Your AI Just Bought Something. Who Does FINTRAC Think the Customer Is?
In 2026, checkout can be done by an AI agent finding the item, checking the terms, and paying for it while you're asleep. That's an agentic payment. It's the biggest change in payments since the smartphone put a card reader in every pocket. And it breaks the assumption every AML rule in Canada was built on. The assumption: a human is present when the purchase happens. Take that away, and your compliance program is operating on maybes.

What Is an Agentic Payment?
It's any purchase where an AI agent starts and approves the transaction on someone's behalf.
The agent could be a shopping assistant in a chat app.
A browser copilot comparing prices across ten tabs.
A back-office bot that reorders stock before the warehouse runs dry.
What matters is the decide-and-pay loop that always needed a human hand now runs by itself, inside limits someone set days or weeks earlier.
Everyone Is Building This Right Now
This is an arms race across the entire card industry.
Google launched the Agent Payments Protocol (AP2) in September 2025. By April 2026, it had more than sixty partners on board, including Mastercard, Visa, PayPal, American Express, Coinbase, Adyen, Revolut, and UnionPay.
OpenAI and Stripe put out the Agentic Commerce Protocol as an open standard that same month.
Visa shipped its Trusted Agent Protocol. Mastercard launched Agent Pay and ran its first authenticated agentic transaction before 2025 ended.
Then, in January 2026, Mastercard's chief digital officer said the company is building for every major protocol at once. People don’t know which standard wins, so nobody's betting on just one.
Even the IMF is paying attention. It published a note this year on how agentic AI will reshape payments. Once the IMF writes about your payment rail, it's stopped being a demo.
OpenAI's in-chat Instant Checkout launched with Etsy in September 2025 and was quietly retired in March 2026, with OpenAI pivoting to product discovery instead.
So Who Is the Customer Now?

Every KYC obligation under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act assumes an identifiable human or entity sitting behind the account. You verify them. You risk-rate them. You monitor how they behave.
Now an agent holds the wallet. So which one is your customer?
|
Candidate |
Case for it |
Problem with it |
|---|---|---|
|
The human who set the limits |
They authorized it, they own the funds |
They may never have seen this specific transaction |
|
The AI agent |
It made the call and hit "buy" |
Not a legal person, can't be identified |
|
The platform running the agent |
Controls the infrastructure and the traffic |
May sit outside Canada, outside your contract |
The answer is: it's still human. The account holder is your customer. Delegation doesn't change that.
Canada already wrote this principle down, just for a different situation. Since October 2025, reporting entities can use an agent or mandatary to verify an entity's identity, and the rule is explicit that the reporting entity stays responsible for compliance.
That rule was written about people. But the logic is the same anyway. You can delegate the doing but not the answering.
What Happens to Monitoring When Your Customer Never Sleeps?
Every transaction monitoring model running today was tuned on human behavior.
Odd hours look suspicious because humans sleep. Rapid-fire sequences look suspicious because humans hesitate. Perfectly formatted, identical requests look suspicious because humans are messy.
An agent is none of that. It's nocturnal, fast, and immaculate by design.
So two things happen at once, and they pull in opposite directions.
Legitimate agent traffic trips every velocity and timing rule you've built. Your analysts spend the week clearing alerts on a bot buying printer paper.
Once your team learns that fast, odd-hour, structured activity is "just the agents," actual layering finds somewhere lovely to hide.
Agentic traffic delivers alert fatigue at machine scale. We've covered what FINTRAC expects from AI-assisted monitoring before. Automation raises the bar for human oversight.
Can an Agent Structure Payments Better Than a Person?

Yes.
Structuring means splitting a large transaction into smaller ones to dodge reporting thresholds. A human doing this is slow, sloppy, and leaves fingerprints.
An agent doesn't get bored. It can spread purchases across merchants, rails, currencies, and hours in a pattern no human analyst would catch while technically doing exactly what it was told to do.
Chain that across multiple agents in different jurisdictions, and you get layering with an audit trail that looks flawless at every single step.
Nobody has to build a malicious agent for this to happen. Somebody just has to write clever instructions for an ordinary one.
Wait, Is There Any Good News Here?
Actually, yes.
Mandate architecture produces better evidence than most compliance programs generate on their own today.
Think about what a signed Intent Mandate actually contains: what the customer asked for, the limits they set, the exact time they set them, and a cryptographic signature proving none of it was altered afterward.
Most reporting entities can't produce anything that is clean about a human customer's intent. What they usually have is a login record and a timestamp.
If agent traffic arrives with a verifiable chain of authorization attached, that transaction's evidence trail is stronger than the one for the person who typed their card number in by hand.
The catch: you only get this benefit if you actually capture, store, and can retrieve the mandates. Evidence you didn't keep is evidence you don't have.
Has FINTRAC Said Anything About This?
Not specifically. There's no guidance today with the words "agentic payments" in it, and anyone telling you otherwise is selling something.
But the existing standard already addresses this problem.
Since March 2026, Bill C-12 requires compliance programs to be reasonably designed, risk-based, and effective. FINTRAC's compliance program guidance already requires your risk assessment to cover your delivery channels, your products, and new technologies.
An agent-initiated payment is a delivery channel.
So here's the question an examiner can ask you today: does your risk assessment mention this? If agent traffic is reaching your platform and your risk assessment stays silent about it, that's a blind spot under current law.
Are You Already Exposed Without Knowing It?
Probably worth checking.
You may already be seeing agent traffic if any of these sound familiar:
-
Your checkout accepts card-on-file or tokenized credentials from a third-party assistant
-
You're a PSP whose merchants have turned on agentic checkout
-
You process for marketplaces with agent-facing storefronts
-
Your crypto platform supports programmatic trading or automated purchase flows
-
Your customers include businesses running procurement or restocking bots
Firms in these categories can't currently tell you what percentage of their volume is agent-initiated because nothing in their stack tags it.
That's the first problem to fix. You can't risk-rate a channel you can't see. For PSPs, this stacks on top of your existing RPAA obligations to the Bank of Canada, in force since fall 2025.
What Should a Canadian MSB or PSP Do This Quarter?
1. Find out if agent traffic is reaching you and tag it.
Ask your payments and engineering teams: can we tell agent-initiated transactions apart from human ones today? If the answer's no, that's ticket one.
2. Write the channel into your risk assessment.
A short section beats silence every time. Name the channel. Say what you know. State your controls. Say what you're still figuring out. Examiners are far kinder to documented uncertainty than to an omission.
3. Decide your policy before you need one.
Do you accept agent-initiated payments? Above what value? With what authentication, and which credentials are required? A one-page position is enough as long as it has a date and an owner.
4. Look at your monitoring thresholds with fresh eyes.
If a bot can trip fifty rules a night doing something completely legitimate, your rules need a segment built for it.
And keep a human in the loop with real authority to pull the plug. Whether an AI can actually hold the compliance function has a clearer answer than vendors want you to believe.
FAQ
What is an agentic payment?
A transaction that an AI agent starts and authorizes for a person or business, inside pre-set limits, with no human present at the moment of purchase.
Does Canadian AML law cover agentic payments?
Yes, indirectly. There's no agent-specific guidance yet, but PCMLTFA obligations attach to the reporting entity no matter what initiates the transaction. Your program has to work for the channels you actually have including this one.
Who is the customer when an AI agent pays?
Today, it's the human or entity who holds the account and sets the limits. The agent is a delegate. Delegation doesn't transfer your obligations.
Do agent payments increase money laundering risk?
They change the risk more than they raise it outright. Structuring and layering get faster and cleaner. Audit trails, when mandates are captured, get stronger. Which way it nets out depends entirely on whether you can see the traffic.
Do we need a brand-new risk assessment?
No, an updated one. Agent-initiated payments are a delivery channel and belong in the channel section you already maintain.
Our vendor says their agentic tooling is compliant. Is that enough?
No. Compliance is a property of your program, not their product. Ask what evidence their tooling actually gives you, who reviews it, and what happens when it's wrong.
Get In Touch
If your AML program leans on automation and you're not sure the human oversight underneath it would survive a real review, better to find out now than during an examination.
- AML Effectiveness Review: a structured review of your program, including how your AI compliance tools are governed, documented, and overseen, benchmarked against current FINTRAC expectations.
- CAMLO and MLRO Services: an embedded, qualified compliance officer who meets FINTRAC's actual standard for authority and sector knowledge, without the cost of a full-time hire.
- FINTRAC MSB Registration: for firms that need their program, AI tooling included, structured correctly from day one.
Book a discovery call and we'll walk through exactly where your program stands.




