Agentic payments need operating controls, not only a trusted identity
Visa, Mastercard and Ant International are aligning how payment ecosystems recognise purchasing agents. Their proposal already reaches beyond identity, but organisations still need to own limits, exceptions, revocation and redress.

What happened
Ant International, Mastercard and Visa announced work on a Know-Your-Agent interoperability framework for cards, wallets, agent platforms and marketplaces, while preserving each network's own verification and decision processes.
Why it matters
Shared trust signals may reduce duplicate integration, but they do not decide an organisation's spending mandate, exception policy, escalation threshold or accountability when an agent acts incorrectly.
Ant International's 10 September announcement says it has begun working with Mastercard and Visa on a Know-Your-Agent, or KYA, interoperability framework. The intended participants are card networks, digital-wallet ecosystems, agent platforms and marketplaces. An accessible syndicated copy of Reuters' report independently confirms the announcement and its stated scope.
This is exploratory alignment, not a completed common standard. The organisations say they will build on Visa's Trusted Agent Protocol, Mastercard Verifiable Intent and Ant International's Agentic Mobile Protocol through BuildFin.ai, a platform convened by the Monetary Authority of Singapore. Ant's release says common trust signals could reduce duplicate verification and integration work, while each network keeps its own verification and decisioning. Those are objectives stated by the participants, not measured outcomes.
The proposal is broader than identity
It would be a mistake to describe the initiative as identity alone. Ant lists three centres of collaboration: linking an agent to a validated operator, cardholder or organisation; shared security and behavioural certification requirements; and continuous monitoring using identity and transaction-related signals. Mastercard's Verifiable Intent description goes further, presenting a tamper-resistant record that links identity, a user's specific instructions and the resulting purchase. Visa's protocol specification describes signed agent recognition and information that merchants can use to control or limit an interaction.
That counterevidence narrows the editorial claim. The gap is not that payment protocols ignore intent or monitoring. It is that interoperability between trust signals cannot by itself determine a buyer's local mandate or operating response. A protocol may carry evidence that an agent and instruction are authentic; the deploying organisation must still define which sellers, categories, currencies and spending levels are allowed, what change invalidates consent, and who can pause or revoke authority.
The public material also does not establish production performance. Ant's announcement contains no final cross-network specification, implementation timetable, participating-customer results, fraud or false-positive rates, dispute outcomes, or measured integration cost. Mastercard said in March that integration with Agent Pay intent APIs would occur “in the coming months”. These pages show design direction and vendor commitments, not demonstrated effectiveness across three networks.
Turn the trust layer into an operating model
The IMF's April note on agentic payments supplies a useful independent stress test. It describes the tension between probabilistic agents and deterministic payment infrastructure, and identifies an instruction gap when broad mandates are used without transaction-level instructions. Its risk discussion includes authorization traceability, ambiguous liability, machine-speed error propagation and expanded API attack surfaces. The note is conceptual and says adoption remains early, so it is a risk framework rather than evidence that these failures have occurred at scale.
A practical operating model therefore needs four connected controls. First, verify the agent, its operator and the integrity of the trust signal. Second, bind each action to a current mandate: amount, merchant, purpose, time window and permitted substitutions. Third, enforce exceptions before commitment, including price changes, recurring charges, split orders, unavailable items and a switch of seller. Fourth, preserve observable pause, revocation, appeal and dispute paths, with an accountable human owner. High-value or unusual actions may require explicit approval; lower-risk actions still need machine-enforced limits and audit evidence.
This changes the capability plan. Product and procurement teams define delegation policy; payments and security engineers implement enforcement and telemetry; legal, privacy and risk teams decide evidence and redress requirements; customer operations must reconstruct what the user authorised and what the agent did. Teams should test expired mandates, replayed instructions, conflicting policies and partial checkout failures before enabling autonomous purchase.
The interoperability effort may make trustworthy signals more portable. It does not eliminate the organisational work of deciding what trust permits. The Skills Atlas can provide a vocabulary for policy translation, controls testing, monitoring and incident handling; payment owners still need to assign thresholds, evidence retention and decision rights.