Mastercard adds fraud checks for AI agents, UK rules lag behind
Mastercard has added identity and risk signals to flag AI-initiated payments, but the first tool is US-only, and UK consent, authentication and liability rules remain unresolved.
- Published

Mastercard has added a set of "trust and intelligence" services to Agent Pay, its scheme for payments initiated by artificial intelligence agents rather than by a person tapping a card or typing in details. The services, announced on 30 September 2026, combine identity, intent, behavioural and fraud signals intended to help banks and merchants estimate whether software, rather than a shopper, triggered a transaction.
The announcement matters to UK banks, payment providers and online merchants because Mastercard cards are issued and accepted across the UK, and any new fraud or identity signal that Mastercard builds into its network could eventually reach UK processing. But the first of the new services — a probability score estimating whether an AI agent initiated a transaction — is currently being tested only in the United States. Mastercard has not announced a UK launch date, a participating UK bank, or a participating UK merchant.
The timing is pointed. HM Treasury opened a consultation on 14 July 2026 asking whether UK payment rules, several of which predate AI, still work when an agent rather than a person is making the purchase. That consultation is still open. Below is what Mastercard says its new layer does, what UK law currently requires, and where the two do not yet meet.
What Agent Pay is
Mastercard first unveiled Agent Pay on 29 April 2025. The design lets an AI shopping agent register with the network, receive a unique digital identifier, and use a tokenised credential to make purchases without exposing the underlying card number. Mastercard says this is meant to let a bank or merchant recognise and trace an agent-led transaction after the fact.
Registration and tokenisation address a narrow question: was this transaction run by a registered, identifiable agent rather than an unidentified piece of software or a fraud script? They do not, by themselves, establish that the customer behind that agent wanted this particular purchase to happen.
Five trust layers
Mastercard groups its approach into what it calls the Agent Pay Trust Framework, with five parts:
| Layer | What Mastercard says it covers |
|---|---|
| Identity | Registering and recognising the agent itself |
| Intent | Carrying the customer's explicit instructions, such as item and price |
| Controls | Pre-authorised spending rules and limits set by the customer |
| Trusted execution | Processing the payment within those rules |
| Intelligence | Risk and fraud signals, including the new probability score |
The probability score, the first intelligence-layer product, is rolling out for testing in the United States only. Mastercard says it may later draw on behavioural information, merchant risk, transaction patterns, credential risk and consumer propensity — a list of intended future inputs, not a description of what the score currently uses in production.
Proving what the customer actually wanted
The harder problem is intent, not identity. Mastercard's separate Verifiable Intent initiative, announced on 5 March 2026 and co-developed with Google, is designed to produce a tamper-resistant, cryptographic record of what a user authorised an agent to do. Mastercard said at the time that integration into Agent Pay's intent application programming interfaces would happen "in the coming months". Nothing in the material reviewed confirms that integration is complete as at 4 October 2026.
For UK-regulated payment services, this record would sit alongside, not replace, the existing test for authorisation. Regulation 67 of the Payment Services Regulations 2017, in force since 13 January 2018, says such a payment is authorised only where the payer consents to that transaction, or to a series of transactions, in the form and procedure agreed with their payment provider. A cryptographic log of an instruction given to an agent is evidence that could support a finding of consent. It is not automatically the same thing as consent under the regulations, and whether a broad instruction such as "book a hotel under £150 a night" counts as consent to each resulting payment has not been settled by any UK rule reviewed for this article.
That distinction matters if something goes wrong. Regulation 75 puts the burden on the payment provider, not the customer, to prove that a transaction was authenticated and correctly recorded if the customer denies authorising it. Recorded use of the payment instrument — including, presumably, a verified agent token — is not necessarily enough on its own to prove authorisation, fraud or gross negligence by the customer.
Spending limits and who can set them
Regulation 71 already gives payers and payment providers a legal basis to agree spending limits on a payment instrument. That provision could offer an existing basis for issuer-side limits, but how it would relate to Mastercard's agent-level "controls" layer — or any UK implementation of it — has not been established in the material reviewed. Mastercard's own guidance describes pre-authorised rules and limits carried alongside the purchase instruction. What is not established in the material available is the exact vocabulary of those limits — whether a UK customer could restrict an agent by merchant, category, location or time window, how quickly a revoked instruction takes effect, and what happens to a transaction an agent has already submitted when the customer changes their mind.
Strong customer authentication rules, which have applied to UK card-based e-commerce in full since enforcement forbearance ended on 14 March 2022, require additional verification at electronic payment initiation unless an exemption applies. How that requirement should apply to a standing mandate that covers several later agent-initiated payments, rather than a single checkout moment, has not been addressed in FCA guidance reviewed here.
What banks and merchants would gain, and what they would not
For an issuing bank, an agent-origin signal adds context that is not visible today: whether a given transaction came from a registered, tokenised agent rather than an unknown script. For a merchant, the same signal could help distinguish a legitimate shopping agent from hostile automation at checkout.
What neither party gains, on present evidence, is a published accuracy figure. Mastercard has not disclosed the probability score's false-positive rate, its effect on fraud losses or approval rates, its pricing, or how a bank, merchant or customer could challenge a wrong classification. Independent testing of those claims has not taken place in public view.
Fraud, refunds and the gap in between
UK statutory protection for payments determined to be unauthorised under the existing regulations does not change because an agent was involved. Subject to statutory qualifications, regulation 76 requires a payment provider to refund an unauthorised transaction and restore the account, normally by the end of the following business day after becoming aware of it. A customer generally has up to 13 months from the debit date to report an unauthorised or incorrectly executed payment, while also acting without undue delay once they notice it, under regulation 74.
None of that resolves a scenario this analysis has identified: an agent that was genuinely authorised by the customer, but that bought the wrong item, exceeded an instruction the network could not read, or was manipulated by a merchant after the event. HM Treasury's consultation raises exactly this kind of consent and liability gap. The CMA's guidance, by contrast, addresses a business's own use of AI agents and does not resolve who is responsible when a consumer's own shopping agent exceeds its instructions. Mastercard's scheme chargeback rules are a separate, private mechanism from a customer's statutory claim against their payment provider, and the reviewed material does not show how the two would interact for an agent-led dispute.
The regulatory question is still open
HM Treasury said in July 2026 that the Payment Services Regulations were designed before AI existed as a mainstream purchasing channel and may not fully accommodate agentic payments. Its consultation, opened 14 July 2026, specifically asks whether authentication, consent and unauthorised-payment liability provisions need updating. The government-commissioned Financial Services AI Adoption Plan, published the same day, reports that firms face significant uncertainty over consent, legal accountability and liability in automated payment flows, alongside increased fraud concerns.
Separately, the Competition and Markets Authority has said that a business using its own AI agent to deal with customers remains responsible for complying with UK consumer law — guidance that covers merchant-run agents, not the separate question of who is responsible when a consumer's own shopping agent exceeds its instructions. The CMA also says consumer-facing autonomous agents are not yet common: current shopping agents typically search or compare, and ask for user confirmation before acting. That sits against Mastercard's framing of agentic commerce "moving into the mainstream" and a cited forecast that one in 10 consumers will routinely use agents to shop by 2030 — a global projection whose methodology was not disclosed, not a UK-specific or current figure.
What is not known
- No UK launch date, participating bank, acquirer or merchant has been announced for the probability score or the wider intelligence layer.
- Mastercard has not published accuracy, false-positive or fraud-reduction data for the score.
- It is not confirmed that Verifiable Intent is fully integrated into Agent Pay's intent systems as at 4 October 2026.
- No UK rule yet settles when a broad instruction to an agent amounts to consent for each resulting payment, or how loss is allocated when an authorised agent goes beyond what the customer meant.
- Whether and what personal data would be exchanged between Mastercard, its named technology partners, a bank or a merchant — and how any such processing would be governed under UK data protection rules — was not established in the material reviewed.
What to watch next
The clearest signal of UK relevance will be any announcement naming a UK bank, acquirer or merchant testing these services, or confirmation that Verifiable Intent has gone live in Agent Pay's intent systems. On the policy side, HM Treasury's consultation response and any resulting FCA guidance on authentication and liability for agentic payments would settle questions that scheme-level tools cannot answer on their own. Readers who want the primary detail should consult HM Treasury's consultation document directly rather than a summary of it.
Sources
- Trust in agentic commerce (opens in a new tab)
Mastercard · · Accessed
- Get ready for AI-powered shopping experiences (opens in a new tab)
Mastercard · · Accessed
- When AI starts buying for you, trust becomes the product (opens in a new tab)
Mastercard · · Accessed
- The Payment Services Regulations 2017 (opens in a new tab)
The National Archives · · Accessed
- Strong Customer Authentication (opens in a new tab)
Financial Conduct Authority · · Accessed
- Deadline extension for Strong Customer Authentication (opens in a new tab)
Financial Conduct Authority · · Accessed
- Modernising Payment Services Regulation Consultation (opens in a new tab)
HM Treasury · · Accessed
- Financial Services AI Adoption Plan (opens in a new tab)
HM Treasury · · Accessed
- Using AI agents: complying with consumer law (opens in a new tab)
Competition and Markets Authority · · Accessed
- Agentic AI and consumers (opens in a new tab)
Competition and Markets Authority · · Accessed


