Agentic payments are moving from concept to execution. As AI payment automation expands, agents can move beyond recommending what a business should do and begin initiating purchases, reimbursements and supplier payments. The central question behind AI agent transactions and autonomous payments is no longer whether the technology can move money. It is whether the enterprise can define, enforce and prove the authority behind every transaction.
AI Agents Are Crossing Into Financial Execution
Enterprise AI has largely operated in an advisory role. It summarized documents, answered questions and recommended next steps, while a person remained responsible for acting. Agentic systems are now crossing that boundary. Connected to procurement, ERP and finance platforms, an agent can prepare a purchase order, submit an invoice, schedule a payment or complete a pre-authorized transaction.
Payment networks are already preparing for this shift. Visa Intelligent Commerce is designed to support AI-initiated transactions across a network containing 4.8 billion payment credentials and more than 175 million merchant locations. By December 2025, Visa and its partners had completed hundreds of secure, agent-initiated transactions. These volumes remain small beside conventional payments, but they show that agentic commerce has moved into live transaction testing.
Traditional automation follows a predefined path. An agent interprets intent, selects tools, evaluates context and may decide which action to execute. Once that action reaches a payment rail, an AI judgment becomes a financial event affecting cash, budgets, accounting records and third parties.
The moment an AI agent can initiate a financial transaction, governance becomes a financial control problem—not simply an AI problem.
Every Agent-Initiated Payment Is an Authority Decision
Executives often frame the adoption question around capability: Can the agent complete the payment accurately? A stronger question is whether the agent has the right to complete it at all.
Every payment carries an implied chain of authority. Someone authorized the spending. A budget covers it. A policy permits the category. A supplier has been approved. A threshold determines whether another person must review it. Human-led processes often handle these conditions through experience and informal escalation. An AI agent needs them expressed explicitly.
Giving an agent access to a finance API does not establish legitimate authority. Access only answers whether the system can technically perform an action. Authority answers on whose behalf it is acting, for what purpose, within which limits and under which policy.
The distinction became visible in March 2026, when Santander and Mastercard completed Europe’s first live end-to-end payment executed by an AI agent within a regulated banking framework. The transaction ran through Santander’s live payment infrastructure, but the agent operated inside predefined limits and permissions. The pilot took place in a controlled environment and was not a commercial rollout. Its significance was that permissions and operational controls were treated as part of the transaction itself.
Enterprises do not lose control merely because an agent makes a poor decision. They lose control when the agent’s authority was never precisely defined.
Financial Policies Must Become Machine-Readable Controls
Most organizations already have financial controls. They live in procurement policies, finance handbooks, approval matrices and delegated-authority schedules. These documents work because employees can interpret language, recognize unusual circumstances and ask a manager when a rule is unclear. An agent executing a transaction cannot rely on the same ambiguity.
Policy must therefore become executable. A statement such as “routine operating expenses may be approved by the relevant department head” is insufficient for an agent. The system must know what counts as routine, which cost center applies, who currently holds approval authority, whether the supplier is trusted and what happens when available budget is lower than the invoice.
In practice, policy must become enforceable controls:
- Permissions tied to the agent’s identity and business role
- Thresholds based on value, category, vendor and budget
- Workflow rules determining when execution can continue
- Approval paths and exception handling for higher-risk cases

The goal is not to convert every finance policy into software overnight. It is to identify the decisions that must be deterministic before an agent may act. A recurring software invoice from a verified supplier may be processed within a defined tolerance. The same agent should stop when bank details change, the invoice exceeds the purchase order or the department has exhausted its budget.
Visa’s agentic-commerce research illustrates this at transaction level. It describes controls such as a maximum of five transactions per run, whitelists of approved merchants and services, and customer confirmation when a transaction exceeds predefined boundaries. It also describes payment-instruction controls that validate whether an agent’s action remains aligned with user intent.
An AI agent does not need another policy PDF in its knowledge base. It needs business rules that can allow, block, escalate or reverse an action at the moment of execution.
Auditability Must Cover the Decision, Not Only the Transaction
Conventional payment logs prove that a transaction occurred. Agentic execution creates a broader evidentiary burden: the enterprise must also explain why the transaction was permitted.
A useful record should connect the final payment to the agent that initiated it, the person or function it represented, the instruction it received, the data it consulted, the policy version it applied and any approval that changed the outcome. Without that chain, finance may see that money moved but still be unable to reconstruct how the system reached the decision.

Google’s Agent Payments Protocol offers one emerging model. AP2 uses cryptographically signed “mandates” to record user intent and transaction approval. In a delegated purchase, an intent mandate can specify conditions such as price and timing before the agent acts. A later cart mandate binds approval to the exact items and price, creating an auditable chain from instruction to payment. The protocol is still emerging, but the principle applies well beyond retail: authorization evidence should travel with the action.
A CFO does not only need a dashboard saying that an agent paid an invoice. The organization needs to know which authority was used, which budget absorbed the cost, whether the agent encountered an exception and whether the action can still be interrupted or reversed.
Automation without end-to-end visibility does not remove operational risk. It allows that risk to move faster and become harder to investigate.
Controlled Autonomy Is the Operating Model for Agentic Payments
The practical answer is neither unrestricted autonomy nor human approval for every transaction. The enterprise model is controlled autonomy: agents execute routine actions within a bounded mandate and return decisions to people when value, uncertainty or risk exceeds it.
That model requires more than a payment connection. Agent identity must be verifiable. Permissions must reflect business context rather than a generic system role. Approval checkpoints must sit inside the workflow, not in a separate inbox after the action has happened. ERP and finance data must inform the decision before payment, while transaction logs preserve what happened afterward.
This is why agentic payment programs should begin with operating design rather than interface design. A polished conversational experience may make the agent easier to use, but it does not define who is accountable when the agent selects the wrong vendor, uses the wrong cost center or acts on outdated approval data.
At Twendee, we help enterprises connect AI agents with ERP and financial systems through controlled workflows. Permissions, approval steps and transaction actions can be defined across the process, allowing an agent to prepare or execute work without operating outside the company’s financial controls.
The objective is not to make every payment autonomous. It is to determine which payments can safely become autonomous—and make every other path visible, reviewable and traceable.
Conclusion
Agentic payments will scale when enterprises can govern authority as precisely as they govern access. That means turning policy into executable rules, preserving evidence from intent to transaction and giving agents enough autonomy to remove operational work without giving them undefined financial power.
The winners will not be the companies whose agents move money first. They will be the companies that can explain, for every transaction, who authorized it, why it was allowed and how control can be restored.
Visit the Twendee website, follow Twendee on LinkedIn, or book a conversation through Twendee’s Calendly to build AI agent workflows that connect securely with your ERP and finance operations.



