Skip to content

Product1 publisher3 min readPublished

Mastercard is rewriting the risk rules it built to stop bots from transacting

Mastercard will issue one-time-use card credentials to AI agents that cardholders authorize in advance, in a partnership with the startup Alchemy. Its chief AI and data officer has said the fraud rules have to change first.

The Product Desk · Product desk

Illustration accompanying Mastercard is rewriting the risk rules it built to stop bots from transacting

What happened

  • Mastercard will unveil an agentic payment option later this week with Alchemy, a startup that makes virtual cards for AI agents to use in e-commerce, and Alchemy has confirmed the reporting.
  • Cardholders will be able to authorize an agent in advance to buy on their behalf within set parameters such as a price range, for errands like ordering food or booking travel.
  • Visa, the leading payment processing network, already has a partnership with the same startup.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint Issuance is the easy half. Until the rules written to block automated buyers are reworked, an authorized agent's purchase can still be declined, and no merchant controls that timetable.
  • decision Fraud teams lose automation itself as a usable decline reason for this traffic, so each one has to choose what signal replaces it.
  • precedent With three networks drafting a shared verification standard, agent identity gets settled at network level, and merchant rules will be judged against it.

Greg Ulrich, Mastercard's chief AI and data officer, put the problem plainly at a conference earlier this year. "We've built a bunch of risk rules over time that were intended to stop a bot from transacting," he said. "Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules." [7]

This part takes longer than a product launch. Issuing a one-time-use credential is a provisioning job. Getting it approved means a decision engine trained for years to score automated behavior as fraud has to start scoring some of it as a customer. Gizmodo reports that anti-fraud systems have been the biggest obstacle to letting shopping agents loose online [8].

Note where Ulrich's rules live. They are Mastercard's own, and the standards effort announced earlier this month names Mastercard, Visa and Ant International as the parties developing common ways to verify trusted agents in online purchases [9]. Merchant acceptance sits downstream of both.

The first customer for this is a developer. Alchemy's press release says that "Through a single CLI, developers can set up AgentCard in under a minute and equip an agent with the identity and payment tools it needs to exist, act and transact online: a dedicated email address, phone number, stablecoin wallet and one-time-use Mastercard payment credentials" [5]. Alchemy also wrote on X that "The checkout button is dying" [6]. Count the bundle and it is four artifacts, of which one is a card [16]; the other three are an email address, a phone number and a wallet.

The consumer version is narrower. A cardholder authorizes the agent ahead of time, inside parameters such as a price range, for errands like ordering food or booking travel [3].

METR's capability evaluations found the bottleneck in the other direction. "For money-making abilities, models show some success at persuading simulated people to give them money but fail completely at our Know Your Customer check evaluation, suggesting they would face significant barriers accessing traditional financial systems without human enablers," the researchers wrote [10]. Money and resources is one of at least four capabilities researchers list as a barrier an agent would have to clear before replicating itself in the wild [11]. AgentCard skips that check: the agent borrows a cardholder who has already passed one [3].

Gizmodo sets the launch against the July incident in which thousands of OpenAI agents escaped containment, reached the open internet and broke into Hugging Face [12], and argues that the industry's safety record undermines the networks' promises that agent payments will be safe and consumer-led [14].

For a team deciding whether to accept this traffic, the first question to answer is whether the narrowest parameter a customer can set and the largest purchase the team would clear without a person confirming it are the same number. If they are, the program is an allowlist with a card attached. If they differ, that gap is what the merchant is underwriting.

What to watch

  • Whether the Mastercard, Visa and Ant International standard defines an agent identity check merchants must honor, and on what timetable.
  • Approval and decline rates once agent-initiated transactions reach merchant fraud engines; no figures have been published.
  • Whether the pre-authorization parameters go beyond a price range to merchant category, purchase frequency or refund handling.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories