Every payment system built over the last fifty years assumes the same thing: a human is at the keyboard, clicking “buy.” That assumption is now breaking. AI agents are booking travel, restocking inventory, and comparing prices without a person approving each step and increasingly, without a person present at the moment money actually moves. Agentic payments infrastructure is the plumbing being built to make that safe: the identity, authorization, and settlement layer that lets an autonomous agent transact on a person’s or business’s behalf without turning every purchase into a fraud risk.
McKinsey estimates agentic commerce could generate $3 to $5 trillion globally by 2030, with Morgan Stanley projecting as much as $385 billion of that in U.S. e-commerce spend alone. For banks, fintechs, and platforms built on Banking-as-a-Service rails, this isn’t a distant trend to watch. It’s a design question that’s already showing up in how payment authorization, compliance, and settlement need to work.

Defining Agentic Payments Infrastructaure:
Agentic payments infrastructure is the set of protocols, credentials, and settlement rails that let an AI agent initiate, authorize, and complete a payment on behalf of a user or organization while still giving merchants, banks, and card networks a way to verify that the agent was actually authorized to act, and within what limits.
This matters because traditional payment infrastructure was never built to answer a basic question: is the party clicking “confirm” a human, a script, or an autonomous agent making its own decisions within a budget? The International Monetary Fund’s April 2026 analysis frames this as a structural tension: payment infrastructure is built on deterministic rules, while agentic AI behavior is probabilistic. Agentic payments infrastructure exists to reconcile that gap by putting hard boundaries, spend limits, merchant categories, human-approval triggers around inherently flexible AI decision-making.
How Agentic Payments Infrastructure Works?
Most emerging frameworks split the problem into three layers: intent, authorization, and settlement. Intent is where a user tells an agent what to do “buy concert tickets the moment they go on sale,” or “reorder inventory when stock drops below 200 units.” This step captures the human’s actual goal and any conditions attached to it.
Authorization is where the system proves the agent is acting within the scope the user actually granted. Google’s Agent Payments Protocol (AP2), announced September 16, 2025 with more than 60 payments and technology partners including Mastercard, PayPal, Coinbase, and American Express, handles this through cryptographically signed “mandates.” An Intent Mandate captures what the user asked for and any conditions; a Cart Mandate creates an immutable record of the exact items and price once the agent finds a match; a Payment Mandate authorizes the actual charge. The protocol itself doesn’t move money; it produces a verifiable record that a specific payment was authorized, which any settlement rail can then act on. (AP2 is easy to confuse with OpenAI and Stripe’s Agentic Commerce Protocol, announced two weeks later on September 29, 2025 the two are separate standards from separate companies, covered below.)
Settlement is the actual movement of funds, and this is where existing payment infrastructure card networks, bank transfers, and stablecoin rails still do the work. Agentic payments infrastructure doesn’t replace settlement rails; it adds an authorization layer in front of them.
The Protocols Taking Shape in 2026:
A handful of frameworks are emerging as the building blocks for agentic commerce, and they’re largely designed to complement each other rather than compete. The field has grown well beyond the two or three protocols that dominated headlines in late 2025 by mid-2026, at least six distinct standards are live, each anchored to a different part of the payment stack:
- Google’s AP2 standardizes the authorization layer through signed mandates and is payment-rail agnostic, supporting cards, bank transfers, and stablecoins.
- OpenAI and Stripe’s Agentic Commerce Protocol (ACP), announced September 29, 2025 and co-created by the two companies under an Apache 2.0 open license, defines how an AI agent interacts with a merchant’s systems across the full purchase lifecycle: catalog browsing, cart management, checkout, and payment. ACP already powers Instant Checkout inside ChatGPT. Stripe followed on December 11, 2025 with the Agentic Commerce Suite (ACS), a merchant-side toolkit that lets a business plug into multiple AI agents through one low-code integration instead of building a separate connection for each. ACS is built around Shared Payment Tokens (SPTs) credentials a user issues to an agent that are scoped to one seller, capped at a set amount, and expire at a fixed time along with the Stripe Agent Toolkit for developers. Coach, Kate Spade, URBN (Anthropologie, Free People, Urban Outfitters), Revolve, Ashley Furniture, Etsy, and Shopify merchants including Glossier and Spanx are among the named businesses already onboarding.
- Visa’s Trusted Agent Protocol (TAP), introduced in October 2025 with more than 10 launch partners, helps merchants distinguish a legitimate AI agent acting on a consumer’s behalf from a malicious bot a distinct problem from authorization, closer to identity and fraud screening.
- Mastercard’s Agent Pay, launched in April 2025 with Microsoft and IBM as early partners, issues “Agentic Tokens” that bind a tokenized card credential to a specific agent, merchant scope, and consent policy. Mastercard extended this in June 2026 with Agent Pay for Machines, aimed at continuous agent-to-agent and machine-to-machine payments rather than one-off consumer purchases.
- Stripe and Tempo’s Machine Payments Protocol (MPP), launched March 18, 2026, targets a different problem than ACP or AP2: machine-to-machine and API-level payments rather than consumer checkout. MPP embeds payment negotiation directly into HTTP and MCP requests, so an agent can hit an endpoint, receive a standard “payment required” response, pay in a stablecoin or card rail, and get the resource back in one round trip. Visa joined as a design partner to extend MPP to card rails, and Lightspark added Bitcoin Lightning support.
- Ant International’s Agentic Mobile Protocol (AMP), open-sourced April 28, 2026, is the first agentic payment framework built specifically for mobile interfaces digital wallets, banking apps, super apps, and wearables rather than the card-rail assumptions behind AP2 and ACP. AMP connects agents to Alipay+’s network of wallets across Southeast Asia and beyond, which matters given that global digital wallet users reached 4.4 billion in 2025 and are projected to exceed 6 billion by 2030.
Running underneath several of these sits x402, an open standard Coinbase open-sourced in May 2025 (later co-governed with Cloudflare through the x402 Foundation) that turns the long-dormant HTTP 402 “Payment Required” status code into a stablecoin settlement mechanism. It’s sometimes described as an extension of AP2, but x402 functions as its own standalone protocol: a server can return a 402 response with payment terms, an agent signs a token transfer, and the resource is delivered once a facilitator confirms on-chain settlement, all in a single round trip and without an account or API key. By spring 2026 x402 had processed more than 150 million transactions totaling roughly $50 million in volume evidence that the “pay-per-call” model for API and compute access is already running in production, not just theoretical.
None of these protocols move money entirely on their own. They sit above existing bank and card rails, adding the identity, authorization, or fraud-screening layer those rails were never built to provide.
Comparing the Major Protocols:

| Protocol | Backer(s) | Layer it solves | Credential type | Rail support | Status (mid-2026) |
| AP2 | Google, 60+ partners | Authorization (consumer) | Signed Mandates (Intent, Cart, Payment) | Cards, bank transfers, stablecoins | Live, widely adopted |
| ACP / ACS | OpenAI, Stripe | Checkout lifecycle (consumer) | Shared Payment Tokens | Cards, wallets | Live, named merchants onboarding |
| TAP | Visa | Agent identity / fraud screening | Agent credentials at checkout | Visa network | Live, 10+ launch partners |
| Agent Pay | Mastercard | Card-scoped authorization | Agentic Tokens | Mastercard network | Live; extended to machine-to-machine (June 2026) |
| MPP | Stripe, Tempo, Visa | Machine-to-machine / API payments | HTTP-native payment request | Stablecoins, cards, Bitcoin Lightning | Live since March 2026 |
| AMP | Ant International | Mobile wallet / super-app checkout | Wallet-native agent credentials | Alipay+ wallet network | Live since April 2026 |
| x402 | Coinbase, Cloudflare (x402 Foundation) | Machine-to-machine micropayments | HTTP 402 payment header | Stablecoins (multi-chain) | Live, 150M+ transactions |
The Fraud Problem Agent Transactions Create:
Most existing fraud detection was built to read human behavioral signals: how someone moves a mouse, how they type, which device they’re on. An AI agent generates none of that. It doesn’t hesitate at a suspicious price, doesn’t have a recognizable typing cadence, and can complete a checkout flow in milliseconds. That gap is precisely why identity and fraud-screening protocols like Visa’s TAP exist as their own category, separate from authorization protocols like AP2.
The problem is already showing up in the numbers. Experian’s January 2026 fraud forecast identified agentic AI as having crossed a threshold where it now surpasses human error as a leading cause of data breaches and financial fraud, and nearly 60% of businesses reported increased fraud losses from 2024 to 2025. Stripe’s own 2025 fraud report found that a quarter of the testing attacks it blocks now involve fraudulent actors attempting more than a million transactions against a single business patterns consistent with automated, agent-scale probing rather than one-off human fraud. That’s part of why Stripe ships dedicated agentic fraud signals as part of the Agentic Commerce Suite, rather than relying on the behavioral fraud tools built for human checkout.
For platforms preparing to support agent-initiated payments, fraud screening needs to be treated as its own requirement, not folded into general compliance controls. That means monitoring for machine-speed transaction patterns specifically, not just flagging activity that looks unusual for a human.
Real Pilots Already in Production:
This isn’t purely theoretical. Visa’s own newsroom names specific closed-beta deployments running on its Intelligent Commerce infrastructure as of late 2025: Skyfire is powering a Consumer Reports product-recommendation agent through a demonstrated Bose headphones purchase via browser automation; Nekuda is letting Gensmo’s fashion app move a user from an AI-styled outfit to a one-tap purchase at Fabrique through Rye’s checkout API, and separately enabling Henry Labs to complete Price.com purchases at Honeylove; and PayOS is providing BeyondStyle with the payment infrastructure behind agent-driven checkout at Jomashop. On the B2B side, Ramp is applying Visa Intelligent Commerce to its spend-management platform so business buyers can settle invoices instantly with full reconciliation, rather than routing every payment through a manual approval queue.
Regulated banking has moved past the pilot-only stage too. On March 2, 2026, Banco Santander and Mastercard completed what they describe as Europe’s first live, end-to-end payment executed by an AI agent not in a sandbox, but on Santander’s production payments infrastructure, using Mastercard Agent Pay with PayOS handling orchestration. The transaction followed earlier live milestones from Commonwealth Bank of Australia and DBS Singapore, meaning agent-initiated payments have now cleared regulated banking rails on three continents within a matter of months.
These are still named as pilots and closed betas rather than mass-market rollouts, which matters for how to read the hype around this space: the plumbing is real and running live transactions, but it’s running at pilot scale, with a small set of named partners, not yet as default checkout infrastructure.
Where Agentic Commerce Is Still Struggling?

Coverage of agentic payments tends to lead with the protocol launches and skip the adoption numbers, which is worth correcting. Forrester’s own tracking data shows US consumer adoption of OpenAI’s Instant Checkout feature stayed low and largely flat from its debut through its discontinuation, and broader consumer interest in letting an AI agent complete a purchase remains lukewarm outside of specific groups Forrester’s data points to younger and male consumers as the most receptive segments so far, not a broad base.
OpenAI’s own pivot is a useful signal here: as of April 2026, the company moved away from pure in-chat “Instant Checkout” toward a merchant-controlled checkout model, where the AI agent handles discovery and intent but the merchant’s own systems retain control of the final transaction and remain the system of record. That’s a meaningful walk-back from the original vision of an agent completing a purchase entirely inside a chat interface, and it suggests the industry is converging on a model where agentic infrastructure augments existing merchant and payment systems rather than replacing them outright.
For a Banking-as-a-Service platform, the practical read is that the underlying authorization and settlement layer matters more right now than any single consumer-facing checkout experience protocols and infrastructure are advancing faster than consumer behavior is shifting, and that gap is exactly where BaaS providers have room to build ahead of demand rather than chasing it.
Why This Matters for Banking-as-a-Service and Payment Infrastructure?
For a platform issuing accounts, moving funds, or processing payments on behalf of customers, agentic commerce changes what “authorization” needs to mean. A transaction monitoring system built to flag an unusual human purchase pattern isn’t necessarily built to evaluate whether an AI agent stayed within a spend cap its owner set three weeks earlier. Ledgering needs to record not just that a payment was cleared, but which mandate authorized it and under what conditions. Compliance workflows need an answer to “who is accountable if an agent transacts outside its scope” that holds up under actual regulatory scrutiny a question the IMF’s analysis identifies as still largely unresolved industry-wide.
This is consistent with a broader shift already underway in banking and payments infrastructure: AI moving from pilot programs into production systems that make decisions with less direct human oversight. Deloitte’s 2026 Banking Outlook points to exactly this shift as the next phase after several years of AI pilots, and agentic AI is increasingly reaching board-level agendas at banks and credit unions.
What to Look for in Agentic-Ready Payment Infrastructure?

A platform preparing to support agent-initiated payments whether that’s an AI shopping assistant, an automated procurement system, or a machine-to-machine billing flow needs infrastructure built around a few specific requirements:
Mandate-aware ledgering:
The system of record needs to capture not just that a transaction happened, but the authorization chain behind it: what was requested, what conditions were attached, and what was actually charged.
Compliance controls that don’t assume a human is present:
KYC, AML, and transaction monitoring workflows built around human behavioral patterns need extending to account for agent-initiated activity, including sanctions and fraud screening that can operate at machine speed.
Multi-rail settlement:
Agentic transactions increasingly span card rails, bank transfers, and stablecoin settlement in the same workflow, so payment infrastructure needs to support more than one settlement path without forcing a separate integration for each.
Named, verifiable accounts:
Whether the ultimate payer is a person or an agent acting for a business, the underlying account structure still needs to resolve to an identifiable, compliant entity the same requirement that’s always underpinned banking relationships, just applied to a faster-moving set of counterparties. This is the same principle behind Coinbase’s Agentic Wallets, launched February 11, 2026: rather than giving an agent unrestricted access to funds, the wallet infrastructure enforces programmable guardrails session spending caps, per-transaction limits, and defined operation allowlists so an agent’s authority is bounded and auditable even without a human approving each transaction. Named accounts that resolve to a real, compliant entity are what PRETpayments’ USA bank account issuance infrastructure is built around.
PRETpayments’ own Capabilities are built around this kind of foundation: named U.S. bank accounts, funds movement, ledgering, and a compliance program covering KYB/KYC/KYCC, beneficial ownership verification, sanctions and adverse-media screening, and transaction monitoring the infrastructure layer that agentic payment authorization ultimately has to settle against. That includes support for stablecoin settlement and domestic wire transfer infrastructure alongside traditional banking rails, which matters as agentic transactions increasingly move across more than one rail in a single workflow.
The Open Questions Still Being Worked Out:
Agentic payments infrastructure is still early. The IMF’s analysis flags authorization, liquidity management, settlement finality, compliance, and system resilience as the areas where agentic AI creates genuinely new problems rather than just faster versions of old ones for instance, what happens to liquidity planning when an agent can execute a chain of transactions in milliseconds rather than the hours or days a human approval process assumes. Liability is similarly unsettled: when an agent transacts outside the scope its owner intended, responsibility currently gets negotiated case by case rather than resolved by a standard.
For platforms building on Banking-as-a-Service infrastructure now, the practical takeaway isn’t to wait for these questions to resolve before preparing. It’s to build on infrastructure ledgering, compliance, and settlement flexible enough to absorb whatever the eventual standard looks like, rather than hard-coding assumptions about who, or what, is initiating a payment. If you’re planning a program that needs to support agent-initiated payments, contact the PRETpayments team to talk through your requirements.
Frequently Asked Questions
1. What is agentic payments infrastructure?
It’s the identity, authorization, and settlement layer that lets an AI agent initiate and complete a payment on a user’s or business’s behalf, while giving merchants and banks a way to verify the agent acted within its authorized scope.
2. Is agentic payments infrastructure the same as agentic commerce?
They’re related but distinct. Agentic commerce refers to the broader shift toward AI agents shopping and transacting on a user’s behalf. Agentic payments infrastructure is the underlying technical layer protocols, mandates, and settlement rails that makes that commerce possible and auditable.
3. What is Google’s AP2 protocol?
AP2 (Agent Payments Protocol) is an open protocol Google announced on September 16, 2025 with more than 60 partners. It uses cryptographically signed “mandates” to prove a user authorized a specific agent-led purchase, and it’s payment-rail agnostic, supporting cards, bank transfers, and stablecoins.
4. How is this different from Visa and Mastercard’s agentic payment products?
Visa’s Trusted Agent Protocol focuses on distinguishing legitimate AI agents from malicious bots at the point of checkout. Mastercard’s Agent Pay issues tokenized credentials scoped to a specific agent and consent policy. Both sit closer to the card-network layer, while AP2 operates as a protocol layer above individual networks.
5. What’s the difference between AP2 and Stripe/OpenAI’s ACP?
Both use signed, scoped credentials to authorize agent-led purchases, but they come from different companies and launched roughly two weeks apart in September 2025. AP2 is Google’s protocol, built to be rail-agnostic across card, bank, and stablecoin payments. ACP is OpenAI and Stripe’s protocol, purpose-built for the ChatGPT Instant Checkout experience and merchant integrations through Stripe’s Agentic Commerce Suite.
6. Does agentic payments infrastructure replace existing payment rails?
No. It adds an authorization and identity layer in front of existing rails card networks, bank transfers, and stablecoin settlement rather than replacing the infrastructure that actually moves funds.
7. What should a fintech or platform do to prepare for agent-initiated payments?
Build on payment and banking infrastructure that supports mandate-aware ledgering, compliance workflows that don’t assume a human initiated every transaction, dedicated agentic fraud screening, and settlement across more than one rail, since agentic transactions increasingly span card, bank, and stablecoin paths in the same workflow.