Mastercard and Danske Bank complete an AI agent payment
Mastercard and Danske Bank say an AI agent booked and paid for a Danish coffee tasting with explicit consumer consent. Here is what UK payment rules would require before this becomes routine.
- Published

On 21 September 2026, Mastercard said that it and Danske Bank had completed what Mastercard describes as Denmark's first purchase and payment carried out by an AI agent acting on behalf of a consumer. A shopper asked an AI agent to book a coffee-tasting experience through Priceless.com; the agent found the booking, completed it and paid using a Mastercard card issued by Danske Bank. Mastercard says Agent Pay, the technology behind the payment, was enabled at network level across every Mastercard issuer in Europe from 2 June 2026 — though no UK bank, merchant or payment service provider has been named in connection with it, and no UK launch date has been announced, so that network enablement is not evidence of a live UK product.
For UK readers, this matters less as a technology first than as a test of an old question in a new setting: who is answerable when software, not a person, chooses the merchant, the item and the moment of payment. The money moved over an ordinary card network, not a new rail, and Mastercard says the consumer gave explicit consent and confirmed the purchase through Mastercard Payment Passkeys before it completed. That matters, because some coverage describes the payment as made "entirely" by the AI agent; Mastercard's own account is more specific, with a human approval step sitting inside the agent's workflow. The defensible description is that the agent executed the purchase after the consumer authorised it, not that a machine spent money unsupervised. The rules that would govern a UK version of this already exist, even without a named UK pilot.
How the transaction worked
Mastercard's account, as reported on 21 September 2026, sets out four elements: the consumer instructed the agent to book a coffee tasting; the agent completed the booking on Priceless.com and paid with the Danske Bank-issued Mastercard; Agent Pay supplied the payment framework while a company called PayOS handled the transaction's end-to-end technical execution; and consent was explicit, confirmed through Mastercard Payment Passkeys.
Much is missing from the public record: the transaction value, whether the card was debit or credit, the merchant's identity, whether the event ran in live production or a controlled test, the consent-screen design, the token lifecycle, the dispute process, and any success or fraud metric. Treat this as a disclosed demonstration, not a case study with the operating detail that would let a bank or merchant assess it like a normal product launch. Mastercard also calls the event Denmark's first payment of its kind; no independent Danish regulator or payments register confirms that, so it should be read as Mastercard's own framing.
The genuinely new part of this transaction is that software, not the customer, searched for a merchant, selected a product and initiated checkout. The rail is not new: this was a card payment on existing tokenisation and passkey infrastructure, not an open banking payment and not a UK-regulated payment initiation service. Conflating the two would mislead readers, because card payments and regulated account-to-account initiation sit under different parts of UK payment law.
The UK baseline: cards versus regulated payment initiation
Under the Payment Services Regulations 2017, in force since 13 January 2018, a payment is authorised only where the payer has consented to it, or to a series of transactions, in the form and by the procedure agreed with their payment service provider. That consent requirement is the hinge on which any UK agentic-payment product would turn.
Where a UK provider offers payment initiation services — the regulated route letting a third party trigger a payment directly from a customer's bank account — the rules are more prescriptive: explicit consent, self-identification, secure communication, credential protection, and no alteration of the amount, payee or other notified feature. The Danish demonstration was a card transaction, so these specific duties did not apply to it as reported; they would matter if a UK agent product were built over account-to-account payments instead.
Strong customer authentication applies in the UK whenever a payer initiates an electronic payment, accesses a payment account online, or takes a remote action carrying payment fraud risk, unless an exemption applies. These requirements took effect on 14 September 2019 and were retained after EU withdrawal, and attach to the act of initiating a payment rather than to a specific rail, so they can apply to cards as well as account-to-account initiation. Mastercard's passkey step in Copenhagen looks consistent with authentication of this kind, but a Danish demonstration does not establish UK compliance, or that any exemption used there would be available here.
If a UK customer denies authorising a transaction, the law does not treat recorded use of a payment instrument as automatically sufficient proof of consent, fraud or gross negligence; the statutory burden of proving authorisation sits with the provider. A bank would need evidence connecting the customer's actual instruction to the specific merchant, amount and timing the agent acted on, not just a log showing valid credentials were used. Subject to statutory conditions, a provider must refund an unauthorised transaction and restore the account.
The UK's mandatory reimbursement scheme for authorised push payment scams, capped at £85,000 per qualifying claim from 7 October 2024, covers qualifying Faster Payments and CHAPS transfers. It does not generally extend to card purchases like the one demonstrated in Denmark. Any chargeback protection on a card transaction like this comes from scheme and contractual rules, not a statutory guarantee, and this article cannot confirm its availability for an agentic purchase specifically.
| Feature | Card payment (as in the Danish demo) | UK regulated payment initiation service |
|---|---|---|
| Legal basis | Card scheme rules plus general PSR 2017 consent rule | PSR 2017, regulations specific to payment initiation |
| Consent standard | Payer consent per agreed procedure | Explicit consent; provider cannot alter amount or payee |
| Authentication | UK strong customer authentication rules can also apply here, subject to exemptions; the Copenhagen passkey step is a scheme-level implementation, not proof of UK compliance | UK strong customer authentication rules apply |
| Dispute route | PSR 2017 unauthorised-payment refund rules can apply, alongside separate contractual scheme chargeback rules | PSR 2017 unauthorised-payment refund rules apply |
| APP scam reimbursement | Does not generally apply | May apply where the initiated payment is a qualifying Faster Payments or CHAPS transaction meeting the scheme's conditions; otherwise the mandatory regime does not extend to it |
Who bears the risk when an agent buys the wrong thing
The Danish release does not disclose how liability is divided among the consumer, the agent provider, PayOS, Mastercard, the issuer, the acquirer and the merchant, so no allocation can be reported as fact. UK law already assigns responsibility along a similar chain for ordinary card payments, but an agent adds a layer existing rules do not name. If a consumer authorised broad parameters, such as a category or price ceiling, and the agent then chose the merchant, item or price within that scope, it is not established how a UK issuer would classify the result if something went wrong: an authorised transaction the customer must accept, or one that fell outside the mandate actually given. It is similarly unresolved how UK law would treat a purchase affected by mistaken product selection, a misread cancellation policy, or interference such as prompt injection.
Controls needed before this becomes routine
Firms would need a way to verify an agent's identity to the issuer and merchant, and to record the customer's exact instruction beyond a token being presented. A one-off passkey confirmation, as used in Copenhagen, does not show whether the mandate covered one purchase or an ongoing budget, category or expiry. UK issuers would need real-time ways to recognise agent-initiated transactions, default spending and merchant limits, and monitoring capable of catching a compromised agent or a rapid sequence of small transactions. Consumers would need a straightforward way to pause or revoke an agent's authority, with clarity on what happens to orders already placed.
Consumer protection and data
The FCA's Consumer Duty, in force since 31 July 2023, requires firms in scope to act to deliver good outcomes for retail customers and avoid foreseeable harm. Applied to agentic payments, this points toward mandates a customer can understand, provision for vulnerable customers, working cancellation routes and accessible complaints handling — though the Duty does not itself prescribe agentic-payment controls; these are implications, not quoted requirements.
The Information Commissioner's Office has said organisations deploying agentic AI need a clearly defined and communicated purpose for personal-data processing, should minimise the data an agent can access, and should let people contest important automated decisions and obtain meaningful human review where applicable. The ICO's fuller agentic-AI guidance was still under development at the time of writing.
What the survey data suggests about readiness
The Bank of England and FCA's 2024 survey of 118 regulated firms, published 21 November 2024, found that 75% already used AI and a further 10% planned to within three years. Of the AI use cases reported, 55% involved some automated decision-making, 24% of those semi-autonomous, and only 2% of all use cases fully autonomous. A third of use cases relied on third-party implementations, up from 17% in 2022, and the three largest providers accounted for 73% of cloud usage, 44% of model usage and 33% of data usage among respondents. This measures firms' internal AI use, not consumer-facing agentic payments, but it shows fully autonomous decision-making remains uncommon in UK-regulated finance, and dependence on a small number of external providers is already recognised in the sector.
What to watch next
No UK regulator has been identified as having reviewed or endorsed Agent Pay. Watch for a UK pilot naming a participating bank or merchant, FCA statements on where agentic payment services sit within the payment services perimeter, the ICO's finished agentic-AI guidance, and published scheme rules on agent identification, mandate scope and dispute handling. Until those appear, anyone assessing an agentic-payment product should check directly with the FCA and the provider concerned what protections apply, rather than assume card or open-banking safeguards transfer automatically.
Sources
- Mastercard and Danske Bank complete Denmark's first AI agent payment (opens in a new tab)
The Paypers · · Accessed
- Europe is building the foundations for trusted agentic commerce (opens in a new tab)
Mastercard · · Accessed
- The Payment Services Regulations 2017 (opens in a new tab)
UK Parliament / The National Archives · · Accessed
- Account information and payment initiation services (opens in a new tab)
Financial Conduct Authority · · Accessed
- Strong Customer Authentication (opens in a new tab)
Financial Conduct Authority · · Accessed
- Payment Services Regulations 2017 and Electronic Money Regulations 2011 (opens in a new tab)
Financial Conduct Authority · · Accessed
- PS24/7 Faster Payments APP scams reimbursement requirement: Confirming the maximum level of reimbursement (opens in a new tab)
Payment Systems Regulator · · Accessed
- One year on: Impact of APP reimbursement on victims (opens in a new tab)
Payment Systems Regulator · Accessed
- PRIN 2A: The Consumer Duty (opens in a new tab)
Financial Conduct Authority · Accessed
- Data protection and privacy risks (opens in a new tab)
Information Commissioner's Office · Accessed
- Artificial intelligence in UK financial services – 2024 (opens in a new tab)
Bank of England and Financial Conduct Authority · · Accessed


