Debate | 7 min read

Who Audits the Agent?

Payment networks now verify transactions, mandates and disputability. Nobody verifies the agent itself: its identity, quality and authorization. This is the open liability question of agentic commerce, and it bites first in regulated industries.

The Transaction Is Verified. The Agent Is Not.

When an AI agent executes a purchase on behalf of a user, the payment network validates the cryptographic token, the spending limit, and the mandate. What it does not validate is the agent itself: who created it, what instructions it is currently following, whether the entity that originally authorized it still endorses those instructions, or whether the agent's underlying model has changed since enrollment.

This is not a design flaw in any specific product. The protocols being built and launched in 2026 are payment protocols. They solve what payment protocols are designed to solve. The agent audit question sits in a different layer entirely.

What Mastercard Agent Pay Actually Guarantees

Mastercard Agent Pay introduces Verifiable Intent: a cryptographically signed record that an authorized agent initiated a specific transaction on behalf of an identified account holder. The mechanism creates an auditable chain for dispute and chargeback resolution. [Q3]

Verifiable Intent addresses dispute resolution. It does not address whether the agent's current behaviour matches the mandate under which it was enrolled.

Source: Mastercard Agent Pay press release (Q3)

What the protocol covers: when a transaction is contested, the record provides a clear chain from the account holder's authorization through the agent's action to the merchant settlement. This is a genuine advance over the status quo, where automated transactions often have no structured accountability trail at all.

What the protocol does not cover: whether the agent's behavior at time of execution matched the mandate under which it was originally enrolled, whether its model has been retrained or modified since that enrollment, or whether the account holder's authorization remains current.

What Visa Intelligent Commerce Actually Guarantees

Visa Intelligent Commerce went live in July 2026 with more than 30 European issuers, including lastminute.com, Frasers, and Cleverbridge. The Trusted Agent Protocol and the Agent Directory address enrollment: they register that a specific agent has been authorized to act on behalf of a specific account holder. [Q1]

What enrollment addresses: confirming that an agent exists, that it has been provisionally authorized by an issuer, and that it is listed in a directory that merchants can query.

What enrollment does not address: ongoing quality. Directory inclusion is a point-in-time credential. It records the state of the agent at enrollment, not the state of the agent at the moment it executes a transaction six months later.

The enrollment mechanism is necessary infrastructure. It is not the same as continuous verification.

The Supervisory Open Question

PSD2 and its successor directive were written for third-party payment service providers: human entities with legal registration, regulatory licenses, capital requirements, and ongoing compliance obligations. An AI agent is none of those things. It has no legal personality. It cannot hold a license. It cannot be fined.

The question of which entity bears accountability when an enrolled agent executes a transaction that the account holder later disputes, or that a supervisory authority later examines, is structurally open. No directive, technical standard, or regulatory guidance published through mid-2026 has resolved it.

This article frames the question. It is not legal advice, and the regulatory landscape is actively evolving. Regulated entities should take independent legal advice on how the frameworks in their jurisdiction apply to their specific agentic deployments.

Regulated Industries Face This First

Banking, insurance, and healthcare are the sectors where liability chains are most precisely defined and most heavily supervised. They are also among the sectors where AI adoption is accelerating fastest. Consumer adoption data points to why this matters now: 70 percent of US consumers already use AI when shopping, and 30 percent have completed at least one purchase via AI. [Q14]

As that share grows in regulated product categories, the agent accountability question moves from theoretical to operational. A financial institution whose AI agent recommends and executes an insurance product purchase faces questions that its existing compliance framework was not built to answer.

The Audit Gap Is Structural, Not a Product Gap

The gap described here is not one that another vendor protocol will close by itself. Mastercard and Visa are building exactly what payment networks should build: payment verification layers. Their scope is transactions, mandates, and dispute mechanics.

What is absent is the layer above payment verification: a mechanism for independently verifying agent identity on an ongoing basis, agent quality relative to the mandate parameters, and the current scope of an agent's authorization as distinct from its original enrollment scope.

This connects to the broader control layer question analyzed in The Control Layer: Why Agentic Commerce Is Not Decided at Checkout. The attribution consequence of agents that operate without continuous verification is examined in Dark Agentic Traffic, or Why Your Reporting Hides the Shift.

Sources:

  • Q1: Visa Intelligent Commerce press release, July 2026. Trusted Agent Protocol, Agent Directory, 30+ European issuers including lastminute.com, Frasers, Cleverbridge.
  • Q3: Mastercard Agent Pay press release. Verifiable Intent, programmatic limits, dispute and chargeback mechanism.
  • Q14: Similarweb Downstream study; LDWW consumer data. 70% of US consumers use AI when shopping, 30% have already bought via AI.

Governance and Risk Advisory for Agentic Commerce

Regulated industries face the agent accountability gap first. We help financial institutions, insurers, and healthcare organizations map the liability exposure and build the governance infrastructure before supervisory questions arrive.

Start the conversation