No spam - just the latest insights!
Join over 30,000 industry professionals who subscribe for free
Subscribe for free!
We'll never share your information or send you spam
Ashlin Perumall is a partner and Head of the IPTech practice at Baker McKenzie in Johannesburg, dual-qualified in South Africa and England and Wales. His practice centres on transactions, regulation and strategy at the intersection of financial services and emerging technology. He acts as key advisor to clients entering or acquiring in African fintech, including paytech, open banking, digital banking and APIs, and advises on responsible AI governance, AI procurement, crypto-asset regulation, and blockchain and distributed ledger technology. He has particular experience establishing legal, compliance and diligence frameworks for novel, technically complex products and businesses. Ashlin is a Fellow of the World Economic Forum’s Centre for the Fourth Industrial Revolution, where he conducted regulatory and policy research in San Francisco, and has also worked in the firm’s London office. He writes and speaks regularly on law, AI and technology. He is ranked Band 1 for FinTech by Chambers Global and holds an LLM in Innovation, Technology and the Law from the University of Edinburgh.
Delegating standing payment authority to autonomous AI agents exposes a fundamental gap in how liability is attributed within traditional banking frameworks. Consider a procurement platform where an AI agent automatically settles an invoice. On paper, one could argue that the process is flawless: once the ordinary credentials check out, the parameters are essentially met, and the payment rail can clear the funds. But what happens if the invoice itself is fabricated? For example, where a compromised email from a supplier contained hidden text instructing any AI reading it to reroute the cash to a new account, and the agent simply processed the text and complied. Right now, in South Africa and many other countries, the result is a complete deadlock. The customer will argue that they never approved the transfer, while the bank maintains their security was never breached. The core problem is that, from both a technical and legal standpoint, both positions are presently entirely defensible.
That dispute is one of the core legal problems existing today for the coming wave of ‘agentic commerce’, i.e. systems where software agents initiate and complete payments on behalf of human users. The current legal framework governing these transactions rests on a core assumption that a payment instruction represents the actual intent of its issuer. Agentic AI processes break that assumption. Agents can be manipulated into executing genuine instructions their human principals never intended, and further, deepfake technology complicates the identity verification processes relied upon to resolve such disputes. As a result, authorisation and authentication are colliding, and South Africa’s existing statutory framework, payment rail architecture and current modernisation programme each offer part of the answer.
The agentic infrastructure supporting this shift is already taking shape, and has arrived much faster than many in the industry expected. Throughout 2025, major payment networks launched protocols explicitly built for agentic commerce. One global network introduced an ‘agent pay’ solution using tokens to bind credentials to specific AI agents, while a key competitor rolled out a similar trusted agent protocol. Technology providers moved in tandem, with leading AI developers releasing frameworks that anchor transactions in cryptographic proof of both the user’s request and the agent’s proposed action.
The terminology emerging from these developments is worth noting. Global standards for machine-initiated payments have overwhelmingly adopted the term “mandate”, seen directly in a prominent agent payments protocol that structures every transaction around a signed “Intent Mandate”, “Cart Mandate” and “Payment Mandate”. Under South African law, a mandate is the precise mechanism used to authorise one party to act on behalf of another. By adopting this language, the technology sector has arguably conceded that the core challenge in agentic commerce is fundamentally a question of agency law.
South Africa’s financial sector is already laying the groundwork for this transition. A November 2025 joint report from the FSCA and the PA reported that, as at its 2024 industry survey, 52 per cent of banks and 50 per cent of payment providers had AI in production. While current applications are concentrated in areas such as fraud detection, operations and customer service, the leap to transacting agents is likely imminent.
Jurisdictions confronting the same question have produced three broad groupings of responses, and each is instructive for emerging markets such as South Africa.
The first grouping engineers the mandate directly into the payment rail, and India is furthest along this path. The National Payments Corporation of India introduced delegated payments on the Unified Payments Interface in 2024 through UPI Circle, allowing an account holder to grant controlled payment access to a secondary user within defined limits. An October 2025 circular extended that delegation to software and connected devices, creating a framework for payments executed by AI agents on the national rail. According to press reports, the corporation is developing a Unified Agent Protocol, a proposed national registry through which AI agents would be registered, verified and authorised to transact; the protocol reportedly requires Reserve Bank of India approval before launch. India’s technology ministry has separately proposed mandatory human-in-the-loop interventions for defined categories of agentic payments. Brazil is adopting a similar approach. Pix Automático, live since June 2025 and mandatory for every payer-side institution participating in the Pix instant payment system, lets a payer grant a single in-app authorisation against which the central bank’s rail validates all future recurring collections.
The second grouping accepts that some deceived payments will clear and reallocates the loss by regulation. The United Kingdom’s mandatory reimbursement regime for authorised push payment fraud, in force since October 2024, requires payment service providers to refund defrauded customers up to GBP 85,000, with the cost split equally between sending and receiving institutions. In July 2026, the Payment Systems Regulator published the first full independent evaluation of the regime, conducted by Frontier Economics. The evaluation estimated that annual APP fraud losses over Faster Payments were approximately GBP 73 million lower than they would otherwise have been, a reduction of roughly 21 per cent, with the share of losses reimbursed rising from 54 per cent
to 65 per cent. Frontier further found that more than 99 per cent of reimbursable claims and more than 95 per cent of reimbursable value fall below the GBP 85,000 cap; the cap, the 50/50 cost split and the consumer-caution exception are all under review, with findings due during 2026/27. Similarly, Singapore’s Shared Responsibility Framework (effective December 2024) distributes phishing scam losses along a waterfall (based on duties breached): financial institutions bear the first tranche, then telecommunications providers, before any loss rests with the consumer. The European Union’s Payment Services Regulation, whose final text was agreed in April 2026 and which is expected to apply roughly 18 to 21 months after publication in the Official Journal, goes a step beyond: it will grant an uncapped refund right where a fraudster impersonates the customer’s own provider, conditional on the customer reporting the matter to the police and notifying the provider. The regulation will also extend payee-name verification beyond the SEPA Instant rail, where it has been mandatory since October 2025 under the Instant Payments Regulation, to credit transfers more broadly. These regimes matter for agentic commerce because a prompt-injected payment is, in substance, the machine-executed version of the deceived authorised payment they were built to address. The UK data indicates that deliberate loss allocation changes behaviour rather than simply redistributing cost across the system, with fraud losses falling measurably. The EU is also constructing an identity layer: every member state must offer citizens a European Digital Identity Wallet by the end of 2026, built on verifiable credentials of the same kind agentic payment protocols now demand.
The third grouping modernises the underlying contract law. The UNCITRAL Model Law on Automated Contracting, adopted in July 2024, was drafted for the same gap. It establishes updated rules attributing the outputs of automated systems (including AI systems) to the party using them, together with an optional rule addressing unexpected outcomes; it is designed to supplement first-generation electronic transactions statutes of the kind South Africa enacted in 2002. No African state is known to have enacted it. The first to do so will, as a result, have the continent’s most current legal foundation for machine-initiated commerce.
South Africa addressed some of the legal questions of automated commerce relatively early. The Electronic Communications and Transactions Act 25 of 2002 (ECTA) validates agreements formed by electronic agents. Section 20, which in retrospect was far ahead of its time, presumes a party using an electronic agent is bound by the resulting terms, regardless of whether a human reviewed the action. Section 25 attributes a data message to its originator if sent by an automated information system, unless the system failed to execute its programming properly.
Beneath ECTA lies the common law of mandate, which dictates the scope and limits of authority. Above it sits the National Payment System Act 78 of 1998 and the SARB directives governing third-party payment providers, much of which is undergoing significant overhaul in 2026.
On paper, this hierarchy appears coherent. Every layer, however, was drafted for deterministic automation: systems that execute pre-set instructions in rigid ways. The drafters of ECTA envisioned two outcomes: the system works as programmed (binding the principal) or it malfunctions (releasing them). However, a probabilistic large language model agent introduces a third. It interprets context, takes instructions from the unstructured data it reads, and may act independently in goal-driven systems rather than acting on deterministic choices by human principals.
The OWASP 2026 Top 10 for LLM Applications, published on 4 August 2026, ranks prompt injection as the primary security risk for large language model applications, a position it has held since the list’s inception but now with expanded scope covering cross-modal attacks, memory persistence and agentic blast radius. The same edition elevated Excessive Agency from sixth to third place, driven by real-world agentic deployments. The underlying structural vulnerability is that these models process instructions and data through the same channel. Text an agent reads from an invoice or email can therefore function as an executable command if structured in certain ways and if guardrails don’t catch it. For an agent holding payment credentials, the possible result is a fully authorised outbound transfer, which would be difficult to distinguish from a validly authorised one, given that no system intrusion or stolen password is required.
Applying this scenario to existing legal frameworks exposes several gaps. Standard banking practice for unauthorised transactions relies on evidence of compromise, such as a stolen card or a hijacked session. In an agentic commerce scenario, the agent’s own credentials sign the instruction. Under the law of mandate, the agent technically operates within its express authority to pay approved suppliers. ECTA, and similarly structured legislation in other countries, provides no clear remedy either. An AI agent manipulated by injected text has not malfunctioned; processing contextual instructions is its intended function. The defect lies in the external data it read, a scenario the statute does not contemplate. Loss allocation will therefore depend on improvised readings of contract terms and negligence principles designed for human agents. The UK, Singaporean and EU regimes described above show what a deliberate allocation looks like, and South Africa currently has no equivalent default.
South Africa’s financial regulators have identified these vulnerabilities. In particular, the FSCA and PA explicitly ranked cybersecurity among the top risks of AI adoption. Their reporting details specific mechanisms of concern: data poisoning, privacy exposures under POPIA, and the systemic risk created when AI capabilities concentrate among a few third-party vendors. The Financial Stability Board, an international body that strongly influences South Africa’s financial regulatory framework, identified third-party dependency and cyber vulnerability as central supervisory issues for the sector in a June 2026 consultation paper on responsible AI adoption, with practices 11 and 12 addressing AI-related cyber, ICT and third-party risks specifically. The consultation closed on 22 July 2026, and the final report is due in October 2026. Notably, the FSB’s October 2025 monitoring report on AI in financial services was produced at the request of the South African G20 Presidency, underscoring the country’s direct stake in shaping the international supervisory consensus on these issues.
Supervisory standards are evolving accordingly. Joint Standard 1 of 2023 on IT governance and Joint Standard 2 of 2024 on cybersecurity and cyber resilience compel financial institutions to maintain strict access controls and report material cyber incidents. A prompt-injection compromise of a transacting agent would ordinarily meet the materiality threshold for notification, which runs to 24 hours under Joint Standard 2.
South Africa has managed systemic payment disputes at scale before. Following widespread debit order abuse in the previous decade, the SARB mandated the DebiCheck system. DebiCheck shifted mandate authentication from the endpoint to the national payment rail itself. Under this model, the delegation of authority becomes an independently verifiable digital asset. Disputes were resolved against the registered mandate rather than through reconstructing intent.
International agentic payment systems are converging on a very similar architecture, using scoped tokens and verifiable agent identities. UPI Circle and Pix Automático are, in structural terms, members of the design grouping that DebiCheck pioneered for humbler technology. One could therefore argue that South Africa already has the institutional knowledge to implement mandate authentication at a national scale.
African payments are wallet-first and instant-payment-first, and therefore agentic AI will likely meet most African consumers inside mobile money platforms and national instant payment systems, not at card checkouts. The design decisions made by African rail operators will therefore matter more here than in card-dominated markets.
Nigeria illustrates the infrastructure trajectory clearly. The country issued Africa’s first open banking regulatory framework in 2021. Subsequently, the Central Bank of Nigeria committed to a phased commercial rollout in 2026, anchored on a central registry of verified participants operated by the Nigeria Inter-Bank Settlement System and a consent management framework tied to the Bank Verification Number. A national registry of authorised participants, joined to identity-anchored consent, is agent-registration architecture by another name; extending it to software agents is an increment, echoing the agent registry India is now designing. Kenya illustrates the governance trajectory: its National AI Strategy 2025-2030, launched in March 2025, is among the continent’s most developed, and a dedicated AI Bill is progressing. Both operate under the African Union’s Continental AI Strategy of 2024. At least sixteen of Africa’s fifty-four states have adopted national AI strategies to date, leaving a wide governance gap into which agentic commerce will arrive regardless.
Addressing this both locally and across African countries will be an important challenge, as ever-growing cross-border rails raise the stakes. The Pan-African Payment and Settlement System now connects twenty-eight countries and more than 190 commercial banks and fintechs, with the Bank of Central African States joining in July 2026. Once an agent’s payment instruction can cross a border in local currency, mandate authentication becomes a continental interoperability question: a delegation registered in one market must be verifiable in another. That is a standards problem the African Continental Free Trade Area’s digital trade agenda exists to solve, and one it can hopefully address. It is also an opening for South Africa: a mandate layer proven domestically could be exported through the same regional infrastructure now being joined together.
As a unique convergence of timing, these new developments come at a time when South African payments laws are undergoing unprecedented change. The SARB is advancing its Payments Ecosystem Modernisation programme, the most extensive intervention since the 1998 Act. With the development of the Vision 2030+ strategic framework and the PEMKey credential system, a new credential layer for the national rail is being designed now, and may be able to take advantage of the timing.
Regulators and institutions have an immediate opportunity to design this infrastructure so that it recognises the delegated and revocable authority held by software agents. The forthcoming National Payment System Bill offers a legislative vehicle to formalise these structures and to set default rules for loss allocation when a credentialed agent is deceived. The comparative lesson is that the two tracks work best together: rails that authenticate the mandate (as India and Brazil are building) and liability rules that decide the residual losses (as the UK, Singapore and the EU have introduced). South Africa is well placed to pursue both at once.
Institutions deploying transacting agents cannot wait for final regulatory instruments, as they will take time to develop and will likely trail the industry. The immediate defence requires treating the payment mandate as an independently governed asset. Financial providers must scope agent credentials at the transaction level (enforcing strict limits and short-lived tokens) and evaluate AI vendors with the rigour applied to cloud infrastructure. Existing compliance frameworks demand strict access controls; prompt-injection testing and privacy reviews fall within this perimeter.
The hypothetical dispute at the beginning of this article lacks a clear resolution under current South African law. Existing doctrine assumes a genuine instruction always aligns with user intent and, right now, agentic commerce severs that connection. A transacting agent can execute a cryptographically valid payment based entirely on manipulated external data.
The remedy requires hardwiring mandate controls into the payment rail. South Africa possesses the statutory foundation in ECTA to recognise automated acts; it holds the practical precedent in DebiCheck for authenticating authority at the network level. With the Payments Ecosystem Modernisation programme reconstructing the domestic rail, regulators have the legislative vehicle to embed delegated software authority directly into the clearance layer. Disputes over machine-initiated payments belong at the infrastructure level rather than in a courtroom.