Visa Just Put Payments Inside OpenAI: What the Agentic Commerce Land Grab Means for Payment Providers
TL;DR
Visa’s 6 October 2026 collaboration with OpenAI matters because it places credentials, authorisation controls and fraud monitoring inside agentic commerce.
The contest is no longer only about which AI agent finds the product or which wallet completes checkout. It is about who can prove that a human authorised an agent to act, under which conditions, and who should route the resulting transaction.
That matters for issuers, acquirers, Payfacs, ISOs, POS companies and merchants because the counter, terminal and mobile wallet still matter, but the payment decision is shifting into a machine-readable policy layer before checkout appears.
Agentic commerce is real, but still early. Stripe’s Link wallet reportedly saw agentic purchases rise 38-fold in the month to late September, yet from a small base, and agentic commerce remains below 1% of US e-commerce today. The opportunity is substantial; the economics and liability model are not settled.
What did Visa and OpenAI actually announce?
Visa and OpenAI announced a strategic collaboration at the Visa Payments Forum in San Francisco on 6 October 2026. Visa will provide its global network, credentialing capabilities, tokenisation and security infrastructure to support payments across OpenAI experiences.
The arrangement forms part of Visa Intelligent Commerce, Visa’s broader effort to make its network available to AI agents and other machine-led commerce environments.
The proposed transaction model is permission-based. Users can establish controls such as:
Spending limits
Approved merchant categories
Required approvals
Tokenised Visa credentials
Real-time authorisation
Fraud monitoring
Visa’s Jack Forestell described AI as a force that could transform commerce “more profoundly than the internet or mobile technology ever did”. OpenAI’s Marco Mahrus similarly positioned agents as participants in purchases, payments and more complex transactions.
The immediate commercial implication is straightforward: a user may instruct an OpenAI-powered agent to complete a task, while Visa supplies the payment network and trust infrastructure underneath.
However, this is not merely a distribution deal. Visa is attempting to become part of the identity, authorisation and dispute architecture for agentic commerce.

Why is the trust layer more important than the agent?
The winning agent will not necessarily be the most intelligent one. It will be the one whose decisions can be trusted by the customer, merchant, issuer, acquirer and network.
That requires answers to five questions:
Who is the agent?
Which human authorised it?
What was the agent allowed to do?
Did the transaction stay within those permissions?
Who carries the loss when something goes wrong?
This is the emerging proof-of-intent problem.
Mastercard is developing an Agent Pay trust and intelligence layer, including a probability score that identifies whether a transaction was agent-initiated. It is also working on Know Your Agent verification with Skyfire and web signals with Cloudflare.
Mastercard and Google have also open-sourced Verifiable Intent, a protocol-agnostic record of user authorisation designed to be cryptographically tamper-resistant. Its SD-JWT credential format is intended to align with protocols such as Google’s Agent Payments Protocol and Universal Commerce Protocol.
These developments matter because a card authorisation response alone may not prove what happened. A transaction can be technically valid while still being outside the user’s actual instruction.
For example, a user might authorise an agent to purchase groceries up to $150 from approved merchants. The agent purchases $220 from an unapproved marketplace after interpreting a promotion incorrectly. The payment may pass traditional fraud checks, but the underlying question is different: did the agent have valid authority?
The provider that can answer that question will influence routing, approval decisions, fraud controls, chargebacks and liability allocation.
Why does the merchant counter become less important?
The payment decision is moving from the point of sale to the point of policy.
At a physical terminal, a merchant can influence payment choice through branding, loyalty incentives, contactless payments, tap to pay prompts and least-cost routing options. In an e-commerce checkout, the merchant still controls much of the interface.
An agent changes that balance. It may compare products, merchants, delivery terms and payment costs before presenting the user with a recommendation, or complete a permitted purchase without another interaction.
The terminal becomes a sensor and fulfilment endpoint rather than the primary decision point.
That has direct consequences for retail payment strategy. A merchant’s payment proposition must become legible to machines, including:
Price and availability
Delivery and returns
Payment acceptance options
Cost of acceptance
Refund and dispute rules
Loyalty or rewards value
Authentication requirements
A closed loop wallet, mobile wallet adoption strategy or Google Pay acceptance programme does not disappear. These remain important payment instruments. But agentic checkout is the layer above wallets and terminals. The agent may decide whether to use a card, wallet, account-to-account rail or stablecoin settlement method based on policy and economics.

What happens to cost of acceptance, disputes and liability?
Cost of acceptance becomes a machine-readable input rather than only a merchant finance metric.
An agent could compare total transaction cost, approval probability, rewards, delivery reliability and consumer protection before selecting a route, creating a new opportunity for acquirers, Payfacs and ISOs to offer machine-readable payment optimisation rather than simply a terminal or gateway.
It also creates tension. If an agent systematically selects the cheapest acceptable route, premium card propositions may lose volume, and issuers will need to understand whether the choice was driven by rewards, approval reliability, consumer protection or a commercial incentive embedded in the agent’s policy.
The same trust primitive that permits an agent to spend also makes disputes more complicated. Providers will need to determine whether the user approved the agent or only a general shopping task, whether the agent exceeded spending or merchant-category limits, whether the merchant supplied accurate machine-readable information, whether the issuer, network, platform or merchant failed to apply a control, whether agent-originated transactions receive existing purchase protections, and how refunds or partial fulfilment are represented to the agent and user.
The first significant agent-originated chargeback cases may establish more practical precedent than the current protocol debates.
Why do stablecoins belong in this discussion?
Agentic commerce is not only a card-network story. It is also a treasury, settlement and reconciliation story.
Machine-native payment protocols such as x402 and Stripe/Tempo’s Machine Payment Protocol point towards automated settlement between software systems. Stablecoins are being positioned as a possible settlement layer for machine-to-machine transactions, particularly where agents need to make frequent, low-value or cross-border payments.
That matters for remittance businesses, fintechs and payment companies. The key question is not whether a stablecoin replaces Visa or Mastercard at checkout. It is whether programmable settlement sits underneath an agent’s payment decision while card networks remain one of several funding or consumer-protection options.
The operational challenge will be reconciliation: mapping a human instruction, agent session, tokenised credential, authorisation event, settlement asset, refund and accounting record into one auditable transaction history.
What should payment providers do in the next two quarters?
For fintechs and start-ups, this is a chance to build the trust and orchestration layer. For established providers, it is a warning that a strong terminal, wallet or gateway proposition may not be enough.
RivaTech Consulting’s role is advisory: payments strategy, provider selection, risk and operational readiness, growth planning and stakeholder alignment. We are not a processor, sponsor bank or Payfac. See our payments consulting and risk management services.
What should the industry watch next?
Whether Mastercard’s agent probability score moves beyond US testing
Whether the Personal Agent Protocol and UCP converge or compete
Whether the first agent-originated chargeback cases establish liability precedent
Whether OpenAI’s reported 4% agentic commerce fee changes merchant economics
How Australia’s cost-of-acceptance disclosure milestones around 30 October 2026, 30 January 2027 and 1 April 2027 interact with agent-readable pricing
Australia’s card surcharge ban is now holding-pattern context, but greater cost transparency could become strategically important if agents begin comparing payment routes on acceptance economics.
FAQ: What does agentic commerce mean for payment providers?
Is agentic commerce real or hype?
It is real, but the current scale should be treated carefully. Stripe Link’s reported 38-fold increase is meaningful operationally, but it started from a small base, and agentic commerce remains below 1% of US e-commerce today. The medium-term opportunity is large, but mass adoption still depends on trust, liability and reliable merchant data.
What does the Visa and OpenAI deal actually change?
It gives OpenAI a path to support Visa payments within agentic experiences and gives Visa a role in tokenisation, credentialing, authorisation and fraud monitoring for those transactions. It does not mean every ChatGPT interaction will automatically become a payment, but it does move Visa deeper into the trust layer.
Do merchants and issuers need to rebuild everything now?
No. Merchants should start with structured product data, accessible checkout, clear returns information and reliable APIs, while issuers should test agent indicators, delegated credentials, spending policies and new dispute scenarios. The immediate job is readiness, not a full stack rebuild.
Does agentic commerce replace tap to pay, contactless payments and mobile wallets?
No. It sits above them. An agent may still choose a Visa card stored in a mobile wallet, use Google Pay acceptance, support tap to pay or complete contactless payments at a terminal; the shift is that the policy and routing decision may happen earlier.
What is the real moat in agentic commerce?
The moat is not intelligence alone. It is verifiable intent: proving who authorised the agent, what the agent was allowed to do and whether the transaction complied with that authority. That is why the machine-readable trust layer matters as much as the agent itself.
Conclusion: The payment decision is becoming programmable
Visa’s OpenAI collaboration confirms that agentic commerce has moved from protocol announcements towards production infrastructure.
But the land grab is not really for the checkout button. It is for the trust layer that governs identity, permission, routing, authorisation and liability.
Our analyst call is clear: payment providers should prepare for machine-readable commerce now, but avoid overbuilding around today’s adoption figures. The winners will be those that can make agent activity auditable, payment economics comparable and liability understandable.
In agentic commerce, the agent may make the recommendation. The trust layer will decide who gets paid.
Further reading
