Controls for AI payments in UK retail infrastructure
Bank of England · Consultation response ·
Proposes five requirements for the UK’s future retail payments infrastructure: authority references, an attested marker for agent-initiated payments, request keys, controls against duplicate clearing outcomes and retained transaction records. Assigns duties across payment providers, clearing infrastructure and scheme rules, with provisions for privacy and accessible human approval.
The document
- Title
- Personal response on programmable and agentic payments
- Consultation
- Design of the Future Retail Payments Infrastructure, Retail Payments Infrastructure Board
- Questions answered
- Q16, Q17 and its sub-question a, Q18, and the Equality Act question
- Capacity
- Personal capacity
- Submitted
- Length
- 27 pages, numbered paragraphs 1 to 54
- Confidentiality
- None. “I am content for this response to be published in full and attributed to me.”
The five asks
- A mandate reference carried unaltered end to end, so the institution enforcing a delegated authority and a later reviewer identify the same mandate.
- An agent-initiated marker, distinct from the agent’s identity, attested by the authorised participant that submits the instruction.
- A client-supplied request key, scoped by the submitting participant and carried into the core with that participant’s identifier, with that participant recording the result against the key and answering a repeat with the original result.
- A uniqueness constraint on that key, applied where inter-participant obligations are determined, so one key and one canonical instruction produce at most one clearing outcome.
- A record binding authority, payment and outcome, required and retained at the infrastructure boundary, holding references and not content, with bounded access and retention.
The central position: the core should carry three fields whose meaning it never reads, enforce one uniqueness property it can actually guarantee, and require one record at its boundary. It should not administer mandates, authenticate an agent, judge a purpose or allocate liability. Those belong to institutions, schemes and regulation.
What no design of the core can do
The response is explicit about the limits of its own proposals. The core cannot tell a repeat from a second legitimate purchase where the payer sends it under a fresh key, because the payer, payee, amount, currency and mandate are identical in both. It cannot infer a human purpose. It cannot decide who bears a loss.
Those sit with the submitting participant and the product, with the principal, and with regulation, in that order.
On the Equality Act question
Three observations. Delegating routine payment to an agent could improve access for disabled and older consumers in particular, and that is a benefit to test with affected users rather than assume. The same design can exclude them where an escalation condition requires a prompt response through a single digital channel, so the approval route should admit a nominated delegate, a longer response window and a non-agent alternative.
The third concerns one of the asks above. Where a payment service provider treats the agent-initiated marker alone as a reason to decline, the cost falls first on the consumers for whom delegation is the accessible route to paying. Scheme rules should state that the marker is an input to fraud controls and never a sufficient reason to decline, and should require agent-initiated decline rates to be monitored.
Sources
- The response in full PDF · 27 pages
- The consultation on bankofengland.co.uk Design of the Future Retail Payments Infrastructure
- The working paper the response cites SSRN · 46 pages