BeaconGuard Insights — Agentic Payments

Before an AI Agent Can Pay: What NPCI Is Separating Before Settlement

NPCI's emerging agentic-payment design separates an AI agent's interpretation of user intent from the controls that verify mandate, limits, consent, and authorization before payment settlement.

Modern Authorization Lock canal metaphor: AI agent vessel delivering payment intent approaches an independent AUTHORIZATION gate checking Identity, Mandate, Limits, and Consent; Evidence Control Log and SETTLEMENT beyond; BeaconGuard Insights branding; no NPCI or UPI logos.
The agent can navigate. It does not control the lock.

Executive Summary

What is changing

Agentic payments are often framed as a new checkout experience. The more consequential change is architectural: before a payment rail moves money on an agent’s behalf, it must separate the agent’s interpretation of user intent from the controls that verify mandate, limits, consent, and authorization — and from settlement finality.

Where the control boundary sits

In NPCI’s emerging agentic-payment discussion, three functions remain distinguishable even when the user experiences one automated workflow: intent interpretation (agent derives a proposed transaction), authorization controls (whether that specific transaction fits established delegation), and settlement (the rail executes and finalizes). The agent can navigate inside standing authority; the rail does not have to treat the agent’s own interpretation of intent as sufficient authorization for the debit.

What financial institutions should ask

Where is delegation created and machine-readable? Where are limits evaluated before the consequential debit? How does revocation propagate? What exactly is bound to the allow decision? What evidence survives so a reviewer can reconstruct authority, constraints, and transaction facts at execution time?

Agentic payments are often described as a new checkout experience: tell an AI what you want, let it find the option, and allow it to pay. The more consequential change is underneath that experience.

Before a payment rail can move money on an agent's behalf, it has to answer a different class of questions. Which principal authorized the agent? What mandate exists? What limits apply to this transaction? Is the relevant consent still valid? And which component is responsible for turning an allowed transaction into final settlement?

That separation is becoming explicit in India's Unified Payments Interface (UPI) ecosystem.

At Global Fintech Fest 2026, Ajay Kumar Choudhary, non-executive chairman and independent director of the National Payments Corporation of India (NPCI), said NPCI was examining protocols to identify and authorize digital agents within UPI while preserving interoperability, auditability, and settlement finality. In contemporaneous reporting of his remarks, Choudhary said the authorizer must verify identity, mandate, limits, and consent, and described an architecture that separates intent, authorization, and settlement.[1]

That is the article-specific signal. It is not merely another statement that AI systems need security controls. It is a financial-execution architecture in which three functions remain distinguishable even when the user experiences them as one automated workflow:

  1. an agent interprets the user's objective and derives a transaction;
  2. authorization controls determine whether that specific transaction fits an established delegation; and
  3. the payment rail performs and finalizes settlement.

An AI agent can participate in execution. What the rail does not have to do is treat the agent's own interpretation of the user's intent as sufficient authorization for the debit.

NPCI is the payments infrastructure organization behind UPI, not India's regulator. NPCI's own UPI materials describe UPI as an instant payment system developed by NPCI, an RBI-regulated entity.[2] Its August 2026 statistics report 24,508.96 million UPI transactions across 752 live banks, worth ₹29,82,355.95 crore.[3] At that scale, the placement of authorization controls is infrastructure design, not merely an application-level UX decision.

Financial execution is being decomposed

An AI agent may understand that a user wants groceries below a budget, identify a merchant, compare alternatives, wait for a sale condition, and select the transaction that best satisfies the goal.

Those reasoning capabilities do not, by themselves, answer the payment system's control questions.

A payment authorizer still needs trusted inputs that establish whether the proposed debit fits authority that actually exists at that moment. Choudhary's reported formulation is concrete: identity, mandate, limits, and consent belong in that verification step.[1]

A useful way to read the emerging architecture is therefore:

Layer Function Core question
Intent interpretation Convert a user objective into a proposed transaction or execution plan What transaction best satisfies the user's objective?
Authorization controls Evaluate identity, delegation, mandate, consent, lifecycle state, and applicable limits Is this specific transaction permitted under authority that is valid now?
Settlement Commit the financial state change according to payment-system rules Can this authorized transaction be executed and made final?

The distinction does not require a human to approve every transaction. Agentic payment systems are specifically exploring the opposite: a user establishes authority in advance, and the agent later initiates or completes qualifying transactions without fresh approval each time.

The important boundary is that delegated autonomy operates inside independently established constraints. Agent execution and independent authorization are compatible. They are different functions.

Claim boundary: Choudhary's remarks are an attributed public statement carried by secondary reporting. They support the architectural separation described above. They are not a published NPCI technical specification for a finalized agentic protocol.[1]

Figure 1 - Inside the Authorization Lock. The agent can initiate a proposed payment request, but independent controls evaluate Identity, Mandate, Limits, and Consent before evidence is recorded and the approved payment proceeds to settlement.

The control lineage predates the 2026 agentic-payment discussion

The September 2026 discussion is not NPCI's first move toward software-mediated payment delegation.

On October 8, 2025, NPCI published UPI Operating Circular NPCI/UPI/OC-201B/2025-26, extending UPI Circle's Full Delegation framework to IoT devices and software profiles. The circular explicitly lists AI Profiles among the software-profile examples, initially for limited users.[4]

The circular's significance is not that it defines a 2026 agentic-payment protocol. It does not. Its significance is that it shows an existing first-party control lineage for non-human or software-mediated delegation.

OC-201B requires, among other controls:

  • user consent before linking and authorizing a device or software profile, with two-factor authentication;
  • defined monthly and per-transaction limits;
  • lifecycle management, including limit management and delinking;
  • validation of device or user-profile identifiers during registration and payment requests;
  • security controls and due diligence for participating apps and payment-service providers; and
  • issuer-bank validation of device/user identity and requisite authorization details for every transaction before the account is debited.[4]

That lineage matters because it changes the framing. The story is not that NPCI suddenly discovered in September 2026 that software needs payment controls. NPCI already had a documented mechanism for delegating bounded payment capability to software profiles.

The newer signal is broader: as agents become capable of interpreting objectives and completing transactions, the infrastructure discussion is separating the agent's decision process from the authorization and settlement functions that financial finality depends on.

OC-201B should also not be stretched beyond what it says. It is not evidence that a finalized Unified Agentic Protocol has been publicly specified. No published NPCI technical specification for such a finalized protocol was identified in the sources reviewed for this article.

A live example: autonomy after prior authorization

A first-party BLIK pilot from Poland shows the same architectural tension from a different payment ecosystem.

On September 9, 2026, BLIK reported that an AI agent independently completed a purchase without the user's involvement at the moment of transaction. The user had provided a prior instruction and granted payment consent in the banking app. When the specified product became available, the agent completed the purchase under the previously defined conditions. BLIK states that the agent operated within prior payment consent, defined spending limits, and specified conditions.[5]

This does not establish that BLIK and UPI use the same architecture. It does establish something narrower and useful: autonomous execution can happen after authority has been created in advance.

That changes the design question for enterprise systems. The choice is not simply between "human approves every action" and "agent acts without controls." A third model is increasingly important: the human or enterprise principal establishes a bounded authority envelope, and the system evaluates each later execution against that envelope.

For payments, that envelope can include merchant scope, amount limits, cumulative limits, time windows, device or agent identity, lifecycle state, and revocation. In other domains, the relevant constraints will differ, but the control problem is structurally similar.

What is public versus what remains reported development

A second evidence tier surrounds NPCI's current agentic-payment work and should remain separate from the stronger evidence above.

Reuters reported on September 1, citing three unnamed sources familiar with the matter, that India was preparing a framework for agentic UPI payments and that the proposed design could draw on UPI Circle and Reserve Pay, with rule-based instructions, spending limits, identity checks, audit trails, and a liability framework.[6]

On September 10, Reuters separately reported, again citing unnamed sources, that NPCI was developing an AI-agent registry associated with a planned agentic protocol.[7]

Those reports add useful context. They do not carry the same evidentiary weight as NPCI's published circular or Choudhary's on-record remarks.

The strongest public claim that can be made today is narrower: NPCI leadership has publicly described the need to identify and authorize digital agents, verify identity, mandate, limits, and consent, and keep settlement finality distinct from the agent's interpretation of intent.[1]

The exact mechanics, naming, registry structure, implementation timeline, and production status of any future agentic protocol should remain attributed reporting until NPCI publishes the relevant specification, operating circular, or other first-party artifact.

Payments show both the opportunity and the compression risk

For enterprise AI, the important lesson is architectural rather than promotional.

Payments infrastructure has a major advantage over many enterprise environments: the rail can encode domain-specific authorization semantics itself. It can understand payer accounts, mandates, limits, participating banks, revocation, reconciliation, transaction state, and settlement finality. A payment network can therefore place purpose-built authorization controls directly in the payment path.

That creates an important boundary for the broader authorization-assurance category. If a payment rail already provides all of the controls an enterprise needs for a payment-only workflow, another external authorization layer may add little value in that path.

This is the payments-native compression risk. It should not be hidden. The emergence of native agent authorization inside payment rails can simultaneously validate the importance of the control problem and reduce the need for a separate product inside that specific domain.

BeaconGuard's relevant category is broader: authorization assurance for consequential AI actions across enterprise systems where equivalent native infrastructure does not exist, or where authority must remain coherent across multiple systems and execution domains.

That may include financial actions, but it also includes data release, workflow approval, account changes, infrastructure operations, regulated-system mutations, and other actions where a target system may expose credentials and APIs without exposing a complete agent-specific delegation and authorization model.

NPCI is not endorsing BeaconGuard, and this article does not imply that BeaconGuard is a UPI or payment-authorization product.

The category signal is more general: once software can act autonomously, infrastructure owners have to decide where authority is represented, how it is constrained, how changes and revocations propagate, and what evidence survives after execution.

Identity is necessary, but it is only part of the decision

The payment architecture also clarifies the role of identity and IAM.

Strong identity, authentication, device validation, IAM policy, agent registries, and cryptographic credentials can all be important inputs. OC-201B requires identity and registration checks for linked devices or software profiles, and Choudhary's reported remarks explicitly include identity among the elements an authorizer must verify.[1][4]

But identifying the actor does not determine the full decision.

A payment authorization also depends on the relationship among the principal, the delegated agent, the mandate, current consent, transaction-specific constraints, and the action being attempted. Lifecycle state matters as well: an authorization that was valid yesterday may have been narrowed or revoked today.

For enterprise architects, the more useful object is therefore not simply an agent identity. It is the full binding:

principal → delegated agent → permitted action → applicable constraints → authorization decision → execution evidence

That is where agentic systems become control systems rather than merely model integrations.

Questions enterprise buyers should ask

The payments case makes several discovery questions concrete:

  1. Where is delegation created? Is it explicit, machine-readable, attributable to a principal, and separable from the agent's own reasoning?
  2. Where are limits evaluated? Are they enforced before the consequential action, or merely detected afterward?
  3. How does revocation work? Can authority be narrowed or withdrawn immediately, and will every execution path observe the change?
  4. What exactly is bound to the decision? Agent identity alone is insufficient if authorization is not tied to the action, target, amount, merchant, time window, workflow state, or other relevant facts.
  5. Who bears responsibility when the agent acts inside formal limits but against the user's actual interest? That is partly an authorization question and partly a liability, product-design, and dispute-resolution question.
  6. What evidence survives? Can a reviewer reconstruct which authority, constraints, identity signals, and transaction facts produced the allow decision at the time of execution?

Payments make those questions visible because settlement is concrete. Money moves, balances change, disputes occur, and responsibility has to be allocated.

Other enterprise actions can be equally consequential without a payment rail's built-in vocabulary. That is where the same architectural separation becomes useful outside finance.

The signal to watch

The most important development in NPCI's public agentic-payment discussion is the decomposition of financial execution.

An AI agent may interpret a user's objective. It may select the transaction. It may initiate or complete the payment inside a standing delegation. But before funds move, the infrastructure still needs a defensible answer to a separate question: does this specific transaction fit the authority that exists right now?

After that decision, settlement remains another function with its own rules and finality.

That architecture is materially different from simply making a chatbot capable of paying. It turns mandate, limits, consent, identity, lifecycle, and transaction state into enforceable infrastructure around autonomous execution.

For enterprise leaders, that is the useful question to carry beyond payments: when an AI system acts, can the organization establish—at execution time—why this action was permitted, under which authority, within which constraints, and with evidence that remains reconstructable afterward?

Source notes and claim tiers

Research provenance: Candidate research date: 2026-09-14. Evaluation date: 2026-09-16. Correct packet age at evaluation: 2 days, not 0. Public sources below were re-checked during authoring on 2026-09-16.

  1. ATTRIBUTED FACT — secondary reporting carrying on-record NPCI leadership remarks. The Economic Times, “NPCI working on protocols to authorise AI agents on UPI, says chairman Ajay Kumar Choudhary,” 10 Sep 2026. Supports the claims that NPCI is examining protocols to identify/authorize digital agents, that an authorizer must verify identity, mandate, limits and consent, and that intent, authorization and settlement should be separated. This is not a first-party NPCI technical specification. MediaNama S-001 is classified the same way: secondary reporting containing on-record quotations, not a primary source. Retrieved/re-checked 16 Sep 2026.
    https://economictimes.indiatimes.com/ai/ai-insights/gff-2026-npci-working-on-protocols-to-authorise-ai-agents-on-upi-says-chairman-ajay-kumar-choudhary/articleshow/133998036.cms
    https://www.medianama.com/2026/09/223-npci-ai-agents-upi-payments/
  2. FIRST-PARTY — NPCI product background. NPCI's UPI page states that UPI is an instant payment system developed by NPCI, an RBI-regulated entity. This supports classifying NPCI as payments infrastructure/operator rather than the regulator. Retrieved/re-checked 16 Sep 2026.
    https://www.npci.org.in/product/upi
  3. FIRST-PARTY — NPCI statistics. NPCI UPI Product Statistics for August 2026: 752 live banks; 24,508.96 million transactions; ₹29,82,355.95 crore in value. Retrieved/re-checked 16 Sep 2026.
    https://www.npci.org.in/product/upi/product-statistics
  4. FIRST-PARTY — NPCI operating circular. NPCI/UPI/OC-201B/2025-26, dated 8 Oct 2025, “Addendum to NPCI/UPI/2024-25/OC 201 – Introduction of IoT devices & software on UPI Circle.” The circular extends Full Delegation to IoT devices and software profiles including “AI Profiles,” and specifies consent/2FA for linking, limits, lifecycle management and delinking, registration validation, security requirements, and issuer-bank validation of requisite authorization details before debit. It is evidence of prior software/AI-profile delegation controls, not a published specification for a finalized 2026 agentic protocol. Retrieved and visually inspected 16 Sep 2026.
    https://www.npci.org.in/uploads/UPI_OC_No_201_B_FY_2025_26_Addendum_to_NPCI_UPI_2024_25_OC_201_Introduction_of_Io_T_devices_software_on_UPI_Circle_09ec83c893.pdf
  5. FIRST-PARTY CORROBORATION — BLIK. BLIK, “First pilot BLIK transaction completed independently by an AI agent,” 9 Sep 2026. BLIK states that the user authorized the process in advance and that the agent later completed the purchase without direct user involvement at transaction time, operating within previously granted payment consent, spending limits and specified conditions. Retrieved/re-checked 16 Sep 2026.
    https://www.blik.com/en/first-pilot-blik-transaction-completed-independently-by-an-ai-agent
  6. REPORTED DEVELOPMENT — anonymous-source Reuters reporting. Reuters, “India preparing rollout of agentic payments on UPI, sources say,” 1 Sep 2026. Three unnamed sources described a planned framework, possible use of UPI Circle and Reserve Pay, rule-based instructions, spending limits, identity checks, audit trails and liability concepts. NPCI did not immediately respond to Reuters' request for comment. These mechanics remain reported development, not a finalized NPCI specification. Retrieved/re-checked 16 Sep 2026.
    https://www.reuters.com/world/india/india-preparing-rollout-agentic-payments-upi-sources-say-2026-09-01/
  7. REPORTED DEVELOPMENT — anonymous-source Reuters reporting. Reuters, “India plans AI registry as it looks to roll out agentic payments, sources say,” 10 Sep 2026. Three unnamed sources described a planned AI-agent registry associated with an agentic protocol. This remains attributed reporting unless and until NPCI publishes the relevant first-party artifact. Retrieved/re-checked 16 Sep 2026.
    https://www.reuters.com/world/india/india-plans-ai-registry-it-looks-roll-out-agentic-payments-sources-say-2026-09-10/

Start with one consequential workflow

Evaluate where authorization should sit between an AI-initiated action and the system that ultimately executes it - without replacing the existing identity, access-management, or system-of-record controls.