top of page

AI Agents and Payments Regulation 2026: What Fintechs Need to Know Before Launching Agentic Payments

  • 6 days ago
  • 13 min read
AI Agents and Payments Regulation 2026: What Fintechs Need to Know Before Launching Agentic Payments

AI Agents and Payments Regulation 2026: What Fintechs Need to Know Before Launching Agentic Payments

Agentic payments are moving from concept to a realistic new category of financial technology. Instead of simply helping a customer make a decision, an AI agent can potentially select a product, choose when and how to pay, initiate a transaction and act within limits set by the customer without requiring a separate instruction for every payment.


That creates a different regulatory problem from conventional payment automation. Existing UK payment rules were largely designed around identifiable payment service users giving instructions to regulated firms, with clear rules around consent, authentication and responsibility when something goes wrong. An autonomous agent acting on behalf of a customer can make those boundaries less clear.


The FCA and HM Treasury are now actively considering how the UK regulatory framework should respond. For fintechs developing AI agents that can initiate, approve or orchestrate payments, the immediate question is not whether a new “AI payments licence” exists. It does not. The key issue is whether the activities performed by the business already fall within payment services regulation and whether future changes to consent, authentication and liability rules will affect how the product must operate.


What are agentic payments?

Agentic payments involve AI systems acting with a degree of autonomy in deciding when, where or how a payment should be made. The customer gives the system objectives, permissions and limits, and the agent performs actions within those parameters rather than waiting for a separate instruction at every stage.


A consumer might instruct an AI agent to find the cheapest suitable flight, book it if the price falls below £400 and pay using a specified account. A business could authorise an agent to replenish stock when inventory falls below a defined level, select from approved suppliers and make payments within agreed spending limits. Treasury agents could eventually move funds between accounts, optimise liquidity or initiate payments according to predefined financial rules.


This differs from conventional automation because the system may exercise judgement within the authority given to it. A scheduled Direct Debit follows a predetermined instruction. An agentic system may assess changing information, select between alternatives and decide whether a transaction should occur.

That additional autonomy is what makes the regulatory analysis more complex.


Are agentic payments regulated in the UK?

There is currently no separate FCA regulatory regime specifically for agentic payments. The FCA has also made clear that it does not intend to introduce an entirely separate body of AI-specific financial services rules simply because a firm uses artificial intelligence.


Existing financial services regulation continues to apply according to the activity being performed. A firm that provides a regulated payment service does not become unregulated because an AI model performs part of the customer journey, just as using an API or automated decision engine does not remove an activity from the regulatory perimeter.


For firms developing agentic payment products, the first regulatory question is therefore what the business actually does. If it receives customer funds, operates payment accounts, initiates payments from accounts held elsewhere, executes transactions or provides another regulated payment service, FCA authorisation may already be required under the Payment Services Regulations 2017.


The use of AI changes how the service operates, but the starting point remains the underlying regulated activity.


When could an AI payment business need FCA authorisation?

An AI business can remain outside direct payment regulation where it provides technology to a regulated institution and does not itself provide the regulated payment service. However, the position becomes more complicated where the fintech contracts directly with the customer and its agent initiates, controls or executes payment activity on the customer’s behalf.


Consider an AI procurement platform that identifies suppliers and recommends purchases but sends the user to their bank or payment provider to approve and complete each transaction. Its regulatory position may differ substantially from a platform that receives authority from the customer to initiate payments autonomously whenever specified purchasing conditions are met.


The analysis should consider who contracts to provide the payment functionality, who has authority to initiate the transaction, how the customer’s consent is obtained and whether another authorised firm is actually responsible for executing the regulated payment service.


Where the business itself provides regulated payment services, an Authorised Payment Institution permission may be required. Where the product also involves issuing stored monetary value or operating customer e-money accounts, Electronic Money Institution authorisation may become relevant.


The appropriate regulatory structure should be determined from the complete operating model rather than from the fact that the product uses AI.


Payment initiation is likely to become particularly important

Agentic payments have a natural connection with payment initiation services and Open Banking.

A Payment Initiation Service Provider initiates a payment at the request of a payment service user from an account held with another payment provider. In a conventional Open Banking journey, the customer actively instructs the service to initiate a particular payment and normally goes through the required authentication process.


An AI agent introduces a different model. The customer may provide a broader mandate allowing the agent to initiate transactions later when certain conditions are satisfied. The individual may not be actively present at the point each transaction is initiated.


This creates questions around whether the original mandate constitutes sufficient payment consent, when the customer must authenticate and how much discretion the agent can exercise before the regulatory character of the service changes.


Fintechs building agentic payment functionality should therefore analyse carefully whether their activities amount to regulated payment initiation rather than assuming that using an authorised bank or Open Banking provider underneath the product automatically places the fintech outside the perimeter.


The contractual and technical structure matters. A platform can use regulated infrastructure and still perform a regulated activity itself if its role goes beyond providing software.


Consent becomes more complicated when an AI agent acts autonomously

Payment regulation relies heavily on the concept of customer consent. A payment transaction is generally authorised where the payer has consented to its execution in the form agreed with their payment service provider.


Agentic systems can make that concept less straightforward because the customer may authorise a set of parameters rather than an individual transaction. A customer might tell an agent to pay recurring household bills, purchase approved business supplies below certain limits or move surplus cash according to predefined treasury rules.


The regulatory question becomes whether the customer has consented sufficiently to each resulting transaction and how that consent should be evidenced.


A well-designed agentic payment model will therefore need clear boundaries around what the agent is authorised to do. Spending limits, permitted counterparties, transaction types, time periods and circumstances requiring further customer approval may all become important elements of the control framework.


The customer should also be able to understand, amend and withdraw those permissions. An agent that technically operates within a broad mandate but behaves in a way the customer could not reasonably anticipate may create significant conduct and liability risk even where the underlying technology operates exactly as designed.


Strong Customer Authentication may need to evolve

Strong Customer Authentication was designed around payment journeys in which a customer interacts directly with a payment service provider when accessing an account or initiating certain transactions. Agentic payments challenge that model because the AI agent may need to transact when the customer is not actively present.

HM Treasury is therefore considering how existing authentication requirements should adapt as part of the wider modernisation of payment services regulation.


This does not mean Strong Customer Authentication has ceased to apply. Firms building products today must comply with the current legal framework and should not design systems on the assumption that future reforms will create broad exemptions for autonomous agents.


The more likely direction is that authentication becomes capable of supporting delegated authority in a controlled way. The customer may authenticate the mandate or permissions given to the agent, while additional controls determine which transactions can occur without repeated intervention.


The challenge will be creating enough flexibility for agentic commerce to work without weakening protections against unauthorised transactions and fraud.


Liability is one of the hardest regulatory questions

The commercial potential of agentic payments depends heavily on what happens when the agent makes a mistake.


Suppose an AI agent is authorised to purchase office equipment from approved suppliers but orders ten times the required quantity because it misinterprets inventory data. Alternatively, the agent might select a fraudulent merchant, initiate a payment outside the customer’s intended mandate or be manipulated through malicious data.


Several parties could potentially be involved: the customer, the AI provider, the payment institution, the bank, the merchant and the provider of the underlying model.


Existing payment regulation already allocates responsibility for authorised and unauthorised transactions, but autonomous decision-making can complicate the distinction between the two. A transaction may have been technically initiated under a valid customer mandate while still producing an outcome the customer never intended.


The Government’s 2026 work on agentic payments recognises that clear legal and liability frameworks will be necessary before adoption can scale safely. Fintechs should therefore design contractual responsibility and dispute processes alongside the technology rather than treating liability as an issue to solve after launch.


“Know Your Agent” may become part of payment infrastructure

Another emerging concept is the ability of payment systems to identify and verify autonomous agents.

The Financial Services AI Adoption Plan published in July 2026 recommends developing “Know Your Agent” protocols alongside legal, liability, authentication and governance standards. This is not currently a regulatory requirement, but it highlights an important problem that payment infrastructure will need to solve.


A bank or payment provider receiving a transaction may need to know whether it was initiated directly by the customer, by authorised software acting deterministically or by an autonomous agent exercising discretion. It may also need confidence that the agent is genuinely acting under authority granted by the customer.


Future infrastructure could therefore require reliable ways to identify agents, confirm their authority and distinguish legitimate machine-to-machine transactions from fraud or compromised systems.

For fintech developers, this suggests that identity and permission architecture may become as important as the AI model itself. A sophisticated agent that cannot demonstrate who authorised it or what it is permitted to do may struggle to interact safely with regulated payment infrastructure.


Consumer Duty still applies where retail customers are involved

Agentic technology does not remove existing conduct obligations.


Where an FCA-authorised firm provides payment services to retail customers, the Consumer Duty continues to require it to act to deliver good outcomes. This becomes particularly important where customers rely on an AI agent to make financial or purchasing decisions they would previously have made themselves.


Firms should consider whether customers understand the scope of authority they are giving the agent and whether controls prevent foreseeable harm. Permission settings, cancellation mechanisms, alerts, spending limits and explanations of how the agent makes decisions may all affect consumer outcomes.


The firm should also consider vulnerable customers and customers with lower digital confidence. A technically sophisticated interface can still produce poor outcomes if users do not understand what they have authorised or find it difficult to stop autonomous transactions.


For regulated firms, the correct question is not merely whether the AI performed accurately. It is whether the complete service, including the way authority is obtained and exercised, delivers appropriate outcomes for customers.


Fraud risk changes when machines transact with machines

Agentic payments could reduce some forms of fraud while creating new ones.


An authorised agent could potentially identify suspicious merchants, compare transaction patterns and apply controls more consistently than a human user. At the same time, criminals may attempt to manipulate agents, compromise credentials, alter instructions or create fraudulent counterparties designed specifically to influence automated decision-making.


The risk becomes particularly significant where AI agents can initiate payments without requiring a person to review each transaction. A compromised system could potentially transact at machine speed before conventional fraud controls identify the problem.


Payment firms should therefore consider how existing fraud controls operate when the initiating party is software rather than a human user. Transaction limits, counterparty controls, behavioural monitoring, step-up authentication and mechanisms to suspend an agent quickly may all become important.


The FCA’s 2026 Payments Regulatory Priorities specifically identify agentic AI payments as an area where regulation may need to develop, while continuing to emphasise fraud prevention, operational resilience and good customer outcomes across the payments sector.


Third-party AI providers create additional governance risk

Many fintechs will not build their entire AI stack internally. They may rely on external model providers, cloud infrastructure, specialist agent frameworks, payment APIs and data providers.


This creates a chain of dependencies behind a single customer transaction.


A payment firm remains responsible for meeting its regulatory obligations even where technology is supplied by third parties. Outsourcing a model or using a third-party AI service does not outsource regulatory accountability.

Firms should understand which providers are critical to the service, what happens if they fail, how model changes are controlled and whether the business can identify when outputs or behaviour materially change.


Data security, resilience, access controls and incident management also need to reflect the increased dependence on external technology.


The FCA has emphasised that accountability for regulated activities and customer outcomes must remain clear as agentic systems scale. For authorised firms, this means governance should identify who is responsible for approving the use of AI, monitoring its performance and intervening when the system behaves outside expected parameters.


Can an AI fintech use a regulated payments partner instead of obtaining its own licence?

Potentially. Many fintech businesses can structure their model so that regulated payment activities are performed by an authorised bank, PI, EMI or Open Banking provider while the fintech supplies the technology and customer-facing functionality.


This can be an efficient route where the business does not need to control customer funds or provide the regulated payment service itself. It can reduce the regulatory burden during early product development and allow the fintech to focus on the agentic technology.


However, the structure must reflect how the service operates in reality. The fintech should not present itself as the payment provider, exercise control over regulated payment activities or independently initiate transactions where those activities fall outside the intended technology-provider role.


The contractual position, customer journey and technical architecture should all align. If the customer contracts with the fintech to provide the payment service while the underlying licensed provider is largely invisible infrastructure, the regulatory analysis may be different from a straightforward software arrangement.


A regulatory perimeter review before launch can determine whether direct FCA authorisation is required or whether the model can operate appropriately through regulated partners.


What should firms establish before launching agentic payments?

A fintech developing agentic payment functionality should begin by mapping exactly what authority the customer gives the system and what the agent can do without further human involvement. That analysis should cover the full transaction journey, including how payment instructions reach the regulated payment provider and which entity is responsible at each stage.


The firm should then determine whether it performs any regulated payment activity itself, whether another authorised provider performs those activities and whether the customer-facing contracts accurately reflect that division of responsibility. The payment permissions analysis should be completed before commercial agreements and technical integrations make the model difficult to change.


Consent and control mechanisms should also be designed into the product from the outset. Customers should be able to understand the authority being granted, impose meaningful limits, monitor activity and withdraw or amend permissions. The firm should also establish how errors, unauthorised transactions and disputes will be handled.


Finally, governance should cover the AI system as part of the regulated service rather than treating it as a separate technology project. Model changes, third-party dependencies, security, fraud, operational resilience and customer outcomes all need appropriate ownership and oversight.


The regulatory framework is still developing

Agentic payments remain an emerging area, and firms should distinguish clearly between current law and proposals for future reform.


The Payment Services Regulations 2017 and existing FCA requirements remain applicable today. There is no new standalone agentic payments authorisation, no current “Know Your Agent” regulatory requirement and no general exemption allowing AI agents to bypass existing rules on payment initiation, consent or authentication.


At the same time, the direction of policy is becoming clearer. HM Treasury’s July 2026 consultation expressly considers agentic payments, the FCA is testing agentic payment use cases through its innovation programmes, and the Financial Services AI Adoption Plan recommends a future trust framework covering liability, agent identity and authentication.


For businesses entering the market now, this creates both an opportunity and a planning challenge. Products can be developed under the existing regulatory framework, but their architecture should be capable of adapting as more specific rules and standards emerge.


The HM Treasury consultation on modernising payment services regulation provides the clearest current indication of how the Government is approaching these issues.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting has specialised in UK and European payment and electronic money regulation since 2013, advising fintech businesses, Payment Institutions and Electronic Money Institutions on FCA authorisation, regulatory structuring and new payment models.


For businesses developing agentic payment products, we can assess the complete customer journey and determine whether the proposed activities fall within payment services regulation, whether direct FCA authorisation is required and how responsibilities should be divided between the fintech and any regulated infrastructure providers.


Our work includes regulatory perimeter analysis, Authorised Payment Institution and Electronic Money Institution applications, Payment Initiation Service permissions, Variation of Permission applications, product and payment-flow reviews, governance and FCA regulatory engagement.


The regulatory analysis is most useful before the payment architecture and commercial partnerships are finalised. Establishing who initiates the payment, who provides the regulated service and how customer authority is exercised can materially affect both the permissions required and the way the product needs to be designed.


Where the wider issue concerns AI governance rather than payment regulation alone, firms should consider the governance, accountability and control framework around the AI system alongside the payments analysis. To discuss an agentic payment model, FCA authorisation or the regulatory structure for a new fintech product, contact Buckingham Capital Consulting.


Frequently asked questions

Are agentic payments regulated by the FCA?

There is no separate FCA licence specifically for agentic payments. Existing financial services rules apply according to the activity being performed. A business providing regulated payment initiation, money remittance, payment accounts or other payment services may require FCA permission even where an AI agent performs part of the service.


Does an AI agent need a Payment Initiation Service Provider licence?

The AI agent itself is software and does not hold a licence, but the business providing the service may require Payment Initiation Service permission if it is providing a regulated payment initiation service. The answer depends on who contracts with the customer, who initiates the payment and how the service interacts with the customer’s payment account and regulated providers.


Can an AI agent make payments without Strong Customer Authentication?

Existing authentication requirements continue to apply. HM Treasury is considering how payment authentication should evolve to support agentic payments, but firms should not assume that AI-initiated transactions are currently exempt. The regulatory treatment depends on the payment journey, the authority given by the customer and any applicable exemptions under the existing rules.


Can a fintech use an authorised payment provider instead of becoming FCA authorised?

Potentially. A fintech may be able to provide technology while an authorised bank, PI, EMI or PISP performs the regulated payment activities. The arrangement must reflect the actual customer relationship and flow of responsibility. Using licensed infrastructure underneath the product does not automatically place the fintech outside regulation if it independently performs a regulated activity.


What should an agentic payments fintech do before launching?

The firm should map the customer journey, payment flow and authority given to the AI agent, identify which entity performs each regulated activity and determine whether FCA authorisation is required. It should also establish controls around consent, authentication, spending limits, fraud, liability, third-party technology and customer protection before the service goes live.

 
 
bottom of page