The news itself is quickly told: on 10 June 2026, Mastercard unveiled Agent Pay for Machines (AP4M), a service for fully automated payments between AI agents – including micropayments down to fractions of a cent. The permissions that a person or an organisation grants its agents do not sit in a private Mastercard database but on public blockchains, initially Polygon, Solana and Base. More than 30 launch partners are on board, including Coinbase, Stripe, Adyen, the Solana Foundation and Getnet by Santander. But anyone who reads only the launch announcement misses the real story. It is not about innovation; it is about defending an intermediary role – and it raises an uncomfortable question for banks: where in this transaction chain will their value creation take place in future?
For executives responsible for payments and digital banking, a second look is therefore worthwhile: at the architecture, at the economics and at the regulatory gaps that AP4M opens up in the EU. All three levels have more substance than the press release suggests.
What: Mastercard Agent Pay for Machines (AP4M), unveiled on 10 June 2026 – a service layer for autonomous machine-to-machine payments (M2M) built on the open x402 protocol
Architecture: Four pillars – credentialing, permissioning, transacting, settling. Agent permissions are stored on-chain (initially Polygon, Solana, Base); settlement runs via cards, bank accounts or six stablecoins on eight blockchains
Partners: More than 30 launch partners, including Coinbase, Stripe, Adyen, Cloudflare, Ripple and the Solana Foundation
Context: Not a standalone open protocol – AP4M builds on x402, which has sat under the umbrella of the Linux Foundation since April 2026 and was originally developed by Coinbase
Open questions: Pricing unclear, issuer role unclear, regulation unresolved: strong customer authentication, liability, the MiCA status of individual stablecoins, data protection for on-chain permissions
What AP4M is – and what it is not
Technically, AP4M consists of four building blocks. First, credentialing: AI agents receive digital identity credentials. The foundation is "Verifiable Intent", an open-source specification that Mastercard developed together with Google and maintains – aligned with standards from the FIDO Alliance, EMVCo and the W3C. Second, permissioning: organisations deposit programmatically enforceable authorisation rules and spending limits for their agents, stored on public blockchains. Third, transacting: the actual transaction runs over the x402 protocol, an HTTP-native payment handshake. Fourth, settling: clearing takes place either conventionally via cards and bank accounts or via stablecoins – six tokens on eight blockchains, from USDC to RLUSD.
The distinction matters in two directions. Compared with its predecessor Agent Pay, which Mastercard presented in April 2025, the use case shifts fundamentally: Agent Pay let an AI agent complete individual purchases on behalf of a human; AP4M targets fully automated transactions between machines, with no human interaction at the moment of payment – high-frequency, low-latency, small-ticket. And with respect to the market: AP4M is not an open protocol, even if the coverage occasionally shortens it that way. The open protocol is called x402, originally created by Coinbase, and has sat under the umbrella of the Linux Foundation since 2 April 2026; the x402 Foundation was built by Coinbase, Cloudflare and Stripe. Mastercard is a founding member there – just like Visa, Google and AWS. AP4M is the proprietary service layer that Mastercard places on top of this shared standard.
The strategic reading: defending the intermediary role
That puts the analytically decisive question on the table: why does an open protocol that already standardises payments between machines need an additional Mastercard layer? The answer that emerges from the building blocks: once payment execution itself is commoditised via open standards and stablecoin rails, the defensible margin shifts to what sits above it – identity, trust, permission management. In the machine economy, Mastercard is no longer primarily selling the transaction but the answer to the question of whether the counterparty is who it claims to be. The flanking moves fit the picture: at the end of May 2026, Mastercard secured a BitLicense from the New York financial regulator NYDFS; on 3 June the extension of settlement to stablecoins followed; in parallel, the reported acquisition of stablecoin infrastructure provider BVNK is under way.
The commercial expectations, meanwhile, are remarkably sober. Jorn Lambert, Chief Product Officer of Mastercard, answered the question about next year's revenue contribution in a Fortune interview with a clear no – the new market would become relevant over a horizon of five years. That is the most honest part of the announcement: AP4M is an infrastructure bet on a machine economy that does not yet exist in this form.
An honest assessment also includes the other side. In crypto-native commentary, the Mastercard layer is criticised as a redundant tollbooth: if x402 works openly and permissionlessly, why a centralised credentialing layer – and with it a new single point of failure? Add to that a remarkable note from within the company itself – Mastercard CEO Michael Miebach had himself publicly posed the core question of agentic payments: is the agent actually who it claims to be? That the company is now building a product around precisely this question is consistent. Whether the answer has to come from a card network, of all players, is the open bet.
Where does that leave the bank?
For banks, the most uncomfortable part of the announcement is a blank space: pricing. Mastercard has not communicated a fee structure for AP4M. The classic interchange model – fixed cent amounts plus a percentage component – is simply incompatible with payments of fractions of a cent; the fee would be a multiple of the transaction. What role and what margin the issuer has in an M2M transaction chain, whether it even necessarily remains part of the chain when settlement runs via stablecoins, and who holds the account an agent draws on – all of that is open. Experience from earlier platform cycles suggests: those who only ask these questions once the standard is set negotiate from the weaker position.
The time horizon is no reason for haste, but it is a reason for preparation. Karan Katyal, Head of Agentic Commerce at Adyen, put it succinctly in the launch announcement: machine-to-machine payments are still in their early stages, but the infrastructure decisions made now will determine how this space develops. Translated for bank strategy: 2026 is not about revenue; it is about options for 2028 to 2030.
Regulatory gaps: SCA, MiCA, data protection
In regulatory terms, AP4M arrives in an EU rulebook that was built for humans. Strong Customer Authentication (SCA) under the Payment Services Directive PSD2 has no exemption that fits dynamically acting software agents; the draft of the successor directive PSD3 does not yet address autonomous agent payments either. Equally unresolved is the allocation of liability across the chain of agent, protocol, Mastercard layer, issuer and on-chain settlement: who bears the loss when an agent pays outside its mandate? The UK's Financial Conduct Authority (FCA) at least named the need for action in its payments priorities report of March 2026; from BaFin, the FMA and FINMA there is no positioning so far.
On stablecoin settlement, precision is required, because two regimes of the Markets in Crypto-Assets Regulation (MiCA) run side by side here. The rules for e-money tokens have applied since 30 June 2024 – non-compliant stablecoins had to be removed from EU trading venues. On 1 July 2026, by contrast, the final transition period for the authorisation of crypto-asset service providers (CASPs) ends. For practical purposes this means: whether an AP4M stablecoin can be used in the EU depends on its issuer's authorisation. USDC from Circle is authorised as an e-money token; for other tokens in the AP4M settlement basket, such as RLUSD or PYUSD, the status must be checked individually. And finally, data protection: permissions on public, immutable blockchains potentially collide with the erasure rights and storage limitation of the General Data Protection Regulation (GDPR) as soon as the delegation chain – and by definition it begins with a human – carries personal data. That is not a solved problem.
What banks should do now
Four work packages follow from the analysis, staggered by urgency. None of them requires using AP4M – all of them require being prepared.
Immediately: Mastercard, Visa, Google, Stripe, Adyen and AWS are all members of the x402 Foundation – which gives the protocol the best odds of becoming the de facto standard for machine payments. Anyone offering payment services for tech platforms or B2B APIs should assess x402 compatibility as a roadmap question for 2027/2028, not as an optional extra. Vendor lock-in decisions, however, should be deferred: the standardisation contest between on-chain credentialing (Mastercard) and proprietary approaches such as the Trusted Agent Protocol (Visa) is not decided.
By Q4 2026: Stress-test your own business model against a sub-cent transaction scenario: which revenues disappear when interchange logic does not apply? What role does the institution play when settlement runs via stablecoins – account holder of the agent's wallet, issuer, mere spectator? The uncommunicated AP4M pricing is a deliberate blank space; your own negotiating position grows out of understanding the alternatives.
By Q1 2027: Systematically examine SCA applicability, the consent scope of the initial agent mandate, the liability chain and the MiCA status of the relevant stablecoins – ideally before the first business unit arrives with an agentic commerce pilot. The PSD2 experience shows: those who document their positions early can feed them into consultations instead of chasing interpretation letters later.
2027: Know Your Customer (KYC) and anti-money laundering (AML) frameworks are designed for natural and legal persons, not for software agents with blockchain credentials. A Know Your Agent (KYA) concept – who authorised the agent, which limits apply, how is misuse detected – should be conceived as an extension of existing financial crime prevention, including the GDPR question of which permission data may sit on-chain.
Risks and open questions
Three caveats belong to an honest assessment. First, the bet may simply not pay off: Mastercard itself expects no meaningful revenues in the near term, and whether autonomous agent payments will be a relevant market in five years is an assumption, not a certainty. Earlier infrastructure bets in the industry – from the Internet of Things to instant payment schemes – regularly took longer than their roadmaps. Second, the governance question is open: a centralised credentialing layer on top of an open protocol creates exactly the intermediary position whose abolition the permissionless movement is striving for; it is not a given that the market will accept this tollbooth. Third, the EU dimension remains downstream: AP4M is launching in a visibly US-centric way – with a BitLicense, bank partners in the US and Latin America, and US dollar stablecoins. For European institutions that is a window of time, not a free pass.
The strategic conclusion: AP4M is neither the breakthrough it is marketed as nor the footnote it could be dismissed as. It is a well-documented signal of where the payments industry is shifting its defensible margin – from the transaction to identity. Banks that think this shift through today will negotiate their role tomorrow. The others will read about it in the terms and conditions.
Keep reading – every 14 days in your inbox.
Capital-markets insights, regulatory updates and AI trends. Concise, well-founded, free.
GDPR-compliant. Unsubscribe at any time.