Last month I asked an AI assistant to find me a pair of running shoes. I gave it a size, a budget, and a brand I didn't want. It came back with three options and I picked one. That took a minute. Now imagine I'd said "just buy the best one under 400 riyals" and walked away.
That second version is what the payments industry calls agentic commerce, and it breaks something most people never think about. When you tap your card in a store, or pay with Apple Pay, or type your card into a website, you are there. You chose the thing. You pressed the button. Every party in the chain, the shop, your bank, the card network, can look at the transaction and say: yes, this is what the customer wanted. The whole system of fees, fraud rules, and chargebacks rests on that one fact.
Take the customer out of the room and the fact disappears. The agent chose. The agent paid. Nobody downstream has the sentence I actually said.
Who holds the sentence
The industry has a word for the sentence I said: intent. And the fight of the last eighteen months has been about who gets to hold it.
Google and Mastercard proposed something called Verifiable Intent. The idea is sound, and it's open: turn the customer's instruction into a signed digital document, a mandate, that the agent carries to checkout. The problem is what happens to that document afterwards. In the platform deployments, Google's agent builds the mandate, stores it, and presents it. There is no place outside the platform where your bank can check whether the mandate is still valid, whether you revoked it yesterday, or whether this is the third purchase against a budget meant for one. Tom Noyes, who has been writing about this longer than anyone, calls it grading your own homework. The platform says the agent did what you asked, and the platform is the only one holding the answer key.
Think about how banks handle online payments today. When a 3-D Secure check passes, the bank approves, because the check was run by the bank's own system and the bank carries the loss if it's wrong. When there's no 3-D Secure, the merchant carries the loss instead. In every case the party vouching for the transaction is the party on the hook. Platform-signed intent breaks that. The platform vouches, and nobody has said who pays when the agent buys the wrong thing. That's why the announcements of "100+ banks live on agentic payments" turned out to be lab demos. Banks don't process on a promise from someone who isn't liable for it.
On September 1, EMVCo, the standards body behind the chip in your card and tap-to-pay, published a draft framework that takes the opposite position. It's dense, but the core idea fits in a sentence: the record of what you asked for should live in a neutral place that every party in the chain can check, and the person who signs it should be you.
The draft calls the neutral place Intent Services. It's a registry, not a decision maker. It doesn't approve payments. It records your intent with a stable ID, tracks its state (registered, approved, completed, completed with exceptions, revoked), and lets your bank, the merchant, and the network each pull the piece they're entitled to see.
It's worth being precise about who sees what, because it matters for what comes later. Today, only the merchant sees what you bought. The payment gateway gets an amount, a currency, and an order reference. Your bank sees the amount and the merchant's name. Nobody else sees the cart. EMVCo's design keeps that boundary. The part of the mandate that lists the items goes to the merchant. The part that lists the payment terms goes to the payment side. The registry holds the whole thing as a sealed envelope it can't open; it can confirm the envelope is intact and track its state without reading the contents.
And the signing moves to your phone. Your bank, or the token service behind your card, provisions a trust credential into your wallet. I mean wallet in EMVCo's sense: the app that holds your card credential, like your bank's app, Apple Pay, Google Pay, or Samsung Pay, not your STC Bank or Barq account. When you delegate a task to an agent, the wallet shows you the limits and you sign them with a key tied to your card. The agent gets a narrower key that lets it fill in the final values later, inside the limits you set. If the agent buys the wrong thing, there's a chain of signatures showing exactly where it went outside its authority.
You might ask whether the payment gateway could just do all this. It can't, and the reason is simple. A gateway only sees its own merchants. In the walk-away case, you sign the mandate before any merchant is chosen, and one budget might get spent across three merchants on three different gateways. No single gateway can hold that record. What gateways will do is what they always do: give merchants an SDK, so a merchant's own agent can register intent and check it at checkout without the merchant ever touching the registry directly. Gateways are the front door to the registry. They aren't the registry.
The hard part everywhere else
Here's where it gets interesting for Saudi Arabia.
EMVCo's draft carefully doesn't say who should run Intent Services. It lists payment systems and card issuers as examples and leaves it there. That's deliberate. In the United States or Europe, this is the most politically loaded question in the whole framework. Visa and Mastercard would like to run it. Banks don't fully trust the networks. Google and OpenAI would rather nobody run it, since a neutral registry is precisely the thing that makes their customer data shareable. Noyes guesses the networks win, or maybe a SWIFT-like utility gets built. Either way it's an eighteen-month fight about governance before anyone writes a line of code.
Saudi Arabia skipped that fight thirty years ago without meaning to.
Every domestic card transaction in the Kingdom passes through one switch. mada, owned by SAMA and run by its Payments Deputyship, connects every POS terminal, every ATM, and every local online checkout. Even Visa and Mastercard transactions hit the switch first; each international network keeps its own processing switch hosted inside Saudi Arabia. The neutral coordination point that the rest of the world is now trying to invent already exists here, and has for decades.
That changes the question. Elsewhere the question is "who should hold the intent record." Here it's answered by the shape of the plumbing. The only real question is whether SAMA does it well.
Doing it well
I want to be careful, because "the government should run it" is the kind of sentence that's easy to write and expensive to be wrong about. There are four ways this goes badly.
The first is privacy. The registry doesn't need to see your cart, and built to the framework it won't. But the draft allows one optional field that should worry people: a short, readable summary of what you asked the agent to do, kept for disputes. That's a record of what people asked an AI to buy for them, and a central bank holding it in plain text is not the same as a merchant holding your receipt. The structured limits, the max amount, the allowed merchants, the expiry, should flow to each party automatically. That's not a privacy problem, it's the whole point: the new risk that agents introduce gets split across everyone who can assess it. The readable summary is different. It should be sealed, opened only when a dispute is raised, and deleted on a clock.
And consent has to be one tap. Open banking stalled in Saudi Arabia partly because customers froze when they saw a consent form and a Nafath login. If delegating a task to an agent means a form per bank, per merchant, per network, nobody will do it. The signature you put on the mandate is the consent. Nothing else should be asked.
The second is the referee playing. SAMA would be regulating a market and operating its central utility. It already does this with mada, so this isn't a new conflict, but it means the rules for what agents, wallets, and banks can do with the registry should be published as rules, not learned by asking.
The third is the border. Domestically nothing bypasses mada. But a Saudi card at a foreign merchant, through a foreign acquirer, doesn't need mada at all, and that's ordinary and legal; a startup in California accepts Saudi cards today through its US acquirer and Visa, with no Saudi licence, because the licence sits with the acquirer in its own country. SAMA can't reach that merchant. It can reach the issuer. The lever is a rule that Saudi banks check the registry before approving any transaction flagged as agent-initiated, wherever it comes from. And that only works if foreign agents can register intent in the Saudi registry without special work. Global startups don't adapt to each country. They integrate one orchestrator, Stripe or Checkout.com, and let it handle local rails. Those orchestrators will implement EMVCo's interfaces once. A Saudi registry that matches those interfaces gets covered for free. One that invents its own gets skipped.
The fourth is crowding out. A state utility at the bottom of the stack is only good for startups if it is boring, open, and thin. The registry itself should be a commodity. The interesting businesses sit above it: the wallets that present mandates and collect the signature, the tools that help banks score an agent's track record, the agents themselves, the dispute services that read intent state and settle who owes whom. If the registry ships with public APIs and a sandbox on the same day, you get a local industry. If it ships alone, you get a monopoly with a waiting list.
Why bother being early
There's a version of caution that says: this is a draft, comments close September 30, wait for the specification. I think that's wrong, for a reason Noyes points out about American Express. Amex is the only network with agentic payments actually live, and the reason is structural: it's both issuer and network, so it can set liability rules by itself. Visa and Mastercard need thousands of banks to agree first.
mada is a four-party scheme on paper, but SAMA sets its rules and can require compliance. In practice the Kingdom has the same decision speed as Amex, with the added advantage of being a public utility nobody accuses of self-dealing. That's rare.
And the payoff isn't abstract. Delta Network's 28.8% error rate was the number with no enforcement. When they put a mandate check between the agent's product search and its checkout, so the purchase had to match the signed limits before it went through, they report the error rate fell to zero. That check is exactly what a shared registry makes possible for every bank and merchant, not just the ones on one vendor's platform.
Agents are going to get their hands on our money either way. The only thing still open is whether, when they get it wrong, there's a neutral record to settle it. Most countries have to build the neutral party first. Saudi Arabia just has to decide to use the one it has.