Agentic AI Is Coming For Payments—And Credit Unions Must Prepare For A Fundamental Redesign

ST. PETERSBURG, Fla.—For decades, credit unions have fought a familiar battle: figuring out whether the person initiating a payment is actually a person—a legitimate member, not a fraudster.

Now, in a shift that experts say will redefine the entire payments ecosystem, credit unions are facing a new question: Is the AI agent initiating this transaction legitimate—or has it been compromised?

That pivot captures the scale of transformation arriving with agentic AI—autonomous software agents capable of making purchases, managing accounts, and disputing charges on behalf of consumers. And according to Elizabeth Wadsworth, senior AI innovation strategist at Velera, this isn’t a matter of adding a new payment channel or tweaking authentication tools.

“This is a big, big shift,” Wadsworth told CUToday.info. “We are gearing up for an entire redesign of our payments and chargeback ecosystems. This isn’t an add-on. It changes everything.”

What Exactly Are Agentic Payments?

In traditional digital payments, a human initiates the action: tapping a card, clicking “buy,” submitting a transfer.

Agentic payments flip that model.

An AI agent—operating independently but on behalf of the consumer—can:

  • Search for the best product or price
  • Authorize purchases automatically
  • Schedule recurring payments
  • Initiate chargebacks
  • Manage budgeting and cash flow

In short, the agent becomes the actor, not the user.

But that shift introduces a new threat surface. The central risk is no longer merely account takeover, Wadsworth emphasized, but agent takeover—where a threat actor manipulates or compromises the AI system that performs transactions autonomously.

“Agents can be compromised in ways traditional rails simply weren’t susceptible to,” she said. “We’re not dealing with people anymore—we're dealing with systems that can be compromised.”

A Total Redesign Of Payments—And Chargebacks

Wadsworth said the industry is only beginning to grasp the enormity of what agentic payments will require. Entire processes built over decades—authentication, authorization, fraud scoring, chargebacks—must be rethought.

“We’re exchanging one type of fraud for something much more sophisticated,” she said. “You can’t compare this to what we have today. The liability landscape, the risk landscape, the identity landscape—they all change.”

Chargebacks, in particular, could need a full reinvention, because the initiating party—not a consumer—may be an autonomous agent operating under delegated authority.

“That system depends on regulatory and scientific frameworks that don’t yet exist,” Wadsworth noted. “Once these technologies scale, compliance will have to follow.”

The New Threat Landscape: 4 Major Risks

Wadsworth outlined four high-level categories of risk that will define agentic payments security. Among the most significant:

1. Agent Compromise

Perhaps the most dangerous—and least understood—risk.

Wadsworth said the exploitation potential is vast.

“The number of ways a threat actor can engage with or manipulate an agent is not currently manageable,” she warned. “This is a sophisticated technology that doesn’t exist in payments today.”

2. Prompt Manipulation and Injection

Just as harmful code can be injected into software, malicious prompts can hijack an AI agent.

Wadsworth gave an example: If a bad actor gains access to a member’s OpenAI or online banking chatbot, they could issue prompts that trigger real financial actions.

Elizabeth Wadsworth

“You can basically give code to a chatbot and have it execute on the back end,” she said. “If a credit union doesn’t know how to secure an agent, that introduces serious exposure.”

3. Interface Exploits

Any touchpoint—online banking, mobile apps, embedded banking APIs—could become an entry point for malicious agent manipulation.

4. Model Drift

Over time, AI models can shift or degrade, causing agents to behave unpredictably.

“If an agent starts acting differently than designed, how will a credit union detect it—and who is responsible?” Wadsworth asked. “This is where governance becomes critical.”

Identity Will Be Rewritten: From ‘Who Is the Member?’ to ‘What Is the Agent?’

Traditional authentication has always focused on a simple question: Is this the member?

Agentic payments require new questions:

  • Is this agent authorized?
  • Is the agent who it claims to be?
  • Has the agent been manipulated or compromised?
  • Who bears liability when an agent acts incorrectly?

“Identity becomes one of the biggest issues,” Wadsworth said. “We’ll need agent identity standards and delegated authority mechanisms. These don’t exist today in mainstream practice.”

Visa, Mastercard, and other major networks are working on early frameworks such as Visa’s TAP and Mastercard’s Agent Pay, but Wadsworth stressed, “The liability question is still on the table.”

When Is This Coming? Much Sooner Than Credit Unions Think

Wadsworth believes the early stages are already unfolding.

“It’s coming now,” she said. “We’re probably two to three years from mainstream adoption, but development is happening rapidly. The capability exists—it just hasn’t scaled yet.”

Section: Standard
Word Count: 967
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Agentic-AI-Is-Coming-For-Payments-And-Credit-Unions-Must-Prepare-For-A-Fundamental-Redesign