On Tuesday, 14 July 2026, HM Treasury published its consultation “Modernising Payment Services Regulation”. Its 43 pages and 42 questions concern the law under which, by the Treasury’s count, “nearly 1,200 firms” are authorised or registered: the Payment Services Regulations 2017 (PSRs) and the Electronic Money Regulations 2011 (EMRs). Responses are due by 23:59 UK time on Tuesday, 6 October 2026. For payment service providers planning to let software agents into the checkout, one question carries the most weight, because in it the government asks whether consent, authentication and liability still hold when a machine pays. Question 15 reads: “How does existing payment services regulation need to adapt to support agentic payments? For example, do provisions relating to authentication and consent of payments transactions, and liability for unauthorised payment transactions, need updating?”
It would be tempting to read this as the UK closing the liability gap for agentic payments by law. The text does not support that reading. The government asks the question without answering it, and elsewhere it has already settled who will write the answer. The rules on Strong Customer Authentication (SCA) are to be removed from the PSRs and rewritten by the Financial Conduct Authority (FCA), while the standards for agents, according to the AI Adoption Plan published the same day, are to be developed first by industry. This is a procedure rather than a retreat, since both destinations sit closer to the market than Parliament does. Yet anyone responding before 6 October is answering not so much the question of what should apply as the question of where it will be written. What follows sets out that shift and compares it with the European reform. It does not forecast the answer London will eventually give.
What: HM Treasury consultation “Modernising Payment Services Regulation”, published on 14 July 2026, closing on 6 October 2026, 43 pages, 42 questions on the framework and its delegation, tokenisation and stablecoins, agentic payments, sector risks and Open Banking
Finding: One question concerns agentic payments, 21 concern Open Banking. The SCA rules are to be removed from the PSRs so that the FCA can make “more outcomes-based rules about authentication requirements”
Counterpart: the EU Payment Services Regulation (PSR) and Payment Services Directive (PSD3), politically agreed on 27 November 2025 and not yet adopted by Parliament
For whom: heads of payments and product, Open Banking leads, compliance teams at firms with UK business, providers building agents into the checkout
Status at the editorial cut-off (25 September 2026): no published response from UK trade associations on Question 15, and no date for the Commons second reading of the Financial Services and Markets Bill
Agents get one of 42 questions, and it stays a question
Counting the questions shows a clear order of priorities. Grouped by subject, 21 deal with Open Banking, ten with tokenised deposits and stablecoins, four with the legal framework and its delegation to the FCA, four with financial inclusion and sector risks, and two are open catch-all questions. A single one, Question 15, is about agentic payments. The word “agentic” appears 19 times in the document, “Open Banking” 90 times. Counted by chapter rather than by subject, the agentic section holds two questions, because catch-all Question 16 on “any other innovations” sits there. The proportion is the same either way.
The section itself, headed “Leading the world in agentic payments”, runs to six paragraphs and reads as a pitch for the UK as a location. It describes agents that “autonomously analyse, initiate, approve, and execute” payments, sees a chance “to lead the world”, and explicitly cites the speech in which Rachel Reeves, then Chancellor of the Exchequer, called agentic payments one of the “most promising applications of AI” at the AI Adoption Summit on 9 June 2026. Only the last paragraph, 3.35, turns to the law. The PSRs were “designed before the development of AI and may not fully facilitate the use of agentic AI”, and the government wants views on “what changes to requirements are required, such as authentication standards and liability requirements”. There is no proposal in the section. Chapter 4 on Open Banking, by contrast, asks from Question 21 onwards whether respondents agree with specific proposals.
The law firms that summarised the consultation in July read it the same way. A&O Shearman writes that the government “asks whether the PSRs should be updated in areas such as authentication, consent and liability”, and Travers Smith notes that the Treasury does not claim to know the answers. For a firm planning agents in the payment flow, this is more than a detail. By autumn 2026 it will not learn what applies in London, only whom it will have to ask in future.
Authentication moves out of secondary legislation and into the regulator’s rulebook
The consultation’s real programme sits in Chapter 2. Under paragraph 2.7 the government is considering “whether responsibility for setting certain requirements should be delegated to the FCA”, to allow a “more agile and outcomes-focused regime”. Paragraph 2.12 spells out the consequence: the requirements concerned would be “removed from the statute book”, and the FCA would gain the power to replace them “with new requirements in its Handbook”. According to paragraph 2.9, what stays in legislation is the perimeter of regulated services, core definitions such as that of electronic money, and provisions that establish “key rights, obligations or protections”. Paragraph 2.10 cites, as an example, the notice period a payment service provider must give when terminating a framework contract. The PSRs and EMRs are themselves not Acts of Parliament but statutory instruments made by the government. The shift therefore runs from a layer the government amends to one the regulator amends.
For authentication, the decision has already been made. Paragraph 2.8 records that the government has committed to “commencing the revocation of the payment's authentication regulations relating to Strong Customer Authentication in the PSRs”, so that the FCA can make “more outcomes-based rules about authentication requirements”. The reasoning comes from the Future of Payments Review that Joe Garner delivered in November 2023: the technical standards had reduced fraud but created “burdensome frictions”. The part of Question 15 that matters most to practitioners will therefore sit in the FCA Handbook, and the FCA has explained why it prefers that. Nikhil Rathi, Chief Executive of the FCA, told a techUK audience on 24 June 2026: “Technology is moving much faster than many regulatory paradigms. Legislation will never keep up.”
Admittedly, an outcomes-based rulebook is the obvious choice for a technology changing this quickly, and the FCA has a tool for it in its Supercharged Sandbox, whose second cohort, according to the consultation, drew a record number of applications. The type of rule changes with its location, however. A duty in secondary legislation is amended by the government through a statutory instrument laid before Parliament, and under paragraph 2.13 the government keeps that responsibility. A rule in the Handbook is amended by the FCA after its own consultation, with no new statutory instrument. A firm that needs planning certainty for an agentic checkout gains flexibility and loses legal certainty. The government names this trade-off itself in paragraph 2.11 and invites views on “how best to achieve this balance”.
Industry is to write the standards for agents first
A second document appeared on the same 14 July, and many summaries have merged it with the consultation: the AI Adoption Plan for financial services, written by the independent AI Champions Harriet Rees, Group Chief Information Officer at Starling Bank, and Dr Rohit Dhawan, Head of AI and Advanced Analytics at Lloyds Banking Group. The government “accepts the recommendations for government”, its overview page says, without listing which recommendations those are. Recommendation 10 addresses agentic payments and names the consultation as the lever for building a “trust framework”. That framework is to rest on three pillars: “Legal & Liability Frameworks” to allocate responsibility, “Know Your Agent (KYA) Protocols” to identify and verify agents, and “Authentication & Governance” for authentication between machines. It is here, and not in the consultation, that a proposal can be found.
The address of that proposal is telling. The practical standards “should first be led by industry”, the recommendation says, possibly convened by the Centre for Finance, Innovation and Technology (CFIT). Government and regulators come in afterwards, “supporting this work” and, “where appropriate”, bringing forward legislative changes. The pillars take up the open questions that Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, set out in Sintra on 30 June 2026: how users securely give consent and authorisation to agents, “especially for multiple transactions”, how disputes are settled and liability assigned, and how fragmented protocols can be avoided. To the third, the recommendation replies with “interoperable technical standards”. How agents with payment authority become open to attack is covered elsewhere.
An industry standard is not liability law, though, and liability is what matters to a payment service provider. Visa’s Agentic Ready service, launched in London in March 2026 with Barclays, HSBC UK, Nationwide and Revolut as its first issuers, and protocols such as that of the x402 Foundation govern how an agent identifies itself and triggers a payment. They do not govern who pays when the payment was wrong. Two addresses for one question therefore do not add up to double protection. They create a seam, and seams are where disputes arise.
Current law already knows the mandate, but not where it ends
The PSRs are less unprepared for agents than the debate assumes. Regulation 67 treats a payment as authorised if the payer has consented, either to the single transaction or “to the execution of a series of payment transactions of which that payment transaction forms part”. A mandate for a series of payments is therefore already law, and Chapter 4 of the consultation uses the same idea for variable recurring payments in Open Banking, where a payment initiation service may “lodge a payment mandate for a series of payment transactions”. Regulation 76 sets out the consequence when a payment was not authorised under Regulation 67: the payment service provider must refund the amount and restore the account to its previous state. Regulation 100 requires Strong Customer Authentication when a user “initiates an electronic payment transaction”. The consultation does not draw the link to agents itself. That link is this article’s own reading.
Anyone who has run a trading mandate with limits knows the distinction at stake. The signature on the mandate is rarely the risk. The risk is the single trade at the edge of the limit. In trading-floor terms, Question 15 is a question about limit breaches. As long as the agent pays within its mandate, Regulation 67 carries the consent. Once it goes beyond the mandate, the payment is unauthorised, and under Regulation 76 the refund falls to a payment service provider that may never have seen the agent. Skadden puts the open point as follows: “Who bears responsibility for faulty code, incorrect data or an AI agent acting outside its mandate”. Back in February 2026, before the consultation, the law firm Addleshaw Goddard had already identified the evidential problem: “As these systems become more autonomous, it will become more difficult for PSPs to demonstrate a transaction was appropriately authorised by or on behalf of the customer.”
This is where the practical consequence of the shift lies. The liability provision, Regulation 76, protects the payer’s rights and, by the test in paragraph 2.9, stands a good chance of staying in legislation. The authentication provision, Regulation 100, goes to the FCA under paragraph 2.8. The two halves of the question, whether an agent was allowed to pay and who pays if it was not, would then be governed in two places, by two bodies and on two timetables. Responses to Question 15 carry more weight if they also answer Question 1, on which requirements “should remain in legislation”.
Brussels writes authentication into the regulation and is silent on agents
The consultation supplies its own point of comparison. Paragraph 2.14 refers to the European Union, which has “recently reached a provisional agreement on its new Payment Services Directive and Payment Services Regulation”, and Question 4 asks which “recent reforms in the EU” the UK should adopt. The EU reform takes the opposite route. The Commission proposed the Payment Services Regulation on 28 June 2023 as COM(2023) 367, Parliament and Council reached political agreement on 27 November 2025, and the Council recorded the compromise text on 17 April 2026 as document 8221/26. According to the European Parliament’s Legislative Observatory, the Committee on Economic and Monetary Affairs (ECON) approved the text on 5 May 2026, the procedure is awaiting the Council’s position, and the plenary vote is indicatively scheduled for 14 December 2026. By the end of September, neither act had appeared in the Official Journal.
In substance, the PSR lifts Strong Customer Authentication out of a directive with technical standards and into a directly applicable regulation. Article 85 requires it when the payer “places a payment order for an electronic payment transaction” and exempts payee-initiated transactions to the extent that they occur “without any interaction or involvement of the payer”, although setting up such a mandate through a remote channel still requires SCA. Article 60(2) sets out the liability consequence in the same text: if the payment service provider fails to apply authentication, “the payer shall not bear any financial losses unless the payer has acted fraudulently”. Article 87 requires an outsourcing agreement where a technical service provider supplies and verifies the elements of SCA. The word “agentic” does not appear in the compromise text. “Artificial intelligence” appears once, in recital 103, as a tool for fraud monitoring. The law firm Osborne Clarke noted in March 2026 that agent-based payment models “remain subject to PSD2 and the RTS requirements concerning Strong Customer Authentication”.
On one point the European approach is admittedly firmer than the British one. Duty and liability sit in the same act, which will apply uniformly in all member states once in force, and no single supervisor can adjust them. For a technology the text never names, that same firmness is also its limit. A firm planning an agentic checkout for both markets will have to interpret an EU regulation whose mandate rule was written for the merchant rather than for an agent acting for the buyer, and in the UK it will have to wait for a Handbook that does not yet exist. The difference therefore lies not in speed, since neither regime has a date for an agent rule, but in who is allowed to change it.
The deadline runs out under a different Chancellor
One further circumstance postdates the July summaries. Rachel Reeves published the consultation during her Mansion House week, and according to the government’s register of ministers she ceased to be Chancellor six days later, on 20 July 2026. Her successor is John Healey, and Andy Burnham has been Prime Minister since the same day. The new leadership has issued no public confirmation of, or change to, the consultation. Travers Smith points out that Andy Burnham’s government has already ended the public digital ID programme, which leaves the question of how agents and their principals identify themselves more open, not less.
In parallel, the bill that folds the Payment Systems Regulator into the FCA is moving through Parliament. The Financial Services and Markets Bill passed its third reading in the House of Lords on 15 September 2026 and has since been in the Commons, where no date has been set for its second reading. The same bill is to give the Bank of England a secondary objective on innovation in payment systems, as described here. The FCA thus takes on the oversight of payment systems, the rules on authentication and, if delegation goes ahead, large parts of the PSRs at the same time. Perhaps Question 15 will remain one paragraph among many in the government’s response, just as it is one question among 42 in the consultation. In that case the answer will not sit in a statute but in a Handbook and an industry standard, and both are being written now.
Recommendations
By 23:59 UK time on 6 October 2026: Extend a response on agentic payments to the question of which provision should stay in legislation. Liability for unauthorised transactions under Regulation 76 and consent under Regulation 67 belong together. A response that argues this shapes where the rule sits, not only what it says. Responses go by email to Modernisingpaymentservices@hmtreasury.gov.uk.
Before the first agentic checkout: Record the scope, duration, amount limits and revocation of an agent mandate so that every single payment can be traced to consent under Regulation 67. Whether a payment was authorised by or on behalf of the customer is the question in every dispute, wherever the rule ends up.
Until the plenary vote on PSD3 and PSR: Plan the EU side around Articles 85, 60(2) and 87 of the PSR compromise text, and the UK side for SCA rules moving into the FCA Handbook. A firm building a checkout for both markets should encapsulate the authentication layer so that each side can be adjusted independently.
Ongoing: The AI Adoption Plan puts liability frameworks, Know Your Agent protocols and machine-to-machine authentication in the hands of industry first. Those who contribute to that work shape the rules a regulator will later adopt or supplement.
Glossary
Agentic payments: payments that an AI system analyses, initiates, approves and executes on behalf of a consumer or business, in HM Treasury’s words, agents that “autonomously analyse, initiate, approve, and execute payments on behalf of consumers or firms”.
Payment Services Regulations 2017 (PSRs): UK statutory instrument (SI 2017/752) on payment services, the basis for consent (Regulation 67), liability for unauthorised transactions (Regulation 76) and Strong Customer Authentication (Regulation 100).
Electronic Money Regulations 2011 (EMRs): UK statutory instrument (SI 2011/99) on the issuance of electronic money and the authorisation of e-money institutions.
Strong Customer Authentication (SCA): authentication using at least two independent elements from knowledge, possession and inherence, governed in the UK by Regulation 100 of the PSRs and in the EU in future by Article 85 of the PSR.
FCA Handbook: the Financial Conduct Authority’s rulebook, which it can amend after its own consultation without a legislative procedure.
Know Your Agent (KYA): protocols proposed in the AI Adoption Plan for identifying and verifying AI agents, by analogy with customer identification.