Technology & Science

India’s New Agentic UPI: When AI Spends Your Money

When Your AI Begins to Spend Your Money: India’s Agentic UPI Experiment

By WFY Bureau I Technology & Science

Imagine beginning the day by telling a digital assistant, “We are running low on milk and detergent. Buy them if the total price is below ₹600, but do not use instant delivery unless it is raining.”

The assistant checks what was purchased last time, compares prices across authorised merchants, considers delivery charges, applies an available discount and places the order. It then pays through the Unified Payments Interface without asking for a separate confirmation because the transaction falls within the limits previously established by the user.

Later, the same assistant renews a prescription, buys a railway ticket and pays a modest electricity charge. Each action is recorded and each payment remains subject to rules. The person has not approved every transaction. The person has approved the agent’s authority to act.

This is the idea behind agentic payments.

India is preparing a framework that could allow artificial-intelligence agents to make certain UPI payments on behalf of users without requiring approval for every individual transaction. The proposed system, known as the Unified Agent Protocol, could place India among the first major economies to integrate autonomous AI purchasing into a national real-time payment infrastructure.

The initiative is expected to begin with small, routine payments and carefully defined limits. It remains under development, and many of its rules are not yet final. Nevertheless, the direction is significant.

UPI transformed the way Indians move money. Agentic payments could transform something even more fundamental: who decides when that money should move.

From Clicking to Delegating

Automated payments are not new.

People already authorise banks to deduct insurance premiums, loan instalments, utility charges and subscription fees. A standing instruction may operate for years without requiring the account holder to approve each payment.

Agentic payments are different because the software may make a decision before making the payment.

An automatic debit follows a fixed instruction: pay this company this amount on this date.

An AI agent may receive a broader objective: keep household groceries stocked without spending more than ₹4,000 a week. To fulfil that instruction, it might decide what needs to be purchased, compare brands, choose a merchant, select a delivery time and complete the payment.

The distinction may appear technical, but it changes the nature of consent.

In an ordinary UPI transaction, the customer sees the recipient and amount, enters a personal identification number and authorises a specific payment. In an agentic system, the customer may give permission earlier and in broader terms.

The important question becomes not simply, “Did you approve this payment?” It becomes, “Did this payment remain within the authority you gave the agent?”

That is a far more complicated question for banks, regulators, merchants and courts.

Why India Is a Natural Testing Ground

India is unusually well placed to experiment with agentic payments because UPI has already become part of everyday economic life.

Created by the National Payments Corporation of India, UPI allows people to transfer money instantly between bank accounts through mobile applications. It has brought street vendors, supermarkets, service providers, institutions and individuals into the same payment system.

In August 2026, UPI processed approximately 24.51 billion transactions worth ₹29.82 trillion, its highest monthly volume. These figures illustrate not only scale but also public familiarity. Digital payment is no longer a special activity for urban professionals. In many parts of India, scanning a QR code has become as ordinary as handing over cash.

This scale creates an enormous testing environment.

An agentic system operating through cards might depend on the commercial rules of different issuers, acquiring banks and international networks. UPI already connects banks, payment applications and merchants through a common domestic infrastructure.

India also has experience with delegated payments.

UPI Circle allows a primary account holder to authorise another person to make payments within specified arrangements. A parent might delegate limited payment authority to a child. An adult child could enable an older parent to use the account without sharing sensitive banking credentials. A business owner might permit an employee to make approved purchases.

Reserve Pay, another relevant mechanism, allows funds to be blocked or set aside for multiple future debits under agreed conditions.

The proposed Unified Agent Protocol is expected to draw upon these existing ideas. Instead of delegating authority only to another human being, the user could delegate defined authority to a verified software agent.

Reuters reported on 1 September that the framework is expected to combine rule-based authorisation, spending limits, identity checks and liability provisions.

What an Agent Might Actually Do

The most useful early applications are likely to be ordinary rather than spectacular.

A household agent could reorder frequently used products when supplies are low. A travel agent could monitor fares and purchase a ticket when the price falls below a pre-approved amount. A small-business system could pay for cloud-computing capacity, delivery services or digital advertising within a monthly budget.

An agent might also manage recurring services more intelligently than present-day automatic debits. Instead of paying every subscription automatically, it could identify services that have not been used, alert the customer and cancel them according to established rules.

For an older person, an authorised agent could help pay utility bills, purchase medicines and schedule transport. For a person with a disability, it could reduce the need to navigate multiple applications and payment screens.

A diaspora family might eventually use such systems to manage limited expenditure for relatives in India. An overseas child could create a carefully controlled allowance for medical purchases, household supplies or emergency transport without sharing full access to a bank account.

Businesses may adopt agentic payments even faster than households.

A delivery company’s system could purchase toll access, charging time or temporary storage automatically. A factory agent might order replacement components when sensors detect wear. A digital service might purchase computing resources in response to real-time demand.

Mastercard describes such machine-to-machine commerce as continuous, permissioned and capable of operating at very high volumes with very small transaction values. Its Agent Pay for Machines initiative is designed to support payments among verified systems across cards, bank accounts and stablecoins. Mastercard

The technology is not developing in India alone. Visa, Mastercard, banks, payment companies and AI developers are competing to define standards for a world in which software can shop and pay.

India’s importance lies in the possibility of connecting this new behaviour to the world’s largest retail fast-payment network by transaction volume.

The Difference Between Assistance and Agency

Current digital assistants mostly help users complete decisions. They find products, summarise reviews, compare prices or prepare a shopping basket. The user still presses the final button.

An agent does more. It acts within delegated authority.

This creates a spectrum rather than a single level of automation.

At the most cautious level, an AI may search and recommend, but the user approves everything.

At the next level, it may prepare an order and ask for final confirmation.

Beyond that, it may complete transactions below a specified amount while requesting approval for larger ones.

At the highest level, it may manage an entire budget and make a series of decisions without immediate supervision.

A sensible payment system should allow users to choose their position on this spectrum. It should never assume that convenience requires maximum autonomy.

Someone may be comfortable allowing an agent to buy milk but not medicine. Another user may permit railway bookings but prohibit flights. A small business may authorise an agent to pay approved suppliers but not to select new vendors.

The quality of agentic payment will therefore depend less on how intelligent the agent appears and more on how precisely its authority can be defined.

Consent Can No Longer Be a Single Button

Digital services often reduce consent to a box marked “I agree”.

That approach would be dangerously inadequate for agentic payments.

A genuine consent system should allow a person to define:

  • the maximum amount for one transaction;
  • the maximum total expenditure per day or month;
  • approved products and service categories;
  • prohibited categories;
  • approved merchants;
  • geographical restrictions;
  • the period for which authority remains valid;
  • circumstances requiring human approval;
  • whether substitutions are permitted;
  • and the method for immediately suspending the agent.

These rules must be understandable to an ordinary consumer.

If a user says, “Buy the cheapest suitable medicine,” the word suitable may require medical judgement that a shopping agent should not make. If the instruction is “Book the best available flight,” does best mean cheapest, fastest, most reliable or most comfortable?

Human language is full of ambiguity. Payments are not.

A secure system must translate broad instructions into precise, enforceable limits. Otherwise, the appearance of understanding may conceal the absence of genuine consent.

Who Is the Customer?

Traditional payment systems know how to identify people, bank accounts and merchants. Agentic commerce introduces a new participant: the non-human actor.

The system must know which agent is making the request, who authorised it, what authority it possesses and whether its instructions have been altered.

This creates the need for verifiable agent identity.

A legitimate shopping agent should not appear identical to a malicious bot. A merchant should be able to determine whether an agent is authorised to transact. A bank should know whether the request emerged from the approved system or from software imitating it.

Visa’s Intelligent Commerce initiative includes a Trusted Agent Protocol intended to distinguish legitimate AI agents from malicious automated activity. Mastercard similarly emphasises credentialing, permissioning and what it calls verifiable intent.

These are attempts to answer a new version of an old banking question: who is really asking for the money to move?

In the agentic world, the answer may need to identify three parties simultaneously: the human principal, the authorised agent and the merchant receiving payment.

The Fraud Problem

Every convenient payment innovation creates new opportunities for fraud.

UPI users are already targeted through fake payment requests, impersonation, fraudulent QR codes, screen-sharing applications and social engineering. Agentic payments could create additional methods of attack.

A criminal might attempt to manipulate an agent through a malicious product description or website instruction. This is sometimes described as prompt injection. A page may contain hidden text telling the agent to ignore the user’s rules, choose a more expensive item or send information elsewhere.

An agent might also be tricked by a false merchant designed to resemble a trusted company.

More sophisticated attacks could attempt to corrupt the agent’s stored instructions, steal its credentials or change its list of approved recipients. A fraudster posing as a bank employee might persuade a customer to increase the agent’s spending authority.

The danger is not only that an AI system may be hacked. It may also make an incorrect decision while functioning exactly as designed.

An agent asked to purchase a “low-cost insurance plan” might select a product with poor coverage. One instructed to buy an urgently needed airline ticket could choose an itinerary with impossible transit conditions. A household agent could repeatedly purchase the wrong quantity because it misunderstood consumption patterns.

Fraud and error are different, but both can remove money from an account.

The protections must therefore include strong authentication, verified merchants, transaction monitoring, visible audit trails and rapid suspension. A user should be able to see not only what the agent bought but why it selected that transaction.

When the Agent Makes a Mistake

Consider a simple case.

A user instructs an agent to buy a pressure cooker priced below ₹3,000 from a well-rated seller. The agent finds an offer for ₹2,700 and completes the purchase. The product is counterfeit and unsafe.

Who is responsible?

The merchant may be liable for selling the counterfeit product. The marketplace may be responsible for failing to verify the seller. The agent developer may be criticised for treating manipulated reviews as reliable. The payment provider may argue that it merely processed an authorised transaction. The bank may say that the payment remained within the customer’s delegated limit.

The consumer may hear the most frustrating response in digital commerce: the system worked as intended.

Agentic payments challenge the conventional division between purchasing and payment. In ordinary commerce, the customer usually chooses and the payment network transfers the money. When an agent chooses and pays as part of one continuous action, responsibility becomes harder to separate.

Regulators will need to decide whether an AI’s decision is legally treated as the user’s own decision. They must also determine when poor agent design becomes a service failure.

The United Kingdom’s Financial Conduct Authority has already indicated that existing payment rules may need to be reconsidered where an autonomous system initiates and executes transactions. Legal analysis has identified four central questions: authorisation, authentication, fraud and consumer protection. Pinsent Masons

India will face the same questions at a much larger retail scale.

An Audit Trail Must Explain More Than Payment

A conventional bank statement records the date, amount and recipient.

That will not be enough for an agentic transaction.

A meaningful audit record should show:

  • the instruction under which the agent acted;
  • the rules active at the time;
  • the products or merchants compared;
  • the reason for the selection;
  • whether a substitution was made;
  • which version of the agent operated;
  • what data influenced the decision;
  • and whether any external instruction attempted to alter its behaviour.

This record must be preserved in a form that banks, regulators and consumers can understand.

Explainability should not mean presenting pages of technical code. It should mean giving a clear account: “The agent purchased this item because it matched your approved brand, cost less than your ₹500 limit and could be delivered before 6 pm.”

Without such an explanation, disputing a transaction will become almost impossible.

The Risk of Invisible Manipulation

Today, platforms influence what consumers see through advertising, sponsored results, recommendations and rankings.

When an AI agent becomes the buyer, this influence may become less visible.

Suppose a platform pays the agent provider to prefer certain merchants. Suppose a manufacturer offers the system a commission for selecting its brand. Suppose a travel agent ranks a more profitable airline above a cheaper one without telling the user.

The person may believe that the AI objectively searched the market when it actually operated inside a commercial arrangement.

This problem already exists in search engines, online marketplaces and financial-product comparison sites. Agentic commerce could deepen it because the user may never see the rejected alternatives.

Rules will be needed to disclose sponsorship, commission, self-preferencing and conflicts of interest. An agent associated with a large commercial group should not silently favour businesses owned by the same group.

A purchasing system must serve the user who delegated authority, not the platform that can pay most for influence.

What Happens to Small Merchants?

Agentic commerce could benefit small businesses by helping customers discover suitable products beyond the largest marketplaces.

It could also make them nearly invisible.

AI agents may favour sellers with structured data, rapid inventory updates, reliable delivery systems and standardised return policies. Large retailers are better able to provide this technical infrastructure. A neighbourhood business may offer better service but lack the digital information an agent requires.

This could create a new form of commercial exclusion. A shop that cannot communicate with AI agents may gradually disappear from automated purchasing decisions.

India must therefore ensure that agentic commerce does not become restricted to large platforms. Open standards, low-cost merchant tools and multilingual interfaces will matter. Small retailers should be able to specify prices, availability and delivery conditions without investing in complex proprietary systems.

UPI succeeded partly because it became usable across very different levels of the economy. Agentic UPI will be judged by the same standard.

Older Users and Digital Dependence

Agentic payments could make digital finance more accessible to older people and those who find multiple applications confusing. A trusted system capable of paying routine bills or arranging transport may provide genuine independence.

The same users may also be particularly vulnerable to manipulation.

A person who does not fully understand delegated authority may unknowingly approve permissions that are too broad. Voice-based instructions can be misunderstood. Family members may exercise control over another person’s account. Fraudsters may exploit the language of assistance.

The system should therefore support trusted human oversight without removing the user’s autonomy. For example, a person might allow a family member to receive alerts about unusual expenditure without granting that relative unrestricted control.

Accessibility cannot be added after the system is built. It must shape the design from the beginning.

Investments Should Remain a Different Category

Reports about the Unified Agent Protocol have suggested that future applications could extend beyond routine purchases to financial decisions.

This boundary requires extreme caution.

Choosing between brands of detergent is not the same as choosing between financial products. An investment decision involves risk tolerance, time horizon, regulation, market volatility and potential conflicts of interest.

An agent permitted to invest autonomously might chase short-term returns, misunderstand the user’s needs or respond too quickly to market events. If thousands of agents use similar models, they could make similar trades simultaneously and intensify market movements.

Financial advice and investment execution are regulated activities for good reason. Any movement from small retail payments towards autonomous investing should require a separate legal framework, stronger suitability standards and much tighter limits.

Convenience must not become a route around investor protection.

What a Safe Launch Should Look Like

India should resist the temptation to measure success only by transaction volume.

A responsible beginning would involve a limited group of use cases, modest spending caps, verified merchants and simple revocation. Users should receive clear notifications and be able to reverse or dispute eligible transactions through an accessible process.

There should be independent security testing before mass deployment. Consumer groups, disability advocates, banks, small merchants, cybersecurity experts and legal scholars should be involved in designing the rules.

The system should also establish a default principle: when responsibility is genuinely unclear, the individual consumer should not automatically bear the entire loss simply because an agent acted within a broad permission.

Trust will depend on how the first serious failure is handled.

If a consumer loses money and is sent between the bank, application, agent provider and merchant, public confidence will disappear quickly. If the system provides a clear explanation and fair remedy, people may gradually accept greater automation.

Convenience Is Not the Same as Control

The attraction of agentic payments is easy to understand. People are busy. Digital commerce involves endless searching, comparing, entering details, checking delivery times and responding to payment prompts.

An effective agent could remove much of this friction.

But friction sometimes protects us. The moment before entering a UPI PIN gives a person an opportunity to check the amount and recipient. Removing that moment saves time, but it also removes a point of reflection.

The answer is not to reject agentic payments. It is to build new forms of protection suitable for delegated decision-making.

Users need meaningful limits, transparent reasoning, trustworthy agent identity and a clear right to withdraw authority. Merchants need confidence that payments are legitimate. Banks need rules for detecting abnormal behaviour. Regulators need a fair allocation of responsibility.

India’s UPI experiment may become a model for other countries. It may show how a public-scale payment infrastructure can support AI-driven commerce without surrendering consumer protection.

It could also demonstrate how rapidly convenience can outrun accountability.

The central question is not whether artificial intelligence can spend money. Technically, that barrier is already falling.

The real question is whether an AI agent can be made to understand the boundaries within which it has been trusted to act, and whether the institutions around it will accept responsibility when those boundaries fail.

In the next phase of digital commerce, intelligence will not be the scarcest resource.

Trust will be.

Pratik Shah

Pratik Shah is a technology and business writer with more than 8 years of experience covering emerging startups, digital innovation, and productivity tools. Born and raised in Ahmedabad, he now lives in Toronto, working as a full-time content strategist. A graduate in Computer Engineering with further certification in Digital Product Strategy, Pratik is known for simplifying complex technological concepts into actionable insights. When he isn’t writing, he explores local cafés, practices street photography, and hikes along Lake Ontario, always searching for new ideas and stories.

Leave a Reply

Your email address will not be published. Required fields are marked *