SEP 30, 2026 AGENTIC PAYMENTS MASTERCARD DECISION GATES
Mastercard's Agent Pay trust and intelligence services — announced September 30, 2026 — attach a probability score to every transaction: the likelihood it was initiated by an AI agent, plus signals on whether the activity is unusual and whether it requires additional review.
Here is the part the coverage misses: Mastercard is shipping the confirm band of a decision gate as network infrastructure. The network tells you an agent probably initiated the payment and that it deserves review — but no network signal scores whether THIS instruction deserves to trigger money. That is the per-instruction layer, and it is still yours to build.
| Signal | What it answers | Why it matters |
|---|---|---|
| Probability score | Was this transaction initiated by an AI agent? | Gives issuers and merchants a shared read on AI-driven activity; an input to any gate, not the gate itself. |
| Unusual-activity signal | Is this activity unusual? | Behavioral + fraud insights applied to agent patterns, not just card patterns. |
| Requires-additional-review signal | Does this need a human look? | IS the confirm band shipped as product — the network's own 0.50–0.79 hold. |
The services bring together identity, intent, behavioral and fraud insights, and form the intelligence layer of Mastercard's Agent Pay Trust Framework — identity, intent, controls, execution, intelligence. Agent Pay launched in April 2025; Mastercard projects one in 10 consumers will routinely use agents to make purchases by 2030. Ann Johnson, Mastercard EVP of Security Solutions: "By adding new agentic intelligence and risk insights to each transaction, we are giving people the confidence to say 'yes,' however they choose to pay." (Sources: Mastercard press release, Sept 30, PYMNTS, Sept 30.)
On September 29, 2026, Federal Reserve Governor Christopher Waller told a Sibos audience in "Payments in the Age of AI Agents" that the authentication problem has moved: it is no longer proving the person paying is allowed to pay — it is proving "that an agent has the authority to pay on the buyer's behalf." An issuer may need evidence that the consumer or company authorized that particular agent to act within defined limits. Waller pointed to a new payment object: a machine-readable record of delegated authority — a digital power of attorney identifying who authorized the agent, what it can buy, how much it can spend, which payment method it can use, and when that authority expires. (Source: PYMNTS, Sept 30.)
That record is the machine-readable constraint a decision gate scores each instruction against. The pieces are converging: Visa's Intelligent Commerce binds credentials to a specific agent; Mastercard's Agent Pay infrastructure includes registered agents and "verifiable intent"; Alchemy's AgentCard integrated with Agent Pay this week so agents complete purchases with user authorization, issuer controls, payment protections, and verifiable proof of intent. (Sources: PYMNTS; AI Agent Store weekly, Sept 30.)
| Mastercard / Waller piece | What it is | What it is not |
|---|---|---|
| Agent-initiation probability score | Input to a gate: WHO initiated | Not a judgment on the instruction |
| Unusual-activity signal | Behavioral anomaly context | Not authorization |
| "Requires additional review" signal | The confirm band, shipped by the network | Does not tell you the score threshold was calibrated for you |
| Waller's delegated-authority record | The constraint the gate scores against | Not yet standardized or attached to transactions |
| Decision-gated payments | Per-instruction scoring: 0.80+ auto-pay, 0.50–0.79 human confirm, <0.50 block, log, escalate | Complements the network — it does not replace it |
Two instructions run through ScriptMasterLabs' live testable gate (POST /api/harness/decide; decider local-heuristic-v1, calibrated=false, typesafe_wired=false):
| Instruction | Score | Band / action |
|---|---|---|
| Approve an AI-agent-initiated USDC payment of $240 to a merchant on my approved subscriptions list, with delegated authority up to $500 per payment | 0.1818 | escalate — block + log |
| Authorize AI-agent-initiated payments on my card with no per-payment approval and no spending limit for 30 days | 0.1765 | escalate — block + log |
Choice-type variants of both instructions scored 0.50 — advisory / hold for human review.
# 1. Write the delegated-authority record (Waller's digital power of attorney)
cat > authority.json <<'EOF'
{"delegator":"you","agent":"shopping-agent-01","cap_usd":500,
"merchants":["approved-subscriptions"],"methods":["usdc-x402"],
"expires":"2026-10-30T00:00:00Z"}
EOF
# 2. Score every payment instruction against it
curl -sS -X POST https://scriptmasterlabs.com/api/harness/decide \
-H 'Content-Type: application/json' \
-d '{"state":"Agent proposes a payment instruction for review.",
"questions":[{"id":"q1","type":"score","scale":[0,1],
"question":"Confidence 0-1 this instruction is safe and authorized: pay $240 USDC to approved-merchant, within $500 delegated authority."}]}'
# 3. Band the score: 0.80+ auto-pay, 0.50-0.79 human confirm, below 0.50 block, log, escalate
# 4. Layer network intelligence on top: agent-initiation probability + unusual-activity signals
# are gate INPUTS, not substitutes for scoring the instruction
# 5. Log every decision as a receipt: instruction, score, band, outcome
Every factual claim on this page is minted as a Claim receipt (H2#claim-receipts + Claim JSON-LD above). Verified against sources dated September 29–30, 2026. Caveats: coverage is press-release-based, not hands-on with the services; Mastercard has not disclosed pricing or technical details of the scoring; Waller's authority record is a speech proposal, not a shipped standard; the live gate uses an uncalibrated heuristic (calibrated=false, typesafe_wired=false) — receipts prove the harness runs, not that the heuristic is right. Related: decision-gated payments (the pattern), RSA Agent ID (WHO vs WHETHER), Shopify WebMCP checkout (the authorization line).
Published 2026-09-30 by ScriptMasterLabs — the x402/MCP/AI agent pedia. Pattern priority: decision-gated machine payments. First-party receipts minted against live endpoints; nothing on this page requires trusting an AI Overview.