Introduction
India is becoming a critical test market for agentic payments on UPI, its widely used instant-payment network. In this emerging model, an AI agent doesn't just recommend a product or build a cart. With authority granted in advance, it can initiate a payment when defined conditions are met.
The significance extends beyond India. Agentic payments raise a central enterprise AI question: when software can act, not just advise, how should we grant, constrain, monitor, and revoke its authority?
India offers an unusually consequential place to find out. UPI processed 24.51 billion transactions worth INR 24.85 trillion in August 2026. Introducing AI agents to infrastructure operating at that scale turns agentic commerce from a product feature into a test of digital trust.
What Are Agentic Payments on UPI?
Agentic payments on UPI are transactions initiated by an AI agent on behalf of a person or business under preauthorized conditions. UPI, or Unified Payments Interface, is the instant bank-to-bank payment system operated by the National Payments Corporation of India (NPCI).
The key distinction is the agent’s authority:
AI-assisted payment: The agent searches, compares, or fills a cart, but a person approves the transaction at checkout.
Agentic payment: A person or business approves a mandate in advance, allowing the agent to transact when preset conditions are met.
This doesn’t mean that AI has unrestricted account access. An agent will follow a predefined set of rules to manage spending limits, purchase conditions, identity checks, audit records, and controls. Human approval shifts from approving each transaction to setting the rules for transactions.
Why Is India Moving from Conversational Checkout to Delegated Authority?
India’s market already illustrates two stages of AI-led commerce.
In October 2025, Razorpay, NPCI, and OpenAI announced a pilot that lets ChatGPT users discover products on Bigbasket and complete a UPI purchase within the conversation. The agent can check the retailer’s catalog and present options, but the user confirms before the order is placed. The pilot uses UPI Circle and UPI Reserve Pay, with Axis Bank and Airtel Payments Bank participating as banking partners, according to Razorpay.
User asks → AI selects → User confirms → UPI payment completes
Pine Labs introduced a more autonomous model in June 2026. Its Pine Labs Payment Protocol, or P3P, extends UPI’s mandate infrastructure so customers can authorize rules in advance. Pine Labs made Gullak live on the protocol. Gullak is a fintech mobile application that allows users to automate small daily, weekly, or monthly savings and invest them in 24K digital gold. Here, a user can tell an agent to buy INR 500 of gold if the price falls below INR 16,000 per gram, approve the mandate once, and receive confirmation after the agent acts. Grantex provides identity, delegated authorization, spending controls, and auditability, according to the Pine Labs P3P announcement.
User defines rules → User approves mandate → Agent monitors conditions → Agent pays
The difference between these models is not merely fewer clicks. In the first, AI supports a human decision. In the second, the human delegates bounded decision-making authority to software. That is the threshold enterprise AI must cross if autonomous agents are to become economically useful.
How Unified Agentic Protocol Could Become a Trust Layer?
Reuters reported in September 2026 that NPCI was developing a registry as part of a planned Unified Agentic Protocol. According to sources familiar with the work, the registry would vet and monitor AI agents making payments for users. NPCI had not publicly released the complete technical or liability framework at the time.
The proposal is best understood as a trust layer above the payment rail. UPI moves money; the registry would help establish which agent is acting, whether it is recognized, and how its activity can be monitored.
That distinction matters because customer authentication is no longer sufficient. A payment network must also identify the software acting for the customer, verify the scope of its authority, and connect every transaction to an auditable mandate.
Why Know Your Agent Is Becoming a Payment Standard?
The same challenge is emerging globally. Ant International, Mastercard, and Visa announced work on a Know Your Agent (KYA) interoperability framework. The goal is to establish shared principles for agent onboarding and identification across payment networks, digital wallets, agent platforms, and marketplaces while allowing each network to retain its own verification processes.
Know Your Customer establishes who the customer is. KYA must establish which agent is acting, who authorized it, what it may do, how much it may spend, and whether that authority remains valid.
Control | Question it must answer |
Agent identity | Which agent initiated the transaction? |
Principal | Which person or organization authorized it? |
Scope | What can it buy, from whom, and for what purpose? |
Limits | How much can it spend, and how often? |
Evidence | Can the instruction and decision be reconstructed? |
Revocation | Can its authority be withdrawn immediately? |
KYA could become foundational infrastructure for agentic commerce. Without it, payment systems may confirm that a credential is valid without knowing whether the software using it is the intended agent or whether its decision falls within the original mandate.
What Are the Limits of Enterprise AI Governance?
An agent could reorder approved inventory, release a verified invoice, renew software based on usage, or buy cloud capacity at a defined price.
But these remain forward-looking enterprise scenarios, not evidence of widespread autonomous procurement. The live examples in India are still narrow and largely consumer-focused. Their value lies in demonstrating the mechanism: software can trigger a payment after a person has approved the governing conditions.
That mechanism raises the standard for AI governance. Payment authority cannot be treated as another application permission. It requires verified agent identity, delegated authorization, transaction limits, merchant restrictions, approval thresholds, tamper-resistant logs, immediate revocation, and separation of duties.
These principles align with the broader focus on governance, traceability, and human oversight in the NIST AI Risk Management Framework, although NIST’s framework is not payment-specific.
The deeper lesson is that autonomy requires enforceable boundaries. A policy document may describe what an agent should do, but a payment control layer must determine what it is technically allowed to do.
What Security Risks Emerge When AI Agents Move Money?
Agentic payments create risks that conventional fraud monitoring may not fully capture. A compromised agent could generate a transaction that appears normal because it stays within assigned credentials and spending limits.
The risks include agent impersonation, credential theft, manipulated merchant data, replay attacks, and gradual expansion beyond an approved scope. Prompt injection is particularly relevant because untrusted content can alter an agent’s instructions or decisions. OWASP identifies prompt injection as a leading risk in its security guidance for large language model applications.
A compromised chatbot may produce a bad answer, whereas a compromised payment agent can move money incorrectly.
Controls therefore need to cover the full decision chain: the instruction the agent received, the data it trusted, the policy it applied, the credential it used, and the merchant it selected. Monitoring only the final transaction is too late.
Who's Liable When an Agent Gets It Wrong?
The most difficult case is not an obviously fraudulent payment. It is a transaction made by a correctly authenticated agent that stays within its formal limit but makes the wrong decision.
Imagine a procurement agent authorized to spend INR 50,000 on office supplies. Its credentials are valid, but it relies on a manipulated supplier listing and orders the wrong inventory. The payment rail may work exactly as designed, yet responsibility could be disputed among the enterprise, agent provider, payment provider, and merchant.
Reuters reported that liability for unauthorized or erroneous agent transactions remained unresolved as NPCI prepared its protocol. Until regulations and contracts allocate responsibility more clearly, organizations should assume that delegating authority does not delegate away accountability.
Agentic Payments Are Really About Institutional Trust
India’s shift toward agentic payments on UPI is not simply a faster-checkout story. It is an early attempt to determine whether institutions can give software meaningful authority without weakening identity, consent, security, or accountability.
The winners in agentic commerce may not be the companies that give agents the most freedom. They may be the ones that make delegation precise: every agent identifiable, every permission limited, every decision traceable, and every mandate revocable.
That is why India’s experiment matters globally. Payment rails will differ, but the governance problem will not. Before AI agents can become trusted economic actors, the systems around them must prove that autonomy can operate inside enforceable boundaries.

