As of July 2026
Continuous machine payments break controls designed around a person, a cart, and one considered purchase. The control plane has to govern the actor and its authority before the payment cadence begins.
The transaction still matters for accounting and settlement. It is no longer the right unit for every risk decision.
Launch
Jun 10
Mastercard announced Agent Pay for Machines and Visa announced agent-commerce infrastructure.
Participants
30+
Mastercard named payment, crypto, cloud, and infrastructure firms in the launch group.
Control unit
Agent
identity, purpose, spend bounds, and revocation become the durable authorization object.
Velocity loses its old meaning
A dozen attempts in a minute can signal credential abuse when a person is paying. The same count may be ordinary for a software fleet buying API calls or other machine services. Static count thresholds can’t tell the two apart. Detection has to examine the agent identity, its declared purpose, the merchant or service boundary, the spend envelope, and the shape of activity inside that envelope.
Approval moves up one level
Tiny payments make a human approval or a full authorization round trip on every event uneconomic. The system still needs permission. It grants that permission as a bounded mandate: who may act, where it may spend, what it may buy, how much it may spend, and when the authority expires. Each payment consumes authority that already exists instead of inventing a new decision from scratch.

The durable control object is the agent mandate. Transactions become evidence against that mandate.
Remediation becomes containment
Traditional disputes assume the recovery effort is proportionate to the payment. That assumption fails at machine cadence. Investigating and disputing a tiny event may cost more than the event itself. The first response is containment: stop new authority, revoke or rotate the credential, freeze the remaining envelope, and preserve the event trail for reconciliation. The envelope bounds loss while the operator decides what to restore.
This collapses an old organizational boundary. Identity teams own credentials and access. Fraud teams own transaction patterns and losses. Agent payments require one decision path across both. An authenticated agent with the wrong scope is an authorization problem. A correctly scoped agent with abnormal behavior is a fraud problem. The control plane has to see both at the same time.
When machines pay continuously, the risk question changes from 'is this transaction normal?' to 'is this agent still acting inside the authority we granted?'




