India is laying the groundwork for something no large payment system has fully attempted: letting artificial-intelligence agents spend money on a consumer's behalf without a human approving each transaction. Through 2025, executives at the National Payments Corporation of India (NPCI), the utility that runs the Unified Payments Interface, began publicly discussing "agentic commerce" on the country's instant-payment rail, and Indian business outlets including The Economic Times and Moneycontrol reported that NPCI was exploring how an AI agent could initiate UPI transactions inside limits its owner sets. No formal framework text has been published in the public record so far. The posture is visible; the paper is not yet.
The stakes follow from the scale. UPI is the real-time, bank-to-bank payment system used by roughly half a billion Indians. According to NPCI's product statistics, it processed about 186 billion transactions worth roughly 261 lakh crore rupees (around $3 trillion) in the fiscal year ending March 2025, and it passed 600 million transactions a day during 2025. Research firm ACI Worldwide has estimated that India accounts for close to half of all real-time payment volume worldwide. Three consumer apps, PhonePe, Google Pay and Paytm, route most of that volume.
Once software can spend, the payments system has to answer questions it never needed for human thumbs: What is the machine's identity? How much may it spend? Who answers when it errs? How is every action logged? And how fast can the plug be pulled? India has been quietly assembling pieces of those answers for years, in a different context.
UPI already knows how to let someone else pay
Every payment system eventually confronts delegation: the need to let someone other than the account holder spend the account holder's money. India has spent six years building delegation in layers, each one exchanging the ritual of per-transaction approval for pre-configured, capped, revocable consent.
The first layer was the recurring mandate. The Reserve Bank of India's 2019 e-mandate framework let cardholders authorize merchants to pull payments automatically, and NPCI extended the idea to UPI Autopay in 2020. A mandate is a standing instruction with ceilings, dates and a kill switch, revocable inside the user's app. The RBI initially required an additional authentication step for recurring debits above a few thousand rupees, then raised the no-extra-approval ceiling to 15,000 rupees in 2021 after the system proved itself, and later to one lakh rupees for categories like mutual-fund installments and insurance premiums. The pattern is the RBI's signature: cap tightly first, widen after monitoring.
The second layer separated small money from big money. UPI Lite, launched in 2022, let phones hold a small balance on device for low-value purchases with no PIN; the RBI raised its per-transaction cap to 1,000 rupees in December 2024. UPI 123PAY pushed payments onto feature phones. Each step put money further from fresh human approval.
The third layer is the most relevant precedent. In August 2024, NPCI launched UPI Circle, a delegated-payments feature that lets a primary account holder authorize a secondary user (a spouse, a child, an elderly parent who may have no bank account) to spend from the primary's account. Partial delegation requires the primary to approve each transaction. Full delegation lets the secondary user spend independently, inside a NPCI-set monthly cap of 15,000 rupees, and the primary can revoke the arrangement entirely from the app. UPI Circle is, in effect, a spending envelope with another identity attached to it, and an off switch.
An AI agent with a UPI wallet is a continuation of this staircase, not a break from it. What changes is that the delegate stops being a person.
What changes when the delegate is a machine
Every actor on UPI today resolves to a legal identity: an account holder verified through bank KYC, frequently anchored to Aadhaar-based e-KYC from UIDAI, or a merchant onboarded by a payment aggregator. Even a UPI Circle secondary user is a human with their own UPI ID and device. The reported direction of India's agentic framework breaks that pattern. If the reporting survives into a final text, every agent would carry its own verifiable, revocable digital identity on the network, distinct from its owner's, alongside per-agent and per-transaction spending caps.

That is a far bigger structural decision than a spending limit, and it deserves to be treated as the center of the debate. Compare the design space.
Identity for software, not people
India's identity plumbing is people-shaped; Aadhaar enrolment involves fingerprints and irises. But the country is not short of machine-identity ingredients. The IT Act, 2000 already recognizes digital signatures administered by licensed certifying authorities, and organizations routinely hold signing certificates today. The W3C's Verifiable Credentials standard offers a portable format for cryptographic credentials that can be presented and revoked. And India's Account Aggregator framework, built by Sahamati on the DEPA consent architecture, already makes consent itself a machine-readable, signed, revocable artifact for financial data sharing. An agent identity scheme is largely a matter of choosing which of these pieces carries which claim: this is a registered agent, made by this vendor, authorized by this user, inside these limits, until this revocation.
The alternative, letting an agent ride silently on the user's own credentials, is the cheaper path and the dangerous one. If the network cannot distinguish "the user tapped pay" from "the user's software decided to pay," liability and audit both collapse into guesswork. That distinction is exactly what a separate, revocable agent credential preserves, and it is the piece most global card networks have so far left inside private vendor arrangements rather than placing on the rail itself.
From spending caps to a written contract
Caps are easy; UPI is saturated with them. The hard part is permission semantics. An autopay mandate says what, to whom, at what ceiling, on what schedule. An agent needs something more like a bounded instruction set: which categories, which merchants, which price limits, and what counts as exceeding the mission. UPI already gives every transaction a unique reference number and full end-to-end logging at NPCI, so auditing movement of money is routine. Auditing the agent's reasoning, what instruction preceded the spend, is new, and it runs into India's Digital Personal Data Protection Act, 2023, which pushes companies toward purpose limitation and data minimization while fraud auditors push toward retention. That tension is unresolved in the public record.
Implementation roles fall out naturally. Banks, which hold the KYC and the money, would authenticate and enforce caps at the account level, under RBI's 2021 Master Direction on Digital Payment Security Controls, which already requires risk-based transaction monitoring and velocity checks. Wallet apps and UPI apps would host the configuration and revocation interface, as they do for mandates and UPI Circle today. Even telcos have an involuntary role: UPI's device binding ties credentials to the SIM linked to the bank account, which is why SIM-swap fraud is a payments problem, not just a telecom one.
Who pays when an agent buys the wrong thing?
India's liability baseline is the RBI's July 2017 circular on limiting customer liability for unauthorized electronic transactions. It draws a line the industry has lived with for years: zero liability for the customer in cases of bank failure or third-party breach reported promptly, limited liability in other cases, and, critically, the burden of proof placed on the bank.
An agent scrambles that binary. A purchase executed by a delegated agent is "authorized" by configuration, yet the user may contest the specific spend: the agent misread the instruction, hallucinated the need, exceeded a sensible reading of the mission. Was it unauthorized? Was the user negligent in configuring it? Did the vendor's model misbehave? Did the bank's controls fail? The 2017 framework has no vocabulary for "my software, acting wrongly inside my permission." Some allocation rule, dividing exposure among user, agent vendor, bank and merchant, is a prerequisite for launch, and there is no published Indian text settling it yet.
Dispute plumbing exists but was built for simpler failures. UPI disputes flow through the app to the banks, through NPCI's UDIR mechanism, and onward to the RBI's Integrated Ombudsman Scheme if unresolved within 30 days. That machinery handles failed, duplicate and misdirected transfers. UPI has no card-style chargeback; it is a push-payment system. Agent disputes insert a question of intent in the middle of an infrastructure that settles everything else in seconds.
Can a payment rail police a machine in real time?

India does not have the luxury of imagining fraud hypothetically. Data the finance ministry shared in Parliament in December 2024 recorded about 1.34 million UPI-related fraud incidents involving roughly 1,087 crore rupees in fiscal 2023-24 alone. The documented vectors are familiar: social engineering, screen-sharing apps, fake collect requests (a vector NPCI largely closed for person-to-person transfers in 2019), QR-code swaps at merchants, and SIM swaps to defeat device binding.
Agents change the physics of those attacks in two ways. First, speed and scale: a compromised agent can make dozens of decisions before a human would have finished reading one warning. Second, a new attack surface. An agent that reads web pages, listings and chat messages can be fed crafted text that nudges it toward the wrong purchase, the class of manipulation known as prompt injection. The RBI's own infrastructure has been converging on this problem from the other side: in December 2024 the RBI Innovation Hub announced MuleHunter.ai, an AI system to detect mule accounts that launder fraud proceeds. Defending agentic commerce will require the same machinery pointed at machine customers: per-agent velocity analysis, behavioral baselines, and a genuine real-time kill switch at the credential level, not the account level.
Oversight hooks exist. CERT-In's 2022 directions require service providers to report specified cyber incidents to CERT-In within six hours of noticing them and to retain logs for 180 days, with KYC and transaction records kept five years. Whether and how those obligations extend to agent vendors, who may sit abroad and have no payment-system license, is an open jurisdiction question.
How Visa, Mastercard and the AI labs are handling the same problem
India is not reasoning alone. Since early 2025, nearly every major Western payments player has shipped an agentic answer, and their architectures differ from India's reported one in an instructive way.
Visa Intelligent Commerce, announced on April 30, 2025, gives AI agents access to tokenized card credentials with limits and conditions set by the consumer, piloted with partners including Anthropic, Microsoft, OpenAI and Perplexity. A day earlier, Mastercard announced Agent Pay, extending its tokenization system into "Agentic Tokens" for agent-initiated transactions, with Microsoft as an early collaborator. Google's agentic checkout in AI Mode, announced in May 2025, buys a tracked item when the price drops to a threshold the shopper set, confirmed via Google Pay. In September 2025 Google went further and published the Agent Payments Protocol (AP2), an open standard in which cryptographically signed "mandates" act as verifiable proof that a user authorized an agent's intent or a specific cart, backed by more than 60 organizations including American Express, Coinbase, Mastercard and UnionPay. OpenAI's path was similar in spirit: its Operator agent in January 2025 handed the screen back to the user for payment, and its "Buy it in ChatGPT" Instant Checkout, launched September 29, 2025 with Etsy sellers, requires explicit confirmation of each purchase and runs on the open Agentic Commerce Protocol co-developed with Stripe, which passes a payment token scoped to a specific merchant and amount.

Notice what unites them: the agent carries proof of the human's authorization and rides the human's instrument. Identity stays with the person; the machine is a verified courier. The radical exception is Coinbase's x402 protocol, which revives the HTTP 402 status code so software can pay software in stablecoins, giving the machine genuine wallet ownership but walking off the banking system entirely. Amazon's "Buy for Me" and Perplexity's "Buy with Pro" remain confirmation-centric hybrids.
India's reported approach, agent-native identity plus hard caps plus an existing revocation muscle, sits between these poles and, if it materializes, would answer in public regulation what the card networks have answered in private network rules. None of these systems, India's or the West's, is yet proven at scale. The agentic checkout on the biggest platforms today still mostly ends with a human tapping confirm.
Do people want machines to spend for them?
The honest answer is that nobody has measured it. The Western pilots are months old, and none has published outcome data. India's own evidence urges caution. UPI Autopay has existed since 2020, yet recurring mandates remain a small slice of total UPI volume on NPCI's own dashboard, and the RBI felt compelled in 2021 to force extra authentication into silent card debits after mounting consumer complaints. UPI conquered India by being instant and friction-free, yes, but also by making every payment a deliberate act: the PIN entry is a ritual of control as much as a security step. Fraud statistics like the ones above suggest many Indians hold that ritual tightly.
The plausible wins are mundane, which may be the point: utility bills that pay themselves inside a 2,000-rupee envelope, transit and data-plan top-ups, grocery replenishment, subscribed services, price-watched purchases, and, on the enterprise side, agent-to-agent payments for APIs and services. Whether those use cases measurably expand commerce or merely shave seconds off checkout is precisely what a capped pilot would tell regulators.
What has to happen before the first agent spends a rupee
The documents to watch are specific. A formal NPCI or RBI framework text on agent-initiated payments. Finalized authentication directions building on the RBI's July 2024 draft framework for alternatives to SMS one-time passwords. An update to the 2017 liability rules covering delegated software. A chosen machine-identity standard. A dispute taxonomy that can ask what an agent was told to do, and data-retention rules reconciled with the DPDP Act. The RBI's regulatory sandbox is the obvious staging ground, and every precedent on this network, from e-mandates to UPI Lite to UPI Circle, suggests the first live limits will sit in the hundreds-to-low-thousands of rupees, widened only after the fraud dashboards come back clean.
Two further fronts lurk beyond the horizon. UPI is already cross-border, live with Singapore's PayNow since February 2023 and accepted for merchant payments in countries from the UAE to France; an agent spending across those lines collides with foreign-exchange rules that were written for humans and their paperwork. And the RBI's digital-rupee pilots explicitly flirt with programmability, purpose-bound money enforced by the token itself, which is arguably the native habitat of an agentic payment. Neither front has a published answer yet.
India's payment stack was built, layer by layer, on one idea: delegation should be cheap, capped and reversible. UPI Circle proved a third party can hold a spending envelope on your account and lose it with a tap. The argument now playing out in Mumbai and Delhi is whether that envelope can be handed to a program, with an identity the network can name, limits it can enforce, and a plug it can pull. When the next UPI user is not human, "the machine spent it" will either be a settled legal phrase with an assignable bill, or the start of every dispute call in the country. Which one it becomes is being decided in the plumbing, right now.
Sources / References

- National Payments Corporation of India. UPI product statistics. Monthly and annual UPI transaction volumes, values and usage metrics.
- National Payments Corporation of India. NPCI website. UPI Autopay (2020), UPI Lite (2022) and UPI Circle delegated payments (August 2024) announcements and product documentation.
- Reserve Bank of India. RBI website. Framework for processing e-mandates on recurring transactions (2019, ceiling raised 2021); Statement on Developmental and Regulatory Policies (December 2024, UPI Lite limits); Master Direction on Digital Payment Security Controls (February 2021).
- Reserve Bank of India. Draft Framework on Alternative Authentication Mechanisms for Digital Payment Transactions, July 2024.
- Reserve Bank of India. Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, circular dated July 6, 2017.
- Reserve Bank of India. Integrated Ombudsman Scheme, 2021.
- Reserve Bank of India. RBI Regulatory Sandbox framework.
- RBI Innovation Hub. MuleHunter.ai announcement, December 2024.
- Ministry of Finance, Government of India, via Press Information Bureau. UPI fraud incidence data tabled in Parliament, December 2024.
- Indian Computer Emergency Response Team (CERT-In). Directions under subsection (6) of section 70B of the IT Act, 2000, April 28, 2022.
- Ministry of Electronics and Information Technology. MeitY website. IT Act, 2000 (digital signatures) and Digital Personal Data Protection Act, 2023.
- Unique Identification Authority of India. UIDAI website. Aadhaar e-KYC infrastructure.
- Sahamati. Account Aggregator framework and DEPA consent architecture.
- W3C. Verifiable Credentials Data Model 2.0, 2025.
- ACI Worldwide. Prime Time for Real-Time report. Global real-time payments share estimates.
- Visa. Visa Intelligent Commerce, announced April 30, 2025.
- Mastercard. Agent Pay announcement, April 29, 2025.
- OpenAI. Introducing Operator, January 2025.
- OpenAI. Buy it in ChatGPT: Instant Checkout and the Agentic Commerce Protocol, September 29, 2025.
- Agentic Commerce Protocol. Specification repository. Open standard co-developed with Stripe.
- Google. Agent Payments Protocol (AP2) repository, September 2025.
- Google. Shopping announcements at I/O 2025, including agentic checkout, May 2025.
- Anthropic. Model Context Protocol, November 2024.
- Coinbase Developer Platform. x402 protocol, 2025.
- Amazon. Buy for Me announcement, April 2025.
- Perplexity. Buy with Pro, November 2024.
- The Economic Times (economictimes.indiatimes.com) and Moneycontrol (moneycontrol.com). Reporting on NPCI's exploration of agentic commerce on UPI, 2025.
- India Code. Payment and Settlement Systems Act, 2007.
Continue exploring
17,000 Cracks and a $76 Million Bribe Trail: The Coca Codo Sinclair Reckoning
A Quito court sentenced Lenín Moreno to five years in prison for taking bribes tied to Ecuador's largest hydroelectric plant. The…
How drones, Starlink and covert flights through Chad and Libya are redrawing Sudan's war
What began as a power struggle in Khartoum is now a drone war supplied through Chad and Libya, connected by smuggled satellite…
The Quiet Relay: How China-Linked Hackers Turned IoT Devices Into Espionage Highways
The QScan and QTRouter takedown reveals how ordinary routers, cameras, and other connected devices can become hidden relay points…
Comments
No comments yet. Start the conversation below.