FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Back to newsfeed
Draft framework · feedback review

EMVCo reviews feedback on a draft framework for AI payment permissions

EMVCo is assessing comments on its proposed framework for carrying consumer-authorized intent through card payments. An October 2 interview clarifies the work after the September 30 consultation deadline; no final specification or rollout date was announced.

3 min read · estimatedAI-generated analysis · Methodology
Related research, policy & entities ↓
0% through article

Tap a dotted-underlined term for a definition. Use Aa in the navigation for reading preferences.

Analysis

The work addresses a gap between possessing a payment credential and having authority to make a particular purchase. Its significance is the possibility of a common record that different participants can interpret when software shops on a consumer’s behalf.

From public consultation to review

EMVCo’s Agentic Payments Task Force is collecting feedback and considering next steps after public comments closed September 30, director of engagement and operations Oliver Manahan said in an interview published October 2. The development is a review milestone, rather than the launch of an operating payment standard. [1]

The technical body released its draft EMV Agentic Payments – Framework for Specifications on September 1. The proposal focuses on card purchases made by AI agents under authority delegated by consumers. It is intended to inform possible future specifications. [2]

Permission that lasts beyond checkout

The proposed Intent Services would give authorized payment participants a shared way to record, find and maintain information about a consumer’s purchasing instructions. The issue becomes more complicated when instructions cover recurring purchases, a budget spread across transactions or activity after the sale. A shared record would help participants interpret the same permission over time. [2]

Manahan said historical intent information could also be needed when a transaction is disputed. He distinguished EMVCo’s technical work from commercial decisions about how payment products are used; the framework does not itself set those business rules. [1]

Why a valid credential is only part of the picture

Task-force chair Clinton Allen explained in EMVCo’s September 1 background paper that a customer may authorize spending within limits and be absent when the agent actually pays. The work aims to complement cryptographic evidence of permission with coordination across participants. [3]

An illustrative example is a household authorizing several purchases within one monthly budget. A valid card credential alone does not reveal how much of that budget has already been used. The shared-state problem concerns the continuing instruction and its history, rather than simply whether the card details are genuine. This example illustrates the proposal’s purpose; it is not a reported deployment.

The Financial Current’s research on EMV 3-D Secure explains how authenticating a customer differs from the issuer’s decision to approve a payment. Agentic commerce adds another question: what did the customer permit the software to do? [4]

The next specifications remain undecided

EMVCo has identified possible future work on agent identification and indicators showing that an AI agent participated in a transaction. Its discussion also covers potential changes to existing authentication, payment-tokenization and online-checkout technologies. Allen described interoperability with other standards as a way to reduce fragmentation. These are development possibilities, not completed capabilities. [3]

The October 2 interview supplied no final specification or implementation timetable. Feedback review will help determine which new requirements, if any, are developed. [1]

What remains uncertain

The reviewed sources establish a draft and subsequent feedback review. They do not establish deployment, measurable fraud reduction, a final technical standard or a settled allocation of liability.

Sources

Flag an error or suggest a correction →Public corrections log →