


A look at how AI agents are starting to make purchases and payments for us—offering real convenience while raising sharp new questions about control, liability, and fraud.
Picture the scene. You tell your phone, “book me the cheapest flight to London next Friday,” slip it back into your pocket, and think no more about it—until the boarding pass quietly appears the following morning. You never compared prices. You never tapped “pay.” Something did it for you.
That something is closer than most people realise. And in truth, we have been inching toward it for years. Salaries land automatically. Bills clear by standing order. Card details sit saved in a dozen apps. Subscriptions renew in the background whether we use them or not.
But a real line is being crossed. Until now, software simply repeated instructions we had already given it. What is emerging is different: artificial intelligence that makes the decision itself—which product, which merchant, which price, and when to pay. This is agentic payments, and 2026 is the year the industry began treating it seriously, with payment networks, banks and technology firms all racing to build the plumbing.
Which leaves an uncomfortable question hanging in the air. If an AI agent can spend money on your behalf, how much control are you really keeping?
Put simply, an agentic payment is a transaction that an AI system starts, manages and completes for you, using authority you granted it in advance.
The distinction from ordinary automation is the whole point. A standing order repeats a fixed instruction. An agent exercises judgement.
An agent might, for instance:
You do not sign off on each step. You sign off on a result.
This is already leaving the lab. Open standards have appeared that let AI agents transact with merchants without bespoke integrations, and major payment companies are positioning themselves as the trusted layer—the referee that checks whether an agent is genuine before any money moves.
The shift did not begin with payments. It began with search.
Most consumers now ask an AI tool for product recommendations rather than reaching for a search engine—in fact, a majority say they have already swapped traditional search for generative AI when hunting for what to buy. Once you trust AI to choose, letting it buy is a short step.
Several forces are pushing hard in the same direction:
Bahrain is better prepared for this than many. The Kingdom has run a mandatory open banking framework for years—built around customer consent, authentication and standardised APIs—and the Central Bank of Bahrain refreshed its authorisation rules for payment and account information service providers in May 2026. Consent-based access and dependable APIs are precisely what agentic payments run on.

Comparing options across ten browser tabs is a chore few enjoy. Handing it off is genuinely appealing.
An agent can check more merchants in seconds than a person manages in an hour.
Renewals, bills and deadlines can be handled before they curdle into late fees.
Booking a trip means juggling flights, hotels, transfers and dates. An agent can hold the whole puzzle at once.
For anyone who finds digital interfaces a struggle, an assistant that acts on a spoken word is a real step forward.
The convenience and the danger flow from the same source: delegation.
When you approve a result instead of a transaction, the individual decision slips out of view. You may have no idea what was bought, from whom, at what price, or under what return policy—until the money has already gone.
Fraud teams are watching closely. In one industry survey, roughly four in five financial institutions said they expect fraud to climb as AI shopping agents spread. Security researchers warn that agents can be tricked or impersonated, and that sloppy implementations open doors to automated fraud moving faster than any human could.
There is a quieter risk, too. An agent optimises for whatever you told it to optimise for. Ask for the cheapest option, and the cheapest is exactly what you may get—from a merchant you would never have chosen yourself.
Consumer research reveals something telling. People are far happier letting AI compare products than letting it complete the purchase. Trust in AI to inform a decision runs high. Trust in AI to actually buy stays stubbornly low.
That gap is the most honest signal in the whole trend. People want AI to advise, not to decide.
But trust has a way of creeping upward through small wins. An agent orders the groceries correctly. Then it renews a subscription. Then it books a flight. Each success makes the next hand-off feel safer—until one day the sum is large and the assumption goes untested. And younger users, the most willing to delegate, tend to reach that point first.
This is the question no one has properly answered.
If an AI agent makes a mistaken or fraudulent payment, the blame could fall on the user who granted the authority, the developer who built the agent, the bank or processor that offered it, or the merchant that accepted it. Legal specialists point out that today’s consumer protection rules were written for transactions decided by humans—and they do not map cleanly onto this.
There is a technical snag as well. Several regulatory regimes demand clear human authorisation for a payment order, and there is no accepted way, yet, to treat an AI agent as the equivalent of a human payer.
The International Monetary Fund has flagged an awkward trade-off on top of all this. Insisting a human approve every step is the obvious safeguard—but in an automated payment chain, a human pause can itself create delays and fresh risks. Designing a reliable stop button, it turns out, is harder than it sounds.
The defence against agentic fraud is, inevitably, more artificial intelligence.
Payment providers already score transactions for risk in milliseconds, reading real-time context to approve, decline or flag a payment before it settles. That same approach is being stretched to cover agents, alongside newer ideas:
Some providers have also started warning users before a suspicious payment rather than blocking it outright—respecting the customer’s choice while dropping a moment of friction exactly where it is needed.
Regulators are moving, but carefully, because this touches consumer protection, payments law and AI governance all at once.
The open questions include:
Bahrain’s existing consent-based framework is a sensible starting point. But agentic payments will eventually demand rules written for a payer that is not a person.
The honest answer is that it depends on how much authority you hand over—and how easily you can claw it back.
Used with care, with clear limits and visible records, an agent is a genuinely useful tool. It strips friction from tasks that never deserved our attention in the first place.
Used carelessly, with open-ended permissions and no caps, it becomes an efficient way to lose money quietly.
The technology is not the risk. The unexamined permission is.
Payments are shifting from something we do to something done for us—and that change is arriving faster than most consumers notice.
Bahrain’s open banking foundations put it in a strong position to adopt this responsibly, provided the rules keep pace with the technology and consumers understand what they are agreeing to.
Before handing an agent the keys to your money, three plain questions are worth asking: what can it spend, where can it spend it, and how fast can I stop it?
Because the real question was never whether artificial intelligence can spend your money—
—it is whether you will notice when it does.
Agentic payments are transactions initiated and completed by an AI system acting on your behalf, using authority you delegated to it in advance.
An automatic payment repeats a fixed instruction. An AI agent makes a decision—choosing what to buy, from whom, and at what price.
The technology is still early everywhere, but Bahrain’s mandatory open banking framework and consent-based APIs provide much of the groundwork it needs.
Losing sight of the detail. When you approve a result instead of a transaction, you may not know what was bought until after the payment is made.
This is currently unsettled. Responsibility could rest with the user, the developer, the bank or payment provider, or the merchant—and existing consumer protection rules were not written with AI payers in mind.
Mr. Ali Haji
College of Administrative and Financial Sciences — Gulf University, Bahrain
Last Updated: July 2026