Agentic payments: when payments learn to think Monthly Report – September 2026

Monthly Report Published on

The payments landscape is potentially facing structural change. In the future, payments could not only be executed automatically, but could also be planned, initiated and managed autonomously by AI agents as “agentic payments”. With a high level of autonomy, AI agents can independently select payment instruments, payment timing and payment rails, and can also execute payments within a given mandate without requiring renewed human authorisation. Decision-making thus becomes part of the payment process and, in this sense, payments learn to “think”.

Agentic payments could unlock considerable benefits in terms of efficiency, productivity and innovation in payments. They could reduce settlement costs, shorten settlement times, and, at the same time, pave the way for innovative, automated services. In retail payments, agentic payments are often embedded in agentic commerce applications, but also offer advantages for other use cases, such as cross-border transactions or micropayments and split payments. In institutional payments, AI agents allow for applications in planning, aggregating and submitting payments as well as in liquidity management, in particular. 

These opportunities harbour new risks. AI agents make probabilistic decisions and, as a result, are not always entirely predictable or reproducible. This poses particular challenges for the payments landscape, which relies on auditability, legal certainty and trust. Flawed decision-making, manipulation, cyberattacks, unclear liability issues, and possible herd behaviour of AI agents acting in similar ways could amplify operational and systemic risks. In the emerging technical architecture, there are signs of trends towards concentration on a small number of protocols, interfaces and platforms, as well as dependencies on non-European providers. The key questions are therefore not only which technology will prevail, but also who will shape the decision-making and authorisation layers of payment systems in the future. These developments need to be monitored with a critical eye in the context of interoperability, security and market power. 

At present, agentic payments hold only a small share of the market and are mostly still in the early stages of development. However, due to the strong market dynamics and disruptive potential of these solutions, central banks need to understand how agentic payments are changing stability, efficiency, competition, security and sovereignty in payments. In order to facilitate innovation, safeguard trust in payments, and limit risks, it is necessary, amongst other things, to build interoperable infrastructure, set clear (regulatory) requirements for dealing with probabilistic decisions, and establish suitable governance frameworks.

1 Definition and function

Agentic payments, in the narrower sense, are payment processes that are autonomously planned, initiated and managed in a goal-oriented way by AI agents. 1  Unlike rules-based automation solutions, AI agents pursue predetermined goals and make decisions autonomously for this purpose within a framework of defined rules and authorisations (mandate). 2 In this context, they respond in real time to changes in conditions and information as well as identify patterns from completed actions (settlements, for example). 3 Whilst AI agents can generally perform a variety of different tasks, agentic payments (often also referred to as “agent-driven” or “autonomous” payments) focus on autonomous execution and management of payment processes. 4 Particular challenges arise as financial decisions are, in some cases, being delegated to AI agents.

Whether or not agentic payments will bring about further innovations in payments, or even cause disruptive changes, will depend largely on AI agents’ level of autonomy. With a low level of autonomy, an AI agent acts largely as an execution software tool. The user initiates explicit payment orders and defines relevant parameters, such as amount or means of payment. In this case, the AI agent only performs the technical initiation of the payment. With a high level of autonomy, by contrast, an AI agent has greater discretionary powers. In an extreme form, for example, it would be able to initiate payments autonomously, for example based on signals from other applications, without the need for explicit intervention by the user. In practice, the autonomy of AI agents is likely to be restricted by predefined frameworks, such as maximum amounts or permissible payment instruments, similar to a mandate in direct debit payments. The higher the level of autonomy, the more far-reaching the potential impact on existing payment processes and structures may be. 5

AI agents are based on machine learning algorithms and are characterised by interaction, autonomous planning, dynamic adaptation, and orchestration of external software. They are autonomous software systems, often based on large language models (LLMs). AI agents can interact with their environments autonomously and adapt dynamically based on new information or learned preferences. They have the ability to orchestrate external software, which means that they can integrate and control it flexibly. This allows them to optimise the interaction between systems and actors and thus supports user-friendly processes. 6 AI agents are also task-specific applications that each pursue clearly defined, overarching goals. For this reason, in order to execute complex (payment) processes with various sub-processes, multiple AI agents are generally used simultaneously. These capabilities open up new forms of interoperability and enable AI agents not only to interact with users, but also to function as self-controlled actors within complex (digital) ecosystems. 7

As AI agents make use of LLMs, one of their main characteristics is their probabilistic decision-making. Unlike traditional, rules-based systems that operate deterministically and always produce the same output given identical input, LLM-based AI agents make decisions based on probabilities and the provided context. Using large volumes of text, they have learned to model language statistically. 8 This probabilistic nature allows for flexible and adaptive responses to different inputs and context conditions, but also poses challenges, such as in the consistency and auditability of decisions. 9

2 Retail payments

The use of AI agents appears especially obvious for cashless retail payments, as many transactions in everyday life can be simplified in this area. 10 Many use cases are not especially complex, and the high level of standardisation of payment instruments would provide a good basis for simple implementation. At the same time, it would encompass and simplify a large number of daily transactions. Here, AI agents could evaluate a comprehensive volume of data, compare payment rails, initiate payments, or transmit payment information. The first live applications are already available on the market, but are often still in test, pilot, or early trial phases, meaning that they have not yet been launched on the broader market. 11

In retail payments, agentic payments are currently used primarily in conjunction with agentic commerce. “Agentic commerce” describes commercial processes in which AI agents search, compare, select, and order goods or services. 12 In this context, agentic payments constitute the payment component. For example, agentic commerce applications delegate the settlement process itself to an agentic payments application, without the conscious awareness of the customer. Due to these “invisible” payments, agentic commerce and agentic payments are sometimes considered to be the same, even though they perform different tasks. 13 Chart 5.1 shows a stylised payment process of an instant credit transfer using agentic payments with full autonomy. By minimising the required user interactions and integrating search, purchase and payment processes, the entire purchasing process can be made efficient, error susceptibility can be reduced, and the user experience can be improved. Furthermore, agentic payments can create additional benefits, for example by selecting means of payment in such a way as to take advantage of discounts and price reductions as well as maximise loyalty points or cashback. 14

Stylised payment process for an online purchase using fully autonomous agentic payments and instant credit transfers
Stylised payment process for an online purchase using fully autonomous agentic payments and instant credit transfers

Payment processes can also be managed by AI agents independent of agentic commerce. This applies, for example, to traditional checkout processes in which the user makes the purchase decision themselves and the AI agent only handles the initiation of the payment. In this context, AI agents could handle the selection of payment instrument as well as the automated and encrypted transmission of payment information to the merchant or payment service provider without additional user interaction. In this way, a simplified payment process would not be dependent on means of payment that have been saved and authorised in various customer accounts. 

Agentic payments enable user-friendly micropayments and split payments, thus creating the basis for more usage-based business models and machine-to-machine payments. While current payment instruments are primarily oriented towards traditional single transactions, AI agents could, in future, allow for very small-scale payments (“micropayments”) that have generally not been particularly user-friendly thus far. This would allow individual digital content or data-driven services to be billed according to usage, for example. The breakdown of payments according to usage, progress or fulfilment of certain conditions (split payments) will gain significance through agentic payments in that AI agents would monitor the relevant conditions and initiate the payments automatically. 

Agentic payments could make cross-border payments more efficient, transparent, and user-friendly. Cross-border payments are often associated with high fees, long execution times and non-transparent costs. AI agents could compare different providers and means of payment and then select the most suitable payment rail for the user, including selecting the currency exchange (routing) 15 and initiating the payment. The advantage of AI agents is that they can search and process information faster and more efficiently. The greater degree of transparency could promote competition and also reduce costs and execution times, for example for remittances to family members abroad.

3 Institutional payments

In institutional payments, 16 agentic payments could optimise payment and settlement processes as well as liquidity management. Larger enterprises, banks, and other payment service providers, in particular, could use AI agents to plan or aggregate incoming and outgoing payments or to select suitable settlement rails (routing), both for their own payments and for customer payments. As a result of agentic payments, financial market infrastructures will potentially be confronted with higher transaction volumes and technical developments. At present, the current market situation can only be assessed to a limited degree, as it is difficult to evaluate the extent to which agentic payments are already being used (internally) for institutional payments. Financial market infrastructures do not currently make use of agentic payments. 

Agentic payments could optimise the selection of payment means and rails. Like in the retail segment, payment service providers and enterprises could use agentic payments to optimise the way in which they select the most economically appropriate payment means and rails, especially for cross-border payments. Traditionally, these decisions are based more on contractual and account relationships as well as network dependencies. AI agents could establish data-driven, dynamic routing outside of these traditional structures. In addition, they could incorporate information from internal systems, such as accounting, into their decision-making.

AI agents could, in some cases, autonomously control liquidity management for payment service providers. They could weigh up the trade-offs between the costly holding of liquidity for payments on the one hand and the advantages of faster settlement on the other, maintain liquidity buffers, prioritise urgent payments, and, when doing so, factor in the likelihood of expected inflows and outflows, taking into account the behaviour of other actors. 17 In more complex applications, AI agents could automatically retrieve the large volume of information required for payment settlement from internal systems and external sources in a very short amount of time and, overall, make faster and potentially more informed decisions compared to human managers or current (deterministic) treasury management systems. 

The opportunities for using AI agents to manage settlement mechanisms in financial market infrastructures as centrally as possible appear less promising. In theory, the management of payment coordination within a payment system by an AI agent could lead to faster settlement and greater efficiency with lower liquidity needs compared to existing settlement logic. However, AI agents’ probabilistic decision-making processes are incompatible with the predictability needed for payment coordination. In order to ensure the stability of payment systems, transaction settlement must be deterministically predictable. Participants rely on predictable settlement, even in the event of disruption. Probabilistic management may lead to unpredictable, non-transparent, and non-reproducible decisions and could disadvantage individual payment service providers, reduce trust in systems, and lead to unexpected credit and liquidity risks. In addition, system-inherent hallucinations, 18 increased vulnerabilities for attempts at manipulation 19 due to the probabilistic nature of the system, and the limited availability of information from institution-specific systems 20 could represent additional hurdles to the use of AI agents at the heart of financial market infrastructures. Nevertheless, agentic payments also offer financial market infrastructures the possibility of improving their services.

Supplementary information

Architecture of agentic payments

In the complex payments ecosystem, dynamic AI agents can integrate and coordinate various actors, technical standards and regulatory requirements. Since numerous actors are involved in the full cashless settlement process, secure interfaces, protocols and requirements are essential. 1 AI agents, thanks to their adaptability, can optimise this interaction, connect systems and actors, and thus support a smoother, user-friendly process. 

Agentic payments primarily operate at layers of the payment process that are upstream of the actual clearing and settlement. The focus is therefore not on settlement mechanisms as such, but on the AI agents’ autonomous decision-making processes, their communication with external systems, the use of payment mandates and the proof of their identity. In the upstream processes, in particular, the existing payment infrastructure is being expanded, while settlement mechanisms are affected only indirectly. This creates a multi-layered architecture with, in some cases, different protocols and market players involved. Chart 5.2 provides an overview of these layers, the relevant protocols in each case, and the market players involved. As the technical landscape is still in an early and fragmented phase of development, several approaches are competing with one another, and it is currently uncertain which standards will prevail.

Architecture of agentic payments
Architecture of agentic payments

Delegating payment-related decisions to AI agents requires that decision-making be considered as an independent technical layer of the payment architecture. In the traditional payment architecture, decision-making has so far not been understood as a technical layer, as selection and payment decisions have generally been the responsibility of a (natural) person. Autonomous AI agents shift decision-making to the technical layers. No payment-specific standards exist at present. Instead, the architecture of the agentic framework determines what actions an agent can perform and thus also defines what actions are passed to downstream layers.

As a point of integration between the layers, the communication layer is of particular strategic importance. It makes payment operations available to AI agents at a technical level and determines how they are called up and controlled. Since AI agents can only use those payment instruments that are made available via appropriate interfaces or protocols, the communication layer plays a key role. It acts as a “gatekeeper” and builds a bridge between the AI agents involved and all other actors and systems. At the same time, this layer is necessary in order to translate upstream decisions into concrete payment processes. This combination of access control and operational translation is what gives it its particular strategic importance. The Model Context Protocol (MCP) 2 and the Agent2Agent Protocol (A2A) 3 for multi-agent scenarios are emerging as key standards. 

The authentication layer defines the operational framework for AI agents and is also strategically important. In traditional settlement processes, each payment must generally be authorised by a (natural) person with the proper credentials. 4 Where AI agents have a high degree of autonomy, the powers of the AI agent with regard to authorising payment and transmitting personal information must be clearly defined. The authorisation layer therefore defines by whom and under what conditions a payment mandate is granted to which AI agent and how this mandate can be encoded, reviewed and revoked in a machine-readable manner. Those who set the standards in this layer effectively shape the conditions for the other layers and significantly influence which AI agents are allowed to initiate transactions under what conditions. The authorisation layer is therefore that closely linked to the identification layer, as mandates can only be issued to uniquely verifiable AI agents. Unlike other layers, the Agent Payments Protocol (AP2) 5 has already assumed a particularly prominent position amongst authorisation protocols. Other protocols, such as TAP 6 and Agent Pay, 7 are attempting to establish a foothold as trusted alternatives. 

The transaction execution layer generates specific payment instructions and is characterised by a protocol landscape that is still fragmented, but in which concentration is rising. The transaction execution layer governs how the mandate is translated from the authorisation layer into an executable payment instruction. Compared with other layers in which largely complementary protocols have become established, two similar protocols – the Agentic Commerce Protocol (ACP) 8 and the Universal Commerce Protocol (UCP) 9  – have become de facto standards here. An alternative execution model built exclusively on DLT infrastructure is offered by the x402 protocol. 10

Since actions are attributable only once AI agents are clearly identified, the identity layer is at the heart of agentic payment systems. The idea is to ensure that an AI agent is uniquely identifiable. Technical procedures are designed to enable the AI agent to identify and authenticate itself to a payment service provider with no human action involved. In traditional payment systems, implicit identification is often carried out via account numbers and card data, and authentication is often carried out via passwords, possession or biometric features (single-factor or multi-factor authentication). However, these mechanisms are tailored to (natural) persons and are not directly applicable to autonomous agentic systems. TAP, Agent Pay and AP2 are emerging as AI identity verification solutions. 11

The settlement layer will remain largely independent and is more likely to be complemented than replaced by agentic payments. Payment settlement is characterised by high barriers to entry, network effects and considerable regulatory requirements, which is why agentic payments are unlikely to establish entirely new settlement infrastructures, but could have an impact on their use. Structural changes are therefore to be expected less in settlement itself than in the opening and standardisation of interfaces to traditional payment infrastructures for autonomous AI agents. However, the x402 protocol already supports settlement on new DLT-based infrastructures, such as stablecoins. 

 

4 Impact on market structures and current market overview

By largely automating payment-related decisions and processes, agentic payments could significantly reduce coordination costs and change existing market structures in the payments space. 21 If AI agents are able to switch between providers, protocols, and payment rails with almost zero friction, the traditional lock-in effects in payments and the pricing-setting power of established intermediaries will lose their significance. Beyond this, agentic payments could also fundamentally change the institutional structure by lowering barriers to market entry, promoting highly granular market coordination, and shifting the role of payment intermediaries from gatekeepers to interoperable infrastructure providers. Agentic payments would thus represent not only an innovation in payments, but also a mechanism with the potential to redefine market organisation and competitive dynamics. 22 In combination with instant payments, in particular, AI agents could identify cheaper and faster payment rails and systematically prioritise cost-efficient means of payment over means with wider margins. As a result, existing sources of revenue and business models in payments would come under pressure. This is particularly true for cross-border payments, where AI agents could reduce settlement costs through more efficient routing as well as faster and more comprehensive evaluation of information.

Control over interfaces with end customers could become a fiercely competitive field for agentic payments. 23 Many entities are currently developing solutions to tap into the large estimated market potential. 24 Due to their technical, regulatory, and organisational experience, established payment service providers are in a good starting position. 25 At the same time, AI model providers, technology firms, and cloud and infrastructure providers are competing by providing decision-making logic, platforms, interfaces, or scalable infrastructure. Agentic payments could tend to avoid existing, currently profitable payment networks, and thus put pressure on them, as these networks have higher costs compared to alternatives, such as instant payments. In addition, partnerships are increasingly being seen between different entities, especially between technologically leading companies and traditional payment service providers. The aim of these collaborations is to achieve the integration of technically advanced solutions into existing ecosystems. 26

Technology and AI providers could take on central roles in the emerging ecosystem without providing traditional payment services themselves. Their influence is based on control over decision-making, communication and authorisation in the architecture of agentic payments. As operators of platforms that are used by AI agents, they determine which protocols and interfaces are available. Open communication standards can serve as integration points across platforms, whilst authorisation standards define how payment rights are delegated to AI agents and made verifiable. Those who control these layers have an influence not only over access to payment services, but also over the relevant data flows. In addition, agent architecture and authentication logic determine which actions an agent is allowed to perform before the protocol is actually used. This creates an upstream control instance. Especially broad partner alliances can generate strong network effects and establish standards at an early stage. 27  

Traditional payment networks and payment service providers are faced with the challenge of integrating agent-based actions into existing processes in order to safeguard their roles with their own standards. Their existing authentication and authorisation logics are based predominantly on human interaction and need to be adapted for AI agents. However, with protocols and frameworks, they are increasingly trying to make existing payment infrastructures accessible to AI agents and ensure their own influence over identity and authorisation standards. Alongside global networks, regional players are also developing their own solutions. 28 Due to their existing user relationships, regional ecosystems, and integrated trading platforms, they can quickly embed agentic payments into everyday digital environments. At the same time, this increases the likelihood of regional or platform-specific solutions and thus the risk of fragmentation.

Cloud and infrastructure providers have an interest in agentic payments regardless of layers or protocols and thus differ structurally from other entities. The use of autonomous AI agents generates additional demand for computing power, interfaces, memory and data processing. At the same time, these providers can influence identity and communication layers by implementing certain payment protocols at the network level. The verification of agent identities at the protocol level, similar to the certification of web domains, is particularly attractive. As their economic interests are largely independent of individual payment standards, cloud service providers usually do not compete directly with other providers.

Agentic payments are coming up against a market environment that is already changing as a result of digital finance, which could allow new dynamics to unfold. Digital finance is already bringing considerable momentum to payments through smart contracts and tokenised assets, in particular. 29 Nevertheless, the technologies used here are based fundamentally on deterministic logic and do not achieve the same level of autonomy as agent-based systems. However, combining both technologies could create new dynamics, for example, if AI agents autonomously make use of tokenised assets or forms of money, or create, execute or link smart contracts themselves. 

If a small number of central protocols are dominant, then market structures in payments could become more concentrated. The observed concentration on a small number of protocols could pose a risk. A small number of technology providers could control core functionalities, which may range from interpreting user intentions to initiating and executing payments. Payment service providers and users could become equally dependent on external systems. Agentic payment providers could indirectly influence transaction decisions, such as the choice of merchant or means of payment, via the (large language) models used. The lack of transparency among many AI agents exacerbates this risk, as the output is only auditable to a limited extent.

If agentic payments are used more frequently, merchants, payment service providers and infrastructures will need to adapt their systems accordingly. Services and processes would need to be set up in such a way as to allow autonomous systems to recognise, parse and make use of agentic payments. 30 Merchants are faced with the challenge of making their offerings accessible to AI agents, for example by means of machine-readable product catalogues and agent-compatible interfaces. At the same time, they could guide the use of specific means of payment in a more targeted manner and influence agent preferences through attractive conditions. 31 Consumers would have new possibilities for outsourcing purchase and payment processes to AI agents. However, this would require access to sensitive payment data and an explicit mandate to act. That entails issues of data sovereignty, security, and acceptance, as well as a need for trust-building mechanisms. Payment service providers and other players in the payments settlement space will also need to adapt their systems to accommodate agent-based transactions. The wide variety of different technical approaches and governance models makes the situation more complex and encourages fragmentation. This means that interoperability between actors will be a key factor for success. Standardised protocols, open interfaces and clear regulatory frameworks are crucial to ensuring seamless communication between AI agents, merchant systems and payment infrastructures, as well as legal certainty for all parties involved.

5 Challenges

Central banks and supervisory authorities are facing new challenges to the stability and security of payment systems, which might necessitate adjustments to the regulatory framework and oversight regime. The regulatory framework is fundamentally technology-agnostic by design and incorporates risk management and the concept of operators’ responsibility. 32 However, AI agents may potentially give rise to new types of risks not seen with existing technological solutions. These novel risks could arise, for instance, from AI agents’ higher level of autonomy, significantly faster processing speeds, limited predictability, the possibility of hallucinations, and the unavoidable potential for collusion-like behaviour 33 across multiple AI agents. 34 Issues relating to the imputability of actions carried out by AI agents as well as auditability, logging and effective options for intervention or shutdown are also relevant in this context.

Supplementary information

Regulatory treatment of agentic payments

Agentic payments are governed by the relevant (European) legislation. In the EU, this includes general regulations such as the General Data Protection Regulation (GDPR) 1 and the EU AI Act 2 as well as specific directives in the area of payments, in particular the Second Payment Services Directive (PSD2), 3 which was transposed into German law mainly by means of the German Civil Code (Bürgerliches Gesetzbuch) and the Payment Services Oversight Act (Zahlungsdiensteaufsichtsgesetz), 4 , 5 as well as the Digital Operational Resilience Act (DORA). 6

Key agentic payment requirements are derived from rules governing the consent, authorisation and authentication of payments. They are used to regulate liability claims and ensure payment security. In particular, the degree of autonomy that an AI agent has is of particular importance here. For agentic payment models in which customers themselves authorise payments, compatibility with the requirements of PSD2 will generally already exist or at least be relatively easy to implement, possibly with specific licensing requirements. 7 AI agents that operate largely autonomously, whereby the customer is removed from the payment process, pose more fundamental questions about compliance with PSD2. For example, it should be clarified whether a mandate granted to an AI agent is deemed to be payment authorisation under Article 64 of PSD2 or whether an AI agent regularly carries out a transaction requiring authorisation, such as a payment initiation service. Furthermore, for largely autonomous AI agents, it is necessary to check whether they meet the existing PSD2 requirements concerning strong customer authentication (SCA) and are compliant with existing exceptions. These can be exceptions for low-value payments, for the whitelisting of merchants or based on a transaction risk analysis. 8 As the development towards increasingly autonomous agentic payment models progresses, it is likely that these questions regarding the interpretation of PSD2 will become more relevant.

Specific liability issues arising from the use of AI agents, for example in connection with erroneous or fraudulent transactions, might not yet be conclusively clarified by existing legislation. PSD2 governs compensation claims for payments that have not been executed in accordance with the requirements contained therein. As the burden of proof lies with the payment service providers, 9 they will probably execute payments initiated by AI agents only if it is assured that the payments comply with the statutory requirements laid down in PSD2. In addition, liability agreements are likely to become more important in the future in agentic commerce, especially in the event of errors by an AI agent, such as the initiation of payments without a mandate, the purchase of unwanted products or transactions with fraudulent merchants. Clear contractual and liability agreements between all parties involved, reliable documentation of the mandates granted to the AI agent and effective risk mitigation mechanisms appear essential. Equally important are the easy and unique identification of trusted and legally compliant AI agents based on secure technological standards and documentation standards for agent-based payment transactions for compliance purposes, such as in terms of anti-money laundering, fraud analysis and incident management.

It is not possible to completely rule out flawed decision-making by AI agents, but appropriate measures can reduce its occurrence. In addition to the complex issue of liability in the event of errors – such as those caused by, for example, model distortions, misinterpretation of user preferences, software errors or hallucinations – there is also the question of effective risk mitigation strategies. Users in the retail segment may be exposed to additional risks, such as a reduced degree of control over their own spending, the possibility of unintended purchases, and the potential for erroneous transactions that are only noticed later. Conceivable solutions include building in specific checkpoints prior to final execution and making review by a human mandatory for large transactions. 35 Furthermore, inherent model distortions 36 and the lack of transparency intrinsic to complex algorithms (the “black box” problem) hamper diagnostic processes and can produce results that are flawed or difficult to audit. 37

Coordinated behaviour amongst AI agents can jeopardise system stability and competition. Homogeneous models, identical data sources or similar target functions could result in AI agents making similar decisions at the same time, even where the underlying user preferences or fundamental information are heterogeneous. This herd behaviour can turn individual efficiency gains into collective – and, in particular, procyclical – stability risks. 38 Unexpectedly high settlement volumes could, for instance, increase (system-wide) liquidity needs and overload technical capacities. Monopolistic market structures and feedback effects could further amplify these dynamics. 39 In addition, when AI agents repeatedly interact with other AI agents, they can also develop collusive patterns of behaviour, which is referred to as “implicit algorithmic collusion”. 

Shortcomings in data quality or data availability can lead to erroneous output and market distortions. The effectiveness of AI agents depends on the availability of high-quality data and standardised interfaces that enable automation, real-time processing and interoperability with other systems. Access to data will become a key competitive factor. As a result, asymmetric availability of data may lead to market distortions. Overall, closed systems like SWIFT are currently the dominant means of communication in payments systems, meaning that open interfaces are not fully in place. Successful integration of agentic payments into the ecosystem requires more openness and greater harmonisation.

Interconnection of agent-based systems brings issues of interoperability and cyber security to the fore. Studies show that AI-based systems create new kinds of vulnerabilities in the financial sector, 40 especially where automated decision-making processes are directly linked to financial transactions. 41 Without uniform standards, it is especially difficult to ensure secure interaction between different agent-based systems. To do so, payment systems and payment service providers have to provide suitable interfaces. This can create increased vulnerabilities to cyber risks, in particular through manipulated AI agents, compromised access data, misuse of interfaces or targeted attacks on system availability. 42 The parties involved therefore need to reassess which actors are critical and how system resilience can be strengthened. 

Agentic payments broaden the scope for potential fraud. A new dimension taking shape is that of targeted attacks on the activities of AI agents, such as those perpetrated by criminals posing as merchants and gearing their activities towards AI agents’ logic. Direct attacks on AI agents themselves are also conceivable, for example with a view to spying on security features, stealing confidential customer information or manipulating decision-making processes by means of prompt injection. Another potential risk lies in the possibility of agentic payment applications developed by criminals themselves.

The use of AI agents as institution-specific liquidity managers entails considerable risks. AI agents make decisions based on historical data and predefined objectives. If a system encounters an event that is unexpected or unfamiliar, such as a financial crisis, it could assess it incorrectly or fail to recognise it due to its lack of experience with exceptional circumstances. The same applies to company-specific particularities. There is also a risk that the widespread use of similar AI algorithms will fail to sufficiently internalise negative external effects, such as gridlock and free-riding effects. 43 This could amplify systemic risks such as herd behaviour. Adjusting AI agents’ target functions and ensuring transparency in their responses could help to reduce systemic feedback effects. Furthermore, it may be necessary to calibrate an AI agent’s mandate or level of autonomy based on the degree of human involvement. Escalation mechanisms that trigger human review or intervention in the event of unusual constellations of data could likewise be needed. 44

6 Implications for central banks

Agentic payments can impact the tasks of central banks in a variety of ways, with the implications for payments being especially prominent. Agentic payments could amplify bank run risks, as the capacity for autonomous action combined with collective behaviour can jeopardise financial stability. Given the general trend towards 24/7 availability of instant payment settlement systems and developments in digital finance, this threat is not, in structural terms, a new one. Nevertheless, it is imperative that supervisors take due account of agentic payments and the risks that they entail. Central banks especially are likely to see more major implications when it comes to their roles as operators, catalysts and overseers in the payments landscape.

As operators of financial market infrastructures, central banks should play an active part in bringing the benefits of agentic payments to fruition, whilst also mitigating the associated risks. It is in central banks’ interests to make systems accessible for agentic payments in order to enable efficiency gains. At the same time, they should take into account possible system effects, such as multiple AI agents behaving in similar ways or the difficulty of predicting the outcomes of decision-making processes. 45 Financial market infrastructures could also be confronted with higher transaction volumes and frequencies. This is because agentic payments prefer cost-effective instant payments and, also, favour means of payment that support usage-based business models and machine-to-machine payments. Harmonised data standards, the establishment of interoperable infrastructures, transparent documentation, clear rules for working with probabilistic decision-making and the creation of suitable governance frameworks are therefore important. Some financial market infrastructures have already made preparations for the use of agentic payments. 46 New forms of central bank money (for example, CBDC) as well as newly developed settlement systems should account for the use of AI agents early on, when they are first being developed.

In their role as a catalyst, central banks provide impetus for constructive innovations in payments and support their development. The network-like way in which payments systems operate can give established systems considerable advantages. The danger of this is that path dependencies can result in a failure to move away from sub-optimal structures and an unwillingness to shoulder the high costs of initial investment in promising technologies. This is why central banks specifically foster innovation in their roles as catalysts. As new technologies require high degrees of cooperation and interaction, central banks bring together public and private actors, for instance in national and international forums.

Agentic payments could further reinforce the dominance of non-European market participants. This could hamper competition and thereby also weaken European sovereignty. When it comes to payments – which are part of critical infrastructure – the Eurosystem strives to ensure resilience and sovereignty through providers that are from Europe or regulated in Europe. At present, however, it is mainly non-European market participants that are offering solutions for agentic payments. 47 Competition and supplier diversity could be fostered through increased interoperability, open interfaces and easier market entry.

Autonomous AI agents that initiate transactions could also pose new challenges for supervision, payment systems oversight and the existing legal framework. Although the regulatory framework is fundamentally technology-agnostic by design, regulation may need to be adapted and refined to accommodate new (non-financial) actors and technologies and, above all, new risks. A key aspect is to ensure that agentic payments meet cyber security requirements, regardless of their provider. In addition, questions concerning how to apply the Second Payment Services Directive (PSD2) in practice as well as the potential need to adapt the Principles for Financial Market Infrastructures, 48 which are foundational to payment systems oversight around the world, could take on greater prominence. As a rule, the principle of “same business, same risks, same rules” should apply in order to ensure fair competition and avoid regulatory arbitrage. At the same time, however, innovation that boosts efficiency should be facilitated, for example by applying the principle of prudential proportionality. 49

AI systems’ probabilistic decision-making must be transposed to deterministic logic. Payment systems and even DLT systems themselves are based on clear deterministic rules, unambiguous accountability and legal certainty. Agentic payments, by contrast, reach decisions in a probabilistic manner. This is not inherently risky per se, but it can make outputs unpredictable and difficult to reproduce. Customers expect auditable, logical transactions. If random outcomes, such as in the order in which individual transactions are processed, have economic consequences, there may be legal, supervisory or balance sheet ramifications. In order to ensure legally sound, final settlement, providers of AI agents, payment service providers and financial market infrastructures could agree on a governance framework that translates probabilistic decisions into binding, deterministic processes prior to execution. 50 At the same time, it is necessary to set out clear rules about what AI agents are and are not permitted to do, especially with regard to payment authorisation and transmitting personal data in situations where payments are no longer directly authorised by users.

7 Conclusion

Agentic payments are more than just another step in the automation of payments. In some cases, they shift payment-related decisions from humans or deterministic systems to AI agents, potentially bringing tangible changes to market structures, efficiency, competition, security and the resilience of payments. They are strategically important primarily because they entail new technical layers in which decisions will be made about access, identity, authorisation, data flows and the selection of payment rails. Those who shape these layers will be in a position to exert significant influence over how payments work in future. Agentic payments thus also raise issues around European sovereignty in a critical infrastructure.

It is still uncertain whether their potential will be realised. Many applications are still in the early phases of development. The extent of their adoption in future depends not only on their technical performance, user acceptance and how they are treated from a regulatory perspective, but also on how the costs of AI services will evolve. If costs increase significantly, agentic payments are initially likely to be used only for complex cases or those where the potential for value added is particularly high. Not all of the options for agentic payments that are currently technically feasible would, in that case, actually be implemented. 51

The use of agentic payments raises new kinds of challenges. The probabilistic decision-making process of AI agents can only guarantee auditable and legally sound payments if it is transposed into unequivocal and verifiable payment instructions. Clear mandates, reliable identity and authorisation mechanisms, effective control and escalation mechanisms, and clear liability and governance rules are therefore needed. In addition, there are new types of risks stemming from manipulation, flawed decisions, herd behaviour and potential tendencies towards concentration around small numbers of protocols, platforms and non-European providers.

Central banks should address the potential implications of agentic payments at an early stage. As operators of financial market infrastructures, they should examine how their own systems can interact with agent-based applications in a secure and controlled manner. As catalysts, central banks can foster dialogue between public and private actors, support interoperability, and help to ensure that there is a set of open and secure standards that will drive competition. As overseers, they should analyse the impact on stability, resilience, cyber risks and governance on an ongoing basis and, where appropriate, work towards refining existing rules.

The crucial point is therefore not simply whether agentic payments will be used in the future, but under what conditions they will be used. An appropriate framework should be technology-agnostic, risk-oriented and proportionate, whilst ensuring that the principle of “same business, same risks, same rules” is upheld. In this way, agentic payments will be able to contribute to a more efficient and innovation-friendly payments system without jeopardising trust in the system’s ability to function.

List of references

Acemoglu, D. (2025), The simple macroeconomics of AI, Economic Policy, Vol. 40, Issue 121, pp. 13‑58.

Agentic Commerce Protocol (2026), Agentic Commerce Protocol – An open standard for programmatic commerce flows between buyers, AI agents, and businesses.

Aldasoro, I. and A. Desai (2025), AI agents for cash management in payment systems, BIS Working Papers No 1310.

Araujo, D., S. Doerr, L. Gambacorta and B. Tissot (2024), Artificial intelligence in central banking, BIS Bulletin No 84.

Bornet, P., J. Wirtz, T. H. Davenport, D. De Cremer, B. Evergreen, P. Fersht, R. Gohel and S. Khiyara (2025), Agentic Artificial Intelligence: Harnessing AI Agents to Reinvent Business, Work, and Life, World Scientific, July 2025.

Calvano, E., G. Calzolari, V. Denicolò, V. and S. Pastorello (2020), Artificial Intelligence, Algorithmic Pricing, and Collusion, American Economic Review, Vol. 110, No 10, pp. 3267‑3297.

Canton Network, The (no date), Canton ecosystem.

Committee on Payment and Settlement Systems and Technical Committee of the International Organization of Securities Commissions (2012), Principles for financial market infrastructures.

Consumer Bankers Association (2026), Agentic AI Payments: Navigating Consumer Protection, Innovation, and Regulatory Frameworks, 22 January 2026.

Davidovic, S. and H. Tourpe (2026), How Agentic AI Will Reshape Payments, IMF Notes No 2026/004.

Deutsche Bundesbank (2023), Digital money: options for the financial industry, Monthly Report, July 2023, pp. 17‑32.

Deutsche Bundesbank (2021), Digital money: options for payments, Monthly Report, April 2021, pp. 57‑75.

Deutsche Bundesbank (2019), Crypto tokens in payments and securities settlement, Monthly Report, July 2019, pp. 39–59.

Deutsche Bundesbank (2017), Distributed ledger technologies in payments and securities settlement: potential and risks, Monthly Report, September 2017, pp. 35‑49.

Diehl, M. (2013), Measuring free riding in large-value payment systems: the case of TARGET2, Journal of Financial Market Infrastructures, Vol. 1, No 3, pp. 31‑53.

Elgendy, I. A., M. Y. I. Helal, M. A. Al-Sharafi, M. A. Albashrawi, M. S. Al-Ahmadi, I. Jeon and Y. K. Dwivedi (2025), Agentic systems as catalysts for innovation in FinTech: exploring opportunities, challenges and a research agenda, Information Discovery and Delivery, 27 May 2025.

European Central Bank (2025), Report on card schemes and processors.

Feng, K., D. McDonald and A. Zhang (2025), Levels of Autonomy for AI Agents, Knight First Amendment Institute.

Financial Stability Board (2026), Sound Practices for Responsible Adoption of Artificial Intelligence (AI), Consultation report, 10 June 2026.

Financial Stability Board (2024), The Financial Stability Implications of Artificial Intelligence, 14 November 2024.

Fourez, P. (2025), Scaling agentic commerce with trust, Mastercard, 14 October 2025.

Gartner (2025), Gartner Predicts Over 40 % of Agent AI Projects Will Be Canceled by End of 2027, 25 June 2025.

Giesen, H. (2026), Agentic Finance verändert Geschäftsmodelle von Banken, bank und markt – Die digitale Bank, Vol. 55, No 3, pp. 25‑27.

Google (2025), Announcing the Agent2Agent Protocol (A2A).

Grabowski, M. and I. Costea (2026), Selected European Law Challenges Related to the Use of Artificial Intelligence Payment Agents, IMFS Working Paper Series No 232.

Gutowska, A. (no date), What are AI agents?, International Business Machines Corporation.

Hale, C. (2026), Experts warn software budgets could be set to soar as AI bills are on the rise, TechRadar Pro, 17 July 2026.

Jonas, O. (2026), Deutschlands erste agentische Transaktion: Mastercard bringt Agentic Commerce gemeinsam mit Deutsche Bank, DZ Bank und N26 in die Praxis, Mastercard, press release of 13 May 2026.

Kezron, I. E. (2024), Securing the AI supply chain: Mitigating vulnerabilities in AI model development and deployment, World Journal of Advanced Research and Reviews, Vol. 22, No 2, pp. 2336‑2346.

Kirilenko, A., A. S. Kyle, M. Samadi and T. Tuzun (2017), The Flash Crash: High-Frequency Trading in an Electronic Market, Journal of Finance, Vol. 72, No 3, pp. 967‑998.

Kumar, M. (2025), Balancing Probabilistic and Deterministic Intelligence: The New Operating Model for AI‑Driven Enterprises, Acceldata, 17 July 2025.

Levine, A. (2026), The Pricing Crisis Clouding the AI Trade, Barron’s, 2 July 2026.

Li, S. and K. Heine (2026), Developing a harm-based approach to understand digital vulnerability in the era of AI: a perspective of the European Union, Computer Law & Security Review, Vol. 60, Article No 106266.

MacFadden, D. (2026), Who pays for AI?, Financial Times, 17 July 2026.

Monetary Authority of Singapore (2026), Safeguards for Agentic Finance at Runtime, Information Paper, 3 July 2026.

Morgan Stanley (2025), Here Come the Shopping Bots, 8 December 2025.

Noel, T. (2026), Purpose-Built Payment Infrastructure for Autonomous AI Agents: A Hybrid Stablecoin-Fiat Architecture with Graduated Autonomy, working paper.

Panjwani, R., A. Mathur and N. Aggarwal (2025), Agentic AI Will Rewrite the Rules, in Global Payments Report 2025: The Future Is (Anything but) Stable, Boston Consulting Group, September 2025.

PayPal (2025), PayPal Launches Agentic Commerce Services to Power AI‑Driven Shopping, press release of 28 October 2025.

Quick, J., C. Colter, L. Dillingham and K. T. Cochran (2025), The Next Wave Arrives: Agentic AI in Financial Services, FinRegLab, September 2025.

Reppel, E., N. Dalal and D. Kim (2025), Introducing x402: a new standard for internet-native payments, Coinbase Developer Platform, 6 May 2025.

Schumacher, K., R. Roberts and K. Giebel (2025), The agentic commerce opportunity: How AI agents are ushering in a new era for consumers and merchants, McKinsey & Company, 17 October 2025.

Sundararajan, R., U. Jeenah and A. Ellis (2025), The end of inertia: Agentic AI’s disruption of retail and SME banking, McKinsey & Company, 15 August 2025.

Tenner, T. and N. Glasmeier (2026), The future of artificial intelligence (AI): The rise of autonomous AI systems and their potential in banking, Journal of Digital Banking, Vol. 11, No 1, pp. 25‑32.

Universal Commerce Protocol (no date), Universal Commerce Protocol – The common language for platforms, agents, and businesses.

Vaswani, A., N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser and I. Polosukhin (2017), Attention Is All You Need, Advances in Neural Information Processing Systems, Vol. 30.

Visa (2025), Find and buy with AI: Visa unveils new era of commerce, press release of 30 April 2025.

Weis, F., B. von Walter and S. Hofer-Fischer (2026), Generative Engine Optimization (GEO), Wirtschaftswissenschaftliches Studium, Vol. 55, No 5/6, pp. 48‑52.

Williamson, O. E. (1985), The Economic Institutions of Capitalism – Firms, Markets, Relational Contracting, Free Press.

Worldpay (2025), The Agentic Commerce Report 2025.

Xing, W., M. Li, M. Li and M. Han (2026), Towards Robust and Secure Embodied AI: A Survey on Vulnerabilities and Attacks, ACM Computing Surveys, Vol. 58, No 12, pp. 1-36.

Zetzsche, D. A., D. W. Arner, R. P. Buckley and B. Tang (2020), Artificial Intelligence in Finance: Putting the Human in the Loop, CFTE Academic Paper Series: Centre for Finance, Technology and Entrepreneurship, Vol. 1, University of Hong Kong Faculty of Law Research Paper No 2020/006.