Thredd’s McCarthy Says Payments Will Govern the Agentic Enterprise

PYMNTS eBook, Thredd

The agentic enterprise won’t be defined by how much autonomy it hands to AI, but by how well it governs that autonomy, Thredd CEO Jim McCarthy writes in a new PYMNTS eBook, “Building the Agent-Ready Payments Enterprise.”

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The interesting question about the agentic enterprise is not whether agents can act. They clearly can. It’s whether enterprises can scale that action safely — and the evidence so far is that autonomy is harder to scale than the demos suggest. The bottleneck is not intelligence. It’s permission, control and proof.

    Businesses are putting policies and governance in place to safely scale generative AI across their enterprise. At Thredd, green shoots of innovation are sprouting daily, leveraging agentic capabilities for fraud, credit, sales, billing automation and client servicing. But we see the challenge, and equally the opportunity, for agentic experiences more acutely on the payment side, where an agent recommending a purchase, not all that interesting, becomes useful when it’s trusted to initiate and complete a payment. At that moment the question stops being “can the agent pay?” and becomes “what is this agent permitted to do, on whose authority, under what limits, and how is that permission proven, monitored and revoked in the milliseconds an authorization takes?”

    That’s a payments problem before it’s an AI problem, and payments has a head start most people underestimate. At every technology inflection point during my career — eCommerce, mobile commerce, the launch of Apple Pay, cryptocurrency — someone predicted the end of cards, and yet each time the trust infrastructure proved far harder to replicate than the rails were to reinvent. Tokenization, scheme rules, dispute and chargeback rights, issuers that underwrite risk and bind consumers to credentials — these aren’t legacy baggage. They’re the exact controls agentic commerce needs, and they already exist.

    But raw materials aren’t readiness, and this is where the conversation gets too casual. A network token already carries merchant and category restrictions and can be revoked providing a real head start, not an answer on its own. The new work is binding a verifiable mandate to that credential which is essentially a cryptographic proof of what the consumer authorized their agent to do, and then surfacing, at authorization, a signal that an agent rather than a human initiated the transaction, so the issuer can decide in real time rather than discover it after the fact. Visa and Mastercard are standardizing this through Intelligent Commerce and Agent Pay respectively; we monitor and, in some cases, build those frameworks while staying deliberately neutral on the merchant-side protocols, so our clients, issuers and program managers, are insulated from bets that haven’t been resolved.

    It’s also why a connection standard, on its own, doesn’t solve this. Protocols like MCP matter because they standardize how agents plug into systems. They don’t answer who authorized this agent, what the consumer actually intended, whether the behavior is anomalous or who is liable when it’s disputed. Those are issuer-layer questions, and they don’t get easier by stacking another protocol on top of them.

    Liability is the one the industry hasn’t fully answered, and the one I’d tell any enterprise to watch. Fraud detection is being retuned for a new class of automated behavior. The old question was, “is this the genuine customer?” The emerging one is, “is this still what the customer authorized the agent to do?” That’s necessary but not sufficient. The harder case is the agent that behaves exactly as mandated and the cardholder disputes anyway. Today’s chargeback rules were never written for a third party acting on standing instructions. My view is that verifiable intent, proven at authorization, must become the basis for reallocating that liability — and the issuers who can prove intent will be the ones who can actually underwrite agentic commerce, not merely permit it.

    For a card issuer, the point of sale is the tip of the agentic iceberg. Strip away the consumer experience and the work of card issuing is repetitive, rules-based, operational work. Things like reconciling settlement files, onboarding and screening customers, assembling dispute evidence, servicing cardholders and producing regulatory reports represent high-headcount work that has scaled almost linearly with volume. That’s exactly the shape of tasks agents are good at, and where costs can actually be stripped out of businesses: an agent that reconciles a file and escalates only the genuine inconsistencies, or triages an onboarding case, breaks the link between growth and headcount that has constrained this industry for years. Programmable payments extend the same logic to money movement itself where value that moves on conditions and rules set in line with the transaction rather than preset instructions configured at the program level, with an agent orchestrating inside guardrails set by the customer.

    An agent reconciling a ledger, or releasing a payment on a rule, needs exactly what an agent at checkout needs: defined permission, proof of what it was authorized to do, an audit trail and the ability to revoke it the moment something looks wrong. Solve that governance problem once and you apply it across the operation; that’s the compounding advantage, and why the trust layer is worth owning. It’s also where discipline matters most, because the back office is where autonomy is easiest to justify and hardest to trust. A silent reconciliation error doesn’t announce itself, it compounds. Those who capture these savings will be the ones who put escalation thresholds, manual review thresholds and provable authority in place first — taking cost out rather than trading labor cost for risk.

    The agentic enterprise won’t be defined by how much autonomy it hands to AI, but by how well it governs that autonomy where liability shifts and value is created. The winners won’t just have smarter agents. They’ll have agent-ready infrastructure beneath them, verifiable intent underwriting it, and partners willing to absorb that complexity so they can move quickly.