AI Standards Push Can Borrow From the Payments Playbook

AI-standards-playbook-payments

Highlights

Anthropic, Google and OpenAI are discussing an industry body for AI testing and auditing.

Payments standards narrow broad questions of trust into technical requirements that can be tested.

AI developers still disagree over who should evaluate models and how often those evaluations should occur.

Anthropic, Google and OpenAI may agree that powerful artificial intelligence models need common safety standards. Getting to that commonality will mean they must also set standards governing who writes the tests, who administers them, and what a model must do to fail.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Payments knows that territory well, as shown by several years’ worth of initiatives.

    The standards infrastructure has been built over years. The FIDO Alliance and the World Wide Web Consortium’s FIDO2 and WebAuthn emerged in 2018 as common specifications for passwordless authentication, while EMVCo introduced its common Contactless Kernel Specification in 2022. The organizations are now extending that work to AI agents. FIDO began developing agentic authentication and payment specifications in April, and EMVCo released its draft Agentic Payments Framework in September.

    At a high level, EMVCo doesn’t certify that card payments are simply “safe.” It writes specifications for defined pieces of the payment system and establishes processes for determining whether implementations meet them.

    The FIDO Alliance has established standards for authentication and is now developing specifications for how users can securely delegate actions to AI agents.

    The experience offers a useful reference point as representatives from Anthropic, Google and OpenAI discuss establishing an industry standards body to audit and test AI, as PYMNTS reported Monday (Sept. 14). The companies have been meeting regularly since July. OpenAI CEO Sam Altman has supported an industry testing and auditing organization, while Anthropic CEO Dario Amodei has called for independent evaluation and greater coordination among AI developers.

    Payments Learned to Define the Test

    As for the lesson takeaways that AI might gather from the payments sector, consider what happens when a consumer taps a card or phone at a checkout terminal.

    The terminal and payment credential can come from different companies, yet the systems need a common method of communicating and processing the transaction. EMVCo specifications provide technical requirements for parts of that exchange.

    Within the contactless payments continuum of activity, a software component called a kernel enables a terminal or ATM to process a contactless transaction. EMVCo developed a common Contactless Kernel Specification after industry participants identified the complexity created by supporting multiple kernels.

    The specification covers defined technical functions, including a secure communications channel, elliptic curve cryptography for card authentication, support for biometric and mobile verification, and cloud operation. EMVCo also said it would introduce approval testing through accredited and audited laboratories and publish approved kernels, PYMNTS reported in 2022.

    That sequence is instructive for AI, which should define the requirement, specify how it works, and establish how an implementation is tested against it.

    An industry organization would need to identify individual capabilities it intends to evaluate and establish common methods for measuring them.

    Google DeepMind CEO Demis Hassabis has proposed testing frontier models for dangerous capabilities, cybersecurity risks and the ability to bypass safeguards before release, PYMNTS reported in July. Turning those categories into standards would require more detail. A cybersecurity evaluation, for example, needs rules governing the tasks a model receives, the tools and network access it has, the environment in which it operates, and the threshold that produces a failing result.

    FIDO Defines Who Gets to Act

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    FIDO provides another payments precedent that is already moving into AI.

    Its authentication standards use public-key cryptography to let services authenticate users without relying on reusable passwords. FIDO2 helped establish the technical foundation for passkeys across competing devices, operating systems, browsers and online services.

    AI agents introduce a related question. How does another participant establish that software has permission to act for a person?

    FIDO formed an Agentic Authentication Technical Working Group this year to develop specifications for users to delegate actions to AI agents with strong authentication. Its Payments Technical Working Group is developing specifications for agent-initiated commerce using Google’s Agent Payments Protocol and Mastercard’s Verifiable Intent as contributions to that work, PYMNTS reported in April.

    EMVCo is addressing the same emerging market from another part of the payment chain.

    Its draft Agentic Payments Framework proposes an Intent Services layer that could allow authorized payment participants to register, reference, retrieve and manage the instructions consumers give agents. Future work could include know your agent capabilities and agentic transaction indicators identifying an agent and signaling its participation in a transaction. The proposal remains under consultation and isn’t a requirement for payment participants, PYMNTS reported Sept. 2.

    The significance for broader AI standards is specificity. Payments organizations are taking questions such as whether an agent was authorized to act and breaking them into information that systems can exchange and verify.

    A cryptographic credential can establish that an agent possesses particular authority. A contactless implementation can be tested against technical requirements. Evaluating whether a model possesses a dangerous cyber capability involves judgments about the test, the environment and the level of performance considered dangerous.

    The AI companies don’t fully agree on how outside oversight should work. Anthropic backed Massachusetts legislation imposing AI safety requirements, while OpenAI opposed the AI provisions and urged lawmakers to consider an Illinois approach requiring annual third-party safety audits, PYMNTS reported Sept. 3. OpenAI also warned that differing state requirements could produce fragmented oversight.

    The differences will follow the companies into any industry organization they create. They will have to determine who selects evaluators, what access evaluators receive, which tests are common across developers, how results are disclosed and how quickly standards are revised when model capabilities change.

    FIDO and EMVCo cannot tell AI developers where to draw those lines, but they do illustrate how an industry gets from agreeing that a problem exists to producing a standard that other participants can actually use.

    For all PYMNTS AI coverage, subscribe to the daily AI newsletter.