Around the world, the race to let AI agents make payments has been a corporate scramble, with Visa, Mastercard, Stripe, and others each building their own version. India is preparing to do it differently. According to reports, the National Payments Corporation of India is readying a framework that would let AI agents make small payments on UPI without asking permission for every transaction, and it would be baked into the country’s public payment rail rather than owned by any one company.
The scale is what makes it striking. UPI is the world’s largest retail fast-payment system, handling more than 24 billion transactions in a single month, worth over $300 billion, for roughly half a billion Indians. Wiring agentic payments into that rail would, at a stroke, create one of the largest AI-payment networks anywhere. The new standard, called the Unified Agent Protocol, is expected to be unveiled next week at the Global Fintech Fest in Mumbai, though the NPCI has not confirmed the details.
A shared standard, not a walled garden
The most telling detail is what India’s payment companies chose not to do. Rather than each build a rival protocol, the country’s big players have reportedly agreed to rally around the NPCI’s single standard. That is the opposite of the fragmented, company-by-company approach elsewhere, and it echoes exactly what made UPI itself a phenomenon: one open, interoperable rail everyone plugs into. It also leans on plumbing that already exists, UPI Circle, which lets an account holder delegate limited payment authority to someone, or something, else, and a feature that blocks a pot of funds for repeated debits. An AI agent simply becomes that trusted secondary actor, boxed in by limits the user sets.
The guardrails, at least on paper, are sensible: spending caps, identity checks, audit trails, and a design where the network verifies that an agent is authorised without necessarily inspecting what was bought. Early uses would be humble, groceries and routine e-commerce, before graduating to agents that hunt for discounts or invest at preset price thresholds.
The unsolved questions are the important ones
Here is where enthusiasm needs a check. UPI’s entire trust model was built around human beings and their phones. Agentic payments demand something new: proving not just who you are, but that your agent is legitimate and acting within the authority you gave it. That is a truly hard problem, and the hardest part of it, liability, is still a blank. The NPCI reportedly plans a liability framework but has not said what it will look like. When an agent overspends, misreads an instruction, or gets hijacked, who pays? Until that is answered clearly, the rest is scaffolding.
The scale that makes this exciting also raises the stakes. Handing spending power to software on a rail used by hundreds of millions, including many first-time and less tech-savvy users, is not a small consumer-protection question. The upside of a public standard is that safeguards can be built in for everyone at once; the risk is that a flaw is shared by everyone at once too.
So is India about to leapfrog the world in agentic payments, or racing into a problem no one has fully solved? Both, probably. The infrastructure instinct is right, and doing this as shared public rails rather than corporate silos is clearly smart. But an AI that can spend your money is only as trustworthy as the rules and the liability behind it, and those are the parts still being written.
















Comments