AI agents that can shop and pay for you are arriving — and the FIDO Alliance just moved to keep those transactions secure. FIDO has formed two working groups to create standards that authenticate and protect payments and other transactions initiated by AI agents. Google and Mastercard are among the initial contributors, offering interoperable verification tools that cryptographically prove a user authorized a given agent action.

Why the move matters Agentic AI — software that acts on a user's behalf to carry out tasks rather than just answer questions — is moving out of labs into everyday apps. That shift changes the threat model for online security: fraud that used to target people directly can now target the agents acting for them. When an agent can make purchases or move money, phishing, impersonation, and account takeover risks can lead to automated, large-scale misuse unless systems are redesigned. The FIDO Alliance will create two working groups focused on authenticating and protecting transactions performed by agents. The goal isn't to invent a new payment network or wallet, but to develop interoperable technical standards and practices so services can verify an agent truly acted with the user's consent and that consent can't be trivially faked or stolen. What the standards will try to do The planned standards aim to deliver several concrete capabilities: - Cryptographic proof that a transaction was authorized by the user, so merchants and banks can verify authorization without exposing broader identity or history. - Authentication methods that resist phishing and account takeover, reducing the chances an attacker can impersonate an agent or its user. - Privacy-preserving frameworks so platforms can confirm an agent-initiated action while minimizing data exposure. - Accountability and traceability mechanisms so it's possible to determine whether an agent behaved correctly and to provide recourse for disputed transactions. Tools already on the table Google has proposed the Agent Payments Protocol (AP2), designed to cryptographically verify that a user intended an agent to carry out a specific transaction. Mastercard is offering a Verifiable Intent framework developed to interoperate with AP2. Both projects are open source and intended to work with existing authentication systems as building blocks for broader adoption. Speed vs. rigor Creating widely applicable technical standards usually takes years, but contributors say the pace of agent adoption requires moving faster. The Alliance and partners plan to leverage existing cryptographic and authentication primitives to avoid rebuilding the entire stack and to use open-source contributions to accelerate testing and cross-platform adoption. They say interoperable standards are needed to avoid a patchwork of incompatible protections.

Related Articles

"Agents are becoming more and more common, they're moving into mainstream use, but preexisting models aren’t necessarily designed for this sort of paradigm—they weren't built to contemplate actions performed on a user’s behalf," said Andrew Shikiar, CEO of the FIDO Alliance.

This article was created with AI assistance.