Insight, AI & Digital
India is preparing to let software agents spend from a person's account without approving each transaction, using a framework built for lending your card to a family member. The mechanism transfers. The thing that made it safe does not.
The National Payments Corporation of India is developing a Unified Agent Protocol that would let artificial intelligence agents make payments over the Unified Payments Interface without requiring approval for every transaction. It is expected to be presented at the Global Fintech Fest in Mumbai in September and requires Reserve Bank of India approval before launch.
The design is careful and worth describing accurately. It builds on UPI Circle, which already lets a primary account holder delegate spending-capped payment authority to a trusted secondary user such as a family member, and Reserve Pay, which lets a user block funds once for multiple future payments. On top of that it adds a registry: an agent must be registered, verified and authorised before it can transact. Initial use cases are low-value, high-frequency transactions such as grocery orders and routine digital purchases. Spending limits, identity checks and audit trails are expected, and a liability framework is planned, though its details have not been published.
This is being built on the largest retail payment system in the world by volume, which processed 24.51 billion transactions worth 29.82 trillion rupees in August 2026. India will be among the first countries to build national infrastructure for agentic payments, and the approach of extending an existing delegation framework rather than inventing a new rail is a sound instinct.
It is also worth being precise about what the existing framework was carrying, because the part being reused is not the part that made it work.
Consider what actually protects you when you authorise your mother, your adult child or your business partner to spend from your account within a limit.
The cap is the smallest part of it. What does the work is that the delegate is a person you know, who has a continuing relationship with you, whose judgement you have observed over years, who can be asked what they were thinking, who is embarrassed by a mistake, and who can be argued with. If they spend badly, there is a conversation, and the conversation is a real constraint on their behaviour in advance.
Replace that delegate with an agent and the cap remains and everything else disappears. There is no relationship, no accumulated judgement about their reliability, no embarrassment, and no way to ask what they were thinking that produces an answer you can evaluate.
The formal structure of the delegation is identical. Its safety properties are not, and a numeric limit is being asked to carry a load that was previously carried by social accountability.
That is not an argument against building it. It is an argument that the framework needs a substitute for the missing element rather than an extension of the existing one, and the substitute has to be built deliberately.
The deeper problem is that agentic payments collapse a distinction that almost all payment consumer protection is built on.
Payment dispute regimes everywhere separate two categories. A transaction you authorised, which you generally cannot reverse simply because you regret it. And a transaction somebody else caused by impersonating you, which is fraud, and which the system absorbs.
The line between them is authentication. Was it you.
An agent operating under a registered delegation is, by construction, authorised. It authenticates correctly because it was given permission to. Every transaction it makes falls on the authorised side of the line, including the ones the user did not want, did not expect, would not have made, and cannot explain.
So the category that consumer protection was designed around, the unauthorised transaction, becomes structurally impossible, and it is replaced by a new one with no established law: the authorised transaction the principal did not intend.
That is where the unpublished liability framework has to do its work, and it is a genuinely hard drafting problem. The candidate answers each have a cost.
The user bears it. Simple, and it makes delegation unattractive to exactly the cautious users who would benefit most, while pushing risk onto people least able to absorb a wrong purchase.
The agent provider bears it. Correct in principle and requires agent providers to be capitalised, insured and identifiable, which favours large incumbents and forecloses the small local developers who would build for underserved users.
The merchant bears it. Merchants will price it in, and small merchants will refuse agentic payments, which fragments the rail.
A pooled fund bears it. Requires a levy, a claims process and an adjudicator, which is a new institution rather than a clause.
There is no costless option. What matters is that the choice is made explicitly, published before launch, and tested against the users who will find it hardest to contest a transaction, rather than settled quietly in scheme rules.
The economics here is old and the application is new. Jensen and Meckling's account of agency costs defines them as the sum of monitoring expenditure by the principal, bonding expenditure by the agent, and the residual loss where the agent's decisions still diverge from what the principal would have chosen.
Every term in that assumes the principal can observe enough to monitor.
Two features of this design make monitoring unusually difficult, and one of them is a deliberate virtue of the system.
The rail does not see what was bought. NPCI confirms that a payment request is authentic and does not access the details of what was purchased, which mirrors how UPI works today and is a genuine privacy protection. In a human-initiated system that is exactly right. In an agentic system it means the infrastructure that could detect a pattern of wrong purchases is, by design, unable to.
Audit trails are reviewed by whoever is capable of reviewing them. A log of forty small transactions a month is monitorable by a person with a smartphone, time and numeracy. It is not monitorable by a user with a feature phone, limited literacy, or an account operated on their behalf by a shopkeeper.
Which produces the distributional question, and it is the same shape as the one in automated speech systems: the failure will fall hardest on the users least able to detect it and least able to contest it, which is the population the infrastructure was celebrated for reaching.
The proposal is at draft stage and requires central bank approval, which is the right moment for evidence rather than after the first dispute wave.
A dispute rate and resolution outcome, disaggregated by user segment. Not an aggregate complaint number. Whether resolution outcomes differ for users on feature phones, in rural districts, in vernacular interfaces and at low transaction values.
Whether users can state what they delegated. A pilot can test this directly. Ask enrolled users, some weeks after enrolment, what their agent is permitted to buy and what the limit is. The gap between the consent recorded and the consent understood is the measure that determines whether the framework is meaningful, and it is the sort of thing established by asking rather than by reading logs.
Revocation in practice, not in principle. How long it takes a user to stop an agent, through which channel, and whether people who wanted to stop one succeeded. Ease of exit is the real consumer protection and it is rarely measured.
Who ends up using it. If uptake concentrates among users who were already well served, the framework is a convenience product. If it reaches further, the protections have to work further, and that should be established before scale rather than inferred from it.
India is building this earlier and more deliberately than anybody else, which means the rest of the world will copy whatever it settles on. That is a strong argument for the evidence being generated here, in public, at pilot stage.
The Lab works on this in AI and digital systems and financial inclusion, through field research with the users a system is most likely to fail.
If you are designing or approving a delegated payments framework and want the consent gap measured before launch, tell us what you need to know.
This is an independent insight piece by Transitions Lab. For the Lab's applied work, see AI & Digital Systems. See also Who Does It Fail For? on why an average accuracy figure cannot describe who a system fails, What the Bond Is Actually Secured On on enforcement mechanisms hidden inside financial products, and The Cheaper It Gets to Verify on what falling monitoring costs quietly remove. To discuss a study, see Contact.