

AI agents in payments are autonomous software agents that start, authorize, route or reconcile payments for a person or business. Their main risks are unauthorized spending, prompt injection, AML and sanctions gaps, broken authentication and unclear liability. They are governed by payment law (PSD2/PSD3, Regulation E, RBI directions), AI law (the EU AI Act) and data law (GDPR, India's DPDP Act).
The scale is no longer hypothetical. McKinsey estimates that AI agents could orchestrate up to $5 trillion in global consumer spending by 2030 (Fortune). Visa, Mastercard, Google and Stripe have all launched rails for agent-initiated payments. Regulators are still catching up.
This guide is for payments, risk, compliance and finance leaders. It covers how AI agents are used in payments applications today, the 10 risks they create, the regulations that apply in the EU, UK, US and India, and a practical framework for deploying them safely. It also includes a risk → regulation → control matrix and anonymized results from production deployments of Assistents, the enterprise AI agent platform by Ampcome.

Key takeaways

Agentic payments are payments that an AI agent starts, authorizes or completes on a user's behalf, within limits the user sets. A traditional payment follows a fixed instruction. An agentic payment follows a goal, such as "pay approved invoices before the early-payment discount expires" or "buy the cheapest flight under $400 that lands before 6 pm." The agent decides when, how much and to whom.

That last row matters. AI agents fail differently from older automation. Their errors look reasonable, which is why controls must sit outside the model.

The IMF's 2026 note on agentic AI in payments describes payments in three layers:
The IMF's core warning is that AI agents are probabilistic, while payment systems need consistent, predictable outputs. The practical design rule follows from that: let agents reason at the intent layer, and put deterministic controls between the agent and the money.
Consumer "buy for me" agents get the headlines. Most enterprise value today sits in back-office payment work: invoices, orders, disputes, screening and cash. Here are the eight applications we see most often.

For more examples outside payments, see our guides to agentic AI use cases in banking and agentic AI examples in finance.
Each risk below includes what it looks like and the control that addresses it. The matrix maps each one to the rules it touches.

An agent pays more, pays the wrong party or pays at the wrong time, while technically holding valid credentials. In one case we've seen, a vendor-payment agent approved early payments based on ERP data and missed a contract PDF that said otherwise. Control: an explicit mandate (amount caps, allowed counterparties, timing rules), contract-aware context and approval above thresholds.
Instructions hidden in an invoice, email or web page can redirect an agent. The best-known example is the Freysa experiment, in which a user talked an AI agent into releasing a crypto prize pool it had been told never to transfer (Cambridge EJRR). Control: treat every external input as untrusted, restrict which tools the agent can use, allow-list payees and keep payment execution outside the model.
Small errors multiply across multi-step tasks: a misread IBAN, a wrong currency or a duplicate invoice. Control: validate every extracted field against master data, check for duplicates, run payee-name verification and send mismatches to human review.
Strong customer authentication (SCA), OTPs and 2FA assume a person is present. Agents break that assumption. Control: tokenized, agent-specific credentials, delegated-authority flows and step-up confirmation for unusual payments.
Agents can hide who is really paying and why. A screening service that times out can let a payment through by default. Control: screen every counterparty before payment, and fail closed. A timeout or an unclear result holds the payment (OWASP).
Fraudsters can deploy their own agents to probe merchants, test cards or pose as legitimate buyers. Control: Know Your Agent checks: cryptographic agent identity, a verified operator and trust levels that the agent cannot raise for itself.
Agents handle card data, bank details and personal data, and they can leak it through prompts, logs or third-party tools. Control: keep raw card data away from the agent (use tokens), mask PII, limit data to what the task needs and control where it is hosted.
Credit-limit changes, payment-plan offers or fraud blocks made by an agent can be hard to explain and may treat groups unfairly. Control: source-backed reasoning for each decision, recorded explanations, bias testing and human review for decisions that significantly affect people.
When an agent exceeds its authority, it's often unclear whether the consumer, the bank, the merchant or the agent provider carries the loss. See the liability section. Control: written mandates, consistent contracts across the payment chain and an audit trail that can serve as evidence.
Many agents running on the same model can act in the same way at the same moment. A model outage can stop payment operations, and agents widen the cyberattack surface (IMF). Control: multi-model routing with fallback, circuit breakers, rate limits and scenario testing for agent-specific threats.
No major jurisdiction has a dedicated law for agentic payments yet. AI agents in payments are still regulated: existing payment, AI, AML, consumer-protection and data laws all apply, and several changed in 2026.

European Union
PSD2's strong customer authentication still applies when an agent starts a payment. That's hard to reconcile with an agent acting while no person is present. Firms are relying on tokenized credentials and existing exemptions such as merchant-initiated transactions (Ashurst Perkins Coie).
PSD3 and the PSR are close to final. The final texts were published on 23 April 2026, with formal adoption pending. They extend payee name checks to all credit transfers and make providers liable for some impersonation fraud (summary). For agent builders, every agent-initiated transfer will need a name check, with mismatch warnings acted on before execution.
The EU AI Act applies where AI is used for high-risk purposes, including creditworthiness assessment. The Digital Omnibus (Regulation (EU) 2026/1744) entered into force on 27 July 2026 and moved Annex III high-risk duties from August 2026 to 2 December 2027 (National Law Review). Article 14 (human oversight) and Article 26 (deployer duties) are the provisions most relevant to payment agents. The Cambridge paper points out that, in an agent chain, it's often unclear who the "deployer" is: the consumer, the platform or the bank.
UK firms face SCA, the Payment Systems Regulator's mandatory APP fraud reimbursement, the FCA Consumer Duty, SM&CR accountability and UK GDPR rules on automated decisions. Freshfields recommends agent-aware fraud analytics, mapping controller and processor roles for every agent in a chain, and adding agent threats (tool misuse, identity spoofing, memory poisoning) to resilience testing.

There is no agent-specific federal rule yet. According to Goodwin:
The Consumer Bankers Association expects no fast federal action and urges the industry to set its own protections.
RBI's directions on authentication for digital payments apply from 1 April 2026. They allow and encourage risk-based authentication beyond SMS OTP, which suits agent flows that use device binding and tokenization (RBI). The RBI FREE-AI framework sets expectations on governance, accountability and consumer protection for AI in regulated entities. The DPDP Act governs personal data. See also our guide to AI agents in Indian fintech.
Card-network agent rules, Know Your Agent frameworks and AML expectations are moving faster than legislation. The OWASP cheat sheet on AML and sanctions for AI agent payments is the most practical technical baseline available.
Use this table to check any AI agent in a payment flow. Each row links a risk to the rules it touches and the minimum control.


Today, liability depends on the jurisdiction, the payment method and the contracts in place. No law yet assigns it to "the agent".
In every jurisdiction, three things decide who carries the loss in practice:
This is why governance isn't overhead. It is your evidence. For the wider framework, read our guide to agentic AI governance.

These are real Assistents deployments, anonymized by industry and region. Each shows the controls that made the agents safe to run with money, data or compliance decisions.

Across 30+ implementations in the US, UK and Europe, the Middle East, India, Australia, Canada and Africa, the pattern is the same: agents create value when they act within business context, under policy, with people in control of the decisions that matter.
Most AI tools help one person finish a task. Payments need something different: a system that runs a process from trigger to verified outcome, under control. Assistents is built for that. Each capability maps directly to what regulators expect.

All of this runs on one platform with five capabilities: Conversational Agents (answers and actions), Agentic BI (questions to insight and alerts), Document AI (documents to structured data), Voice AI (multilingual conversations to service) and Autonomous Workflows (events to completed work). It's backed by Forward Deployed Engineers, AI engineers and data scientists in the USA, Australia and India.
Explore Assistents for finance teams and Assistents for banking.

"We already have Copilot, Claude or ChatGPT." Those assistants are excellent for personal productivity: drafting, summarizing and analysis. Payment operations need organizational productivity: shared processes that connect teams, rules and systems and can be measured on cycle time, throughput, exceptions and control.
Note: the vendors below also offer enterprise and agent capabilities. This table compares typical use.

The Assistents path to value has six steps: Select → Connect → Configure → Validate → Operate → Expand. Start with the one payment process that matters most, agree how success will be measured, and build from there.

AI agents in payments are already in production. They read orders, screen transactions, resolve disputes and flag cash risks. Regulation is catching up through PSD3, the EU AI Act, card-network rules, RBI's authentication framework and emerging Know Your Agent standards. The firms that benefit will be the ones that put mandates, policy checks, human approval and audit trails between their agents and their money.
Ready to put governed AI agents to work in your payment operations? Book a tailored Assistents platform walkthrough and bring the process that matters most.
This article is for general information and isn't legal advice. Check specific obligations with qualified counsel in each jurisdiction.
Agentic payments are payments that an AI agent starts, authorizes or completes for a person or business, within limits the user sets. Unlike scheduled payments, the agent decides when, how much and to whom, based on a goal such as "pay approved invoices before the discount expires."
Yes. Visa Intelligent Commerce, Mastercard Agent Pay and Google's AP2 let agents pay with tokenized credentials under a user mandate. In businesses, agents already prepare and execute invoice payments, refunds and sales orders, usually with human approval above set thresholds.
It depends on the jurisdiction and the contracts. In the US, Regulation E may treat a transfer as authorized once a consumer gives credentials to an agent. EU and UK payment rules don't yet address agents. Clear mandates, aligned contracts and audit trails decide who carries the loss.
There's no agent-specific payments law yet, but existing rules apply: PSD2 and the upcoming PSD3 and PSR in the EU; SCA, Consumer Duty and APP reimbursement in the UK; Regulation E and Regulation Z in the US; and RBI authentication directions in India. AML, data-protection law and the EU AI Act also apply.
Not well yet, because SCA assumes a person is present. Firms use tokenized, agent-specific credentials, delegated-authority exemptions such as merchant-initiated transactions, and step-up confirmation for unusual payments. Card networks now require agent registration.
Know Your Agent verifies which AI agent is starting a transaction, who owns it and who authorized it. It extends KYC to software. In September 2026, Ant International, Mastercard and Visa began work on a shared KYA interoperability framework.
Yes, where AI is used for high-risk purposes such as creditworthiness assessment. After the 2026 Digital Omnibus, those high-risk obligations apply from 2 December 2027. AI-literacy duties already apply, and transparency duties are being phased in.
The biggest risks are unauthorized spending beyond the mandate, prompt injection, compounding errors, authentication gaps, AML and sanctions blind spots, malicious agents, data leakage, opaque decisions, unclear liability and systemic resilience risk.
They route every agent action through policy checks. Low-risk actions run automatically, medium-risk actions run within limits, and high-risk or unusual actions go to an authorized person for approval. Each step is logged.
Pick one bounded process, such as invoice-to-payment or dispute handling. Define the mandate, connect systems through governed connectors, add policy checks and approval tiers, test on real cases in shadow mode, then expand.

Agentic automation is the rising star posied to overtake RPA and bring about a new wave of intelligent automation. Explore the core concepts of agentic automation, how it works, real-life examples and strategies for a successful implementation in this ebook.
Discover the latest trends, best practices, and expert opinions that can reshape your perspective
