Skip to content
Agentic AI

Only 23% Of Consumers Trust An AI To Pay For Them. Visa And Mastercard Just Built The Plumbing To Change That

On 17 September Mastercard and Visa released a wave of agentic-commerce risk tools - Mastercard's Agent Connect, Agent Suite for Merchants and Verifiable Intent for Agent Pay, Visa's Trusted Agent Protocol and Intelligent Commerce Connect - and, more tellingly, a shared know-your-agent framework with Ant International to validate, trace and continuously monitor AI agents across networks. The number behind it all is stark: Visa's own research found just 23% of US consumers trust generative AI to handle payments on their behalf. 'Agentic commerce will only scale at the speed of trust,' said Mastercard's Sherri Haymond. For anyone building agents that touch money - in payments, in banking, on a trading desk - the networks have just told you what the control layer is going to look like.

AlchmAI Editorial12 min read

23%

Of US consumers trust generative AI to handle payments on their behalf, per Visa research published in early September

17 Sept

Mastercard and Visa release updated agentic-commerce risk tools and a joint know-your-agent framework with Ant International

150+

AI-powered applications Visa has deployed, alongside Agent Score, Agent Directory and its Token Assurance Framework

3 signals

KYA rests on cross-network traceability, validation against security and behavioural requirements, and continuous monitoring of identity and transaction signals

The most important number in agentic commerce this month is not a transaction volume or a valuation. It is 23% - the share of US consumers who, according to Visa's own research published in early September, trust generative AI to handle payments on their behalf. Every product announcement from the card networks since should be read as a response to that figure, because a payment method that three quarters of people will not trust with their money is not a payment method. It is a demonstration.

On 17 September the two networks responded in the way that matters, with infrastructure rather than reassurance. Mastercard announced Agent Connect, an integration platform that lets AI agents reach merchants and payment providers; an expanded Agent Suite for Merchants; and Verifiable Intent for Agent Pay, co-developed with Google, designed to ensure that a purchase an agent makes is one the customer actually authorised. Visa set out its Intelligent Commerce platform, a Trusted Agent Protocol and Intelligent Commerce Connect, on top of the 150-plus AI applications it already runs and the Agent Score, Agent Directory and Token Assurance Framework it built earlier in the year. And the two rivals, together with Ant International, published a shared know-your-agent framework.

Why The Networks Moved First

It would be easy to read this as Visa and Mastercard defending card rails against stablecoins and agent-native protocols like AP2 and x402, and that reading is not wrong. But there is a more interesting reason the networks are the ones building the trust layer: they are the only participants in the chain who see both sides of every transaction, and trust in agentic commerce is fundamentally a problem of the two sides not being able to see each other. A merchant receiving an order from an agent cannot tell whether the human behind it consented to this purchase at this price. A consumer whose agent is shopping cannot tell whether the merchant it reached is the one it was told to reach. The network sits between them and has, since the 1970s, been in the business of making strangers transact safely.

Mastercard's Sherri Haymond put it in a sentence worth pinning above any agentic project: agentic commerce will only scale at the speed of trust. Visa's Oliver Jenkyn made the historical point - every major shift in commerce has been built on a foundation of trust, and this one will be no different. The subtext is that the technology to let agents pay has existed for a year. What did not exist was a way for the rest of the chain to believe the agent.

The Control Pattern Every Financial Agent Now Needs

We build agentic systems for financial firms, and the network announcements are useful precisely because they generalise. Strip the card-specific detail and what Visa, Mastercard and Ant have described is the control architecture for any agent that moves money or makes a consequential decision - in payments, in a bank's back office, on a trading desk. Four elements recur.

  1. 01Verifiable intent, captured before the action. Agent Pay's design records what the customer authorised - the scope, the merchant, the ceiling - as a signed artefact the agent carries, so that a merchant can check the purchase against the mandate rather than trust the agent's word. On a trading desk this is the difference between an agent that is instructed 'you may trade up to £250,000' in a prompt and one that carries a signed envelope a pre-trade gate can verify independently of anything the model says.
  2. 02Agent identity that is separable from user identity. An agent acting for a customer is not the customer, and pretending otherwise is how a compromised agent inherits its principal's full authority. Separate identity, with separately scoped and separately revocable credentials, is the foundation KYA assumes. Usio's Louis Hoch made the practical version of the point - agents should have their own wallets with their own spending limits.
  3. 03Behavioural monitoring after onboarding, not just checks at it. KYA's continuous-monitoring leg is the acknowledgement that agents fail in motion. A pattern of requests that drifts from the mandate, a velocity that no human shopper would produce, a merchant category outside the authorised set - these are runtime signals, and a control that only fires at registration will miss every one of them.
  4. 04Traceability across parties. When something goes wrong, someone has to reconstruct which agent, operated by whom, acting under which mandate, did what. The cross-network traceability in the Ant framework is an audit-trail requirement dressed as an identity feature, and it is the same requirement every regulated firm already has for human actions.

“The networks have just written down the four things a financial agent needs before it touches money: signed intent, its own identity, monitoring in motion, and a trail someone can follow. None of that is card-specific. All of it is missing from most agent pilots we are asked to review.”


Where This Leaves Banks, Fintechs And Trading Firms

  • Banks issuing cards get the trust layer from the network, but the liability model for agent-initiated disputes is not settled, and the bank is where a 23%-trust product's failures will land first. Chargeback policy for agent purchases is a decision to make now, not after the first wave.
  • Payments fintechs building on the rails have a choice of trust frameworks - the networks' KYA, Google's AP2 mandates, x402 for machine-to-machine - and the realistic outcome is that they will need to speak more than one. FIS's move to give banks a platform for agentic commerce is a sign the middle layer is being built by the incumbents, not left to startups.
  • Trading and wealth firms are not in the card business, but the mandate-and-envelope model is exactly the one their pre-trade controls need. An agent that assembles a rebalancing order should carry a verifiable scope in the same way a shopping agent carries a spending ceiling, and the pre-trade gate should check the envelope rather than the model's assurance.
  • Compliance functions everywhere inherit a new entity type. KYC, KYB and now KYA - with the awkward property that an agent's behaviour can change without anyone re-onboarding it, because its model, its prompt or its tools were updated upstream. Change control on the agent's configuration becomes part of the monitoring obligation.

The Bottom Line

Agentic commerce spent a year proving that AI agents can pay. On 17 September Visa and Mastercard - with Ant International - moved on to the harder problem, which is making everyone else in the transaction believe them. Agent Connect, Verifiable Intent, the Trusted Agent Protocol and a shared know-your-agent framework are the networks' answer to a figure that should give every agent builder pause: only 23% of consumers trust an AI to pay on their behalf. The answer is not a better model. It is signed intent captured before the action, agent identity separate from the user's, monitoring that runs after onboarding rather than only at it, and traceability across every party in the chain. That pattern is not specific to cards; it is the control architecture for any agent that touches money, and it maps directly onto the pre-trade envelopes, scoped credentials and audit trails that a trading desk or a bank back office already needs. As an agentic AI agency in London, we think the networks have just handed the industry its specification - and that trust, not capability, will decide which agents get to spend.

References & Further Reading

Agentic AIAgentic AI Londonagentic commerceknow your agentAI AutomationEnterprise-Grade Security & ScalabilityFintech AI Agency London
Share Email
AI

AlchmAI Editorial

Research and analysis, London

The AlchmAI team writes about the markets, technology and regulation we work with every day. We build trading platforms, real-time charts and AI analysis tools for brokers, prop firms and fintech teams from our office in Mayfair, London. Every article lists its sources. Nothing we publish is investment advice.

This article is general information and commentary. It is not investment advice or a recommendation to buy or sell any investment. Important information