l0grisk intelligence · english

// analysis

Your AI Is About to Spend Your Money

Illustration for the analysis: Your AI Is About to Spend Your Money

EMVCo, Visa, Mastercard, Google and OpenAI are preparing purchases delegated to AI agents. Payment rails are moving faster than the rules governing choice.

dated revision: September 02, 2026French originalprimary sourcesno tracker

“Find me a pair of white trainers for less than €100, delivered before Friday. Avoid that brand. Buy the best deal.” It sounds clear enough to a person. For a machine authorised to pay, it is already a badly drafted contract.

Does the ceiling include delivery? Is an off-white sole acceptable? May the item be refurbished? Is an unknown marketplace allowed? What should the agent do if the correct size is available only from a seller with no history? Does “best” mean lowest price, fastest arrival, free returns, strongest reviews or highest probability that the parcel actually turns up?

And if the company operating the agent receives money from a merchant, does that payment affect the answer?

Every one of those questions comes before the card transaction. Yet the payment layer is where the industry is now erecting its first formal guardrails.

On 1 September 2026, EMVCo, the body that develops major technical specifications for card payments, opened a draft agentic-payments framework for comment. It is a draft, not a finished standard. Its proposed Intent Services are meant to register and manage the consumer’s authority over time, including cumulative budgets, recurring purchases and some post-purchase operations. The announced comment period runs until 30 September 2026. Source: EMVCo, 1 September 2026.

The same day, Reuters reported, citing three sources, that India was preparing a protocol under which agents could make small UPI payments without asking the user to approve every transaction. NPCI, the operator of UPI, had not publicly confirmed the plan when the story was published. It is credible reporting about a project under preparation, not an official launch notice. Source: Reuters, 1 September 2026.

Both developments point to the same question: how do you let a machine spend without giving it an unlimited mandate?

The technical answer is taking shape. The economic, legal and political answer is not.

“Agentic payment” covers several very different things

An agent, in this article, is software that can pursue a goal, call tools and string actions together. It does not merely display shoes. It can query catalogues, compare offers, build a basket, obtain or request a payment credential and submit the order to a merchant.

The vocabulary remains loose. Companies speak of agentic commerce, agentic payments, Human Not Present purchasing and shopping agents. Those labels often blur distinct levels of delegation:

  • an AI recommends a product and the user completes the purchase elsewhere;
  • it fills the basket, but the user reviews the merchant and pays;
  • it selects an offer, then asks for explicit approval;
  • it receives a bounded mandate in advance and buys later while the user is absent;
  • it manages a budget, repeat purchases, returns or renewals over time.

A transaction can therefore run on production banking infrastructure while still requiring a human at the decisive moment. This analysis extends our earlier account of machine-to-machine payments, x402 and stablecoins without confusing those technical rails with the consumer purchases examined here.

On 2 June 2026, Worldline, ING and Mastercard announced a live, end-to-end European agentic payment in a production environment. In the scenario they described, the agent found concert tickets within the customer’s budget, but she then explicitly approved the purchase. The event demonstrates that real payment rails can process an agent-mediated journey. It does not establish that consumers can generally tell an agent to buy while they sleep. Source: Worldline–ING–Mastercard joint release, 2 June 2026.

Worldline also describes European scenarios in which an initial authorisation may remain usable for a limited window. These are bounded experiments, not universal availability across all cards, agents and merchants. Source: Worldline, “Agentic commerce”, accessed 2 September 2026.

Visa, for its part, said in July 2026 that agents had completed real purchases at European merchants under parameters set by users. That is Visa’s own account of what it ran. It is evidence of an announced operational test, not an independent audit of safety or scale. Source: Visa Europe, July 2026.

Established. Real transactions and production payment journeys have been documented. Open protocols and standards work now cover agent identity, user authority and evidence tying a basket to a payment.

Not established. Public data do not reveal transaction volumes, error rates, losses, disputes, the share of genuinely autonomous purchases or broad consumer adoption.

The agent does not need your raw card number

“Giving the robot a credit card” is a vivid but misleading image. Proposed architectures split the task into several stages: interpret the instruction, select the basket, prove authority, obtain a constrained payment reference, and let existing payment systems approve or reject the transaction.

Tokenisation replaces card details with a token that can be restricted to a merchant, device, channel or other context. It lowers the value of stealing the raw card number. It does not make a usable token harmless, and it does not eliminate fraud. Source: EMVCo, payment tokenisation overview.

AP2, the Agentic Payment Protocol, offers the clearest public map of the mechanism. Version 0.2 defines five roles: the Shopping Agent, Credential Provider, Merchant, Merchant Payment Processor and a Trusted Surface that collects consent. The Trusted Surface must be non-agentic. The critical approval step is not meant to depend solely on the same probabilistic model that searched the web and interpreted the request. Source: AP2 v0.2, “Roles”.

AP2 then separates two forms of evidence.

A Checkout Mandate proves that the agent is authorised to buy a particular checkout. The merchant signs the checkout description; the closed mandate is cryptographically bound to it.

A Payment Mandate proves that the agent is authorised to pay for that checkout. Signed receipts are then returned to the relevant parties.

In a direct flow, the user sees the final basket and approves it. In an autonomous flow, the user first signs an open mandate, an envelope of constraints. The agent may later sign a closed basket on the user’s behalf, provided deterministic verifiers can establish that it falls within those original limits. The specification recommends keeping an autonomous mandate’s validity as short as the task permits. Source: AP2 v0.2, “Mandates” and “Autonomous”.

Visa’s Trusted Agent Protocol addresses another part of the problem: allowing a merchant to recognise a legitimate agent, verify the integrity of transmitted information and distinguish approved automation from hostile bot traffic. Its documentation describes signed messages and replay protections around agent requests. Source: Visa Developer, Trusted Agent Protocol Specifications.

Choosing and paying are different problemsThe agent first interprets the request and ranks offers. Payment systems then verify the mandate, basket and authorisation. Payment evidence does not measure the quality of the choice.AGENTIC PAYMENTS · TWO LAYERSChoosing and paying are different problemsA technically valid transaction may follow a poor decision.1 · INTERPRET AND CHOOSEThe agent’s decisionInterpret the user’s requestChoose which sellers to searchCompare price, speed and returnsRank and select an offerModel, data and untrusted content2 · AUTHORISE AND PAYEvidence and controlsVerify the agent’s identityCheck the mandate limitsBind the basket to paymentProduce a verifiable receiptDeterministic code and cryptographyEvidence can answer: “was the agent allowed to pay?”It does not automatically answer: “did it choose the right offer?”Choosing and paying are different problemsThe agent chooses an offer, then payment systems verify the mandate. Valid evidence does not measure the quality of the choice.AGENTIC PAYMENTSChoosing and paying:two separate problemsValid evidence does not grade the choice.1 · INTERPRET AND CHOOSEThe agent’s decisionInterpret the requestSelect sellersCompare and rankSelect an offer2 · AUTHORISE AND PAYEvidence and controlsIdentify the agentCheck the mandateBind basket and paymentProduce a receiptPermission to pay ≠ quality of choiceBoth layers need controls.
AP2 and neighbouring protocols aim to make authority, checkout and payment verifiable. Search, interpretation and ranking remain a separate problem. l0g diagram based on the AP2 and Visa specifications accessed 2 September 2026.

The first risk is hidden inside the instruction

Consider a simple standing order: “Buy coffee whenever the bag falls below €16.” A usable mandate must still specify the pack size, the maximum quantity, whether delivery counts, how long the offer may remain valid, which sellers qualify, whether a new blend is acceptable, whether the agent knows what is already in the cupboard and whether it may start a subscription.

Without those details, three very different outcomes may all appear compliant:

  1. a 250-gram bag at €15.90 plus €8 delivery;
  2. four bags bought on the same day because each falls below the unit cap;
  3. a €15.50 monthly subscription whose price can rise later.

A per-transaction ceiling is not enough. It needs an aggregate budget. The aggregate budget needs a time window. The time window needs substitution rules and a definition of what must return to the user for approval.

That persistence is what EMVCo’s proposed Intent Services are trying to address. Authority would become an object that can be registered, retrieved and managed over time rather than a one-off click. That may stop an agent from improvising consent at every step. It also creates a sensitive data layer describing what a person is prepared to buy, under which conditions and for how long. Source: EMVCo, draft framework page.

The tool below does not connect to a shop or simulate a payment. It does something more basic: turns a loose instruction into explicit permissions, then exposes what remains unresolved.

INTERACTIVE TOOL · NO REAL PAYMENT

Write your AI’s licence to spend

Turn “buy it for me” into rules that can be checked. Everything runs locally in your browser; no data is sent anywhere.

Additional guardrails
Data available to the agent
Your mandate
Autonomy level
Guardrail quality

Theoretical automatic capacity

Proposed mandate

Questions still open
    Data access

      This l0g framework describes the delegation selected. It does not assess the security or legal compliance of a real service. The purchase count is the minimum needed to exhaust the budget at the automatic cap, not a spending forecast.

      The discomfort is the point. Once an agent may act in your absence, a casual sentence turns into revocable permissions, ceilings, exceptions and responsibility. It becomes a mandate.

      Cryptography can prove the mandate, not the wisdom of the purchase

      AP2 draws its boundary clearly. It secures what is being purchased and the related payment. Catalogue APIs, checkout updates and the exact process by which the agent determines what the user wants belong to the commerce layer or application, not to AP2 itself. The mandate contents are assembled after the Shopping Agent has interpreted the task; that interpretation is outside the specification’s scope. Source: AP2 v0.2, introduction and “Mandates”.

      That is a sensible boundary for a payment protocol. No single standard can solve product search, advertising, data quality, consumer law and after-sales service.

      It also reveals the central risk.

      Suppose the agent holds a perfectly signed mandate: new trainers, size 43, below €100 delivered, before Friday, no subscription. It finds a €92 pair from an allowed merchant and pays with a credential constrained to that checkout. Every cryptographic proof may be valid.

      Yet the agent may have searched only three partner merchants. The first result may be sponsored. A misleading product page may have described ten-day delivery as immediate dispatch. Another seller may offer the identical item for €74. The selected merchant may have poor return terms that the ranking model barely weighted. A hidden instruction on a page may have altered the model’s priorities.

      A signature cannot turn those decisions into a good purchase. It can help establish who authorised what, which basket was presented and whether the signed data were altered.

      There is a serious counterargument. People already shop through opaque rankings, questionable reviews, commissioned comparison sites and artificial promotions. A well-built agent could compare delivered prices, detect pre-ticked subscriptions, apply exclusions consistently and keep a better audit trail than a hurried consumer. Delegation could formalise preferences that today’s commerce exploits without making them explicit.

      The question is not whether AI is inherently worse than a human shopper. It is what evidence will explain its decision when the purchase is challenged.

      Whoever chooses the shops is already close to owning the sale

      Traditional online commerce divides the journey. Search engines capture demand. Marketplaces organise offers. Merchants set prices. Banks and card networks authorise transactions. Logistics companies deliver.

      An agent can compress much of that chain into one conversation:

      expressed needmerchants searchedoffers comparedseller selectedpayment initiatedreturn managed.

      The valuable position is therefore not confined to the payment fee. It sits upstream, in deciding which universe the consumer gets to see.

      OpenAI is a useful example precisely because its commerce strategy has moved. In September 2025 it introduced Instant Checkout, built with Stripe and the Agentic Commerce Protocol. Each purchase still required explicit confirmation, and OpenAI said merchants would pay a fee on completed transactions. The company said Instant Checkout items were not given preference in product results. Its page nevertheless listed Instant Checkout availability among the factors used to rank merchants selling the same product. Those were company statements about its own system, not an independent test. Source: OpenAI, “Buy it in ChatGPT”, September 2025.

      By 2 September 2026, OpenAI’s merchant page placed more emphasis on product discovery and completing purchases on the merchant’s website or app. It says richer, structured feeds can improve accuracy, presentation and visibility. Its help material still documents an integrated checkout for some eligible sellers or items. The evidence therefore supports a mix of routes and an evolving strategy, not a clean disappearance of checkout from ChatGPT. Sources: OpenAI’s product-discovery update and shopping help page, accessed 2 September 2026.

      That matters because the assistant may retain the most powerful position even when the merchant processes the sale. It receives the intention first and determines which offers deserve attention.

      At least five mechanisms must be kept separate:

      • ranking one product against another;
      • ranking sellers of the same product;
      • the quality and freshness of each merchant’s data;
      • technical compatibility with a checkout route;
      • commercial compensation, where it exists.

      They can produce the same visible outcome, one offer appears first, for different reasons. A merchant’s over-representation is not, by itself, proof of paid preference. Conversely, a platform can shape results without a direct commission by favouring richer integrations, lower operational risk or data that are easier to process.

      Visa’s protocol contemplates experiences adapted to recognised agents. That can be useful: merchants can expose more structured information, avoid treating legitimate agents as hostile bots and streamline checkout. It may also create two versions of the web, one shown to people, another delivered to agents. Trust then depends on whether price, stock, fees, availability and return terms remain consistent and auditable across both. Source: Visa Trusted Agent Protocol, use cases and specifications.

      A merchant can whisper to the machine behind your back

      Large language models often treat the content they read as text to interpret. That is both their power and a known weakness. A web page can contain an instruction aimed not at the customer but at the model: ignore competing offers, reveal information, call a tool or describe this product as the priority.

      An indirect prompt injection is a hostile instruction embedded in an external source consulted by the agent rather than in the user’s own request.

      A preprint first posted in January 2026 and revised in May tested this class of attack in an experimental shopping-agent environment involving AP2-related mechanisms. The authors report that they were able to alter product rankings and trigger unwanted behaviour in their prototype. It does not measure real-world attack frequency and does not document fraud against Visa, Mastercard, Google or OpenAI. It is evidence of technical possibility in one setup, with the normal limits of a preprint. Source: arXiv:2601.22569, accessed 2 September 2026.

      A second preprint, submitted on 24 August 2026, analyses the trust boundaries of AP2 v0.2. It distinguishes the integrity of checkout and payment after signing from the interactions and external inputs that shape a transaction before authorisation. With no complete public deployment available, its demonstrations use a testbed. This protocol analysis reinforces the boundary examined here; it does not measure attack frequency in production. Source: arXiv:2608.23858, 24 August 2026.

      AP2 does not ignore the broader trust problem. It treats an LLM-handled role as potentially adversarial and requires critical validation to run in deterministic code. Source: AP2 v0.2, “Agentic vs Non-Agentic”.

      That boundary is essential: the model cannot simply declare its own purchase compliant. A separate rules engine must check amount, dates, merchant, category, checkout hash and other constraints.

      But consider a subtler attack. The page never asks the agent to exceed the budget. It persuades the model that this item best matches the user’s criteria. The basket stays below €100. The seller is allowed. The payment is correctly bound. The deterministic checker sees no formal breach.

      The mandate has been followed. The choice was manipulated upstream.

      A prudent architecture therefore needs several layers: treat catalogues and reviews as untrusted data; separate exploration from payment authority; minimise tool and data access; verify total price and seller at the moment of payment; return material changes to a human; keep a comprehensible log of searched and excluded offers; and make the mandate immediately revocable.

      No single control is sufficient. Together they reduce the chance that one reasoning error turns directly into a bank debit.

      The payment was authorised. The purchase was bad.

      Payment law already asks a central question: was the transaction authorised? Under PSD2, a payment is treated as authorised only if the payer consented to its execution. The directive also governs strong customer authentication and, for certain remote electronic payments, links authentication to the amount and payee. Source: Directive (EU) 2015/2366, including Articles 64 and 97.

      The regulatory technical standards on strong authentication specify dynamic linking: the authentication code is tied to the amount and payee and must be invalidated by a change. Source: Commission Delegated Regulation (EU) 2018/389.

      An agentic mandate introduces distance between consent and payment. When the user grants general authority, the final merchant or exact amount may not yet be known. Protocols try to bridge that distance by signing open constraints and then proving that a closed checkout complies with them.

      That leaves at least three classes of dispute:

      Situation Core question What public sources currently support
      The user never issued a mandate Was the payment unauthorised? Existing authorisation and fraud rules provide a framework, subject to the facts and payment method.
      The agent exceeded a signed limit Which party failed to verify or execute the mandate? Mandates and receipts may help locate the failure; exact contractual allocation depends on the system.
      Every formal limit was met, but the agent chose badly Is this defective agent service, bad merchant information, unfair ranking or risk accepted by the user? I found no general public European doctrine cleanly resolving this case as of 2 September 2026.

      The third line is the genuinely new one. A payment may be authorised in the technical sense. The product may arrive. The consumer may still argue that the agent misunderstood the goal, missed a better offer or was influenced.

      Payment services law, distance-selling rules, advertising law, data protection, contract liability and card-scheme rules may all become relevant. A chargeback may be available in defined circumstances under a scheme and contract. It is not a universal right that reverses every poor recommendation.

      Protocols allocate technical roles, not legal liability by themselves. AP2 also permits one entity to play several roles or delegate them. That flexibility helps adoption, but makes the external chain harder to read: the visible app, model provider, wallet, processor and merchant may be controlled by different firms. Source: AP2 v0.2, “Roles”.

      Limit of this investigation. Public sources allow us to describe proposed mechanisms, several transactions and the general law of payment authorisation. They do not support a universal allocation of losses when a purchase is authorised, technically compliant and economically poor. A more definitive claim would go beyond the evidence.

      A useful shopping agent needs to know a great deal about you

      A conventional comparison site needs a query. A genuinely personal agent will want more: address, sizes, rejected brands, order history, loyalty cards, household constraints, travel dates and previous returns.

      Each additional datum can improve the decision. It also increases the impact of error, compromise or secondary use.

      The GDPR requires, among other things, purpose limitation, data minimisation and data protection by design. It gives stricter treatment to certain categories of sensitive information and the processing that may expose them. Source: Regulation (EU) 2016/679, including Articles 5, 9 and 25.

      In its technology-futures report on agentic AI, the UK Information Commissioner’s Office highlights unclear responsibility, excessive collection, sensitive inferences and the need for users to monitor, constrain and stop agents. Source: ICO, “Tech futures: agentic AI”, accessed 2 September 2026.

      The transmission mechanism is straightforward:

      more personalisationmore context accessiblebetter potential decisionslarger profiling and attack surface.

      An agent that knows you leave on Friday can book the right train. The same knowledge reveals when the house may be empty. Purchase history can improve recommendations and also reveal health, pregnancy, religion or financial stress without any of those facts being stated directly.

      A robust mandate must therefore define not only how much the agent may spend, but what it may learn, combine and retain in order to spend it.

      The contest is larger than Visa versus Mastercard

      Each group of firms is defending a function.

      Payment networks want to remain the trust layer that identifies agents, carries evidence and applies transaction rules. Issuing banks retain the account relationship, authentication and fraud controls. Merchants do not want to become interchangeable warehouses behind an interface that owns the customer. AI platforms want to receive the consumer’s intention before anyone else does.

      Standards can open the market. Shared mandates and interoperable identities may prevent every agent from requiring a proprietary integration with every shop. Standards can also create new gatekeepers. Who attests that an agent is trusted? Who can revoke that status? Which small merchants can afford the required structured data, controls and evidence? An open protocol does not prevent concentration if a handful of firms control identity, consumer access or consent interfaces.

      Agents may also strengthen competition. They can compare delivered cost rather than headline price, detect a preselected subscription, account for paid returns and search beyond the largest marketplace. A specialist merchant with accurate data, reliable stock and strong terms could win without the biggest advertising budget.

      Both outcomes are technically plausible. The business model and transparency will decide more than the word “assistant”:

      • Does the agent work only for the user?
      • Does it receive a seller commission?
      • Is it funded by a subscription that reduces pressure to monetise rankings?
      • Are sponsored offers separated?
      • Can the user see which merchants were excluded and why?
      • Can the mandate and preference profile move to another agent?

      A seller-paid broker can still be useful. It simply occupies a different economic position from an agent paid solely by the buyer.

      Five levels, five different risk profiles

      The industry uses several taxonomies. To avoid calling every AI-assisted checkout “autonomous”, l0g uses the following editorial scale. It is not an industry standard.

      Five levels of purchasing delegationFrom level zero, where the agent only advises, to level four, where it manages a budget over time. Human intervention falls as the need for guardrails rises.L0G EDITORIAL SCALE · NOT A STANDARDFive levels of purchasing delegationThe farther the human is from the transaction, the tighter the mandate must be.0Advice onlyThe user still finds the seller and completes payment.STRONG HUMAN CONTROL1Basket preparedThe item and merchant remain visible before checkout.NO PAYMENT2Waits for approvalThe agent chooses, but every closed basket returns to the user.HUMAN PRESENT3Buys within limitsBudget, duration, merchants and exceptions are pre-authorised.HUMAN ABSENT4Manages over timeRepeat purchases, aggregate budget, returns or renewals.SUPERVISION BY EXCEPTIONFive levels of purchasing delegationFrom advice without payment to continuous budget management.L0G SCALE · NOT A STANDARDFive levelsof delegationLess human presence needs tighter limits.0Advice onlyYou still find the sellerand complete payment.1Basket preparedProduct and merchant remainvisible before checkout.2Waits for approvalEvery closed basket comesback to you.3Buys within limitsBudget, duration and merchantsare authorised in advance.4Manages over timeRepeat purchases, aggregate budget,returns or renewals.SUPERVISION BY EXCEPTION
      This scale is used only to distinguish the journeys analysed here. Level 2 can operate on production infrastructure without being autonomous. Levels 3 and 4 require authority that remains usable while the user is absent.

      The change between levels 2 and 3 is not merely incremental. At level 2, the user can still notice that the shoes are grey, the seller unfamiliar or delivery €18. At level 3, rules, models or alerts must catch those facts before money moves.

      At level 4, risk accumulates. An agent that makes one mistake creates one poor purchase. An agent managing a budget for six months can repeat the mistake, renew an unwanted subscription or keep applying an outdated preference.

      Standardised, reversible purchases are the natural starting point

      Delegation is easier when the product is standardised, the amount low, the purchase reversible and success measurable.

      Reordering the exact same detergent below a delivered-price ceiling is easier than choosing perfume. Booking a familiar train under a cap may be easier than assembling a family holiday. Renewing an existing subscription is technically easy but economically dangerous if the agent never reassesses whether it is still useful.

      The hardest cases combine subjectivity, high value, sensitive data or consequences that are difficult to unwind: insurance, credit, investing, health, complex travel, important gifts and custom products.

      This is not a forecast of launch order. It identifies where mandate compliance is easiest to verify.

      A cautious deployment should not begin with “how far can the agent go?” It should ask “what is the smallest permission sufficient for this task?” That is least privilege applied to commerce: minimal data, short duration, narrow budget, bounded categories, identifiable merchants and human review whenever the context changes.

      The available evidence and its limits

      As of 2 September 2026, this is no longer only a keynote diagram. Transactions have been executed, large networks are publishing protocols and EMVCo is working on a shared layer around consumer intent. AP2 already describes how to bind mandates, checkout and payment, including a mode where the human is absent when the transaction occurs. Sources: AP2 v0.2 and EMVCo, 1 September 2026.

      Public evidence is still too thin to call autonomous commerce a mass market, to say fraud has been solved or to know whether consumers will accept this form of delegation. Corporate releases describe scenarios and proofs of operation. They rarely disclose failure rates, losses, disputes or full costs.

      The plumbing is moving faster than the doctrine.

      The industry is learning to answer four questions: which agent acted, which mandate it held, which basket was closed and which payment was authorised.

      A fifth question remains open: why that offer?

      It contains the future bargaining power of online commerce. An agent that receives your intention can exclude a merchant before you know it exists. It can also protect you from a misleading headline price, an accidental subscription or impossible returns. The same automation can strengthen the buyer or create a new invisible toll.

      The obvious risk is a machine spending without permission. The standards are being built precisely to reduce it.

      The subtler risk is a machine spending with every required permission, after making the wrong decision on your behalf.


      Method and limitations

      This investigation relies on public material available on 2 September 2026. Technical documents describe protocols; they do not prove adoption. Corporate releases establish what firms announced or said they executed, not independent validation. The Indian UPI item relies on Reuters and anonymous sources because NPCI had not publicly confirmed it at publication. The five-level scale and interactive tool are l0g editorial devices.

      I found no sufficiently detailed public series on agentic-payment volumes, error rates, fraud, refunds or disputes. No consultancy market forecast is used to fill that gap.

      Main sources

      Protocols and standards

      Transactions and company products

      Law, privacy, research and reporting

      This analysis is not investment advice.

      // cite this analysis

      l0g, “Your AI Is About to Spend Your Money”, l0g.fr, published September 02, 2026, updated September 02, 2026, https://l0g.fr/en/analysis/your-ai-is-about-to-spend-your-money/


      $ cd ../analysis