization takes?" That's a payments problem before it's an AI problem, and payments has a head start most people underestimate. At every technology inflection point during my career -- eCommerce, mobile commerce, the launch of Apple Pay, cryptocurrency -- someone predicted the end of cards, and yet each time the trust infrastructure proved far harder to replicate than the rails were to reinvent. Tokenization, scheme rules, dispute and chargeback rights, issuers that underwrite risk and bind consumers to credentials -- these aren't legacy baggage. They're the exact controls agentic commerce needs, and they already exist. But raw materials aren't readiness, and this is where the conversation gets too casual. A network token already carries merchant and category restrictions and can be revoked providing a real head start, not an answer on its own. The new work is binding a verifiable mandate to that credential which is essentially a cryptographic proof of what the consumer authorized their agent to do, and then surfacing, at authorization, a signal that an agent rather than a human initiated the transaction, so the issuer can decide in real time rather than discover it after the fact. Visa and Mastercard are standardizing this through Intelligent Commerce and Agent Pay respectively; we monitor and, in some cases, build those frameworks while staying deliberately neutral on the merchant-side protocols, so our clients, issuers and program managers, are insulated from bets that haven't been resolved. It's also why a connection standard, on its own, doesn't solve this. Protocols like MCP matter because they standardize how agents plug into systems. They don't answer who authorized this agent, what the consumer actually intended, whether the behavior is anomalous or who is liable when it's disputed. Those are issuer-layer questions, and they don't get easier by stacking another protocol on top of them. Liability is the one the industry hasn't fully answered, and the one I'd tell any enterprise to watch. Fraud detection is being retuned for a new class of automated behavior. The old question was, "is this the genuine customer?" The emerging one is, "is this still what the customer authorized the agent to do?" That's necessary but not sufficient. The harder case is the agent that behaves exactly as mandated and the cardholder disputes anyway. Today's chargeback rules were never written for a third party acting on standing instructions. My view is that verifiable intent, proven at authorization, must become the basis for reallocating that liability -- and the issuers who can prove intent will be the ones who can actually underwrite agentic commerce, not merely permit it. For a card issuer, the point of sale is the tip of the agentic iceberg. Strip away the consumer experience and the work of card issuing is repetitive, rules-based, operational work. Things like reconciling settlement files, onboarding and screening customers, assembling dispute evidence, servicing cardholders and producing regulatory reports represent high-headcount work that has scaled almost linearly with volume. That's exactly the shape of tasks agents are good at, and where costs can actually be stripped out of businesses: an agent that reconciles a file and escalates only the genuine inconsistencies, or triages an onboarding case, breaks the link between growth and headcount that has constrained this industry for years. Programmable payments extend the same logic to money movement itself where value that moves on conditions and rules set in line with the transaction rather than preset instructions configured at the program level, with an agent orchestrating inside guardrails set by the customer. An agent reconciling a ledger, or releasing a payment on a rule, needs exactly what an agent at checkout needs: defined permission, proof of what it was authorized to do, an audit trail and the ability to revoke it the moment something looks wrong. Solve that governance problem once and you apply it across the operation; that's the compounding advantage, and why the trust layer is worth owning. It's also where discipline matters most, because the back office is where autonomy is easiest to justify and hardest to trust. A silent reconciliation error doesn't announce itself, it compounds. Those who capture these savings will be the ones who put escalation thresholds, manual review thresholds and provable authority in place first -- taking cost out rather than trading labor cost for risk. The agentic enterprise won't be defined by how much autonomy it hands to AI, but by how well it governs that autonomy where liability shifts and value is created. The winners won't just have smarter agents. They'll have agent-ready infrastructure beneath them, verifiable intent underwriting it, and partners willing to absorb that complexity so they can move quickly.
Share
Copy Link
Financial institutions are deploying AI agents to handle payments and operational tasks, but a critical question emerges: how do you govern systems that act autonomously? From Santander's first AI-executed payment to multi-agent systems resolving incidents in minutes, the industry is discovering that trust frameworks and accountability matter more than speed.
AI agents are rapidly transitioning from experimental tools to active participants in financial transactions. In 2026, Santander and Mastercard demonstrated Europe's first live payment executed by an AI agent within a regulated banking environment
1
. Similar initiatives announced by BBVA with Visa and Nordea with Mastercard signal that agentic AI systems are moving beyond detection to autonomous action1
. The International Monetary Fund has described agentic AI as a development that could shift payments from human-initiated instructions towards agent-mediated decisions1
.This shift creates a fundamental challenge for financial institutions. When an AI agent scans emails, compares due dates, and prepares payment recommendations for a small business owner, it removes hours of repetitive work
1
. But for the financial institution processing those payments, it changes the nature of trust. A payment may still come from a legitimate account, but the decision behind it may have been shaped, prepared, or initiated by software acting on someone's behalf1
.Agentic payments are moving from demo territory into infrastructure, with the market organizing around wallets, vaults, cards, merchant acceptance, and direct rail access for AI agents
2
. Natural's recent raise signals growing investor interest in the category2
. But movement is only one side of the problem. The harder institutional question is what happens before and after the payment moves2
.When an AI agent initiates or participates in a financial transaction, banks, payment service providers, enterprises, and marketplaces need to answer basic questions: Who was the actor? What authority did it have? What mandate applied? What limits were enforced? Which policy produced the decision? What evidence survives for audit, dispute resolution, risk review, or regulatory examination
2
? A wallet may identify where value is held, but it doesn't explain why an autonomous or semi-autonomous actor was permitted to act2
.The financial system is accustomed to human actors, corporate actors, service providers, delegated users, API credentials, and regulated intermediaries. AI agents don't fit neatly into any one of those categories
2
. They may act on behalf of a person, a business, another system, or a chain of delegated instructions, operating across merchants, jurisdictions, workflows, and rails2
. This creates a control gap that requires a governance layer above payment stacks: actor identification, mandate binding, policy evaluation, decision logging, and audit evidence2
.Modern financial institutions run on tens of thousands of interconnected services, moving billions of transactions daily under overlapping regulatory regimes including Sarbanes-Oxley Act, Basel III, Markets in Financial Instruments Directive, and Europe's Digital Operational Resilience Act, which gives institutions as little as 30 minutes to detect, escalate, and act on major incidents
3
. Industry data suggests systemically important institutions face a serious operational disruption roughly once a quarter, with the average one taking well over two hours to resolve3
.Instead of one large model trying to do everything, the more promising approach involves specialized AI agents, each responsible for one part of the job
3
. One agent watches for early signs of trouble across transaction flows, compliance signals, ledger reconciliation, and infrastructure health together. A second agent handles root cause analysis, tracing anomalies back through the system's dependency graph. A third proposes the fix. A fourth executes it, but only after a governance layer checks whether the action is allowed under applicable regulatory constraints3
.Early results from multi-agent systems are striking. Incident resolution times drop from over two hours to under half an hour, with roughly two out of every five incidents resolved without any human escalation
3
. This compresses a two-hour, multi-team scramble into a single, auditable, machine-speed decision loop, with humans still in the loop for anything the system isn't confident or authorized to do alone3
.Related Stories
According to i2c CEO, most companies building agentic AI are answering the wrong question by focusing on which model to deploy rather than whether the infrastructure underneath was ever designed to let something act on its own
4
. The companies winning aren't necessarily those with the most sophisticated AI strategy but those whose architecture was built to support it4
.An AI agent can only orchestrate across systems it can see and only act in real time if the underlying platform responds to events as they happen
4
. When AI is layered onto fragmented systems and disconnected data, what looks like an AI initiative quickly becomes a data integration project4
. Unified data models across platforms allow fraud management systems to read signals across a customer's entire relationship, not just a single transaction type, and learn continuously from outcomes4
.In fraud management, what once required analyst review and call-center processes can increasingly be handled within the transaction flow. An anomaly is detected, action is initiated, and the customer experience becomes a quick confirmation rather than an embarrassing decline or lengthy dispute process
4
. That's not automating a stepāit's removing the step entirely4
.As organizations scale AI at speed, a critical question emerges: what will it take to build an environment in which agentic AI can operate safely, reliably, and with confidence
5
? The challenge isn't just about deployment but about integrating models, data, and systems safely and responsibly across the enterprise so that autonomous systems operate in tandem rather than isolation5
.For financial services businesses operating in highly-regulated environments where a misstep can cost millions and materially impact consumers, AI systems must be explainable, accountable, and governed in ways that satisfy customers, regulators, boards, and auditors
5
. As organizations scale agentic systems, scrutiny will shift beyond the model itself to interrogate the data, context, expertise, and governance frameworks that underpin outcomes5
.The real competitive advantage won't come from sheer volume of data alone but from its quality, authority, and contextātrusted, true data
5
. Through semantic layers, governance frameworks, and codified domain knowledge, organizations can better ensure autonomous systems operate within defined boundaries while remaining transparent and compliant5
. Organizations that succeed with agentic AI will not simply be those that move fastest but those that invest the time and resources to build strong foundations combining trusted data, embedded expertise, and robust governance5
.Summarized by
Navi
[2]
[5]
27 Jun 2025ā¢Technology
27 Oct 2025ā¢Technology

02 Dec 2025ā¢Technology
1
Technology

2
Technology

3
Policy and Regulation
