Payment Gateway

EMVCo Agentic Payments Framework Explained (Part 1 of 5)

Published:
September 30, 2026
Author:
Sascha Huwyler
TL;DR

EMVCo has published a draft framework for card payments made by AI agents on a consumer's behalf. It defines two modes (immediate and autonomous), a three-layer model for proving what the consumer approved, and core concepts such as mandates and constraints. It also introduces Intent Services, a shared layer for tracking approvals. It is not a specification.

Agentic Payments Series, Part 1: What EMVCo's Draft Framework Proposes

On 30 September 2026, the public comment period for EMVCo's draft framework on agentic payments came to a close. For a month, anyone in the industry could read the draft and send feedback. EMVCo now turns to that feedback, and future versions will build on it.

That makes this a good moment to look at what the draft actually says. Agentic payments are purchases an AI agent makes on a consumer's behalf, and many people across payments are asking how they will work with cards. The draft is EMVCo's first detailed answer to that question.

It is worth being clear about what this document is. It is a draft, and an informative framework rather than a specification. It sets out shared terms, roles and concepts, not message formats, APIs or rules, and details may change before anything is final. In this series, we summarise what the draft contains in plain language, so you know where things stand today.

What EMVCo published

On 1 September 2026, EMVCo released EMV® Agentic Payments – Framework for Specifications (v1.0 Draft) (press release).

EMVCo is the technical body behind EMV chip, EMV 3-D Secure, Payment Tokenisation and Secure Remote Commerce. When it publishes a framework, it signals where future card specifications may head. EMVCo describes this one as a foundation for deciding whether, where and how future specifications are needed.

Why agents challenge today's card flows

Card payments have long assumed that the cardholder is present when checkout, authentication and payment happen. With an agent, those steps can come apart. A consumer might approve a purchase today, and the agent might pay next week, at a merchant the consumer never visited.

That raises questions every participant has to answer:

  • Was an agent involved in this transaction?
  • What exactly did the consumer approve, and can that be proven?
  • Does the payment being made match what was approved?
  • Who keeps track when one approval covers several purchases over time?

EMVCo's concern is that, without shared answers, each network, wallet and merchant builds its own version. The framework calls this a risk of fragmentation and proprietary extensions. Its aim is a common vocabulary before detailed specifications are written.

Two ways an agent can pay: immediate and autonomous

The framework separates agentic payments into two execution modes, based on whether the consumer is around when the payment happens.

Immediate modeAutonomous mode
Consumer at payment timePresent, or available in the same sessionNot present
What the consumer approvesExact products, merchant and final priceLimits, such as a maximum amount, a time window or preferred merchants
Who sets the final valuesThe consumerThe agent, within the approved limits
Example“Buy these two train tickets for CHF 84 now”“Book a hotel in Lisbon under EUR 150 a night sometime in October”

Examples are illustrative. Source: EMVCo, EMV® Agentic Payments – Framework for Specifications (v1.0 Draft)

A flow can switch modes. If an autonomous purchase needs the consumer's input at the last moment, it effectively becomes immediate.

In both modes, the framework suggests the agent can produce a short plain-language summary of what the consumer asked for. This summary can help later, for example as a reminder or when checking whether the agent understood the request. The framework also notes that such summaries should hold as little sensitive information as possible.

The layered model: how an approval travels

The framework describes intent in three layers. Each layer builds on the one above it, so any participant can trace a payment back to the consumer's approval.

  1. Trust Anchor. The payment credential provider, such as a card issuer, issues a credential that links the consumer to their card. Everything else builds on this foundation.
  2. Authorised Intent. The consumer signs their approval. In immediate mode, it holds the exact purchase details. In autonomous mode, it holds the limits the agent must stay within.
  3. Autonomous Fulfilment. This layer exists only in autonomous mode. When the agent makes the purchase, it signs the final values in two parts: the payment details, seen by networks, acquirers and issuers, and the cart details, seen by the merchant.

In immediate mode, the chain ends at the second layer, because the consumer has already approved the final values. In autonomous mode, the final values from the third layer are checked against the limits the consumer set.

Five core concepts

The framework builds on five terms. Together they describe the path from approval to payment:

  1. Intent: the consumer-authorised activity, such as "buy a hotel stay within these limits". It is the starting point everything else is derived from.
  2. Payment Mandate: how that intent is expressed for the payment side. It covers a payment credential reference, a payee, an amount or range, and a validity period.
  3. Constraints: the limits on a mandate, such as allowed payees, per-transaction amounts, total budgets, recurrence and expiry. Some are checked per transaction; others, like budgets, need tracking over time.
  4. Bindings: links that tie a payment to the specific checkout the consumer approved, so a different or modified cart cannot be paid for under the same approval.
  5. Fulfilment: the final values of the actual payment, checked against the mandate, constraints and bindings.

The framework defines what these concepts mean, not how anyone must enforce them. Each participant keeps its own decision-making and risk models.

What else the framework introduces

  1. ‍Intent Services. This is the framework's central new idea. An Intent Service is a shared place where a consumer's approved intent can be registered, looked up and tracked over its lifetime. It matters most when one approval covers several purchases, a budget or a recurring order. EMVCo positions it as a complement to cryptographic approaches such as Verifiable Intent (press release).‍
  2. Verifiable Intent. The framework describes Verifiable Intent (VI) as one way to make intent cryptographically provable. VI is maintained outside EMVCo, in a repository hosted by the FIDO Alliance, and the framework reflects a snapshot of its version 0.1.‍
  3. Know Your Agent and Agentic Transaction Indicators. These are flagged as future topics. KYA is about identifying which agent was involved. Indicators are about signalling in payment messages that an agent took part.

What the framework does not cover

The draft is explicit about its limits. It does not define:

  • Message formats, APIs or data schemas
  • Authorisation decisions, risk thresholds or conformance programmes
  • Liability allocation or dispute rules
  • Non-card payments, or payments split across several cards
  • How an agent picks between several eligible cards

It also states that laws and regulations take precedence over any industry standard built on it.

What happens next

The draft was first reviewed by EMVCo Associates and then opened for public review, which ended on 30 September 2026. EMVCo is now expected to review the feedback it received. EMVCo has formed a dedicated Agentic Payments Task Force and works with the FIDO Alliance, the OpenID Foundation, the OpenWallet Foundation and W3C (press release).

Feedback will shape further versions of the framework. It may also lead to enhancements in EMV 3-D Secure, Payment Tokenisation, Secure Remote Commerce and the EMV Digital Payment Credential, each through its own EMVCo process.

About this series

This article is Part 1 of a five-part series on agentic payments. The framework covers many participants and concepts at once, and each one deserves more room than a single overview allows.

So we have split it up. This overview gives you the big picture. Each of the next four parts explains one area in depth, in plain language and based on EMVCo's published material. You can read them in order, or jump straight to the part most relevant to your role.