Managing the health and status of a delegated authority ensures that an AI agent cannot exceed its pre-authorized budget or operational timeframe. As artificial intelligence shifts from mere conversational tools to autonomous agents capable of executing complex financial tasks, the industry faces a pivotal moment in payment security. This evolution, often termed agentic commerce, requires a fundamental shift in how transactions are authorized and authenticated. EMVCo has recognized this necessity by releasing its “EMV® Agentic Payments – Framework for Specifications” draft, which provides a roadmap for securing non-human financial interactions. The framework establishes a controlled environment where these software entities can perform transactions while remaining under the strict oversight of the consumer. This initiative is not merely about technical connectivity but about establishing a baseline of trust that allows merchants and banks to recognize AI-initiated payments as legitimate actors. By formalizing these roles, the industry prepares for a landscape where software acts as a primary economic participant in a global digital marketplace.
Part 1: Defining the Scope of Delegated Authority and Consent
The shift from human-driven transactions to agent-driven ones changes the very nature of consent. In traditional electronic payments, the user is present at the moment of purchase, providing immediate verification through biometric scans or PIN entries. Agentic commerce replaces this instantaneous interaction with a prolonged delegation of authority, where an AI might manage a household’s grocery budget or optimize enterprise supply chain payments over several weeks. This persistence introduces new risks, as the original intent must be preserved and verifiable throughout the entire lifecycle of the delegation. EMVCo addresses this by creating a structure where the scope of the agent’s power is clearly defined and immutable. By doing so, the framework ensures that the autonomous actor cannot deviate from the parameters set by the owner. This level of control is essential for preventing unauthorized spending and maintaining the integrity of the financial system in an era of automation.
Part 2: Maintaining the Integrity of the Shared Intent State
A critical component of this strategy is the “intent state,” a shared record that stays consistent as a transaction moves through various intermediaries. In a standard setup, information can become fragmented, but the agentic framework proposes a unified view of what the consumer originally authorized. This means that when an AI agent interacts with a merchant, the merchant can verify that the agent is acting within its allowed constraints. Furthermore, the issuing bank receives the same set of intent data, allowing its risk engines to confirm that the payment request aligns perfectly with the user’s predefined rules. This transparency reduces the likelihood of false declines while simultaneously hardening the system against sophisticated fraud attempts. By standardizing the way intent is expressed and shared, EMVCo is building a bridge between human desires and machine execution. This structural alignment ensures that every participant remains protected against the vulnerabilities inherent in autonomous financial decision-making.
Part 1: Orchestrating Payments via Interoperable Intent Services
To support the orchestration of these complex payment flows, the framework introduces the concept of Intent Services. These services function as a specialized layer within the existing payment architecture, specifically designed to register and track the authorizations granted to AI agents. Rather than relying on isolated databases, Intent Services offer an interoperable solution where different platforms can communicate seamlessly. This centralized yet distributed approach allows for the real-time retrieval of delegation details, ensuring that the “health” of an agent’s authority is always known. For instance, if a consumer decides to revoke an agent’s access or if a specific budget limit is reached, the Intent Service updates this status across the network immediately. This capability is vital for managing high-frequency transactions that might otherwise overwhelm traditional fraud detection systems. By providing a single point of truth for authorization, these services streamline the process for all stakeholders involved in the digital commerce chain.
Part 2: Implementing Know Your Agent Protocols for Identity
Security in an autonomous environment also requires the implementation of “Know Your Agent” (KYA) protocols. These are a digital evolution of the traditional “Know Your Customer” standards, designed to verify the identity and legitimacy of the software entities conducting commerce. By using specific agentic transaction indicators within the payment data stream, merchants and issuers can distinguish between a legitimate, authorized autonomous agent and potentially fraudulent automated activity. These indicators communicate specific agent attributes, allowing risk engines to adjust their parameters accordingly. For example, a high volume of transactions that might look suspicious if performed by a human could be perfectly normal for an AI managing enterprise logistics. This nuanced understanding of transaction origins is fundamental to scaling agentic commerce safely. By establishing these identity and status protocols, EMVCo ensures that autonomous actors are as recognizable and accountable as the human users they represent.
Part 1: Adapting Existing Security to Autonomous Commerce
Rather than discarding current infrastructure, EMVCo plans to secure the future by evolving existing technologies like EMV 3-D Secure and payment tokenization. The framework identifies opportunities to adapt these protocols so they can support agent-led interactions without exposing sensitive cardholder data. For instance, EMV Payment Tokenization can provide secure credentials specifically for use by AI agents, while Secure Remote Commerce standards can be streamlined to allow agents to navigate checkouts efficiently while maintaining the highest levels of encryption. This approach leverages the global footprint of existing systems, ensuring that the transition to agentic payments is both cost-effective and secure for participants. By utilizing restricted tokens that are bound to specific tasks or merchants, the risk of broad-scale credential theft is minimized. This strategic integration ensures that the underlying mechanics of payment remain robust even as the entities initiating the transactions undergo a fundamental shift.
Part 2: Achieving Global Scalability through Collaboration
The publication of this draft framework represented a pivotal moment for the financial industry as it sought to standardize autonomous interactions. Stakeholders from across the globe collaborated to refine these specifications, ensuring they met the rigorous demands of modern security and interoperability. This period of development highlighted the necessity of maintaining a unified approach to prevent the fragmentation of digital markets. EMVCo invited industry participants to provide feedback on the draft through 2026, ensuring that the final specifications were refined by real-world insights from merchants and banks. Organizations analyzed their current risk management systems and integrated agentic indicators to better identify machine-led transactions. This proactive strategy ensured that the global payment ecosystem remained resilient during the widespread adoption of AI agents. By establishing these foundations, the industry prepared for a future where software operates with the same integrity as human participants.
