Agentic payments do not break the cryptography. They break a quieter assumption underneath it — that a person is present at the moment of decision, and that disputes can be sorted into things they meant to do and things they did not.
Consider a procurement agent with a standing mandate: renew software contracts under £25,000, prefer annual terms, do not exceed the prior year by more than fifteen per cent. At three in the morning it renews a licence at eleven per cent above last year's price, on a card token it has been issued, against a vendor that quietly changed its billing entity two months ago. Every constraint held. The payment went through. Nobody authorised that specific transaction, and nobody failed to authorise it either.
When the finance team spots it three weeks later and wants the money back, the dispute process asks a question it has always asked and can no longer answer: was this transaction authorised by the cardholder?
"Authorised" is a legal category, not a technical one
Payment disputes across most major markets run on a binary. Either a transaction was unauthorised — someone used the instrument without the holder's consent, and the loss generally sits with the issuer or the merchant — or it was authorised and the holder is bound by it, with negligence arguments deciding the residue. That binary is doing enormous work. It sits under chargeback rights, under strong customer authentication carve-outs, under the reimbursement regimes that have expanded across payments regulation in the past three years.
Delegated software authority is a third thing, and the frameworks do not have a slot for it. The International Monetary Fund's note on agentic payments, published this year, puts the problem plainly: liability turns on whether the agent acted within its authority, and on whether the harm came from the agent's own conduct or from the principal's instructions. Both of those are questions of fact about a system that, by design, does not produce a clean record of its reasoning. The note observes that current legal frameworks struggle to separate unauthorised use from user negligence once an agent hallucinates or misdirects funds.
You will not lose these disputes because an agent was compromised. You will lose them because three weeks later nobody can prove what the agent was told, what it was permitted to infer, and which of those produced the payment.
This is the part the security framing obscures. Treat agentic payments as a fraud problem and you buy detection. Treat it as an evidence problem and you buy something more useful: a durable, timestamped record of scope at the moment of instruction. Only one of those survives contact with a dispute.
What each control was built to assume
Nearly every control between an instruction and settlement encodes a belief about a human being present. Not one of them is wrong on its own terms. All of them were specified in a world where the payer had a pulse.
Visual 1 — Existing payment controls and the human assumption inside each
Control | What it assumes about the payer | What an agent does to it |
|---|---|---|
Strong customer authentication | A person can be challenged and can respond in the moment | No one is at the device; the challenge either blocks the flow or is pre-satisfied and stops being a check |
Behavioural and device signals | Typing, dwell and navigation patterns indicate a returning human | Machine behaviour is uniform and fast; the signal inverts from reassuring to anomalous |
Velocity and anomaly rules | Unusual frequency implies compromise | Normal agent operation looks exactly like the compromise pattern the rule was written to catch |
Chargeback and dispute rights | The holder either consented or did not | Consent was given once, in advance, to a scope — not to the transaction under dispute |
Negligence tests | Care is something a person exercises | Care becomes a question of how the mandate was configured, which is a product decision |
Know Your Customer | Identity attaches to a legal person | The acting party has no legal personality and no identity record to check |
How to read it: None of these controls fail technically. Each fails semantically — it keeps returning an answer to a question that no longer describes what happened.
The separation argument, and why the mandate is load-bearing
The most useful structural idea in circulation is not a protocol. It is a boundary. The IMF note argues for keeping probabilistic reasoning strictly out of deterministic execution, across three layers: an intent layer where agents plan and negotiate; a control layer of rule-based constraints expressed as mandates and scoped authorisations; and a settlement layer — real-time gross settlement, card rails, distributed ledgers — that executes instructions with legal finality and no opinions.
Visual 2 — Where authority is created, constrained and spent

How to read it: The middle layer is the only one you control and the only one a dispute will interrogate. Architecture that lets Layer 1 reach Layer 3 directly is not a performance optimisation; it is an uninsurable position. Structure after the IMF's three-layer model for agentic payments.
Put like that, the mandate stops being configuration and becomes the primary legal artefact of the transaction. It is the thing that says what authority existed, how wide it was, when it was granted, when it expires and who can revoke it. If it is a row in a settings table with no version history, you have delegated authority you cannot later describe. Emerging patterns — mandate-based authorisation built on OAuth-style scoping, agent-payment protocols, programmable wallet standards that enforce limits in the account itself — are all attempts to make that artefact durable rather than implied.
Know Your Agent is not a rebrand of Know Your Customer
Identity frameworks in financial services attach to legal persons. An agent is not one. It acts for a principal, but it is not the principal, and the practical questions — is this the agent it claims to be, who deployed it, what has it done before, has its authority been revoked since — have no home in a customer file. Work on verifiable agent identity and registry-based reputation is early and fragmented, and the standards proposals in circulation are not settled.
The commercial layer is moving faster than the identity layer. Mastercard's agent suite arrived in the second quarter of this year; Visa has been running its intelligent-commerce programme; PayPal bought its way toward a trust layer for agent-mediated commerce. Gartner's estimate, cited in the IMF's note, that agents could autonomously resolve as much as eighty per cent of common customer-service issues by 2029 describes a world where machine-initiated interaction is unremarkable. Payment rails will meet that demand before dispute rules catch up with it. That gap is where losses accumulate.
The systemic risk is sameness, not rogues
The scenario that attracts attention is the agent that goes wrong. The more plausible problem is agents that all go right, identically. The IMF note flags correlated behaviour as a genuine concern: a small number of foundation models, wrapped in similar tooling and pointed at similar objectives, will make similar decisions at the same moment. That produces synchronised payment flows, sharp intraday liquidity demand and settlement capacity strain — none of which is fraud, and none of which any individual firm's controls would flag.
Treasury teams should read that as a forecasting problem before a risk problem. Intraday liquidity models assume payment timing is smoothed by the fact that thousands of humans decide independently. Remove the independence and the smoothing goes with it.
What follows from this
Write the mandate down as though a court will read it, because eventually one will. Scope, cap, counterparty constraints, expiry, revocation path, and an immutable record of which version was in force at the moment of each instruction. If you cannot reconstruct that from logs today, no protocol adopted later will fill the gap retrospectively.
Set human-in-the-loop thresholds on exposure and reversibility, not on value. A small irreversible payment to a new counterparty deserves more friction than a large recurring one to a known vendor. Value-only thresholds are simply the old rule, reapplied to a payer that does not behave like the one it was written for.
Treat the kill switch as graduated, not binary. The IMF's recommendation is layered governance with staged responses rather than abrupt shutdown, and the reasoning is operational: a hard stop on an agent mid-sequence can leave obligations half-settled, which is its own incident.
Decide now whether your anomaly rules should treat machine-pattern behaviour as suspicious or as expected. You cannot have both. Firms that leave this undecided will spend 2027 tuning fraud models against their own customers' legitimate automation.
The protocols will land. The wallets will get their spending controls, the registries will fill up, the networks will publish their agent programmes and the demos will be smooth. What will not arrive on schedule is a settled answer to the question the dispute clerk has to ask. Until then, the firms that can evidence exactly what authority existed at the moment of instruction will be the only ones able to price this risk. Everyone else will be arguing about intent, three weeks late, with nothing in the file.
Sources and method. A FinancyHub original. Principal source: International Monetary Fund, “How Agentic AI Will Reshape Payments”, IMF Note 2026/004 — for the three-layer separation model, the liability and Know-Your-Agent analysis, the correlated-behaviour and liquidity observations, the graduated kill-switch recommendation, and the Gartner customer-service projection cited within it. Network and vendor activity as reported in that note and in accompanying IMF materials: Mastercard's agent suite (Q2 2026), Visa Intelligent Commerce, PayPal's acquisition of Cymbio. Mandate and wallet standards referenced generically; specifications remain in draft and are not settled. Figures are dated where stated. Journalism, not procurement advice — nothing here is a recommendation to buy, renew or terminate any product. Corrections will be made openly on this article.


