The network's new trust services aim to tell issuers and merchants when a payment was probably initiated by an AI agent and whether the surrounding activity looks legitimate.

Mastercard has expanded its Agent Pay programme with trust and intelligence services intended to give banks and merchants more context about AI-initiated transactions. The company said the services combine identity, intent, behavioural and fraud signals within a framework covering identity, intent, controls, execution and intelligence.

The first service is a probability score that indicates whether a transaction was likely to have been initiated by an AI agent. Mastercard said it is rolling the score out for testing in the United States and plans to enrich it over time with signals about behaviour, merchant risk, transaction patterns, credential risk and consumer propensity.

The design addresses a practical problem. A travel agent making several purchases across airlines, hotels and transport providers may look anomalous to systems tuned to human shopping patterns. More context could help an issuer distinguish a legitimate sequence approved by a customer from compromised credentials or an agent acting outside its mandate. The company has not yet published independent performance evidence for the service, so claims about reduced friction or better authorisation remain to be proven in deployment.

For banks, agentic payments create a new control object: delegated intent. Authentication can no longer stop at proving the cardholder's identity. Issuers, merchants and networks need a verifiable chain showing which agent acted, what authority it held, what the customer approved and how exceptions were handled.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!