Imagine an ordinary morning in Mumbai, Bengaluru, or Ahmedabad. Before you finish your first cup of chai, your digital assistant has paid the electricity bill, ordered milk, booked a cab, and found a better price for a household item you buy every month. Nothing required a separate payment approval. The assistant knew your preferences, understood your budget, and acted on your behalf.
Then you notice one more purchase. It is not fraudulent in the familiar sense. The product exists, the merchant is genuine, and the amount is small. Yet you never asked for it. The machine concluded that you probably wanted it.
Was that convenience an error or an unauthorised decision?
This is no longer a distant thought experiment. India is reportedly preparing a framework that could allow artificial intelligence agents to make small payments through the Unified Payments Interface without asking the user to approve every transaction. According to reports, the proposed Unified Agent Protocol may be presented at the Global Fintech Fest in Mumbai. It is expected to rely on defined permissions, spending limits, identity checks, and existing mechanisms for delegated or reserved payments.
The scale makes this development globally significant. In August 2026, UPI processed a record 24.51 billion transactions worth nearly Rs 29.82 lakh crore. A change introduced into such a system is not merely a new feature. It can alter the relationship between citizens, businesses, banks, and machines.
India should be proud that this next frontier is emerging on its soil. UPI is among the most consequential public digital innovations of our time. It turned an act that was once slow, complicated, or expensive into something immediate and familiar. From a large retailer in a metropolitan mall to a neighbourhood vendor displaying a QR code, the same basic infrastructure connects very different parts of the Indian economy.
Over years of working with Indian companies, entrepreneurs, and advisers, I have learned that successful innovation in India is rarely about technology alone. It is about scale, adaptation, and trust. A solution that looks impressive in a boardroom but cannot work naturally in a kirana store, a family home, or a small town is not yet a complete Indian solution.
That is precisely why the arrival of payments made by AI deserves more than technical excitement.
Until now, most digital payment systems have operated on a simple assumption. A human being makes a decision, and technology executes it. Agentic payments change that order. The human being defines a broad intention, while the machine may search, compare, select, and pay. Technology is no longer only carrying out the decision. It is participating in making it.
The distinction matters because spending money is never a purely mechanical act. When a family chooses groceries, medicine, transport, insurance, or a subscription, price is only one factor. Familiarity, quality, health, urgency, loyalty, and personal relationships may matter just as much. An algorithm can compare ten prices in a second. That does not mean it understands why a family trusts one neighbourhood pharmacist more than a cheaper seller on an unfamiliar platform.
India also has a financial culture that cannot always be reduced to the image of a single consumer with a single account making isolated choices. In many households, financial responsibility is shared across generations. An adult child may pay for the needs of elderly parents. A parent may allow a younger family member to make limited purchases. A small business owner may authorise an employee to buy supplies. UPI Circle already recognises the practical value of allowing one person to extend limited payment authority to another.
Delegating authority to a machine, however, introduces a fundamentally different relationship. A relative understands family history and can be questioned. An employee can explain a purchase. A machine can generate an answer, but an answer is not necessarily an honest account of how the decision was reached.
The first challenge is therefore not security. It is the meaning of consent.
If a user tells an assistant to keep the refrigerator stocked, what exactly has been authorised? Can the agent change brands? Can it respond to a promotion? Can it subscribe to automatic deliveries? Can it choose a merchant that pays the platform a commission? Can it spend more because it predicts that prices will rise next week?
A single click at the beginning of this relationship cannot serve as permanent consent for every decision that follows. Consent must function as a living mandate. Users should be able to set clear limits by amount, merchant, product category, frequency and time. When the nature of a purchase changes, the machine should have to ask again.
The second challenge is commercial influence. An AI assistant may appear to be a loyal representative of the consumer while operating inside an ecosystem funded by merchants, advertisers, or platforms. If it recommends a product because the seller paid for visibility and then uses the consumer’s money to buy that product, it becomes something far more powerful than an advertisement. It becomes a salesperson holding the customer’s wallet.
Any commercial incentive that affects an autonomous purchase must therefore be disclosed clearly. A payment agent should never quietly place the interests of a platform ahead of the instructions and welfare of the person whose money it controls.
The third challenge is responsibility when something goes wrong. Consider the likely chain of responses after a disputed purchase. The bank may say that the transaction occurred within an authorised limit. The payment application may say that it only processed a valid instruction. The AI provider may say that its agent followed the available information. The merchant may say that it delivered exactly what was ordered.
The consumer could be left alone in the middle of a perfectly documented failure.
India should prevent this blame cycle before it begins. For the consumer, there must be one clearly responsible point of contact. Responsibility among the bank, payment provider, technology company, and merchant can be settled behind the scenes. Citizens should not need legal or technical expertise to discover which machine in the chain made the mistake.
Liability should follow power. If a system is permitted to make a decision, the organisations that designed, deployed and benefited from that authority must bear responsibility for its foreseeable failures. A consumer who has acted reasonably should not be forced to prove the internal logic of a system that even its operator may struggle to explain.
Every autonomous payment should also produce a simple and useful receipt. It should state what was purchased, why that option was chosen, which permission allowed it, whether any commercial relationship influenced the choice and how the transaction can be challenged. This explanation must be available in the language and format the user actually understands.
That last point is especially important in India. A system designed only for fluent English speakers with high levels of digital confidence would contradict the inclusive achievement of UPI itself. Permissions and warnings must work across Indian languages and, where practical, through voice. Elderly users and people with limited literacy must not be asked to approve dense terms they cannot realistically evaluate. Consent that cannot be understood is not meaningful consent.
There must also be a visible and immediate stop mechanism. One action should freeze the agent’s spending authority without disabling the citizen’s access to ordinary payments. And when a problem occurs, the user must retain the right to speak to a human being. Nobody should be required to argue with one automated system about a mistake made by another.
Some in the technology industry may describe these protections as friction. That would be a mistake. UPI succeeded because it removed needless friction, not because it removed human control. A brief confirmation before an unusual purchase, a clear warning when a limit changes or a human review of a disputed transaction is not a failure of innovation. It is the infrastructure of trust.
The business case for such protections is as strong as the ethical one. Indian consumers adopt useful technology with remarkable speed, but trust, once damaged, is expensive to rebuild. If people suspect that their assistants are serving advertisers, exceeding instructions or leaving them helpless after an error, adoption will slow. Clear standards will protect not only consumers but also banks, startups, merchants, and the reputation of the entire ecosystem.
Indian business culture has taught me that speed can open a door, but trust keeps it open. A contract matters, yet the relationship that gives the contract life matters just as much. Agentic commerce will need to earn a similar relationship with the public. Clever software alone cannot achieve that.
The safest path is not to stop progress. It is to begin with deliberately narrow authority. Early use should remain voluntary, transparent, and limited to low-value, predictable purchases. Sensitive categories and unusual transactions should require fresh approval. Independent testing should examine not only whether the payment succeeds, but whether the agent remains faithful to the user’s interests when confronted with advertising, conflicting instructions, or misleading information.
India has an unusual opportunity here. Most countries will try to attach autonomous agents to fragmented and ageing payment systems. India can design rules for agentic commerce around a digital infrastructure already used at an extraordinary scale. If it gets the principles right, those principles may influence markets far beyond India.
The country can establish a global standard built on clear mandates, understandable explanations, visible commercial interests, rapid human assistance, and unambiguous responsibility. It can demonstrate that innovation and consumer protection are not opposing forces. Properly designed, each strengthens the other.
The central question is not whether AI can spend money. It can. Nor is it whether consumers will welcome greater convenience. Many will. The real question is whether the human being remains sovereign at the moment the machine acts.
India’s success with UPI gives it both an opportunity and a responsibility. The real measure of the next phase will not be how quickly an AI agent can complete a transaction, but whether an ordinary citizen can understand why it was made, stop it when necessary, and know who must answer when it goes wrong. The safeguards adopted now will shape more than a new payment service. They will determine whether machine commerce strengthens individual agency or gradually moves economic power beyond the citizen’s view and control. That is not merely a technical design choice. It is a public choice about the kind of digital economy India wishes to build.
