On this day in 1958, Bank of America mailed 60,000 BankAmericards to households in Fresno, California — the first true revolving credit card, later renamed Visa. Friday’s Journal carries that fact in a box on the markets page and, a few pages earlier, the next chapter: Mastercard has rolled out a payment option in which the card is issued not to you but to your AI agent, and the agent can spend without asking.
The partnership is with a startup called Alchemy. A user signs on with an AI agent they have already created and adds their card information, then sets restrictions — a spending cap, or purchases only at certain retailers. From there the agent can pay anywhere a Mastercard is accepted online. Cardholders can also configure it to check back before buying, but that is an option, not the default architecture.
The industry is not waiting
Visa partnered with Alchemy earlier this year, which means a majority of credit cards can now work with the tool. Visa, Mastercard and American Express have each announced their own instruments and standards for AI platforms and merchants to support agent purchases. Meta’s recently announced agent, Muse, is named in the Journal’s account as one that can use it.
“We believe it’s not about if, it’s about when and how quickly,” said Mastercard’s chief product officer, Jorn Lambert. “Nothing happens overnight.”
Mastercard says the arrangement includes a permissions system meant to verify that bots represent a cardholder’s intent. Issuing banks must support what the industry calls agentic tokens, which carry a user’s intent and the data for the purchase.
The unresolved sentence
Brendan Coughlin, president of Citizens Financial Group, gave the banker’s version: the concept “is a really good one but it is certainly not without its risks.” Executives say the biggest barrier is trust — many users are not eager to give card credentials to a bot, or to risk a confused agent going on a shopping spree.
Underneath the trust question is a legal one nobody has answered: who is liable for an unauthorized agentic payment, whether by a confused or a rogue agent? Regulators have not said how they will treat these transactions at all.
That gap deserves to be stated precisely, because it is the whole story. The consumer protections around card payments in the United States are excellent and they were built on a specific assumption: that a human being made or did not make a purchase, and that the question “did you authorize this?” has a yes-or-no answer. An agent you configured, operating inside limits you set, buying something you would not have bought, is a third category. The framework does not currently have a box for it.
Our read
This is likely to be genuinely useful and it should be adopted slowly, in that order.
The practical guidance for anyone who tries it is short. Use a card, never a debit card or a bank-linked account — the dispute protections are stronger and the money at risk is the issuer’s rather than yours while a dispute runs. Set the spending cap at a number you would be relaxed about losing entirely, not at a number that is merely convenient. Turn on the check-back requirement for the first few months; convenience you have earned is different from convenience you assumed. And keep it away from anything that recurs, because a mistaken subscription is the failure mode that costs the most and is noticed the latest.
Above all, ask the question before signing up rather than after: in writing, what happens if the agent buys something I did not want? If the answer is not in the terms, the answer is you.
