In today’s deep dive, we look at what happens when AI moves from helping you shop to actually spending your money. We will examine how agentic payments could work through UPI, what changes for PhonePe, Google Pay, banks and e-commerce companies, who is liable when an AI makes a bad purchase, and how the economics of online commerce may shift. We will also look at regulation, global parallels and what this could mean for the way Indians buy, pay and manage money over the next few years.

In February this year, Razorpay and NPCI demonstrated something at the India AI Impact Summit that looked like a small improvement to online shopping. A user could open Claude, ask for samosas and chai for the office, let the AI look through Zomato, and complete the order without leaving the conversation. The same setup worked with Swiggy and Zepto. Instead of the usual jump from chat to merchant app to checkout to UPI app, much of the journey happened inside Claude.

The payment part was built using UPI Reserve Pay. A user could give permission beforehand and set spending limits. Once those limits were in place, the AI could complete an eligible purchase without asking for a UPI PIN at every step. The pilot was small, but the important part was that the assistant was no longer just telling the customer what to buy. It had entered the transaction.

Four months later, Pine Labs pushed the idea further. Its P3P payment protocol went live with Gullak, where a customer can create a rule such as: buy ₹500 of digital gold if the price falls below ₹16,000 per gram. The customer approves the mandate once. If the condition is met later, the software can execute the payment. Vijay Sales is testing a similar idea for electronics, where a purchase could happen when a product falls below a price chosen by the customer.

Now NPCI is preparing the more important piece. Reuters reported this week that it is developing a registry to identify and monitor AI agents that make transactions through UPI. The registry is part of what is being called the Unified Agentic Protocol. The first use cases are expected to involve small, frequent purchases such as groceries, while more complicated transactions could come later. Cards, bill payments and other forms of payment may eventually sit inside the same framework.

Look at those developments together and the direction becomes clearer. India is slowly moving from a payment system where software helps a person pay to one where a person gives software limited authority to spend.

That sounds like a small difference. Economically, it is a very large one.

UPI has already built much of what an AI buyer needs

India does not need to invent a completely new payment network for this.

UPI already processed 24.51 billion transactions worth ₹29.82 lakh crore in August. That works out to nearly 800 million transactions a day. It is already normal for an Indian customer to pay ₹200 for groceries, ₹150 for food, ₹500 at a petrol pump or ₹300 for a recharge without thinking much about the payment technology underneath.

NPCI has also spent the last few years separating the person who owns the money from the person or system that is allowed to initiate a payment.

UPI Circle was initially designed around people. A parent could allow a child to make payments from the parent's account within a set limit. A business owner could delegate limited payment authority to somebody else. NPCI later extended the concept towards software profiles and connected devices. Reserve Pay added another useful building block by allowing money to be authorised and set aside for multiple future debits rather than requiring a completely new approval every time.

That starts looking very useful once the delegated party is not another person but software.

Pine Labs is already using this logic. Its documentation says a customer can approve a UPI mandate through their UPI app and the agent can subsequently use the approved mandate for eligible transactions. The mandate can still be changed or revoked.

The interesting part is what happens when all of these pieces are put together.

Imagine that you tell an AI assistant on Saturday night: "Order my normal household groceries tomorrow morning. Compare BigBasket, Blinkit and Zepto. Spend no more than ₹2,500. Do not change the brands of coffee, detergent or cooking oil. Use my HDFC account through PhonePe."

Today, that instruction would probably end with a shopping list or links.

Under an agentic payment system, you could first authorize that shopping agent for grocery merchants, up to ₹2,500 per order and perhaps ₹10,000 a month. Its identity could be checked against NPCI's agent registry. PhonePe, a bank or another payment provider could verify that the payment falls inside the authority you gave.

On Sunday morning the AI could find the basket for ₹2,190 on BigBasket, ₹2,280 on Zepto and ₹2,340 on Blinkit. It could check delivery times, confirm that the brands match your instruction and select BigBasket.

The payment request would then travel through the normal financial system. Your bank account still exists. UPI still moves the money. A regulated payment provider still checks the transaction. BigBasket still fulfils the order.

What disappears is a surprising amount of what sits in between.

You may never search BigBasket. You may never open PhonePe. You may never look at a checkout page.

You would simply receive a message saying that ₹2,190 was spent on the grocery order you had authorised.

This exact PhonePe flow is illustrative because NPCI has not published the final architecture of UAP. But every major piece required to build something close to it already exists or is being tested.

That is why this should not be viewed merely as another UPI feature.

PhonePe can still process the payment and lose the customer

For most of UPI's history, the payment app has been the visible part of the transaction.

A customer opens PhonePe or Google Pay, scans a QR code, selects a bank account, sees the merchant name and confirms the payment. The apps may not own the bank account or the UPI rail, but they own an important moment with the customer.

PhonePe and Google Pay have built enormous businesses around that position. Together they handle roughly four out of every five UPI transactions. That concentration has already become a policy issue. In July, Paytm, CRED and Super.money objected to a proposed one-click UPI checkout system because customers could save a preferred UPI option with a merchant. Their argument was simple: once PhonePe or Google Pay becomes the stored default, smaller payment apps get fewer opportunities to win the customer back.

Agentic commerce makes the default problem much bigger.

Suppose the customer never reaches the page where a payment app is chosen.

ChatGPT, Gemini or another assistant has already understood the request, compared the products, chosen the merchant, built the basket and asked for the payment. PhonePe might still sit somewhere underneath as the payment provider. But the customer relationship has moved one layer higher.

That matters because the most valuable part of commerce is often not moving the money. It is deciding where the money goes.

Google understood this in search. Amazon understood it in e-commerce. Zomato understands it in food delivery. Whoever controls discovery can decide which businesses the customer sees before a transaction happens.

An AI assistant could control both discovery and decision.

That is a much more powerful position.

PhonePe's response is already visible. In February it launched natural-language search that lets customers type or speak instructions such as "Pay Hemanth ₹20" or "Recharge FASTag" rather than navigate through the app. The current product still routes the customer to the relevant payment flow, but the direction is obvious: PhonePe itself wants to become more conversational.

That may be the strongest defence available to UPI apps.

Instead of waiting for Gemini or ChatGPT to become the layer above them, they can become agents themselves.

A future PhonePe app may be less about scanning and paying and more about managing financial permissions. A customer could allow one agent to spend ₹8,000 a month on groceries, another to pay electricity and broadband bills, and a travel agent to book flights below ₹15,000 while asking for approval above that amount.

The UPI app then stops being merely the thing that initiates a payment. It becomes the place where the customer decides which pieces of software are allowed to touch their money.

That would be a much better business to own.

The business model of UPI apps may have to change with it

There is a misconception that companies such as PhonePe simply earn money every time somebody makes a normal UPI transfer. They do not.

UPI has operated under a zero-MDR regime for most merchant transactions. Payment companies have therefore built revenue around adjacent services such as merchant devices and subscriptions, payment processing in categories where charges are allowed, lending distribution, insurance, advertising and other financial products.

PhonePe's FY25 filings show how dependent the company still is on payments broadly defined. It reported ₹6,497.9 crore of revenue from payment services in FY25, equal to about 91% of revenue from operations. Consumer payments accounted for roughly ₹4,507 crore and merchant payments another ₹1,991 crore, while lending and insurance distribution contributed about ₹558 crore.

The economics of UPI itself are also beginning to move. Parliament has created an enabling route for merchant fees to return, although the government has made clear that consumers will not be charged and that most merchant UPI transactions should remain free. If MDR eventually returns, it is expected to apply only to a limited part of merchant payments above specified thresholds.

Agentic payments add another possible revenue layer.

A merchant may eventually pay not merely for payment processing but for access to agent-ready checkout, trusted identity, fraud screening, recurring mandates and machine-readable payment infrastructure. A bank or UPI app could charge for business services built around those capabilities even if the basic consumer payment remains free.

But there is also a downside.

If an AI assistant chooses the merchant before PhonePe appears, PhonePe has fewer chances to sell the customer a loan, insurance policy, investment product or another service. The app can process more transactions while becoming less important to the person making them.

That is why the battle is likely to move from payment initiation to trusted delegation.

Being the app that can move ₹2,000 is useful. Being the company that a customer trusts to decide which software may move ₹2,000 is potentially much more valuable.

E-commerce websites may lose the part designed for people

The second large change will happen on the merchant side.

Look at a normal e-commerce website today. An enormous amount of work goes into things meant for human eyes: banners, navigation menus, search boxes, category pages, recommendations, filters, product photography, discount pop-ups and checkout screens.

An AI shopping agent needs a very different store.

It wants accurate product names, specifications, price, inventory, delivery time, seller reputation, return rules, warranty, available discounts and a way to place an order.

The beautiful homepage matters less. The quality of the data behind it matters more.

Shopify is already moving in this direction. Its Agentic Storefronts allow eligible merchants to make products available through AI channels including ChatGPT, Google's AI products, Microsoft Copilot and Meta. Shopify Catalog turns the merchant's product information into a format these systems can discover, while orders can still flow back into the merchant's existing systems. In some AI channels the purchase can already happen without the shopper leaving the conversation.

This does not mean websites disappear.

For fashion, beauty, luxury, cars and other categories where browsing itself is part of shopping, people will still want photographs, stories and brand experience. But for a packet of dishwasher tablets, printer cartridges, pet food or the same coffee bought every month, the website could become much less important.

The useful part of the retailer increasingly sits behind the website: catalogue, inventory, pricing, reviews, logistics, payment and returns.

There are signs that customer behaviour is already moving in that direction even before fully autonomous buying becomes common. Adobe says traffic from AI sources to US retail websites was up 62% year-on-year in July and more than 12 times higher than in October 2024. Those shoppers converted 60% better than non-AI traffic, spent more time on retail sites and were less likely to leave immediately.

Today the AI sends many of those customers to a website.

Tomorrow it may send an order.

That creates a new problem for Amazon, Flipkart, Myntra and other marketplaces. Their businesses are valuable partly because millions of consumers begin their shopping journey inside their apps. Sellers pay for sponsored listings and better visibility because ranking high on Amazon or Flipkart can materially affect sales.

What happens if the customer begins somewhere else?

A person could tell an assistant, "Find me genuine AirPods Pro below ₹20,000 that can reach Agra tomorrow." The agent can theoretically compare Amazon, Flipkart, Croma, Reliance Digital and Vijay Sales without caring which marketplace the customer usually opens.

Amazon then becomes one supplier competing to fulfil an order rather than the destination where the shopping journey starts.

But this does not necessarily weaken large marketplaces.

AI agents care about reliable data. They need to know whether the item is genuine, whether inventory is actually available, whether delivery will happen tomorrow and whether a return will be accepted. Amazon and Flipkart already have enormous amounts of structured product data, seller history, reviews, fulfilment information and fraud controls.

A random D2C website may have a beautiful Instagram page but terrible product data.

The agent may therefore trust the marketplace more.

Agentic commerce could weaken the marketplace's hold over discovery while strengthening its value as a trusted fulfilment system. Both things can happen at the same time.

Brands may discover that AI does not care about brands as much as people do

There is another uncomfortable possibility for consumer companies.

Suppose somebody has bought Finish dishwasher tablets for five years. Today habit may be enough to keep that customer.

Now the instruction becomes: "Buy dishwasher tablets for this month. I need at least 60. Spend below ₹600 and choose the best value product with strong reviews."

The software has no childhood memory of the brand, no attraction to a celebrity endorsement and no reason to be impressed by a premium homepage. It can calculate price per tablet, delivery time, customer ratings and return rates in seconds.

That makes some consumer categories easier to commoditise.

The effect will not be uniform. A person may still insist on Nike shoes, MAC lipstick or a particular whisky because the brand itself is part of the product. But there are hundreds of functional purchases where the customer mainly wants the job done.

Detergent. Batteries. Office supplies. Cables. Pet food. Cleaning products. Basic groceries. Repeated household purchases.

Those are precisely the categories where autonomous buying can spread fastest.

Marketing will change with it.

The old question was whether a brand ranked on Google.

Then it became whether the brand ranked on Amazon.

The next question may be whether an AI agent understands and trusts the product enough to recommend it at all.

That means companies will start spending money to improve machine-readable product data, reviews, availability feeds, pricing APIs and whatever signals AI systems use to judge credibility. The SEO industry will not disappear. Part of it may simply become an industry trying to influence software buyers rather than human searchers.

That opens a much more difficult question: can brands pay the agent to recommend them?

If an e-commerce site places a "Sponsored" label next to a product, the customer can see the commercial relationship.

If an assistant quietly says, "I found the best detergent for you and ordered it," while the winning manufacturer paid the assistant for preference, the advertising problem becomes much more serious.

The agent is no longer merely showing an ad.

It is spending the customer's money.

Consumer-protection rules around sponsored placement, self-preferencing and disclosure will therefore become central to agentic commerce. The more authority the customer delegates, the less room there should be for undisclosed commercial incentives to shape the decision.

The hardest payment dispute will involve a completely valid payment

NPCI's proposed registry helps solve one problem: proving which AI agent initiated a transaction.

It does not solve the harder problem of deciding who is responsible when the agent does something stupid.

Consider a customer who says: "Buy me good running shoes below ₹8,000."

The agent spends ₹7,800 on leather formal shoes because it misunderstands the instruction.

There has been no conventional payment fraud. The customer did authorize the agent. The bank correctly debited the account. The merchant delivered exactly what was ordered. The payment system may have worked perfectly.

Yet the customer has still suffered a loss.

Today's RBI customer-protection framework is mostly built around unauthorised electronic transactions. It provides strong protection in cases such as bank failures and certain third-party breaches, with liability depending partly on where the fault occurred and how quickly the customer reports it.

An authorised AI making a bad decision does not fit comfortably inside that framework.

There will be several different kinds of disputes.

Sometimes the agent itself may be fake or compromised. Sometimes a legitimate agent may exceed a ₹5,000 limit and spend ₹8,000. Sometimes it may remain completely within its mandate but misunderstand "running shoes". In another case the merchant could send the agent incorrect inventory or price information. And sometimes the instruction itself will be vague enough that nobody can easily prove what the user expected.

Those cases should not all have the same liability.

This is why the audit trail may become as important as the payment record.

A future dispute may need to reconstruct the customer's original instruction, the agent identity, the spending limit, which merchants were searched, what prices were returned, why one product was chosen, what information the merchant supplied and exactly what authority existed when payment was made.

Banks are already thinking in this direction. SBI chairman C S Setty argued this week for a "Know Your Agent" framework covering identity, authentication, consent, spending limits, audit trails and revocation. His point was that KYC tells a bank who the customer is, but autonomous software creates another actor inside the transaction that also needs to be known and controlled.

NPCI's registry could become India's version of that layer.

But registering an agent is much easier than deciding who pays when a registered agent gets something wrong.

Reuters says the liability framework for erroneous or unauthorised agentic transactions is still unresolved. That may prove to be the part that determines how quickly banks are willing to allow higher-value autonomous payments.

Fraud will also move from fooling the person to fooling the software

UPI scams today usually try to manipulate a human.

Someone sends a fake collect request. Someone pretends to be a bank employee. A customer is persuaded to share a PIN or install an app.

An autonomous buyer creates a second target.

A malicious merchant could feed false product information to the agent. A compromised website could try to give hidden instructions to the software. An attacker could impersonate a merchant that the customer has approved. A hacked agent could spread theft across hundreds of ₹200 or ₹500 transactions so that none of them looks serious on its own.

The payment industry will therefore need controls that go beyond asking whether a mandate exists.

Banks and payment firms will have to look at where the agent came from, whether its behaviour matches the customer's normal spending, whether it suddenly changed merchants, whether transaction frequency has jumped and whether the software itself has been altered.

This also creates a data problem.

An effective shopping agent works better if it knows what you buy, where you live, which bank you use, your preferred brands, your usual grocery basket, travel habits and previous spending. Some of that information is ordinary shopping data. Some of it sits very close to regulated financial data.

RBI already requires payment-system data to be stored in India so regulators can have supervisory access to it. The moment a foreign AI model becomes part of a transaction, firms will have to be extremely careful about which parts of the payment journey, authorization record and customer data can move through overseas infrastructure.

The agent may make shopping easier precisely because it remembers so much about the customer.

That same memory will make regulators nervous.

The rest of the world is trying to solve the same problem

India is not early because it invented the idea of an AI buyer. It is interesting because UPI gives the country an unusually large and interoperable payment network on which to try it.

The global card companies are preparing for the same transition.

Visa's Intelligent Commerce work includes agent-specific payment credentials, authentication and controls intended to make sure an agent's payment matches the customer's original instruction. Visa, Mastercard and Ant International also announced a common effort this week to build standards for identifying and verifying AI agents.

Google introduced the Agent Payments Protocol, or AP2, as an open framework for agent-led payments across different payment methods. Stripe launched the Machine Payments Protocol in March because ordinary checkout flows, with accounts, pricing pages and human authentication, were built for people rather than software.

The common idea underneath all of them is fairly simple.

Do not hand an AI your bank password and hope for the best.

Give it a specific authority that can be verified, limited and revoked.

India has an advantage here because millions of consumers already understand UPI mandates and recurring digital payments. The payment rail is interoperable. Banks are connected. Merchants already accept UPI at huge scale.

The harder question is whether the layer above that rail remains equally open.

UPI may be interoperable, but the AI assistant does not have to be.

If Gemini becomes the customer's default buying agent, will it treat Google Pay, PhonePe and Paytm equally? If PhonePe builds its own shopping agent, will it prefer businesses using PhonePe's merchant products? If Amazon's agent is asked to find the cheapest product, how seriously will it search Flipkart?

These are competition questions disguised as product features.

India has spent years ensuring that a merchant does not need a different QR code for every bank. It would be ironic if the next generation of commerce rebuilt closed systems one layer above that open payment network.

Small merchants may face a different problem: the AI cannot see them

The local kirana can accept UPI because accepting payment requires little more than a QR code.

Selling to an AI is much harder.

An agent needs to know what is in stock, the exact price, the pack size, delivery availability and perhaps the return policy. Most small stores have no machine-readable catalogue that stays accurate through the day.

That means the first wave of agentic commerce may favour businesses that are already digitally organised.

Zepto knows its inventory. Amazon knows its inventory. A large pharmacy chain knows its inventory.

The neighbourhood shop may know that five packets of atta are sitting on a shelf, but the AI has no way to discover that information.

The next opportunity for Indian merchant software may therefore be larger than payments. POS companies, ONDC participants, commerce software providers and fintech firms could help make millions of offline merchants understandable to software agents.

UPI digitised the act of paying a small merchant.

The next layer has to digitise what that merchant actually sells.

If that does not happen, agentic commerce could quietly push more spending towards the large platforms simply because machines can see them better.

Voice could make the Indian version much bigger

There is another reason India may not follow exactly the same path as the US.

The interface does not have to be a text box.

A customer could say in Hindi: "Kal subah doodh, bread, ande aur mera normal coffee mangwa dena. ₹700 se zyada mat kharch karna."

The system does not need to show ten search results. It needs to understand the instruction, find the goods, check the spending rule and complete the purchase.

That is particularly important for people who are comfortable speaking into a phone but do not want to navigate five apps, compare product pages and type payment details.

Razorpay is already experimenting with conversational and voice-led commerce, while PhonePe's AI search accepts voice as well as text commands.

UPI made digital payments possible without credit cards.

Voice plus delegated payments could eventually make some digital purchases possible without navigating an e-commerce app at all.

That is a much bigger change than making checkout faster.

The first useful agents will probably be boring

The near-term future is unlikely to involve an AI casually buying a ₹15 lakh car or taking out a personal loan while the owner sleeps.

Trust will have to be earned through boring transactions first.

Groceries are a good place to begin because they are frequent, relatively low value and easy to put inside rules. Recharges, utility bills, food orders and household supplies have similar characteristics. This is also why NPCI is reportedly looking at small and frequent purchases first.

Once customers become comfortable, the next stage could be conditional buying.

Buy this flight if the fare drops below ₹8,000. Order the air purifier if the price goes below ₹12,000. Refill the dog's food five days before the current packet normally runs out. Book my normal hotel in Bengaluru if it is below ₹6,000 a night.

This is where agentic payments begin to change the economics of commerce rather than merely save clicks.

Today many transactions never happen because the customer forgets, gets distracted or does not want to keep checking the price. A software agent can watch continuously.

Pine Labs' Gullak example already shows the basic model. The customer defines a condition once and payment happens later when the condition becomes true.

At some point the idea reaches financial products, and that is where the rules will become much tighter.

An AI buying detergent under a ₹1,000 monthly mandate is one thing. An AI taking a ₹2 lakh consumer loan because it found a laptop financing offer is completely different. Buying mutual funds, selling shares, buying insurance or creating debt brings RBI, SEBI and sector-specific suitability rules into the transaction.

Reuters says more complex conditional purchases and even investment use cases are being considered as the architecture develops. That does not mean autonomous investment will simply be switched on. Financial products are likely to require much stronger approval rules and human involvement than routine commerce.

So the likely progression is not from "human buys everything" to "AI controls the bank account."

It is from transaction approval to spending policy.

A customer first allows an agent to buy groceries below ₹2,000. Later they might allow a travel agent to book a flight below ₹10,000. Eventually several specialist agents could sit under one set of financial rules, each with its own category, limit, expiry date and level of approval.

The customer would stop deciding every individual transaction.

They would decide the rules within which transactions are allowed.

That changes what it means to own the customer

PhonePe spent years convincing Indians to open PhonePe when they wanted to pay.

Google Pay did the same.

Amazon spent years convincing people to open Amazon when they wanted to buy something.

Zomato wants people to begin with Zomato when they are hungry.

Google built one of the most valuable businesses in history by owning the moment when somebody searches for what they want.

Agentic commerce puts pressure on every one of those positions at the same time.

If the customer begins with one instruction to an AI assistant, the assistant can potentially choose the product, merchant and payment method before the existing apps get a chance to influence the decision.

That is why NPCI's agent registry matters more than the small grocery payment it may initially enable.

It creates the beginning of a new layer above UPI.

India has already seen what happens when control concentrates at one layer of digital commerce. PhonePe and Google Pay came to dominate UPI even though the underlying network itself was designed to be open. Amazon and Flipkart became major gateways to online retail even though thousands of sellers remained independent.

The same thing can happen again with AI assistants.

The company that becomes the default spending agent does not need to own the bank, the UPI rail, the warehouse or the product. It only needs to be trusted by the customer to decide what happens next.

That is potentially a very valuable position.

It is also why the winners may not be obvious today.

PhonePe could be disintermediated by AI, or it could turn its payment identity, merchant network and financial relationships into the trusted permission layer that AI needs. Google Pay could lose screen time, or Google could combine payments with Gemini and own far more of the transaction than it does today. Amazon could lose discovery to independent agents, or its catalogue, logistics and returns system could make it the merchant those agents trust most. Small brands could suddenly reach buyers through AI, or disappear because software shoppers care more about price and data than Instagram branding.

All of those outcomes are possible because the payment itself is becoming the least interesting part of the transaction.

The February Claude pilot still asked the customer for confirmation. Pine Labs has now shown that narrowly defined payments can happen later under an earlier mandate. NPCI is building the registry that could tell the financial system which software is acting. Visa, Google, Stripe and others are building similar systems abroad.

The next difficult step is not technical. It is deciding how much authority people are willing to hand over, who earns money from that authority and who carries the loss when the software makes the wrong decision.

UPI spent the last decade removing friction from moving money. Agentic payments could remove the person from parts of the decision itself, while still leaving that person legally and financially behind the transaction.

If that happens, the most important question in Indian payments will no longer be which app a customer uses to pay. It will be which company the customer trusts enough to let it decide when to spend.