Long description for screen readers. This page, "Agentic commerce and travel," has a hero, four numbered sections, an outlook band, and a footer. Hero: headline reads "The infrastructure, the risk, and the money behind agentic travel," summarizing that AI agents are starting to plan, price, and pay for trips on a traveler's behalf, and that infrastructure, risk, and law don't yet agree on how that works. Dated August 2026. Section 1, Consumer behavior: headline "Travelers trust AI to plan. Not yet to pay." A roles-based process map shows the traveler or guest describing a trip in plain language in step one, then the AI agent taking over for steps two through four: comparing live flights and hotels, refining the itinerary through follow-up chat, and requesting authorization to book and pay, which is flagged as the current trust ceiling. A callout explains that verification happens once, at the booking step, not during the earlier chat refinement. A second callout flags that corporate travel likely follows a different path, with a policy engine and possible human or travel-management-company checkpoint constraining the agent before it can book. A bar chart shows 68 percent of survey respondents would use AI to compare flights and 57 percent would let AI book, sourced to PwC's Holiday Outlook. Section 2, Technical execution: headline "Five rails now let AI agents pay. None share a token." A roles-based process map shows the traveler's AI agent proving identity, the card network issuing a token scoped to that agent, merchant, and spend limit, the merchant or acquirer validating the token at checkout, and the issuer handling settlement and disputes. A paragraph distinguishes Visa's Trusted Agent Protocol, a recognition layer that proves an agent is legitimate, from the separate spending credential issued by Mastercard Agent Pay, Visa Intelligent Commerce, or American Express's ACE developer kit. A timeline lists Mastercard Agent Pay launching in April 2025, Visa publishing its Trusted Agent Protocol specification in October 2025, Google unveiling its Universal Commerce Protocol in January 2026, and American Express launching its ACE developer kit with purchase protection for registered-agent errors in April 2026. A callout explains that card networks already assess fees for excessive failed authorization attempts, which limits runaway retries, but that whether or how a traveler is alerted to a failure is left to each agent platform, not standardized in the specs. A second callout explains that a merchant who hasn't adopted a recognition protocol will see agent traffic as an anonymous bot, which can be blocked or challenged, typically handing control back to the traveler. Section 3, Consent and control: headline "The cardholder sets the limits. Who they hand that job to is a bigger decision than it looks." Two comparison cards show that Mastercard's consent lives with the issuing bank's app, where the cardholder sets spend ceiling, merchant categories, and expiration before the bank requests the token, while Visa's consent lives with the agent platform itself, where the cardholder uploads the card via Visa Payment Passkeys and sets limits directly inside that platform. A callout lists five implications: enrollment UX becomes critical infrastructure, rollout is issuer-by-issuer rather than network-wide, merchant-category scoping is an open question for travel specifically, the real-time approval option means many "autonomous" bookings still require a manual approval tap, and whichever surface owns enrollment ends up owning the primary financial relationship with the cardholder. A stat bubble quotes Visa's global head of consumer products describing a "$500 ceiling for a hotel or an airline ticket" as a real, travel-specific example of the model. Section 4, Regulatory and fraud: headline "Agents can now prove who they are. The bill for when they're wrong is still unsettled." A roles-based process map, color-coded in shades of gold consistent with the piece's travel theme, shows the cardholder granting a scoped mandate, the AI agent completing checkout without a CAPTCHA, OTP, or biometric step, the card network classifying the transaction as card-not-present by default, and the merchant holding the liability by default unless a validated token program applies, flagged as the risk point. A callout explains this isn't the same across networks: Mastercard's token-validated flow keeps the issuer liable and preserves normal chargeback rights, Visa's Trusted Agent Protocol proves identity but doesn't yet shift liability, American Express has voluntarily pledged to protect eligible customers from charges tied to registered-agent error, and other rails set their own terms. Another callout notes a related Mastercard fee change on all authorizations, including declines, that raises the stakes of a poorly-tuned agent. A prominent stat bubble states that there are zero federal AI-specific exemptions from existing consumer-protection law, and explains what that means for merchants: they remain bound by standard consumer-protection and UDAAP obligations regardless of whether an AI agent completed the transaction. Section 5, Industry impact: headline "Automation eats the middle of the market first." A legend explains a four-step gold gradient from fastest-automating to most human-led. A grid of segment cards covers roadside and economy stays, retail and leisure direct booking, corporate transient travel, travel-agent-assisted booking, group travel, wedding and event travel, and luxury and bespoke travel, each labeled with its relative automation pace as a directional assessment, not a sourced forecast. A callout lists ideas for how travel agents and advisors can use AI to better serve clients: automated pre-trip research, disruption monitoring with human sign-off, tracking fare and award changes for existing clients, and faster quoting for group and wedding blocks. A closing reframe states that whoever owns the trust layer, the token, the identity check, the liability chain, owns the booking, and that owning the inventory is no longer enough. Outlook band: four short callouts cover personalization, loyalty, promotions, and dynamic pricing, each with a sourced data point. External claims throughout the piece are marked with small superscript numbers keyed to a numbered References list near the end of the page, ahead of the footer. The footer itself carries only a disclosure line and the publication date, August 2026.
Payments × travel - agentic commerce

The infrastructure, the risk, and the money behind agentic travel

AI agents are starting to plan, price, and pay for trips on a traveler's behalf. Here's what's actually live today, and where the payments infrastructure, the fraud risk, and the law still don't agree.

Updated August 2026
01 - Consumer behavior

Travelers trust AI to plan. Not yet to pay.

"Agentic commerce" means an AI assistant that does more than answer questions - it compares prices, builds an itinerary, and in a growing number of cases, completes the purchase. The planning half of that shift is already normal. The paying half is still the sticking point.

Traveler / guest
01Describes the trip in plain language - sets the boundaries the agent will operate inside
AI agent
02Compares live flights, hotels, and fares
AI agent
03Refines the itinerary through follow-up chat - no purchase authority yet at this step
AI agent
04Requests authorization to book & pay The trust ceiling - where adoption currently stalls
Where does verification actually happen? Only once, at step 04. The back-and-forth in step 03 is just conversation; the agent isn't authorized to spend anything yet, so nothing gets re-verified each time the itinerary changes. The identity and payment check happens a single time, the moment the agent presents its token to actually book.
Corporate travel likely won't follow this same path For managed, corporate transient travel, step 01 isn't really open-ended - a policy engine set by the travel manager or TMC constrains what the agent is allowed to search and book in the first place. Many programs will also insert a human or TMC checkpoint before step 04, rather than letting the agent request authorization directly from the traveler. See the corporate transient card in Section 05 for how this changes the pace of adoption.
Share of travelers willing to use AI, by task1
Compare flights
68%
Book the trip
57%
02 - Technical execution

Five rails now let AI agents pay. None share a token.

An AI agent can't hand a merchant a physical card. Instead, the card networks built a new credential: a token tied to one agent, one merchant, and a spend limit the cardholder set in advance. Five major players - Visa, Mastercard, American Express, Google, and Stripe/OpenAI - have each shipped a competing version of this within about a year of each other.

Traveler's AI agent
01Proves identity via attestation, verifiable credential, or signed mandate
Card network
02Issues a token scoped to that agent, merchant, and spend cap
Merchant / acquirer
03Validates the token at checkout - no CAPTCHA or OTP required
Issuer / settlement
04Settles the transaction; handles disputes under network-specific rules

"Token" actually covers two different jobs here, worth separating. Visa's Trusted Agent Protocol is a recognition layer - a cryptographic signature that tells a merchant "this is a real, sanctioned agent, not a bot," built on standard HTTP message signatures. It doesn't move money. The actual spending credential is a separate, scoped payment token - issued through Mastercard Agent Pay, Visa Intelligent Commerce, or American Express's own ACE developer kit - that caps what the agent can spend, where, and for how long.

April 2025
Mastercard launches Agent Pay with Microsoft, IBM, and Braintree.2
October 2025
Visa publishes the Trusted Agent Protocol specification.3
January 2026
Google unveils the Universal Commerce Protocol at NRF.4
April 2026
Amex launches its ACE developer kit, plus purchase protection for registered-agent errors.5
What happens when a payment fails? Card networks already fine repeat failed attempts on the same card - Visa assesses a per-decline fee after 15 failed attempts within 30 days, Mastercard after 10 attempts within 24 hours - which puts a built-in brake on an agent that just keeps retrying.6 What's not standardized: whether or how the traveler is alerted in the moment. That's currently left to each agent platform's own product design, not mandated by any card-network spec.
What if the merchant doesn't accept agent payments yet? Recognition protocols like TAP are opt-in for merchants. Without it, an agent's traffic looks like anonymous bot traffic to that merchant's fraud systems - it can get blocked, CAPTCHA-challenged, or silently fail, and today the agent typically hands control back to the traveler to finish the booking manually. There's no standardized fallback across networks yet; it depends on how each merchant's fraud stack is tuned.
03 - Consent & control

The cardholder sets the limits. Who they hand that job to is a bigger decision than it looks.

Neither the card network nor the agent invents the spending rules - a human always sets them. But where that consent gets captured differs by network, and that detail carries more weight for adoption than the specifications make it sound.

Mastercard: consent lives with the bank
  1. 01 Cardholder enrolls the agent inside their issuing bank's app
  2. 02 Sets the policy there - spend ceiling, merchant categories, expiration
  3. 03 The bank requests the token from Mastercard's token service on the cardholder's behalf
Live with Citi and US Bank cardholders since September 2025; full US rollout followed in November 2025, expanding globally through 2026.7
Visa: consent lives with the agent platform
  1. 01 Cardholder uploads the card directly to the AI agent, via Visa Payment Passkeys
  2. 02 Sets spend limits, merchant categories, and approval triggers inside that same platform
  3. 03 Visa Intelligent Commerce tokenizes the card and enforces the instructions from there
Live in the US for cards from most banks, per Visa's own developer documentation - the enrollment surface is the agent platform, not the issuer.8 9
Why this matters more than it looks
  • Enrollment UX becomes critical infrastructure - a clunky flow pushes cardholders to either over-grant permissions (fraud exposure) or under-grant them (the agent stalls constantly and the "autonomous" pitch falls apart)
  • Rollout is issuer-by-issuer, not network-wide - whether agentic commerce actually works for a given traveler depends on their specific bank's rollout status, not just the logo on their card
  • Merchant-category scoping is a genuinely open question for travel: Visa's own example sets a spend ceiling "for a hotel or an airline ticket" - a single trip spanning both could hit two separate limits, not one
  • The real-time approval option undercuts the full-autonomy pitch: most complete trip bookings will exceed a low pre-set threshold, meaning many "autonomous" bookings are really agent-shops, human-approves - at least for now
  • Whichever surface owns enrollment - bank app or agent platform - ends up owning the primary financial relationship with that cardholder. That's a bigger stake for banks and AI platforms alike than either side has said out loud yet
"$500 ceiling"
Visa's own example is travel

Mark Nelsen, Visa's global head of consumer products, described the model to PYMNTS using a travel example directly: a cardholder can set "a $500 ceiling for a hotel or an airline ticket," and the agent works within that constraint automatically.10

04 - Regulatory & fraud

Agents can now prove who they are. The bill for when they're wrong is still unsettled.

Recognition is the solved half of this problem - a merchant can now cryptographically confirm an agent is legitimate rather than a bot. Liability is the unsolved half: who's on the hook when a properly recognized agent still gets the transaction wrong depends on which rail it ran on, and today's default fraud rules were largely written for a human at a keyboard.

Cardholder
01Grants the agent a scoped mandate to transact on their behalf
AI agent
02Completes checkout - no CAPTCHA, OTP, or biometric step possible
Card network
03Classifies the transaction - card-not-present by default, unless a validated token program applies
Merchant
04Holds the liability by default, unless a validated token program shifts it Where the exposure concentrates
Is this the same across every network and agent? No. Mastercard's token-validated flow (Agent Pay / Agentic Tokens) keeps the issuer on the hook and preserves the cardholder's normal chargeback rights - the same protection as an ordinary card-present dispute. Visa's Trusted Agent Protocol, by contrast, is a recognition layer, not yet a liability-shifting one: a transaction can be provably agent-initiated and still default to ordinary card-not-present treatment. American Express has gone further than either on paper: its April 2026 ACE launch came with a pledge to "protect eligible customers from charges related to AI agent error" on registered agents - a voluntary consumer commitment, not a rule that binds merchants the way Mastercard's token program does. Non-card rails - Google's UCP, OpenAI and Stripe's Agentic Commerce Protocol - each set their own terms again. There's no single industry answer yet; it depends on which rail carried the transaction.
A related wrinkle for merchants Mastercard began assessing its mail/telephone-order fee on all authorizations, including declines, starting January 2026. That's a general interchange change, not something written specifically for AI agents - but it raises the stakes of a poorly-tuned agent generating repeat failed authorizations on a merchant's account.11
0
What this means for merchants - United States

Zero: the number of federal exemptions carving AI-driven transactions out of existing consumer-protection law. The CFPB has stated that AI-driven financial tools remain fully subject to existing law, with no exception for new technology.12 13

In practice: a merchant that accepts agent-initiated payments is bound by the same consumer-protection and UDAAP obligations as any other checkout. "The AI did it" isn't a liability shield - if a booking is completed incorrectly, standard remedies still apply, and the burden of proving proper authorization still runs through the merchant's own systems.

The "is this the same everywhere" question isn't just about which network carried the transaction - it's also about which jurisdiction the transaction happened in. The US and EU are heading toward genuinely different liability models, on genuinely different timelines.

United States: no exemption, no new clarity
  1. 01 The CFPB has said AI-driven financial tools remain fully subject to existing consumer-protection law
  2. 02 No federal framework written specifically for autonomous-agent transactions exists yet
  3. 03 Liability still defaults to whichever network rail carried the transaction - see above
The whole US answer, for now, is existing law applied to a new fact pattern - not a dedicated agentic-payments rulebook.
European Union: a real liability shift, not built for agents
  1. 01 The Payment Services Regulation (PSR) shifts fraud liability onto the payment service provider whenever it failed to run adequate fraud-prevention and authentication checks - regardless of whether the customer "authorized" the payment in a narrow technical sense
  2. 02 Extends mandatory payee-name verification, already required on instant euro transfers, to ordinary transfers
  3. 03 Requires PSPs to share fraud intelligence with each other
None of it was written with autonomous agents in mind. PSR applies directly across the EU without national transposition, but its own transition period pushes first enforcement to roughly the second half of 2027.14 PSD3, its companion directive covering licensing and supervision, still needs national transposition - targeted for 2027–2028.15 A single EU-wide agentic-payments answer won't fully exist until then.16
05 - Industry impact

Automation eats the middle of the market first.

The instinct is to assume agents flatten the whole industry evenly. What's actually showing up is a split: the most commoditized bookings automate fastest, while both the most human-dependent and the most loyalty-anchored segments hold their ground.

Automation pace: Fastest Fast Gradual Human-led
Roadside & economy
Simple, price-driven, low customization - the easiest booking for an agent to complete end to end.
Fastest
Retail & leisure direct
Individually booked trips through OTAs and direct channels - a natural fit for agent-led comparison shopping.
Fastest
Corporate transient
Rules-based and policy-bound, which favors automation - but approval workflows and TMC checkpoints add friction (see Section 01).
Fast
Travel agent-assisted
AI becomes the advisor's tool, not the client's - reshaped into a co-pilot role rather than replaced.
Fast, as a co-pilot
Group travel
Multiple travelers, block coordination, and negotiated rates - AI can assist logistics, but a single agent booking the whole group unattended is a harder problem.
Gradual
Wedding & events
Highly bespoke, emotionally significant, many stakeholders and vendors to coordinate - low agent-autonomy tolerance.
Human-led
Luxury & bespoke
Co-designed, iterative, trust-dependent - expertise and relationship are the product, not just the booking.
Human-led
Directional assessment based on how rules-based versus judgment-dependent each segment is today - not a sourced forecast.
How can travel agents use AI to better care for clients, rather than compete with it?
  • Let AI assemble the pre-trip research packet, freeing the advisor's time for the higher-touch parts of planning
  • Use AI to monitor active bookings for disruptions and rebooking options, with the advisor reviewing before anything is confirmed
  • Track fare drops, loyalty-award availability, and price changes automatically for existing clients - a retention play, not just an acquisition one
  • Speed up quote turnaround for group and wedding blocks, while the advisor still owns the final vendor negotiation
Directional analysis, broadly consistent with WiT's 2026 reporting on corporate travel, which describes advisors leaning into human-centric service as automation absorbs the routine work.17
The reframe

Whoever owns the trust layer - the token, the identity check, the liability chain - owns the booking. Owning the inventory is no longer enough.

Where this goes next

Personalization, loyalty, and pricing all run through the same question.

Every one of these depends on whether a brand exposes clean, structured data for an agent to reason over - or leaves an agent guessing.

Personalization

IDC projects that by 2030, 30% of travel bookings will be executed directly by AI agents - which only works if brands expose accurate guest data for an agent to act on, not just for a human to browse.18

Loyalty

Business travelers surveyed for Direct Travel's 2026 forecast describe loyalty as less about points and more about experiences that fit how they actually travel - a harder thing for an agent to shop around on price alone.17

Promotions

33% of travelers already expect individually tailored communication, and brands that deliver it can command up to a 20% price premium.19

Dynamic pricing

More than 60% of travel businesses are already experimenting with or scaling AI-driven dynamic pricing, per Phocuswright - raising the stakes on pricing transparency once an agent, not a person, is the one comparing rates.20

Next step

Rethinking how your payments or booking stack handles agentic traffic?

Open to conversations about VP and Director roles in loyalty, travel, and payments - and to advisory conversations on where agentic commerce is headed next.

References
  1. PwC, "The future of agentic commerce for travel," Holiday Outlook survey. pwc.com (accessed August 2026)
  2. Mastercard Agent Pay overview. eco.com (accessed August 2026)
  3. Visa Developer, Trusted Agent Protocol specifications. developer.visa.com (accessed August 2026)
  4. Skift, "Google UCP." skift.com January 11, 2026
  5. PYMNTS, "American Express to back purchases made by customers' AI agents." pymnts.com April 2026
  6. TD Bank, excessive transaction attempt fee schedule. td.com (accessed August 2026)
  7. Eco, "Mastercard Agent Pay Explained." eco.com (accessed August 2026)
  8. Visa Acceptance Developer Portal, Intelligent Commerce. developer.visaacceptance.com (accessed August 2026)
  9. Basis Theory, agentic payments documentation. developers.basistheory.com (accessed August 2026)
  10. PYMNTS, "Visa Powers AI Shopping Agents With Intelligent Commerce Payment Rails." pymnts.com 2025
  11. Merchant Cost Consulting, "2026 Interchange Updates." merchantcostconsulting.com (accessed August 2026)
  12. Consumer Financial Protection Bureau, "Advanced Technology." consumerfinance.gov (accessed August 2026)
  13. Skadden, summary of the CFPB's 2024 AI comment. skadden.com August 2024
  14. Freshfields, "PSD3/PSR: what the EU's new payments rules mean for your business." freshfields.com (accessed August 2026)
  15. DLA Piper, "PSD3 and the PSR." dlapiper.com March 2026
  16. Ping Identity, "The road to PSD3/PSR compliance." pingidentity.com (accessed August 2026)
  17. WiT, "AI, loyalty leakage, and human-centric tech in corporate travel's new equation." webintravel.com 2026
  18. IDC, FutureScape 2026. idc.com (accessed August 2026)
  19. Simon-Kucher, "AI in the travel industry: paving the way to better growth." simon-kucher.com (accessed August 2026)
  20. RateGain, "AI-powered pricing strategies." rategain.com (accessed August 2026)

Industry analysis; not legal or compliance advice. August 2026