Speaking at the VB Transform 2026 conference in Menlo Park, Greg Ulrich, Chief AI and Data Officer at Mastercard, revealed that the company is fundamentally restructuring its risk management framework to allow AI entities (bots and AI agents) to conduct transactions directly. This marks a massive paradigm shift for a payment network that has spent decades training its security systems to treat bots as credential-stealing threats.
Background & Drivers
Over the past year, the Mastercard network processed up to 175 billion transactions, with risk assessments taking less than 100 milliseconds per transaction. The system assigns a risk score from 0 to 999, helping issuing banks decide whether to approve or decline a payment. However, with the rise of 'agentic commerce'—where consumers or businesses delegate purchasing power to AI agents—legacy security rules designed to block all automated bot activity have become obsolete. According to Mastercard, transitioning from blocking bots to securely facilitating their transactions is essential to prepare for this new technological wave.
Technical Analysis & Technology
To address the complexities of autonomous transactions, Mastercard has developed a five-layer security architecture: - Identity: Integrates the 'Know Your Agent' (KYA) concept to register and verify the legitimacy of each agent. - Verifiable Intent: Uses tamper-proof cryptographic records to log the user's original instructions. - Controls: Restricts spending limits and compiles approved merchant whitelists. - Execution: Powered by Mastercard Agent Pay and integrated with tokenization technology, developed in partnership with Microsoft, OpenAI, and Google. - Intelligence: Monitors risk behavior and provides deep analysis of emerging threats.
Expert Perspectives & Insights
Greg Ulrich emphasized that the greatest barrier to scaling AI lies not in the capabilities of Large Language Models (LLMs), but in user trust regarding agents acting on their behalf. A June 2026 VentureBeat study highlighted a major security gap: only 32% of surveyed enterprises assign dedicated administrative identities to individual AI agents, significantly increasing the risk of data leaks or unauthorized transactions. Mastercard is actively promoting open standards to identify and closely bind agents to their human or corporate owners.
Impact & The Future
Beyond consumer retail, Mastercard anticipates even larger opportunities in B2B procurement, where autonomous agents can manage inventory, track budgets, and automatically place orders with approved vendors. To secure this complex ecosystem, Mastercard has been testing advanced AI models, including Anthropic's 'Mythos' and OpenAI's 'GPT-5.5-Cyber', to proactively detect system vulnerabilities. This shift heralds a future where financial transactions are no longer strictly dependent on human actions, demanding a more comprehensive and unified digital trust infrastructure.