Not in the way you’d probably assume. When an AI shopping agent completes a purchase on your behalf, it typically isn’t reaching into your wallet and typing out your actual card number. It’s using a stand-in — a tokenized, often single-use credential that points back to your real card without ever exposing the number itself. That distinction is the whole reason payment companies believe this can work safely at all.
Here’s how it actually functions, what’s changed just in the past few days, and what’s still genuinely risky about handing an AI agent access to your money.
The Short Answer: It’s a Token, Not Your Real Card Number
The core safety mechanism behind agentic payments is tokenization. Rather than an AI agent being handed your 16-digit card number to type into a checkout form, the payment network issues a separate token tied to that card — one that can be scoped to a specific merchant, a specific spending limit, or even a single transaction. According to a breakdown of agentic payment security from Reap, the entire risk calculation changes once the actual card number never touches the AI system at all — an agent that’s handed a raw card number creates real exposure if that number ends up embedded somewhere inside the AI’s own processing, as explained in Reap’s analysis.
This is why “can an AI agent use your saved card” and “does an AI agent see your actual card number” are two different questions with two different answers. The functional answer to the first is increasingly yes. The answer to the second, on any well-built system, should be no.
How Payment Networks Are Building This Right Now
This part of the story is moving fast enough that what’s true this month may already look outdated in a few more.
Mastercard just took its most direct step yet. In a partnership with the startup Alchemy announced this week, Mastercard is issuing virtual, tokenized, one-time-use card credentials directly to AI agents linked to a user’s existing account. Cardholders authorize an agent in advance to shop independently — ordering food, booking travel, buying products — within limits the user sets, and without approving each purchase individually, according to Gadget Review’s coverage of the launch. Alchemy’s own framing of the shift, posted publicly on X and cited in that reporting, put it bluntly: the traditional checkout button is on its way out as agents take over discovery, comparison, and purchasing directly.
Visa has been building a parallel track since late 2025. Its Trusted Agent Protocol, developed with Cloudflare, gives an AI agent a cryptographic signature that a merchant’s system can check to confirm it’s dealing with a legitimate, authorized agent rather than a rogue bot pretending to shop on someone’s behalf, per the same Reap analysis. Visa has also said it expects millions of consumers to complete purchases through AI agents by the 2026 holiday season, and has been running live pilots with partners across travel, retail, and B2B payments, according to Visa’s own announcement of early agentic transaction milestones.
Google has taken a somewhat more cross-platform approach with its Agent Payments Protocol and a companion specification called Verifiable Intent, developed jointly with Mastercard. Both have since been donated to the FIDO Alliance — the same industry body behind passwordless login standards — with the goal of binding an AI agent’s actions to exactly the scope a cardholder approved, rather than leaving that enforcement up to any single card network. PayPal has its own version, called Agent Ready, which lets existing PayPal merchants accept payments initiated by AI agents and integrates directly with ChatGPT for in-conversation checkout, based on a comparison of current agentic payment infrastructure from Privacy.com.
Verifying Which Agents Can Be Trusted: The “Know Your Agent” Framework
Issuing a token to an agent only solves half the problem. The other half is knowing, with confidence, which agent you’re actually dealing with — and that’s what the industry’s newest initiative is aimed at.
On September 10, 2026, Mastercard, Visa, and Ant International jointly announced a framework called Know Your Agent, building on top of Visa’s Trusted Agent Protocol, Mastercard’s Verifiable Intent work, and Ant International’s own Agentic Mobile Protocol. The goal, functionally, is the AI-agent equivalent of Know Your Customer verification that banks already run on human account holders. According to a detailed breakdown of the framework, it rests on three pillars: tracing every agent back to a specific, validated human or organization across networks; holding agents to shared certification requirements around security and behavior; and running continuous transaction monitoring that can revoke an agent’s certification if its behavior shifts unexpectedly, as described by Gadget Review.
That last piece matters more than it might sound. It means an agent’s trusted status isn’t a one-time approval — it’s something that can be pulled if the agent starts behaving in ways that look suspicious after the fact.

What Happens If an Agent Does Get Your Raw Card Number
Not every AI shopping tool on the market today is built on top of these tokenized frameworks. Some browser-automation agents work by literally filling in a checkout form the same way a human would — which means, depending on how the tool is built, the actual card number may pass through the AI system to do it.
That’s the scenario security researchers are specifically warning against. The Cloud Security Alliance argues that an AI agent’s identity should be treated as its own distinct, first-class identity — not folded into the user’s account as if the two were interchangeable — and should be monitored on an ongoing basis through behavioral tracking and auditable logs of what the agent actually did, rather than trusted by default once it’s set up. A joint Cloud Security Alliance and Anjuna survey on financial services and AI found that 65 percent of respondents believe the shift to agentic payments will require an entirely new authorization model — not a patch on the existing one, according to the survey findings cited by Reap. The same research frames the open question plainly: when something goes wrong, whose identity is actually behind the transaction — the consumer, the agent, the merchant, or whoever built the platform running the agent? As of now, that same source notes, responsibility in practice still falls to the user by default — which lines up with how retailers have been writing their own terms of service around agentic purchases more broadly.
The Bigger Risk Isn’t the Card Number — It’s the Permissions Around It
Security experts increasingly argue that tokenization solves the easy part of this problem. The harder part is permission sprawl.
Jordan Mauriello, CTO at IT services firm SHI, described the pattern plainly in comments to IT Brew: people set out to solve one specific task with an AI agent, grant it the permissions needed for that task, and then never circle back to lock those permissions down again — leaving the agent with standing access to things it no longer has a real reason to touch, as reported by IT Brew. Torii CEO Uri Haramati made a related point in the same piece, framing identity and access management — tracking exactly what each agent can do and for how long — as just as important as the payment security layer itself.
That risk compounds because financial access is specifically what makes a compromised AI agent dangerous at scale. Coverage of Mastercard and Alchemy’s launch noted that safety researchers have flagged financial access as the key resource a rogue or hijacked AI agent would need to cause real damage — not because the tokenized credential itself is necessarily weak, but because an agent with broad, unmonitored spending permissions is a much bigger target than one with none.
What This Means for You Right Now
A few practical takeaways, based on where the infrastructure actually stands today rather than where it’s headed:
- Prefer tools built on tokenized or virtual-card systems over ones that simply automate filling in your real card number on a checkout page. Mastercard Agent Pay, Visa’s Trusted Agent Protocol, and similar frameworks are specifically designed so your actual card number never reaches the AI system.
- Set spending limits and merchant restrictions wherever the platform allows it. Every framework built so far — Mastercard’s, Visa’s, Google’s — is designed around scoped, bounded authorization rather than handing an agent unlimited access.
- Periodically review what permissions you’ve actually granted, rather than assuming a one-time setup is still appropriate months later. This is the exact gap security professionals are flagging as the real risk, more than the payment mechanism itself.
- Treat “trusted agent” verification as still maturing. The Know Your Agent framework launched only this month, and as of now, no single agent-identity standard spans every card network — different platforms and merchants are still catching up to consistent verification.
Also Read: Who Is Responsible When an AI Shopping Agent Buys the Wrong Product?
Frequently Asked Questions
Can an AI shopping agent see my actual credit card number?
On systems built around tokenization — such as Mastercard Agent Pay or Visa’s Trusted Agent Protocol — no. The agent uses a separate, often single-use credential tied to your card rather than the card number itself. Tools built on older browser-automation approaches may not offer that same protection, so it depends on which system you’re using.
Is it safe to let an AI agent use my saved card automatically?
It’s reasonably safe when the purchase is routed through a tokenized, scoped credential with spending limits you’ve set. The bigger risk isn’t usually the payment mechanism — it’s granting an agent broad permissions for one task and forgetting to revoke them afterward.
What is Mastercard Agent Pay?
It’s Mastercard’s framework for issuing virtual, tokenized, often one-time-use card credentials directly to AI agents, allowing them to make purchases within limits set by the cardholder, without approving each transaction individually.
What is the Know Your Agent framework?
Announced by Mastercard, Visa, and Ant International in September 2026, it’s a shared system for verifying which AI agents can be trusted to make payments — tracing each agent back to a validated human or organization, holding it to common certification standards, and monitoring its behavior on an ongoing basis.
Who is responsible if a hacked or malfunctioning AI agent misuses my saved card?
There’s no single settled answer yet. Industry research shows most experts believe agentic payments need an entirely new authorization model, but in current practice, responsibility for an authorized agent’s actions typically still falls on the person who granted it access.
Do all AI shopping agents use tokenized payment credentials?
No. Some tools, particularly simpler browser-automation agents, may interact with checkout pages more directly. It’s worth checking whether a shopping agent is built on a tokenized framework like Mastercard Agent Pay or Visa’s Trusted Agent Protocol before giving it access to a saved card.


