Book a call

Authorised Is Not Intended: Where Agentic Payments Actually Stand in October 2026

Authorised Is Not Intended: Where Agentic Payments Actually Stand in October 2026

AI agents can now hold a card token, sign a mandate and pay for an API call in the same round trip. Mastercard says nearly every one of its cards can be used by an agent. Stripe has made checkout agent-ready at more than 7.8 million businesses. And yet, outside China, almost nobody is letting agents spend. We spent a week mapping the protocols, the card networks, the platforms, nine regions and the regulators. The gap between what is built and what is used comes down to one unanswered question. When an agent buys the wrong thing, who can prove what the human actually meant?

The short version

  • The problem. Agentic payments, where software finds, chooses and pays for something on your behalf, are fully plumbed but barely used. No card network has disclosed a single agentic volume figure in 2026 earnings. PayPal told investors the category becomes meaningful from 2028 onward.
  • The exception. China runs agent payments at consumer scale. Alipay's AI Pay passed 100 million users in February and 300 million cumulative transactions by late May. It works because one company owns the agent, the wallet and the merchants.
  • The reality check. OpenAI wound down ChatGPT Instant Checkout in March 2026, about six months after launch, with roughly 12 to 30 merchants live. Checkout went back to the retailers.
  • The real progress. It was institutional. The competing standards moved into neutral bodies (FIDO Alliance, Linux Foundation, IETF), and the networks built "know your agent" identity layers.
  • The blocker. The authorised-but-wrong purchase. You authorised the agent, but not the outcome. No major jurisdiction has a rule for it, and no card network has an agent-specific dispute code. Until the record of intent can settle a dispute, merchants carry the risk and the market stays small.

What changed in a year

A year ago the bet was simple: AI assistants would become shops. ChatGPT launched Instant Checkout with Etsy in September 2025, Instacart added the first full in-chat grocery checkout in December, and Visa predicted that "millions" of consumers would buy through agents by the 2026 holidays.

The bet did not pay off the way it was placed. Merchants refused to hand over the customer relationship. Walmart listed about 200,000 products in ChatGPT, found onboarding cumbersome and product data often wrong, and saw in-chat conversion at roughly a third of its own site's. In March OpenAI moved checkout to retailer apps inside ChatGPT and refocused on discovery. Shopify answered within weeks with Agentic Storefronts, which make merchants discoverable in ChatGPT, Copilot, Gemini and Google's AI Mode by default while keeping checkout on the merchant's own store.

So the 2026 default is a hybrid. Discovery happens in the AI. Payment happens where the merchant controls it. Google (through its Universal Commerce Protocol), Microsoft's Copilot Checkout and Perplexity still run checkout inside the conversation, but none of them has disclosed sales.

What the AI influences is large and growing fast. Adobe measured AI-referred visits to US retail sites up 138% year on year in May 2026, converting 54% better than other traffic. What the AI executes is still close to zero everywhere but China.

The stack is settling into four layers

The acronym soup of 2025 (ACP, AP2, UCP, TAP, MPP, x402) looked like a protocol war. By late 2026 it looks more like a stack, where each layer answers a different question.

The agentic payments stack, October 2026

  • Commerce and checkout: what is for sale, and how do I buy it? Google's Universal Commerce Protocol (UCP), launched in January with Shopify, Etsy, Wayfair, Target and Walmart, now has a ten-member Tech Council that includes Amazon, Meta, Microsoft, Salesforce and Stripe. OpenAI and Stripe's Agentic Commerce Protocol (ACP) survived its flagship's retreat and went through four revisions, but is still labelled beta. This is the one layer where a real contest remains.
  • Authorisation: did the human really ask for this? Google's Agent Payments Protocol (AP2) introduced signed "mandates": an Intent Mandate for your instruction, a Cart Mandate for your approval of an exact basket, and a Payment Mandate that tells the network an agent was involved. In April Google donated AP2 to the FIDO Alliance and released v0.2, which adds fully autonomous "human not present" purchases. Mastercard and Google's Verifiable Intent does a similar job: a tamper-resistant record linking who the cardholder is, what they instructed and what was bought.
  • Identity: is this agent who it says it is? Visa's Trusted Agent Protocol, built with Cloudflare, has agents sign each web request so a merchant can tell a shopping agent from a scraper. Mastercard registers agents and binds each one to a user through Agentic Tokens.
  • Settlement: how do machines pay each other tiny amounts? The web's long-unused "402 Payment Required" status code finally has a job. Coinbase's x402 passed about 205 million transactions worth roughly $53 million by August, an average of about 26 cents, and its governance moved to a Linux Foundation group in July. Stripe and Tempo's Machine Payments Protocol works across stablecoins, cards and wallets, and its core is now an IETF draft.

Underneath sit the two general-purpose agent standards, MCP for tool calls and A2A for agent-to-agent messaging, both now at the Linux Foundation.

Two things stand out from this map. First, cross-membership is dense. Stripe, Visa, Mastercard, Google and Shopify sit in almost every body, which is why the "war" framing faded. Second, the authorisation layer is where the hard problem lives, and it is the least tested in production.

Where the world actually stands

The regional picture divides cleanly. China ships. Everyone else counts "firsts".

Where agentic payments stand, by region

China is about a year ahead. Alibaba's Qwen app integrated AI Pay and Taobao in January. Around Chinese New Year, AI Pay handled more than 120 million transactions in a single week. Tencent followed in June, linking its WorkBuddy agent to a dedicated "AI card" in WeChat Pay, with the final confirmation on the user's phone. Two caveats: the volumes come from Alipay itself, and nearly every one of these payments still has a human confirming it. It is confirmed delegation, not autonomy. China also produced the world's first agent-specific conduct code, from the Payment & Clearing Association, which requires "know your agent" checks and filing before launching autonomous agent payments.

Everywhere else, the card networks ran a country-by-country series of firsts. Australia in January (cinema tickets and a ski-resort stay on CBA and Westpac cards). Santander in Europe in March. Singapore with DBS and UOB in March. Japan with MUFG Nicos in May. Worldline, ING and Crédit Agricole put production payments through in June. Mastercard reported live transactions across Latin America with 16-plus banks. Each was tokenised, explicitly confirmed by the customer, and tiny.

The interesting alternatives are the ones that skip cards. Ant International open-sourced an Agentic Mobile Protocol that rolls out across more than 40 Asian wallets and 1.8 billion accounts, with an Agent Trust Rating that sets how much autonomy an agent gets. In Brazil, Iniciador launched an MCP tool for agent payments over Pix, with each payment approved biometrically. India's NPCI is building agent payments into UPI itself.

Notice the pattern that runs through all of it, from Tencent's phone confirmation to Crédit Agricole's explicit validation. Wherever money actually moves, a human still approves the final step. Europe does it because Strong Customer Authentication requires it. China does it by design. Nobody has yet trusted the record of intent enough to take the human out.

Influence is booming. Delegation is not.

Influence versus delegation in agentic commerce

Every credible dataset tells the same story. Shoppers want AI to help them choose, and they are wary of letting it pay. Gartner found only 11% of US consumers would let AI make purchase decisions, and more than half of AI-using shoppers double-check everything. Merchants in Checkout.com's survey say about 3% of their transactions involve an agent, while 89% say they are preparing.

The forecasts span two orders of magnitude, from about $28 billion (Ant International) to $3–5 trillion (McKinsey) by 2030. That spread is mostly definitional. The trillion-dollar figures count commerce an agent influenced. Morgan Stanley's estimate for US e-commerce actually handled by agentic shoppers, $190–385 billion, is closer to the agent-paid market, and it assumes trust and liability get solved along the way.

The gap is an evidence problem

Here is the part we think matters most, and where the industry discussion is thinnest.

Payments law has two clean cases. If you made the purchase, it is yours. If a criminal hijacked your card, it is fraud, and you are protected. Agents create a third case: you authorised the agent, but not the outcome. You asked for "running shoes under $120 in my size". The agent bought trail shoes, in the right size, for $118. Was that authorised?

The authorised-but-wrong gap in one agent purchase

Current rules do not say.

  • In the US, Regulation E protects transfers made "without actual authority", which arguably excludes a mistaken purchase by an agent you empowered. The CFPB has issued no guidance. At Sibos on 29 September, Fed Governor Christopher Waller put it plainly: who is on the hook if an agent makes the wrong purchase?
  • In the EU, PSD3 and the Payment Services Regulation reached political agreement last November without mentioning AI agents.
  • The UK is furthest along. HM Treasury's July consultation asked whether consent, authentication and liability rules need rewriting for agents, and called for "Know Your Agent" protocols. It closed on 6 October.
  • Visa's April rulebook reportedly defines an "agentic transaction" but adds no agent-specific dispute reason code. OpenAI's spec states it is not the merchant of record. So disputes default to the merchant, who also loses fraud signals because the order carries the AI platform's device and IP address. In one survey, 93% of merchants said AI providers should carry the loss. None has volunteered.

Strip away the legal vocabulary and every one of these is the same question: what is the evidence of what the human intended, and what is the evidence of what the agent did? A dispute is a comparison between those two records. Today, the first record is a chat transcript the platform controls, and the second is a payment log the merchant controls. Neither side can prove the other's record is complete or unaltered.

That is why the mandate and intent-record work matters more than any checkout protocol. AP2 mandates and Verifiable Intent are the first serious attempt to make the human's instruction a signed artefact rather than a screenshot. But look at what the specs themselves leave out. AP2 calls issuing trusted identity keys out of scope. Visa's protocol proves which agent arrived at the merchant, not the chain of delegation behind it. And none of them records what the agent did in between: the pages it read, the options it rejected, the hidden instruction on a deals site that may have nudged it toward a gift card.

That middle part is not hypothetical. Palo Alto's Unit 42 has described prompt-injection scenarios that add items at checkout. Bot-defence firm DataDome counted more than 16 million spoofed requests claiming to be Meta's agent in two months. And fraud specialists expect the bigger near-term problem to be "my agent did it" refund abuse, which scoped tokens do nothing to stop. You cannot adjudicate any of these without a trustworthy record of the agent's run.

How we approach it

This is the same problem we work on, from the agent side rather than the payments side.

Tracekit keeps a signed, tamper-evident record of what an agent was asked, what it said and what it did. Records are hash-chained, signed by a process the agent cannot control, and anchored off the machine. For a payment dispute, that is the missing middle record: not just "the mandate said X and the network saw Y", but the verifiable sequence of steps that turned one into the other.

Causeway answers the next question a dispute raises: which input actually caused the purchase? It re-runs the agent without each suspect input and sees whether the action still happens. That is the difference between "the agent read a malicious coupon page" and "the malicious coupon page made the agent buy".

And for agents that hold money directly, our work on transaction guards moves the safety check to the moment of execution, because a check done before signing can be stale by the time the payment lands.

The trade-off is real. Evidence wants hashes and minimal content, so you can prove what happened without exposing it. Dispute resolution and model improvement want the content itself. Payment records add card data and personal information to that tension. Any design here has to choose per workflow what is kept in clear, what is redacted at write time, and who can verify it.

What these tools do not do yet

  • Tracekit is not a payment mandate standard. It does not replace AP2, Verifiable Intent or network tokens. It records the agent's run alongside them.
  • No card network currently accepts an agent trace as dispute evidence. Until rules change, a trace strengthens a merchant's or issuer's case but does not settle it.
  • Linking an agent's record to the verified human behind it is still an open problem across the whole ecosystem, including for us.
  • Causeway's replay is most useful for reconstructable runs. Some live web state cannot be replayed exactly.

Where to start

If you are building or deploying an agent that will spend money, these steps hold regardless of which protocol wins.

  1. Capture intent as an artefact, not a transcript. Record the human's instruction, constraints and approval as a signed object. Use AP2 mandates or Verifiable Intent if your stack supports them.
  2. Scope every credential. Use agent-bound tokens or single-use virtual cards, with per-merchant, per-amount and time limits and instant revocation. Never hand an agent a raw card.
  3. Record the run where the agent cannot edit it. Log tool calls, page reads and decisions through a mechanism outside the agent's control, signed and anchored.
  4. Keep a human on irreversible steps, deliberately. Waller called it "purposeful friction". The global pattern is already confirmed delegation. Design the confirmation so it shows the exact basket and price, not a summary.
  5. Treat every page an agent reads as untrusted input. Product pages, reviews and coupons are all prompt-injection surfaces. Separate what the agent reads from what it is allowed to do.
  6. Prepare your dispute file before the first dispute. Decide now which records you would hand an issuer, and check they can be verified by someone who does not trust you.

The takeaway

China proves agent payments work at hundreds of millions of transactions when one company owns the whole loop. The rest of the world built the plumbing in 2026 and then stopped at the same place: the moment a human has to trust that the agent did what they meant. The decisive change will not be another checkout protocol. It will be the first card network rulebook that lets a verifiable record of intent, and of the agent's run, settle a dispute. When that happens, liability stops being a blocker and becomes a priced risk. Until then, "authorised" and "intended" are different things, and the only way to close the gap is evidence.

Research for this piece covered public sources from September 2025 to 10 October 2026, including company announcements, earnings calls, regulator publications, standards drafts and trade press. Several figures, including Alipay's volumes and some protocol membership counts, are self-reported or come from secondary sources and are marked as such in our underlying notes.

← Back to Research