
The Bot Problem Flips
For a quarter-century, card-not-present payments have operated on a single defensive premise: prove the buyer is human, authorized, and in control. Fraud systems, merchant controls, and authentication tools were trained to treat nonhuman behaviour as inherently suspicious. That logic worked when bots were mostly fraudsters.
It breaks down when the bot is a legitimate artificial intelligence agent acting on behalf of a consumer or business.
Robin Gandhi, chief product officer at Lithic, told PYMNTS that most online commerce technology has been built around the assumption that bot-like activity from a non-device source should be stopped. Agentic payments reverse that question. Commerce infrastructure must now decide when nonhuman behaviour signals delegated commerce rather than fraud. The industry does not just need better checkout flows — it needs a new trust grammar and logic flow for validating and settling machine-initiated transactions.
B2B Emerges as Agentic Commerce's Proving Ground
The consumer use case is easy to imagine: an agent buys sneakers, books a trip, finds a household item. But the more durable opportunity may sit in B2B, where autonomy maps to behaviour businesses already understand, Gandhi said.
The reality is, the programmable aspect of it is going to sit on the B2B side of things.
Consumers often enjoy discovery, comparison, and selection — they may not want to fully delegate the purchase itself. Businesses, by contrast, routinely buy supplies, services, and inputs that are necessary but uninteresting. That makes them better candidates for rules-based autonomy.
For CFOs and procurement leaders, payment control shifts upstream from approval after purchase to permission before purchase. Gandhi said that when supply runs low, it may be acceptable to automatically trigger a purchase. The first major wave may not be AI agents acting like personal shoppers — it may be agents acting like procurement assistants, replenishment systems, and back-office operators, executing transactions within predefined rules.
Virtual Cards as the Control Layer Agentic Payments Need
While stablecoins and micropayments attract much of the attention around programmable commerce, virtual cards are emerging as a natural control mechanism for delegated spending.
Virtual cards are an amazing way to keep your underlying funding source safe. They are an unlock for agentic. Agentic needs a way to be able to spend, and virtual cards are a clear way to do it.
Virtual cards can be single-use, limited by amount, merchant, timing, and other controls. If an AI agent makes a mistake, gets compromised, or hallucinates, the potential loss can be contained. That containment matters because agentic payments shift the risk model from one-time authentication to ongoing delegated authority. The system must answer not only whether the agent is legitimate, but whether the specific transaction fits the permission set.
Gandhi noted that the benefit of cards is that it's not a big leap — merchants are already accepting them. Most merchants do not need to adopt a new settlement asset or redesign their treasury workflows to receive payment. By contrast, stablecoin-native payments may require merchants to adopt new protocols, accept new assets, and decide what to do with those assets after settlement. To bridge that gap, Lithic issues cards backed by stablecoin accounts, allowing a stablecoin funding source behind a familiar card credential and removing that barrier for merchants entirely.
Tokenization and the Intent Layer
Agentic payments challenge the way payments controls are typically applied. In conventional systems, many decisions happen in real time at the moment of authorisation. But autonomy requires more control to be embedded before the transaction happens, Gandhi said.
The market is moving toward a familiar solution: tokenisation. Gandhi pointed to Visa's Intelligent Commerce and Mastercard's Agent Pay as evidence that networks are likely to extend existing token frameworks rather than start from scratch. Tokens are already legible to merchants, issuers, and acquirers — they are known infrastructure.
But the next layer is not simply proving that an agent is authenticated. It is proving what that agent was authorised to do. Gandhi framed the issue as the ability to embed additional information into the payments credential.
This is coming from an authenticated agent. No different than like an authenticated human. And ideally you also include intent in there.
If an AI agent is buying 100 reams of paper for a business, the issuer, merchant, and acquirer may need to know that the transaction fits a preapproved use case, supplier, price range, or replenishment trigger. That creates a new data-sharing bargain. Networks may want more transaction context. Merchants may resist sharing line-item or proprietary data unless it improves approval rates, lowers fraud exposure, or reduces liability.
Source
Original coverage by PYMNTS.
Use the button below to read the article on the publisher website.
Read on PYMNTS