
Banks are facing a new security and compliance challenge as artificial intelligence agents move beyond helping consumers search for products and begin making purchases and payments on their behalf.
The development is shifting part of the payment process from direct human action to software that can interpret instructions, make decisions and execute transactions with limited human involvement.
Financial institutions have spent decades building systems around “know your customer” requirements. They are now confronting a related question: who is the AI agent acting for the customer, who authorized it, and what is it permitted to do?
Zhuoqun Bian, president of Ant Digital Technologies, raised the issue at the Fortune Leaders Forum in Macau on September 8. She said financial institutions already perform know-your-customer checks when transactions are initiated, but the development of an agent economy creates the additional need to identify the agent, its owner and the person who authorized it. Fortune’s report detailed her comments.
Ant International, the global payments arm of Ant Group, said on September 6 that it had begun working with Mastercard and Visa on a “know your agent” interoperability framework. The initiative is intended to help card networks, digital wallets and marketplaces recognize trusted AI agents across different ecosystems.
The companies are working through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore.
The issue is becoming more urgent as payment companies move agentic transactions from demonstrations toward live environments.
Visa said on July 2 that AI agents were completing live purchases with participating merchants across Europe. The agents could browse products, select items and initiate purchases according to consumer-defined parameters. Visa said its infrastructure connects banks, merchants and AI systems for authenticated agentic transactions. Visa’s announcement described the transactions as a move beyond controlled storefront testing.
Mastercard has also been developing infrastructure intended to establish stronger links between user authorization and actions taken by AI systems.
In March, Mastercard introduced Verifiable Intent, an open, standards-based trust layer developed with Google for agentic commerce. According to Mastercard, the system is intended to create a tamper-resistant record of what a user authorized, providing a shared record for consumers, merchants and financial institutions. Mastercard’s description of Verifiable Intent says it is designed to connect identity, intent and action while providing an audit trail for disputes.
Mastercard has also described a broader model in which agents are credentialed, given defined permissions and spending limits, and allowed to transact within those rules. Its Agent Pay for Machines initiative is designed to support machine-driven transactions across cards, accounts and stablecoins. Mastercard’s June announcement describes credentialing, permissioning, transaction processing and settlement as core parts of the system.
Banco Santander and Mastercard demonstrated another step in March, announcing what they described as Europe’s first live end-to-end payment executed by an AI agent within a regulated banking framework.
The transaction was carried out in a controlled environment using Mastercard Agent Pay but processed through Santander’s live payments infrastructure. The system allowed an AI agent to initiate and execute a payment within predefined limits and permissions. Santander said the exercise was a pilot and not a commercial rollout. Santander’s announcement provides details of the test.
The central security problem is that AI systems do not behave like traditional payment software.
An International Monetary Fund analysis published in April described agentic AI systems as probabilistic and adaptive. The same prompt can produce different outputs, while payment systems are built around predictable rules, legal certainty and clearly defined accountability.
The IMF identified authorization, settlement, liquidity management, compliance and operational resilience as areas that could be affected as agents become capable of initiating transactions. It also highlighted risks involving cybersecurity, traceability, opacity, systemic effects and legal uncertainty.
The Bank of England has raised similar concerns. Its July 2026 Financial Stability Report said autonomous AI systems are becoming an area of rapid innovation in payments and could increase the speed and scale of financial flows.
The Bank also identified unresolved questions involving authorization, traceability, fraud detection, liability, resilience, legal accountability and the arrangements needed when payments fail, are disputed or have to be reversed. The Bank of England’s report also highlighted the tension between probabilistic AI behaviour and the deterministic requirements of payment infrastructure.
Giving an AI agent access to money creates security risks that go beyond stolen card numbers or compromised passwords.
A malicious instruction encountered during an agent’s interaction with a website, tool or other external system could potentially affect what the agent attempts to do. The greater the agent’s autonomy, the greater the potential scale of an error or compromise.
Amazon Web Services has introduced controls aimed at reducing those risks. Its AgentCore payments service, which reached general availability on August 18, allows AI agents to pay for paid APIs, MCP servers and content. AWS says spending limits are enforced at the infrastructure layer, outside the AI model.
The service supports time-bounded payment sessions, configurable spending limits and short-lived tokens. AWS also says agents should not receive the user’s raw card details and that payment credentials should remain outside agent code. AWS’s general-availability announcement and its security guidance describe these controls in detail.
American Express is also building mechanisms around identity, authorization and customer intent.
Its Agentic Commerce Experiences developer kit includes agent registration, account enablement, intent intelligence, payment credentials and cart context. American Express says verified AI agents can use tokenized payment credentials, while customer purchase intent can be captured to support authentication, authorization and dispute handling.
The company has also announced Amex Agent Purchase Protection. Under the planned programme, eligible customers could receive protection from charges resulting from certain AI-agent errors when the agent is registered, the customer has authorized it and authenticated purchase intent has been provided to American Express. American Express’ agentic commerce documentation says claims would be subject to review and that subjective or non-verifiable purchase instructions may not qualify.
The scale of potential adoption is adding to the industry’s urgency. McKinsey has estimated that AI agents could orchestrate as much as $5 trillion in global consumer spending by 2030. That figure is a projection rather than a measure of current spending.
Evidence of current activity also needs to be treated carefully.
TRM Labs reported on September 9 that roughly $52.7 million had moved across 198.9 million settlement transactions mediated by known x402 facilitators across Base, Solana and Polygon since May 2025. But the company cautioned that blockchain records cannot by themselves establish whether a transaction was made by an AI agent, a scheduled script or conventional automation.
After filtering self-payments, concentrated flows and sellers with very few buyers, TRM said about half of the settled volume was removed. Its analysis concluded that the headline x402 transaction figures should not automatically be treated as the size of the AI-agent payments market. TRM Labs’ analysis explains the limitation.
Consumer adoption is also showing a gap between willingness to use AI and willingness to give it direct control over payments.
Visa’s 2026 Stay Secure study found that 88% of surveyed consumers in Nigeria had used AI to assist with shopping, while 97% said AI-powered tools make online shopping faster and easier.
At the same time, only 34% said they currently trust AI agents to complete checkout. The survey found that 89% believe AI will play a critical role in future fraud protection, while 64% said real-time alerts about suspicious activity would make them feel more secure when paying online.
Only 7% of respondents said consumers should be primarily responsible for protection against fraud when shopping online.
The Nigerian findings came from Visa’s Stay Secure study, conducted by Wakefield Research between January and February 2026 among 5,800 adults across 17 Central and Eastern Europe, Middle East and Africa markets, including Nigeria. Visa’s Nigeria report provides the methodology and findings.
The emerging payment model therefore requires more than traditional customer authentication. Banks and payment companies must also determine the identity of an agent, the identity of the person who delegated authority, the purpose of the transaction and the limits placed on the agent.
That also creates a difficult liability question. When an autonomous system makes an unauthorized or mistaken purchase, responsibility could potentially involve the customer, agent provider, bank, payment network, merchant or another company participating in the transaction.
JPMorgan Private Bank managing director Benson Wong told Fortune that the difficulty is increasingly linked to operating models, processes, compliance and controls rather than whether the underlying technology can function. He warned that the consequences of a failure can scale with the agent’s level of autonomy.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.


