security

When AI Starts Making Payments: The New Challenge of Trusting a Machine

September 30, 2026 4 min read
When AI Starts Making Payments: The New Challenge of Trusting a Machine

For years, the evolution of digital commerce focused on reducing the number of steps required to make a purchase.

First came online stores. Then came mobile apps, digital wallets, and one-click payments. Now, a new stage is emerging: the artificial intelligence agent capable of searching, comparing, deciding, and executing a purchase on the user's behalf.

We are no longer talking merely about using AI to recommend what to buy. We are talking about allowing a machine to act on human intent and giving it the authorization to carry that intent through to payment.

And this changes a fundamental question for financial institutions. It is no longer enough to simply know who is performing a transaction. It will also be necessary to understand who authorized the agent, what it was permitted to do, and whether the action it is executing truly aligns with that intent.

From Assistant to Agent

The difference may seem small, but it carries significant implications. An AI assistant can recommend a product, show alternatives, or help the user compare prices. An agent can take the next step. It can select an option, fill in information, initiate a purchase, and—under specific authorization mechanisms—participate in executing the payment.

Visa describes this evolution as "agentic commerce" and notes that agents will be able to perform tasks such as making purchases, managing subscriptions, or negotiating on behalf of users. The company also published research on consumer trust in this model.

Meanwhile, in September, Mastercard launched new capabilities to connect AI agents with merchants and enable user-authorized transactions. The company envisions agents that can discover products, build a purchase, and complete the transaction using secure payment credentials.

The shift, therefore, is no longer purely conceptual. The infrastructure for this type of commerce is already being built. The issue isn't just whether the payment is valid.

This is where one of the major security challenges arises. Imagine a user authorizes an agent to purchase a plane ticket for up to US$500. The agent finds an option for US$430.

So far, everything seems correct.

But what happens if the agent subsequently receives manipulated instructions, misinterprets a condition, or attempts to carry out a transaction different from the one the user authorized?

From a traditional perspective, a transaction might appear perfectly valid.

  • The credentials are legitimate.
  • The account belongs to the user.
  • The payment is technically authorized.

But there is an additional question:

Does the transaction align with the user's original intent?

This distinction between authentication, authorization, and intent will become increasingly important as machines begin to act directly within financial systems. Identity will no longer be solely human.

The traditional digital identity model is built around a person.

  • A person logs in.
  • A person is authenticated.
  • A person confirms a transaction.

In an "agentic" environment, a new participant appears between the user and the financial service: the agent.

This introduces a new layer of trust.

The system must be able to distinguish, for example, between:

  • The user establishing the intent.
  • The agent authorized to act.
  • The merchant or service being interacted with.
  • The transaction ultimately executed.
  • The limits within which that transaction was permitted.

The question is no longer just "Is this person authenticated?"

It may become:

"Was this action executed by an authorized agent, within established limits, and in accordance with the user's intent?"

The challenge for banks and fintechs

The arrival of autonomous agents can create much more seamless experiences, but it can also create new risk surfaces.

An agent will have access to information, permissions, and—potentially—the ability to initiate actions with financial consequences. This means that institutions will need to consider controls that allow for the assessment not only of the user's identity but also of the context in which an action was generated.

The Bank for International Settlements (BIS) is already addressing this transition from a supervisory perspective. In September 2026, its Financial Stability Institute noted that banks are incorporating AI into areas such as fraud detection, compliance, and risk management, while supervisors are also exploring its use. At the same time, it warns that AI adoption must take into account technological, operational, and governance risks.

This will be especially relevant as AI shifts from merely analyzing information to executing actions.

Trust must travel with the transaction. The traditional model might view the payment as the final step in the process. But when an agent participates in the journey, trust must accompany the operation from a much earlier stage.

It will be necessary to understand the context of the request, the permissions granted, the established restrictions, and any changes occurring during the interaction.

Mastercard highlights this very need, noting that agent-based commerce requires the continuous assessment of elements such as trust, intent, consent, and risk, in addition to verifying the agent itself.

This represents a significant shift. Security is no longer just a barrier placed before the payment.

It becomes a capability to continuously interpret whether the action taking place remains consistent with what was intended.

Are we ready to trust a machine?

Adoption still faces an obvious barrier: trust.

Research published by Visa in September 2026 found that only 23% of surveyed US consumers would currently trust generative AI to manage payments on their behalf. However, the same study shows that trust levels shift when recognized brands and payment mechanisms are involved.

This reveals something important.

The challenge is not solely technological.

It is also a matter of trust.

Users will need to know what an agent can do, what information it can use, what its limits are, and how they can regain control when things do not go as expected.

Financial institutions will have to answer these same questions from the perspective of security and risk.

The next trust perimeter

AI agents are still in the early stages, but the infrastructure needed for them to execute transactions is already advancing.

In June, Visa announced a collaboration with OpenAI to enable payments within agent-based commerce experiences. For its part, Mastercard announced new tools in September to connect agents, merchants, and payment providers.

This means the debate on security shouldn't wait until agents account for a significant share of transactions.

It needs to start sooner.

Because when a machine can act on a person's behalf, protecting an account will no longer be just about verifying that the right person is behind it.

It will be necessary to verify that the right action is being executed by the right agent, with the right authorization, within the right context.

The next frontier of digital identity might not be proving who you are. It might be proving what you authorized a machine to do on your behalf.

Stay Ahead of Fraud

The evolution of digital identity, payments, and artificial intelligence is redefining how financial institutions must assess trust.

Subscribe to receive a new article every Wednesday featuring analysis on fraud prevention, digital identity, cybersecurity, and emerging threats.

You can also schedule a meeting with our specialists to discuss how risks evolve throughout the digital journey.

Back to articles