Agentic payments liability: what UK payment law answers, and what it does not

Agentic payments liability - allocating loss under the Payment Services Regulations 2017

In short: agentic payments liability is largely governed by the Payment Services Regulations 2017. Whether the payer consented under regulation 67 determines whether the provider must refund under regulation 76, and regulation 75 puts the burden of proving authentication on the provider. What the regulations do not settle is the scope of a delegation exercised by software. HM Treasury’s consultation on potential changes closes on 6 October 2026.

By Rob Bratby, Managing Partner, Bratby Law. 30+ years in regulated industries, including current Fractional General Counsel to UKPI. Chambers UK Band 2 (Telecommunications), Legal 500 Leading UK Telecoms Partner.

Consumers and businesses are beginning to let AI agents choose when to pay, how much and to whom. That raises questions the Payment Services Regulations 2017 were not drafted to answer, and HM Treasury is consulting on whether the rules need to change. Much of the existing framework applies to an agent-initiated payment, and it settles the immediate position between payer and provider. What it does not settle is the scope of a delegation exercised by software: whether the payer consented to what the agent did, who has to prove it, and where the party that supplied the agent sits in the loss chain.

HM Treasury published the Financial Services AI Adoption Plan and its Modernising Payment Services Regulation consultation on 14 July 2026, and the FCA set out its payments regulatory priorities on 25 March 2026. What those documents say about consent, authentication and liability is set out in agentic payments: what HM Treasury is consulting on. This post sets out how the existing rules apply to an agent-initiated payment, where they are ambiguous, what the Treasury is consulting on, and what follows for firms now.

Agentic payments liability in summary

  • The regulation 76 refund duty arises where the transaction was “not authorised in accordance with regulation 67”. Sources: regulation 76 and regulation 67.
  • Where a payer denies authorising a transaction, the provider must prove it was authenticated. The recorded use of an instrument is not in itself necessarily sufficient. Source: regulation 75.
  • Payer liability for an unauthorised transaction is capped at £35 for a lost, stolen or misappropriated instrument, and is unlimited only on fraud or an intentional or grossly negligent breach of regulation 72. Source: regulation 77.
  • A payer that is not a consumer, micro-enterprise or charity may agree with its provider to disapply regulations 75 and 77. Those protections cannot be contracted away for the customers the regulation protects. Source: regulation 63(5).
  • An account servicing provider that refunds may require compensation from a liable payment initiation service provider, and a payee side that fails to accept strong customer authentication must compensate the payer’s provider. Sources: regulation 76(5) and regulation 77(6).
  • Where an agent-initiated payment is authorised, the mandatory reimbursement regime for authorised push payment fraud may apply instead of regulations 76 and 77. It covers Faster Payments and CHAPS, protects individuals, micro-enterprises and charities, caps reimbursement at £85,000 per claim and splits the cost equally between the sending and receiving providers. Sources: Specific Direction 20 and the PSR reimbursement protections.
  • Redress under regulation 76 is conditional on the payer notifying the provider without undue delay and within 13 months of the debit, subject to the exception in regulation 74(2). Source: regulation 74.
  • HM Treasury’s Modernising Payment Services Regulation consultation closes on 6 October 2026, and asks whether the consent, authentication and liability provisions need updating for agentic payments. Source: HM Treasury.
IssuePosition under the PSRs 2017What the contract can do
Was the payment authorised?Regulation 67 requires the payer’s consent to a transaction, or to a series, in the agreed form and procedure. An agent acting within a defined delegation may be authorised; an instruction outside its scope may not be.The delegation can be defined tightly in the terms. The contract cannot make an out-of-scope instruction “authorised” where the payer never consented to it.
Who proves it?Regulation 75 puts the burden on the provider to prove authentication. A payment initiation service provider carries it within its own sphere. Recorded use of the instrument is not in itself necessarily sufficient.The evidential burden cannot be shifted onto a consumer, micro-enterprise or charity by contract.
Who bears the loss?Regulations 76 and 77 allocate loss between provider and payer. The payer’s exposure for a lost, stolen or misappropriated instrument is capped at £35, and is unlimited only on fraud or an intentional or grossly negligent breach of the security obligations.Regulation 63(5) lets a payer that is not a consumer, micro-enterprise or charity agree to disapply regulations 75 and 77. It does not allow the parties to disapply the payer’s regulation 76 refund right.
Recourse among firmsRegulations 76(5) and 77(6) provide statutory compensation routes between the firms in the chain.Contract, agency law and any applicable scheme rules govern recourse beyond those statutory routes.

Authorisation under regulation 67

Regulation 67 of the Payment Services Regulations 2017 governs payment authorisation. A payment is authorised only where the payer consented to that transaction, or to a series of which it forms part, in the form and procedure agreed with its provider. An agentic payment may be authorised where the agreed consent mechanism and the facts establish consent to the individual payment, or to a defined series. Whether the limits a customer supplies to an agent amount to that consent is fact-specific and depends on the contract; configured parameters are not the same thing as the payer’s legal consent. Difficulty arises where the instruction falls outside the agreed consent, where the parameters were ambiguous, or where the agent was manipulated.

The refund duty in regulation 76 applies where the transaction was not authorised in accordance with regulation 67. How the failure is characterised therefore determines the outcome. Where the customer set the limits too loosely, the payment will usually fall inside the consent, because the agent did what the delegation permitted. Where an outside party subverts the agent by prompt injection, the resulting payment may be unauthorised, but that depends on how the payer gave consent, the agreed authentication and instruction process, whether the agent had authority to generate the instruction, the scope of the mandate and whether the compromised instruction fell within the configured permissions. A model error, where the agent misreads its own instruction, falls between the two and depends on how the delegation was framed.

What Philipp v Barclays decides, and what it does not

The most recent Supreme Court authority on when a payment instruction binds a bank is Philipp v Barclays Bank UK plc [2023] UKSC 25, decided on 12 July 2023. In 2018 Mrs Fiona Philipp was deceived by fraudsters into instructing Barclays in person to transfer £700,000 to accounts in the United Arab Emirates, in the belief that she was assisting a Bank of England and FCA investigation. She argued that the bank owed her a duty not to execute those instructions where it had reasonable grounds to suspect she was being defrauded.

That argument rested on the Quincecare duty, named after Barclays Bank plc v Quincecare Ltd [1992] 4 All ER 363. Steyn J held that a bank owes its customer an implied duty to use reasonable skill and care in executing instructions, and that where the bank has reasonable grounds for believing a payment instruction given by an agent of the customer is an attempt to misappropriate the customer’s funds, it must refrain from executing the instruction for so long as it is put on inquiry. The duty is not an obligation to refuse every unusual instruction. It is an obligation to pause and make reasonable inquiries where there are grounds to suspect a fraud on the customer, and reasonable grounds for suspicion are enough without certainty. In its original form the duty was said to arise whether or not the agent had actual authority, because the question was fraud rather than authority.

Lord Leggatt, giving the judgment of a unanimous court in Philipp, rejected the claim and reversed the Court of Appeal. The Supreme Court held that where a customer personally gives a clear and valid instruction, the bank’s duty is to execute it promptly, and the bank is not required, absent an express term, to second-guess the customer’s decision. There is no conflict between that duty and the duty to exercise reasonable skill and care, because the care duty operates only where the mandate leaves room for interpretation, verification or choice. The court re-explained the Quincecare duty through agency principles: an agent acting dishonestly against the principal lacks actual authority, and may lack apparent authority where the bank is put on inquiry and does not check. That is why the duty arises in agent-fraud cases and not where the customer gave the instruction herself. One part of the claim survived, on whether the bank failed to take prompt steps to recall the funds once the fraud was reported, and was remitted for trial.

Philipp treats authority as the organising question. The payer’s state of mind does not determine whether a payment was authorised, so an instruction procured by deception can still be an authorised one. Applied to an agent, the question is whether the instruction fell within the authority the payer conferred. The court’s agency reasoning may inform that analysis by analogy, though it does not decide it. An autonomous AI agent does not fit comfortably into the law of agency, which contemplates a person capable of holding authority, and the point has not been tested. What the reasoning does supply is the shape of the enquiry: whether the instruction was authorised, and whether the provider was put on inquiry, are the questions regulations 67 and 75 ask. Philipp is a common-law decision about the Quincecare duty in the banker-customer relationship. It did not decide authorisation under regulation 67 for an agent-initiated payment, and it does not determine eligibility under the reimbursement arrangements. The court treated loss allocation in authorised push payment fraud as a matter for legislation and regulation rather than for expansion of private-law duties, which is where the Treasury consultation now sits.

Where the reimbursement regime takes over

Where a payment is authorised for the purposes of the PSRs, regulations 76 and 77 will generally not supply the unauthorised-transaction remedy, and the question becomes whether the mandatory reimbursement regime applies instead. That regime rests on section 103A of the Financial Services (Banking Reform) Act 2013, inserted by section 72 of the Financial Services and Markets Act 2023, and is implemented through the Payment Systems Regulator’s Specific Direction 20 for Faster Payments and Specific Direction 21 for CHAPS, each given under section 56. It applies to payments made on or after 7 October 2024, covers transfers between UK accounts over Faster Payments and CHAPS, and protects individuals, micro-enterprises and charities. Card, cash and cheque payments have their own protections and fall outside it, as do credit unions, municipal banks and national savings banks. The background is set out in APP fraud reimbursement and cross-sector liability.

The regime allocates loss on a different basis from the PSRs. The sending provider reimburses the customer where the claim qualifies, and the cost is then apportioned equally between the sending provider and the provider holding the fraudster’s account, with the dispute mechanics set out in the Faster Payments Reimbursement Rules issued by Pay.UK. Reimbursement is due within five business days of the claim, although a firm may stop the clock to gather information and must reach an outcome within 35 business days. A firm may apply an excess of up to £100, but not to a vulnerable consumer. Reimbursement is capped at £85,000 per claim, a figure subject to periodic review, and a customer whose loss exceeds that figure may take the balance to the Financial Ombudsman Service. The consumer standard of caution operates as an exception rather than as a positive test of eligibility: reimbursement is not required where the sending provider can demonstrate that the consumer, through gross negligence, failed to meet one of four listed standards. The exception does not apply where the victim was a vulnerable consumer and that had a material impact on their ability to protect themselves. PS25/5 consolidates the policy framework.

The definition is the difficulty. Under the Faster Payments Reimbursement Rules an APP scam is where a person uses a fraudulent or dishonest act to manipulate, deceive or persuade a consumer into transferring funds, so that the recipient is not the one the consumer intended or the payment is not for the intended purpose. The deception has to operate on the consumer. Where a fraudster instead corrupts the instructions given to the software, and the customer is neither deceived nor persuaded of anything, the payment may fall outside the definition rather than merely raise an awkward question about the standard of caution. A payment of that kind may be authorised for the purposes of the PSRs, and so outside regulations 76 and 77, while also falling outside the reimbursement regime. That is a gap, and it is the clearest example of what agentic payments expose.

The class the reimbursement regime protects is also the class regulation 63(5) protects, so a business payer that is neither a micro-enterprise nor a charity has neither the protected-customer floor in the PSRs nor the reimbursement regime, and is left with whatever its contract provides. Neither regime allocates loss to the supplier of the agent. The PSRs allocate between the payer, the provider and, through regulations 76(5) and 77(6), other firms in the payment chain, and the reimbursement regime allocates between the sending and receiving providers. Neither creates a liability rule that bites on a person merely because it supplied the software, although a supplier may itself hold a regulated role on particular facts. The Financial Services and Markets Bill proposes to transfer the Payment Systems Regulator’s functions to the FCA, and the FCA says it is consolidating those functions ahead of legislation where it can. That is a proposed institutional change and it would not alter the substantive obligations.

Who has to prove what

Regulation 75 allocates the burden of proving authentication to the provider. Where a payer denies authorising a transaction, the provider must prove that the transaction was authenticated, accurately recorded and unaffected by any technical breakdown. The recorded use of a payment instrument is not in itself necessarily sufficient to prove either that the payer authorised the payment or that the payer acted with gross negligence. A provider that alleges fraud or an intentional or grossly negligent breach of regulation 72 must produce supporting evidence. Where the transaction was initiated through a payment initiation service provider, that provider carries the same burden within its own sphere under regulation 75(2).

Authentication and authorisation are not the same question, and the distinction matters for an agent-initiated payment. Regulation 75 does not allocate the separate question of whether the instruction fell within the authority the payer conferred. That depends on regulation 67 consent and the agreed form and procedure. A payer is entitled to redress only if it notifies the provider without undue delay, and in any event within 13 months of the debit, under regulation 74, subject to the exception in regulation 74(2). Within that period the outcome depends on the record the provider can produce after the event.

What a framework contract can and cannot reallocate

Regulation 63(5) is the express mechanism for reallocation. Where the payer is not a consumer, a micro-enterprise or a charity, the payer and the provider may agree that regulations 75 and 77, and the withdrawal-of-consent provisions in regulation 67(3) and (4), do not apply. A business-to-business agentic arrangement can therefore move the evidential burden and the liability split by contract. Regulation 76 is not in that list, so the provider’s duty to refund an unauthorised transaction survives even a business agreement. Other contractual recovery rights may affect the ultimate economic allocation, but they cannot be assumed to displace the statutory refund obligation. For a consumer, a micro-enterprise or a charity that freedom does not exist, so a contract cannot displace the statutory refund right where the payment was unauthorised. That is narrower than a rule that every term allocating agent-error loss is ineffective: the agreed form and procedure for consent under regulation 67, the terms of the agent mandate and any recourse against the agent’s supplier all remain live. Where strong customer authentication was required but the provider did not apply it, regulation 77(4)(c) removes the payer’s liability entirely, short of fraud.

The framework contract also defines the operational controls. Regulation 71 supports agreed spending limits where a specific payment instrument is used to give consent, a right to stop use of that instrument on reasonable security or fraud grounds, and an account servicing provider’s right to deny a payment initiation or account information service provider access to an account for reasonably justified and evidenced reasons. An approved-payee list or an agent-specific stop control is a matter of product design and contract rather than a control the regulation itself provides. Recourse beyond the customer contract is governed by the statutory routes in regulations 76(5) and 77(6), by agency law, and by any applicable scheme rules. For a product within its scope, the FCA’s Consumer Duty requires the firm to act to deliver good outcomes for retail customers and to avoid foreseeable harm. That bears on the design, testing, monitoring and intervention controls for an agentic payment product, but it does not prescribe a spending limit or a mandatory intervention trigger. Termination of the framework contract is dealt with in framework contract termination under the PSRs 2017. Our payments product, safeguarding and scheme governance page sets out where these questions are worked through.

The Treasury has left the allocation open

HM Treasury has not reached a conclusion. In its Modernising Payment Services Regulation consultation it says the regulations were written before AI and may not fully accommodate agentic payments, and question 15 asks whether the consent, authentication and unauthorised-transaction liability provisions need updating. That is an open question rather than a finding that the current rules have ceased to apply. In its payments regulatory priorities of 25 March 2026 the FCA said it would work with the Treasury to modernise the regulation of payment services and electronic money, and that this would include considering whether change or development of regulation is needed to support agentic AI payments. It is not treating the existing framework as settled for this purpose. On the supervisory side it offers firms the Supercharged Sandbox and AI Live Testing, which sits alongside the FCA AI approach and the AI Lab. The AI Adoption Plan proposes work on a Know Your Agent standard as part of its agentic payments recommendation. Identity and governance standards of that kind can supply evidence of who the agent is and what authority it holds, but they do not answer either the authorisation question under regulation 67 or the loss-allocation question under regulations 76 and 77.

Perspective

Regulation 63(5) and regulation 75 between them fix the immediate allocation of loss as between payer and provider. This is the limit of what the regulations currently achieve. They supply no dependable test for authority exercised by software, and neither they nor the reimbursement regime allocate anything to the party that designed or supplied the agent. The constraint is evidential: a provider has to be able to show, after the event, what the payer delegated, and that depends on how well the consent, the limits and the authentication were recorded at the outset. I would watch the consultation for whether the Treasury adopts a defined test for when an agent-initiated instruction counts as authorised. That would do more for the pricing of these products than a Know Your Agent standard.

Frequently asked questions

Does a framework contract decide who pays when an AI agent gets it wrong?

Only in part, and only for some customers. Under regulation 63(5) of the Payment Services Regulations 2017, a payer that is not a consumer, micro-enterprise or charity may agree to disapply the unauthorised-transaction liability and evidence provisions. For consumers, micro-enterprises and charities those protections are mandatory, so a contract cannot displace the statutory refund right where the payment was unauthorised. Other terms, including the agreed consent procedure and any recourse against the agent’s supplier, remain effective.

Is an agent-initiated payment authorised under the PSRs 2017?

It depends on the scope of the consent. Regulation 67 allows a payer to consent to a transaction or to a series, so an agent acting within a defined delegation can be authorised. An instruction outside that delegation, or one produced by manipulation of the agent, may be unauthorised, which brings the refund duty in regulation 76 into play.

Does the APP reimbursement regime cover an agent-initiated payment?

It cannot be assumed. An APP scam is defined as a fraudulent or dishonest act that manipulates, deceives or persuades the consumer. Where the fraudster corrupts the instructions given to the software and the customer is not deceived, the payment may fall outside the definition altogether, leaving neither the unauthorised-transaction remedy nor the reimbursement regime available.

What is the Quincecare duty?

The Quincecare duty comes from Barclays Bank plc v Quincecare Ltd [1992] 4 All ER 363. A bank must refrain from executing a payment instruction given by an agent of its customer for so long as it has reasonable grounds to believe the instruction is an attempt to misappropriate the customer’s funds. It requires the bank to pause and make reasonable inquiries rather than to refuse every unusual instruction. Following Philipp v Barclays it does not apply to an instruction the customer gave personally.

Does Philipp v Barclays apply to agentic payments?

Not directly. Philipp v Barclays Bank UK plc [2023] UKSC 25 concerns the Quincecare duty in the banker-customer relationship, and holds that a bank must execute a clear and valid instruction given by the customer personally. Its reasoning that authority, rather than the payer’s state of mind, is the organising question may inform the analysis of agent-initiated payments by analogy, but the case did not decide authorisation under regulation 67.

Who has to prove the payment was authorised?

The provider. Under regulation 75, where a payer denies authorising a transaction it is for the payment service provider to prove the transaction was authenticated and correctly recorded, and the recorded use of an instrument is not in itself necessarily sufficient. A payment initiation service provider carries the same burden within its own sphere.

When does the Modernising Payment Services Regulation consultation close?

HM Treasury’s consultation closes on 6 October 2026. Question 15 asks how payment services regulation should adapt for agentic payments, including whether the consent, authentication and unauthorised-transaction liability provisions need updating.

Law stated as at 22 July 2026. For advice on agent-initiated payment products, liability allocation or scheme arrangements, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts