
Picture your grocery order placing itself. Not a saved basket you approve, but a software agent that watches your pantry, knows your budget, negotiates the delivery slot and pays — all without you opening an app. That future took a concrete step closer this fortnight, and the fingerprints on it belong to the biggest names in payments.
On 18 August 2026, the stablecoin infrastructure company Rain launched the Agentic Payments Alliance, a coalition built to answer a deceptively simple question: when an AI agent buys something on your behalf, how does the money move safely? Within days, the founding roster read like a payments hall of fame — Visa, Mastercard, Fiserv, Circle, Solana and Remitly.
Why the card giants are suddenly interested
For two years, “agentic commerce” has been a conference buzzword. It is now a competitive scramble, because the numbers are impossible to ignore.
By the numbers:
- McKinsey projects between US$3 trillion and US$5 trillion in global agentic AI commerce by 2030.
- Six founding members span card networks, core banking, stablecoins and cross-border remittance — a deliberately full-stack coalition.
- Visa CEO Ryan McInerney’s framing has hardened from “if” to “when”: “Agentic commerce is a when, not an if.”
When a market that size is forming, the incumbents cannot afford to let a startup define the standards. Visa and Mastercard did not join the alliance to be polite; they joined to make sure the rails of agentic commerce still run through them rather than around them.
The three problems nobody has solved yet
The alliance is refreshingly honest that agentic payments are not ready. It has named three gaps as its opening agenda, and each one is a genuine unsolved problem.
1. Identity: who is this agent, really?
Today’s payment system authenticates people — a PIN, a passkey, a face. An autonomous agent is neither the cardholder nor a fraudster; it is a delegated actor. The industry has no shared standard for proving “this agent is authorised to act for this customer, within these limits.” Without that, every agent transaction looks either like the customer or like fraud, and neither is true.
2. Fraud: how do you spot a bad agent?
Fraud models are trained on human behaviour — the hesitation, the geography, the odd hours. Agents behave differently by design: fast, tireless, pattern-driven. The tools that catch a stolen card at 3am may flag every legitimate agent as suspicious, or miss a compromised one entirely.
3. Loyalty and rewards: who earns the points?
If your agent books the flight, do you still earn the frequent-flyer miles? Does the agent’s operator? This sounds trivial next to fraud, but rewards economics underpin a huge share of card usage, and nobody has written the rulebook for a world where the buyer is software.
Scoped Cards and the “control layer”
Rain’s technical answer offers a preview of where this heads. Its Agent Control Layer and Scoped Cards give an agent credentials with hard boundaries baked in — spend up to this amount, at these merchants, for this purpose, and no further. Instead of handing an agent your card, you hand it a tightly fenced key. That “scoped delegation” model is emerging as the design pattern the whole industry is converging on, and it neatly sidesteps the identity problem by making the limits, not the identity, the thing that is verified.
It also explains why Circle and Solana are in the room. Stablecoins and programmable settlement rails let those spending rules be enforced in code at the moment of payment, rather than reconciled after the fact. Agentic commerce and stablecoins are turning out to be two halves of the same story — a theme Visa reinforced at its own Payments Forum with a run of AI, token and stablecoin announcements aimed squarely at programmable commerce.
What it means from an Australian merchant’s seat
This is a US-led coalition, but the implications land locally faster than most realise.
For merchants, the near-term question is checkout readiness. Agent-driven purchases will arrive through the same acquiring rails you already use, but they will carry different risk signals and different dispute patterns. The retailers who win early are the ones whose fraud settings and checkout APIs can tell an authorised agent from a scraper.
For issuers and fintechs, the identity and scoping standards being drafted now will become the ones Australian institutions have to interoperate with later. Being at the table — or at least reading the minutes — beats retrofitting in 2028.
It is worth being clear-eyed about the risks, too. Handing spending authority to software raises hard questions that a “scoped card” only partly answers. What happens when an agent misreads an instruction and buys the wrong thing at scale? Who is liable when a compromised agent drains a limit it was legitimately granted? How does a consumer even dispute a purchase they never consciously made? These are not reasons to dismiss the trend — the McKinsey numbers make dismissal a poor bet — but they are the reason the alliance exists. The founders would rather write the rulebook now than inherit a mess of incompatible, insecure implementations later.
And for everyone, there is a strategic tell worth noting: the card networks are treating agentic payments not as a threat to be resisted but as a rail to be captured. That posture — embrace and standardise — is exactly how Visa and Mastercard have absorbed every disruption of the past thirty years. Agents with wallets look like the next one.
This is the shift worth watching. If you know a merchant, product lead or issuer who still thinks “AI agents” is science fiction, send them this piece — the standards being written this year are the ones they’ll build on next. Share it forward.