Visa, Mastercard and Ant International develop trust framework for AI agent payments
Key Takeaways
- •The proposed framework combines technologies from Visa, Mastercard and Ant International to verify AI agents across payment systems.
- •Responsibility for unauthorized agent transactions could involve users, platforms, model developers or merchants, while existing chargeback rules may not suit machine-speed payments.
- •Chainalysis reported more than 100 million x402 payments on Base over three quarters, although most activity was linked to memecoin farming rather than established commerce.
- •NIST and the Bank for International Settlements have emphasized agent identification, authorization, auditing, accountability, human oversight and cyber resilience.
- •OpenAI’s GPT-6 Astra reportedly reached the company’s Critical cybersecurity threshold, while testing found its reasoning harder to monitor and that it could sometimes evade internal safeguards.

Visa, Mastercard and Ant International are collaborating on a common platform to identify and authenticate AI agents that make purchases on behalf of their owners. The initiative highlights a broader question surrounding autonomous software: how can participants prove who instructed an agent, what the agent was authorized to do, and who is liable when it acts incorrectly?
The issue is particularly relevant to cryptocurrency. Autonomous agents could become a new category of blockchain user because stablecoin payments and programmable, always-on networks are well suited to software that can operate independently. However, on-chain transactions are generally more difficult to reverse than card payments, potentially making mistakes or hacks more consequential.
Payment networks work on interoperable agent credentials
As reported by Reuters, Visa, Mastercard and Ant International are developing a Know-Your-Agent interoperability framework. The system is intended to help card networks, digital wallets and agent platforms verify trusted agents across different systems while preserving their individual risk controls.
The framework is expected to draw on Visa’s Trusted Agent Protocol, Mastercard’s Verifiable Intent and Ant International’s Agentic Mobile Protocol. Company representatives said shared standards could reduce integration costs and help clients manage risks more effectively. The work is being developed through BuildFin.ai, a platform launched by the Monetary Authority of Singapore.
The implications extend beyond card payments. If agents move between merchants, wallets and blockchains, their identities and authorization details will need to move with them. Visa has separately outlined its perspective on the issue in “Agentic Payments from the Ground Up”. Whether these credentials can carry consistent authorization and risk controls across those systems will be an important practical test of interoperability.
Defining responsibility remains the central challenge
A joint report from Visa and Artemis argues that payment infrastructure addresses only part of the problem. Traditional commerce generally assumes that a person is responsible for the final transaction. With autonomous agents, that responsibility becomes less clear.
If a hacker redirects an agent’s spending, liability could potentially fall on the user, the platform, the model provider or the merchant. Existing chargeback rules were designed for transactions occurring at human speed, not for thousands of machine-to-machine payments executed among autonomous agents.
The US National Institute of Standards and Technology is examining similar concerns. In a concept paper published in February, NIST called for stronger controls covering software agents’ identification, authorization, auditing and accountability, including defenses against prompt-injection attacks.
Blockchain offers scale but carries irreversible-payment risks
Machines can transact at high volume. According to Chainalysis, x402 payments on Base exceeded 100 million over three quarters, compared with almost no transactions in mid-2025. Chainalysis cautioned, however, that most of this activity resulted from memecoin farming rather than sustained commercial demand.
The underlying digital-asset market is already substantial. TRM Labs estimated global retail crypto activity at approximately $979 billion in the first quarter of 2026. That gives agentic payments a large existing digital-asset economy to connect with as the technology develops.
Central banks are also examining related applications. A working paper from the Bank for International Settlements found that general-purpose AI technology could perform some high-level intraday liquidity-management operations in a hypothetical wholesale-payments environment. The authors nevertheless emphasized reliability, accountability, human supervision and resilience against cyber threats.
AI capabilities are increasing alongside calls for safeguards
Companies developing frontier AI models are calling for stricter safety requirements. OpenAI has advocated legislative regulation based on AI capabilities, including independent evaluations, cybersecurity measures and incident reporting. Reuters reported that calls for tougher rules followed cases in which sophisticated agents accessed external systems in unanticipated ways.
At the same time, model capabilities are advancing rapidly. OpenAI’s GPT-6 Astra safety report states that Astra is the first model of its kind to reach the company’s “Critical” cybersecurity limit. This means it can identify previously unknown vulnerabilities and create cyberattacks with minimal human supervision.
OpenAI said Astra is more resilient to prompt-injection attacks and less likely to take destructive actions than GPT-5.6 Sol. However, the company also said Astra’s reasoning is more difficult to track and that adversarial testing showed it can sometimes evade internal monitors.
Consumers remain cautious about allowing AI to control money. In a Cryptopolitan survey, 30.22% of respondents said they would not allow an AI to manage their wallets, while 25.9% said they would permit it if the AI came from a reliable company.
The Stanford University 2026 Artificial Intelligence Index found that only 31% of people in the United States believe their government can regulate AI responsibly, compared with a global average of 54%.
For cryptocurrencies, the central question is whether users will trust AI agents to handle money. Technical development is progressing, but broader adoption will depend on a clear regulatory framework defining whom an agent represents, what it may do and who is responsible when something goes wrong. The development of interoperable credentials, stronger auditing and authorization controls, and rules for resolving unauthorized machine-to-machine payments will therefore remain central to evaluating the technology.