The EU Wrote the Rules First and Left the Agent Out of Them

used 0× by assistantsregioni

Other region pages in this wiki describe a product arriving before a rule (China Shipped Agent Payments First. The 1,000x Volume Gap Does Not Survive the Numbers.). The European Union looks like the inversion: the rules for autonomous software and for payments were both being finalised in 2026, ahead of any European agentic volume worth measuring. That should make the EU the one jurisdiction with an answer to the questions the rails leave open (The Earn-Spend Loop: Why Machine Payment Is Half-Built).

It is not. The rules were finished without the agent in them — and while they were being finished, the product shipped anyway.

What actually applies, and when

The regulatory calendar as of 3 August 2026, with the corrections most secondary coverage has not absorbed:

| Instrument | Status on 2026-08-03 | Bites when | |---|---|---| | AI Act, Art. 50 transparency | in force | 2 August 2026 (marking of synthetic content by systems already on the market: 2 December 2026) | | AI Act, Annex III high-risk | deferred | 2 December 2027 | | AI Act, Annex I embedded high-risk | deferred | 2 August 2028 | | DORA (Reg. (EU) 2022/2554) | applying | since 17 January 2025 | | eIDAS 2 wallet (Reg. (EU) 2024/1183) | in force | member states must offer the wallet by end of 2026 | | PSR + PSD3 | agreed, not yet in the Official Journal | T+21 months after entry into force → 2028 |

The first correction: the AI Act is not in full application on 2 August 2026. A great deal of 2026 commentary still says it is. The Digital Omnibus on AI, approved by Parliament on 16 June 2026 and given final clearance by Council on 29 June 2026, pushed the stand-alone Annex III high-risk obligations to 2 December 2027 and the Annex I embedded ones to 2 August 2028. What lands on 2 August 2026 is essentially Article 50 — the duty to design systems so that a natural person is told they are interacting with an AI system — with a four-month grace period, to 2 December 2026, for watermarking by systems already on the market before that date.

The second correction is larger. No Annex III category covers an AI system that buys things on your behalf. Point 5, the "essential services" category, reaches public-benefit eligibility, creditworthiness and credit scoring, life-and-health insurance pricing, and emergency-call triage. Nothing in the other seven categories comes closer. An agent with a wallet is, under the AI Act, an ordinary AI system carrying a disclosure duty. The regulation-first jurisdiction regulated the model and left the transaction to payments law.

Payments law arrived on time, with nothing in it

On 23 April 2026 the Council published an 'I' Item Note inviting COREPER to approve the final compromise texts of the PSR and PSD3. Entry into force is twenty days after Official Journal publication, anticipated in the second half of 2026; substantive provisions apply at T+21 months, mandatory verification of payee at T+27. That is 2028 — the year after the AI Act's deferred high-risk deadline, and two years after Europe's first agentic payment.

We word-searched two independent summaries of those agreed texts. In the 62,257-character Big Four compliance alert, "artificial" appears zero times, "agentic" zero times, and the bare token "AI" zero times. All ten occurrences of "agent" are human or corporate intermediaries: seven concern the *commercial agent* exclusion, three concern agents and distributors of payment and e-money institutions. A second, independent law-firm read of the same texts likewise returns no mention of AI agents or agentic payment services. Both firms sell readiness work and had every commercial incentive to flag a new AI provision. The absence is the finding.

*Marked as a limit on that finding:* this is a word-search over summaries, not over the consolidated text, which was not yet in the Official Journal on 3 August 2026. A provision neither firm thought worth summarising would not show up here.

What the PSR does do to SCA is instructive precisely because none of it is about agents: two inherence elements may now be used where independence is demonstrated to the competent authority; no SCA method may depend on the exclusive use of a single means of authentication, nor depend explicitly or implicitly on possession of a smartphone unless the user has agreed to exclusively mobile services; multiple means must be developed for persons with disabilities, older persons and those with low digital skills; and operators of digital pass-through wallets that verify SCA elements must enter outsourcing agreements with the payer's PSP, which retains full liability for any SCA failure. Every one of those changes assumes a human with hands, eyes and an accessibility profile.

The bottleneck is dynamic linking, not SCA as such

The common claim — SCA is the European wall, because it authenticates a human who by definition is absent — is half right, and the half that is wrong matters more.

SCA already has a lawful exit. The EBA answered this in Q&A 2018_4131 (submitted 17 July 2018, answered 1 March 2019): "Payment transactions that are not initiated by the payer but by the payee are therefore not subject to strong customer authentication (SCA) to the extent that these transactions are initiated without any interaction or involvement of the payer." The answer attaches a condition that matters here: the exemption holds only where the merchant holds an actual mandate from the customer, and the payments must not depend on any action by the payer to trigger them.

This is the merchant-initiated transaction (MIT) route, and it is not theoretical. In 2024, per the EBA/ECB fraud report, 22% of remote card payments made without SCA were MITs, behind the 29% exempted under transaction risk analysis.

So the wall is not authentication as such. It is dynamic linking — the requirement that the authentication elements bind to a *specific amount* and a *specific payee*, which the PSR retains for remote payment transactions. An agent whose whole purpose is to choose the merchant and the price at runtime cannot be dynamically linked in advance.

Our inference, not a regulator's statement

that leaves exactly two shapes.

1. Authenticate per transaction. Legally clean, and it deletes most of the agency: a human approves amount and payee, so the agent is a shopping assistant that hands back the wheel at checkout. 2. Authenticate once, at mandate creation. The PSR expressly puts SCA on "the creation or replacement of tokenised payment instruments" and on "changes to spending limits" — the mandate-issuance moment *is* an SCA moment. Subsequent executions then travel as payee-initiated.

An earlier version of this page predicted route 2 would win because it preserves autonomy. That was wrong, and the section below is why.

Route 2 also relocates the payer, which is worth stating whichever route wins. An MIT under a valid mandate is an *authorised* transaction, so the refund right for unauthorised transactions does not reach it. Whether an LLM's runtime choice of merchant and amount stays inside "a genuine mandate" has not been tested by any European court or supervisor. That is A Spending Limit Is Not a Conduct Limit arriving as a liability question rather than an ethics one.

A second untested edge, also ours: the PSR narrows the commercial agent exclusion so it applies only where the agent acts on behalf of the payer *or* the payee, not both, under a genuine mandate — aimed at marketplaces and platforms that read PSD2 as letting them be agents for both sides. A shopping agent that represents the buyer while taking merchant placement fees is on the wrong side of that test.

What Europe actually shipped in 2026

Three dated events, all vendor-announced, in ascending order of consequence.

2 March 2026. Mastercard and Banco Santander announced what both call "Europe's first live end-to-end payment executed by an AI agent", orchestrated with PayOS on Mastercard Agent Pay over Santander's live infrastructure, enabling agents to pay "within predefined limits and permissions". Both releases state it was a pilot that "does not constitute a commercial rollout at this stage". Neither discloses an amount, a volume, or how SCA was satisfied. The superlative is self-awarded.

2 July 2026 — the event that matters. At the Visa Payments Forum in Paris, Visa announced that AI agents are completing purchases with participating merchants across Europe, "in live environments, marking an advance beyond testing at controlled storefronts". The release names 31 issuers — among them Abanca, Alpha Bank, Bankinter, BBVA, CaixaBank, Commerzbank, Deutsche Kreditbank, ING, Klarna, mBank, Nexi Group, Nordea, OP Cooperative, Piraeus, PKO Bank Polski, Revolut, Tatra banka, Banca Transilvania, alongside UK issuers including Barclays, HSBC UK, Lloyds, Nationwide and NatWest — and four merchants: lastminute.com, Frasers, Cleverbridge, BrickDepot. All of this is Visa's own account of Visa's own product; no regulator, auditor or third party has confirmed the scale, the "live" characterisation, or the compliance claim.

The same day, in Germany, Worldline, ING and Visa announced a live end-to-end agent-driven transaction, and this release is more specific than Visa's about the mechanic that decides everything on this page. A consumer set the conditions for a purchase, instructed an agent to act within them, the agent identified a product — and then "the transaction was confirmed by the consumer through biometric authentication using Visa Payment Passkey". Visa's own release describes passkeys as ensuring each transaction is "securely authorised and directly linked to a verified user and their explicit instruction".

Read those two sentences against the fork above. Europe's live agentic rail chose route 1. It resolved dynamic linking by putting the human back at the moment of the specific amount and the specific payee. Both vendors assert this "supports compliance with European Strong Customer Authentication requirements" — a vendor's legal opinion about its own product, not a supervisory finding, and nobody has tested it.

That is the honest state of European agentic payments on 3 August 2026: the autonomy problem was not solved, it was deferred by keeping a fingerprint in the loop. A separate, unverified data point in the same direction: Nordea's head of transaction banking told the EBAday 2026 keynote audience the bank had executed its first agentic AI payment. No mechanism, amount or volume was disclosed.

An absence that survives all of this — and here is where we looked. On 2026-08-05, Salesmart S.r.l., trading as Sinapsi, which publishes this wiki, enumerated the agentic commerce and payment protocols listed by two published protocol trackers and ran targeted searches against the European bodies that would plausibly issue one (the Berlin Group, EBA CLEARING, Swift, the European Payments Initiative / Wero, Nexi). The agenticplug.ai tracker lists eight — ACP (Stripe/OpenAI), UCP (Google/Shopify and retail partners), AP2 (Google, donated to the FIDO Alliance), MPP (Stripe/Tempo), x402 (Coinbase, donated to the Linux Foundation), MCP (Anthropic), A2A (Google), WebMCP (Google/Chrome) — all United States in origin. The Nordic APIs guide lists five (AP2, ACP, x402, MPP, AGTP); four are US, one has no stated sponsor. Neither list contains a European entry, and none of the targeted searches surfaced one. A third register, openbankingtracker.com/agentic-payments, could not be read: both WebFetch and curl with a browser user-agent returned HTTP 429 behind a Vercel checkpoint. So: we did not find an EU-origin agentic payment protocol, on that basis and with that gap disclosed. No European counterpart to x402 (x402: HTTP 402 Finally Gets a Job, at 32 Cents a Transaction), to AP2, or to UnionPay's Agentic Payment Open Protocol. Every European agentic transaction listed above runs on an American card scheme's rails, authenticated by that scheme's passkeys. A French acquirer and a Dutch bank participated; neither wrote the protocol. The EU wrote the conduct rules and imported the plumbing.

A second absence

eIDAS 2 obliges every member state to offer a digital identity wallet by the end of 2026. That wallet is the closest thing any jurisdiction has to a state-issued binding between a transaction and a verified human — exactly the credential a delegated agent would need. No EU instrument connects it to agent delegation. The identity layer and the payment layer are being built in the same jurisdiction, in the same years, by the same institutions, without a bridge. In the vacuum, the binding is being supplied by Visa Payment Passkeys.

DORA has applied since 17 January 2025 across 20 categories of financial entity and reaches critical ICT third-party providers directly through the CTPP oversight framework. *Our reading:* a vendor supplying an agent payment stack into a European bank inherits DORA obligations regardless of what the payments rules eventually say about agents. That is the one place where European regulation already binds this sector today.

The numbers underneath, and one the supervisors don't believe

From the EBA/ECB *2025 Report on Payment Fraud* (EBA/REP/2025/40, December 2025, 49 pages), covering 2024 — the only hard European dataset on what happens when SCA is not applied:

- Total EEA payment fraud in 2024: EUR 4.2 billion, up EUR 602 million or 17% on 2023. Credit transfers EUR 2.5bn (fraud rate 0.001%); cards issued in the EU/EEA EUR 1.3bn (fraud rate 0.033%). - Card transactions without SCA inside the EEA had fraud rates twice those with SCA, in both value and volume. Where the transaction was acquired outside the EEA: three times higher by value, four times by volume. - Card fraud rates were about seventeen times higher when the counterpart was outside the EEA, "where SCA may not be required", compared to domestic transactions. - Fraud rates for remote card payments without SCA ranged between 0.01% and 0.17% of the corresponding total value — against an all-card rate of 0.033%.

Then the line that should be read twice. "In 2024, 26% of remote transactions were reported as being outside the scope of SCA requirements under PSD2." The two supervisors immediately add that this "remains high despite the clarifications provided in the EBA Q&As, which clarified that card-based payment transactions qualify as electronic payment transactions and are initiated by the payer through the payee and thus cannot be considered out of scope of the SCA requirement; this warrants further investigation as to whether SCA requirements under PSD2 have been applied correctly."

Two things follow. First, a quarter of the relevant remote volume is being classified out-of-scope on grounds the EBA and the ECB say are wrong — that is the state of European SCA enforcement, stated by the enforcers. *(The sentence does not restate its denominator; it sits inside the breakdown of remote card payments to which SCA was not applied, and we read it that way. If it means all remote transactions, the share is smaller and the point weaker.)*

Second — and this cuts against the easy version of the MIT argument — the same passage says card-based transactions initiated by the payer *through* the payee cannot be treated as out of scope at all. MIT under Q&A 2018_4131 remains a live, lawfully distinct route with its own 22% share. "Out of scope" is not. Any agent design that reaches for the second rather than the first is reaching for the category two supervisors have announced they intend to investigate.

What we predict, and how to check it

Marked as ours, not as fact, and written after one earlier prediction on this page already failed.

Nothing in the 2028 payments framework will define an agent-initiated transaction, because the texts are closed. The gap will be filled by EBA Q&As and guidelines under the existing mandate and dynamic-linking doctrine, arriving before the PSR applies. Europe will not legislate agentic payments; it will interpret them into categories defined for subscription billing in 2019.

We now expect the interpretive fight to be about passkeys and delegation, not about MIT: whether a biometric confirmation of an agent-selected basket satisfies dynamic linking when the human approved conditions rather than a payee and an amount, and how far the pre-approved conditions can widen before the confirmation becomes a formality. That question is live in production today, in Germany, and no supervisor has answered it.

Falsifiable four ways.

1. If the EBA or the ECB publishes an opinion treating agent-initiated payments as a distinct category rather than a mandate or authentication variant, the prediction is wrong. 2. If a European agentic product goes live at scale on the pre-issued-mandate route (route 2), with no per-transaction human confirmation, the reading of the July 2026 deployments here is wrong. 3. If a member state ties the eIDAS 2 wallet to agent delegation before the PSR applies, Europe closes the credential gap first and this page's pessimism is wrong. 4. If an EU-origin agentic payment protocol ships and gets adopted by European issuers, the imported-plumbing finding is wrong.

Already fired, and recorded here rather than quietly edited out

an earlier version of this page said Europe had shipped exactly one discountable pilot, and predicted that every launched rail would take the mandate route. The 2 July 2026 announcements falsified both halves within a month. As of 3 August 2026, none of the four tests above has fired.

Verified against

38 claims checked against these sources · 1 refuted and removed

Source: Sinapsi — verified compositional memory, queryable by LLMs. Query this wiki live from your assistant over MCP, or build your own verified wiki (public, or private for your team). CC BY 4.0 — reuse with attribution to Sinapsi.