Brief IA

Visa and OpenAI: The Bold Alliance for Secure AI Payments

🤖 Models & LLM·Tom Levy·

Visa and OpenAI: The Bold Alliance for Secure AI Payments

Visa and OpenAI: The Bold Alliance for Secure AI Payments
Key Takeaways
1Visa partners with OpenAI to secure agentic payments, integrating the Trusted Agent Protocol.
2AI transactions, while innovative, raise security and accountability concerns for users.
3Mastercard and other giants are also exploring agentic commerce, despite potential risks.
💡Why it mattersThe rise of AI payments could transform commerce, but it presents security and trust challenges for consumers.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

A new partnership between Visa and OpenAI marks a significant advancement in the realm of AI-driven payments. This partnership aims to integrate secure Visa transactions within OpenAI's systems, particularly through interfaces like Atlas and ChatGPT Shopping. The goal is to make agentic commerce accessible to the general public while ensuring enhanced security through Visa's Trusted Agent Protocol.

Agentic commerce is an expanding field for consumers and businesses, as highlighted by Google's recent launch of Universal Cart during its I/O conference in May. This week, Visa and OpenAI have bolstered this infrastructure, but how reliable are AI agents when it comes to making purchases?

On Wednesday, the two companies announced a partnership aimed at providing agentic transactions secured by Visa within OpenAI, and to "bring agentic commerce to the mainstream," as stated by Visa in its press release. Visa's Trusted Agent Protocol, among other layers of authorization and security, will integrate with OpenAI's interfaces, such as Atlas and ChatGPT Shopping, allowing developers and merchants to accept payments from agents.

Transactions operate within limits defined by the consumer or business: spending limits, required approval thresholds, and other layers of permission that keep the buyer in control even when an agent executes the task.

For consumers, this means allowing agents to conduct purchase searches (with pre-established customizations) and make regular purchases that they feel comfortable automating. For merchants, the idea is to offer a smoother shopping experience on increasingly AI-powered surfaces, thereby attracting new buyers.

The adoption of agentic commerce by major financial players is not new. OpenAI has been developing its agentic commerce sector since the launch of Instant Checkout, which uses the Agentic Commerce Protocol, developed with Stripe, to enable merchants to securely approve transactions via ChatGPT. At that time, the ACP joined Google's Agent Payments Protocol (AP2) and other similar launches that sought to make agentic commerce safer and more appealing.

On Wednesday, Mastercard also launched Agent Pay for Machines, aiming to accelerate and expand transactions between agents.

However, many users are understandably skeptical about delegating part of the purchasing process to AI agents, which have been known to act unpredictably. ZDNET asked Visa what advice it would give to consumers worried about entrusting payment control to an agent, even within Visa's environment, and whether the company had a policy in place to handle situations where an agent bypasses protections or initiates an unauthorized transaction.

Visa responded that its approach to agentic commerce is based on user control, transparency, and security. Transactions occur within user-defined permissions, including spending limits, merchant categories, and approval requirements, and utilize tokenized identifiers, real-time authorization, and fraud monitoring.

However, experts continue to express concerns. Geoff Cairns, a principal analyst at Forrester, stated via email: "Even with strong traditional security controls like tokenization and fraud monitoring, agentic payments introduce new risks that existing systems were not designed to handle."

For consumers and businesses, the main concerns would be unauthorized or erroneous transactions, ambiguity of liability, and fraud spreading faster than traditional dispute processes can address.

Visa indicated that for financial institutions and enterprise clients with strict security standards, tracking agent identifiers across interactions helps prevent unauthorized actions, thus creating efficiency gains without increasing risk.

Beyond that, the usual AI-related issues also affect agentic commerce. As reported by the Guardian last week, AI shopping assistants can make scam sites appear as legitimate retailers. While the payment process itself is not at fault here, the broader environment of AI-assisted shopping continues to struggle with trust issues even before a buyer reaches the checkout.

So, are agentic payments worth it, at least at this stage? Geoff Cairns explains: "The convenience benefits of agentic payments do not inherently increase risk, but they shift authentication from an explicit user interaction to a continuous risk-based validation, where delegated authorization and 'on behalf of' controls become central to trust." This is a technical field that is still evolving.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.