Skip to main content
Live
Main content

FIDO, Google and Mastercard launch working groups for AI agent payments

Two new FIDO Alliance working groups will draft authentication standards for agent-initiated transactions, with AP2 and Verifiable Intent as starting code.

Jaeden Schafer
Editor in Chief · · 4 min read
FIDO, Google and Mastercard launch working groups for AI agent payments

The FIDO Alliance, Google and Mastercard announced on April 28, 2026 that they are launching two industry working groups to draft authentication standards for AI agents that buy things on a user's behalf. Google is seeding the effort with its Agent Payments Protocol, known as AP2, and Mastercard is contributing its Verifiable Intent framework, which the two companies codeveloped to plug into AP2. The aim is a baseline that any merchant, platform or payment network can adopt before agent-driven commerce scales past the point where it can be retrofitted.

The standards will cover three problems at once. Users need a way to authorize an agent that resists phishing and prompt injection. Merchants and payment networks need cryptographic proof that the agent is acting on a real, authenticated instruction. And every party in the chain needs a privacy-preserving way to verify the transaction without exposing data the others do not need.

Pablo Fourez, Mastercard's chief digital officer, said the timeline pressure is the unusual part. "This tech is evolving very, very fast, so it compresses standards timelines that in the past might have taken two or three years," Fourez said. He added that when bad actors exploit weaknesses in agent payments, the cost of covering cardholders becomes high enough that the industry has to move first rather than clean up later.

Key facts

  • 01FIDO Alliance announced two working groups on April 28, 2026 to set standards for AI agent payments and transactions.
  • 02Google contributed its Agent Payments Protocol (AP2); Mastercard contributed the Verifiable Intent framework, codeveloped with Google.
  • 03Mastercard's Pablo Fourez says agentic AI is compressing standards work that previously took two or three years.
  • 04Sample use case: a user instructs an agent to buy sneakers autonomously if they restock at $100 or less.
  • 05Andrew Shikiar, FIDO Alliance CEO, frames the moment as a precipice comparable to the early password era.

Andrew Shikiar, CEO of the FIDO Alliance, framed the launch as a chance to avoid repeating the password mess. "Agents are becoming more and more common, they're moving into mainstream use, but preexisting models aren't necessarily designed for this sort of paradigm — they weren't built to contemplate actions performed on a user's behalf," Shikiar told Wired. He compared the current moment to the decades-old security foundations underneath today's web, which the FIDO Alliance has spent years trying to replace with passkeys.

Mastercard's Pablo Fourez says agentic AI is compressing standards timelines that previously ran two or three years, with cardholder liability costs forcing the industry to move faster.
Jaeden Schafer

Stavan Parikh, Google's vice president and general manager of payments, described the design goal as selective disclosure. "We want to provide cryptographic proof that a transaction was authorized by the user themself, but keep it private so there is built-in selective disclosure," Parikh said. "Different players in the ecosystem — platforms, merchants, payment providers, networks — only see the information that's relevant to them, but the right action gets fulfilled at the right time. Payments is a complex ecosystem problem."

Parikh used a concrete example to explain the use case. A shopper wants a specific pair of sneakers, but they are sold out. The shopper tells an agent to buy them autonomously if they restock at $100 or less. AP2 and Verifiable Intent are meant to make sure that when the drop happens, the right card gets charged the right amount for the right item, with each party in the loop able to confirm authorization without seeing the rest of the user's data.

AP2 and Verifiable Intent give the working groups a head start, but neither is a finished standard. The groups will need to build a library of real-world cases, then convince platforms, merchants, payment providers and card networks to implement the protocols at scale. That is the part of standards work that historically takes years and where most efforts stall.

The push lands as agent infrastructure is being assembled in adjacent corners. Anthropic has been wiring Claude into creative software through new connectors, and Red Hat engineers have shipped Tank OS to harden agent deployments at the operating-system layer. None of that work answers the payments question, which is why FIDO is treating it as a separate standards track rather than letting individual model providers ship their own checkout flows.

Related · from this week
Vendors move to block Google's data buy from bankrupt Spirit Airlines
Jaeden Schafer · 5 min read →

The skeptics' case is straightforward: standards bodies are slow, agent capabilities are not, and the gap between the two is where fraud lives. Fourez acknowledged the asymmetry directly, noting that Mastercard will continue to back cardholders against fraud but that the support cost climbs sharply when agents are the attack surface. There is also the question of whether AP2 and Verifiable Intent become a genuine cross-industry baseline or get forked into competing implementations once OpenAI, Anthropic, Amazon and Apple weigh in.

For now, the more telling signal is who is at the table. Mastercard processes transactions for most of the world's card-issuing banks, Google sits underneath a meaningful share of consumer agent traffic, and FIDO already runs the passkey standard that replaced password logins at Apple, Microsoft and Google. If agent payments end up with a credible security floor before the first large-scale fraud incident, this is the configuration of players that would build it. If they do not move fast enough, the regulators almost certainly will.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Google logo
Security

Vendors move to block Google's data buy from bankrupt Spirit Airlines

Springshot says the auction hands Google 15 years of its IP; the EFF calls it the first public bankruptcy fight over employee data.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI, Anthropic, Google sign open letter on rogue AI cyber threats

Over 100 tech and cyber firms want joint public-private defense as AI agents keep breaking out of their sandboxes.

Jaeden Schafer5 min read
Google logo
Security

Google's SynthID watermark debunks viral McConnell hospital deepfake

Snopes used Google's invisible watermark to confirm a widely-shared image of the ailing senator was AI-generated — a rare public win for detection tech.

Jaeden Schafer4 min read