AI, Agentic Payments, and Legal Liability: What Fintech Needs to Know
Live from Baltic Fintech Day, the latest episode of Fintech Daydreaming brought a sharp perspective to one of the industry’s most debated topics — AI in payments — courtesy of Sophia, Legal Counsel at Expate, an acquiring and payment processing company. The conversation moved fast, covering the EU AI Act, Anti-Money Laundering (AML) obligations, autonomous AI agents, and the thorny question of who is legally responsible when an AI makes the wrong call.
TL;DR / Quick Takeaways
The EU AI Act is already a live compliance concern — parts of it apply from 2 August, specifically targeting high-risk AI systems, which are already deployed across payments, credit, and investment.
AI in payments today functions as an assistant, not an autonomous executor — no market participant is using AI to fully and independently execute payments without human oversight.
Agentic payments face two hard blockers: regulatory gaps and the absence of tested technical solutions that cover both payer identification and institutional verification requirements.
Legal liability for AI-driven payment errors sits with the financial institution that authorised the payment — not the user, not the merchant, and not the agent itself.
What Is the EU AI Act and Why Does It Matter for Payments?
The EU AI Act is a regulation that classifies AI systems by risk level and imposes compliance obligations accordingly. For fintech companies, the critical date is 2 August, when provisions covering high-risk AI systems come into force.
High-risk AI systems in financial services include those used in:
Payments processing and authorisation
Credit assessment and lending decisions
Investment recommendations and portfolio management
Many of these systems are already deployed across the industry. For legal and compliance teams at acquiring companies and payment institutions, the Act is not a future concern — it is a present one. The task is to map existing AI deployments against the regulation’s requirements and ensure each system meets the applicable standards before enforcement begins.
How Is AI Actually Being Used in Payments Right Now?
The honest answer: carefully, and with human oversight firmly in place.
AI is not executing payments autonomously. No financial institution is running a fully autonomous AI pipeline where a system independently initiates, authorises, and settles transactions without a human in the loop.
What AI is doing in payments:
Assisting with AML screening — identifying suspicious patterns faster and more consistently than manual review
Supporting compliance teams — helping interpret regulatory requirements and flag potential breaches
Improving operational efficiency — reducing the manual burden on legal and compliance functions
AML, in particular, is one of the most important areas for any fintech or payment institution. Doing it efficiently, accurately, and in compliance with applicable regulation is not optional — it is foundational. AI tools that assist with this without replacing human judgement represent the current state of the art.
What Are Agentic Payments and Why Aren’t They Here Yet?
Agentic payments refer to AI agents executing financial transactions on behalf of a user — autonomously, without approval for each individual action. Think of an AI agent that receives an instruction («buy groceries for the week») and handles the entire transaction flow independently.
Companies like Visa and Mastercard are actively discussing this model. In practice, it currently operates at two levels:
Level 1 — Human in the loop: The agent proposes each payment; the user approves each one individually before execution.
Level 2 — Bounded autonomy: The user sets limits and guardrails; the agent executes within those parameters without seeking approval for each transaction.
Two barriers are blocking full autonomy:
Regulatory gap: Payment authorisation currently requires strict identification — including two-factor authentication (2FA). Replacing a fingerprint with a voice command, for example, raises immediate questions about how that authorisation is interpreted and who bears responsibility if it fails. Regulation has not yet caught up with what agentic execution would require.
Technical gap: There is no complete, market-tested solution that satisfies both the payer identification requirements and the financial institution’s verification obligations simultaneously. Until that solution exists and has been validated, full autonomy is not viable.
Who Is Legally Responsible When an AI Agent Gets It Wrong?
This is where legal frameworks meet real-world ambiguity. Consider a scenario: a user tells their AI agent to buy 12 eggs. The agent buys 12 chickens instead. The user wants their money back. Who is liable?
Not the user — they gave a clear instruction.
Not the merchant — the agent placed the order for chickens.
Not the agent — its error-prone nature is often disclosed in terms and conditions.
The liability sits with the financial institution that authorised the payment.
If a bank or payment institution permits authorisation by voice — processed by an AI — it takes on responsibility for how that voice instruction is interpreted and acted upon. The authorising entity owns the outcome. This is consistent with existing payment law, which places strong obligations on institutions that authorise transactions to verify that authorisation is valid, informed, and traceable.
This has direct implications for acquiring companies and payment processors considering how to support agentic payment flows. Enabling autonomous AI-driven payments without regulatory clarity and a fully tested technical framework is not just a product risk — it is a legal one.
What Does a Fintech Legal Counsel Actually Do Day to Day?
In a company operating across acquiring and payment processing, a legal counsel’s scope covers both sides of the function:
Commercial legal: Contracts, partnerships, agreements with counterparties and technology providers
Regulatory compliance: Ensuring products and operations remain within applicable regulation — including AML/KYC obligations, licensing requirements, and emerging frameworks like the AI Act
Neither side operates in isolation. Staying compliant is what keeps the business running. For a company in the payments space, the two functions are deeply intertwined — a contract with a new partner triggers compliance checks; a new product feature triggers a regulatory review.
FAQ
What is the EU AI Act and when does it apply to fintech?
The EU AI Act is a regulation classifying AI systems by risk and setting compliance requirements for each category. For fintech, the most relevant provisions — those covering high-risk AI systems in payments, credit, and investment — apply from 2 August. Companies with AI already deployed in these areas need to be compliant now, not at a future date.
Can AI authorise payments autonomously today?
No. Current regulation — including two-factor authentication requirements — makes fully autonomous payment authorisation without human involvement non-compliant in most European jurisdictions. AI supports payment processes; it does not independently execute them.
What guardrails would agentic payments need to be viable?
Two things need to be in place: regulatory frameworks that define what constitutes valid authorisation for AI-initiated payments, and technically complete solutions that satisfy both payer identification and institutional verification requirements. Neither currently exists in a fully tested, market-ready form.
If an AI agent makes a payment error, can a user get their money back?
Most likely yes — but the liability mechanism matters. The financial institution that authorised the payment bears responsibility for that authorisation. If the institution permitted a non-standard authorisation method (such as voice) and the AI misinterpreted the instruction, the institution is exposed. Users retain strong protections under EU payment law.
Is AML compliance relevant for AI-assisted payment systems?
Absolutely. AML is one of the most critical compliance areas for any financial institution. AI tools are increasingly used to assist with AML screening and monitoring — but they operate under human oversight. The obligation to comply remains with the institution, regardless of how much of the process is automated.
AI, Agentic Payments and Legal Liability in Fintech

