From Conversational to Agentic Payments
Artificial Intelligence in payments isn't just one single concept; it's an evolution. The first step, which is already being rolled out, is 'conversational payments'. This allows users to instruct an AI chatbot, using natural language in English or Hindi,
to complete a transaction. For example, you could simply say, "Send ₹500 to my sister." The AI interprets the command and initiates a standard UPI transaction that you then approve. The next, more advanced step is 'agentic AI'. This is where an AI agent doesn't just follow a direct command but takes action on your behalf based on pre-set rules. Imagine telling your AI to order groceries every week within a certain budget or to automatically buy a flight ticket when the price drops below a specific threshold. The AI would complete the entire transaction, including payment, without needing your approval for that specific purchase.
The Challenge of Meaningful Consent
Giving an AI agent the power to spend your money introduces complex questions about consent. Currently, UPI transactions require a PIN for every payment, a clear act of explicit, one-time consent. With agentic AI, the model shifts to a broader, pre-authorised consent. You might give an agent permission to spend up to a certain limit for specific categories, but what happens when the lines get blurry? This is a key area regulators are focused on. The Digital Personal Data Protection (DPDP) Act, for instance, mandates that data collected for one purpose cannot be used for another without specific consent. This means a payment app can't use your transaction data to train a marketing AI without your permission. The Reserve Bank of India (RBI) is actively developing a framework, dubbed 'FREE-AI' (Framework for Responsible and Ethical Enablement of AI), to ensure that consent is managed properly and that financial institutions remain accountable for AI-driven outcomes.
Building the Guardrails: Proposed Spending Controls
To prevent an AI from going on an unsupervised spending spree, the National Payments Corporation of India (NPCI) is developing a 'Unified Agent Protocol' (UAP). This framework aims to create a secure environment where AI agents can operate within strict boundaries set by the user. Several mechanisms are expected to form the backbone of these controls. Users will likely be able to set specific rules, such as spending limits per transaction, daily or monthly caps, and approved merchant categories. The system is expected to include robust identity checks for the AI agent and maintain detailed audit trails for every transaction it performs. This protocol will likely build upon existing UPI features like 'UPI Circle', which allows delegation of payment authority, and 'Reserve Pay', which lets users block funds for future debits. For example, you could create a ₹5,000 reserve that your grocery-shopping AI is allowed to draw from over a month.
Regulatory Oversight and Liability
Both the RBI and NPCI are taking a proactive approach, aiming to establish rules before problems arise. The RBI's proposed FREE-AI framework is built on seven core principles, or 'Sutras', including trust, fairness, accountability, and safety. It recommends creating AI innovation 'sandboxes' for testing and proposes amendments to existing regulations covering cybersecurity, digital lending, and fraud detection to specifically include AI. A critical piece of the puzzle that is still being developed is the liability framework. If an AI agent makes a mistake, exceeds its authority, or is compromised, who is responsible? Is it the user, the bank, the payment app, or the AI developer? The UAP is expected to include provisions that clarify how responsibility will be allocated in case of erroneous or disputed transactions, which will be crucial for building consumer trust.














