Visa, Mastercard and Ant Want AI Agents to Spend Your Money — But One Question Could Decide Whether Anyone Trusts Them

Business

Visa, Mastercard and Ant Want AI Agents to Spend Your Money — But One Question Could Decide Whether Anyone Trusts Them

SINGAPORE — The next revolution in online shopping may not begin when artificial intelligence recommends what you should buy.

It may begin when the AI buys it for you.

Ant International, Visa and Mastercard are joining forces to tackle one of the biggest obstacles standing between today’s AI assistants and a future in which software agents can independently shop, book services and execute payments on a consumer’s behalf: How does a merchant know the AI asking to spend your money is legitimate?

The three payments heavyweights announced a collaboration on a Know Your Agent, or KYA, interoperability framework, designed to make it easier for card networks, digital wallets, AI platforms and online marketplaces to recognize and verify trusted AI agents across different payment ecosystems.

The move could become a significant piece of infrastructure for the emerging world of agentic commerce, where AI systems go beyond answering questions or comparing prices and actually carry out purchases within limits established by users.

And the amount of money potentially moving through those systems is enormous.

McKinsey estimates AI agents could mediate or orchestrate roughly $3 trillion to $5 trillion in global consumer commerce by 2030, including as much as $900 billion to $1 trillion in U.S. B2C retail alone under its estimates.

But there is a problem: the internet was built to distinguish humans from bots—not necessarily good bots from criminal ones.

The New Question: ‘Know Your Customer’ Is Becoming ‘Know Your Agent’

Banks have spent decades building systems around Know Your Customer, or KYC, rules intended to establish who their customers are.

AI commerce introduces another identity problem.

When an automated agent tells an online store to purchase a P40,000 laptop, book a hotel room or reorder groceries, the merchant may need to determine several things almost instantly:

Is the agent legitimate?

Who owns or controls it?

Did the customer actually authorize it?

What exactly was it allowed to buy?

How much was it authorized to spend?

And has the agent begun behaving in a way that could indicate fraud or compromise?

That is the problem the proposed KYA interoperability work is designed to address.

Under the collaboration announced by the companies, the framework centers on cross-network operator traceability, shared certification requirements and continuous transaction monitoring. Each participating agent would ultimately need to be linked to a validated person, cardholder, business or organization so its activity can be attributed rather than disappearing behind an anonymous automated process.

Agents would also be evaluated against security and behavioral requirements, while identity and transaction signals could be monitored continuously.

In simpler terms, the industry wants AI agents to carry something resembling a verifiable digital identity card before merchants allow them to spend real money.

Visa, Mastercard and Ant Already Built Their Own Systems

The collaboration is important precisely because the three companies are not starting from scratch.

Each has already been developing its own approach.

Visa introduced its Trusted Agent Protocol, which uses cryptographic signatures to help merchants distinguish approved shopping agents from ordinary web crawlers, malicious automation and potentially fraudulent bots.

Visa says its protocol can communicate an agent’s intent, information useful for recognizing the consumer behind it and payment-related information required by the merchant.

Mastercard, meanwhile, has developed Verifiable Intent and its broader Agent Pay infrastructure.

Its approach focuses on credentialing agents, proving the consumer’s instructions, setting authorization and spending rules, and allowing payments to settle through existing and emerging payment rails. Mastercard says verified agents can receive digital credentials that make automated transactions traceable.

Ant International launched its open-source Agentic Mobile Protocol, or AMP, in April.

AMP was designed particularly for mobile wallets, banking apps, super apps, smartphones, wearables and other mobile interfaces.

Ant’s framework includes its own KYA system, which establishes an agent’s digital identity and certifies what that agent is authorized to do. It also includes an Agent Trust Rating mechanism intended to assess risk and determine how much autonomy an agent should receive.

The latest collaboration therefore is not about replacing all three systems with one new technology overnight.

It is about finding ways for those systems to recognize compatible trust signals across networks.

Why Interoperability Could Matter More Than the AI Itself

Consider what happens without interoperability.

A developer builds an AI travel agent that can search flights, reserve hotels and pay automatically.

The agent might need one identity-registration process for a Visa transaction, another for Mastercard, another for a mobile wallet and still another when interacting with a different marketplace.

That fragmentation could make AI commerce slow and expensive to deploy.

The companies want to reduce that duplication.

Their stated goal is to let payment ecosystems recognize common KYA signals so developers and merchants do not repeatedly rebuild identity checks for every network they connect to. The companies say that could reduce integration costs and accelerate the rollout of agentic services while preserving each network’s own risk decisions.

This is why describing the announcement simply as an “AI payment standard” can be misleading.

There is not yet one universal standard replacing Visa, Mastercard or Ant’s existing protocols.

The companies are working toward interoperability and shared principles—the groundwork from which broader standards could eventually emerge.

Consumers Still Have a Trust Problem

Technology may not be the biggest obstacle.

Trust could be.

Visa research released this week found that only 23% of U.S. consumers surveyed said they trusted generative AI itself to handle payment transactions on their behalf.

Confidence increased considerably when established payment companies entered the equation: Visa said 61% of respondents in its research would trust Visa to handle agentic transactions.

The difference explains why payment networks are racing to position themselves between AI assistants and consumers’ money.

People may be comfortable asking an AI:

“Find me the cheapest nonstop flight to Singapore next Thursday.”

The psychological leap comes when the instruction becomes:

“Find it, book it and charge my card without asking me again.”

Once AI can actually spend money, questions about fraud, disputes, authorization and liability become much more serious.

AI Shopping Is Already Moving Beyond the Laboratory

Agentic payments are no longer entirely theoretical.

Mastercard has already completed authenticated agentic-payment pilots, including a live transaction in Malaysia involving CIMB and RHB, where an AI agent facilitated a transport booking and payment using tokenized credentials and Mastercard Payment Passkeys.

The company said consumer consent was explicitly captured and that commercial deployment would proceed in phases.

Visa has similarly been building its Visa Intelligent Commerce infrastructure to provide agents with tokenization, authentication, payment controls and risk-management capabilities.

The competition is also moving beyond card networks.

Reuters reported this month that India is preparing infrastructure that could allow AI agents to make certain small payments through UPI, with proposed features including spending limits, audit trails, identity verification and rules determining when an agent is allowed to transact.

That signals a much larger industry race.

The question is becoming less about whether machines will transact and more about which infrastructure will determine who can be trusted when they do.

Ant Gives the Partnership a Huge Digital-Wallet Footprint

Ant International could also bring considerable reach outside traditional credit-card payments.

Its Alipay+ network now connects around 150 million merchants with more than 50 digital wallets and banking apps reaching approximately 2 billion user accounts, according to the companies’ latest joint announcement.

That matters because the future of AI payments is unlikely to be exclusively card-based.

Consumers across Asia already rely heavily on QR payments, mobile wallets, super apps and bank-account transfers.

A KYA framework that works across both global card networks and wallet ecosystems could therefore be particularly significant for markets in Asia-Pacific, where payment systems are highly fragmented.

Singapore Is Becoming Part of the Testing Ground

Ant International, Mastercard and Visa also plan to work through BuildFin.ai, an industry initiative convened by the Monetary Authority of Singapore, to advance approaches to AI-agent verification, accountability and risk management.

Their work will build on Singapore’s Safeguards for Agentic Finance at Runtime, or SAFR, framework.

That regulatory dimension could prove crucial.

Giving an AI permission to purchase a pair of shoes is one thing.

Allowing agents to move money continuously, make thousands of microtransactions, interact with financial institutions or eventually manage complex financial tasks raises much harder questions involving fraud, privacy, consumer consent and responsibility when something goes wrong.

The Biggest Battle May Be Over Trust, Not Payments

This is why the Visa-Mastercard-Ant collaboration is bigger than another fintech partnership.

AI companies are racing to build agents capable of doing things.

Payment companies are racing to determine which agents should be allowed to do them with money.

The companies that control identity verification, transaction authorization and trust signals could occupy an enormously valuable position between AI platforms, merchants, banks and consumers.

Mastercard has summed up the challenge in its own work on agentic commerce: adoption will depend not simply on how capable AI becomes, but on whether transactions remain transparent, controllable and grounded in consumer authorization.

For consumers, the future may look deceptively simple.

Instead of opening five websites, comparing prices, entering card details and clicking “buy,” you might eventually tell an AI:

“Book me the best hotel in Tokyo under $250 a night and pay for it.”

Everything after that could happen automatically.

But before the world’s payment networks allow software to spend trillions of dollars on people’s behalf, they have to solve a deceptively basic question:

When an AI shows up at checkout carrying your money, how does anyone know it really has your permission?

Leave a Reply

Your email address will not be published. Required fields are marked *