top of page

EMVCo Wants to Build the 'Intent Layer' for AI Agent Payments: What the Draft Framework Means for Fintechs, Issuers and Merchants

  • 3 days ago
  • 6 min read

TL;DR: EMVCo’s draft EMV Agentic Payments – Framework for Specifications, released on 1 September 2026, proposes “Intent Services”: a shared layer for registering, retrieving and managing consumer-authorised intent before, during and after a card transaction. The goal is to solve a central problem in AI agent payments: a valid card credential proves an agent can pay, but not whether it should make a particular purchase. The draft focuses on recurring purchases, cumulative budgets, returns, disputes and top-ups. It is not yet a technical specification. Payments businesses should review it, submit feedback before 30 September 2026, and begin treating intent data as part of the transaction record.

What is EMVCo proposing? A shared intent layer for agentic payments

EMVCo is proposing a common, interoperable coordination layer that allows authorised payment participants to register, reference, retrieve and manage consumer intent.

This layer is called Intent Services.

The important point is that EMVCo is not simply designing a faster way for an AI agent to submit a payment. It is addressing the more difficult question of how a payment ecosystem can understand the authority behind that payment.

In a traditional card transaction, an issuer can check whether a credential is valid, whether authentication requirements have been met and whether the transaction appears risky. In an agentic transaction, those checks are not enough.

A valid card token may prove that an AI agent has access to a payment credential. It does not prove that the agent was authorised to:

  • Buy this product

  • Spend this amount

  • Use this merchant

  • Continue making purchases

  • Exceed a cumulative budget

  • Initiate a return, dispute or top-up

EMVCo’s draft attempts to create a framework for carrying that authorisation through the transaction lifecycle.

Abstract digital payment lifecycle showing persistent intent across recurring purchases, budgets, returns, disputes and top-ups

Why does AI agent payment intent matter? Because payment permission is not the same as payment authority

Consider a consumer who authorises an AI agent to spend $300 per month on groceries.

The agent makes three purchases:

  1. $110 from one supermarket

  2. $95 from another merchant

  3. $130 from a third merchant

The card credential remains valid. The token may be correctly provisioned. The transactions may pass standard fraud checks. But the third purchase exceeds the consumer’s cumulative mandate.

This is the gap EMVCo is targeting.

Agentic commerce requires payment participants to distinguish between:

  • Credential validity: can the agent access the funding source?

  • Transaction authorisation: was this individual payment approved?

  • Delegated intent: was the agent acting within the consumer’s broader instructions?

That third layer becomes essential when purchases are recurring, budget-based or dependent on previous transactions.

It also matters after payment. A return, dispute or top-up may depend on the original mandate, the agent’s authority and the state of the consumer’s instructions at the time.

How would Intent Services work? They would preserve intent across the payment lifecycle

The draft describes Intent Services as a shared source of reference for authorised participants. It is designed to support intent before, during and after a transaction.

In practical terms, that could mean:

  • An intent is created when a consumer delegates authority to an agent.

  • The intent receives a reference that can be used by relevant participants.

  • The agent uses that reference when initiating a payment.

  • The issuer, acquirer, merchant or other authorised party retrieves the relevant intent data.

  • The intent state is updated as purchases are made, budgets change or authority expires.

  • The record remains available for post-transaction activities such as returns and disputes.

This is different from storing a simple “yes” or “no” approval. Intent is likely to require context, including limits, categories, timeframes, recurring rules, permitted merchants and the status of prior transactions.

The draft does not provide the final technical schemas or implementation rules. That is why it should be read as a foundation for future specifications, not as a production standard that businesses can implement immediately.

Is EMVCo trying to replace existing agentic payment protocols? No : it is positioning cards as the default rails

The strategic significance is broader than the terminology.

Mastercard Agent Pay, Visa’s Trusted Agent Protocol, Google’s AP2 and Stripe’s Agentic Commerce Protocol are already shaping the market. These initiatives address different parts of the agentic commerce stack, including agent identity, mandates, tokenisation, checkout and payment execution.

EMVCo’s intervention is an attempt to ensure that card payments remain the path of least resistance as agentic commerce develops.

The card networks already have:

  • Global acceptance

  • Established tokenisation infrastructure

  • Issuer and acquirer relationships

  • Dispute and chargeback processes

  • Authentication frameworks

  • Merchant and wallet integrations

By developing an interoperable intent framework, EMVCo is extending those existing advantages into a world where the buyer may be an AI agent rather than a person actively clicking “buy”.

This is not simply an innovation exercise. It is also an incumbency strategy.

Accenture estimates that more than 30% of online commerce could be handled through AI agents by 2030, representing close to US$3.1 trillion in transactions. At that scale, the provider that controls the evidence of authorisation will have significant influence over risk, liability and payment routing.

Futuristic AI agent payment transaction passing through an issuer shield, merchant gateway and dispute evidence ledger

Will the framework solve chargebacks and liability? It could provide the evidence, but rules still need to be written

The most important unresolved issue in agentic commerce is not whether an agent can pay. It is who is responsible when the agent pays incorrectly.

A merchant may have delivered exactly what the agent ordered. The consumer may still claim that the agent exceeded its instructions. An issuer may see a valid token and a successful authentication event. An agent platform may argue that it acted on incomplete or ambiguous information.

Intent data could become the evidentiary substrate for resolving these disputes.

A future dispute record may need to show:

  • What the consumer authorised

  • When the authorisation was created

  • Which agent received the authority

  • What spending limits applied

  • Whether the intent had expired or been cancelled

  • Which transaction consumed part of a cumulative budget

  • Whether the agent altered or exceeded the mandate

  • What data the merchant and issuer received

This could support new liability models and dispute categories, such as “agent exceeded mandate” or “unauthorised agent activity”.

However, Intent Services alone will not decide liability. EMVCo, networks, issuers, acquirers and regulators will still need to define how evidence is interpreted and which participant carries the loss.

What are KYA and Agentic Transaction Indicators? They could make the agent visible to issuers

The draft also flags potential future work on Know Your Agent, or KYA, and Agentic Transaction Indicators.

KYA could help answer:

  • Who operates the agent?

  • Which business or consumer is responsible for it?

  • What permissions has it been given?

  • Is its identity verified?

  • Has it been compromised or revoked?

Agentic Transaction Indicators could signal to issuers and other participants that a transaction involved an agent acting on behalf of a consumer.

That distinction matters for fraud monitoring, authentication, customer service and dispute handling. It may also allow issuers to develop different risk controls for transactions initiated by trusted, registered agents.

The proposed direction aligns with EMVCo’s planned work across EMV 3-D Secure, EMV Payment Tokenisation, EMV Secure Remote Commerce and the EMV Digital Payment Credential. Collaboration with the FIDO Alliance, OpenID Foundation, OpenWallet Foundation and W3C also shows that agentic payments will require cooperation beyond the card networks.

What should fintechs and payment companies do now? Treat intent as a core payment data object

The framework is still a draft, but businesses should not wait for a final specification before preparing.

1. Read the draft and submit feedback

EMVCo has opened the framework for public feedback until 30 September 2026. Fintechs, issuers, payfacs, ISOs, merchants, POS providers and payment technology companies should assess whether the proposed roles, data fields and access controls reflect real operating conditions.

2. Map intent through your existing transaction flow

Document where your systems would capture:

  • Consumer consent

  • Agent identity

  • Delegated permissions

  • Budgets and velocity limits

  • Recurring instructions

  • Cancellation and expiry

  • Returns and disputes

If these records do not exist today, that is a strategic gap.

3. Plan tokenisation and 3DS readiness

Review how your tokenisation, authentication and digital credential infrastructure could carry agent-related data. Do not assume that a card token alone will be sufficient evidence of authority.

4. Design for evidence, not just approval

Intent records should be tamper-resistant, timestamped, retrievable and linked to the transaction. Treat them as part of the transaction record, not as temporary application data.

5. Decide where you want to compete

The emerging agentic payments stack will create opportunities in agent identity, payment orchestration, machine wallets, risk controls, tokenisation, reconciliation and dispute management.

As we discuss in our earlier analysis of the machine-wallet opportunity, the strategic value may sit less with the agent interface and more with the control layer that determines how money can be spent.

RivaTech’s view

EMVCo’s draft is important because it moves the industry discussion beyond the headline demo of an AI agent buying a product.

The real challenge is persistent authority: whether an agent can continue acting within a consumer’s instructions across multiple payments, changing circumstances and post-transaction events.

Intent Services could become the connective tissue between consumer delegation, payment credentials, risk decisions and dispute evidence. But the commercial and liability rules remain unfinished.

For payments businesses, the immediate priority is not to predict the final EMV specification. It is to understand where intent already exists in your business, where it is missing and which systems will need to consume it.

Suggested sources

 
 
bottom of page