AI Agents Are About to Start Paying for Things on Their Own — India Is Going First

Rohit Baniwal, writer

By TechSun News Desk | September 1, 2026 | Tech / AI / Trending | ~9 min read

You tell your AI assistant to reorder your usual groceries, renew a subscription, or pay a small bill. Instead of stopping to ask you to open an app, pick a product, and approve the charge, it reads the instructions you set earlier, chooses the option that fits, and pays — quietly, in the background.

That may sound futuristic, but the technology needed to make it happen is already being built. Over the past year, some of the biggest names in tech and payments have quietly laid the groundwork for a world where software, not people, taps “buy.” And now one country is preparing to take that idea further than anyone else has at a national level: India.

Here’s what’s actually happening, what’s real today versus still on the drawing board, and — the part that matters most — what could go wrong when the thing spending your money isn’t you.

What “agentic payments” actually means

The industry term for this is agentic payments: transactions carried out by an AI agent acting on your behalf, rather than by you clicking through a checkout yourself.

It helps to separate two very different levels of autonomy.

The first is assisted checkout, where the agent does the legwork — finding the product, filling the cart, lining up the payment — but you still confirm the final purchase. That’s largely what exists today.

The second is conditional autonomous payment, where you set rules once (“spend up to this much on groceries each week,” “renew this service if it costs under X”) and the agent transacts within those limits without asking you every single time. That’s the leap that changes everything — and it’s the one India is now preparing to enable.

The distinction sounds small. It isn’t. It’s the difference between a tool that saves you a few taps and a system that moves your money while you’re asleep. If you’re new to how these systems operate, our explainer on AI assistants that act without asking is a useful starting point.

The global shift: what OpenAI, Google, and Visa are building

This isn’t an India-only story, and it isn’t hypothetical. Several major players spent 2025 and early 2026 building the plumbing for agent-led commerce — though it’s worth being precise about what each one actually does.

OpenAI launched Instant Checkout inside ChatGPT, powered by its open-source Agentic Commerce Protocol, co-developed with Stripe. Crucially, in its current form, this is not unrestricted autonomous spending. OpenAI is explicit that users stay in control and confirm each step before any purchase goes through, that payment tokens are encrypted and authorized only for a specific amount and a specific merchant, and that the merchant — not OpenAI — handles the actual payment and remains the merchant of record. Today it supports single-item purchases for U.S. users, with multi-item carts and more regions still to come. In other words: the agent shops, but you still tap “buy.”

Google introduced the Agent Payments Protocol (AP2), an open standard built with more than sixty payments and tech partners. AP2’s whole purpose is authorization and accountability. It uses cryptographically signed “mandates” — think of them as tamper-proof digital permission slips — to create a verifiable record of what you intended, what the agent selected, and what was actually charged. It’s designed to answer the question that agentic payments raise most sharply: did the user really authorize this?

Visa took a related but distinct angle with its Trusted Agent Protocol. Rather than moving money or capturing consent, it focuses on verifying that an AI agent is who it claims to be and is genuinely authorized to act for a cardholder — giving merchants a way to tell a legitimate, trusted agent apart from a bot or a hijacked credential.

Read together, the pattern is clear. The industry has spent the last year building the rails, permissions, and identity checks for agent payments — the guardrails — well before handing agents the keys to spend freely.

Now India steps in

India UPI QR scanner
Against that backdrop, a genuinely new development landed today.

According to a Reuters report (Mumbai, September 1, 2026), India is preparing a framework that would let AI agents make small digital payments through UPI — the Unified Payments Interface — without requiring the user to approve every individual transaction. Three sources familiar with the matter described the plan, which is expected to be unveiled next week at the Global Fintech Fest in Mumbai.

A careful word on timing: as of today, this is a framework being prepared and previewed, not a product that has launched. Nothing is live yet.

But the scale is what makes it striking. UPI, operated by the National Payments Corporation of India (NPCI), is the world’s largest retail fast-payment system by transaction volume, processing tens of billions of transactions worth hundreds of billions of dollars in a single month. A national rollout of agentic payments on that infrastructure would put India among the very first countries with agentic AI payments built into its core payment network — not bolted on by a single company, but wired into the rails the whole country already uses.

Reporting suggests the framework — referred to as a Unified Agent Protocol — would lean on two mechanisms UPI already has: UPI Circle, which lets a primary account holder delegate payment authority to a secondary party (in this case, an AI agent), and Reserve Pay, which lets a customer block a pool of funds for multiple debits. Low-value, frequent purchases like groceries are expected to be among the first use cases, with more sophisticated ones — such as an agent acting on sale offers or price thresholds — envisioned later.

The real question: what happens when the AI gets it wrong?

Convenience is the easy part of this story. The hard part is everything that happens when an autonomous system spends money and something doesn’t go to plan. Consider the failure modes:Smartphone payment security risk

  • The agent buys the wrong product or the wrong quantity because it misread your instruction.
  • It pays the wrong merchant — a lookalike, a stale link, a spoofed listing.
  • A malicious website manipulates the agent, feeding it hidden instructions to trigger a purchase you never wanted.
  • An attacker gains access to the agent’s delegated payment authority and drains the funds you set aside.
  • A subscription renews that you thought you’d cancelled, because the agent was operating on old rules.
  • The agent simply spends more than you expected within limits you set too loosely.

An AI agent that can read your email is one thing. An AI agent that can also initiate a financial transaction is a much bigger security problem — the blast radius is no longer your inbox, it’s your bank balance. We’ve covered how AI agents can be hacked or turned against you, and a real-world case where an AI agent broke into a gym booking system shows this isn’t just theory.

Who’s responsible for a payment you didn’t personally approve?

This is the question that turns a convenience feature into a genuinely hard problem, and it’s why protocols like Google’s AP2 obsess over signed, auditable authorization.

If an agent makes a payment you didn’t individually click “yes” on, and it turns out to be wrong or fraudulent, who bears the loss? You, because you set the rules? The company that built the agent? The bank or the payment network? The merchant who accepted it?

Today’s consumer-protection frameworks were written around a human pressing “pay.” Agentic payments quietly remove that human from the loop — which is exactly why the serious efforts in this space are being built around consent records, spending limits, identity verification, and audit trails rather than raw autonomy. The safeguards aren’t a nice-to-have. They’re the whole point.

Will AI agents replace payment apps?

Probably not right away — and probably not the way headlines imply. What’s emerging looks less like a replacement for UPI, cards, or your banking app, and more like a new layer sitting on top of the payment infrastructure you already use. The rails stay the same; the thing initiating the payment changes. The same questions we asked about whether tap-to-pay is safe apply here too — just with a lot more autonomy in the mix.

What you should watch for as a consumer

You don’t need to opt into any of this yet. But when agentic payments do reach you, a few habits will matter:

  1. Set hard spending limits — and set them lower than you think you need.
  2. Don’t hand over blanket payment authority. Scope each agent to a specific, narrow task.
  3. Keep a transaction history you actually review. Audit trails only help if someone reads them.
  4. Use separate permissions for separate jobs, so one compromised agent can’t touch everything.
  5. Turn autonomous payments off when you’re not using them. Standing authority you’ve forgotten about is the most dangerous kind.

The bottom line

UPI made digital payments almost effortless. Agentic payments could make them almost invisible — money moving on your behalf without a tap, a PIN, or a second thought.

That’s genuinely convenient. But invisible payments also create a new kind of risk and a new accountability gap, and the countries and companies moving first will effectively be writing the rulebook the rest of us inherit. India preparing to do this at national scale is the clearest signal yet that the shift from AI that answers to AI that acts — and pays — has moved from concept to countdown.

We’ll be following the Unified Agent Protocol announcement at the Global Fintech Fest and will report on the specifics as they’re confirmed.

 

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.