Skip to main content

Opinion

Securing agentic commerce: who should hold the power to pay?

During May, I decided to look more closely at how the payments industry is racing to secure a world where AI agents do the buying. My view is that the hardest question is not whether agents can pay, but whether they should ever hold the power to.

The promise of agentic commerce is a frictionless one. You state a need. An agent anticipates, compares, negotiates, assembles the basket and checks out, while you touch nothing. The prize is large. McKinsey's October 2025 report, The agentic commerce opportunity: How AI agents are ushering in a new era for consumers and merchants, suggests agentic commerce could orchestrate $900 billion to $1 trillion of US retail revenue by 2030, and $3–5 trillion globally. McKinsey's point is that this may scale faster than previous shifts because agents can ride the rails humans already use: websites, APIs, loyalty programmes and existing checkout flows. However, riding existing rails is exactly where the security question begins.

Power to execute a payment should remain inside controlled payments infrastructure

To my mind that question is not the one the industry tends to ask: it is not "can an agent be allowed to pay?", but "should an agent ever hold the power to pay at all?" My answer to that vital second question is an emphatic "no". An agent should carry a constrained, time-limited, provable instruction but the power to execute the payment itself should remain inside controlled, certified infrastructure that the agent cannot reach into.

The reason is that agentic commerce quietly conflates two very different jobs. The first is letting an agent understand commerce: the product, the basket, delivery, loyalty, the customer's intent. The second is executing a payment: tokenised credentials, strong authentication, authorisation, settlement and dispute handling.

Model Context Protocol (MCP), the open standard Anthropic launched in November 2024 to let agents connect to external systems, solves the first job well. However, MCP is not, and was never meant to be, a payment standard. It does not replace PCI DSS, tokenisation, Strong Customer Authentication, EMV, 3DS or acquirer processing. But if you collapse the two jobs together, you unwittingly hand an AI system structured access to payment APIs, refunds and credentials. The questions that then matter are uncomfortable: "what is the agent allowed to call, under whose authority, with what limits, and with what audit trail?"

What is striking is that the rest of the market, building independently, is converging on the same instinct: keep payment power away from the agent. Mastercard's Agent Pay programme, announced in April 2025, introduced Agentic Tokens built on the tokenisation that already secures contactless and card-on-file, alongside Mastercard Payment Passkeys.

Visa frames its own agentic work around tokenisation, replacing card details so they are never stored or transmitted in plain text by an agent, and around Strong Customer Authentication, particularly in Europe.

OpenAI and Stripe's Agentic Commerce Protocol, which has powered ChatGPT's Instant Checkout since September 2025, keeps the merchant as merchant of record and issues delegated payment credentials that are single use, capped by amount and expiry, and scoped so they cannot be used outside the approved purchase. Google's Agent Payments Protocol (AP2), published in September 2025, takes a complementary route: cryptographically signed 'mandates' that act as non-repudiable proof of a user's instructions, with configurable guardrails and an audit trail.

The infrastructure players are saying the same thing in their own language. Checkout.com describes a stack of network tokenisation, agent identifiers, passkeys and biometrics, 'Know Your Agent' identification and customer notifications. Thales argues tokenisation should become the backbone for securing AI agent shopping. None of these is letting the agent hold raw card data. Every one of them is, in effect, reducing the agent to a bearer of instructions.

PCI guidance needs to be translated into standards

The standards body is moving too, if more slowly. The PCI Security Standards Council, the body behind Mobile Payments on COTS (MPoC), published in November 2022, which combined and superseded the earlier SPoC and CPoC standards, sets out its position in AI Principles: Securing the Use of AI in Payment Environments, in September 2025. It is clear that agentic offerings must be deployed in line with applicable PCI requirements, and it already flags sensitive-data exposure and the need to keep secrets out of AI flows.

The momentum is real enough that Stripe joined the Council as a Principal Participating Organization in April 2026, saying it wanted payment standards to "remain flexible for the many ways that card-based payments are accepted in the internet economy". However, principles are not yet a standard, and agentic offerings are arriving faster than the rules to govern them.

Beware of removing friction everywhere

There is a deeper lesson here that the industry should not lose in the rush to remove friction, and it is this: frictionless everywhere is a proven failure mode. We have run this experiment before. Card-not-present commerce became seamless, and card-not-present fraud rose with it, which is precisely why Europe mandated Strong Customer Authentication under PSD2.

SCA is, at heart, regulators putting friction back at the moment money moves. The UK's faster payment rails made bank transfers instant, irreversible and effortless, and became the preferred channel for authorised push payment fraud. This is why Confirmation of Payee was introduced and mandatory reimbursement rules followed in October 2024. In both cases, the friction came back, late and expensively, after frictionless transacting had already done some damage.

The discipline, then, is not less friction. It is friction in the right place — at the moment of value and risk, and none anywhere else. Put another way, the friction that matters is verification: a deliberate, well-placed check that the instruction is genuine before the money moves. An agent that holds only a signed, time-bound instruction, verified at the point of execution, is friction designed in at exactly the right moment. An agent that holds payment power is friction removed at exactly the wrong point.

This is where the market still has a gap to close. If every scheme, platform and PSP builds its own proprietary enforcement, merchants inherit fragmentation and lock-in at precisely the layer that ought to be neutral, certified and common.

Payment standard must enforce the agent's constrained instruction deterministically

What agentic commerce needs is an enforcement layer that is independent of any single network, certified to the standards that already govern software-based acceptance, device-agnostic, and fully auditable. In this way, it enforces the agent's constrained instruction deterministically, whoever's agent it is. Building that independent layer for payments, authentication and verification, is the work we are focused on at Mypinpad; but the principle matters whoever delivers it.

Which brings the question back to the Council. The existing AI principles are the right start, but a genuine agentic-commerce standard will need to go further and certify the transaction-control architecture around the agent, not merely the agent's behaviour.

The standard I would argue for is simple to state and hard to game: the agent should never hold payment power. It should hold a constrained, time-limited, provable instruction. And the payment system, whether PSP, acquirer, issuer, network or merchant, must enforce that instruction deterministically at the back end. Get that right, and agentic commerce can have the frictionless front-end it promises, built on a back end that never has to trust the agent at all.

Talk to Us

Ready to explore what Mypinpad can do for you?

Certified. Independent. Deployed across 28 countries. Let's talk about your use case.

Get in Touch