
AI agents are increasingly performing purchases on behalf of users, creating new challenges for the payments industry. According to Suresh Sethi, Group Country Manager, India & South Asia, Visa, as reported by The Economic Times, "Agents are today going out and doing the purchase for you. They are looking at variants, creating the carts and doing checkouts." This fundamental shift means the traditional human buyer may soon be replaced by artificial intelligence agents that discover products, compare options, create carts and complete purchases. The internet was built for human interaction, but commerce now needs to become "agent-ready," requiring websites and payment systems to recognize legitimate AI agents and establish that they are acting on user intent. "Today, how people are discovering and purchasing stuff is going to be a very critical determinant as to how payments evolve," Sethi explained, adding that "the entire experience can be delegated."
The biggest challenge for banks, payment networks and merchants will be establishing trust in AI-driven transactions. As reported by The Economic Times, "Now, we are looking at a scenario where the trust has to be actually built into intent," Sethi explained, noting that "the human intent of whatever you are giving as the program decision and the permission has to stay corrected." Trust will increasingly be "at the bedrock rather than just looking at how you make the journey faster." According to PD Singh, CEO-India & South Asia, Standard Chartered, "AI will drive the next phase of payments, but safety will remain more important than sheer speed." The industry will need to move away from static fraud rules toward real-time, risk-based intelligence that examines factors such as transaction velocity, timing, value and behavioral patterns. "Static rules do not work. Static rules can only look backwards for you," Sethi observed, adding that "whenever you have a challenge, you slow the transaction, you take your time and make out whether it is true or not."
Before granting AI agents full autonomy, companies must establish clear permission boundaries and safety mechanisms. According to DigitalShield, "The more difficult it is to undo an action, the more sense it makes to maintain some type of human control." Creating an incorrect task can be corrected in seconds, but authorizing payments, accepting contracts, or modifying bank accounts belongs to another category requiring human oversight. A well-designed agent should resemble an employee with specific responsibilities rather than a digital god with universal access. There will be decisions where wanting a person at the end will not be a sign of technological backwardness, but a perfectly rational decision. The key lies in distinguishing between three capabilities: consulting information, preparing actions, and executing them, with agents able to read inboxes, detect urgent messages, and classify them without modifying anything important. Utility and access are not the same thing - an agent can read emails and detect urgent messages without modifying anything important, draft responses for review, or send them automatically without approval.
New solutions are emerging that address the trust and security challenges by giving users direct control over AI agent spending. According to recent developments, control-based payment systems allow users to approve every agent purchase request while maintaining full visibility into agent activity. These systems enable agents to pay using one-time-use cards or shared payment tokens across businesses online, with users receiving alerts when agents are ready to make purchases. Users can track agent activity and set controls for when agents can spend with or without approval, ensuring that payment credentials are never exposed to AI agents. The systems also allow agents to access purchase history and shop smarter on behalf of users, with next-generation payment protocols and digital currencies supported for enhanced security and functionality. Setting a maximum number of operations per hour, establishing maximum amounts, restricting recipients, determining operating hours, and limiting accessible folders are all crucial controls that can be implemented. Controls can't be a post-facto bolt-on. You must do it as a part of the transaction, as noted by Madhav Kalyan, managing director and head of payments, JP Morgan Asia Pacific.
Industry leaders anticipate significant changes in banking operations as AI adoption accelerates. PD Singh, CEO, India & South Asia, Standard Chartered, told The Economic Times that "banks, as we know them today, may not be in the same form in the next three to five years." For Coinbase's John O'Loghlen, the growing interaction between machines makes guardrails even more important, with human oversight, regulation, governance and security remaining critical as AI agents begin making decisions with real financial consequences. "When machines are talking to machines, there have to be guardrails in place," cautioned O'Loghlen, adding that Coinbase requires human confirmation for code touching customers. "At a customer level, they don't really care about the rail or the tool that is being used. All they care about are outcomes," said Madhav Kalyan, noting that consumers focus on "whether it is delivered speedily? Is it delivered in a reliable manner? Is it delivered in a cost-efficient way?" Banks that can verify identity and authority, ensure settlement certainty, carry data and keep transactions auditable can move beyond being merely infrastructure providers to become "trusted value providers in the payments ecosystem."