What Amex, Mastercard, and Visa Reveal About the Control Layer for AI Agents

Agentic commerce will depend on proving user intent, constraining delegated authority, and preserving evidence when transactions are disputed.Agentic commerce: autonomous agents with wallets, payment credentials, and new trust requirements. Source: author-generated using OpenAI image generation.I…

Agentic commerce will depend on proving user intent, constraining delegated authority, and preserving evidence when transactions are disputed.Agentic commerce: autonomous agents with wallets, payment credentials, and new trust requirements. Source: author-generated using OpenAI image generation.I spent years building in regulated payment environments before moving into agentic AI, and one thing that environment drills into you is that the interesting question in payments is rarely whether the transaction executes. It almost always executes. The interesting question is who eats the loss when it executes wrong, which is why every payment system I worked on had more code dedicated to disputes, reversals, reconciliation, and exception handling than to the happy path.So when three announcements landed over the past three months, I read them as risk news, and specifically as three different answers to the same underlying problem: when a software agent transacts on someone’s behalf and something fails, what evidence exists to decide who absorbs the loss?Here is the sequence:April 14, 2026: American Express launched its Agentic Commerce Experiences (ACE) Developer Kit and announced a forthcoming commitment called Agent Purchase Protection. In Amex’s own words, in the future, if a Card Member authorizes a registered AI agent and that agent sends Amex the customer’s authenticated purchase intent, Amex will protect eligible customers from charges related to agent error, for eligible charges on U.S. credit cards issued by American Express and subject to terms that it has been careful to flag.June 10, 2026: Mastercard launched Agent Pay for Machines (AP4M), a platform for machine-driven and agent-to-agent payments with credentialing, programmable spend limits, and a Mastercard-backed settlement guarantee across cards, bank accounts, and stablecoins, launching with more than 30 partners including Stripe, Adyen, and Coinbase.July 2, 2026: Visa announced that AI agents are completing live purchases at independent merchant websites across Europe, enabled by its Trusted Agent Protocol (TAP) and Agent Directory, with Cloudflare and Akamai embedding agent verification into merchant infrastructure.It is worth being precise about what each of these actually is, because they are not three versions of the same product.Amex is defining what counts as an eligible agent error for customer protection.Mastercard is assuring settlement for machine payments, which is a different risk category from consumer purchase protection.Visa is building the identity and authorization layer that lets merchants decide which agents to admit in the first place, and its announcement says nothing about Visa absorbing customer losses when an agent makes a mistake.What connects them is not a shared coverage model but a shared premise: transacting agents will need credentials, controls, and evidence that can map a failure to a responsible party.Timeline. Source: author-generated using OpenAI image generation.Why the sequencing mattersThe conventional story is that liability rules in payments get written after the damage. Federal law created a formal billing-error framework for credit cards through the Fair Credit Billing Act of 1974, which amended the Truth in Lending Act. In 1978, the Electronic Fund Transfer Act established a parallel consumer-protection framework for electronic transfers, with Regulation E implementing it.The 2015 EMV liability shift is often lumped into that story, but it actually belongs to a different one, and that difference is the point of this article. The EMV shift was not legislation. It was a card network rule change that reallocated fraud liability to whichever party had not adopted chip technology, and it reshaped terminal hardware, issuer roadmaps, and merchant budgets across the US without a statute ever being passed. Private payment network rules have shaped architecture and risk allocation before, ahead of regulators, and it worked.Agentic commerce starts from a murkier baseline than “no rules exist.” Existing consumer protection regimes still apply depending on the rail and the facts: qualifying electronic fund transfers sit under EFTA and Regulation E, and credit card billing errors sit under TILA and Regulation Z. What does not exist yet is a settled, agent-specific allocation rule for the genuinely new case, where an authorized agent acts contrary to what the user actually instructed. The Financial Brand covered this gap in early May and framed the Amex move as a partial answer to it. What I think that framing undersells is that the networks are not waiting for that rule to be written for them. They are shipping the definitions, credentials, and evidence formats that any future rule will have to reckon with, and the EMV precedent suggests those private rules can harden into the operating reality long before anyone legislates.A taxonomy before the strategyThe mistake I made in my own first pass at this topic was treating “the agent failed” as one problem. It is at least four, and each of the three announcements maps onto a different one.Once you separate these, the more defensible version of this article’s thesis becomes visible. Agentic commerce is not converging on a single liability model, and pretending otherwise flattens real differences between what these companies shipped. What it is converging on is a requirement for evidence-conditioned loss allocation. Every one of these mechanisms works by demanding proof up front: proof of what authority the agent held, what constraints applied, what the user actually asked for, and what the agent actually did. The platforms competing to matter here are the ones building the machinery that can produce that proof at transaction time.Failure Taxonomy. Source: author-generated using OpenAI image generation.The fine print is where the architecture gets decidedNone of these commitments are unconditional, and the conditions are the part that will reach into your system design.Amex’s protection applies only to registered agents integrated with ACE that transmit the cardholder’s authenticated purchase intent, and the program’s eligibility is deliberately narrow: subjective requests like “find me something really nice” may fall outside coverage, customers are expected to attempt a merchant return first where possible, and pieces of the specification, including agent registration and cart context, are still under development. Amex’s EVP of Global Innovation, Luke Gebb, has been explicit that the intent record is what Amex will use for authorization decisions and for adjudication when something goes wrong.Mastercard’s settlement guarantee applies to credentialed agents whose permissions and spending limits are defined upfront and whose identity flows through its Verifiable Intent system, combining network-issued credentials with off-chain cryptographic verification for machine-speed transactions.Visa’s model routes merchant trust through the TAP specification: request-context-bound, time-limited, nonce-protected HTTP message signatures that let a merchant verify agent identity and detect tampering or replay attempts, with trust anchored in Visa’s Agent Directory and the associated TAP verification process, and with validation increasingly handled at the edge by Cloudflare and Akamai.In each case, access to the assurance runs through the network’s definitions. Amex decides what an eligible error is and what valid intent evidence looks like. Mastercard decides what a properly credentialed and permissioned agent is. Visa decides which agents appear in its directory and what a valid signature contains. The operational criteria for proving authority, validating intent, and determining whether a transaction is trusted are being encoded upstream into developer kits and protocol specifications. Traditional dispute processes will still exist, but the evidence available to those processes will increasingly be shaped before the transaction executes.Where this concentrates power, stated carefullyI want to make the strategic claim here without overrunning the evidence, because the evidence is three months old.The party that conditions protection on its own evidence requirements accumulates a few durable advantages. It controls admission: Visa operates an Agent Directory today, Amex is building a registered-agent model, and Mastercard issues network credentials with a shared discovery layer, and if merchant infrastructure providers like Cloudflare and Akamai make those credentials the default filter for agent traffic, losing trusted status could become commercially consequential for an agent platform. It controls the definition of failure: when Amex adjudicates an agent-error claim, it interprets an intent record its own kit captured, against criteria it wrote. And in closed-loop or heavily instrumented flows, the accumulated record of authenticated intent versus actual execution could become a genuinely valuable risk-data asset, though how valuable depends on privacy law, contractual limits, and how much of the raw intent the network actually sees.The historical analogy is closer to Lloyd’s Register than to Lloyd’s of London itself. Lloyd’s Register gave underwriters and merchants a shared way to assess vessel condition, and its classification rules later influenced ship construction standards. The parallel is imperfect, but useful: the party that makes risk legible can gain influence over the technical standards producers adopt. The parties offering agent-error protection and settlement assurance are positioned to play a version of that role, and the EMV experience shows that in payments specifically, network-written rules have redirected billions in infrastructure spend without waiting for a legislature.What this means if you are building agentic systemsI architect agentic platforms for a living, and this shift changes several things I would treat as engineering requirements today rather than legal questions for later.Build the intent artifact as a first-class object, and do not confuse it with your logs. My first instinct was that the prompt and structured-output chains I already capture for observability would serve as the intent record. Working through the Amex model changed my mind. Raw prompts are ambiguous, privacy-sensitive, and painful to adjudicate, which makes them the wrong financial artifact even though they are the right debugging artifact. What a dispute needs is a constrained approval object the system generates at the moment of delegation, something like:intent_iduser_or_org_principalagent_identitymerchant_or_allowed_merchant_setproduct_or_category_constraintscurrency_and_max_amountquantity_and_price_toleranceapproval_method_and_timestampexpirypolicy_versionoutbound_execution_request_hashpayment_and_order_referencesThat object should be durable, signed, and audit-reconstructible, and it must be non-replayable, because an intent record that can be reused as a live authorization is a vulnerability rather than evidence. Design the intent ledger before you design the checkout flow.Give every agent a verifiable identity with scoped authority. All three programs assume the agent itself holds a credential: ACE registration, Mastercard’s Verifiable Intent credentials, directory-verified signing keys under TAP. If your architecture treats agents as anonymous clients of your backend, you will retrofit identity under pressure later. This is the same workspace-scoped, ownership-based authorization work I have done on multi-tenant AI platforms, extended to non-human principals with explicit spend and permission bounds.Align your internal error taxonomy with the failure table above. A delegation failure, an authority failure, a settlement failure, and a fulfillment failure have different evidence requirements, different responsible parties, and under these new programs, very different cost profiles. If your incident classification cannot distinguish “agent contradicted signed intent” from “agent executed ambiguous intent plausibly,” you cannot predict which of your failures a network will cover.Do not flatten the protocols into one abstraction. ACE, TAP, AP4M, Google’s AP2, and the Agentic Commerce Protocol created by Stripe, OpenAI, and Meta all exist simultaneously, but they operate at different layers. TAP handles merchant-side trust and request integrity. ACE and AP2 handle intent, delegation, and approval evidence, with AP2 built around signed intent and cart mandates. ACP covers the commerce workflow itself, meaning catalog and cart interactions, checkout, fulfillment options, and delegated payment. AP4M handles payment execution and settlement, and MCP is tool integration rather than a payment protocol at all. My earlier instinct was to abstract all of this behind a single routing layer the way I abstract model providers, and I now think that is wrong, because a lowest-common-denominator wrapper erases exactly the evidence semantics that make each layer useful in a dispute. Build layered adapters instead: one for identity, one for intent and mandate evidence, one for commerce workflow, one for settlement, each preserving its protocol’s native evidence objects.Builder’s checklist. Source: author-generated using OpenAI image generation.The limits of this argumentA few honest caveats, because this trend is young and the fine print is still moving.Amex’s protection is a forthcoming commitment with narrow eligibility, not a live general program, and parts of its specification are still under development. None of these mechanisms has been stress-tested by a large-scale agent failure, and we have no public data on how adjudication behaves when an agent misinterprets ambiguous intent. In my experience running LLM systems in production, ambiguous intent is the dominant failure mode, far more common than clean wrong-item errors, and Amex’s apparent exclusion of subjective requests suggests the hardest cases may sit outside coverage entirely. Ambiguity disputes are where these frameworks will earn or lose credibility.This is also, so far, a card network story concentrated in the US and Europe. Stablecoin-native agent payments follow different economics, and while Mastercard is hedging by supporting stablecoin settlement inside AP4M, an open agent payment ecosystem could still develop outside these verification regimes, particularly for machine-to-machine microtransactions where card economics do not work. I am skeptical that path wins for consumer retail, because dispute protection is precisely what consumers will demand from autonomous purchasing, but it is a real fork in the road.And regulators will eventually engage. Whether they codify the deployed private evidence standards, override them, or layer new duties on top is an open question. What the EMV history suggests is only that deployed network rules tend to define the starting point of that conversation, not that they always win it.Closing thoughtIf you lead engineering or AI strategy, the practical takeaway is that the evidence requirements for transacting agents are being set right now, in developer kits and protocol specifications, by the companies offering to stand behind agent transactions. That competition is probably good for adoption and good for consumers. It also means the record-keeping, identity, and authorization design of your agent platform is being shaped by loss-allocation logic whether you engage with it or not, and it is cheaper to engage now than after those requirements harden into the compliance baseline you get audited against.I would start with the Visa TAP spec on GitHub and the Amex agentic commerce documentation. Read them the way you would read a draft regulation, because that is the role they are currently auditioning for.I build production agentic AI platforms in regulated enterprise environments, with a prior background in banking payment systems. Opinions are my own.This story is published on Generative AI. Connect with us on LinkedIn and follow Zeniteq to stay in the loop with the latest AI stories.Subscribe to our newsletter and YouTube channel to stay updated with the latest news and updates on generative AI. Let’s shape the future of AI together!What Amex, Mastercard, and Visa Reveal About the Control Layer for AI Agents was originally published in Generative AI on Medium, where people are continuing the conversation by highlighting and responding to this story.

Source: Generative AI Pub — Published — Category: Image AI

🔗 Read full article on Generative AI Pub →