Title: UPI’s Unified Agent Protocol: India Is Building the First Legal Person for Software
24.51 billion transactions per month. Roughly 49% of the world’s real-time payments. A national rail that already carries close to 85% of India’s domestic digital payments. And still, an AI agent cannot buy a cart of groceries without stopping to ask for permission.
That is not a lag in engineering. It is a lag in legal imagination. The most important infrastructure missing from the agentic economy is not faster models or better APIs. It is a rule for who answers when software spends money on behalf of a human and gets it wrong.
A new Reuters report claims that the National Payments Corporation of India is preparing a Unified Agent Protocol for UPI. Three sources, no formal confirmation. No final caps, no published liability matrix, no rollout date. The architecture, however, is becoming visible through the fog. The protocol would let AI agents make small digital payments without per-transaction human approval. It would borrow from UPI Circle, which already permits delegated payment authority, and Reserve Pay, which allows funds to be blocked for multiple debits up to roughly Rs 10,000 for 90 days. The innovation is not cryptographic. It is the decision to treat an agent as a formal participant rather than a fancy interface.
I have watched payment protocols fail before. During the 2017 ICO cycle, I reviewed more than 200 whitepapers. Most failed not because the token math was wrong, but because nobody had defined what happened after a bad transaction. The technical layer was clean. The social layer was empty. India is now trying to solve the social layer first.
This is why the Unified Agent Protocol matters beyond India. It is not an experiment in convenience. It is an experiment in liability.
The old problem was simple. A human taps, approves, and owns the consequence. The new problem is that an AI agent acts autonomously. It books a hotel. It orders a subscription. It buys a flight. The human is not in the loop at the moment of payment. So who is the counterparty to the bank?
UPI Circle solved the identity question by allowing a primary user to delegate payment authority to another human. The proposed protocol expands that same logic to software. An AI agent becomes a secondary user, not in the legal sense of citizenship, but in the operational sense of access. Reserve Pay solves the pre-authorization problem by locking funds for future debits. Combine those two mechanisms, and you have a machine account.
Do not underestimate how strange that is for a central bank-owned national payment system. Traditional card networks treat AI agents as a new kind of cardholder. India is treating AI agents as a new kind of account user. That is not the same thing. A cardholder has credentials. An account user has responsibilities. The distinction is where every future fight will happen.
The transaction cap will probably follow NPCI’s existing IoT delegation limits: Rs 5,000 per transaction and Rs 15,000 per month. Those limits are low enough to contain damage. They also reveal the real purpose of the initial rollout. This is not meant for high-ticket agentic commerce. It is meant for repeated, small-value, autonomous replenishment: groceries, medicines, transit, daily subscriptions.
That is a sensible runway. The worst possible way to introduce autonomous agents to national payment infrastructure is with a $5,000 airline ticket on day one. Start with the boring stuff. Let the machines buy the vegetables.
The Hidden Debate Is Liability
The most radical line in the proposed framework is not about transaction speed. It is the principle that liability follows control. If a bank controls authentication, the bank carries authentication failure. If a payment service provider controls execution, it carries execution failure. If a merchant misrepresents a product or price, the merchant carries that misrepresentation. And if an AI provider enables a transaction outside the authenticated instructions of the user, the AI provider answers.
This is a genuine institutional breakthrough. Most consumer payment systems still require the user to prove they were not negligent before receiving redress. The new framework appears to reverse that burden. Consumers should not have to identify which algorithm failed. Redress should come first. Attribution should come afterward.
That is easier said than done. In the real world, failures rarely respect clean lines. Imagine an agent that receives a prompt-injected instruction from a malicious webpage and books a product the user never requested. Is that authentication failure, execution failure, merchant misrepresentation, or AI misbehavior? In practice, it is all four at once.
The phrase “liability follows control” is elegant until control is distributed across a bank, a payment gateway, a merchant, and an AI model that no human fully understands. Then it becomes a legal war over telemetry.
From my work in institutional asset management, I have learned one thing about control. Control is not ownership. Control is the ability to demonstrate, after the fact, exactly where a decision originated. In human finance, that demonstration relies on signatures, voice recordings, and audit trails. In agentic finance, the demonstration relies on logs that an AI can generate, but cannot be held accountable for.
The question is not whether India can make an agent pay. The question is whether India can make an agent explain.
Card Rails Are Overlay. UPI Is Native.
The structural conflict in the global agentic payments market is now clear. Visa’s Trusted Agent Protocol and Mastercard’s Agent Pay are building agent commerce on top of existing card rails. They add cryptographic trust signals to a network that was designed for human merchants and physical cards. Their advantage is global reach. Their disadvantage is architectural debt.
India is doing the opposite. UPI is already the default digital payment method for most domestic transactions. Instead of layering agent logic on top, NPCI is considering a protocol that makes the agent native to the national rail.
Native versus overlay changes more than speed. Overlay networks inherit legacy dispute timelines, legacy merchant categories, and legacy assumptions about who holds the card. Native networks can redefine the unit of payment itself. In a native agent protocol, the payer is not a person with a phone. The payer is an instruction set with spending constraints, legal control, and a balance limit.
That is essentially stablecoin logic wrapped in sovereign settlement.
Crypto observers will look at this and say it proves the superiority of programmable money. I understand the temptation. But it proves something less comfortable for the crypto thesis. India is building agent-native money without requiring decentralized consensus. It is using a centralized national rail with legal accountability and explicit liability allocation. The result may be more robust than a smart contract, not because the code is smarter, but because the consequences are enforceable.
Code is law, but capital decides who writes it. In this case, capital is choosing the state.
The Forgotten Bottleneck: Error Attribution
The hardest technical problem in agentic payments is not authorization. It is attribution. When an agent makes a bad payment, the human victim cannot explain what happened. The agent cannot explain what happened. The only reliable evidence is the chain of instructions that led to the transaction.
In traditional finance, that chain is preserved through legal documentation. In agentic commerce, the chain is preserved through model inputs. Those inputs include user messages, merchant pages, API responses, and possibly hidden instructions buried in a product image. Attributing a decision to a specific cause is a machine learning research problem, not a compliance workflow.
No transaction limit will solve that. A liability framework can allocate blame in theory, but in practice it needs forensic transparency. If an AI provider cannot prove which model version made a decision, or which prompt led to that decision, then “liability follows control” becomes a slogan.
This is the blind spot of every optimistic agentic commerce announcement. They all promise control. None of them explain how control is audited.
Mastercard demonstrated its Agent Pay framework in February 2026 at the India AI Impact Summit. The demo involved banks and merchants like Swiggy and Zepto. It was an authenticated agentic transaction. It was impressive. It also happened in a controlled environment with a few dozen variables. The real environment will have billions of variables, including merchants who are actively trying to manipulate agents into buying things the consumer never wanted.
Let me be precise. The problem is not only malicious merchants. It is the ordinary friction of commerce: promotional offers that obscure terms, refund policies that change after purchase, and subscription renewals that are easier to start than to stop. An AI agent navigating those conditions is not solving a payment problem. It is solving a legal interpretation problem.
The proposed UPI protocol implicitly acknowledges this by keeping transaction limits low and requiring pre-blocked funds. That is a defensive architecture. It treats every agent as a possible source of error. That is the correct posture, but it will limit the commercial value of the first version. Groceries and cabs are not where the fees live. Cross-border settlement, corporate procurement, and high-value purchases are where the fees live. None of those will be safe in the first generation.
The Contrarian Read
Most market participants will interpret India’s move as proof that agentic commerce is coming faster than expected. I think the opposite is true. The Unified Agent Protocol reveals how far away we are from an open AI economy.
If agentic commerce were genuinely ready, it would not need a new protocol. It would simply use existing payment APIs with higher limits. The fact that India is designing a separate liability framework means the market has discovered that AI agents cannot be treated as consumers. They cannot consent. They cannot complain. They cannot be defrauded in a way that a court understands.
The deeper problem is that an AI agent has no subjective experience of being cheated. A human knows when a price is wrong. An agent knows only what it is trained to detect. Fraud against agents will not look like fraud against humans. It will look like token manipulation, hidden incentives, and adversarial prompts.
Risk is not what you don’t know. Risk is what you think you have controlled because you added a liability clause.
The countries that win the agentic economy will not be those with the most advanced AI models. They will be those with the most credible error attribution systems. India has an advantage because UPI is centralized and the NPCI can impose standards on all participants. But centralization also creates a single point of legal bottleneck. If the first major autonomous payment dispute reaches the courts before the framework matures, the resulting jurisprudence will last for decades.
The Only Number That Matters
Nobody will remember the first agentic transaction. They will remember the first unresolved dispute.
At the Global Fintech Fest in Mumbai, from September 8 to 11, the industry will gather around agentic AI, tokenization, and quantum security. Announcements will be made. Demos will be shown. The Unified Agent Protocol will be discussed as if it is inevitable.
It is not inevitable. The protocol will work only if India can build a dispute resolution layer that operates faster than an AI agent can repeat its mistake. That layer does not exist yet. It cannot be solved by model fine-tuning. It cannot be solved by blockchain settlement. It requires institutional design.

India’s UPI already processes more than 24 billion transactions per month. It already represents nearly half of global real-time payments. It has the scale to make agentic commerce a national default. But scale is a trap when the failure rate is measured in basis points. On 24 billion transactions, even a 0.001% agentic failure rate would produce hundreds of thousands of contested payments every month. Each contested payment requires evidence. Each piece of evidence requires interpretability. Each interpretable decision requires an AI that can explain itself.
The real test of the Unified Agent Protocol is not speed. It is whether India can make the machine legible to the law.
Volatility is the fee for admission to the future. But liability is the toll for crossing into machine commerce. India is about to find out who can afford to pay it.