AI use case

AI agent for payment initiation within a customer mandate

An AI agent that initiates and completes payments or purchases on a customer's behalf, within a mandate the customer set in advance (spending caps, allowed merchants or categories, a tokenized credential and rules for when to ask for confirmation), and then confirms and reconciles every transaction it made.

By Len Debets · Last verified 27 September 2026 · 7 public deployments

USD 18,000 to USD 648,000
Indicative value per year
An online retailer with 2 million orders a year. Worked example, see how it is calculated.

What problem does it solve?

AI assistants have become good at finding things: the right product, the cheapest ticket, the bill that is due. The moment money has to move, they stop. The customer is sent to a checkout page, types in card details, passes a one time passcode and may give up before paying. Recurring chores such as paying a service charge, topping up a transit card or reordering groceries still need a human at every step.

Letting software pay on someone's behalf is not new (standing orders, card on file, merchant initiated payments), but those rails assume a fixed amount or a known merchant. An AI agent picks the merchant, the item and the amount itself. That raises questions the existing rails do not answer: did the customer actually authorise this purchase, can the issuer and merchant tell a legitimate agent from a bot, who carries the loss when the agent buys the wrong thing, and how does the customer see and undo what the agent did. Card networks, wallets and banks are now piloting answers: an explicit mandate, a credential issued per agent, authentication at the right moment and a record of what was authorised.

This page covers the payment step. Helping a shopper discover and compare products is covered by the conversational shopping assistant page; servicing an existing account or card (blocks, limits, statements) is covered by the account and card servicing page.

How does it work?

  1. Set the mandate. The customer tells the agent what it may do: a budget or a cap per transaction and per period, allowed merchants or categories, which card or account to use and when it must ask first (for example above a set amount, for a new merchant, or always). The mandate is stored as structured data, not as a line in a prompt.
  2. Bind a credential to the agent. The issuer or wallet provisions a tokenized credential for this agent only, so the real card number never reaches the agent, and the token can be limited, paused or revoked on its own.
  3. Find and decide. The agent searches, compares and builds the purchase (a product, a ticket, a ride, a bill payment) and checks it against the mandate before anything is paid.
  4. Confirm when the rules say so. Inside the mandate the agent proceeds; outside it, or where the mandate requires it, the agent asks the customer, who approves with strong authentication such as a passkey or app confirmation.
  5. Pay through the rails. The agent submits the payment through the network, wallet or payment service provider with identifiers that mark it as agent initiated, so the issuer and merchant can see who acted and the issuer can still authorise or decline.
  6. Confirm and reconcile. The agent tells the customer what it bought, for how much and from whom, matches the authorisation, capture and any refund against the order, and logs the mandate, the decision and the payment as one record for disputes and audit.
Audience
Customer facing
Autonomy
Supervised agent
Adoption
Emerging
Channels
Mobile app, Web chat, WhatsApp, Phone and voice, API and system to system

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

No public deployment has disclosed a measurable outcome yet.

Value drivers: Customer experience, Revenue growth, Risk and loss reduction, Speed and cycle time.

Indicative value

An online retailer with 2 million orders a year

USD 18,000 to USD 648,000

Incremental gross margin from orders completed by AI agents per year

How this is calculated

Formula: orders * agentShare * incrementalShare * averageOrderValue * grossMargin. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Online orders per year orders, orders per year2,000,0002,000,000The reference retailer.
Share of shoppers who buy through an AI agent agentShare, fraction of orders0.0050.03Editorial assumption, replace with your own. No deployment on this page has published a share of orders completed by an AI agent: the cited deployments are pilots and single milestone transactions. The Mastercard figure elsewhere on this page is a 2030 forecast about the share of shoppers who will use AI agents routinely, not a measured share of orders today, so it is not a benchmark for this input.
Share of agent orders that would otherwise be lost incrementalShare, fraction of agent orders0.10.3Editorial assumption for orders that would have been abandoned or placed with a competitor without agent checkout. Replace with your own test results.
Average order value averageOrderValue, USD per order6090Editorial assumption. Replace with your own figure.
Gross margin grossMargin, fraction of order value0.30.4Editorial assumption for a general online retailer. Replace with your own margin.

What it leaves out: Gross margin on incremental orders only. It leaves out the cost of integrating with agent platforms and payment networks, fees charged by agent platforms, returns and disputes on agent orders, and cannibalisation of orders that would have come through the retailer's own site.

Market estimates (analyst estimates, not deployments)

Who already uses it?

7 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Banco Santander

Spain · Banking · 2026

PilotGrade B

Banco Santander and Mastercard announced a live payment from start to finish that was initiated and executed by an AI agent, run in a controlled environment through Santander's live payments infrastructure using Mastercard Agent Pay, with PayOS orchestrating the transaction. The model lets agents pay on behalf of customers within predefined limits and permissions, and the aim was to validate the bank's operational and control framework under real conditions. The release calls it a pilot that is not a commercial rollout; Santander will now move into extended testing and scaling. No outcome figures are disclosed.

No outcome disclosed.

ING

Netherlands · Banking · 2026

PilotGrade B

Worldline, ING and Mastercard completed a live agentic card payment in production between an ING cardholder and a merchant in the Netherlands, on infrastructure that also runs in Belgium. A merchant's AI agent found concert tickets within a defined budget, presented a selection and paid only after the shopper gave explicit approval. The transaction carries identifiers that mark it as agentic, so ING as issuer keeps control through authentication and authorisation. The parties call it a pilot and name recurring transactions and delegated purchases within predefined parameters as next use cases. No outcome figures are disclosed.

No outcome disclosed.

PayPal

United States · Payments and cards · 2025

ProductionGrade B

In November 2025 PayPal enabled U.S. users of Perplexity's shopping experience to check out with PayPal without leaving the answer engine, from merchants such as Abercrombie & Fitch, Ashley Furniture, Fabletics, Adorama and Newegg. PayPal's agentic commerce services sync merchant catalogs and let merchants accept agent originated payments with their existing PayPal setup, while the retailer stays merchant of record and transactions pass PayPal's fraud screening, identity verification and purchase protection. No volumes or conversion figures are disclosed.

No outcome disclosed.

Visa

United States · Payments and cards · 2025

PilotGrade B

Visa reported in December 2025 that hundreds of controlled, real world agent initiated transactions had been completed with partners in its Visa Intelligent Commerce programme. In the United States, closed beta pilots with agent enablers Skyfire, Nekuda, PayOS and Ramp executed consumer purchases and, in Ramp's case, corporate bill payments by card. In the UAE, Visa is working with Aldar so customers can use AI agents to pay recurring fees such as real estate service charges. In its June 2026 announcement with OpenAI, Visa says transactions will operate within user permissions such as spending limits, merchant categories or required approvals, on tokenized credentials. No outcome figures are disclosed.

No outcome disclosed.

DBS Bank

Singapore · Banking · 2026

PilotGrade C

Mastercard completed its first live, authenticated agentic transaction in Singapore with DBS and UOB: an AI agent from CardInfoLink booked and paid for a ride to Changi Airport through the mobility provider hoppa. Each agent receives its own Mastercard Agentic Token, the consumer's consent is captured explicitly and the purchase is confirmed with Mastercard Payment Passkeys on a tokenized credential. DBS stresses safeguards, transparency and customer authorization, and UOB calls the collaboration a framework for agentic payments. It is a single milestone transaction, and no outcome figures are disclosed.

No outcome disclosed.

Ulta Beauty

United States · Retail and ecommerce · 2026

AnnouncedGrade C

Google Cloud lists Ulta Beauty as rolling out agentic commerce inside AI Mode in Google Search and the Gemini app, where shoppers get Ulta Beauty product recommendations, compare options and complete checkout for eligible purchases within Google's conversational interfaces. The entry was added in the April 2026 edition of Google's list and describes a rollout, not results. No outcome figures are disclosed.

No outcome disclosed.

Majid Al Futtaim

United Arab Emirates · Retail and ecommerce · 2025

PilotGrade C

Mastercard launched Agent Pay in the UAE together with Majid Al Futtaim as a pilot in which AI assistants help users find products and complete purchases on their behalf, starting with movie tickets at VOX Cinemas. Mastercard frames the collaboration as a pathway to broader adoption of agentic commerce across the region. No transaction volumes or outcome figures are disclosed.

No outcome disclosed.

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • A mandate model per customer (caps, periods, merchants or categories, confirmation rules) stored as structured data
  • Product, price and availability data from merchants in a form agents can read, or access to agent enabled catalogs
  • Order, authorisation, capture and refund events from the payment provider for reconciliation
  • Dispute and chargeback history to calibrate confirmation thresholds

Systems to integrate

  • Card network agent programmes or wallet agent services for agent tokens and agent identification
  • Payment service provider or acquirer (authorisation, capture, refunds, webhooks)
  • Issuer or bank authentication (passkeys, app confirmation, one time passcode)
  • Merchant catalogs and order management systems, directly or through agent commerce protocols
  • Customer notification channels (app push, messaging, email) for confirmations and receipts
  • Ledger or order system for reconciliation and dispute evidence

Complexity: High

The agent itself is the easy part. The work is in the payment plumbing (tokenized credentials per agent, network agent programmes, wallet or PSP integration), in storing and enforcing the mandate outside the model, in authentication that fits both regulation and the customer's patience, and in a dispute process for purchases the customer did not expect.

  1. 1

    Start with narrow, repeatable purchases

    Pick journeys where the item and merchant are predictable and the harm of a mistake is small: reorders, top ups, tickets from one venue, recurring bills. Leave open ended shopping across unknown merchants for later.

  2. 2

    Model the mandate before the agent

    Write the mandate as data: cap per transaction, cap per period, allowed merchants or categories, currency, expiry and the confirmation rule. Enforce it in code at payment time, so a clever prompt cannot talk the agent past a limit.

  3. 3

    Use tokens and agent identifiers, never raw card data

    Issue a credential per agent through the network, wallet or PSP, keep card numbers out of the conversation and the model, and send the identifiers that mark the payment as agent initiated so issuers and merchants can see it.

  4. 4

    Put confirmation where the risk is

    Ask for explicit approval with strong authentication for the first purchase, a new merchant, anything above the threshold or anything the agent is unsure about. Use authorise then capture so a purchase can still be stopped before money settles.

  5. 5

    Close the loop on every transaction

    Send a receipt in the customer's channel, reconcile authorisation, capture and order, and keep the mandate, the agent's reasoning and the payment together as one record for disputes.

  6. 6

    Test the limits, not just the happy path

    Build a test set that tries to exceed caps, switch merchants, repeat payments, inject instructions through product pages and pay in the wrong currency, and run it on every change to the agent or its tools.

Guardrails

  • Mandate limits (amount, period, merchant or category, currency, expiry) enforced in code at payment time, outside the model
  • Explicit customer confirmation with strong authentication above the threshold, for new merchants and for the first purchase
  • Tokenized credentials per agent that can be paused or revoked on their own; no card numbers in prompts or logs
  • Idempotency keys and velocity limits so a retry or loop cannot pay twice
  • A tool policy that lets the agent call only the payment and catalog tools it needs
  • Prompt injection checks on content the agent reads from merchant pages and product data

KPIs to instrument

  • Completed agent purchases and the share that needed customer confirmation
  • Mandate breaches blocked by the payment layer (should be caught there, never by the customer)
  • Dispute and refund rate on agent purchases compared with the same customers' own purchases
  • Fraud losses on agent tokens compared with other card not present spend
  • Reconciliation breaks between order, authorisation and capture
  • Customer satisfaction and revocation rate of mandates

Human in the loop

The customer is the human in the loop: they set the mandate, approve anything outside it and can pause or revoke the agent at any time. Inside the organization, payments and fraud teams own the mandate rules and thresholds, review disputes on agent purchases every week and approve every new merchant category or payment type before the agent can use it.

Common failure modes

The agent buys the wrong thing within its limits
A purchase that is technically allowed but not what the customer wanted, such as the wrong size or a near duplicate. Keep caps tight at first, confirm new merchants and items, and make cancellation and refunds one step away.
Mandates enforced only in the prompt
Limits written as instructions to the model can be ignored or talked around. Enforce them in the payment service, which rejects any request outside the mandate whatever the agent says.
Injection through merchant content
A product page or review tells the agent to pay elsewhere or buy more. Treat everything the agent reads as untrusted, restrict payees to the mandate and screen tool inputs.
Confirmation fatigue
If the agent asks for approval on every purchase, customers stop using it; if it never asks, trust breaks on the first mistake. Tune thresholds per journey using dispute and satisfaction data.
No trail when a dispute comes
Without the mandate, the confirmation and the agent's decision stored with the payment, the issuer and merchant cannot resolve a chargeback. Log them together from day one.

What are the risks and rules?

EU AI Act

Limited risk (transparency)

A customer facing agent must make clear that people are dealing with AI, unless that is obvious from the context (Article 50). Initiating payments within a customer's mandate is not listed in Annex III. It becomes high risk if the same agent evaluates creditworthiness, for example by deciding on a buy now pay later or credit line at checkout (Annex III point 5(b)).

Guidance

Controls to put in place

  • AI disclosure and a clear statement of what the agent may buy, for how much and with which credential
  • Mandate records with customer authentication, versioning and expiry
  • Audit trail that links mandate, confirmation, agent decision and payment for every transaction
  • Per agent token lifecycle management (issue, limit, pause, revoke)
  • Dispute and refund handling for agent purchases with defined liability between issuer, merchant and agent provider
  • Regression tests on mandate enforcement and injection resistance before every release

Frequently asked questions

How is agentic payment initiation different from an AI shopping assistant?
A shopping assistant helps a customer find and compare products and then hands over to a basket or checkout. Agentic payment initiation is the next step: the agent actually pays, using a credential and a mandate the customer set, and confirms and reconciles the payment. Many deployments combine both, but the controls for moving money are different.
Is anyone doing this live yet?
Mostly as pilots. Banco Santander and Mastercard ran a live agent executed payment, ING, Worldline and Mastercard completed an agentic payment in production in the Netherlands, and Mastercard, DBS and UOB completed a transaction in Singapore in which an AI agent booked and paid for a ride. PayPal launched checkout inside Perplexity for U.S. users in November 2025, with the shopper completing checkout in the chat. None of them has published volumes or outcome figures.
Does the customer have to approve every payment?
Not necessarily. The customer sets a mandate, and the agent pays within it; approval with strong authentication is required above a threshold, for new merchants or whenever the mandate says so. Surveys show why this matters: in Visa's research, 60% of Americans would not let AI spend any amount without approval, and in the ING and DBS pilots the customer explicitly approved the purchase.
How does strong customer authentication work when an agent pays?
Current pilots authenticate the customer when the mandate or purchase is confirmed, for example with passkeys, and use a tokenized credential issued to the agent. Whether later payments within a mandate need their own authentication under PSD2 depends on how the payment is structured, so settle it with the issuer and your legal team before launch.

How to cite this page

Blits.ai AI Use Case Library, "AI agent for payment initiation within a customer mandate", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/agentic-payment-initiation. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

Cross industryRetail and ecommerce

AI shopping assistant for product discovery and recommendations

A conversational assistant on a retailer's site or app that answers product questions, compares items and recommends products from the retailer's own catalog for a need, project or occasion described in the shopper's own words, grounded in product data, reviews and stock, and hands the shopper to a basket, a store or a human expert.

Deployments
5 public, best grade B
Reported conversion uplift
3x
Sun & Ski Sports, vendor claim
BankingPayments and cards

AI agent for account and card servicing

An AI agent that resolves routine account and card requests end to end, such as balances, statements, card blocks and replacements, PIN resets and limit changes, across app, web, messaging and phone, and hands anything sensitive or unusual to a human with the full context.

Deployments
2 public, best grade B
Reported containment rate
about 90%
DBS Bank, organization claim
BankingPayments and cards

Real time fraud scoring for card and instant payments

Machine learning that decides in milliseconds, without any conversation, how likely each card authorization and account to account payment is to be fraudulent, combining behavioural, device and network signals, so the bank can approve, challenge or block a payment before the money leaves. Working the resulting alerts and talking to the customer about them are separate use cases.

Deployments
9 public, best grade B
Median fraud loss reduction
30%
3 deployments
BankingPayments and cards

AI agent for card dispute intake

A customer facing AI agent that handles the "I do not recognise this charge" moment: it finds the transaction, separates suspected fraud from merchant disputes and simple confusion, explains the customer's rights and timelines, collects the details and evidence the rules require, and opens a correctly classified dispute case for the operations team.

Deployments
3 public, best grade B
Autonomy
Supervised agent
BankingPayments and cards

AI for ledger and payment reconciliation

AI that matches entries across nostro and vostro statements, card and scheme settlement files, the general ledger and suspense accounts, proposes matches and clearing journals, and routes only the genuine breaks to an operator with a plain language explanation.

Deployments
4 public, best grade B
Autonomy
Supervised agent