CLM & CVM
Agentic Commerce goes into production: What autonomous payment agents mean for banks
Visa, BBVA, Lianlian, and ING report live AI agent payments. What Agentic Commerce means for the card business and customer relationships.
•
acceleraid Editorial Team
5 min read
01
Acquire
Recognize signals
02
Onboard
Control activation
03
Grow
Next Best Action
04
Retain
Reduce churn
05
Reactivate
Reclaim potential

For years, "Agentic Commerce" was a conference slide: AI agents buying and paying independently, at some point, under laboratory conditions. In the summer of 2026, that changed. Within a few weeks, several banks and payment networks reported real, productive transactions initiated by AI agents — with real card data, real merchant systems, and within existing regulation. For banks and financial service providers, the question is no longer whether autonomous payment agents are coming, but how the card business and customer relationship will change when software becomes the customer.
The Milestones of the Summer
The concentration of announcements is remarkable. In early June, Worldline and ING, together with Mastercard, announced the first end-to-end productive agentic payment in Europe — between an ING cardholder and a merchant in the Netherlands, using existing authentication and authorization mechanisms.
In early July, BBVA followed: The major Spanish bank, together with Visa, completed a transaction initiated by an AI agent on behalf of a cardholder — as part of the Visa Agentic Ready program and based on Visa Intelligent Commerce. Technically, the same building blocks that secure today's digital payments were used: tokenization and real-time fraud detection. For the strong customer authentication required in the EU, the transaction used Visa Payment Passkeys, a biometric process without passwords or SMS codes. The message: Agent-initiated payments work within existing European regulation — with the cardholder's full consent and control by the issuing bank.
At the end of July came the B2B proof: Visa and Lianlian DigiTech reported the first productive agentic B2B transaction in Greater China. The agent LoopXPay identified the purchasing need, recommended suitable suppliers, compared options, placed the order, and executed the payment — in a single workflow, within predefined spending limits and approval rules, backed by Visa's Agentic Directory for trusted agent interactions. In parallel, HSBC and Mastercard are piloting end-to-end agentic procurement and payment paths for business customers in Singapore.
Why Securing It is the Real Breakthrough
The technical point of these milestones lies not in the AI, but in the control architecture. All productive transactions share three properties.
First: They run on existing rails. Tokenized card data, real-time fraud detection, established authorization processes — no parallel system, but the existing network with a new access layer.
Second: Consent remains with the human. The cardholder defines what the agent is allowed to do; biometric methods such as Payment Passkeys ensure strong customer authentication; the issuing bank retains oversight over every transaction.
Third: Agents become identifiable. With directories like the Agentic Directory and concepts like "Know Your Agent", which providers like FIS are already translating into issuer solutions, a counterpart to the well-known "Know Your Customer" is emerging: Banks must be able to recognize which agent is acting on behalf of which customer — and whether they are authorized to do so.
Exactly this control architecture is the prerequisite for pilots to turn into volume. However, it is also the point where banks are now setting the course: those who treat agents only as a fraud risk will block them; those who treat them as a new, legitimate channel need rules, limits, and approval processes that give the customer control without making the agent useless.
What is Shifting in the Card Business
For issuers, agentic payment transactions initially change the authorization logic. A transaction initiated by an agent carries different signals than a human checkout: no device in the classical sense, no session, but a delegated mandate with scope and amount limits. Fraud models, limit systems, and dispute processes must learn to distinguish legitimate agents from abusive ones — and do so before significant volume builds up, not after.
Added to this is the strategic level: When agents compare offers and place orders, the competition shifts to the moment of the purchase decision. Visibility in checkout, card preference in the wallet, cashback programs — many of today's card loyalty tools target human attention. An agent decides differently: according to stored preferences, conditions, and rules. The card the agent draws is the card specified in the mandate.
The CLM Perspective: When the Agent Becomes the Customer
For Customer Lifecycle Management, this is the real turning point. Marketing, sales, and service are designed today to reach humans — with campaigns, offers, and messages. If a growing portion of interactions runs through agents, the target object of personalization changes: It is no longer just about addressing the customer at the right moment, but about being selectable for agents and knowing the preferences by which delegated decisions are made.
This enhances the basics that often take a back seat to campaign logic in day-to-day business: clean, up-to-date customer data, explicitly captured consents and preferences, consistent condition and product data that are available in a machine-readable format. An institution that has its customer data and decision logic under control can orchestrate agentic interactions as an additional channel — using the same rules for Next-Best-Action, risk assessment, and offer management that apply to human contacts.
From our perspective at Acceleraid, the same architectural rule applies here as everywhere in the AI stack: The models used to process such interactions should be interchangeable. Our assistant is model-agnostic — the underlying model can be changed at any time, while knowledge, contexts, and configurations are preserved. Especially in a field moving as fast as agentic payments, this is the insurance against wrong bets on individual providers.
What Banks Can Do Concretely Now
Four steps can be derived from the summer milestones. First: test your own card and payment processes for agent suitability — from the token strategy to authentication, limits, and mandates. Second: expand fraud and authorization models to include agent signals before volume builds up. Third: build the data and consent foundation so that preferences and permissions are machine-readable and up-to-date. Fourth: gain experience early with controlled pilots instead of waiting for finished standards — the networks' programs are built exactly for this.
In 2026, Agentic Commerce transitioned from a future topic to an operational topic. The institutions that think of customer relationships, data foundations, and control architectures together now will help decide what role they play in agentic payments: that of the infrastructure provider in the background — or that of the orchestrator of the customer relationship.
Illustration: AI-generated. AI-supported content: We use AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers, to create our articles. Topics, professional direction, and final approval remain with our team.
Further Insights
We use cookies 🍪
Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent, we also use Google Analytics (analytics) and Leadfeeder (visitor identification). Learn more in our Privacy Policy.