Skip to main content
Home » Agentic Payments & AI Literacy » How can agentic payments and trust move at the same speed?
Agentic Payments & AI Literacy

How can agentic payments and trust move at the same speed?

Benjamin David

Head of Intelligence, The Payments Association

Charlotte Amalie Schiøttz Hassing

Head of Product, Banking Circle

Dal Sahota

Global Director of Trusted Payments, London Stock Exchange Group, LSEG

AI agents are already discovering, choosing and paying on a business’s behalf, but almost nobody can prove which one acted or on whose authority. Narrowing that gap requires more than technology, according to industry leaders.


How far would you trust an artificial intelligence agent to spend your money without checking first? Agentic payments enable software to determine what to buy, choose a supplier and complete the payment, without a person approving each step.

Agentic payments require accountability

The agentic payments pitch sounds like a dream: software that can shop, negotiate and pay faster than any person. However, the potential financial nightmare is simple: without the right guardrails or parameters, an agent can overstep, and almost nobody today can say who is accountable.

Agentic payments are still new enough that the outcome is not decided. Identity, authority, verification and the rails carrying the money, built properly now, are what separate the dream from the nightmare.

The technology is live but regulation is catching up

The picture right now is mixed: the technology is already live and moving real money, but trust is lagging, with good reason. Alipay’s AI Pay processed more than 120 million transactions in a single week in February 2026. Further, agentic AI is projected to deliver up to $450 billion in global economic value by 2028 through revenue growth and cost savings, according to a 2025 report by the Capgemini Research Institute.

Yet, the same research showed confidence in fully autonomous AI agents fell from 43% to 27% in a year, with only 2% of organisations deploying them at scale. Regulation lags further behind in the UK. The Government’s Financial Services AI adoption plan, published in July 2026, found the UK has no definition of agent identity, no verification requirement and no operator registry.

Nobody can confirm what merchants suspect

Benjamin David, head of intelligence at The Payments Association (TPA), the industry’s trade body, commissioned research into what his own report calls an unresolved liability question: how many merchants believe agentic activity is already happening on their platforms, and how confident they are in the rules that would apply if something goes wrong.

The report published by TPA’s Merchant Payments Working Group in March 2026, titled Agentic commerce in UK retail: an unresolved liability question, surveyed 100 senior finance and risk decision-makers at UK online retailers. It found that 58% believed AI agents had already transacted on their platforms, 72% were preparing or planning for AI agents, and only 10% ruled out agent activity.

Yet, confidence in the frameworks surrounding that activity is significantly lower. Only 41% of merchants said they were very confident in the liability frameworks around agentic transactions.

B2B agentic payments beat consumer hype

Charlotte Schiøttz Hassing, head of products at Banking Circle, which settles payments for over 900 regulated financial institutions, went looking for that activity in her own data. She found nothing definitive. “We can’t find any clear indicator that points to [identify] agentic payments,” she admits.

Much of the media coverage of agentic payments assumes a consumer story: an agent booking a hotel or comparing trainers. Schiøttz Hassing thinks that misses the real opportunity. A shopper’s preferences are hard for software to weigh. A business paying a repeat supplier under an existing contract has no such difficulty, which suits an agent far better. The stakes differ too. A business whose agent pays the wrong supplier answers for it publicly; an individual’s bad AI purchase rarely makes the news.

Old fraud finds a new target

Dal Sahota, global director of trusted payments at LSEG Risk Intelligence and a fraud specialist, has already watched agents issue refunds a human would have refused, because the decision carries judgement fixed rules cannot capture. “It’s veering outside whatever guardrails existed, or didn’t,” he says. No fraud, no breach, just software repeating a subjective call it was never designed to make.

A human makes an error once. Meanwhile, an agent can repeat “the same mistake a thousand times before anyone notices,” Schiøttz Hassing says. “Detection latency, kill switches and the ability to unwind a payment are as important as pre-authorisation controls,” she adds.

Fraud aimed at people does not disappear once the buyer is a machine. It moves. Sahota calls the range of exploits available to fraudsters, spanning software, human psychology and scam businesses, “exponential.” UK Finance’s latest Annual Fraud Report, published in June 2026, indicated that authorised push payment fraud losses reached £576.4 million in 2025, up 19% on the year. His organisation found 97% of victims change their behaviour afterwards. “The psychological damage is far greater than the financial loss,” he says.

Fraud aimed at people does not disappear once the buyer is a machine. It moves

KYA framework: identity, authority, unclear liability

David argues that any Know Your Agent (KYA) framework needs to answer three questions: Which agent is this? Who does it represent? What is it allowed to do? He wants to fix its meaning before the industry blurs it. “KYA risks becoming one of those phrases everybody uses without necessarily agreeing what it means,” he says. “Authentication tells us who or what is acting,” he adds. “It doesn’t strictly tell us whether that action was authorised.” Knowing which agent you are dealing with means little if you cannot tell whether its owner permitted £50 or £5,000.

No country has a settled answer on regulation yet. “I think it’s a bit of a laggard overall at the industry level,” Sahota says of global rule-making on a technology still emerging everywhere at once. David points to India, where a framework built around the Unified Payments Interface (UPI), the country’s real-time payment network, reportedly includes spending limits and identity checks. Sahota draws a sharper precedent from history: just as anti-money laundering (AML) regulation matured through successive reforms in the early 2000s, a comparable transformation will likely emerge to address agentic fraud.

None of the three could agree on who should cover the loss when an agentic payment fails. The Payments Association’s survey also asked merchants who should pay if an agent completes a £2,000 purchase after being told only to research options; no answer reached even a quarter of respondents. Schiøttz Hassing expects responsibility to spread rather than settle on one link in the chain, as a purchase passes through search, supplier choice and settlement in turn. “Liability will not rest with a single party,” she says.

Counting the cost of waiting for a crisis

Sahota does not think a serious agentic fraud case is far off. “I wouldn’t bet against it,” he says, though he doubts one event alone forces change. “What drives a catalyst for change is organisations coming together to shape regulation in the marketplace,” he adds.

David argues that preparation should come before such an event. “We shouldn’t wait for a catastrophic event to force AI regulation to catch up.” By 2029, David expects significantly more payment decision-making to have moved from people to software: an agent identifying a need, comparing suppliers, choosing one and paying, all inside limits set weeks earlier. “We may move from a world where a human authorises every payment to one where the human authorises the mandate,” he says. Namely: spend up to this amount, with these suppliers, for that purpose.

Build controls first to avoid failure

Sahota advises a cautious approach, stating which types of agentic payment are permissible. Then build the controls and testing that prove the policy is followed, the same structure many organisations use for AML compliance. “You may go a little bit slower, but you will go further,” he says. “If you go fast, you’re likely to fail.”

Sahota reached for a line from Vernon Law, the American baseball pitcher: “Experience is a hard teacher because she gives the test first, the lesson afterwards.” Derivatives arrived before their safeguards, as did the rules against money laundering. Agentic payments are still early enough that, this time, the order could run the other way.

Next article