
For PSPs, acquiring banks and large merchants, that is only half of the story. The other half is quieter and arrives sooner: AI agents working inside payment operations. They read transaction data, investigate declines, prepare reports and, within limits a person sets, make changes.
Here is what happened, and what it means for teams that run payment infrastructure.
Agents That Pay: Networks and Banks Build the Trust Layer
The consumer side moved quickly over two weeks:
- Mastercard expanded Agent Pay with trust and intelligence services (30 September). The first one is a probability score that shows how likely it is that an AI agent started a transaction. It is now rolling out for testing in the U.S. The goal is to give issuers enough context to approve legitimate agent-led purchases. Mastercard cites a projection that one in 10 consumers will routinely use agents to make purchases by 2030.
- Mastercard and Danske Bank completed Denmark's first AI agent payment (21 September). Mastercard also started an agentic commerce pilot for travel with Trip.com (17 September).
- Six banks published shared principles for trusted agentic commerce (22 September). The six are ING, NatWest, Bank of America, Capital One, Commonwealth Bank of Australia and ASB. The principles cover transparency, safety, privacy and data, choice and interoperability. The banks present them as a starting point for industry discussion, not a finished standard.
- GoCardless processed its first UK agentic account-to-account payment (22 September). Shopify extended WebMCP support to checkout for AI agents (29 September).
All of these deal with one problem. When an agent pays, the issuer and the merchant need to know that an agent is involved, what the consumer asked it to do, and whether the activity is legitimate. Mastercard's own example shows why this matters. An agent books a flight, a hotel and a transfer in a few minutes, across several merchants. Without context, that pattern looks like fraud.
Agents That Run Payments: The Operational Side
At the same time, payment companies started giving AI agents access to their own platforms:
- Mesta launched an MCP server for its payment network (30 September). Agents can find payment functions, get quotes, check payment status and submit payment instructions. Those instructions stay pending until a named person releases them. Later phases will add spending limits, approval rules and Know Your Agent checks.
- Several payment infrastructure providers made their API documentation readable by AI coding assistants through the Model Context Protocol (MCP). Developers can now ask questions about endpoints in their coding tools and get answers from the live specification.
- AI co-pilots for payment operations appeared in routing and fraud. They work the same way: the agent analyses data and recommends an action, and a specialist accepts, rejects or adjusts it.
These examples show different levels of delegation: agents can analyse data, recommend changes or submit payment instructions. Controls may require approval for each action or allow execution within limits authorised in advance.
What This Means for a PSP
Issuers will soon have signals that show whether an agent started a transaction. Their authorization decisions will change, and those changes will reach your merchants as approvals and declines. A burst of purchases from one cardholder across several merchants may be approved by one issuer and declined by another.
Early visibility helps a PSP investigate whether declines relate to issuer decisions, authentication, fraud screening or a processing connection. Routing changes may help with connection-specific problems, but changing acquirers does not override an issuer’s decision. Any retry must follow applicable decline-response guidance and scheme rules. Visibility into decline patterns and flexible routing were important before agents. They become more important as new types of traffic appear.
Payments teams already use AI assistants for reporting, investigation and integration work. The next step is obvious: point an agent at the payment platform itself. Nobody wants to export a CSV and paste it into a chat.
That raises a practical question for every PSP: what can an agent safely read, what can it change, and who decides? The examples point to structured access and defined permissions. A PSP must decide which actions require individual approval and which may run within pre-approved limits. A restricted token limits callable methods; it does not by itself create a human approval workflow.
Card networks and issuers own trust at the transaction level: is this agent legitimate, and is this purchase what the consumer intended? PSPs own trust at the infrastructure level: who and what can access payment data and operations, and with which permissions. Both layers are needed, and the second one is fully in the PSP's hands today.
How Payneteasy Approaches It: Two Paths for AI Agents
Payneteasy gives clients two separate ways to work with AI agents. Each one fits a different job.
Payneteasy MCP: the insight layer. The MCP server connects AI assistants to live payment data on Payneteasy. Payment teams ask in plain language and get answers and reports quickly. No dashboards, no API knowledge needed.
- Support teams check batch transactions and investigate logs.
- Analysts query transaction statistics and compare performance across merchants, processors and reporting periods.
- Executives get the analytics they need in their preferred format.
Payneteasy MCP helps teams investigate decline patterns, review routing outcomes and prepare reports from available operational data. It cannot authorise, capture, refund, move money or change platform settings, and it does not expose raw PAN or CVV. Clients control access through scoped, time-limited, revocable tokens and decide which AI assistants may receive the permitted data.
Payneteasy UI API: the action layer. For teams that build their own agents, the UI API is the full read-and-write interface behind the Payneteasy dashboard. That covers routing changes, adjustments, endpoint creation, reports and merchant onboarding. It is documented in OpenAPI 3.0.1, with more than 130 services and more than 1,500 operations.
Control stays with the client. An agent works with a restricted token limited to specific methods when it is issued. The token never has more rights than the user who issued it. A 40-minute morning report export becomes a scheduled task. Reconciliation and batch adjustments run through an agent your team defines and limits.
| Payneteasy MCP | Payneteasy UI API |
| Role | Insight layer | Action layer |
| Best for | Support, analysts, executives asking in plain language | Teams building their own agents |
| What agents do | Read live payment data, get answers and reports | Read and write: routing changes, adjustments, endpoint creation, reports, merchant onboarding |
| Control model | Scoped, time-limited, revocable token; no payment actions or configuration changes | Restricted token, limited to specific methods, never above the issuing user's rights |
Both paths sit on the same infrastructure: up to 10 million transactions per day with 99.95% verified uptime.
What to Watch Next
- Issuer-side agent signals. How quickly Mastercard's probability score and similar tools go beyond U.S. testing, and how issuers use them in authorization decisions.
- Industry principles turning into rules. Whether the six banks' framework turns into shared standards for agent identity, liability and dispute handling.
- Mandates and spending limits for agents. Mesta plans a mandate layer for Q4 2026. Expect more providers to define how agents get permissions, and how those permissions are limited and audited.
Agentic commerce will take time to reach scale. Agentic payment operations are already here. PSPs that decide now what their agents can see and do will be ready for both.
Want to see how Payneteasy MCP and the UI API fit your payment operations? Book a call with our team →
Sources
- Mastercard, “Mastercard advances agentic commerce with new trust and intelligence services”, 30 Sep 2026 — mastercard.com
- The Paypers, “Six global banks publish principles for trusted agentic commerce”, 22 Sep 2026
- The Paypers, “Mastercard and Danske Bank complete Denmark's first AI agent payment”, 21 Sep 2026
- The Paypers, “Mastercard, Trip.com pilot agentic commerce for travel”, 17 Sep 2026
- The Paypers, “GoCardless processes first UK agentic A2A payment”, 22 Sep 2026
- The Paypers, “Shopify extends WebMCP support to checkout for AI agents”, 29 Sep 2026
- The Paypers, “Mesta launches agentic payments infrastructure”, 30 Sep 2026
- The Paypers, “FinteqHub launches AI Advisor for payment routing”, 30 Sep 2026
- The Paypers, “Feedzai launches Farol agent to speed up fraud investigations”, 28 Sep 2026