The global card payment infrastructure is about to encounter a fundamental question it was never designed to answer: not just who is paying, but on whose behalf, under what instructions, and within what limits. EMVCo, the technical standards body jointly owned by American Express, Discover, JCB, Mastercard, UnionPay, and Visa, is now developing a framework to address precisely that gap — one created by the rapid proliferation of artificial intelligence agents capable of initiating and completing card payments autonomously on behalf of consumers.
The urgency of the initiative reflects a structural mismatch that is quietly widening across the payments ecosystem. Today, when an AI agent executes a purchase — booking a flight, renewing a subscription, ordering supplies — the card networks, issuing banks, and merchants involved in that transaction receive no standardized signal indicating what the consumer originally authorized the agent to do, nor whether the specific transaction in question falls within the boundaries of that authorization. That informational void is not a minor operational inconvenience. It sits at the intersection of fraud liability, dispute resolution, regulatory compliance, and consumer protection — an increasingly combustible combination as agentic commerce scales.
EMVCo's proposed framework is designed to close this gap by defining how consumer intent and authorization scope can be encoded and transmitted through existing card payment rails. Rather than rebuilding the underlying infrastructure from scratch, the approach appears oriented toward embedding new data fields or structured metadata within the message flows that merchants, issuers, and networks already exchange — extending the current architecture to carry information it was never originally built to transport. The standards body closed its public comment period on September 30, 2026, marking a significant procedural milestone that moves the framework closer to formal adoption.
The implications for the card ecosystem are substantial. Issuers, who ultimately bear fraud liability and manage dispute processes, currently have limited visibility into whether an AI agent acted within the consumer's sanctioned boundaries when a contested transaction arises. Under the emerging framework, an issuer could theoretically receive structured data confirming — or calling into question — whether the agent's action matched what the cardholder originally permitted. That shifts the evidentiary landscape for chargebacks and disputes in ways that could benefit both issuers and consumers, while creating new compliance obligations for the platforms and developers deploying AI agents in commercial contexts.
Merchants, too, stand to gain clarity. A retailer processing a high-value agentic transaction currently has no standardized mechanism to verify that the AI initiating the purchase was genuinely authorized to do so by the cardholder — or to what degree. Fraud rings and unauthorized agent deployments represent a non-trivial attack surface. A standardized consumer intent signal embedded in the payment message would give merchants and their acquirers a new layer of verification, potentially reducing friction in legitimate agentic transactions while strengthening defenses against abuse.
The broader context is one of accelerating urgency. Agentic artificial intelligence — systems that perceive their environment, make decisions, and take actions autonomously — is moving from experimentation to commercial deployment across retail, travel, financial services, and enterprise procurement. Each of these domains involves payment initiation, often at high velocity and across multiple merchants in a single session. The card networks and their member institutions built their authentication and authorization frameworks around a human being making a deliberate, singular choice at a point of sale. That model is under increasing strain as AI agents multiply those decisions, compress the time between consumer instruction and transaction execution, and operate across jurisdictions and merchant categories simultaneously.
EMVCo's intervention represents one of the first concerted efforts by an established standards body to confront this challenge at the infrastructure level rather than leaving it to individual networks, issuers, or regulators to solve piecemeal. The public comment process — now closed — will have gathered input from banks, payment processors, card networks, technology platforms, and merchant groups, offering EMVCo a cross-industry perspective on where the most acute pain points lie and which technical approaches command the broadest support for implementation.
What This Means for the Payments Industry
The transition to agentic commerce is not a future scenario — it is an operational reality that is already straining the edges of card payment infrastructure designed for human actors. EMVCo's framework, if adopted broadly, would establish a common language for expressing consumer authorization in machine-initiated transactions, creating the evidentiary foundation that issuers, networks, merchants, and regulators will all eventually require. The closure of the public comment period signals that the industry is moving from diagnosis to prescription. Financial institutions, payment technology providers, and the developers building AI agents for commercial use should treat this development not as a distant standards exercise, but as an active signal to begin evaluating how their systems will produce, transmit, and consume consumer intent data when the framework reaches formal publication. The architecture of trust in card payments is being quietly rewritten — and the window to shape it is narrowing.
Written by the editorial team — independent journalism powered by Codego Press.