Picture asking your phone to “pay the electricity bill, renew my streaming subscription, and book the usual cab home”, and having it simply happen, with no PIN entry for each payment. That is the promise of so-called agentic banking: software that does not merely suggest what to pay but pays. India, whose UPI network carries about 24.5 billion transactions a month according to a recent report, is unusually well placed to build it, and the National Payments Corporation of India (NPCI) is reportedly working on the rules. Before anyone hands their money to a machine, it is worth knowing what has actually been announced, what has only been reported, and what could go wrong.
What is confirmed
At the Global Fintech Fest in Mumbai (8 to 11 September 2026), NPCI's non-executive chairman and independent director, Ajay Kumar Choudhary, said the body is “examining the protocols that may be required to identify and authorise digital agents within the Unified Payments Interface (UPI) ecosystem while preserving interoperability, auditability and settlement finality.” He also set out a principle. As MediaNama reported his remarks: “Decision making and execution must remain separate. AI may recommend, but authentication and final settlement must follow deterministic auditable rules.”
That is the extent of what NPCI has said on the record. MediaNama noted that no timeline, no RBI approval status, no transaction limits and no consent framework were disclosed at the keynote, and that its questions to NPCI remained unanswered.
“AI may recommend, but authentication and final settlement must follow deterministic auditable rules.” That sentence is the whole design philosophy.
What is reported, but not confirmed
Reuters reported, citing three unnamed sources, that NPCI is developing a Unified Agent Protocol (UAP) that would let AI agents make small payments on UPI without the user approving each one. NPCI has not formally confirmed the plan. As reported, it would build on two existing UPI features rather than invent new plumbing.
UPI Circle lets a primary user delegate payment authority to a secondary user, which in this case could be an AI agent. Under the “full delegation” setting, reports put the ceiling at Rs 15,000 a month and Rs 5,000 per transaction, and the limits floated for agents are described as similar to those NPCI already applies to delegated payments for connected devices. Reserve Pay lets a customer block funds for multiple later debits, at present up to about Rs 10,000 for up to 90 days. Treat these figures as the existing framework the protocol is expected to lean on, not as announced limits for agents.
Whether it needs approval from the Reserve Bank of India is likewise not settled in the reporting. Any product that moves customer money in India ultimately answers to the RBI, so a regulatory step would not be surprising.
What already exists
Private players have moved ahead. Pine Labs launched what it called India's first agentic payment protocol built on UPI, P3P, in June 2026, reported as live in production. A 2025 pilot involving Razorpay, NPCI and OpenAI tested payments initiated through ChatGPT using UPI Circle and Reserve Pay. Internationally, Mastercard reportedly demonstrated a first authenticated agentic transaction in February 2026. The direction is clear even where the details differ.
The risks, in plain terms
Overspending. An agent that is told to “find me a good course” may decide to buy one. MediaNama's commentary on the subject cited a case in which an agent authorised a $2,500 course purchase influenced by social-media content. Autonomy and control pull in opposite directions: the more the agent can do without asking, the less you see before money leaves.
Manipulation. An agent that reads emails, websites or messages can be misled by content written to trick it, a well-known weakness of current AI systems sometimes called prompt injection. In a payments setting, the concern is that a malicious page or message could instruct an agent to pay someone. This is a general risk for AI agents, not a finding about any specific Indian product, but payments are where it hurts most.
Accountability. When a human taps “pay”, responsibility is clear. When an agent pays under delegated authority and gets it wrong, who bears the loss: the user, the app, the bank, the agent's developer? Existing rules on unauthorised transactions were written for humans and stolen credentials, and may not map cleanly onto a case where the user technically gave permission.
What good design looks like
The NPCI chairman's principle points at the answer: keep the AI on one side of a wall and the money on the other. The agent works out what you want. A separate, deterministic system checks whether the payment is within your rules, authenticates it, and settles it, and leaves a record you can inspect.
Technology commentator Nikhil Pahwa has argued in MediaNama for specific controls: give each agent its own delegated identity, separate from the user's; protect it with its own PIN that the user can disable; and set tight, adjustable default limits. His illustrative starting point was very small, of the order of Rs 100 per transaction and a handful of transactions and a few hundred rupees a month, precisely so that a mistake costs little. He also argued that prepaid wallets, which cap exposure to what has been loaded, deserve a place alongside UPI. These are one commentator's proposals, not NPCI's plans, but they are a useful yardstick.
The safest agent is not the smartest one. It is the one that can lose you the least.
What you can do now
None of this is available as an NPCI-standard product yet, so the practical guidance is about habits that will apply when it is. Prefer caps over trust: if an app offers to pay for you, start with the lowest limit and raise it only after a few months. Prefer allow-lists: an agent that can pay only named billers, such as your electricity board and your broadband provider, is safer than one that can pay anyone. Prefer notifications: every agent payment should reach you as an alert you can dispute. Keep separate accounts: fund the account the agent uses with a small monthly amount, not your main balance. And read what you are consenting to, especially any wording that lets the app act “on your behalf” in general terms.
What to watch
Three things will show whether India's version is safe as well as fast. A published protocol with clear consent, identity and audit rules. A statement from the RBI on liability for agent-initiated payments. And real-world numbers from the early products: how many transactions, how many disputes, and how they were resolved. Until those appear, the honest summary is that the infrastructure is being designed, the principle is sound, and the details that matter most are still unwritten.