
Mastercard and Alchemy give AI agents virtual cards to shop autonomously
Published by AINave Editorial • Reviewed by Ramit
Mastercard is partnering with Alchemy to give AI agents their own virtual cards, letting them autonomously shop, book travel, and pay within user-set limits. The move requires flipping anti-fraud rules that were built to block bots. For AI builders, this unlocks a new category of agent-driven commerce, but it also forces hard questions about governance, spending controls, and safety.
How AgentCard works: CLI, virtual identities, and one-time credentials
Through Alchemy's AgentCard, developers can use a single CLI command to equip an AI agent with a full identity and payment toolkit: a dedicated email address, phone number, stablecoin wallet, and one-time Mastercard payment credentials. The system uses tokenized permissions via Mastercard Agent Pay, where the customer authorizes the agent ahead of time with specific constraints like a price range or spending cap. Visa already has a similar partnership with Alchemy.
The risk framework reversal that makes this possible
For years, payment networks have built risk rules designed to stop bots from transacting. Mastercard's chief AI and data officer Greg Ulrich acknowledged the shift: "Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules." Mastercard is also working with Visa and Ant International to develop common standards for verifying and monitoring trusted AI agents in online purchases, a crucial step before large-scale deployment.
What builders need to know about AI agent payments
If you're building shopping agents, this infrastructure removes a major friction point: the agent can now complete the purchase instead of just adding items to a cart. McKinsey projects AI agents could handle $3 trillion to $5 trillion in global consumer commerce by 2030, and Mastercard's own report predicts one in ten online shoppers will routinely use AI agents to buy products by that year. But building with these tools means implementing your own spending limits, transaction monitoring, and kill-switch mechanisms, because the network-level controls are still evolving.
Rogue agent risks and the need for guardrails
The safety debate is not abstract. AI safety organizations like METR and the AI Security Institute have warned that if AI agents become capable enough to evade Know Your Customer checks and self-replicate, they could pose serious threats to financial infrastructure. The parent article references concerns that enabling agent payments could remove the human enablers that currently act as a barrier to abuse. For now, the practical risk is lower, but builders should treat agent payment capabilities as a powerful tool that demands proportional governance.
FAQs
Sources
- Mastercard Is Giving AI Agents Virtual Cards to Handle Your Shopping
- Mastercard Is Giving AI Agents Virtual Cards to Handle Your...
- Mastercard launches Agent Connect to help... | Mastercard US
- Visa, Mastercard give AI credit cards | The Rundown AI
- Ant International joins Visa, Mastercard to build AI agent payment...
- PYMNTS | Mastercard Enhances Virtual Cards to Streamline...
- AI agents are learning to spend money. Who will handle the payments?
- Virtual cards for AI agents: How they work and what to look for
- Virtual Cards To Protect Your Payments | Virtual Payment Cards
- Virtual cards for AI agents: How they work and what to look for
- Mastercard joins race to enable AI agent payments | LinkedIn
- Mastercard Launches New AI Commerce Tools for Merchants and...
- Ant International partners with Visa, Mastercard on developing AI payments
- Mastercard report predicts that 1 in 10 people will routinely use AI agents to shop and pay by 2030
- Mastercard’s Sherri Haymond on Letting AI Shop While Consumers Stay in Charge






















