AsiaTechDaily – Asia's Leading Tech and Startup Media Platform
The meaning of an “authorized payment” is becoming harder to define as artificial intelligence moves from recommending transactions to potentially executing them. In August 2026, India’s Unified Payments Interface (UPI) processed 24.51 billion transactions worth ₹29.82 trillion, or about $314 billion. Now, India is preparing a framework that could allow AI agents to make certain low-value payments without requiring approval for every transaction. The proposed system is expected to incorporate spending limits, rule-based instructions, identity checks, audit trails and a liability framework.
That puts one of the world’s largest real-time payment infrastructures at the center of a broader transition in financial technology. The question is no longer simply whether a customer authorized a payment. If an AI agent is acting on the customer’s behalf, banks and payment networks must establish whether the customer authorized that agent, for that purpose, within those limits.
Asia is already becoming a testing ground for this model. Visa has enrolled more than 50 issuing partners across 10 Asia-Pacific markets in its Agentic Ready program, including DBS, UOB, HSBC, Standard Chartered, Maybank, Bank of China, KB Kookmin and others. The program combines tokens, identity, risk management and controls for agent-initiated transactions. Mastercard has also reported live agentic transactions and is working with partners in Australia and New Zealand on AI-driven procurement, including sourcing from approved suppliers, placing orders and initiating payments. The infrastructure is therefore developing faster than the terminology used to govern it.
Traditional digital payments are built around a relatively straightforward relationship. A person or business initiates a transaction, authenticates themselves and authorizes the payment. Agentic commerce inserts another actor into that chain. The customer gives an AI agent instructions, the agent interprets those instructions, selects an action and potentially executes the transaction. The payment system now needs to understand not only who owns the account, but what authority has been delegated to the software operating it.
This distinction matters because authentication and authorization are not the same thing. An AI agent could be authenticated as a legitimate agent and still initiate a transaction outside the customer’s intended scope. Conversely, an agent could act correctly but lack sufficiently clear evidence that the customer actually delegated the authority.
Payment networks are beginning to address this gap. Mastercard’s Verifiable Intent framework, developed with Google, is designed to connect identity, user intent and the resulting transaction through an auditable record. The company says the approach is intended to provide evidence of what the user authorized and what the agent subsequently did. This points toward a new concept in payment infrastructure: programmable authorization.
Instead of authorizing every individual transaction, a customer could authorize an agent to spend up to a certain amount, use specified merchants, purchase within a defined category or operate for a limited period. India’s proposed UPI framework is expected to use mechanisms including delegated payment authority and blocked funds, alongside rules, spending limits and audit trails.
The significance of agentic payments is not that AI can technically execute a transaction. Software has been moving money automatically for years. The difference is that AI can increasingly decide what transaction should happen. Consider a conventional automated payment. A company can establish a recurring instruction to pay a known supplier $5,000 every month. The conditions are relatively fixed.
An AI agent could instead be instructed to purchase inventory whenever stock falls below a threshold, select among approved suppliers, negotiate based on price and then initiate payment.
The financial system therefore has to evaluate a decision rather than simply execute an instruction.
That creates new questions around the boundaries of authority. What happens if the agent selects a supplier that technically satisfies the rules but was not the business’s preferred choice? What if an AI system misinterprets an instruction? What if malicious information causes an otherwise legitimate agent to make the wrong decision?
These are not simply cybersecurity questions. They are payment governance questions.
The shift is also beginning inside corporate finance. J.P. Morgan’s 2026 CFO and treasurer survey found that 44% of APAC respondents planned to use AI for data analytics and forecasting, while 36% planned to use it to automate routine tasks. Only 7% cited risk management and compliance as an AI use case. That gap is significant. Finance departments are adopting AI primarily to make processes faster and more efficient, while AI-enabled controls are developing more slowly. As agents move closer to payment initiation, however, the control layer cannot remain a largely manual process surrounding an automated system.
“AI will be both a fraud risk and part of the defence. The same technology that helps criminals create convincing invoices and impersonations can help finance teams identify anomalies that people might miss. The challenge isn’t automation itself. It’s automating money movement without automating the controls around it,” Andy Thiss, VP & GM APAC at Eftsure, told AsiaTechDaily.
The implication is that the next generation of finance automation will need controls that operate at the same speed as the transactions they govern.
The hardest problem may not be technical at all. If an AI agent is authenticated, operates within its spending limit and follows its programmed instructions but still makes a purchase the customer did not intend, determining responsibility becomes complicated. The potential parties include the customer, bank, payment network, merchant, AI provider and company that deployed the agent. India’s emerging framework is reportedly expected to include liability provisions, underscoring the fact that agentic payments cannot be treated purely as a product-design challenge.
For banks, this could eventually require a new category of risk assessment. Instead of asking only whether a transaction is legitimate, systems may need to evaluate whether the agent had legitimate authority to make that particular decision. That makes identity, permissions, transaction limits, intent and auditability increasingly interconnected.
The emerging architecture is beginning to resemble a permission system for financial agents.
Visa’s APAC program is explicitly combining identity, tokens, risk and controls, while Mastercard’s Verifiable Intent approach is designed to create an auditable link between authorization and agent action. For enterprises, the same principle is likely to extend beyond consumer shopping into procurement, software purchasing, logistics and recurring supplier payments. Mastercard is already working with partners in Australia and New Zealand on AI-driven procurement and payment initiation.
“Finance teams need verification built into their workflows so payments can move quickly without sacrificing confidence in where they’re going. That’s how businesses get the efficiency of automation without scaling risk of fraud or error alongside it,” Thiss told AsiaTechDaily.
Agentic payments do not eliminate human authorization. They change where authorization happens. Instead of approving every transaction individually, customers and businesses may increasingly delegate defined financial authority to software. The challenge for banks and payment networks will be making that delegation explicit, constrained, traceable and revocable.
Asia’s emerging agentic payment infrastructure suggests that this transition is already moving from experimentation toward implementation. India’s UPI framework, Visa’s APAC issuer program and Mastercard’s work on verifiable intent all point toward a system in which trust has to travel with an AI agent as it moves through the payment ecosystem. The defining question for the next generation of payments may therefore no longer be “Did the customer authorize this transaction?” It may be: “Did the customer authorize this agent to make this decision?” That is a much more complicated definition of “authorized.” It is also one that Asia’s banks and payment networks will increasingly have to make operational.