For more than a decade, the central question in digital payments has been how to make transactions faster, cheaper and easier for people. India may now be approaching a fundamentally different question: what happens when the person making the payment is no longer a person?
An artificial intelligence agent could soon be authorised to order groceries when supplies run low, renew subscriptions, book a cheaper flight when fares fall below a specified level or pay recurring household bills—without asking its human principal to approve every transaction. The consumer would establish the mandate; the AI would interpret the circumstances and act.
That possibility is moving rapidly from concept to payments architecture. The National Payments Corporation of India (NPCI) is working on a framework for agentic payments on the Unified Payments Interface (UPI), reportedly through a Unified Agent Protocol that could allow AI agents to execute low-value transactions under pre-authorised rules.
The framework is expected to combine existing mechanisms such as UPI Circle, which supports delegated payments, and fund-blocking capabilities to create controlled spending authority for AI agents.
The technological challenge is considerable. The governance challenge is bigger.
The fundamental issue is not whether an AI system can technically initiate a UPI transaction. It is whether India can create a legally and technologically credible chain connecting human consent, machine action, bank authentication, merchant acceptance and eventual liability.
This is particularly significant because of UPI’s scale. In August 2026 alone, the platform processed 24.51 billion transactions worth ₹29.82 trillion. Putting autonomous software on top of infrastructure operating at this scale could make India one of the world’s most important laboratories for agentic commerce.
From delegated payment to delegated judgement
India already possesses part of the architecture required for this transition.
The Reserve Bank of India announced delegated payments on UPI in 2024, enabling a primary user to establish transaction limits for another user operating on the primary user’s bank account. NPCI subsequently expanded UPI Circle to certain IoT devices and software profiles, including AI profiles under a controlled framework.
Under NPCI’s October 2025 rules, approved IoT devices and software can operate under full delegation, subject to safeguards including a ₹15,000 monthly limit and ₹5,000 transaction ceiling. Transactions are restricted to domestic person-to-merchant payments and Online Dispute Resolution must be available. Significantly, however, NPCI specified that debit transactions initiated through IoT must follow “explicit user action.”
Agentic payments cross that boundary.
A conventional delegated payment answers the question: Who else may pay from my account? Agentic commerce asks something much more complicated: Under what conditions may software decide that a payment should be made? That distinction requires a different conception of consent.
A consumer could instruct an agent: buy my usual groceries every week, but spend no more than ₹4,000; renew my broadband plan unless its price rises by more than 10%; book a Delhi–Mumbai flight if the fare falls below ₹6,000.
The AI is not merely transmitting an instruction. It is interpreting one. Therefore, the regulatory system must establish what may be called a consent envelope—merchant categories, individual transaction limits, cumulative limits, duration, permitted purposes and circumstances requiring fresh human authentication.
The narrower and more machine-readable that envelope is, the safer agentic payments become.
Authentication cannot disappear
The second challenge concerns authentication.
RBI’s digital-payment architecture has historically emphasised multi-factor authentication, with regulated entities expected to assess authentication according to transaction value, customer profile, behavioural characteristics and risk.
Autonomous payments cannot simply eliminate authentication. Instead, authentication has to move from every individual transaction towards authentication of the authority delegated to the agent.
In other words, the consumer authenticates the mandate; the AI subsequently operates within it.
This makes revocation crucial. Consumers should be able to instantly suspend an agent, reduce its limit or cancel its mandate across the payment ecosystem. Every transaction should also leave an auditable record showing which agent initiated it, under which mandate, for which merchant and against which user instruction.
The emerging NPCI framework is reportedly considering precisely such rule-based instructions, spending limits, identity checks and audit trails.
When the AI gets it wrong, who pays?
Liability will probably prove the hardest regulatory problem.
Suppose a consumer asks an AI agent to purchase a refundable airline ticket below ₹8,000. The agent purchases a non-refundable ticket because it misinterprets the instruction. Who bears the loss—the customer, AI provider, bank, merchant, payment application or NPCI?
The existing customer-protection framework was designed largely around authorised versus unauthorised transactions. RBI rules provide zero liability in certain bank-fault and third-party-breach situations and place the burden of proving customer liability on the bank.
Agentic payments introduce a third category: authorised delegation followed by potentially unauthorised machine behaviour.
That category cannot comfortably be handled by traditional fraud rules.
India may therefore need liability to follow control. A bank should remain responsible for failures in authentication or account controls; payment service providers for failures in transaction execution; merchants for misrepresentation or fulfilment problems; and AI providers for transactions caused by agents operating outside authenticated consumer instructions.
Most importantly, consumers should not have to determine which participant’s algorithm or API failed before receiving redress.
AI is already entering the payments stack
The transition has already begun.
NPCI announced in February its Finance Model for India, or FiMI, a domain-specific AI model designed for India’s payments ecosystem. It already powers the UPI Help Assistant, using an agentic AI framework for payment queries, grievance handling and mandate management. NPCI said the system was designed around environments where “accuracy, consistency, and trust are critical.”
Private-sector experimentation is moving even faster. Pine Labs announced its P3P agentic payment protocol in June, designed to allow an AI agent to complete a UPI payment after prior authorisation. Mastercard has also demonstrated authenticated agentic commerce transactions in India.
“India is entering a defining phase in its AI journey—one where intelligent, in-flow commerce becomes the norm,” Gautam Aggarwal, President, India and South Asia at Mastercard, said while announcing its initiative.
The regulatory environment is simultaneously evolving. RBI’s Framework for Responsible and Ethical Enablement of Artificial Intelligence, or FREE-AI, reflects recognition that AI adoption in finance brings not only efficiency but risks involving privacy, explainability and accountability.
Agentic payments could become one of the first major tests of those principles.
UPI’s next leap will be institutional, not merely technological
India’s advantage is that it does not have to construct agentic payments from scratch. UPI already provides interoperable payment rails; delegated payments provide a mechanism for transferring limited authority; mandates establish recurring consent; and NPCI’s dispute-resolution infrastructure provides a foundation for redress.
What is missing is a governance layer capable of converting human intent into bounded machine authority.
The safest architecture would therefore treat AI agents not as independent financial actors but as revocable digital delegates. They should possess identifiable credentials, narrowly defined mandates, transaction ceilings, expiry periods and immutable audit trails. High-risk transactions should automatically return to the human for authentication.
That approach would preserve the principal advantage of agentic commerce — automation — without creating unlimited machine access to bank accounts.
The deeper significance extends beyond payments. If India develops an interoperable standard through which humans can safely delegate economic authority to machines, UPI could evolve from digital payment infrastructure into infrastructure for machine-mediated commerce.
But the success of that transition will ultimately depend on something decidedly human: trust.
UPI became ubiquitous because consumers understood one essential principle — they authorised the payment. Agentic UPI will succeed only if the next principle is equally clear: the AI may spend, but the human remains in control.


