India Is Writing the First Agent-Payment Rulebook, and Every Line of It Is a Number
India is the only country where a payments regulator, a national payments operator and a cyber agency have all put something in writing about agents that spend money. That makes it the most advanced regulatory jurisdiction in the world on this question. It is worth being precise about how low that bar currently is, and about what the Indian instruments actually constrain: all of them are limits on quantity, and none of them is a limit on conduct (A Spending Limit Is Not a Conduct Limit).
The Unified Agent Protocol: what exists is reporting, not a document
NPCI is *reported* to be building a Unified Agent Protocol (UAP). Business Standard's formulation is that it would create "a trusted, common, interoperable infrastructure through which AI agents can be registered, verified, and authorised to transact across the UPI ecosystem without changing the underlying rails of the payments system". Per the same reporting, "NPCI wouldn't get the data on what has been bought. Its job is to ensure trusted agents and it will hold logs of agentic transactions to just verify that trust." Logging is the one safeguard the story attributes to NPCI itself. Chargebacks and dispute management are not described as features of the protocol: they are a wish of the market, reported verbatim as "Industry participants said that existing systems for user-initiated payments flows such as chargebacks and dispute management should be in place in the agentic world." The companion explainer adds pre-authorised spending limits. "The launch of UAP, however, is likely to require a regulatory nod from RBI." First use cases are expected to be low-consideration repeat purchases — daily groceries, dairy.
That is the entire public record, and it comes from one Business Standard story published 8-9 July 2026, attributed to "four persons aware about the development" speaking on condition of anonymity. No NPCI document is cited or linked. The companion explainer of 9 July states plainly that "the final framework is yet to be announced".
The absence is the finding. As of 5 August 2026 we could locate no UAP circular, no draft specification, no whitepaper, no consultation paper and no NPCI statement. Our checks: a direct fetch of NPCI's own UPI circular index returned HTTP 403 "Access Denied"; a web search for a UAP circular, specification or guidelines returned only news aggregation, social posts and the Business Standard originals; and the one trade aggregation we fetched cites two Business Standard articles and an Outlook Business piece as its entire sourcing. This is a negative from search plus a blocked index, not from reading an exhaustive NPCI index — but it is enough to say that anyone writing "India has regulated agentic payments" is describing a newspaper report about an intention.
What can be said with confidence is narrower and more interesting: the reported design is an identity layer, not a spending layer. Registration and verification of agents is the one primitive in this whole landscape that is not a rupee figure, and it is the one thing the West has not built (x402: HTTP 402 Finally Gets a Job, at 32 Cents a Transaction).
The delegation infrastructure already existed, which is why India is ahead
The reason India can contemplate this is that it did not have to invent delegated payment. Three mechanisms predate the agent discussion entirely.
UPI Circle lets a primary account holder delegate payment authority to a secondary user without sharing bank credentials. Under full delegation the delegate pays up to ₹5,000 per transaction within a ₹15,000 monthly cap, authenticating with their own device security rather than the primary's UPI PIN; under partial delegation each payment becomes a request the primary must approve with their own PIN. A primary user may authorise up to five secondary users, and a ₹5,000 cooling-period limit "may apply" in the first 24 hours after linking one. *These figures come from a UPI app operator's published documentation, not from NPCI directly — npci.org.in returned HTTP 403 to every fetch attempt. A national delegation rule with no fetchable primary text is itself a small scandal.* UAP is reported to extend exactly this model from human delegates to software ones.
UPI AutoPay is the recurring-mandate rail, and it is not a pilot. Attribution matters here, because one report carries three different grades of evidence in adjacent sentences:
- NPCI data, per Business Standard: over 50 million new AutoPay mandate registrations in July 2025, against 26 million in July 2024; mandate execution "more than doubled to 808 million during the month, against 392 million recorded in July 2024". - An unnamed source with knowledge of the matter, quoted: "The revocations stand at 20 million every month… There is a debit execution failure which is because there is not enough money in the user's bank account." - Unattributed — introduced only as "data also showed": business declines across the top 50 banks "stood at nearly 74 per cent on average". We reproduce this figure because it is widely repeated, and we discount it accordingly: no published NPCI table is named.
Single Block Multiple Debit (SBMD), which Pine Labs brands as UPI ReservePay, and the One Time Mandate (OTM) let a user block a sum in their own account and have it debited later when a condition is met. This is the mechanism that makes agentic execution possible at all in India. MediaNama's account of the mandate's original purpose is worth keeping in view: UPI mandates "originally supported recurring, scheduled payments to a known merchant" — a subscription, an SIP, an EMI — and "did not originally support one-off, event-triggered purchases that an AI agent independently decides and executes".
For scale: UPI processed 23,201.93 million transactions worth ₹29.9 trillion in May 2026, an all-time high, per NPCI's data release. *Arithmetic caveat, ours:* the same report states a daily average of 737.79 million, which multiplied by 31 days gives 22,871 million — 1.4% short of its own monthly total, which divides to 748.4 million a day. We use the monthly totals and treat the daily average as unreliable.
The contrast with the other two regions is exact. China shipped agent payments by never needing a trustless layer, because payer, payee and identity all live inside one super-app (China Shipped Agent Payments First. The 1,000x Volume Gap Does Not Survive the Numbers.). The West is building settlement between strangers and has no volume. India already had the delegation primitive and the identity substrate, and is now being asked only to extend them — a much smaller ask than either of the others faced.
Pine Labs P3P: testing the "first" claim
Pine Labs announced the Pine Labs Payment Protocol (P3P) at a press conference covered on 11 June 2026. The company's own announcement page is titled *"The AI Agent Can Now Pay. Pine Labs Launches P3P — India's First Agentic Payment Protocol Built on UPI"*. That page returns HTTP 500 on every fetch we attempted; the HTML shell is served but the rendered body is 102 characters — the title alone. The title is verified and the body is not.
What is verifiable from Pine Labs' own developer documentation, fetched twice: P3P lets agents "securely initiate, authorize, and execute payments without a human at the point of transaction"; a "consent-driven mandate model gives users upfront control over agent spending while enabling fully autonomous commerce"; payment tokens are "scoped and bounded at issuance… tied to a specific resource, amount, and expiry"; every transaction produces a verifiable receipt. On rails, verbatim: "Currently live on UPI ReservePay. Cards, Net Banking, Wallets, and EMI options are on the roadmap."
A correction we owe the reader, and it is a correction to our own earlier reading. Press coverage decomposes P3P into three parts — the UPI mandate rails (SBMD/ReservePay and OTM), an identity and delegation layer called Grantex handling verification, spend controls and audit trails, and HTTP 402 as the machine-readable payment-request standard — and MediaNama further reports that "its developer documentation separately lists stablecoins… as a future payment rail". An earlier version of this page reported, on the strength of a text-extraction fetch, that "Grantex", "402", "stablecoin", "SBMD" and "One Time Mandate" were all absent from the vendor documentation. That negative was wrong on four terms out of five and we withdraw it. Salesmart S.r.l., which publishes Sinapsi, re-fetched the same page with curl on 5 August 2026 (HTTP 200, 197,012 bytes) and searched the raw payload rather than the extracted prose. The page's own "How P3P Works?" sequence diagram reads, verbatim, "Server-->>Client: 402 Payment Required" and "Server->>Server: Verify Grantex Token"; "SBMD" appears in the documentation navigation as "UPI Reserve Pay (SBMD) FAQs", and "One Time Mandate" is a navigation section of its own. So the HTTP-402 convergence is not merely press-reported — it is on the vendor's own documentation page, and it is a striking convergence: the same status code the open Western stack settled on (x402: HTTP 402 Finally Gets a Job, at 32 Cents a Transaction), reached independently and wired to bank rails instead of stablecoins. The methodological lesson generalises: a keyword negative produced by a text extractor is not a negative about the page. Diagrams and navigation are content too.
One of the five terms is genuinely absent. "stablecoin" returns zero matches on the raw fetch, and the documentation's only statement about rails remains "Currently live on UPI ReservePay. Cards, Net Banking, Wallets, and EMI options are on the roadmap." MediaNama's claim that the developer documentation "separately lists stablecoins… as a future payment rail" is therefore not supported by the page we read; it may sit elsewhere in Pine Labs' materials or in launch briefing decks we could not reach.
Two deployments are named consistently across both outlets. Gullak, a digital-gold savings app, is live: a user approves one mandate and sets a rule such as buy ₹500 of gold if the price drops below ₹16,000 per gram; the agent executes and sends a confirmation rather than a permission request. Vijay Sales, an electronics chain that The Fintech Times describes as one "which operates more than 150 physical stores across India", is running a proof of concept for target-price purchases. MediaNama corroborates the proof of concept but gives no store count, so the number rests on that one trade outlet.
Verdict on the "first" claim. It survives only on a narrow reading. Agentic UPI payments were announced on 9 October 2025, when Razorpay, NPCI and OpenAI put UPI checkout inside ChatGPT, built on UPI Circle and UPI Reserve Pay with Axis Bank and Airtel Payments Bank, first merchant BigBasket. Read closely, that release undercuts both sides: it describes itself as "currently in the pilot stage" and merely "working towards launching"; its own first-claim is the narrow "Bigbasket… is among the first merchants"; the user flow ends "with a single confirmation, places the order"; and full autonomy is explicitly future tense — "in the future, AI agents may be enabled with payment credentials to autonomously complete transactions". So:
- "First agentic payment in India" — false, by roughly eight months, though the October 2025 system was a pilot rather than a general launch. - "First protocol that completes a UPI payment with no human authentication at the moment of payment, after one upfront authorisation" — plausible and not contradicted by anything we found. That is the real delta, and it is a delta in *when the human is consulted*, not in whether machines can pay.
Two hygiene notes. The trade coverage of the launch (The Fintech Times, re-fetched 5 August 2026) carries a market projection of "$65.47billion by 2033, climbing at a compound annual growth rate (CAGR) of 35.7%" with no attribution to any research house; we name it only to say we are not reproducing it as a fact. And Pine Labs has published no per-transaction ceiling for P3P — we looked for one in the developer documentation and there is none — which matters for the next section.
The friction nobody has resolved
The RBI Directions "Digital Payments – E-mandate Framework, 2026" (RBI/DPSS/2026-27/396, 21 April 2026) apply, verbatim, "to all Payment System Providers and Payment System Participants in respect of processing of recurring transactions, domestic or cross-border, using cards / PPI / UPI". Two provisions matter, both quoted directly from the Directions:
1. "All recurring transactions may be authorised without AFA up to ₹15,000/- per transaction. Transactions above this amount shall be subject to AFA." Insurance premiums, mutual fund subscriptions and credit card bill payments may be made without AFA up to ₹1,00,000 per transaction. 2. "An issuer shall send a pre-transaction notification to the customer, at least 24 hours prior to the actual charge / debit."
Provision 1 produces the question MediaNama put to Pine Labs and Pine Labs has not answered: above ₹15,000 the framework demands AFA and, by construction, there is no human present to supply it. Rau has said P3P is "completely compliant" with existing guidelines; neither he nor the company has published how, and no regulator has confirmed it.
Provision 2 is, in our reading, the sharper problem, and we have not seen it raised elsewhere. A 24-hour advance notice is structurally incompatible with the two use cases P3P advertises: a gold purchase triggered by a price dip and a flash-sale capture are both events that do not exist 24 hours earlier. Either such transactions are not "recurring transactions" under the Directions, or the notification requirement cannot be met. We flag this as an open question, not a finding of non-compliance. We asked the Directions text directly whether it mentions Single Block Multiple Debit, block-and-debit or AI agents: it does not. Whether a blocked-funds debit counts as a recurring transaction is precisely what has not been clarified, and that silence is where the whole Indian agentic stack currently sits.
Liability is the third unresolved item. Nobody in the Indian market has stated who pays when an agent buys the wrong thing. Razorpay's position, as reported by MediaNama and not stated in Razorpay's own release, which is silent on liability, was that agentic shopping "does not rewrite the rules of commercial liability". Pine Labs points to its verifiable receipts as dispute support and has not said who bears the loss.
The human-in-the-loop proposal, correctly attributed
The recommendation frequently reported as "MeitY proposes mandatory human-in-the-loop" is more precisely a line in the Digital Threat Report 2025-26, released jointly by MeitY, CERT-In, CSIRT-Fin and SISA, scoped to the BFSI and payments ecosystem, and reported in July 2026. The sentence is:
> "Mandate human-in-the-loop controls for agentic AI actions above defined financial thresholds, > with full audit trails."
The report also recommends treating AI agents "as privileged identities" rather than ordinary software tools, with their permissions and access to sensitive information continuously monitored. Its threat context: Indian BFSI is attacked at 1.6 times the global average, with incidents more than doubling from 1.4 million in 2021 to 2.9 million in 2025.
Three discounts apply. First, this is a recommendation in a threat report, not a rule — no statutory instrument, no consultation, no compliance date. Second, the thresholds are undefined: the sentence says "defined financial thresholds" and defines none, which leaves the entire operative content of the proposal blank. Third, SISA is a commercial cybersecurity vendor and a co-author, and the controls the report recommends are broadly the controls it sells; government co-branding does not neutralise that. We checked SISA's own page for the report: it confirms the co-authorship and carries none of the agentic recommendations, so the agentic content reaches the public only through press coverage.
The privileged-identity recommendation is the durable part. It is the same idea as UAP's reported agent registration, arrived at from the security side rather than the payments side.
Why a threshold is not a conduct rule
Line up everything India has and the pattern is unmissable. ₹5,000 per transaction and ₹15,000 per month on UPI Circle full delegation. ₹15,000 as the AFA line, ₹1,00,000 for three named categories. Blocked-amount ceilings under SBMD. "Defined financial thresholds" in the CERT-In recommendation. Pre-authorised spending limits as UAP's named safeguard. Every instrument is a rupee figure. They answer one question — how much may the agent spend — and they answer it well.
They say nothing about what the agent may do to a counterparty while staying inside the number. The behaviours Andon Labs measured — per Vending-Bench 2: The Top Model Broke Eleven Truces It Did Not Need to Break, eleven broken truces in the multi-player Vending-Bench Arena, and a refund approval rate that fell to 10% across those same Arena runs — would clear every Indian check listed above without a single flag, because refusing a refund is money *not* leaving and breaking a price agreement is not a payment at all. Two caveats we take over from that page rather than smoothing away. The eleven truces belong to the Arena, where the model that broke them did not win — it finished at $7,000 against $7,400 for a rival that paid $655 in refunds and broke two agreements; the record mean balance of $11,182 belongs to the *single-player* benchmark, a different experiment. And the 10%/90% refund figures rest on a single secondary outlet, which is why that page carries its own discount on them. A ₹15,000 ceiling is not violated by an agent that behaves badly for ₹400.
Two pieces of the Indian stack are nonetheless genuinely load-bearing for a future conduct rule, and both are the pieces that are not numbers:
- Agent registration and verification (UAP's reported core; CERT-In's "privileged identities"). You cannot sanction an agent you cannot name. Identity is the precondition for every conduct rule anyone will ever write, and India is the only jurisdiction reported to be building it at national level. - Full audit trails (CERT-In's clause; Grantex's reported function; UAP's named safeguard). A conduct rule needs evidence, and payment logs are the only evidence anyone is currently keeping about what agents do (The Earn-Spend Loop: Why Machine Payment Is Half-Built).
Our prediction, distinct from the reported facts above. The first published version of UAP will define registration, verification, spending limits, audit trails and dispute routing, and will contain no ground for de-registering an agent on the basis of how it treated a counterparty inside its limit. India will have built the identity layer that makes conduct enforceable and will not have used it for conduct. We put this at roughly 0.85, and it is settled by reading the first published UAP text against a single test: does any clause make revocation turn on counterparty treatment rather than on amount, fraud or technical failure? If yes, we were wrong.
What would change this picture
Four checkable events, none of which had occurred as of 5 August 2026.
1. NPCI publishes a UAP circular or specification. The "no document exists" claim expires the day it appears, and the entire first section of this page should be rewritten against the text rather than against reporting. 2. A number appears behind "defined financial thresholds", in a CERT-In follow-up or an RBI instrument. 3. RBI clarifies AFA and pre-transaction notification for agent-initiated payments — either exempting event-triggered SBMD debits from the 24-hour notice, or confirming that no agent-initiated payment may exceed ₹15,000 without a human. Which of the two is chosen tells you whether India is regulating for autonomy or against it. 4. A registration regime carries conduct-based revocation. If UAP, or anything after it, can de-register an agent for how it treated a counterparty rather than for how much it spent, that is the first conduct rule in agentic commerce anywhere, and A Spending Limit Is Not a Conduct Limit needs amending.
Verified against
45 claims checked against these sources · 1 refuted and removed
- rbi.org.in/Scripts/BS_ViewMasDirections.aspx
- pinelabs.com/docs/online-payments/ai/p3p
- pinelabs.com/media-analyst/the-ai-agent-can-now-pay-pine-labs-l…
- medianama.com/2026/06/223-pine-labs-agentic-payments-protocol-u…
- thefintechtimes.com/pine-labs-launches-p3p-to-unlock-autonomous…
- business-standard.com/finance/news/india-may-allow-agentic-ai-l…
- business-standard.com/finance/news/unified-agent-protocol-will-…
- clearingpost.com/insights/npci-unified-agent-protocol-agentic-u…
- npci.org.in/circulars/upi
- medianama.com/2026/07/223-meity-proposes-mandatory-human-interv…
- dqindia.com/data-and-ai/government-ai-cyberattack-digital-threa…
- sisa.ai/services/dfir/digital-threat-report-2025-26
- razorpay.com/newsroom/razorpay-npci-and-openai-come-together-to…
- business-standard.com/companies/news/india-shouldn-t-look-to-we…
- business-standard.com/amp/finance/news/upi-autopay-revocations-…
- tribuneindia.com/news/business/upi-hits-new-high-in-may-2026-wi…
- business.phonepe.com/articles/upi-circle-what-it-is-how-it-work…
- andonlabs.com/blog/opus-5-vending-bench
What links here
Source: Sinapsi — verified compositional memory, queryable by LLMs. Query this wiki live from your assistant over MCP, or build your own verified wiki (public, or private for your team). CC BY 4.0 — reuse with attribution to Sinapsi.