EMVCo Wants to Build the 'Intent Layer' for AI Agent Payments: What the Draft Framework Means for Fintechs, Issuers and Merchants
- 3 days ago
- 6 min read
TL;DR: EMVCo’s draft EMV Agentic Payments – Framework for Specifications, released on 1 September 2026, proposes “Intent Services”: a shared layer for registering, retrieving and managing consumer-authorised intent before, during and after a card transaction. The goal is to solve a central problem in AI agent payments: a valid card credential proves an agent can pay, but not whether it should make a particular purchase. The draft focuses on recurring purchases, cumulative budgets, returns, disputes and top-ups. It is not yet a technical specification. Payments businesses should review it, submit feedback before 30 September 2026, and begin treating intent data as part of the transaction record.
What is EMVCo proposing? A shared intent layer for agentic payments
EMVCo is proposing a common, interoperable coordination layer that allows authorised payment participants to register, reference, retrieve and manage consumer intent.
This layer is called Intent Services.
The important point is that EMVCo is not simply designing a faster way for an AI agent to submit a payment. It is addressing the more difficult question of how a payment ecosystem can understand the authority behind that payment.
In a traditional card transaction, an issuer can check whether a credential is valid, whether authentication requirements have been met and whether the transaction appears risky. In an agentic transaction, those checks are not enough.
A valid card token may prove that an AI agent has access to a payment credential. It does not prove that the agent was authorised to:
Buy this product
Spend this amount
Use this merchant
Continue making purchases
Exceed a cumulative budget
Initiate a return, dispute or top-up
EMVCo’s draft attempts to create a framework for carrying that authorisation through the transaction lifecycle.

Why does AI agent payment intent matter? Because payment permission is not the same as payment authority
Consider a consumer who authorises an AI agent to spend $300 per month on groceries.
The agent makes three purchases:
$110 from one supermarket
$95 from another merchant
$130 from a third merchant
The card credential remains valid. The token may be correctly provisioned. The transactions may pass standard fraud checks. But the third purchase exceeds the consumer’s cumulative mandate.
This is the gap EMVCo is targeting.
Agentic commerce requires payment participants to distinguish between:
Credential validity: can the agent access the funding source?
Transaction authorisation: was this individual payment approved?
Delegated intent: was the agent acting within the consumer’s broader instructions?
That third layer becomes essential when purchases are recurring, budget-based or dependent on previous transactions.
It also matters after payment. A return, dispute or top-up may depend on the original mandate, the agent’s authority and the state of the consumer’s instructions at the time.
How would Intent Services work? They would preserve intent across the payment lifecycle
The draft describes Intent Services as a shared source of reference for authorised participants. It is designed to support intent before, during and after a transaction.
In practical terms, that could mean:
An intent is created when a consumer delegates authority to an agent.
The intent receives a reference that can be used by relevant participants.
The agent uses that reference when initiating a payment.
The issuer, acquirer, merchant or other authorised party retrieves the relevant intent data.
The intent state is updated as purchases are made, budgets change or authority expires.
The record remains available for post-transaction activities such as returns and disputes.
This is different from storing a simple “yes” or “no” approval. Intent is likely to require context, including limits, categories, timeframes, recurring rules, permitted merchants and the status of prior transactions.
The draft does not provide the final technical schemas or implementation rules. That is why it should be read as a foundation for future specifications, not as a production standard that businesses can implement immediately.
Is EMVCo trying to replace existing agentic payment protocols? No : it is positioning cards as the default rails
The strategic significance is broader than the terminology.
Mastercard Agent Pay, Visa’s Trusted Agent Protocol, Google’s AP2 and Stripe’s Agentic Commerce Protocol are already shaping the market. These initiatives address different parts of the agentic commerce stack, including agent identity, mandates, tokenisation, checkout and payment execution.
EMVCo’s intervention is an attempt to ensure that card payments remain the path of least resistance as agentic commerce develops.
The card networks already have:
Global acceptance
Established tokenisation infrastructure
Issuer and acquirer relationships
Dispute and chargeback processes
Authentication frameworks
Merchant and wallet integrations
By developing an interoperable intent framework, EMVCo is extending those existing advantages into a world where the buyer may be an AI agent rather than a person actively clicking “buy”.
This is not simply an innovation exercise. It is also an incumbency strategy.
Accenture estimates that more than 30% of online commerce could be handled through AI agents by 2030, representing close to US$3.1 trillion in transactions. At that scale, the provider that controls the evidence of authorisation will have significant influence over risk, liability and payment routing.

Will the framework solve chargebacks and liability? It could provide the evidence, but rules still need to be written
The most important unresolved issue in agentic commerce is not whether an agent can pay. It is who is responsible when the agent pays incorrectly.
A merchant may have delivered exactly what the agent ordered. The consumer may still claim that the agent exceeded its instructions. An issuer may see a valid token and a successful authentication event. An agent platform may argue that it acted on incomplete or ambiguous information.
Intent data could become the evidentiary substrate for resolving these disputes.
A future dispute record may need to show:
What the consumer authorised
When the authorisation was created
Which agent received the authority
What spending limits applied
Whether the intent had expired or been cancelled
Which transaction consumed part of a cumulative budget
Whether the agent altered or exceeded the mandate
What data the merchant and issuer received
This could support new liability models and dispute categories, such as “agent exceeded mandate” or “unauthorised agent activity”.
However, Intent Services alone will not decide liability. EMVCo, networks, issuers, acquirers and regulators will still need to define how evidence is interpreted and which participant carries the loss.
What are KYA and Agentic Transaction Indicators? They could make the agent visible to issuers
The draft also flags potential future work on Know Your Agent, or KYA, and Agentic Transaction Indicators.
KYA could help answer:
Who operates the agent?
Which business or consumer is responsible for it?
What permissions has it been given?
Is its identity verified?
Has it been compromised or revoked?
Agentic Transaction Indicators could signal to issuers and other participants that a transaction involved an agent acting on behalf of a consumer.
That distinction matters for fraud monitoring, authentication, customer service and dispute handling. It may also allow issuers to develop different risk controls for transactions initiated by trusted, registered agents.
The proposed direction aligns with EMVCo’s planned work across EMV 3-D Secure, EMV Payment Tokenisation, EMV Secure Remote Commerce and the EMV Digital Payment Credential. Collaboration with the FIDO Alliance, OpenID Foundation, OpenWallet Foundation and W3C also shows that agentic payments will require cooperation beyond the card networks.
What should fintechs and payment companies do now? Treat intent as a core payment data object
The framework is still a draft, but businesses should not wait for a final specification before preparing.
1. Read the draft and submit feedback
EMVCo has opened the framework for public feedback until 30 September 2026. Fintechs, issuers, payfacs, ISOs, merchants, POS providers and payment technology companies should assess whether the proposed roles, data fields and access controls reflect real operating conditions.
2. Map intent through your existing transaction flow
Document where your systems would capture:
Consumer consent
Agent identity
Delegated permissions
Budgets and velocity limits
Recurring instructions
Cancellation and expiry
Returns and disputes
If these records do not exist today, that is a strategic gap.
3. Plan tokenisation and 3DS readiness
Review how your tokenisation, authentication and digital credential infrastructure could carry agent-related data. Do not assume that a card token alone will be sufficient evidence of authority.
4. Design for evidence, not just approval
Intent records should be tamper-resistant, timestamped, retrievable and linked to the transaction. Treat them as part of the transaction record, not as temporary application data.
5. Decide where you want to compete
The emerging agentic payments stack will create opportunities in agent identity, payment orchestration, machine wallets, risk controls, tokenisation, reconciliation and dispute management.
As we discuss in our earlier analysis of the machine-wallet opportunity, the strategic value may sit less with the agent interface and more with the control layer that determines how money can be spent.
RivaTech’s view
EMVCo’s draft is important because it moves the industry discussion beyond the headline demo of an AI agent buying a product.
The real challenge is persistent authority: whether an agent can continue acting within a consumer’s instructions across multiple payments, changing circumstances and post-transaction events.
Intent Services could become the connective tissue between consumer delegation, payment credentials, risk decisions and dispute evidence. But the commercial and liability rules remain unfinished.
For payments businesses, the immediate priority is not to predict the final EMV specification. It is to understand where intent already exists in your business, where it is missing and which systems will need to consume it.
Explore RivaTech Consulting’s payment industry consulting services, or contact us to discuss your agentic payments strategy.
Suggested sources
