The ghost is not the AI agent. It is the trust we assume exists between the card and the code.
Visa announced Agentic Ready, a certification program for issuers to handle AI-agent-initiated payments. 85 partners across five regions. A PoC in Germany where a consumer told an agent to buy groceries, and the transaction flowed through Visa Payment Passkeys, a standard authorization protocol, and settled. The prediction: millions of consumers using AI agents to shop by the 2026 holiday season.

Let me stop here.
During my time auditing ICOs in Nairobi, I learned to question the gap between narrative and code. The same principle applies here. The narrative is clear: agentic commerce is coming, and Visa is standardizing the on-ramp. But the code—the actual architecture of trust—has a fracture that runs deeper than most analysts are willing to see.
Tracing the echo of trust back to its source code, I find not a single origin, but a split.
Context: The Standard as a Defensive Move
Agentic commerce is still in the trough of disillusionment. Consumer data is brutal: only 14% trust an AI agent to make a purchase without verification. 42% reject any transaction over $25 initiated by an agent. This is not a technology problem. It is a trust problem. And trust is not a feature you can ship; it is a structure you must maintain.
Visa’s approach is to formalize the issuer side. The 99% of card processing systems that can technically handle agent-initiated transactions are not the same as 99% that can do so safely. The certification verifies card registration, tokenization, and authentication—three pillars that look solid when viewed from the network level. But when you zoom in, you see that the certification is a defensive move. The real battle is not Visa vs Mastercard (Mastercard is running a sandbox in the UK, which is a tactical follow, not a strategic difference). The real battle is against the possibility that agentic payments bypass the card network entirely—through open banking, A2A transfers, or BigTech’s closed loops.
Yield is not a number; it is a narrative of risk. Visa’s yield is the transaction volume from millions of agent-initiated purchases. But the risk is that the narrative of trust collapses before the volume materializes.
Core: The Double Dispute and the Shadow Agent
Let me walk through the technical architecture from the perspective of a structural integrity auditor.
A standard payment dispute has one question: “Was this you?”
An agentic payment dispute has three: “Did you authorize this agent?” “Did the agent execute as authorized?” “Was the agent hijacked?”
Each question introduces a new failure mode. The current fraud detection models are built on device fingerprints and behavioral biometrics of a human. When an agent executes the transaction, the human is not touching the device. The behavioral patterns vanish. The model goes blind.
But the deeper issue is what I call the shadow agent risk. The certification covers the issuer—the bank. It does not cover the agent developer. A consumer can download an agent from an app store, grant it a passkey, and that agent—built by a third party with unknown security practices—now has the ability to initiate payments. If that agent is compromised (prompt injection, malicious code, or simple logic flaws), the consumer becomes an unwitting money mule.
We minted ghosts, but we lived in the machine. The machine is the Visa network, the bank systems, the tokenization standards. The ghosts are the agents—unverified, unregulated, and uncertified.

Truth hides in the silence between the blocks. The silence here is the absence of any KYA (Know Your Agent) requirement in the Agentic Ready program. The certification is a necessary condition but not a sufficient one. Without agent-side certification, we are building a trust layer on a foundation of sand.
Contrarian: The Certification as a Single Point of Failure
The conventional wisdom is that Visa’s network effects and standard-setting power create a moat. I see a different picture: the certification creates a single point of failure.
If the Agentic Ready standard has a vulnerability—say, a flaw in how passkeys are bound to agent sessions—every certified issuer is exposed simultaneously. The risk is not distributed; it is concentrated. In traditional finance, standardization reduces risk. Here, standardization of an immature technology amplifies it.
Moreover, the certification approach assumes that the issuer is the right gatekeeper. But in agentic commerce, the agent is the gatekeeper. The consumer interacts with the agent, not the bank. The bank sees only the authorization request. The agent’s intent, its decision logic, and its vulnerability are opaque to the issuer. This is a structural blind spot that no certification can patch without including the agent layer.
Consider the regulatory dimension. The program spans five regions with different data protection laws. In the EU, the AI Act may classify agentic payments as high-risk AI, requiring conformity assessments. In CEMEA, data localization laws may conflict with Visa’s global tokenization standards. The result will be standard drift—a fragmentation of the uniform trust layer Visa is trying to build. Agents will seek the path of least regulatory resistance, creating a “regulatory arbitrage” that undermines the very consistency the certification aims to achieve.
Takeaway: The 2026 Holiday Season as a Referendum
Visa has placed a bet that by the 2026 holiday season, millions of consumers will trust AI agents with their payments. That bet is not just about technology adoption; it is about the industry’s ability to solve the trust problem before the first major incident.
The real test will not be whether the transactions go through. It will be what happens when a consumer’s agent buys something they didn’t want. Or when a shadow agent is exploited and thousands of accounts are drained in minutes. The dispute resolution infrastructure will be the canary in the coal mine.
I have spent 15 years watching narratives become code and code become law. The narrative of agentic payments is powerful because it promises to eliminate friction. But friction is where trust is built. Remove it all, and you remove the human check.
The ghost in the payment machine is not the AI. It is the assumption that we can standardize trust without understanding who is holding the key.