Skip to content

Security1 publisher2 min readPublished

EMVCo proposes a shared Intent Services layer to track what consumers let AI agents buy

EMVCo has drafted Intent Services, a shared layer for recording what consumers authorise AI agents to buy, with comments due 30 September. The draft comes before any specification, so payment-security teams get a design direction with nothing yet to certify against.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • EMVCo narrowed the work to cases where intent must hold over time, such as recurring purchases, cumulative budgets and activity after the transaction.
  • The release says Intent Services would add a common coordination point to the cryptographic assurance that existing tools such as Verifiable Intent already provide.
  • According to EMVCo, the framework will help identify future enhancements to EMV 3-D Secure, Payment Tokenisation, Secure Remote Commerce and the Digital Payment Credential.
  • Know Your Agent checks and Agentic Transaction Indicators, meant to identify the agent and flag agent-made payments, are only candidates for future EMVCo publications.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An intent record that persists across multiple participants is readable by several parties by design, so its access controls become part of the trust chain for every agent purchase that relies on it.
  • decision EMVCo frames Intent Services as an addition to cryptographic tools such as Verifiable Intent, so teams adopting those tools for agent checkout now are not building against the standards body's direction.
  • constraint Until EMVCo delivers consistent identification of agentic transactions, issuers have no common EMV signal on which to hang agent-specific risk rules.
  • precedent If the enhancements follow, agent intent controls would land inside 3-D Secure and token integrations that issuers already run, and those teams would carry the implementation work.

EMVCo's case for a new layer rests on time. Intent managed over time, it says, "may require access to a shared intent 'state' that persists across multiple participants and their interactions" [6]. A cumulative budget is the plain example [5]. Whoever handles the fourth purchase needs to know what the first three used up, and that running figure has to sit where every participant can reach it [6].

Intent Services is the proposed home for that state. The draft describes a shared, interoperable layer where payment participants register, reference, retrieve and manage consumer-authorised intent before, during and after a transaction [8]. It sets out ecosystem roles and data fields for registering intent, keeping lifecycle and state information, and authorised retrieval of intent-related data [9].

For a security team, retrieval matters most. A shared record of what a consumer told an agent it may spend is readable by more than one party by design [6][8]. The draft's role definitions have to settle who counts as authorised to read it [9].

"Card-based agentic payments require a globally interoperable foundation that consumers, merchants and issuers can all trust," Junya Tanaka, EMVCo Executive Committee Chair, said [10].

The draft went public on 01 September 2026, after an initial review by EMVCo Associates [1][3]. Public review closes on Wednesday 30 September, a 29-day window [3][18]. EMVCo creates and manages the EMV specifications, and it describes specification development from this framework as potential [16][2]. The release does not set an implementation date or say who would operate Intent Services. A draft for comment binds no production checkout today [2].

Agent identification is further off. In EMVCo's account, development may be required before agentic transactions can be identified consistently across the payments ecosystem [14].

A dedicated Agentic Payments Task Force is engaging the hundreds of stakeholders who participate as EMVCo Associates and Subscribers [11]. Outside that membership, EMVCo is working with the FIDO Alliance, the OpenID Foundation, the OpenWallet Foundation and W3C [12]. The release says the framework will also inform work to complement existing and emerging identity and credential standards [17].

What to watch

  • Whether EMVCo follows the 30 September review close with a first specification, turning the framework's roles and data fields into something issuers can certify against.
  • Whether Know Your Agent and Agentic Transaction Indicators appear in a named EMVCo publication, giving issuers a common flag for agent-initiated payments.
  • Whether proposed changes to EMV 3-D Secure or Payment Tokenisation start carrying references to registered consumer intent.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories