A finance team can describe precisely what happens when a person buys something. There is a payer, a consent, an authentication, a settlement, and, when it goes wrong, a dispute with a named party at each end. Put software in the payer's chair and all five become open questions. What is the agent, and how does a merchant know? What happens when the instruction that moved the money was planted in a web page rather than typed by a human?

These are engineering and legal questions, not futurology, and they are what the archived Paris 2026 programme took up in the first session after its opening speech. Tested against what the payments industry has published since, capability is plainly not the constraint. The constraint is trust and liability, and there the shipped record is thinner than the announcement cadence implies.

What the room was asked to consider

Day 1 of the archived Paris edition, 2 June 2026, opened at 10:20 with the opening speech. The session that followed it, at 10:30 on the Hecto Main Stage, was a fireside, Beyond Stablecoins: Mastercard and the Future Rails of Agentic Commerce. Ken Moore of Mastercard was the guest; Christine Lee moderated.

Our listings shorten Moore's title to CIO. Mastercard's own biography, quoted in our roster of institutions on stage, has him as Chief Innovation Officer leading the Mastercard Foundry organisation, and that is the title used in the trade press coverage cited below.

Seven sessions carried the track published as Agentic AI. A reader arriving at the agenda will see four of them without changing anything, because the stage filter opens on the Hecto Main Stage and the other three ran on the Taostats and X Ventures Masterclass stages. The full set, each confirmed on its own page in the session record:

That roster is archived and bound to its edition; for what coverage reported from those rooms, see the record of Paris 2026. This piece marks the question those sessions raised against what the industry has since shipped.

What an agent needs before it may spend

The first requirement is identity: a merchant taking an instruction from software must know which software, operated by whom, on whose behalf. One session was dedicated to it, the Personhood, Provenance and Verification panel, with Pierre Aubert of Parity Technologies, Evin McMullen of Billions Network and Privado ID, Stuart Haber of SureMark Digital and Chi Zhang of Kite, moderated by Mohamed Ezeldin of Animoca Brands.

The state of that layer is sobering. The IETF's Web Bot Auth working group draft, draft-ietf-webbotauth-httpsig-protocol-00, carries a revision date of 1 September 2026: revision zero, Standards Track, IESG state "I-D Exists", no telechat scheduled. The individual submission it grew out of, draft-meunier-web-bot-auth-architecture, is marked no longer active and shown as replaced. Cloudflare had integrated HTTP Message Signatures into its Verified Bots Program in July 2025, more than a year before the working group had a numbered draft: a vendor running ahead of a standard rather than the reverse.

The commerce credentials sit at similar maturity. Google's Agent Payments Protocol is at v0.2; it was announced on 16 September 2025 and has since been donated to the FIDO Alliance. Verifiable Intent, which FIDO credits to Mastercard and which is pitched as the trust layer beneath the competing commerce protocols, is published as "Draft v0.1" and carries no corporate byline of its own. The FIDO Alliance formed two working groups on 28 April 2026, one on agentic authentication, one on payments chaired by Mastercard and Visa, taking AP2 and Verifiable Intent as initial contributions. It says work has commenced. It gives no completion date.

Authorisation is a mandate, not a click

The design consensus is that a customer does not authorise a purchase but issues a scoped mandate, which the agent then proves it acted inside. AP2 splits this into Checkout Mandates and Payment Mandates, each with an open stage recording constraints and a closed stage authorising one specific transaction, chained as tamper-evident signed credentials. Verifiable Intent uses a three-layer delegation chain, identity, intent and action, bound with SD-JWT credentials and eight constraint types, among them amount bounds, merchant allowlists, budget caps and recurrence terms. Osborne Clarke, writing on 6 March 2026, calls the pattern bounded delegation, "delegated authority constrained by explicit rules and evidence": monetary and frequency limits, category segmentation, payee allow-lists and deny-lists, step-up conditions, complete audit trails.

Revocation is mostly a property of scope: a mandate is narrow and short-lived rather than standing, so withdrawal means declining to renew. That answers the technical problem, not the legal one. Under regulation 67 of the UK's Payment Services Regulations 2017, as the solicitor Rob Bratby set out on 28 March 2026, a transaction is authorised only if "the payer has given consent", in the form and procedure agreed with the provider. Strong Customer Authentication requires "two or more independent elements from the categories of knowledge, possession and inherence", and its exemptions, low-value contactless, trusted beneficiaries and recurring transactions of the same amount, rest on a principle Bratby states directly: "a human must authenticate each payment or authorise a defined series of payments". A customer granting a mandate has consented to a delegation, not to the payment the agent eventually makes. Osborne Clarke notes that agent-based models remain subject to PSD2 and the technical standards on Strong Customer Authentication, and leaves the perimeter question open and functional: who is in fact providing a payment service.

A delegated credential is a new attack surface

Ken Moore put the security point plainly in an article Mastercard sponsored with BetaKit on 4 May 2026, and the sponsorship is worth stating: give an agent permission to act on your behalf, he said, and "you're actually creating a new threat surface, a new threat vector". His remedy was that "the technologies exist today" and "the challenge is more about engineering trust into the ecosystem".

The surface is not hypothetical. Google, working from a repository of two to three billion crawled pages a month, recorded a relative increase of 32% in the malicious category of indirect prompt injection between November 2025 and February 2026. Forcepoint X-Labs found live payloads aimed at agents holding payment credentials: one carried a fully specified PayPal transaction with step-by-step instructions for agents with integrated payment capabilities; another used meta tag namespace injection to route AI-mediated financial actions to a Stripe donation link.

Unit 42, in work by Matt Brady and Christa McHugh published on 20 March 2026, modelled two attack classes against shopping agents, explicitly as constructed scenarios rather than observed incidents. In the first, a poisoned deals aggregator tells the agent to append a hidden hundred-dollar gift card to the cart mandate, addressed to the attacker, which a customer approving only a total never sees. In the second, hidden markup tells the agent to skip the return verification step and call instant refund settlement directly, an exploit that scales as fast as the agent does. Of the seven Paris sessions, only DeFi Under Attack was framed around machine-economy security, with Kostas Chalkias of Mysten Labs, Charles Guillemet of Ledger, Rodrigo Coelho of Edge & Node and Jason Jiang of CertiK, moderated by Nikola Stojanow of Bank Frick.

Settlement finality matters more when nobody is watching

Card dispute machinery assumes a human who eventually reads a statement and objects. Visa processed more than 106 million disputes globally in 2025, up 35% since 2019 on its own release, and American Banker reported on 2 April 2026 that its new resolution tools would use AI to auto-populate responses to dispute questionnaires. Nothing there anticipates a counterparty transacting continuously, in fractions of a cent, with nobody reviewing the ledger.

Both networks moved on the same day. On 10 June 2026, eight days after the Louvre Palace session, Mastercard launched Agent Pay for Machines for payments at "very high volumes, very small values", some "only fractions of a cent", naming more than 30 firms as among the first to leverage and support adoption. Chief Product Officer Jorn Lambert said machine payments could let services "be bought and sold among agents at fundamentally different scales than payments today". The release names partners; it states no production volume. Visa the same day announced three separate things: an Agent Score letting merchants evaluate their own websites for agentic commerce readiness, an Agentic Directory of agents and merchants "that Visa has verified as legitimate participants", and a Large Transaction Model for fraud detection. Alongside them sat tokenised deposits it "will build".

Transaction counts are not commerce, so the crypto-native comparison needs care. Crypto Briefing reported on 3 June 2026 that Coinbase's x402 had passed 100 million cumulative transactions on Base within nine months of launch, per Chainalysis, while x402.org's own 30-day window showed 72.41 million transactions against $24.24 million of volume, an average well under a dollar. The piece flags concentration risk: "if the majority of x402 activity comes from a small number of large-scale AI deployments, a single client pulling out could crater the metrics".

Shipped, announced, and the distance between

Forrester's audit of consumer agentic payments, published by Lily Varon on 9 April 2026, is the most useful document in the field. Visa's early pilots, with Nekuda, PayOS, Ramp and Skyfire, had completed "hundreds" of agent-initiated transactions, which is not a commercial rollout. Mastercard's landmark in the same audit is narrower still: Europe's first live end-to-end payment executed by an AI agent, in March 2026. Gap's Gemini capabilities were still in testing. Most merchants with ChatGPT apps redirected customers to their own sites to check out. Stripe's own annual letter conceded that agentic commerce "suffers from having been overhyped too early in some corners".

Two points sharpen it. OpenAI's Instant Checkout was discontinued in March 2026, with United States consumer adoption "low and stagnant from debut to discontinuation" in Forrester's phrase, and Walmart told Wired that conversion was "three times lower" for goods sold inside the chatbot than for those requiring a click out to its own site. The one genuinely large deployment is not American: Forrester records Alipay's AI Pay, driven mainly by its integration into the Qwen app, reaching 120 million transactions in a week in February 2026, mostly food and beverage orders through Taobao Instant Commerce.

None of this is a reversal. In June 2025, weeks after the networks unveiled their agentic programmes, Payments Dive reported that "the networks haven't specified how and when consumers will approve payments for purchases", with Visa's finance chief calling agentic commerce early days. Ten months later, American Banker recorded Mastercard's first agentic payment in Hong Kong, an agent booking and paying for a ride from the airport with HSBC as partner bank, after Australia, the United States and India. Firsts, counted one at a time, are the honest measure.

One adjacent number circulates in board packs and means something else. Adobe found AI-referred traffic to United States retail sites up 138% year on year in May 2026, converting 54% better than non-AI traffic across more than a trillion visits, as Digital Commerce 360 reported on 17 June 2026. Those shoppers also spent 53% more time on site and browsed 23% more pages, which are human behaviours. That is people arriving via an AI answer and buying things themselves, not agents transacting.

What is genuinely unsolved

Liability first. Regulation 76 of the PSRs 2017 obliges the payer's provider to refund an unauthorised transaction immediately, but the framework, in Bratby's reading, "does not allocate liability between PISPs, account servicing PSPs and AI technology providers" when an agent acts outside a customer's actual authorisation. Osborne Clarke frames the same gap functionally: who provides the payment service, who holds the funds, what counts as valid authorisation once activity is delegated.

Regulators are studying rather than ruling. FCA chief executive Nikhil Rathi, speaking on 24 June 2026, described a next phase of "systems that don't just support financial decisions, but coordinate and transact", and held that "accountability for regulated activities and outcomes must remain clear". The speech does not address consent mechanisms or liability allocation, which is the point: a principle, not a rule. Bratby notes that HM Treasury's consultation on the future of UK payment services law was planned for the second quarter of 2026 under the Payments Forward Plan, and that a replacement for the PSRs 2017 is not expected before 2028.

Dispute resolution between automated systems is barely specified. Writing in Tech Policy Press on 29 June 2026, Camille Stewart Gloster, Numa Dhamani, Maggie Engler and Leah Ferentinos set agentic risk inside what Simon Willison named the "lethal trifecta", private data, untrusted content and external communication in one process, and put the open questions as how customers challenge automated outcomes, how misalignment is detected at scale, and who is responsible for protecting the user when systems act.

Demand, finally, is stated rather than revealed. An RTB House survey of more than 1,800 consumers in the United States, the United Kingdom, Japan and France, reported on 13 August 2026, found 42% of American millennials would let an agent buy within a $250 budget if they could return the purchase within seven days, and about a third would without that safeguard. Across all generations 35% wanted a human to review transactions first, rising to 44% among baby boomers. Those are preferences, not behaviour.

The questions worth putting to a board

  • If an agent transacts on our rails, who holds the authorisation record, and can we produce it in a dispute?
  • Which credentials would we depend on, and are they ratified standards or drafts at v0.1?
  • Where does the loss sit contractually when an injected instruction causes an agent to spend?
  • Does our fraud model assume a human reads a statement, and what breaks if nobody does?
  • Are the AI figures in our reporting measuring referrals or agent-initiated payments?

The plumbing is arriving faster than the accountability, and the firms building it say as much when read closely. The programme behind those sessions is built without paid speaking slots. The next edition is Abu Dhabi, at the Louvre Abu Dhabi in the Saadiyat Cultural District on 3–4 December 2026, capped and admitted by application and review.