AI Software

India’s UPI AI Agent Registry: Can Autonomous Payments Be Trusted?

AI agent securing UPI payments across India for The AI Review Hub

India’s next major UPI change may be less visible than scanning a QR code. It could allow an AI agent to make selected payments on a user’s behalf.

On September 10, Reuters reported that the National Payments Corporation of India is developing a registry to verify and monitor AI agents transacting on UPI. NPCI Chairman Ajay Kumar Choudhary also said the organisation is examining protocols for identifying and authorising digital agents.

This is a research-led assessment of a developing framework—not a review of a live consumer service.

What is being proposed?

The planned registry is expected to form part of a Unified Agentic Protocol. Its purpose would be to establish whether an AI agent is recognised and authorised before it initiates a payment.

Reuters previously reported that early uses could include small, frequent purchases such as groceries. A user might provide upfront instructions covering what the agent can purchase, when it can act and how much it can spend, instead of approving every individual transaction.

The framework may build on UPI Circle, which supports delegated payment authority, and Reserve Pay, which can block funds for multiple future debits. These details come from unnamed industry sources and have not yet been published as a final NPCI specification.

The scale matters. UPI processed 24.51 billion transactions worth ₹29.82 trillion in August 2026. Introducing autonomous agents into a network of that size requires more than trusting a chatbot’s judgment.

Why does an AI-agent registry matter?

Today, a payment system identifies customers, merchants, banks and applications. Agentic payments introduce another participant: software that interprets an instruction and decides when to act.

A registry could help establish:

  • Who developed and operates the agent
  • Which payment providers recognise it
  • What permissions it has received
  • Whether its approval remains valid
  • Which version initiated a transaction
  • How its access can be suspended or revoked

My inference is that this could become a “Know Your Agent” layer alongside existing customer and merchant controls. State Bank of India Chairman Challa Sreenivasulu Setty used the same KYA concept at the Global Fintech Fest, arguing that trust must be built in as AI moves from recommendations to execution.

What could users and businesses gain?

A controlled payment agent might reorder routine household items within a budget, pay recurring expenses, purchase when a defined discount appears or complete a transaction started through a conversational assistant.

For businesses, agentic payments could reduce checkout friction and support new automated purchasing journeys. Within an organisation, a tightly controlled agent might eventually pay approved low-value expenses or subscriptions within established policies.

The important benefit is conditional delegation. The user defines the boundary once, and the agent acts only when those conditions are met.

A registry will not make every transaction safe

Knowing an agent’s identity does not prove that it understood the instruction correctly. It could select the wrong product, accept a misleading offer or follow malicious instructions embedded in a webpage.

Security research into agent-payment protocols has highlighted risks including replay attacks, where an approval is reused, and context redirection, where valid authority is applied to a different transaction.

A workable framework will therefore need more than registration. It should include transaction-level mandates, spending and merchant limits, short expiry periods, one-time authorisations where appropriate, immediate revocation, visible audit trails and a clear dispute process.

Liability remains a central unanswered question. If an agent buys the wrong item or exceeds the user’s intent, responsibility could sit with the user, agent provider, bank, payment application or merchant. Current public reports do not provide a final answer.

Initial verdict

An AI-agent registry is a necessary foundation for autonomous payments on UPI, but it is not sufficient protection by itself.

India’s approach appears sensible because it starts with identification, delegated authority and low-value use cases. However, deployment should remain limited until transaction controls, user consent, data use, refunds and liability are clearly defined.

The real test will not be whether an AI agent can make a payment. It will be whether the user can understand, restrict, trace and reverse what the agent has done.