{"id":117712,"date":"2026-07-24T12:23:24","date_gmt":"2026-07-24T12:23:24","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/117712\/"},"modified":"2026-07-24T12:23:24","modified_gmt":"2026-07-24T12:23:24","slug":"lithic-what-payments-assumes-about-shopping-is-about-to-break","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/117712\/","title":{"rendered":"Lithic: What Payments Assumes About Shopping Is About to Break"},"content":{"rendered":"<p>For the past 25 years, card-not-present payments have been built around a defensive premise: Prove the buyer is human, authorized and in control of the transaction. <a href=\"https:\/\/www.pymnts.com\/tag\/fraud\/\" target=\"_blank\" rel=\"noopener nofollow\">Fraud<\/a> systems, <a href=\"https:\/\/www.pymnts.com\/tag\/retail\/\" target=\"_blank\" rel=\"noopener nofollow\">merchant<\/a> controls and <a href=\"https:\/\/www.pymnts.com\/tag\/authentication\/\" target=\"_blank\" rel=\"noopener nofollow\">authentication<\/a> tools were trained to treat nonhuman behavior as suspicious. That made sense when bots were mostly fraudsters. It becomes more complicated when the \u201cbot\u201d is a legitimate <a href=\"https:\/\/www.pymnts.com\/tag\/artificial-intelligence\/\" target=\"_blank\" rel=\"noopener nofollow\">artificial intelligence<\/a> agent acting on behalf of a consumer or business.<\/p>\n<p>\u201cA lot of the technology that\u2019s been built for <a href=\"https:\/\/www.pymnts.com\/tag\/ecommerce\/\" target=\"_blank\" rel=\"noopener nofollow\">online commerce<\/a> has been built around the concept that, if I see something that feels like a bot and it\u2019s coming from something that\u2019s not a device, I need to stop it,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/robingandhi\/\" rel=\"nofollow noopener\" target=\"_blank\">Robin Gandhi<\/a>, chief product officer at <a href=\"https:\/\/www.lithic.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Lithic<\/a>, told PYMNTS.<\/p>\n<p>Agentic payments reverse that question, he said.<\/p>\n<p>Commerce infrastructure in the age of agentic AI now must decide when nonhuman behavior is a delegated commerce signal and not just a fraud signal. As a result, the industry does not just need better checkout flows. It needs a new trust grammar and logic flow for validating and settling machine-initiated transactions.<\/p>\n<p>B2B Payments Emerge as Agentic Commerce\u2019s Proving Ground<\/p>\n<p>The consumer use case is easier to imagine. An agent buys sneakers, books a trip or finds a household item. However, the more durable opportunity may sit in <a href=\"https:\/\/www.pymnts.com\/tag\/b2b\/\" target=\"_blank\" rel=\"noopener nofollow\">B2B<\/a>, where autonomy maps to behavior businesses already understand, Gandhi said.<\/p>\n<p>\u201cThe reality is, the programmable aspect of it is going to sit on the <a href=\"https:\/\/www.pymnts.com\/tag\/b2b-payments\/\" target=\"_blank\" rel=\"noopener nofollow\">B2B<\/a> side of things,\u201d Gandhi said, adding that because consumers often enjoy discovery, comparison and selection, they may not want to fully delegate the purchase itself.<\/p>\n<p>Businesses, by contrast, routinely buy supplies, services and inputs that are necessary but uninteresting. That makes them better candidates for rules-based autonomy. For chief financial officers and procurement leaders, that changes the meaning of payment control. The control layer moves upstream from approval after purchase to permission before purchase.<\/p>\n<p>\u201cWhen we talk about agentic commerce, where it\u2019s truly autonomous, it will likely be the B2B products and services where, when the supply goes down, it\u2019s OK to automatically go ahead and buy it,\u201d Gandhi said.<\/p>\n<p>The first major wave may not be AI agents acting like personal shoppers. It may be agents acting like procurement assistants, replenishment systems and back-office operators, executing transactions within predefined rules.<\/p>\n<p>Virtual Cards Emerge as the Control Layer Agentic Payments Need<\/p>\n<p>That is where <a href=\"https:\/\/www.pymnts.com\/tag\/virtual-cards\/\" target=\"_blank\" rel=\"noopener nofollow\">virtual cards<\/a> become especially relevant. While stablecoins and micropayments attract much of the attention around programmable commerce, virtual cards are emerging as a natural control mechanism for delegated spending.<\/p>\n<p>\u201cVirtual cards are an amazing way to keep your underlying funding source safe,\u201d Gandhi said. \u201cThey are an unlock for agentic. Agentic needs a way to be able to spend, and virtual cards are a clear way to do it.\u201d<\/p>\n<p>Virtual cards can be single use, limited by amount, merchant, timing and other controls. If an AI agent makes a mistake, gets compromised or hallucinates, the potential loss can be contained. That containment matters because agentic payments shift the risk model from one-time authentication to ongoing delegated authority. The system must answer not only whether the agent is legitimate, but whether the specific transaction fits the permission set.<\/p>\n<p>\u201cThe benefit of cards is that it\u2019s not that big of a leap,\u201d Gandhi said. \u201cThe merchants are already accepting cards.\u201d<\/p>\n<p>That means most merchants do not need to adopt a new settlement asset or redesign their treasury workflows to receive payment. By contrast, stablecoin-native payments may require merchants to adopt new protocols, accept new assets and decide what to do with those assets after settlement. To bridge that gap, Lithic issues cards backed by stablecoin accounts, allowing a stablecoin funding source behind a familiar card credential and removing that barrier for merchants entirely.<\/p>\n<p>This makes virtual cards less a legacy instrument than a control plane for delegated spend. A merchant accepting an agent-paid card transaction mainly needs confidence that the transaction is safe.<\/p>\n<p>Agentic Payments Are Testing the Assumptions That Built Online Commerce<\/p>\n<p>The next payments land grab is brewing over trust, not checkout. Agentic payments also challenge the way payments controls are typically applied. In conventional systems, many decisions happen in real time at the moment of authorization. However, that autonomy requires more control to be embedded before the transaction happens, Gandhi said.<\/p>\n<p>The market is already moving toward a familiar solution: <a href=\"https:\/\/www.pymnts.com\/tag\/tokenization\/\" target=\"_blank\" rel=\"noopener nofollow\">tokenization<\/a>.<\/p>\n<p>Gandhi pointed to <a href=\"https:\/\/www.visa.com\/en-us\" rel=\"nofollow noopener\" target=\"_blank\">Visa<\/a>\u2019s <a href=\"https:\/\/developer.visa.com\/capabilities\/visa-intelligent-commerce\" rel=\"nofollow noopener\" target=\"_blank\">Intelligent Commerce<\/a> and <a href=\"https:\/\/www.mastercard.com\/us\/en.html\" rel=\"nofollow noopener\" target=\"_blank\">Mastercard<\/a>\u2019s <a href=\"https:\/\/www.mastercard.com\/us\/en\/business\/artificial-intelligence\/mastercard-agent-pay.html\" rel=\"nofollow noopener\" target=\"_blank\">Agent Pay<\/a> as evidence that networks are likely to extend existing token frameworks rather than start from scratch. That matters because tokens are already legible to merchants, issuers and acquirers. They are known infrastructure.<\/p>\n<p>But the next layer is not simply proving that an agent is authenticated. It is proving what that agent was authorized to do.<\/p>\n<p>Gandhi framed the issue as the ability to embed additional information into the payments credential.<\/p>\n<p>\u201cThis is coming from an authenticated agent,\u201d Gandhi said. \u201cNo different than like an authenticated human. And ideally you also include intent in there.\u201d<\/p>\n<p>Intent is where the downstream implications get sharper. If an AI agent is buying 100 reams of paper for a business, the issuer, merchant and acquirer may need to know that the transaction fits a preapproved use case, supplier, price range or replenishment trigger. That creates a new data-sharing bargain. Networks may want more transaction context. Merchants may resist sharing line-item or proprietary data unless it improves approval rates, lowers fraud exposure or reduces liability.<\/p>\n<p>That changes the role of issuing infrastructure. Instead of simple accept-or-decline logic, agentic commerce requires dynamic rule engines that can evaluate context, historical behavior and statistical anomalies. Lithic calls this approach <a href=\"https:\/\/docs.lithic.com\/docs\/about-authorization-intelligence\" rel=\"nofollow noopener\" target=\"_blank\">Authorization Intelligence<\/a>. It\u2019s a programmable governance layer that lets issuers embed complex logic, such as blocking a card when spend is three standard deviations above historical patterns, rather than relying on binary decisions.<\/p>\n<p>The larger lesson is that agentic payments are not just about letting software spend money. They are about moving economic authority into software while keeping risk, accountability and customer control intact. Those best positioned to enable that shift have already built the infrastructure to support it.<\/p>\n<p>The winners may be the firms that make autonomy feel boring: authorized, bounded, auditable and easy for merchants to accept.<\/p>\n<p>For all PYMNTS AI coverage, subscribe to the daily <a href=\"https:\/\/pymnts.com\/subscribe\/\" rel=\"nofollow noopener\" target=\"_blank\">AI Newsletter<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"For the past 25 years, card-not-present payments have been built around a defensive premise: Prove the buyer is&hellip;\n","protected":false},"author":2,"featured_media":117713,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,10649,307,308,1732,462,66,310,1379,3646,59740],"class_list":["post-117712","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-authentication","tag-b2b","tag-b2b-payments","tag-ecommerce","tag-featured-news","tag-news","tag-pymnts-news","tag-retail","tag-tokenization","tag-virtual-cards"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/117712","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=117712"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/117712\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/117713"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=117712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=117712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=117712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}