The Card Networks Are Writing the Rulebook for What an AI Agent Is Allowed to Buy
AI & ML

The Card Networks Are Writing the Rulebook for What an AI Agent Is Allowed to Buy

EMVCo's proposed Intent Services would force every AI shopping agent to prove exactly what a consumer authorized before, during, and after a purchase, and the comment period just closed.

PublishedOctober 3, 2026
Read time4 min read
Share

The gap this framework is meant to close

When an AI agent books a purchase on a consumer's behalf, the payment network processing that transaction, the merchant receiving it, and the card issuer funding it currently have no standardized way to verify what the consumer actually authorized the agent to do. A consumer might have told an agent to book one flight under five hundred dollars, but once that instruction reaches the payment rails, it arrives looking like any other card transaction, with none of the underlying authorization context attached.

EMVCo's proposed answer is a set of Intent Services designed to register, reference, retrieve, and manage consumer-authorized permissions at every stage of a transaction: before it happens, while it is being processed, and after it completes. That is a materially different model than today's card authorization flow, which was designed around a human directly initiating a purchase rather than a human delegating purchasing authority to a software agent acting with some degree of autonomy.

Know Your Agent is the quietly bigger idea

Alongside Intent Services, the framework proposes Know Your Agent capabilities, a direct echo of the Know Your Customer standards banks already apply to human account holders, and agentic transaction indicators that flag a purchase as agent-initiated rather than human-initiated at the point of sale. Together, these give every party in a transaction, the merchant, the issuer, and the network itself, visibility into whether an autonomous system is on the other end of a purchase decision.

That visibility matters enormously for fraud and dispute handling, which is a problem retailers are going to hit well before most of them have thought it through. A disputed charge initiated by a human has a well-established resolution process built over decades. A disputed charge initiated by an AI agent acting on delegated authority, where the dispute might be about whether the agent correctly interpreted its instructions rather than whether the charge itself was fraudulent, does not yet have one, and this framework is the first serious industry attempt at building that process.

Why a standards body, not a single vendor, is writing this

It matters that EMVCo, the body jointly owned by the major card networks, is the one developing this framework rather than any individual AI lab or e-commerce platform proposing its own proprietary agent-payments protocol. EMVCo's specifications become the baseline every card issuer, acquirer, and payment processor implements globally, which means whatever emerges from this process will function as the actual interoperability layer for agentic commerce, regardless of which specific AI agent a consumer happens to use.

That is a meaningfully different outcome than a fragmented landscape where each major AI lab or retailer pushes its own agent-payments standard and retailers have to support several incompatible approaches simultaneously. A single, card-network-level standard is slower to finalize, evidenced by a formal public comment process that just concluded, but it produces a result every payment processor and merchant acquirer will eventually need to support regardless of which AI agents their customers choose to use.

What EMVCo explicitly is not solving

EMVCo director Oliver Manahan was careful to draw a specific boundary around the framework's scope, noting that it does not define the business rules, in other words, how a given product is actually used in practice. That distinction matters for retailers: EMVCo is building the plumbing that lets a merchant verify an agent's authorization and identity, not the merchant-specific rules for which categories of purchase an agent is allowed to complete, what return policies apply to agent-initiated purchases, or how a merchant handles an agent that appears to be acting outside its stated authority.

Those merchant-level business rules remain squarely a retailer's own responsibility to define, which means retail technology and payments teams cannot simply wait for EMVCo to finish this standard and assume their agentic commerce policy questions will be answered for them. The standard gives merchants the verification tools; it does not give them the actual policy framework for using those tools, and that gap is exactly where individual retailers need to be doing their own work right now.

What retail payments teams should do now

The task force reviewing comment feedback will decide whether genuinely new specifications are required or whether extending existing tools like 3-D Secure and payment tokenization can cover most of this need, and either outcome is still months away from a finalized standard retailers can implement against. That timeline gap is not a reason to wait, however.

Retail payments and e-commerce teams should start drafting their own agent-authorization and dispute-handling policies now, using EMVCo's proposed Know Your Agent and intent-tracking concepts as the working framework, so that whatever specification eventually ships finds an organization that has already thought through its own merchant-level rules rather than one starting from zero once the standard is finalized and vendors start requiring compliance on a deadline.

Tagged#news#retail#retail-ai#ecommerce#agentic-commerce#cpg#emvco#payments#know-your-agent#card-networks#fraud-prevention#checkout-infrastructure#ai-shopping-agents