Your AI shopping assistant no longer needs you to tap “confirm.” Mastercard and startup Alchemy have integrated Alchemy’s AgentCard product with Mastercard Agent Pay to issue virtual, tokenized, one-time-use card credentials directly to AI agents linked to a user’s existing account.
Agents can now autonomously order food, book travel, and manage subscriptions at any online merchant that accepts Mastercard, within user-defined limits and without step-by-step human approval.
How AgentCard Actually Works
A single developer command gives an AI agent a complete financial identity, including a capped, expiring Mastercard credential.
Via one command-line interface call, an AI agent receives an email address, phone number, stablecoin wallet, and a one-time-use Mastercard credential tied to the user’s existing card. Default credentials are capped to a specific amount and valid for seven days, enabling purchases with no approval step inside those limits.
An experimental “connected” mode lets agents draw from an enrolled Visa or Mastercard via network tokenization, but each purchase requires a passkey approval and is locked to a specific merchant and amount. User-defined parameters govern everything: price range, approved merchants, and whether the agent must request confirmation before finalizing a transaction.
That shift required Mastercard to rethink infrastructure it originally built to do the opposite. Greg Ulrich, Mastercard’s chief AI and data officer, put the paradox plainly at a conference earlier this year, as reported by Gizmodo: “We’ve built a bunch of risk rules over time that were intended to stop a bot from transacting. Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules.”
The Industry Is Building Rules for Agents It Can Trust
Visa, Mastercard, and Ant International are converging on a shared “Know Your Agent” standard before agent commerce scales.
On September 10, 2026, Ant International, Mastercard, and Visa announced the Know Your Agent interoperability framework. It builds on Visa’s Trusted Agent Protocol, Mastercard’s Verifiable Intent, and Ant International’s Agentic Mobile Protocol.
The goal is to let payment networks, digital wallets, and marketplaces reliably identify certified AI agents across ecosystems. The function is roughly equivalent to how KYC works for human account holders.
Three pillars support the framework: cross-network operator traceability that ties each agent to a validated human or organization; shared certification requirements measuring agents against common security and behavioral standards; and continuous transaction monitoring with the ability to revoke certification if behavior shifts.
Alchemy described the commercial logic plainly in a post on X, as reported by Gizmodo: “The checkout button is dying. AI agents will discover, compare, and buy products on behalf of their users.”
A Convenience Architecture With an Unresolved Safety Question
Safety researchers warn that financial access is precisely the resource rogue agents would need, and the barriers are getting lower.
AI-safety organizations METR and the AI Security Institute have flagged scenarios in which self-replicating rogue agents exploit financial infrastructure, and both specifically identify money access as a critical resource such agents would need to scale attacks. Critics have framed the stakes in starker terms. Former Anthropic employee Jacob Coxon is quoted by Gizmodo as saying: “The people building AI earnestly believe that it could kill us all by the end of the decade.”
Notably, the AI Security Institute finds that current models still fail KYC-style evaluations, meaning they cannot yet access traditional financial systems without human intermediaries. The central question this infrastructure raises is not whether today’s controls work. It is what happens to the barriers currently keeping illegitimate agents out, as networks actively reduce friction for legitimate ones.
What Comes Next
The controls being designed now will determine whether these rails stay safe as AI models grow more capable.
Near-term, consumer-facing agent apps are likely to proliferate, with early friction centered on misconfigured spending limits and purchases users contest as outside their intent. Over a longer horizon, KYA could become a regulatory reference point as policymakers assess whether agent certification satisfies existing anti-money-laundering and KYC obligations.
The design choices embedded in today’s rollout will prove consequential well beyond the current crop of shopping assistants. Those choices include revocation mechanisms, behavioral audits, and hard identity linkage to real humans or organizations.




























