India Plans AI Agent Registry for UPI Payments
India plans an AI agent registry for UPI payments, creating a proposed identity and monitoring layer for software that can spend on a user’s behalf. Three people involved in the discussions told Reuters that the National Payments Corporation of India is building the registry as part of a planned Unified Agentic Protocol.
The September 10 report adds a concrete trust mechanism to earlier details about agentic payments on India’s dominant retail network. The registry has not been publicly launched, and NPCI did not respond to Reuters’ request for comment, so its final rules, timetable and regulatory status remain unsettled.
India’s AI Agent Registry Would Vet Software Identities
The proposed registry would initially identify, approve and monitor AI agents making transactions through the Unified Payments Interface. That function is different from approving a single payment: it creates a durable record of which agent is acting, who operates it and whether it remains authorized to use the network.
Reuters reported that the registry could later cover cards, bill payments and other methods. That expansion would make the registry a cross-network trust layer rather than a UPI-only directory, although no technical specification or participation requirements have been released publicly.
The reported design separates three jobs that agentic commerce needs:
- Verifying the identity of an AI agent
- Linking that agent to a permitted user mandate
- Monitoring transactions after approval
An identity entry alone would not prove that every payment is legitimate. Banks and payment applications would still need to validate the user’s mandate, enforce spending limits and preserve evidence of what the agent was instructed to do when a transaction was initiated.
Unified Agentic Protocol Starts With Low-Value UPI Payments
NPCI’s reported Unified Agentic Protocol is expected to begin with small, frequent purchases such as groceries. In that model, a user could set rules in advance and allow an agent to pay within those boundaries instead of manually approving every checkout.
A September 1 Reuters report said the protocol could draw on two existing UPI mechanisms. UPI Circle supports delegated payment authority, while Reserve Pay allows money to be blocked for multiple debits. Together, they offer a possible foundation for bounded autonomy without giving software unrestricted access to an account.
The earlier report said banks currently cap such blocked funds at 10,000 rupees for as long as 90 days, though those limits could be revisited for agentic use. It also described planned controls including spending ceilings, identity checks, audit trails and rule-based instructions for merchants to integrate.
Later applications could be more conditional. Reuters’ sources described agents buying a product when its discount reaches a specified level or investing when a price crosses a user-defined threshold. Those examples remain proposed use cases, not evidence that autonomous investing has been enabled on UPI.
UPI Scale Raises the Stakes for Agent Authentication
UPI is the world’s largest retail fast-payment system by transaction volume, according to a 2025 International Monetary Fund report cited by Reuters. It processed 24.51 billion transactions worth 29.82 trillion rupees in August, making even a narrowly scoped agent rollout consequential for banks, merchants and consumers.
The registry proposal addresses a problem that ordinary payment credentials do not solve. A valid account and mandate identify the payer, but an agentic system also needs an attributable software identity so suspicious behavior can be traced, permissions can be revoked and providers can be held to network rules.
India is not developing that layer in isolation. Google introduced its open Agent Payments Protocol in 2025, while Visa, Mastercard and Ant International announced a shared agent-trust initiative on September 10. Mastercard also completed an authenticated agentic transaction in New Delhi in June, Reuters reported.
Common identity signals could help merchants distinguish an authorized shopping agent from automated fraud. The harder question is interoperability: a registry is most useful when banks, payment networks, agent developers and merchants agree on how identities are issued, checked, suspended and audited.
Liability Rules Remain Outside the Registry
The sharpest unresolved issue is responsibility for a wrong or unauthorized payment. One of Reuters’ sources said regulation would need to address liability even if agents are indexed. A registry can show which software acted, but it cannot by itself decide whether the user, bank, merchant or agent provider must absorb a loss.
Disputes could involve several distinct failures: an agent exceeding a clear mandate, a provider misreading an ambiguous instruction, a merchant supplying inaccurate information, or an attacker manipulating the agent. Each scenario may require different evidence and a different allocation of responsibility.
User controls will therefore matter as much as model performance. Practical safeguards include narrow spending categories, per-transaction and cumulative limits, prompt revocation, tamper-resistant logs and fresh confirmation for unusual purchases. Regulators must also decide when an automated decision becomes legally attributable to the person who configured it.
The next credible milestones are an NPCI announcement, a published protocol specification, named bank and merchant participants, and operational rules for disputes. Until those appear, India’s AI agent registry should be understood as a reported infrastructure plan—not a live permission for autonomous software to spend across UPI.