From Prompts to Payments: the rise of agentic AI in payments

By Iti Panwar
September 12th, 2026

Publication : Blog
Themes : Agentic AIFinancePaymentsRegulation

From Prompts to Payments: the rise of agentic AI in payments

Image sourced by www.magnific.com

India’s journey to financial ‘agency’

India’s payments and transactions journey is often touted as one of the most impactful transformations in the global financial ecosystem. To improve inclusion and facilitate commerce, India’s digital payment revolution has historically focused on reducing friction in how people access and move their money. India’s most visible financial transformation journey can be traced back to the emergence of mobile banking and digital wallets and PPIs in the 2010s, through the explosive growth of UPI after demonetisation in 2016, to now a system processing over 600 million transactions daily. It is against this backdrop that India is now experimenting with AI agents, a new frontier that will reshape payments in ways that we are only beginning to understand. 

With AI now perceived as an essential ingredient in digital transformation, the embedding of agentic AI in the financial sector, seems to signal the onset of the next revolution – aimed to reorient the system in a way that direct human involvement in transactions becomes the exception rather than the rule.

In October 2025, National Payments Corporation of India (NPCI) and Razor Pay in partnership with OpenAI launched their pilot use case where AI agents could complete grocery purchases on behalf of their users using ChatGPT, leveraging the UPI circle framework and reserve pay mechanisms. This was followed by similar pilots launched by Razorpay and NPCI with Anthropic and Sarvam AI in 2026. More recently, Pine Labs launched a protocol that lets AI agents execute payments without the need for human authentication on transactions. 

What India is entering now is not merely an upgrade to its payments infrastructure but a potential reorientation of who controls and who pays.

Table 1. Overview of India’s Agentic commerce Stack

EntityRoleIllustrative examples
Payment EntitiesEntities that route, clear and settle transactionsBanks, TPAPs, PSPs, Payment Gateways
Protocol BuildersProtocols to enable identity verification, delegated authorisationsPine Labs (P3P)
AI Partners Provide the underlying models and AI agents that interpret user intent, negotiate and execute on user’s behalfOpenAI (ChatGPT), Anthropic (Claude)
AI storefronts/merchantsMerchants or platforms that provide the catalogue and inventory to LLMs via MCP servers  Swiggy, Gullak (digital gold)

Source: Author’s analysis

What regulates Agentic payments in India today

India’s regulatory architecture around agentic payments reveal three distinct layers of regulatory maturity

  • A mature payments rail, statutorily grounded in the Payment and Settlements Systems Act, 2007, allowing RBI to monitor and regulate payments systems and downstream instruments such as UPI, payment aggregation, alongside NPCI’s operational rules for digital payments systems.
  • A nascent AI governance layer that is principles-based, voluntary in effect, led by RBI’s Free-AI framework and Regulatory principles for model risk management which provides principles for responsible AI adoption and applies only to RBI-regulated entities.
  • An emerging data governance regime anchored on the DPDP Act which establishes the broader framework on data governance but whose substantive obligations and Consent Manager framework are yet to become fully operational.

Missing pieces of the Agentic AI puzzle

The central tension in India’s current regulatory architecture is one of assumed agency with each transaction being initiated and authorised by a human. In other words, crucial aspects remain unanswered when an AI agent, acting on prior instruction, completes a financial transaction on the user’s behalf with no human in the loop. 

Liability allocation

When an erroneous or fraudulent UPI transaction is initiated by an AI agent acting on a one-time mandate, processed by a payment gateway and settling via a TPAP and PSP bank, no framework clearly answers who bears responsibility for it. Further, the mandate framework upon which agentic payments are being built is already showing signs of strain. AutoPay failure rates reported hit 55-90% in August 2025 alone, and RBI flagged a sharp surge in consumer complaints under UPI AutoPay with users being unaware about authorising a recurring mandate.

The current liability framework for safeguarding customers from payment frauds places the burden of liability exclusively on the issuer bank while the beneficiary bank carries no such obligation. The Payments Vision 2028 proposes to correct this asymmetry with a shared responsibility framework, under which both issuer and beneficiary bank would jointly bear the responsibility as a measure to incentivise even the beneficiary bank to take appropriate fraud detection measures. 

This question of liability allocation becomes more consequential as payment systems move towards automation. Autonomous transactions do not introduce a new liability problem – they compound the existing one by introducing new complications around agency and potential model failure. It could stretch the same structural ambiguity across a longer, less legible chain of  actors. If a human-authorised, single purpose mandate already produces this volume of failures and user confusion, then a standing mandate authorising an agent to act on user’s behalf, across different merchants and conditions, is likely to multiply this problem.

Consent architecture

The DPDP Act under clause 6 lays out a clear criteria for valid consent: it must be free, specific to a stated purpose, backed by clear notice, unambiguous and unconditional with an affirmative action. A standing instruction like “buy groceries” isn’t consent to a single, bounded act of processing – it requires persistent authorisation for a series of future acts, each of which may involve pulling in new merchants, data fiduciaries or serving new processing purposes that could not have been pre-identified.

Even under India’s Data Empowerment and Protection Architecture (DEPA), its financial sector implementation via the Account Aggregator framework (AA) does not account for a system that keeps exercising authorisation on a user’s behalf indefinitely against merchants and conditions that shift over time. The compliance guidance for AI also emphasizes fairly conventional fixes such as updating comprehensive privacy notices to DPDP standards and listing out complete operating perimeter, which assumes processing purposes can still be enumerated in advance. 

Consent managers, as envisaged in DPDP Act and rules, may only partially solve the problem due to its design and purpose limitations, and currently may not have a mechanism to address future needs for delegated authorisation. The right to revoke consent is also further strained in an agentic setting where the speed of autonomous execution can outpace a user’s ability to exercise that right before the transaction is complete.

Jurisdictional applicability

RBI’s regulatory perimeter is primarily entity-based and covers regulated entities (REs) involved in payment flows, including banks, NBFCs and payment system operators. Within this framework, accountability is principally placed on banks, even where other actors such as third party payment applications play a material role in facilitating or shaping payment interfaces.

With the emergence of agentic AI, this potential gap becomes more pronounced. As AI assistants and other third party technology providers become embedded in payment journeys, decisions that were previously made by the customer may increasingly be influenced by an upstream technology provider.

This raises a broader question of jurisdictional applicability where the bank or RE remains subject to RBI oversight, the upstream technology provider that materially influences the payment intent may not be. This could create uncertainty over the extent to which RBI’s regulatory framework can apply, particularly where the RE relies on third-party models that it does not directly control or supervise. 

In conclusion, these gaps point towards a missing comprehensive framework or a convoluted regulatory landscape that is able to address these autonomous transactions as a distinct event.

Way forward 

The absence of a comprehensive legislation or regulatory framework governing agentic commerce does not merely translate into procedural gaps but also market-shaping forces that influence who builds what, who takes on risk, and who captures value while the rules are still being written. 

The more important lesson for agentic payments is one of careful sequencing: regulation and policy frameworks must be conceived alongside technology, rather than conceived in response to its failures. Tools like regulatory sandboxes offer a practical mechanism to support development of appropriate regulatory frameworks and allow for agentic payment models to be tested at controlled scale in real time conditions. This would enable regulators to design robust frameworks that preemptively tackle some of the regulatory risks arising from agentic payments before they reach more scaled adoption. 

In addition to Aapti’s work in the digital financial frauds space, we are closely tracking this space, and will be writing more on the broader implications of agentic payments, including questions of market power and incentives, user agency and the distribution of risk. We welcome the opportunity to engage with organisations building, regulating or thinking about agentic payments and commerce whether you’re a platform, a regulator, or a researcher working on adjacent questions.