How does an agentic payment actually work?
The agent holds a payment credential scoped to it, typically a tokenized card or account with its own limits, and an identity the merchant and bank can verify as an agent acting for you. It completes the purchase flow, increasingly through agentic commerce rails built for machine buyers, and the transaction lands with a record of which agent, under whose mandate, bought what. The delegation is the product: scoped credentials, spend limits, and verifiable agent identity, not a model with your company card.
Agent-assisted or agent-delegated: where is the line?
Card networks and banks draw it explicitly. Assisted keeps a person on the final confirmation; delegated hands the agent completion authority inside caps. The sensible migration path is assisted for everything first, then delegation for low-value, repeatable, reversible purchases, with human approval remaining on anything novel or large. Delegate categories of spend, never the account, and the blast radius of a wrong purchase stays priced in advance.
What controls does a business need before agents can spend?
Four, all boring and all load-bearing: a distinct identity for each agent so spend is attributable, authorization scopes that name what it may buy, hard limits per transaction and per period, and an audit log a finance team can reconcile. If the agent pays through a shared credential, you have an untraceable employee with a company card, and no dispute process will reconstruct what happened.
Why are payments companies moving so fast on this?
Because the volume is coming and the liability is unassigned. Networks and banks published trusted agentic commerce principles through 2026 to settle who verifies an agent’s mandate and who eats a bad transaction. For a buyer, the practical reading is simple: the rails are young, so run the smallest delegated pilot that teaches you the controls, and let the standards race settle before you scale it.