AI Agents Choose Open Banking API Over Cards

How AI agents actually pay in 2026: open banking APIs vs card rails, the protocols that matter, and where each one still breaks down.

18 mins read
Anime illustration of a consumer authorizing an AI shopping assistant to pay a merchant directly through open banking.

Agentic payments are the answer to a question most merchants still cannot answer: when an AI agent buys something on your site, what actually moves the money?

Morgan Stanley Research put numbers on the stakes in December 2025. Agentic shoppers could account for roughly $190 billion in its base case and up to $385 billion in its bull case of US e-commerce spending by 2030, or somewhere between 10% and 20% of the online retail market. That is a range with a wide spread, not a settled forecast, but the direction of travel is not seriously disputed.

The infrastructure question underneath it is more contested than most vendor pitches admit. Card networks were designed around a human being present at the moment of purchase, and every liability rule in the system rests on that assumption. Open banking APIs and account-to-account (A2A) rails were designed around bank-side authentication and consent mandates, which maps more naturally onto how an autonomous agent behaves. Neither is a finished answer in 2026.

This guide compares both routes without pretending the winner is obvious. It covers where open banking genuinely outperforms cards, where card rails still hold a decisive advantage, which agentic payment protocols actually matter, and what the picture looks like outside the UK. If you want the underlying mechanics of authorization, capture and settlement first, our breakdown of how payment processing works covers the fundamentals this article builds on.

The Rise Of AI Agents In Global Commerce

During Cyber Week 2025, Salesforce reported that AI and agents influenced 20% of global orders and 17% of US orders. That figure covers personalized recommendations and conversational service rather than autonomous purchasing, and the distinction matters: influence at that scale is real, but it is not agents completing checkouts unattended. Fully autonomous purchasing is still small. NMI research in 2026 found that 11% of US shoppers had completed a purchase through an AI tool and 84% had never given one their payment details. What changed is that the infrastructure shipped anyway, from all three card networks and the major platforms, inside about eighteen months. Merchants are now making architecture decisions ahead of the demand curve rather than behind it, which is an unfamiliar and uncomfortable position.

Agentic Payments Are A Stack, Not A Single Rail

The most common mistake in agentic commerce planning is treating this as one decision. It is four decisions, and they sit at different layers. An agent purchase in 2026 typically touches several of these at once rather than picking one and discarding the rest.

LayerWhat it doesStandards in play
DiscoveryLets the agent read your catalogue, stock and policiesMCP, A2A
CheckoutAssembles and confirms the cart with the merchantACP (OpenAI and Stripe), UCP (Google and Shopify)
AuthorizationProves the human approved this specific purchaseAP2, Mastercard Verifiable Intent, Visa Trusted Agent Protocol
SettlementActually moves the moneyCard rails, open banking A2A, x402 stablecoins

Open banking is a settlement-layer answer. Visa’s Trusted Agent Protocol and Mastercard’s Agentic Tokens are authorization-layer answers. They are not competitors, and a team that treats them as an either-or choice will build the wrong architecture. AP2, published by Google in September 2025 and later donated to the FIDO Alliance, defines how an agent proves it had permission to spend. It says nothing about which rail carries the money, which means an AP2 mandate can sit on top of a card transaction or an A2A transfer equally well.

The practical implication for a merchant or platform is that the settlement question, cards versus open banking, is genuinely open and can be answered per market and per use case. The authorization question is converging fast, and you should design for mandate-based consent regardless of which rail you settle on.

Why Card Processing Fails Autonomous AI Agents

Card authentication was designed to prove a human is present. Under PSD2 in Europe, Strong Customer Authentication applies to most consumer card payments unless a specific exemption applies, which in practice means 3D Secure challenges, one-time passcodes and, at the merchant layer, bot detection and CAPTCHAs. Every one of those is a test an agent is supposed to fail. A typical challenged flow looks like this:

  1. The customer inputs raw credit card details into the merchant gateway.
  2. The merchant processor requests authorization from the issuing bank.
  3. The issuing bank triggers a 3D Secure challenge where no exemption applies.
  4. The human user manually solves a CAPTCHA or enters an OTP.
  5. The bank verifies the human input and approves the authorization request.
  6. Funds settle to the merchant on the acquirer’s schedule, typically one to three business days later.

Virtual cards and agent-scoped tokens work around this rather than solving it, which is why the networks eventually built purpose-made frameworks instead. The friction is not uniform, though, and it is worth being exact about where it bites. Card-on-file and merchant-initiated transactions already run without a challenge. The genuine failure case is narrower than it first appears: an agent’s first purchase at a merchant the customer has never used.

How Networks Adapt With Trusted Agent Protocols

The card networks and major processors have each shipped a framework for agent-initiated transactions. These are not defensive patches. They answer a question open banking does not answer on its own, which is how a merchant verifies that the agent in front of it is legitimate and is operating inside the limits its user actually set.

ProviderAgent SolutionTarget AudienceCore Technology
VisaTrusted Agent Protocol (TAP)Enterprise MerchantsDelegated Authentication
MastercardAgentic TokensGlobal AcquirersCryptographic Keys
StripeShared Payment Tokens (SPTs)API DevelopersScoped Permissions

These sit at the authorization layer rather than competing with bank rails at the settlement layer, and they are converging quickly. In April 2026 Google donated AP2 to the FIDO Alliance and Mastercard donated its Verifiable Intent framework, putting agent authorization on the same standards track as passkeys, with Visa, American Express, PayPal, Stripe, Adyen and others joining the working groups. The real risk for a startup is not that these frameworks are stopgaps. It is building directly against one network’s proprietary SDK before that convergence finishes, and paying for the rework afterwards.

The Open Banking API Advantage For Machines

Where a standing mandate exists, open banking has a structural advantage no card retrofit matches. Authentication happens inside the customer’s own banking app rather than in the agent’s execution path, so the agent never handles or stores a credential and never has to defeat a check designed to catch automation.

  • Payment initiation runs against an existing mandate without a fresh human step.
  • Instant A2A rails such as Faster Payments, Pix, UPI and SEPA Instant deliver final funds in seconds rather than clearing over days.
  • The agent never holds a card credential, so there is nothing to tokenize, rotate, or leak.

The qualifier in the first sentence is doing a lot of work. Open banking is a strong architecture for agents where a mandate is already in place. What happens when one is not in place is the subject of the next section, and it is the part most vendor material leaves out.

Where Card Rails Still Beat Open Banking For AI Agents

An honest comparison has to acknowledge that open banking loses on several dimensions that matter enormously in retail.

  • Disputes and chargebacks. This is the decisive one. A card purchase carries statutory and scheme-level dispute rights, and delegating the click to an agent does not by itself remove the protections sitting underneath a card payment. Most A2A and open banking payments have no equivalent mechanism at all. When an agent buys the wrong item, at the wrong time, from the wrong merchant, a card purchase can be reversed and a bank transfer usually cannot. It is worth being precise about what is unresolved: US regulators have not issued agent-specific dispute guidance, so how the existing rules apply when an agent misreads an instruction is an open question rather than a settled one. That uncertainty is a reason to keep card rails available, not a reason to assume they will protect you.
  • One-off payments are worse, not better. For a single non-recurring purchase, open banking payment initiation requires Strong Customer Authentication on every transaction. The agent has to hand the user back to their banking app each time. A tokenized card credential does not. Open banking wins for agents only where a long-lived mandate already exists, which brings us to the availability problem.
  • Credit, rewards and instalments. Cards carry credit lines, cashback, purchase protection and, in markets like Brazil, instalment plans that a large share of consumers actively prefer. A2A payments carry none of that. Removing them from an agent’s payment options removes a real reason people buy.
  • Merchant-side reconciliation is less mature. Refunds, partial refunds and failed-payment recovery are solved problems on card rails and comparatively immature on A2A rails in most jurisdictions.

The correct read is not that open banking loses. It is that open banking wins decisively for recurring, mandate-backed, high-frequency or low-margin flows, and loses for one-off discretionary retail purchases where dispute rights and credit matter most. Any architecture that assumes a single rail for both is going to be rebuilt.

Designing API Flows For Autonomous AI Agents

Developers must design payment flows tailored to specific AI functions. A standard one-off payment initiation API request requires a single user consent URL for immediate execution.

  1. The platform requests a long-term VRP authorization from the specific bank.
  2. The human user authenticates the initial request through their native banking app.
  3. The bank issues a persistent mandate bound by strict digital spending limits.
  4. AI agents execute subsequent payments against that mandate, in the markets and use cases where the local scheme permits it.

Within its limits, the mandate does what a card-on-file arrangement does, except the consent is stored and revocable on the bank’s side rather than the merchant’s. Those limits are the catch, and they are considerably stricter than most architecture diagrams admit.

Step-by-step API flow showing how an autonomous AI agent executes variable recurring payments using a long-term bank authorization mandate.
By leveraging long-term VRP bank mandates, AI agents can process continuous transactions without repeatedly prompting the user for manual re-authentication.

The VRP Availability Reality Check

VRP mandates are the mechanism that makes open banking work for agents, so it matters a great deal that they are not widely available yet.

The UK is furthest ahead. Commercial VRP went live on 2 June 2026 under a new industry-owned scheme, the UK Payments Initiative, described as the first new UK payment scheme since Faster Payments in 2008. The FCA’s own statement on the launch of the UK Payments Initiative scheme sets out both the scope and the caveats. Wave 1 covers five categories only: regulated financial services, utilities and telecoms, rail, registered charities and government bodies. Wave 2, which extends commercial VRP to general e-commerce, was expected in the second half of 2026.

Read that list again against the use case in this article. An AI agent buying a pair of shoes is not covered by Wave 1. If your product plan assumes UK commercial VRP is available for retail agent purchases today, the plan is ahead of the rail.

Outside the UK, VRP as a defined construct largely does not exist. The EU has payment initiation under PSD2 with SCA applying per payment, and PSD3 is still working through the legislative process. The US has no open banking mandate framework, and agent payments there run predominantly on card rails and increasingly on stablecoin settlement for machine-to-machine flows. Anyone planning a multi-market agentic payments rollout needs a rail matrix by country, not a single architecture.

Solving PCI Scope And High Micro-Transaction Fees

Interchange is priced as a percentage plus a fixed component, which is what makes sub-dollar agent transactions uneconomic rather than technically impossible. A fixed fee of thirty cents on a ten cent API call is not a fee, it is the entire business model. Account-to-account rails price differently. The UK’s commercial VRP scheme is built around a fixed pence-per-transaction charge rather than a percentage, and Pix in Brazil is free to consumers with low fixed costs to merchants. That pricing difference, not the technology, is why high-frequency machine payments are viable on those rails and not on card rails.

The PCI picture is more nuanced than it is usually presented. If you issue agent-scoped virtual cards through a provider’s API and never touch a primary account number, your scope generally does not expand, because the provider carries it. Scope grows when you handle, store or route card data yourself, which is a design decision rather than an unavoidable consequence of using cards. Open banking sidesteps the question by never introducing card data into the flow at all, but a team that assumes cards automatically mean a heavy compliance burden will overestimate what they are saving.

Consumer Trust Is The Real Constraint On Agentic Payments

Trust is the constraint that will decide how fast any of this scales, and the survey evidence is not encouraging. The trust picture is worse than most vendor material suggests. An ACI Worldwide and YouGov survey of UK adults found that only 19% trust AI assistants to make everyday purchasing decisions, compared with 55% for a human adviser; 69% do not trust AI even when it follows rules they set, and 61% said linking an agent to their bank account would reduce their willingness to use it.

  • Hard spending limits cap the total Account-to-Account (A2A) payments an agent executes.
  • Merchant whitelisting restricts autonomous Agentic commerce to pre-approved, trusted digital storefronts.
  • Instant revocation switches allow humans to immediately terminate access during emergencies.

Structured delegation is necessary but the evidence suggests it is not sufficient. People who say they distrust an agent even when it follows rules they set themselves are not asking for better limits. They are asking what happens when the limits are honoured and the outcome is still wrong. That is a recourse problem rather than a controls problem, and recourse is the part of this stack nobody has finished building.

Full-Stack Agent Wallets Power Micro-Transactions Globally

There is a third category that neither cards nor consumer open banking were built for: machine-to-machine payments, where the buyer is software paying for an API call, data or compute rather than a person buying goods. Protocols like x402 revive the HTTP 402 status code so a server can answer a request with a price instead of a rejection, and the agent pays per call in stablecoins and uses the receipt itself as its access credential. MCP is how an agent discovers and calls a wallet or a merchant’s tools. It is not a settlement mechanism, and conflating the two produces architecture diagrams that do not survive contact with a payments team.

RailBest fitRealistic settlement
Card networksOne-off consumer retail purchasesAuthorization instant, funds in 1 to 3 business days
Instant A2A (Pix, UPI, Faster Payments, SEPA Instant)Recurring and high-frequency consumer paymentsSeconds, with final funds
Legacy bank transfer (ACH, SEPA Credit Transfer)Domestic and cross-border B2B1 to 3 business days
Stablecoin (x402 and similar)Machine-to-machine API, data and computeSeconds on chain, longer for full finality

No row wins outright. A platform that sells to consumers, bills subscriptions and buys API capacity from other agents will end up using three of these, and the real design question is how a single consent and audit layer sits above all of them.

What Agentic Payments Look Like Outside The UK And US

The claim that open banking is the natural rail for AI agents is much stronger in some markets than others, and the gap is mostly regulatory rather than technical.

Brazil. Pix, launched by the Central Bank in November 2020, has already overtaken credit cards as the leading online payment method by value. Pix Automático, launched in June 2025, added recurring account-based payments with a single upfront consumer authorization, exactly the mandate primitive an agent needs. Brazil therefore has, in production and at national scale, something the UK has only just started rolling out sector by sector. For any platform serving Brazilian consumers, the agentic payments question is not whether A2A rails are ready. They are, and a large segment of the market has no credit card at all.

India. UPI provides the same instant A2A foundation with a mandate framework via UPI AutoPay, again at national scale and with per-transaction costs near zero.

United States. No open banking mandate exists, FedNow adoption is still building, and agent payment activity has concentrated on card-network overlays and on stablecoin settlement for API and machine-to-machine payments through protocols like x402.

The strategic conclusion is uncomfortable for single-vendor pitches. There is no globally correct answer. A platform selling into Brazil and the UK and the US will end up running three different settlement strategies for the same agent behaviour, and the engineering cost of that is the real project, not the API integration itself.

A Practical Readiness Checklist For Agentic Commerce

Most of the work of preparing for agent purchases is not payment integration. It is everything upstream of the payment.

Make your catalogue machine-readable first. An agent cannot buy what it cannot parse. Structured product data, unambiguous stock and pricing, and clearly stated return and shipping policies do more for agent conversion than any rail choice. We covered the wider problem of building pages that serve human visitors, search crawlers and AI assistants simultaneously in designing website layouts for AI assistants, and the payment layer inherits every weakness in that foundation.

Decide your consent model before your rail. Whatever rail you settle on, you will need to store proof of what the customer authorized: scope, ceiling, duration, merchant whitelist, revocation state. Mandate-based authorization is the one part of this stack that is converging, so build it once and make it rail-agnostic.

Instrument disputes from day one. Agent transactions produce a dispute category that did not previously exist, the “my agent misunderstood me” claim, and it sits awkwardly between fraud and buyer’s remorse. Capture and retain the mandate, the instruction and the agent identity for every agent-initiated order. Without that evidence a merchant loses these disputes by default.

Be realistic about build versus buy. Supporting multiple rails, mandate storage, agent identity verification and dispute evidence is a substantial engineering programme. For store owners weighing that decision, the same trade-offs we set out in when a WooCommerce store needs custom development apply here: plugin-level solutions handle the common case, and anything with cross-market or cross-rail logic almost always requires custom work. If you decide to buy rather than build the initiation layer, the market splits between full-stack aggregators and single-rail specialists. Providers in this category include Plaid, TrueLayer and Tink, alongside others offering Open Banking Payments through a unified API that abstracts away per-bank connection work, which is the bulk of the effort in any multi-market rollout. Evaluate any provider on the specific rails and countries you need rather than on aggregate coverage claims, since bank-level coverage varies enormously within a single market.

Start with recurring, not retail. The clearest early wins for open banking agent payments are subscriptions, top-ups, account funding and utility-style billing, because those are the flows where mandates exist today and where card-on-file failure rates are highest.

Prepare Your Platform For Autonomous AI Purchasing

Agent-initiated purchases are moving into production faster than the rails underneath them are maturing, and the honest position in 2026 is that no single settlement choice is correct everywhere. Open banking wins on cost and on mandate-backed automation in the markets where mandates exist. Cards win on dispute rights, credit and universal acceptance. Stablecoins win for the machine-to-machine flows neither was designed for.

The teams that will be ready are not the ones that pick a rail. They are the ones that build a rail-agnostic consent and mandate layer now, instrument disputes before they have any, and treat market-by-market settlement as a standing operational question rather than a one-time integration.

Frequently Asked Questions About Agentic Payments And Open Banking

How do AI agents actually pay for things in 2026?

Through one of three routes. A tokenized card credential scoped to a specific agent and spending policy, an account-to-account transfer initiated through an open banking API under a stored mandate, or a stablecoin payment over a protocol such as x402 for machine-to-machine and API purchases. Most production flows in 2026 combine an authorization layer such as AP2 with one of these settlement rails.

Can AI agents use ordinary credit cards?

Not directly and not reliably. Legacy card flows depend on human authentication steps such as 3D Secure challenges, one-time passcodes and CAPTCHAs, which block automation by design. The workaround is a scoped agent credential rather than a raw card number, which is what Mastercard’s Agentic Tokens and Visa’s Trusted Agent Protocol provide.

Do chargeback rights still apply when an AI agent makes the purchase?

For card transactions, generally yes. Delegating the purchase to an agent does not remove the protections that sit under a card payment, and all three card networks have built their agent frameworks on the assumption that cardholder dispute rights stay intact. What is genuinely unresolved is the case where an agent buys something the customer did not want. That sits between fraud and buyer’s remorse, US regulators have not issued agent-specific guidance on it, and no published rule currently assigns fault. For account-to-account payments there is usually no equivalent dispute mechanism at all, which is the single strongest argument for keeping card rails in the mix.

Is open banking cheaper than cards for AI agent payments?

For high-frequency and low-value transactions, materially so. A2A payments avoid percentage-based interchange and typically carry a small fixed per-transaction cost, which is what makes sub-dollar agent purchases viable at all. For occasional higher-value retail purchases the fee advantage is much smaller and can be outweighed by the loss of dispute protection and credit options.

What is a payment mandate and why do agents need one?

A mandate is a stored, bank-side authorization that records what an agent is permitted to spend: a maximum amount, a frequency, an expiry, and often a list of approved merchants. The customer authenticates once when the mandate is created, and the agent transacts within those limits afterwards without further prompts. The mandate is also the evidence that proves authorization if the transaction is later disputed.

Should I build for open banking or card rails first?

Neither exclusively. Build the mandate and consent layer first, since it is rail-agnostic and every route requires it. Then choose rails by market and use case: A2A for recurring and high-frequency flows in markets where mandates exist, such as Brazil with Pix Automático or UK financial services and utilities under commercial VRP, and card rails for one-off retail purchases where dispute rights and credit matter to the buyer. For broader context on where autonomous agents are creating operational value beyond payments, see our overview of how AI powered agents help companies automate workflows and reduce costs.

Claudio Pires

Written by

Claudio Pires

Co-founder of Visualmodo, Claudio is a senior web designer and developer with over 15 years of experience in content creation and technical support. A trilingual expert fluent in English, Portuguese, and Spanish, he brings a global perspective to digital design. As an active YouTuber and industry specialist based in Brazil, Claudio is dedicated to pushing the boundaries of web development and sharing his insights with a global community.

Topics
Continue reading iGaming Platform Development and Casino Licensing Guide
Continue reading Elevating E-Commerce Conversions Through Strategic Digital Architecture
Continue reading How to Choose a Website Builder That Generates Inbound Leads
Continue reading Contractor of Record Software: What it Does and How to Choose
Continue reading Embedded Security by Design: Secure Boot and the Cost of Skipping It

Recommended For You