# Agentic Payments: Protocols and Liability When an AI Agent Pays

> AP2, ACP, x402, Visa TAP and Mastercard Agent Pay: how mandates and Know Your Agent work — and who is liable when an AI agent initiates a payment.

Author: Ksenia Voronova — Lawyer, Family Office (https://wiki.private.law/en/authors/voronova)
Last modified: 2026-08-14T13:11:00.000Z
Canonical: https://wiki.private.law/en/agentic-payments
Topics: banking
Jurisdictions: global, usa, eu, uk
Product tags: banking, stablecoin, compliance
Semantic tags: banking, stablecoin, compliance

---

## What an Agentic Payment Is — and Why It Is Not an Auto-Charge

First, a terminology split. In EU and UK payments law an "agent" is a person or company acting on behalf of a licensed payment institution; that construction is covered in the piece on [payment agents and passporting](https://wiki.private.law/en/payment-agents-eu). This article is about a different actor: an AI agent — software that decides what to buy and from whom, and initiates the payment itself within delegated authority. Neither PSD2 nor card network rules knew such a participant before 2025.

What separates an agentic payment from familiar automation is where the decision is made. A subscription or a stored card runs on a pre-agreed template: merchant, amount and frequency are fixed at the moment of consent. In the agentic model the model decides: it picks a merchant, an amount and a moment the user has never seen. Hence the three questions the new architecture answers: how to formalise authority \(mandates\), how to tell a legitimate agent from a malicious bot \(know your agent\), and who pays when things go wrong \(liability\). One line of forecast, with a caveat: estimates diverge by multiples across perimeters — McKinsey sees up to $5trn of agentic sales by 2030 globally, conservative US-only cuts near $1trn; direction, not plan.

## The Protocol Map

Five stacks emerged within eighteen months. Mastercard Agent Pay with its "agentic tokens" came first on 29 April 2025; the next day Visa unveiled [Intelligent Commerce](https://usa.visa.com/about-visa/newsroom/press-releases.releaseId.21361.html) — APIs and tokenised credentials for agents. September 2025 was the month of open standards: Google introduced the Agent Payments Protocol \(AP2\) with 60+ partners — from Mastercard and PayPal to American Express — alongside its A2A agent standard; OpenAI and Stripe open-sourced ACP and switched on Instant Checkout in ChatGPT, first with Etsy, then Shopify merchants; Coinbase and Cloudflare announced the x402 Foundation around a stablecoin protocol built on HTTP status 402. In October Visa added the [Trusted Agent Protocol](https://investor.visa.com/news/news-details/2025/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce/default.aspx) — an agent verification layer on the merchant side. By spring 2026 the map settled: Google [donated AP2 to the FIDO Alliance](https://fidoalliance.org/google-donates-agent-payments-protocol-to-fido-alliance/), taking single-platform control of the standard off the table.

| **Protocol** | **Standard holder** | **Rails** | **Trust mechanics** |
| --- | --- | --- | --- |
| AP2 | FIDO Alliance \(donated by Google, April 2026\) | cards, transfers, stablecoins | cryptographically signed mandates; "human not present" mode since v0.2 |
| ACP | OpenAI and Stripe, open specification | cards \(shared payment token\) | delegated payment token for a specific cart; live in ChatGPT |
| x402 | x402 Foundation \(Coinbase, Cloudflare\) | stablecoins | payment over HTTP 402: machine pays machine per request |
| Trusted Agent Protocol | Visa, built with Cloudflare | Visa cards | agent signature over HTTP Message Signatures |
| Agent Pay | Mastercard | Mastercard cards | agentic tokens + Verifiable Intent |

Read the table as layers of one payment, not a format war: ACP is the cart and checkout between agent and merchant, AP2 the authority framework, x402 the settlement primitive for machine micropayments, TAP and Agent Pay the networks' verification overlays. One payment can cross three layers at once.

## Mandates: A Power of Attorney Verified by Cryptography

Every stack's central construct is the mandate: a digital document signed with the user's key recording exactly what the agent may do. AP2 has two: an intent mandate sets the frame \("flights up to 300 dollars this week"\), a cart mandate signs the specific basket before the charge. In the "human not present" scenario the agent presents its intent mandate — and "did the client ask for this" turns from testimony into signature verification. The carrier of authority is verifiable credentials from the W3C standards family. Mastercard and Google are building the layer above: [Verifiable Intent](https://www.mastercard.com/us/en/news-and-trends/stories/2026/verifiable-intent.html), an open specification published on 5 March 2026, links identity, intent and action into one cryptographic trail with selective disclosure — the merchant sees only the minimum needed to decide. For the client this is the audit answer: the chain "mandate — token — transaction" reads in full after the fact.

## Know Your Agent: Identity Instead of CAPTCHA

The old web split traffic into humans and bots, with CAPTCHA guarding the border. Agentic commerce adds a third category — a bot with authority — which needs a KYC analogue: who issued the agent, whose will it executes, what its track record is. TAP solves this directly in HTTP: the agent signs requests cryptographically, the merchant verifies the signature and receives three blocks of data — the agent's intent, a returning-customer signal and, optionally, payment data. The cast is telling: beyond Cloudflare, feedback came from Adyen, Microsoft, Shopify, Stripe and other gateways — agent verification took root in infrastructure, not only at the network. Early startups outran the market: Skyfire with its KYA protocol left beta back in March 2025, but 2026 milestones for it and for Payman are scarce — the current status of both is unconfirmed.

## Who Answers for the Agent's Payment

The most expensive question in the architecture — and the least finished. The networks' approach so far is evolutionary: an agentic transaction inherits ordinary card dispute mechanics. According to secondary reviews, Visa runs agent transactions under its general VAMP fraud monitoring without a separate liability regime, while Mastercard drafts "rules of the road" for agentic commerce and builds its evidentiary base on Verifiable Intent. The gaps are plain: US Regulation E was written without the concept of an AI-initiated payment, and chargeback codes cannot distinguish three outcomes — the agent erred within its mandate, the agent exceeded the mandate, the client simply changed their mind. Until special rules arrive, the signed mandate is every party's primary defence document.

## Regulators: The EU Is Silent, the UK Is Building a Framework

The EU has no dedicated regime: agentic payments live under PSD2 and the SCA RTS, and there sits the core collision: SCA ties authentication to a human through knowledge, possession and inherence, and delegation to an agent does not fit that logic. Legal reviews record the state of play: no dedicated regime, no published EBA position, future guidance "cannot be ruled out". The [PSD3/PSR package](https://wiki.private.law/en/psd3-psr) was drafted before the agentic wave, but it extends liability to technical service providers and wallets — the likely door through which the agentic agenda enters European law closer to 2028.

The UK named the gap out loud first. In July 2026 HM Treasury made agentic payments one of five priorities of its financial services AI adoption plan and announced a trust framework with three elements: liability for agent transactions, know your agent, machine-to-machine authentication. The FCA's parallel Mills Review delivered a diagnosis that travels: the current rulebook was "designed around a human approving each transaction".

## The Stablecoin Branch and the First Institutions

Card stacks solve "an agent buys from a merchant". The second branch is machine micro-settlement, where cards do not work: acquiring fees kill a quarter-cent payment. x402 revived HTTP status 402 Payment Required, dormant since the 1990s: the server answers the agent with an invoice, the agent pays in stablecoin and repeats the request. The scale is visible at Cloudflare: [over a billion 402 responses a year](https://blog.cloudflare.com/x402/) go out to bots and crawlers — each a potential paid session: crawling, an API call, a data feed. The settlement layer is covered in the [stablecoins overview](https://wiki.private.law/en/stablecoins); the legal frame for dollar issuers is set by the [GENIUS Act](https://wiki.private.law/en/genius-act).

Beneath the protocols, institutions appear. Catena Labs, founded by Circle co-founder Sean Neville, raised a $30m Series A and filed for an OCC national trust charter for an "AI-native" financial institution serving agents; the route itself is mapped in the [OCC trust charters piece](https://wiki.private.law/en/occ-trust-charter). On 8 April 2026 Meow launched agentic banking: a business account that an agent — via Claude, ChatGPT or Gemini — opens and runs, with the human as confirming authority. Stripe, with its stablecoin arm [Bridge](https://wiki.private.law/en/bridge-stripe), covers both branches at once — card-based ACP and stablecoin settlement.

## Treasury Under AI: Limits, Mandates, Audit Trail

Agentic treasury is no longer a hypothesis: agent features run in [Ramp](https://wiki.private.law/en/ramp) for corporate finance, while [Arca](https://wiki.private.law/en/arca) and [Arta Finance](https://wiki.private.law/en/arta-finance) pull the wealth segment the same way. Delegation discipline comes down to three artefacts. Limits: your own per-transaction and per-period ceilings plus counterparty allowlists — set on your side, not only in the platform's settings. Mandates: a written delegation policy — which payment classes the agent executes alone, what requires a human; in protocol terms, narrow intent mandates with short lifetimes. Audit trail: an exportable log of mandates, signatures and transactions — dispute evidence, auditor material and tax defence at once. And an iron rule on top: an agent never extends its own mandate; any extension of authority is made by a human outside the agent's channel — the basic defence against prompt injection.

## The 2026–2028 Niches: KYA Infrastructure and Agent Charters

The window looks like early fintech: standards have settled in neutral homes — the FIDO Alliance and the x402 Foundation — while network liability rules and regulatory frameworks are not yet final; infrastructure positions are taken in this phase. The working niches: KYA infrastructure — agent registries, incident attribution, agent-risk insurance; agent-facing trust charters along Catena's route; dispute services turning mandate evidence into won chargeback cases; a "treasury shield" for family offices — limits, mandates and monitoring assembled on top of third-party agents.

> 🍓 An agentic payment is a delegation of authority, not an automation of charges, so the legal construction matters more than the technical one. The law is catching up with practice: the EU keeps agents inside the old PSD2/SCA frame, the US runs on card network rules, and only the UK has announced a dedicated trust framework. Until the rules are final, the working presumption holds: whoever released the agent and granted its authority answers for its payment. Basic hygiene: narrow cryptographically signed mandates, your own limits, and an exportable audit trail for every operation.

## Q/A

### **How does an agentic payment differ from a subscription or a stored card**

A subscription is a pre-agreed template: merchant, amount and period are known at the moment of consent. An agentic payment is delegation: the agent itself picks the merchant, amount and moment within the mandate's frame. Hence the different infrastructure: signed authority instead of a "save card" checkbox, agent verification instead of CAPTCHA, and a new subject of dispute — whether the agent stayed within its mandate.

### **Who is liable if the agent paid for the wrong thing**

Today the dispute runs through ordinary card mechanics — chargeback against the merchant, claim to the issuer: agent-specific liability rules are not final, and Regulation E and PSD2 do not know the agentic scenario. The outcome turns on evidence — the signed mandate and the agent's action log. No mandate, no case.

### **Can an agent be trusted with treasury already**

Operational tasks — yes, with guardrails: Ramp's agent features and Meow's accounts run in production. The sensible perimeter is execution within narrow mandates: categories and limits set by a human, large and non-standard payments confirmed, every step logged. Full treasury autonomy sits beyond reasonable risk at least until the networks' rules and the UK framework are final.

### **Which protocol will win**

No need to pick one: these are layers, not rivals. ACP is already live in ChatGPT, AP2 became a consortium standard under FIDO's wing, x402 took machine micropayments, TAP and Agent Pay are the networks' verification overlays. The portable investment is mandate discipline: authority, limits and audit trail survive any protocol change.

---

## FAQ

### How does an agentic payment differ from a subscription or a stored card

A subscription is a pre-agreed template: merchant, amount and period are known at the moment of consent. An agentic payment is delegation: the agent itself picks the merchant, amount and moment within the mandate's frame. Hence the different infrastructure: signed authority instead of a "save card" checkbox, agent verification instead of CAPTCHA, and a new subject of dispute — whether the agent stayed within its mandate.

### Who is liable if the agent paid for the wrong thing

Today the dispute runs through ordinary card mechanics — chargeback against the merchant, claim to the issuer: agent-specific liability rules are not final, and Regulation E and PSD2 do not know the agentic scenario. The outcome turns on evidence — the signed mandate and the agent's action log. No mandate, no case.

### Can an agent be trusted with treasury already

Operational tasks — yes, with guardrails: Ramp's agent features and Meow's accounts run in production. The sensible perimeter is execution within narrow mandates: categories and limits set by a human, large and non-standard payments confirmed, every step logged. Full treasury autonomy sits beyond reasonable risk at least until the networks' rules and the UK framework are final.

### Which protocol will win

No need to pick one: these are layers, not rivals. ACP is already live in ChatGPT, AP2 became a consortium standard under FIDO's wing, x402 took machine micropayments, TAP and Agent Pay are the networks' verification overlays. The portable investment is mandate discipline: authority, limits and audit trail survive any protocol change.
