Cloudflare‘s launch of digital identity and payment capabilities for AI agents is accelerating a debate the payments industry has been circling for the better part of a year: whether the technical infrastructure for autonomous commerce is moving faster than the trust frameworks required to govern it.
Andrew O’Connor, agentic AI lead at PSE Consulting, argues the announcement represents meaningful progress but also surfaces the sector’s most pressing unsolved problem. “Giving AI agents a persistent identity and the ability to transact securely addresses one of the biggest barriers to adoption,” he said. “For merchants, knowing an AI agent has been authenticated and is acting within a consumer’s delegated permissions is essential if autonomous purchasing is to become a trusted part of everyday commerce.”
An emerging infrastructure race
Cloudflare’s move does not arrive in isolation. Over the past twelve months, the major payment networks have been staking their own positions in the agentic commerce stack. Visa has developed its Trusted Agent Protocol, Mastercard has introduced Agent Pay, and Google has published its Agent Payments Protocol, known as AP2. Each initiative attempts to solve a similar problem: how to give AI agents a verifiable identity, bounded spending authority and an auditable transaction record that merchants and consumers can rely on.
The proliferation of competing protocols is, in itself, a risk. O’Connor is direct on the point: “Fragmentation risks creating multiple trust models that don’t interoperate, risking a loss of momentum just as consumer and merchant interest begins to accelerate.” The parallel with the early days of contactless payments or open-banking connectivity standards is instructive. In both cases, a period of competing implementations preceded the consolidation around common rails, and the consolidation lag carried a real commercial cost.
Regulatory and standards considerations
The regulatory read-across is still forming. In the UK, the FCA‘s work on AI governance and the Payment Systems Regulator’s focus on authorised push payment liability both touch the question of delegated authority, but neither framework was designed with AI agents in mind. In the EU, PSD3 and the proposed Payments Framework Regulation extend strong customer authentication requirements in ways that may need interpretation before they apply cleanly to agent-initiated transactions. DORA’s operational resilience requirements will also matter for any infrastructure layer that processes payments autonomously at scale.
What is clear is that the accountability question, which entity bears liability when an AI agent transacts erroneously or is compromised, remains unresolved across all major jurisdictions. Cloudflare’s identity layer contributes the authentication piece, but authentication is a precondition rather than a complete answer.
O’Connor frames the next phase in terms that will resonate with payments executives thinking about infrastructure investment: “The next phase of agentic commerce will depend on building infrastructure that makes autonomous transactions as secure, transparent and reliable as tapping a contactless card.”
The near-term markers are whether the competing protocols converge on a common interoperability standard, whether any major payment network or regulator moves to endorse a single framework, and how quickly merchant acquirers and payment service providers build agent-authentication into their own onboarding and risk processes. Cloudflare’s announcement adds weight to the infrastructure side of the ledger; the governance side remains the open question.
The post Cloudflare AI Wallets Put Agentic Commerce Trust Frameworks to the Test appeared first on The Fintech Times.