Stopping Rogue AI Agents from Charging Your Cards: FIDO, Google and Mastercard Build Guardrails for Delegated Payments
As AI agents gain the ability to transact on behalf of users, the FIDO Alliance, Google and Mastercard are collaborating to create authentication and delegation standards that prevent unauthorized or runaway charges. Their work aims to establish secure, verifiable mechanisms for agent authorization, consent, and transaction control across devices and payment networks.
AI agents that can browse, negotiate, and buy on behalf of people promise major convenience but also introduce new failure modes - from accidental overspending to automated fraud and supply-chain abuse. The FIDO Alliance's expertise in phishing-resistant authentication, combined with Google's platform reach and Mastercard's payment rails, is aimed at defining technical patterns for secure delegation: how an agent proves its authorization, how payments are consented to, and how liability and revocation are managed.
For businesses, the immediate significance is twofold. First, merchants and payment processors must prepare for agent-initiated transactions that carry different risk characteristics than human purchases. Second, platforms and identity providers will need standards-based attestation and scoped credentials (think limited-purpose tokens or passkeys with time and amount bounds) so agents can act without exposing full account access. These standards will affect UX, fraud detection, dispute resolution, and contractual relationships across the ecosystem.
Leaders should treat this as a cross-functional exercise: product teams must design consent flows and granular scopes for agent actions; security teams should adopt phishing-resistant authentication (FIDO/WebAuthn, device attestation) and update fraud models to incorporate delegation signals; legal and payments teams need clarified liability frameworks with card networks and third parties. Pilot the approach with limited-scope agents (subscription renewals, simple reorders) before enabling high-risk purchases.
Actionable next steps: inventory where delegated transactions could occur, engage with standards bodies and networks to influence spec decisions, implement revocable scoped credentials, and instrument agent transactions for auditability and explainability. Businesses that move early to support secure delegation will both reduce risk and capture new commerce channels as agent-native purchasing becomes mainstream.
Original Source
WIRED
