AI All

Blog space

Agentic payments security – when delegating purchases to AI makes sense, and what consumers, merchants, PSPs, marketplaces and issuers each risk

In this article you will learn:

  • When delegating purchases to an AI agent makes sense and when it creates too much risk
  • What consumers, merchants, PSPs, marketplaces and card issuers risk
  • How payment mandates, SCA, prompt injection and vendor lock-in affect security and liability

Updated: 20 August 2026

When do agentic payments make sense? Delegating a purchase to an AI agent is justified where the decision repeats, the product is defined by a parameter, and the amount sits within a limit whose loss would not change the buyer’s position. It stops making sense where quality judgement, negotiation, identity verification or an effective right of redress matters. Agentic payment security is not primarily about protecting the card number. It is about whether anyone can prove what the user actually wanted.

Canonical definition: An agent payment mandate is a documented scope of authority granted by a cardholder to an AI agent, specifying permitted merchants, a spend limit, a validity period and the conditions that require additional confirmation.

Agentic payments security – in brief:

  1. Risk has shifted from credential theft to intent manipulation. Visa‘s threat analysis describes counterfeit storefronts engineered specifically to exploit AI shopping agents: convincing, able to pass automated checks, priced well below market.
  2. Commerce has become the most targeted vertical. Akamai‘s 2026 State of the Internet research reports that nearly half of all AI bot traffic across its global network in the second half of 2025 sat in the commerce sector.
  3. The Visa Core Rules effective 18 April 2026 make the cardholder responsible for an agent’s actions as though they had initiated the transaction themselves. That is the single most consequential change for consumers.
  4. For merchants, vendor lock-in is real and operates across three layers at once: the token vault, the card-network relationship, and the choice of agentic protocol.
  5. In the EU there is no separate regime for agentic payments. PSD2 and the regulatory technical standards on strong customer authentication (SCA) continue to apply, while PSD3/PSR is only now reaching publication.
  6. Issuers lose their most useful piece of dispute evidence: the moment of conscious human decision. Mandate metadata has to replace it.
  7. Patronusec, an accredited QSA (Qualified Security Assessor) with an in-house penetration testing team, delivers risk assessment, security testing and compliance readiness for platforms launching AI agent-initiated payments.


When does delegating payments to an AI agent make sense, and when does it not?

Delegation makes sense where the purchase repeats, the product is defined by a parameter, and an agent error costs less than the decision time it saves. It fails for one-off high-value purchases, for goods requiring qualitative judgement, and wherever the right of redress depends on demonstrating what the buyer genuinely intended.

ScenarioDoes delegation make senseBoundary condition
Replenishment of known SKUs at low valueyesspend cap, closed merchant list, post-transaction notification
Travel booking within defined price and date limitsconditionallyconfirmation before the charge, verified refund policy
One-off high-value purchasenono repetition to justify a mandate, and disputes become expensive
Regulated goods or age-restricted itemsnoidentity verification must attach to the human, not the agent
B2B buying under an approval workflowconditionallythe mandate must mirror the authorisation matrix, not bypass it
Financial products, credit, insurancenocreditworthiness assessment falls under a separate regulatory regime
Subscriptions with automatic renewalconditionallymandate lifetime shorter than the service billing period

The common denominator is simple: the harder it is to express the expected outcome as a parameter, the worse delegation performs. An agent does not judge a seller’s credibility the way a person looking at a shopfront does, and it does not hesitate at an offer that is too good.

Delegation works where the expected outcome can be written as a parameter. Where it requires qualitative judgement, the agent replaces the buyer’s decision rather than merely their click.

What risks do agentic payments create for the ordinary consumer?

The primary consumer risk is not a leaked card number. It is a formally authorised transaction the buyer never wanted. Tokenisation protects the credential; nothing protects intent except the quality of the mandate and the care taken by the agent provider. Scheme rules effective 18 April 2026 assign the cardholder responsibility for the agent’s actions as if they had transacted themselves.

Four practical attack routes against the user:

  • Counterfeit storefronts built for agents. Visa describes fake shops that look legitimate, pass automated checks and undercut market pricing precisely so that an agent optimised for the best deal completes the purchase.
  • Prompt injection. A model processes the system prompt, the user’s request and text retrieved from a web page as a single stream. Content on a merchant page can therefore attempt to steer the agent. The OWASP GenAI Security Project’s 2026 edition identifies prompt injection as the technique running through most categories of agentic risk.
  • Agent impersonation. Merchants increasingly treat traffic from recognised agents more permissively than anonymous traffic, which creates a direct incentive to impersonate them.
  • Intent data spread. An agent shares far more context across parties than an order form: preferences, budget, and the history of attempted purchases.

What actually protects the consumer:

  • Strong authentication at the point the mandate is granted. In the EU, SCA requirements under PSD2 continue to apply and do not disappear because software initiates the payment.
  • A narrow mandate. A spend cap, merchant category and credential lifetime bound the maximum loss before anything goes wrong.
  • Immediate revocation. An agentic token can be withdrawn without blocking the card itself, which changes the cost of responding to an incident.
  • A consent trail. Without a record of what the user agreed to, a dispute reduces to one assertion against another.

In practice, a consumer should treat an agent mandate as a power of attorney rather than as saving a card in a shop. A power of attorney has a scope, an expiry and a route to revoke it.

What changes for an eCommerce merchant, and where does vendor lock-in arise?

A merchant gains a high-intent channel and loses its easiest dispute evidence: the navigation path, dwell time and device fingerprint of a human. Vendor lock-in in this model is genuine and operates across three layers simultaneously, and the costliest of them is not the technical one.

Three layers of supplier dependency:

  1. The token vault. A token issued by a payment service provider works only inside that provider’s ecosystem. Changing provider means migrating the vault or re-collecting card details from customers, which usually costs a share of stored payment methods.
  2. The card-network relationship. Network tokenisation depends on the identifier of the entity requesting the token. Where that identifier belongs to the provider rather than the merchant, credential portability stays in the provider’s hands regardless of what the commercial contract says.
  3. Protocol and agent platform. There is no single standard. The Agentic Commerce Protocol published by Stripe and OpenAI on 29 September 2025, the Agent Payments Protocol (AP2) developed by Google with a broad partner coalition, the Universal Commerce Protocol, and the Visa Trusted Agent Protocol introduced on 14 October 2025 as an agent identity layer all coexist. Committing to one as your only channel creates dependency on the platform that mediates the customer relationship.

Disintermediation compounds this. Once an agent mediates the conversation, conventional recognition tools such as logins and cookies lose their effect. Recognition shifts to the payment credential, which makes token ownership a strategic question rather than a technical one.

The sharpest financial consequence sits in disputes. Legal analyses of agentic payment authorisation note that the issuer must investigate and credit the consumer’s account, while the merchant bears the loss in practice. An elevated chargeback ratio then exposes the merchant to penalties from its acquirer.

Patronusec Insight: Across e-commerce engagements we see the same ordering error: teams choose an agent platform first and ask about token portability and card-network ownership second. Reversing that order costs little at design stage and a great deal two years later. The practical test is whether you could move agentic traffic to a second provider within a quarter without asking customers to re-enter their card details. If the answer is no, you have lock-in whatever the contract says. We run this class of architectural decision under a vCISO arrangement, before it hardens into technical debt.

What risks and opportunities do agentic payments create for payment providers?

A payment provider gains the position of trust layer between agent and merchant, and takes on two new duties in exchange: deciding whether a request comes from an authorised agent, and producing mandate evidence for disputes. Both map directly onto regulatory scope.

Four questions that determine the risk profile:

  • Licensing scope. Enabling payment initiation generally constitutes a regulated payment service. As law firms analysing this model observe, the technical service provider exclusion holds only where the entity never comes into possession of client funds at any point.
  • PCI DSS scope. Implementing a delegated payment specification directly means handling cardholder data. OpenAI’s documentation for that specification states the PCI scope impact explicitly.
  • Role under scheme rules. The Visa rules effective 18 April 2026 created the Agentic Payment Enabler category, with registration and PCI DSS compliance obligations attached. We break the obligations down in our asset on Agentic Payment Providers and network tokens under Visa rules.
  • Operational resilience. A provider serving financial entities falls within DORA requirements on ICT risk management and supplier registers, which the agentic layer extends into a wider dependency map.

The opportunity is symmetrical to the risk. Protocol neutrality becomes a product: a merchant unwilling to tie itself to one agent platform needs an intermediary that supports several protocols at once and maintains a single audit trail. That position cannot be occupied retrospectively, because it depends on controls and evidence built beforehand.


Launching support for agent-initiated payments and unsure how your regulatory scope changes?

Our gap analysis maps the data flow through your agentic architecture and identifies which components fall inside PCI DSS scope and which stay outside it. You receive the result as a document ready for conversations with your assessor and your acquirer.

Book a gap analysis


Why does a marketplace carry different risk from a single merchant?

A marketplace is accountable not only for its own checkout but for the credibility of sellers that an agent treats as a single source. A standalone shop protects its own brand; a marketplace becomes the place where a fraudulent listing borrows someone else’s reputation. Seller verification therefore stops being a commercial process and becomes a security control.

Four differences against a single-brand merchant:

  • Risk transfers from the listing to the platform. An agent comparing offers within a marketplace assumes each of them passed operator vetting. One unverified listing damages the credibility of the entire channel.
  • Trader traceability duties. The Digital Services Act (DSA) places obligations on online marketplaces regarding the traceability of traders using their services. In an agentic model that data stops being a formality and becomes a signal on which a purchase decision rests.
  • Dispute volume and composition. The share of “not as described” claims rises relative to classic unauthorised-transaction claims, because an agent buys to a parameter rather than to an expectation.
  • Automated traffic management. A marketplace has to separate an agent acting for a customer from a scraper or a card-testing bot. That requires identity verification at request level, not only rate limiting.

The opportunity is one a single merchant cannot reach: a marketplace holds comparative data on seller behaviour and can build its own trust signal for agents. Whoever first publishes verifiable seller quality attributes in a machine-readable format becomes the preferred source for agents.

For a marketplace, seller verification stops being a commercial process and becomes a security control, because an agent buying on a customer’s behalf does not assess a listing’s reputation the way a person would.

What do agentic payments mean for card issuers?

An issuer loses its most useful dispute evidence: the moment of conscious human decision tied to a specific basket. Adjudication has to rest instead on mandate metadata, meaning agent identity, scope of authority and consent timestamp. That is a change in how authorisation is constructed, not an improvement to dispute handling.

Four operational consequences on the issuer side:

  • Provisioning quality becomes a contractual parameter. Visa Token Service rules require active issuer participants to maintain a minimum monthly token provisioning approval rate of 90% per BIN, and every token must reflect the current account number and expiry date of the underlying credential.
  • Authentication moves to the moment the mandate is granted. Since the agent later acts without a human present, the weight of verification shifts to credential issuance. Hence the emphasis on step-up verification and passkeys in scheme programmes.
  • A new dispute category. Agent-initiated claims sit cleanly in neither the unauthorised-transaction nor the not-as-described bucket. Issuers need a handling path that reflects shared responsibility between user, agent provider and merchant.
  • Regulatory scope beyond cards. An issuer is a financial entity under DORA, and where it uses AI models for creditworthiness assessment it enters the high-risk category under the EU AI Act.

Patronusec Insight: The most common gap we see at financial institutions is not in tokenisation but in the risk register. An AI agent operating on customer credentials tends to be documented as a product feature rather than as a component processing authentication data. It therefore never reaches the threat analysis or the continuity testing scenarios. We recommend the opposite framing: treat the agent as an internal supplier with its own risk profile and its own test schedule. Under DORA, that is the difference between a register that survives supervisory scrutiny and one completed after an incident.

Which regulations beyond PCI DSS cover agentic payments?

Agentic payments have no dedicated legal regime in the EU. Existing payment services law, AI law and card scheme rules all apply, and their shared test is whether authorisation and user consent remain effective when software executes the transaction.

RegimeWhat it governs in an agentic contextStatus as at July 2026
PSD2 and the SCA technical standardsauthenticating the user when initiating a payment or establishing a mandate; licensing of payment servicesin force, with no separate regime for agents
PSD3 and the PSRconduct of business, liability, fraud protectionpolitically agreed and at publication stage; application follows a transition period [VERIFICATION REQUIRED for the current publication date]
EU AI Acttransparency duties towards users; high-risk classificationtransparency duties from 2 August 2026; standalone Annex III high-risk obligations deferred to 2 December 2027 under the Digital Omnibus endorsed by Parliament on 16 June 2026 and Council on 29 June 2026
Visa rules for agentic paymentsAPP and APE categories, mandatory tokenisation, cardholder consentin force since 18 April 2026
DORAICT risk management, supplier register, resilience testingapplies to financial entities
UK GDPR and EU GDPRprofiling and processing of purchase-intent dataunchanged

Three practical conclusions follow:

  • A shopping agent is usually not a high-risk AI system, whereas a creditworthiness model is. That distinction determines the scale of documentation duties and whether the deferral to 2 December 2027 affects you at all.
  • Automation does not remove the SCA obligation. The open question is where in the journey it is satisfied: at mandate creation, at each transaction, or under a risk-analysis exemption.
  • Scheme rules have outpaced statute. The operative source of obligations today is card scheme rulebooks rather than legislation, which means requirements change several times a year rather than once a legislative cycle.

Patronusec Insight: Compliance teams typically read agentic payments through payments law alone and skip the scheme rulebook layer, which changes several times a year and actually determines whether the model is permitted. Product teams make the mirror-image error, reading only the scheme specifications and missing statutory duties. A workable requirements map merges both sources into one register with a named owner, which in practice means an IT Compliance Officer maintaining it between assessments rather than a one-off legal review.


Not sure which requirements apply to your agentic payment model?

In a free scope assessment call we walk through your transaction flow and identify which regimes genuinely apply to you: PCI DSS, scheme rules, DORA, NIS2 or EU AI Act duties. The call takes 30 minutes and ends with obligations mapped to specific roles.

Book a scope assessment call


Myth and fact: what is most often misunderstood about agentic payment security?

The beliefs below recur in design documentation and supplier conversations. Each one leads to a specific control gap.

MYTH: If the agent never sees the card number, payment risk has been eliminated.
FACT: Tokenisation protects the credential, not the intent. A transaction executed on a valid token after the agent was manipulated is formally authorised and harder to challenge than conventional card fraud.

MYTH: The agent provider is liable for a wrong purchase made by its agent.
FACT: No generally applicable law assigns liability to the agent provider. Scheme rules effective 18 April 2026 direct it to the cardholder, and the economic burden of the dispute lands on the merchant in practice.

MYTH: Strong customer authentication does not apply because software initiates the transaction.
FACT: SCA requirements remain in force in the EU. What changes is the point at which they are satisfied, not whether they apply.

MYTH: Verifying the agent’s signature is enough to trust the transaction.
FACT: Agent identity verification proves who sent the request. It does not prove the user asked for that purchase, nor that the agent is free of instructions injected by a third party.

MYTH: Choosing an agentic protocol is a technical decision you can reverse later.
FACT: The protocol determines who owns the customer relationship, who holds credentials, and what evidence reaches a dispute. It is a multi-year architectural decision.

FAQ – Agentic Payments Security

Are agentic payments safer than ordinary card payments?

Partly. The credential is better protected, because the agent operates on a limited token rather than a card number. At the same time a new class of risk appears around manipulating the agent’s decision, which conventional payments do not face. The balance depends on mandate quality and merchant-side controls.

Who is liable if an AI agent buys something I did not want?

Visa rules effective 18 April 2026 make the cardholder responsible for the agent’s actions as though they had transacted themselves. General law does not resolve the question cleanly, and the economic burden of the dispute usually falls on the merchant. The scope of the mandate determines whether redress succeeds.

Does an online shop have to support agentic payments?

No such obligation exists. The decision should follow the economics: the value of an additional high-intent channel against the cost of higher returns and disputes. Retailers whose range needs advice gain less from this channel than retailers selling repeat, well-specified products.

What is vendor lock-in in agentic payments?

It is dependency on one supplier across three layers: a token vault that cannot be moved, a token requestor identifier owned by the provider rather than the merchant, and an agentic protocol that ties the shop to one platform. The practical test is whether you can change provider without asking customers to re-enter card details.

Does SCA apply to agent-initiated payments?

Yes. Agentic payments have no separate regime in the EU and remain within PSD2 and its technical standards on strong customer authentication. The open question is where the requirement is satisfied: at mandate creation, at each transaction, or under a risk-analysis exemption.

What does it cost to prepare a platform for secure agentic payments?

Cost depends on your role in the transaction chain, the number of integrations, and whether you need full certification or a gap analysis. Following a free scope assessment call we provide a fixed quotation with a delivery date. Clients combining security testing with assessment work receive preferential packages.

How do we start working with Patronusec on an agentic payments project?

We begin with a 30-minute call mapping your transaction flow and the roles in the chain. On that basis we recommend a scope: gap analysis, penetration testing of the integration layer, vCISO support, or the full PCI DSS certification path. You receive the recommendation in writing before any commercial decision.


A path from understanding the mechanism to operational readiness:

  1. Network tokens vs agentic tokens – 4 token types and the differences – the credential taxonomy every scope conversation starts from.
  2. Agentic Payment Providers and network tokens under Visa rules – 7 PCI DSS obligations – obligations attached to the APP and APE roles after 18 April 2026.
  3. Agentic Payments by Visa – what CEOs and CISOs must know – the strategic framing behind autonomous agent payments.
  4. AI usage policy for companies – 10 critical elements – the governance layer that control over agents depends on.
  5. AI-enhanced attacks – how AI changes cyber threats – the offensive side of the same shift.
  6. IT security testing – how to choose the right method – selecting the testing approach for the integration layer.

Agentic payments and security – free consultation

Patronusec is an accredited QSA with an in-house penetration testing team, working with clients across fintech, e-commerce, retail and financial services. We combine the assessor’s perspective with hands-on technical practice, so risk assessment and implementation planning happen inside a single engagement.

In a free 30-minute consultation we will help you:

  • establish which role in the agentic payment chain you actually occupy, and what follows from it,
  • identify which components of your agentic architecture fall inside PCI DSS scope,
  • assess your exposure to agent manipulation and plan a proportionate testing scope,
  • consolidate PCI DSS, scheme rules, DORA and EU AI Act duties into a single obligations map.
  • Book a free consultation | Gap analysis | Penetration testing | vCISO | DORA

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top