Consent and liability for AI payments in UK payment regulation
HM Treasury · Consultation response ·
Proposes five changes to UK payment services regulation for payments an AI agent makes for a consumer: a spending grant with limits recognised as consent, strong customer authentication when the grant is set up or changed, a credential issued for the agent, reimbursement on Faster Payments and CHAPS where a fraudster deceives the agent, and an evidence record for each payment. Places each change in legislation, FCA rules or the reimbursement rules.
The document
- Title
- Personal response on agentic payments
- Consultation
- Modernising Payment Services Regulation, HM Treasury
- Question answered
- Q15, how existing payment services regulation needs to adapt to support agentic payments
- Capacity
- Personal capacity
- Submitted
- Length
- 14 pages, numbered paragraphs 1 to 29
- Confidentiality
- None. “I am content for this response to be published in full and attributed to me.”
The five asks
- A bounded delegation, recognised as consent. A consumer’s grant of spending authority to an agent, recorded with its limits, should count as consent to a series of payments. A payment outside the limits should then be unauthorised however it is funded, and refundable, with a counterpart rule where it draws on regulated credit such as a credit card or an overdraft. So should a second execution under the same request key, the identifier each purchase carries in the payment order.
- Authentication at the grant. The FCA’s outcomes-based rules should let strong customer authentication attach to the delegation when it is created or changed, with fresh authentication above a threshold and the provider free to ask for it when its monitoring flags a payment. The liability rules tied to strong customer authentication should move with it, without making the grant proof that a later payment was authorised.
- A credential issued for one agent, bound to the limits the consumer authenticated and revocable at once, with its issuer reserving each amount against the cumulative limit before the payment proceeds. The consumer then need never hand an agent their own codes or passwords.
- A decision on the payment the consumer did not intend. Where a fraudster deceives the agent, the Faster Payments and CHAPS reimbursement rules should treat the consumer as deceived, and the reimbursing provider should recover from the agent’s provider where that provider’s breach of a defined duty caused the loss. Loss on a payment outside the delegation should be recoverable from the party that should have stopped it.
- An evidence record, and Know Your Agent that covers the agent’s state. FCA rules should set what the record of an agent’s payment must show, whichever scheme holds it, and the agent’s provider should keep the consumer’s instructions. Know Your Agent work should cover what the agent was running as well as which agent it was.
The central position: most of what agentic payments need is already in the Payment Services Regulations, which provide consent to a series, withdrawal with prospective effect, a refund where the payer did not consent and a burden of proof on the provider. They do not yet name a bounded delegation as the object of that consent, or provide the authentication, credential and record that make it work. Who bears a payment the consumer did not intend is answered only in part. The consent rule belongs in legislation, authentication and the record in the FCA’s rules, and fraud against the agent in the reimbursement rules.
Where payment regulation stops
The response is explicit about what it leaves to contract and consumer law. A payment the agent makes in error, without fraud and inside the consumer’s limits, stays, like a consumer’s own mistake, a matter of contract and consumer law between the consumer and the agent’s provider. Payment services regulation’s part there is to make the facts of the payment provable.
A repeat the agent sends under a fresh request key meets no key check, and nothing in the payment distinguishes it from a second purchase the consumer wanted. The response would leave its cost between the consumer and the agent’s provider, whose agent made it.
Three proposals elsewhere in the consultation
Paragraphs 25 to 27 apply the five changes to three proposals made elsewhere in the consultation. Under its proposal, overseas-issued stablecoins stay outside the payment services framework, which may later extend to some where HM Treasury formally recognises the issuer’s home regulatory framework. An agent that chooses its own rail could therefore take a consumer’s payment outside Part 7 of the regulations without the consumer choosing that. The delegation’s limits should include the rails the agent may use, and the consent and liability rules should apply to payments in UK-issued qualifying stablecoins on the same terms as to other funds.
The review of the payment initiation definition should decide whether exercising a consumer’s delegated spending authority brings a provider inside the perimeter, whatever the rail. If the proposed right of access for variable recurring payments lets a payment initiation service provider lodge a payment mandate that carries the delegation’s limits, the agent authorised and an agent-initiated marker, agent payments by account transfer have the structure the five asks set out from the start. The interface standards the consultation proposes are where to require it, with each amount reserved against the limit before the payment proceeds.
Sources
- The response in full PDF · 14 pages
- The consultation on gov.uk Modernising Payment Services Regulation
- The Bank of England response it builds on Consultation response · 2 September 2026
- The working paper the response cites SSRN · 68 pages