A valid card credential may tell an issuer that an artificial intelligence agent can pay. It does not necessarily tell the issuer whether the AI agent should make this particular purchase.
That distinction sits at the center of a new effort to build common technical standards for agentic commerce. EMVCo on Tuesday (Sept. 1) released a draft framework designed to help issuers, merchants and other payment participants determine whether an AI agent is acting within authority granted by a consumer.
The public comment period for the framework runs through Sept. 30.
The card system already has tools for authenticating consumers, protecting credentials and authorizing individual transactions. Agentic commerce adds another test. Payment participants may need to determine whether a purchase fits the consumer’s instructions, particularly when those instructions cover multiple transactions or remain active over time.
Consider a consumer who authorizes an AI agent to spend up to $300 a month on groceries. The first $70 purchase may comply with that mandate. The next two may also qualify. A fourth purchase could push spending beyond the monthly limit even though the payment credential remains valid and the merchant has done nothing wrong.
EMVCo’s proposed answer is a shared layer called “Intent Services.” According to the draft Agentic Payments Framework for Specifications, these services would let authorized payment participants register, reference, retrieve and manage consumer intent before, during and after a transaction.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
The framework focuses on cases in which intent must persist across multiple interactions, including recurring purchases, cumulative spending limits and post-transaction activities. The shared service could maintain information about the mandate’s status and lifecycle, giving different participants a common reference point as transactions unfold.
That approach adds a layer that conventional payment authorization was not designed to provide. Authentication can confirm a credential. Agent identification can help establish which AI system initiated a payment. Intent data could show what the consumer allowed that agent to do and whether that permission remained active.
The distinction could become particularly important for disputes and chargebacks. Today, a dispute often turns on whether a cardholder authorized a transaction. An agentic commerce dispute may require a more detailed record showing what the consumer told the agent, the duration of that authority and whether the purchase remained within its limits.
Intent, in other words, could become part of the transaction record.
EMVCo also said later work may include Know Your Agent capabilities and Agentic Transaction Indicators. Those tools could identify the artificial intelligence agent involved, communicate relevant information about it and alert payment participants that an AI system acted for the consumer.
The framework could also inform future changes to EMV technologies covering 3-D Secure, payment tokenization, secure remote commerce and digital payment credentials.
This remains a technical consultation, rather than a law or regulatory requirement. No participant is yet required to adopt Intent Services. Still, EMVCo’s specifications support core parts of global card infrastructure, giving its direction strategic weight.
For issuers, acquirers and merchants, the emerging architecture suggests that no single control will carry agentic payments. The eventual system may need to combine credential authentication, agent identity, persistent intent and transaction authorization. The payment credential can establish that an agent is able to pay. A persistent intent layer could establish whether it stayed within the consumer’s instructions.