EXCLUSIVE: "When the Agents Go Shopping" - Olivier Sery, G+D, Ivan Vukelikj, G+D Netcetera and Trilochan Sehgal, Daon in 'The Fintech Magazine'
By Lauren Towner · 7 October 2026

G+D and Daon partnered to raise the bar on KYC. The next challenge is KYA. But while technology companies are driving forward, are regulators keeping pace?
The run-up to Christmas 1983 saw one of the strangest near-riots in Pennsylvania’s history. Parents were so desperate to get their hands on the must-have Cabbage Patch Kids toy that shopkeepers had to arm themselves with baseball bats. One woman broke her leg in a crush, and another desperate father flew to London just to get a doll.
Imagine if these frantic parents could have simply asked a platform like ChatGPT or Amazon’s Alexa for Shopping to scan marketplaces and buy one for them. That would have saved a lot of fuss, flight tickets and medical bills.
AI driving retail traffic
That future is almost here. The run-up to last Christmas saw generative AI tools drive a 693 per cent increase in traffic to retail sites, according to Adobe Analytics, compared to 2024. Parents are taking Santa lists to ChatGPT and getting on with their day. The next logical step is for the AI platforms to make the purchase unsupervised. In 2025, Amazon launched Rufus, an AI assistant with a Buy For Me service, which doesn’t just shop in Amazon Marketplace, but claims to scan other stores, too.
“These agents will start playing an increasingly active role in terms of representing somebody, doing the transaction for somebody,” say Daon’s Vice President of South East Asia Sales, Trilochan Sehgal.
Indeed, Rufus has already been used by more than 300 million customers, helping to deliver $12billion in sales. Following the success, Amazon has blended its capabilities with Alexa+ to create Alexa for Shopping. This means that with a simple voice instruction – “Alexa, buy 24 toilet rolls with same-day delivery” – customers don’t even need to be in front of a screen.
A bacon topping on a McFlurry
It’s not without risks, however. We’ve all asked Alexa or Siri to play one song, only for it to blast out something completely different. What if, later that afternoon, we find 24 foil bowls on our doorstep? Or toys that roll? Or any other homophone of ‘toilet rolls’? Being oblivious to pranks and lacking basic common sense, USA fast food drive-thrus have faced similar struggles with voice-activated orders. One man broke the Taco Bell system by ordering 18,000 cups of water, while a McDonald’s customer was furious to find bacon toppings on his McFlurry.
Sometimes AI assistants have cost their humans more than just curious-tasting ice cream. In 2021, real estate company Zillow lost $300million and was forced to cut 25 per cent of its workforce when it emerged that its iBuyer assistant had been dramatically overpaying for properties. This clearly dented confidence in the ‘buy-for-me’ movement. One in two people (48 per cent) currently would not be comfortable letting an AI agent spend their money for them, found research by Ipsos.
“People will not trust an AI agent with a blank cheque,” Anne Boden, Founder of Starling Bank, told The Banker magazine this year. “They may trust one with clear limits, audit trails, revocation rights and accountability.”
The issue of accountability is an important one. After all, who is responsible when an AI agent accidentally spends $500million? And how do banks authenticate that a bot belongs to a verified customer who has authorised the trade? Air Canada was found by a tribunal to be liable for promises its agent had made, even though it didn’t accord with the company’s published policies and was ordered to pay. One unsuspecting consumer was forced to pay 24,000CHF – around $30,000 – because his AI agent signed deals on his behalf while he slept.
The threat is real. Trust is at risk.
By 2030, McKinsey estimates that AI agents will spend $5billion of humans’ money on their behalf. With usage mounting, the identification and accountability question needs to be solved quickly.
The FCA weighs in on KYA.
The issue of trust runs deep in payments, whether they’re initiated by a human or a machine. And the partnership between South East Asia-based global digital ID specialist Daon and global securitech company Giesecke+Devrient (G+D) addresses the fundamental pillars that support it. Olivier Se ́ry, Global Head of Digital at G+D, articulates those pillars as identity, consent/ intent, security and frictionless UX, all of which are influenced by regulatory frameworks.
With regulators running fast to adapt regimes to combat identity fraud – particularly the exponential rise of synthetic identity fraud – the G+D/Daon partnership is particularly focussed on identity continuity. It provides ‘continuous trust behind every transaction at every interaction with customers’, says Se ́ry. Under the partnership signed in May 2025, G+D and Daon promised to build solutions to conquer AI-driven fraud and fragmented identity systems.
Daon’s Sehgal describes the partnership as a ‘match made in heaven’.
“G+D is a market leader in secure payments infrastructure. Daon is a leader in identity assurance. These two things cannot operate in parallel. They are embedded together,” he says. Since their deal was signed, further regulatory pressure and the emergence of agentic shopping has only raised the bar across multiple markets. One of the ways that G+D and Daon plan to protect personal information and reduce fraud, including within agentic e-commerce, is to create more moments for seamless identity verification.
“Identity has to be embedded in real time to ensure that it is frictionless,” Sehgal says. “You cannot do identity verification/authentication after the fact. It has to happen in real time for the transaction to occur in real time, too.”
In a recent white paper, Daon stressed the urgent importance of continuous biometric identity checks. While the user probably wouldn’t even notice it’s happening, it makes a huge difference to security. With the wallet-owner becoming more distant – even now acting via proxy – every opportunity for a check counts.
An evolving KYA
For now, the rules of know your agent (KYA) are voluntary and a work-in-progress. But at first glance, the frameworks seem to be just as vigorous, if not more so, than human-based know your customer (KYC). An agent will most likely need to be onboarded into financial services with strict spending limits, counterparty whitelists, velocity caps (transaction frequency limits), and settlement conditions set and audited – all predefined in the contract. Every transaction it undertakes will probably need to be timestamped and recorded on an immutable ledger, in line with the blockchain principles it is built on.
The UK Financial Conduct Authority’s (FCA’s) Head of Innovation, Colin Payne, recently co-authored a landmark paper, Commerce At Machine Speed, Part II, with then-Policy Director of CFIT and Chief Ecosystem Officer of tokenised money network Ubyx Inc, Nicole Sandler. The paper explores the ‘governance, accountability, and regulatory framework agentic commerce requires’. It finds that the process of granting permission – usually done by the customer at the point of sale – has moved upstream, to a more distant permission-based model. And this requires a whole new onboarding procedure that is KYA.
This is something G+D is staying close to.
“We are working on agentic commerce concepts and also applying AI technology into our operational processes,” says Ivan Vukelikj, Senior Product Manager at G+D Netcetera.
The wider group currently provides agentic e-commerce features and services, ‘based on the tokenisation, digital delegated authentication [and] secure remote commerce (SRC) technology’, adds Vukelikj. Data privacy and protection against fraud remain paramount. As the Payne/Sandler paper explains, the agent should be able to ‘confirm sufficient funds without disclosing the account balance, verify identity without exposing personal details, and complete a transaction without revealing its terms to parties not required to know them’.
Redefining identity in agentic e-commerce
Thinking about the world of agentic AI and incoming KYA frameworks, Sehgal says: “Identity will have multiple shapes. Sometimes delegated identities, proxies, agents, machines doing payments in your name with wallets...”
The permutations are evolving all the time, with the FCA in the UK also raising the possibility of agentic digital twins.
“Over time, richer consumer data – potentially supported by open finance – could support far more detailed virtual models (‘digital twins’) of individuals, or even organisations”, it comments. This is yet another ‘shape’ that our future identities could take. As new technologies unfold, Se ́ry reflects that the underlying ethics remain the same.
“It’s about intent and consent, and it’s about security,” he says. Even in regulatory murkiness, steadfast governance must prevent harm to consumers, Se ́ry adds.
Regulation remains patchy
Both Sehgal and Sery welcome regulatory direction as they help clients build solutions for current rapid scaling of agentic e-commerce. But speed is of the essence.
“Without blessings from regulators, without having guidelines,” says Sehgal, “it is very difficult to operate these large digital ecosystems and frameworks.”
In South East Asia, the regulatory landscape around agentic e-commerce is diverse. Some countries, such as Singapore, Hong Kong, Australia, and Japan, have always been more proactive in terms of managing and providing guidelines. While others like Thailand, the Philippines and Malaysia tend to follow later. In January, Singapore launched the world’s first Model AI Governance Framework (MGF) for Agentic AI at Davos, taking a global lead. Although the framework remains voluntary, it offers a glimpse for paytech firms into the potential regulatory future.
EU regulators are considering how to govern agentic e-commerce in the broader context of the EU’s AI Act, latest Payment Services Directive (PSD3) and EU AI Liability Directive. Meanwhile, the UK Competition and Markets Authority released its guidance on agentic AI and consumer law in March 2026. While this went some way to clarify a business’ obligations around AI, it did not provide a solid framework.
In July, the Mills Review commissioned by the UK’s FCA to look at ‘how AI will reshape retail financial services’, observed: “As people shift from consultant to approvers of AI agents – whether these are mainstream consumer platforms or use of independent AI agents – [they] may stop challenging decisions made on their behalf or over-rely on AI applications. This combination will amplify financial crime and cyber risks.”
The FCA has hinted that it’s not planning to push for a new regulatory regime but rather apply an outcomes-based approach to how firms protect customers using autonomous AI. Notably, no regulator has put a mandatory agentic e-commerce framework in place.
Filling framework gaps
Filling the vacuum, several notable technology and fintech giants are putting forward their own standards, reminiscent of the internet era, where open-source collaboration ruled. One of the most prominent frameworks for e-commerce agents is Google’s Agent Payment Protocol (AP2), which launched in September 2025. In line with open-source thinking, the framework is payment-agnostic, meaning merchants, shoppers and payment providers can use all types of payment methods.
Google chose Singapore to develop the technology further, showing how much of a first-mover advantage regulators can create for their fintech ecosystems. It’s little surprise that those with the most developed frameworks attract more business as firms seek reliability and stability.
Mastercard, which has been building the infrastructure for agentic e-commerce with its Mastercard Agent Pay programme, since 2025, also chose South East Asia (Singapore and Malaysia) for its launch this summer. The system uses AI agents and blockchain principles to ensure that transactions move as fast as the internet. In March of this year, Mastercard also launched its Verifiable Intent Initiative to strengthen customers’ consent and authorisation, using cryptographic records.
Collaboration as a requirement
While tech giants speed ahead with frameworks, regulatory oversight is still essential. As Sehgal points out, this is how the focus can stay on matters like ‘bringing financial inclusion into the picture’.
“They are thinking from the end-customers’, the citizens’ point of view,” Sehgal continues. He speaks of the potential to make people’s lives easier, especially in rural areas of South East Asia where ‘banking facilities have not been great’. He believes that this can ‘only happen when regulators take a leading role’.
Another crucial role that regulatory bodies can play is around ensuring fair competitive practices across the industry. If only the most powerful firms gain the first mover advantage, there is a risk that smaller, innovative companies become excluded. All three interviewees in this piece are keen to move forward as an ecosystem.
“We want to contribute and collaborate in shaping this new digital commerce concept,” says G+D Netcetera’s Vukelikj.
For Se ́ry, collaboration is not just better for commercial purposes, but also the best defence for protecting customers, too.
“We have a lot to learn about sharing between the different parties”, he says. “We know fraudsters share, so why shouldn’t we?”
As the months rumble on and the next dreaded Christmas-creep begins, hundreds of millions of parents will likely ask their AI platform to pick up the latest trending toy. Will the frameworks be in place? Nobody wants to risk breaking a leg over a Cabbage Patch Kid, but not many would enjoy an AI-spending frenzy over a Stanley Cup, either.