Key Takeaways
- Visa is expanding payment passkeys from card issuer rollout to AI agent commerce, enabling secure AI agent-initiated transactions.
- This marks a major step in payment authentication for autonomous commerce.
What Happened

Visa is expanding its payment passkey infrastructure to support AI agent commerce, according to a report from Biometric Update. The initiative extends beyond the initial issuer rollout of passkey-based payment verification to enable secure transactions initiated by AI agents on behalf of users.
This development comes amid a broader industry push toward agentic commerce. Square recently launched agentic commerce integrations with ChatGPT and Claude, while eDreams ODIGEO partnered with Visa on secure AI agent protocols for travel. Cross River also teamed with Stripe on issuance for agentic commerce, signaling a coordinated infrastructure buildout across payments.
Technical Details
Visa's payment passkeys leverage FIDO2/WebAuthn standards for biometric and device-based authentication, replacing traditional passwords and one-time codes. The expansion to AI agent commerce means an AI agent—such as a travel booking assistant or personal shopping agent—can authenticate and authorize payments using a passkey linked to the user's Visa card, without requiring manual user intervention at each transaction step.
This requires new protocols for agent identity verification, transaction authorization scoping, and user consent management. Visa is effectively building the authentication layer for autonomous commerce, where AI agents act as authorized delegates for payment decisions.
Retail & Luxury Implications
For luxury retailers and brands, this development addresses a critical bottleneck in agentic commerce: trust and security. High-value purchases, limited-edition drops, and personalized concierge services all require robust authentication that current payment flows don't support for autonomous agents.
Key implications include:
- Concierge commerce: AI shopping agents could authenticate and complete purchases across multiple luxury brands without requiring the user to manually approve each transaction, enabling seamless multi-brand basket checkout.
- Subscription and replenishment: For luxury beauty, fragrance, and personal care, AI agents could manage recurring purchases with passkey-backed authorization, reducing friction while maintaining security.
- Resale and authentication: In the luxury resale market, AI agents could handle payment authorization for authenticated pre-owned goods, with passkeys providing a verifiable audit trail.
- Event and experience commerce: For luxury brand events, trunk shows, and exclusive drops, AI agents could secure reservations and payments on behalf of VIP clients.
Business Impact
The timing is strategic. Square's agentic commerce integrations with ChatGPT and Claude, alongside eDreams ODIGEO's travel-focused protocols, indicate that 2026 is becoming the year agentic commerce moves from concept to infrastructure. Visa's passkey expansion is the payments layer enabling this shift.
For retailers, the business impact will be felt in:
- Conversion rates: Reducing friction in agent-initiated purchases could increase conversion for repeat and subscription purchases.
- Average order value: AI agents with pre-authorized payment capabilities could more easily upsell and cross-sell within a single authenticated session.
- Fraud reduction: Passkey-based authentication is inherently more secure than passwords, potentially reducing chargebacks and fraud losses in agentic commerce scenarios.
Implementation Approach
Retailers looking to prepare for agentic commerce with Visa passkeys should:
- Assess current payment infrastructure: Determine if your payment gateway supports FIDO2/WebAuthn passkey authentication.
- Evaluate agentic commerce use cases: Identify which customer journeys benefit most from AI agent-initiated payments (e.g., replenishment, concierge, event bookings).
- Design consent and authorization flows: Define how users grant and revoke agent payment authority, with clear audit trails.
- Partner with payment providers: Work with Visa-acquiring banks and payment gateways to enable passkey-based agentic transactions.
- Test with limited scope: Start with low-value, high-frequency transactions before expanding to high-value luxury purchases.
Governance & Risk Assessment
Privacy: Passkeys reduce password-related data breaches but introduce new questions about agent identity and user consent. Retailers must ensure transparent disclosure of what agents can authorize.
Security: Passkeys are phishing-resistant, but agent compromise (e.g., a hijacked AI assistant) could lead to unauthorized transactions. Retailers need agent-level authentication and transaction limits.
Regulatory: Payment regulations vary by jurisdiction. Agentic commerce may require updates to liability frameworks, particularly for unauthorized transactions initiated by AI agents.
Maturity: This is early-stage infrastructure. Visa's announcement signals intent, but widespread deployment will take 12-24 months. Retailers should monitor but not rush full implementation.
Source: news.google.com









