Articles

Peach Payments CISO: Agentic Commerce Needs Controls to Match $5 Trillion Opportunity

Payment security has spent two decades treating automated traffic as a threat to be filtered out. Agentic commerce is reversing that logic. Visa has enrolled local banks in its Agentic Ready programme, Mastercard has launched Agent Pay, and OpenAI has integrated Instant Checkout with Stripe. In March 2026, Mastercard and Google open-sourced a protocol called Verifiable Intent. Behind each launch sits the same idea: an AI agent transacts on a customer’s behalf, and the payment completes without further human input.

Peach Payments CISO: Agentic Commerce Needs Controls to Match $5 Trillion Opportunity

Judy Winn, CISO at Peach Payments, African payment service provider (PSP)

McKinsey estimates AI agents could handle between $3 trillion and $5 trillion in global agentic retail commerce by 2030. Judy Winn, CISO at Peach Payments, argues that pulling humans out of the transaction loop opens a new attack surface. Without a person present to authorise a purchase, confirming that an autonomous agent is still acting within a customer’s actual intent becomes its own security discipline.

A reversed threat model

Cyber defences have long rested on a single premise: human activity is legitimate, and automated activity is suspect. CAPTCHAs, rate limits, and behavioural biometrics were built around that premise, to block bots. Winn’s view is that agentic commerce inverts it, since the most valuable traffic now arrives as automation. In her framing, the old question, whether a user is human, no longer applies. The relevant question is whether an agent is authorised and operating within its assigned scope.

That leaves security teams running two regimes at once. Malicious automation has not gone away, and card-testing and scraping remain routine. Systems now need to block hostile bots while clearing legitimate agents, and do so in milliseconds. Winn also points to a subtler risk: because AI agents reason and adapt, they can be manipulated. An agent compromised through prompt injection does not look like a bad bot to a fraud system. It looks like a trusted actor, carrying out instructions an attacker planted.

Three open questions

Winn raises three problems she sees as unresolved. The first is agent identity. Cryptographic frameworks such as Google’s Agent Payments Protocol (AP2) Mandates and Mastercard’s Verifiable Intent are steps toward proving who or what is acting, but the competing protocols are still converging toward common standards, a process now underway inside the FIDO Alliance’s 2026 working groups.

The second is what happens after an agent is compromised. Prompt injection is her example: hidden text embedded in a product listing could alter an agent’s instructions, inflating an order quantity or redirecting a shipment. Guidance on defending against this exists through the Open Worldwide Application Security Project (OWASP), but Winn notes that few of these defences have been tested inside live payment flows.

The third is speed. Human-driven fraud is constrained by human speed, but agents can run thousands of attempts in the time it takes an analyst to refresh a dashboard. That makes older fraud indicators, such as typing patterns or session timing, largely obsolete against machine-speed abuse.

“Human fraud is limited by human speed. Agents operate in milliseconds, executing thousands of attempts before an analyst can refresh a dashboard. Legacy fraud signatures like typing cadence or session velocity are useless here.”

Judy Winn, CISO at Peach Payments

Recommendations for security teams

Winn lays out four steps for companies adopting agentic payment infrastructure. Security should be involved in product design before the architecture is finalised, since adding agent identity controls after launch is far harder. Intent needs to be treated as a security control in its own right, with explicit rules for what an agent can do, how that authority is verified, and how it gets revoked. Fraud models need retraining to separate machine-speed abuse from legitimate automated purchases. And AI governance frameworks already in place should be extended to cover third-party agents interacting with a company’s systems, not just internal AI tools.

Winn’s central point is that in fragmented markets such as African payments, intelligent orchestration delivers immense value, but weak controls will do profound damage. She positions agent identity and machine-speed fraud detection as design requirements rather than later additions, and describes the overlap between payment security and AI governance as one of the more pressing open problems facing the industry.

Pay Space

Pay Space

2292 Posts

https://payspacemagazine.com/author/payspacemagazineauthor/

Our editorial team delivers daily news and insights on the global payment industry, covering fintech innovations, worldwide payment methods, and modern payment options.