AI agents are starting to do something much more consequential than recommend what we should buy. They are beginning to make the purchase themselves.
With Visa enabling live agent-initiated transactions on real payment infrastructure, BBVA and CaixaBank demonstrating agent-initiated transactions in Europe, and payment leaders such as Mastercard and Ant International working on common approaches to identify and verify AI agents, the financial system is starting to make room for software that can actually act on our behalf.
That may sound like a small change from AI-powered shopping assistants. It isn’t. Once an agent can move from recommending a product to actually paying for it, questions around identity, authorization, spending limits, and accountability become much more important.
From Chatbot to Financial Agent
For years, most AI applications in finance focused on things like data analysis, customer support, fraud detection, or workflow automation.
In 2026, that is beginning to change. AI agents are moving from helping with financial decisions to taking financial action. In Europe, Visa and more than 30 issuing banks, including BBVA, CaixaBank, Bankinter and Abanca, are enabling agents to complete purchases on real payment rails with participating merchants.
An AI assistant that recommends a flight is an information tool. An AI agent that checks your preferences, works within your rules, authenticates the transaction, and books that flight using your preferred card is something different. It has become an active participant in the transaction.That creates a fairly simple progression:
Recommendation → Authorization → Execution
The important point is that this does not necessarily mean handing an AI unrestricted access to your money. The idea is to give software narrowly defined authority to carry out decisions that a person has already authorized. To make that work safely, the system needs secure payment access, verifiable identity, spending limits and strong fraud controls.
Real Infrastructure, Real Trust
Visa’s Agentic Ready program launched in Europe in March 2026. By July, the program had moved into live agentic commerce transactions with participating merchants.
These were not simply simulated checkouts. Visa says AI agents were operating in live environments, browsing products, selecting items, and initiating purchases on behalf of cardholders within user-defined parameters. BBVA and CaixaBank were among the issuers that completed live agent-executed transactions through existing payment infrastructure.
Visa says the transactions were secured using Visa Payment Passkeys, linking them to verified users and explicit instructions while supporting compliance with Europe’s Strong Customer Authentication requirements. Visa describes Payment Passkeys as part of the authentication layer that helps keep the person in control while allowing agents to handle more of the purchasing process.
This changes the basic relationship between traditional e-commerce and agentic commerce. In traditional e-commerce, we navigate the website, fill out forms, enter payment details, and click the final button ourselves. Agentic commerce can bring together natural-language instructions, tokenized payments, agent identity, authentication, and programmable spending controls.
Instead of every decision requiring a person to step in manually, an agent can work within rules and spending boundaries that have already been defined. That is where trust becomes essential.
To support that next step, Visa, Mastercard and Ant International announced a joint initiative, coordinated through BuildFin.ai, to develop common approaches for identifying and verifying AI agents. The proposed framework is intended to help payment networks identify who an agent represents, understand what authority it has, and create a common trust layer for agent-initiated transactions.
The flow starts to look something like this:
User Intent & Rules → AI Agent → Agent Identity & Authorization → Guardrail Checks → Payment Rail → Settlement
Human approval remains available for higher-risk transactions.
Opportunities and Safeguards
Financial institutions have an interesting position in this transition. They are not simply watching AI agents become better at shopping. They can become part of the infrastructure that determines what those agents are actually allowed to do.
That creates several opportunities.
- Trusted Infrastructure: Financial institutions can provide the verification and fraud-prevention layer that helps distinguish an authorized agent from an unsafe or malicious one.
- Programmable Spending Rules: Instead of simply approving or declining a transaction, banks could support rules based on amount, vendor, category, frequency and timing.
- Agent-Facing Products: This could eventually include virtual wallets, delegated accounts and machine-readable financial APIs designed specifically for AI agents.
But more autonomy also means more responsibility. A useful agentic payment system needs clear boundaries around what an agent can spend and where it can spend it. It also needs real-time transaction monitoring, human approval for higher-risk transactions, complete audit trails, and a way to shut the agent down immediately when something goes wrong.
The goal isn’t to make the agent completely independent.
The goal is to make its independence bounded, visible and reversible.
How Organizations Implement Agentic AI Payments
The same idea can apply inside businesses. Organizations can use agentic payments to automate repetitive procurement and expense processes while enforcing company policy at the point where a transaction happens.
A simple workflow could look like this:
Business Intent → Agent Reasoning → Identity Check → Tokenized Rail → Human Review → Settlement
Building that kind of payment pipeline may involve foundation models for selection and reasoning, identity frameworks, tokenized payment methods and API-driven governance tools. Consider a simple example. A business could set a rule such as:
Buy packing supplies under $5,000 per month from approved vendors, with delivery within 48 hours.
In this illustrative workflow, the agent could compare approved suppliers, select an appropriate option, request payment through virtual payment rails, and send anything above a defined threshold to a human for approval. Once the transaction is completed, the receipt could be synced directly with the company’s accounting ledger. The important part is not simply that the agent can make the purchase. It is that the business has already defined what the agent is allowed to do.
Five steps to get started
1. Identify high-frequency, low-risk workflows
Start with predictable activities such as routine software renewals, basic office supplies or other purchases that follow clear rules.
2. Map spending limits and exception rules
Define approved vendors, maximum amounts, categories, frequency limits and the situations where a human needs to step in.
3. Test edge cases in sandbox API environments
See how the agent behaves when prices change, a preferred vendor is unavailable, delivery falls outside the required window, or a request breaks one of the predefined rules.
4. Run a HITL pilot
Let agents prepare or stage transactions while humans review and approve them. This creates a practical way to see where the system works and where it still needs supervision.
5. Grant managed autonomy
Once accuracy, controls, monitoring and exception handling have been properly tested, organizations can gradually expand the agent’s authority.
Opportunity Lens
The bigger story here isn’t simply that AI can now shop. Global payment infrastructure is beginning to adapt to a world where software can act as an authorized participant in a transaction.
Visa’s live European transactions show that agent-initiated payments can already operate on existing payment infrastructure. The emerging work from Visa, Mastercard and Ant International also shows that the industry is now dealing with a harder question: How do we know which agent is acting, who authorized it, and what it is actually allowed to do?
That is where the opportunity gets interesting for founders and fintech leaders. The advantage may not come from building another consumer shopping bot. It may come from building the trust layers, programmable controls and specialized workflows that allow autonomous payments to become secure, compliant and routine.
Enjoyed this insight? Subscribe to AI Opportune for more practical perspectives on how AI is changing the way we work and live.
You May Also Like
The Rise of AI Credit Analysts: How EnFi is Solving the Lending Throughput Crisis
- By Mahrukh Lucas
- AI in Finance & Fintech
In the 2026 banking landscape, growth is no longer a question of capital; it is a question of throughput. While liquidity is available, regional and community banks are…
AI in the Core: Redefining Modern Banking
- By Mahrukh Lucas
- AI in Finance & Fintech
What’s Changing Inside the Ledger Itself For years, artificial intelligence (AI) in banking lived on the outside. It analyzed reports, flagged suspicious activity after transactions cleared, and generated…
The AI Advantage: How Finance and Fintech Leaders Are Rewriting the Rules in 2026
- By Mahrukh Lucas
- AI in Finance & Fintech
In 2026, Money Will Not Just Move Faster. It Will Think Smarter. In 2026, AI will quietly reshape how money flows, how risk is managed, and how trust…