Blog Post

Can Pay, Should Pay?

Five standards are currently racing to define agentic commerce. However, no one yet seems to agree on the one question that might just matter most.

Later this week, on 15 September, Stockholm hosts the payments industry's first summit built entirely around agentic commerce. EMVCo's own comment period on a new draft framework, published two weeks earlier, remains open until 30 September. A card proving it can pay has never been the hard part. Whether it should pay, for this thing, at this moment, is the part nobody's actually built yet.

In the space of about eleven months, five separate organisations have each published their own answer to part of that question, without agreeing on which part they're answering. EMVCo, jointly owned by Visa, Mastercard, Amex, Discover, JCB and UnionPay, put out a draft framework on 1 September 2026 built around something it calls Intent Services, a shared layer that lets everyone in a transaction register, reference and manage a consumer's authorised intent before, during and after it happens. Visa had already gone its own way nearly a year earlier with the Trusted Agent Protocol, launched in October 2025 with partners including Cloudflare, Stripe, Shopify and Coinbase, aimed less at intent and more at stopping agent-driven traffic getting mistaken for bots and blocked outright. Mastercard launched Agent Pay for Machines in June, built for the always-on, machine-to-machine end of the problem rather than a person authorising an agent to shop. Google, Shopify and Stripe have their own Universal Commerce Protocol, aimed at the checkout flow itself. And x402, an open, crypto-native protocol for machine micropayments, has gone from close to nothing in mid-2025 to over 100 million transactions by the first quarter of this year.

None of that means racing ahead was the wrong instinct. Waiting for five competing standards to fully agree before shipping anything has its own cost, and every one of these organisations could reasonably argue that adoption is moving too fast to wait for consensus. But racing ahead this way does create the conditions for a seam nobody owns. Not because five standards guarantees a failure, they might yet converge sensibly, but because a join with five interested parties and no named referee can end up behaving a lot like a join with none.

I keep coming back to a diagnostic I've used for years, across every side of the table I've sat at for over 25 years now:

‘At any point where two systems, or two organisations, meet, is there a named owner for the join itself, not the systems either side of it? Do both sides share one definition of what's actually crossing it, whether a manual step is quietly holding it together? And how fast anyone would know if it failed.’

Right now, intent as a concept fails most of those questions by default, not because anything's broken yet, but because nobody's had to answer them under real pressure. I made a version of this argument a few weeks ago using Argos's Marketplace launch as the live example. This is the same pattern, showing up in newer, faster-moving infrastructure.

EMVCo's own example is a good one. A customer authorises an agent to spend up to £300 a month on groceries. The first three purchases, £70 each, sit comfortably inside that. The fourth doesn't. Every card scheme on earth can already tell you whether that fourth transaction carries a valid credential. None of them, until this framework, could tell you whether it should actually go through. Authentication answers can this pay. Intent answers should this pay, right now, for this. I've sat on four different sides of this exact question over the years: as an issuer, watching a technically valid transaction sail through and land somewhere the customer never meant, as a merchant, staring at a chargeback three months later with no real way to reconstruct what anyone actually intended, and as a scheme, trying to write rules that were meant to cover all of it at once. None of that needed an AI agent to happen. Intent is just the industry finally putting a name to a gap I've watched people fall into for years.

Once you accept intent needs managing, the harder question is whose job that is. My initial instinct, worked through slowly rather than landed on immediately, is that accountability sits with the merchant and their acquirer, because they're the end of the chain that actually has to act, decline, process or refund a transaction the moment it arrives. That's not the same as saying they own the intent itself. The intent originates with the cardholder, authorised through their issuer, and if it needs proving later, in a dispute or an audit, that proof has to trace back to that end too. Merchant and acquirer carry the accountability for acting correctly on incomplete information. Customer and issuer carry the burden of having actually granted what they say they granted.

That split creates a genuine seam of its own, and it's the one I'd watch most closely. An agent can believe, correctly by its own logic, that it's acting within its authorised intent when it buys something based on the description it was given. The cardholder can look at what actually arrives and disagree. That's not a fraud problem, and it isn't really an authentication problem either. It's the second question in my own diagnostic showing up somewhere new: do both sides of a seam share a single definition of the thing crossing it? A lot of product data on the internet is still written for humans to read, not for an agent to parse and act on with any precision. A meaningful part of the intent problem won't be solved by a shared authorisation layer at all. It'll be solved by merchants and acquirers getting genuinely good at describing what they sell in a way an agent can act on correctly, an agentic-native description, and until that becomes a real discipline, "as described" disputes are the likeliest place this whole framework gets tested first.

It's worth being honest about how fast any of this is actually moving too, because the numbers get thrown around loosely. UK contactless launched in September 2007 and managed around 160,000 transactions in its first full year, a figure that more than doubled the year after. It took until 2014 to reach 321 million transactions annually, and roughly seventeen years to account for over a third of all UK card payments by volume. Agentic commerce's early numbers look steeper: Adobe's own analytics, tracking over a trillion visits across the top US retail sites, found AI-referred traffic up 138% year on year to May 2026, and roughly fourteen times higher than October 2024. On the x402 rail alone, transactions went from close to nothing in mid-2025 to over 100 million within a year. Those aren't quite the same measurement, traffic and on-chain transaction counts aren't card transactions, and I'd be wary of anyone presenting them as if they were. But both are compounding off a genuinely tiny base, which is exactly when percentage growth always looks most dramatic. Friction is a fundamental rule of physics. It exists for a reason. The real question isn't how fast the curve is climbing, it's whether the plumbing underneath it can hold before the volume actually arrives.

Every dispute I've ever seen resolved comes down to the same handful of questions: was this authorised, was it as described, was it delivered, and can any of that be evidenced? None of those questions change because an agent made the purchase instead of a person. What changes is how they get answered. Was this authorised becomes did the agent act with correct intent when it initiated the transaction, a genuinely harder thing to evidence at machine speed than a signature or a PIN ever was. As described is where I'd expect the real friction to show up first, for the reasons above. My honest view is that an intent violation needs its own dispute reason code entirely, separate from fraud and separate from goods not received, because forcing it into either of those existing categories just buries a new kind of failure inside old data, which is precisely how seams stay invisible until something crosses them badly enough to notice.

There's a useful precedent for how liability eventually gets decided in situations like this. When the US shifted liability for chip card fraud, in stages between 2015 and 2020 depending on the transaction type, the rule that emerged wasn't really about who was morally responsible. It was that whichever party held the inferior technology for that specific fraud type carried the loss. I'd guess, though I can't say for certain, that something similar shakes out here eventually, decided less by principle than by who's actually built the capability to prevent the failure.

None of this makes Intent Services unnecessary, but it does mean it's a start rather than an answer. A shared intent layer still needs an agent identity and attestation piece underneath it, so everyone knows which agent is actually asking. It needs real-time behavioural monitoring tuned to how agents behave rather than how people do. It needs a graduated step-up back to a human at the edge of a mandate, rather than a binary block or allow. And it needs a proper evidence trail and a liability model behind all of it, or the whole framework becomes a more sophisticated version of the same seam it was built to close.

None of this needs to wait for Stockholm, or for the standards to consolidate down from five to whatever number they eventually settle on. If you're a merchant or an issuer working out what agentic commerce actually means for you, the useful starting questions are the same ones I'd ask about any payments estate: what systems are you actually running, where do they source and persist their data, what enterprise boundaries do they cross, and is that understood and stored consistently across all of it. Do you have a named owner for each payment flow and for the data it depends on. And underneath all of that, the question that matters most: what's your real use case for agentic commerce, and how does it genuinely make things better for the people using it. None of that needs to happen in sequence, you can work through it while you're still deciding your wider strategy.

I'm curious whether the people in the room in Stockholm this week are landing in the same place, or whether the standards camps see this differently from the inside. It's certainly turning into one of the better examples for a longer piece I'm working on around AI readiness, Skipping Pre-Season. If any of this sounds like the problem you're facing, get in touch.

Sources

● EMVCo, "EMVCo Requests Feedback on Framework for Secure, Interoperable and Scalable Card-Based Agentic Payments," 1 September 2026 — https://www.finanznachrichten.de/nachrichten-2026-09/69461157-emvco-requests-feedback-on-framework-for-secure-interoperable-and-scalable-card-based-agentic-payments-004.htm

● PYMNTS, "EMVCo Proposes Intent Layer for Agentic Card Payments," 2 September 2026 — https://www.pymnts.com/news/artificial-intelligence/2026/emvco-proposes-intent-layer-for-agentic-card-payments

● Visa, "Visa Unveils Trusted Agent Protocol for AI Commerce," 14 October 2025 — https://corporate.visa.com/en/sites/visa-perspectives/newsroom/visa-unveils-trusted-agent-protocol-for-ai-commerce.html

● Mastercard, "Mastercard Launches Agent Pay for Machines to Unlock Super-Fast, Always-On Payments," June 2026 — https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html

● Universal Commerce Protocol — https://ucp.dev/

● Chainalysis, "Inside x402: 100M Agentic Payments on Base," 3 June 2026 — https://www.chainalysis.com/blog/x402-agentic-payments-adoption/

● Kinfos Events, Agentic Commerce & Payments Summit 2026 (Stockholm, 15 September 2026) — https://kinfos.events/acps/

● Forkast, "The First Dedicated Agentic Commerce Summit Arrives as the Industry Figures Out Who Pays," 6 September 2026 — https://forkast.news/the-first-dedicated-agentic-commerce-summit-arrives-as-the-industry-figures-out-who-pays/

● Thames Technology, "History of Contactless Payments - A Timeline" — https://www.thamestechnology.co.uk/inspiration/history-of-contactless-payments-a-timeline

● Silicon UK, "Contactless At 10: One Third Of All Card Payments Made With A Tap," 2017 — https://www.silicon.co.uk/mobility/smartphones/contactless-card-payments-221031

● Digital Commerce 360, "Adobe: AI-referred traffic to retail sites doubles in a year," 17 June 2026 — https://www.digitalcommerce360.com/2026/06/17/adobe-ai-referred-traffic-to-retail-sites-doubles-in-a-year/

● US Payments Forum, "Understanding the U.S. EMV Liability Shifts," July 2017 — https://www.uspaymentsforum.org/wp-content/uploads/2017/07/EMV-Fraud-Liability-Shift-WP-FINAL-July-2017.pdf

● Lee Tango, "Everything Worked Except The Bit In Between," LinkedIn, 3 September 2026 — https://www.linkedin.com/pulse/everything-worked-except-bit-between-lee-tango-xwgpe/


Tango Payment Strategy & Solutions is a Limited Company, Registered in England & Wales. Company Number 17378388

Tango Payment Strategy & Solutions is a Limited Company, Registered in England & Wales.

Company Number 17378388

Tango Payment Strategy & Solutions is a

Limited Company, Registered in England & Wales.

Company Number 17378388