Mastercard Begins U.S. Testing of a Score That Flags AI Agent-Initiated Transactions: Agent Pay's Intelligence Layer and What It Means for E-commerce Merchants
Mastercard has expanded Agent Pay with a probability score for AI agent-initiated transactions and new behavioral and risk signals. We explain why legitimate agent-led orders get falsely declined and what e-commerce merchants should check.
Key Takeaways
- On September 30, 2026 (U.S. time), Mastercard expanded Agent Pay with a probability score indicating how likely a transaction was initiated by an AI agent (now in U.S. testing), along with risk signals covering behavior, merchants and credentials
- Fraud detection built around human behavior tends to flag legitimate agent-led orders as suspicious. This announcement is an attempt to give issuers, at the network level, the context they need to recognize transactions they can safely approve
- The score is mainly for issuers and payment providers, not something merchants install themselves. Accuracy, pricing and what merchants will be able to see remain undisclosed, so the practical starting point is verifying agent signatures and revisiting bot controls
Mastercard Adds an Agent-Initiated Probability Score to Agent Pay

Today, Mastercard announced an expansion of Agent Pay, its agentic payments program, with new trust and intelligence services that provide greater context for AI-initiated transactions.
www.businesswire.comOn September 30, 2026, Mastercard announced new trust and intelligence services for Agent Pay, its agentic payments program. The services combine identity, intent, behavioral and fraud insights so that financial institutions and merchants can understand AI-initiated transactions from a shared starting point.
The first service is a probability score indicating the likelihood that a transaction was initiated by an AI agent. It is rolling out for testing in the U.S. Over time, Mastercard says it will strengthen the score with intelligence on behavior, merchant risk, transaction patterns, credential risk (risk tied to card details and other credentials) and consumer propensity.
Ann Johnson, who leads Mastercard's security solutions, said that adding risk insights to each transaction will give people the confidence to say "yes." That "yes" is the consumer's consent, and it is also the card issuer's authorization decision. Since launching in April 2025, Agent Pay has focused on securing the entry point of a transaction, with agent tokens and proof of intent (Verifiable Intent). This release adds a component that evaluates what is inside the transaction.
Why Legitimate Orders Get Flagged as Fraud
Card fraud detection has long relied on human behavior: device fingerprints, session flow, click sequences and authentication steps. When an agent does the shopping, those signals break down together.
Chargebacks911 has warned that legitimate AI-initiated purchases are being misclassified as malicious bot activity, triggering a wave of false declines. Founder Monica Eaton noted that the fraud systems most merchants rely on were "built to detect bad human behaviour," not for a world where a legitimate agent and a malicious bot look almost identical.
In retail e-commerce terms, picture this. A consumer hands household restocking to an agent, and late at night the agent places orders for detergent, pet food and coffee beans across several stores at once. This combination of an unfamiliar hour, rapid back-to-back payments and merchants the cardholder rarely uses is a textbook "suspicious" pattern under conventional rules. Mastercard's release gives a similar example: multiple purchases across different merchants completed with a single approval may look unusual on the surface yet still be legitimate.
The hard part is that nobody sees the decline. A PYMNTS analysis points out that when an agent is declined, the consumer may never see a checkout screen at all. If the agent quietly switches to another merchant, the merchant never even learns it turned the order away. Approval rates alone can no longer capture the revenue that was lost. And because a false decline carries no chargeback, the loss never shows up on the books.
What the Score and Signals Answer
The probability score estimates where a transaction came from. Once an issuer knows a purchase came through an agent, it no longer has to treat a departure from human behavior patterns as a fraud signal in itself. According to the release, the signals that accompany the score answer three questions:
- Is the activity consistent with expected behavior or patterns?
- Does the agent, merchant, credential or transaction show anything unusual that requires further review?
- Should the transaction be approved, or are additional checks needed?
The white paper "Trust for agentic commerce," published around the same time, makes the intent clearer. It rejects a simple approve or decline choice. Instead, it describes four responses scaled to the stakes: approve as asked, approve within a narrower limit, refer back for confirmation, or decline. A decline that is explained and correctable is framed as a trust outcome too.
The white paper's appendix names the main users of this decisioning layer as "issuers and wallets, acquirers and PSPs." It also addresses agents that have not been onboarded. When an unknown agent interacts with a merchant or issuer, behavior and risk signals help distinguish legitimate activity from malicious activity, but the paper draws a line: this does not extend trust to the agent; it provides the visibility needed to evaluate it.
This announcement corresponds to the last of the five layers in the Agent Pay Trust Framework described in the white paper, the intelligence layer. Here is the full picture.
| Layer | Question it answers | Main components named in the white paper |
|---|---|---|
| Identity | Who is acting? | KYA, KYM and KYC (checks on agents, merchants and consumers), agent registration |
| Intent | What was authorized? | Verifiable Intent, Agentic Disputes (dispute handling based on intent evidence) |
| Controls | What is the agent allowed to do? | Agent Controls (limits on where, how much and under what conditions) |
| Trusted execution | Did value move securely? | Tokenization, Acceptance Framework, Agent Connect |
| Intelligence | Is risk still visible as behavior changes? | The new probability score and signals, Fraud Models for Agentic, Recorded Future threat intelligence |
The white paper says that if any one of these is missing, the secure default is refusal: merchants block good agents, and issuers decline good transactions.
Web-Side Signals From Cloudflare and Skyfire
A payment network mainly sees payment data. Which sites an agent visited, how it moved through them and when it chose to buy all happen outside the network. Cloudflare and Skyfire were named as the partners to fill that gap.
With Cloudflare, Mastercard is exploring how to combine web signals with payment network signals in privacy-preserving environments to give better visibility into AI transactions. The foundation is the approach Cloudflare described in an October 2025 blog post. Both Agent Pay and Visa's Trusted Agent Protocol use Web Bot Auth (a method of attaching cryptographic signatures to HTTP requests to identify an agent) as their authentication layer. Within the signature, the agent adds a tag showing whether it is browsing (agent-browser-auth) or paying (agent-payer-auth). Merchants and Cloudflare can verify the signature to confirm the agent is registered.
Skyfire provides KYA (Know Your Agent, identity verification for agents) technology, and is working with Mastercard to help financial institutions and merchants recognize trusted agents and make better authorization decisions. CEO Amir Sarhangi said that "every AI agent that transacts on someone's behalf should be identifiable, accountable and auditable." On the issuer side, Capital One commented that visibility into how transactions are initiated, authorized and executed will be critical.
What This Means for E-commerce Merchants
The probability score is not a tool merchants embed in their own sites. It is information for the issuers that make authorization decisions, and for the PSPs and acquirers in front of them. Even so, it hits merchant revenue directly. If issuers can treat agent-led orders as "agent transactions" rather than "anomalies," orders that disappeared to false declines come back.
On the other hand, misjudgments that happen on the merchant's own side are not solved by a network score. If a merchant's bot controls or WAF (web application firewall) turn away a legitimate agent at the door, the transaction is gone before any score is used. Cloudflare has said it will create managed rules that make it easier to allow agents using Agent Pay or the Trusted Agent Protocol, which gives merchants a reason to revisit blanket bot blocking.
What merchants can check today comes down to four points:
- Whether their bot controls can identify agents carrying Web Bot Auth signatures
- Whether fraud thresholds and rules account for the difference between human and agent purchasing behavior (Chargebacks911 also recommends this review)
- How their PSP or acquirer handles Agent Pay agent transactions, and what information it passes back to the merchant
- Whether they keep a record of what was authorized and what was executed for agent-led orders
The last point ties directly to disputes. The white paper includes Agentic Disputes, which uses the Verifiable Intent audit trail to resolve chargebacks faster, in the same framework. A survey cited by PYMNTS found that while 56% of consumers would let AI agents compare products, only 35% would let them access saved payment methods. Authorization accuracy is one of the conditions for closing that gap.
Caveats: Accuracy, Privacy and Competing Approaches
The announcement sets a direction, but many of the conditions needed to judge it are undisclosed. Mastercard has not revealed the score's accuracy or false positive rate, the names and number of issuers in the test, the price of receiving the score, or which field of the authorization message carries it. Whether merchants will be able to see the score or the reasons behind it is also undisclosed.
Privacy is another open question. The work combining Cloudflare's web signals with Mastercard's payment data is described as taking place in "privacy-preserving environments," but which data is used, by whom and to what extent has not been explained. Concerns about linking browsing behavior to payments will remain until the details are published.
Competing approaches cannot be ignored either. In October 2025, Visa announced the Trusted Agent Protocol, designed to pass three kinds of signals to merchants: agent intent, consumer recognition and payment information. According to Cloudflare's blog, Visa-registered and Mastercard-registered agents are managed in separate key directories hosted by each network. From the merchant's point of view, there is more than one party to verify.
The market view is measured as well. A GuruFocus article noted that identifying an AI transaction does not create another payment, and that the service becomes a business only once it delivers measurable fraud reductions.
The goal is to distinguish legitimate authorized activity from automation designed to deceive and steal.
The question is not "is this an agent?" but "is this a legitimate agent acting within the bounds of the consumer's intent?" The probability score answers only the first, and the second still requires proof of identity and intent.
Summary
As agent-led shopping spreads, the main cause of lost revenue shifts from fraud itself to turning away good orders. Mastercard's probability score and signals are the first component for solving that problem at the network level.
The next things to watch are which metrics Mastercard uses to report the U.S. test results, how much information is opened up to merchants, and how this approach will coexist with Visa's. For merchants, the first step is not waiting for the score, but making sure they can correctly recognize agents at their own front door.


