China's payment sector has taken a significant step toward regulating artificial intelligence-driven transactions with the release of a new self-regulatory framework. On August 24, the Payment & Clearing Association of China issued its "Self-Regulatory Convention on Intelligent Agent Payment Applications," which took effect immediately upon publication. The convention applies to member institutions involved in intelligent agent payment services, including those providing account management, transaction processing, acquiring, and clearing services. The framework places strong emphasis on strengthening security management, mitigating risks, and safeguarding user rights, while balancing the dual imperatives of development and safety.
Industry experts note that attempts to integrate various intelligent agents with payment infrastructure are proliferating, with major internet companies and platform providers driving practical implementations forward. Supporting protocols and ecosystem partnerships are being rapidly established. However, significant gray areas remain within this emerging segment, including unresolved questions around business responsibility allocation and risk handling, as well as a lack of unified standards for data management and consumer protection. The introduction of this self-regulatory document therefore addresses a genuine need, helping to guide market innovation while confining experimentation within safe and controlled boundaries. It aims to reduce potential risks such as money laundering and fund security that could arise from uncoordinated exploration, while also providing market participants with clear operational benchmarks.
Clarifying Responsibility and Ownership
At its core, the convention requires member institutions to follow the principle of "whoever provides the payment service bears the responsibility," assuming primary accountability for users' account security, transaction safety, fund protection, and information security. Regarding intelligent agent management, the convention stipulates that member units should, on the basis of existing "Know Your Customer" (KYC) protocols, explore the establishment of a "Know Your Agent" (KYA) mechanism. This involves identifying and verifying the identities of intelligent agents connected to the payment chain, implementing real-name management for users of agent-based payment services, and clearly defining the correspondence between agents and users through agreements.
On authorization management, the convention requires member institutions to define clear authorization boundaries for agent payment applications, sign responsibility-clarifying agreements with users, strengthen verification of users' payment intentions, and safeguard users' right to revoke authorization, thereby ensuring the security of user funds and information. Furthermore, the convention states that technological applications must always serve user rights protection, financial stability, and social welfare, while guarding against technology misuse, algorithmic discrimination, and excessive consumption inducement. It also emphasizes the need to accommodate differences in digital proficiency across various demographic groups, preserving necessary human services and alternative payment channels to prevent technology from widening the digital divide.
The convention specifically highlights that member institutions should implement more cautious risk alerts, permission controls, and transaction protection measures for vulnerable groups such as the elderly and minors. It also encourages the establishment of dedicated human customer service channels for senior citizens. According to Wang Pengbo, chief analyst at Botong Consulting, the most noteworthy aspects of the convention are twofold. First, it clarifies responsibility for core payment functions, reinforcing the obligations of service providers. Second, it emphasizes establishing identification and management mechanisms for the agents themselves, aligning with the developmental paths of major institutions, which includes setting pre-transaction validation, risk testing, and emergency response requirements for agent-initiated transactions, while detailing arrangements for transaction authorization, risk grading, and user rights protection.
Wang further explained that the convention essentially underscores that all agent payment activities must operate within the existing payment system framework and adhere to fundamental compliance requirements, such as following established payment, anti-money laundering, and consumer protection regulations. It also makes clear that core payment functions like account management, transaction processing, and fund clearing and settlement must be conducted by licensed institutions. These provisions will directly shape the trajectory of future business implementations.
Industry Remains in the Agent-Assisted Payment Phase
Under the convention, intelligent agent payment applications are defined as services where member institutions leverage large language models and other artificial intelligence technologies to enable agents to interact with e-commerce and other digital services, initiating and executing payment instructions based on users' genuine intentions and with their authorization. This concept differs from the broader notion of "AI payment" in meaningful ways. AI payment encompasses all payment forms that embed AI large models into payment processes, including more basic conversational payment methods in addition to agent-based payments. As artificial intelligence technology continues to accelerate, the evolution from shallow AI payment toward agent payment systems featuring pre-authorization, preset rules, and autonomous deduction triggers is an inevitable progression.
It is worth noting that despite technological advances reaching what might be called an "advanced autonomous version," agent payment remains in its infancy from an industrial practice perspective. As the association's leadership has pointed out, considering the trajectory of agent technology development and user authorization depth, agent payment evolution can be categorized into three stages: agent-assisted payment, agent autonomous payment under preset conditions, and agent autonomous payment under generalized conditions. "Agent payment is still in its early development phase, with fully autonomous payment execution scenarios yet to achieve large-scale deployment, and most applications currently limited to assisting in transaction processes," Wang noted.
This means every step forward requires greater caution and compliance. Several industry institutions have acknowledged that the principle of "balancing efficiency with security" must prevail, with AI responsible for process execution while final fund approval authority ultimately rests with humans. The association's leadership stated that member units should adopt an application-oriented, scenario-driven approach, prudently exploring agent-initiated payment transactions. Before implementing applications where agents autonomously initiate payments, including both preset-condition and generalized-condition autonomous payment scenarios, member institutions must report to the Payment & Clearing Association of China, assume primary responsibility for safeguarding user funds, and undergo relevant business evaluations and security testing. They must also conduct thorough assessments of business effectiveness, technical security, and ethical compliance, supported by measures including human services, risk monitoring, public opinion surveillance, emergency response, and rollback mechanisms to mitigate potential risks associated with agent payment applications.