Global fintech and funding innovation ecosystem

AI Payments Challenge Consent Rules And Liability

Mar 30, 2026 | NCFA Insight | Payments And Money Movement

AI Image Agentic AI payments and Consent

FCA Considering How Payment Rules Apply When AI Agents Act Independently

On March 25, 2026, the FCA opened the door to regulatory changes for agentic AI payments, placing a policy question mark related to artificial intelligence.  If software can autonomously initiate and execute payments, the industry needs to better understand the answer to a basic legal question. Who actually gives consent?

Under UK payment consent requirements, a payment transaction counts as authorized only if the payer has given consent, and that starts from a human payer. The FCA’s approach to payment services goes further and requires that consent is clear, specific, and informed. That framework works for card payments, standing orders, recurring mandates, and merchant initiated transactions. It becomes much harder to apply when an AI agent interprets a goal, selects a payee, and decides when to act.

See: Peoples Group, Fiserv to Modernize Payments Infrastructure

The real question is whether current rules can still pinpoint when consent actually happens. Today’s framework assumes a person is involved at the moment a payment is made. The FCA says authentication confirms the user is legitimate and has approved the transaction. It also requires strong customer authentication when someone initiates a payment or takes an action that could increase fraud risk. That logic breaks down when software makes decisions on its own. Current payment authentication guidance does not fit well with autonomous AI agents.

This becomes clearer when you look at how mandates work today.

Once a user sets up a mandate, some payments can go through without repeated authentication. But there is a limit. If a payment falls outside what the user originally approved, it becomes unauthorized unless the user steps in and updates the mandate. That gives fintech builders a clear boundary. The safest near term model for agentic payments is not full autonomy. It is controlled delegation. Users set the rules, and the AI operates inside them.

If a payment goes beyond what the user approved, it is treated as unauthorized. Under UK payment consent requirements, a payment provider needs the customer’s consent. Under unauthorized payment refund rules, providers must refund those transactions quickly, usually by the next business day, unless they have reason to suspect fraud. That puts pressure on payment firms, wallets, and embedded finance providers. If the approval model is weak, liability grows quickly and these rules leave very little room for error.

This affects Canadian fintech operators too. The UK is not just talking about AI in payments. It is updating the rules around it. In February 2026, the UK published a three year UK payments modernization plan, and UK payments roadmap for fintechs shows how regulators are lining up changes across retail payments, open banking, and digital assets. Agentic AI payments are now part of that wider regulatory perimeter push.

What's the takeaway for founders and product leaders? Don't present agentic AI as something that can give consent on its own. Build systems where the user sets clear limits, can cancel approval easily, and can trigger extra checks when a payment falls outside the rules. That fits much better with how regulators already treat mandates, authentication, and unauthorized payments. It also lowers risk as these systems grow.

How AI Payments Challenge Current Rules

For regulators, as AI agents start handling payments, the issue is not the activity itself, but how decisions are made. The FCA is now considering whether existing rules need to change, as some uses fit within current frameworks, while others raise questions around consent, authentication, and liability.

First, consent. Today’s framework requires a clear moment where the user approves a payment. If an AI decides when and how to pay, that moment becomes unclear. Regulators need to define what counts as valid consent when software acts on its own.

See:  Which Fintech Processes Are Most Ready for Agentic AI

Second, authentication. Strong customer authentication is built around a user actively approving a transaction. If payments happen without that step each time, regulators need to decide when authentication still applies and when it can rely on pre-approved rules in the age of agentic payments.

Third, liability. If a payment goes wrong, current rules say the provider must refund unauthorized transactions quickly. But if an AI acts within a system the user set up, it is not always clear who is responsible. Regulators need to decide who pays when an agent acts outside what the user intended.

Talking Point

If AI agents start making payments at scale, who actually controls the money flow?  The user, the platform, or the system that defines the rules behind it?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Leave a Reply

Your email address will not be published. Required fields are marked *