October 9, 2026 · 6 min read · Aizhan Azhybaeva

Visa Agentic Ready in the UAE: What Issuers Must Build Before Go-Live

Visa Agentic Ready launched in the UAE in May 2026 with nine participants. What issuers need to build first: agent tokens, authentication, risk rules and disputes.

Visa Agentic Ready in the UAE: What Issuers Must Build Before Go-Live

Visa Agentic Ready launched in the UAE on 20 May 2026, and it puts issuers at the centre of agentic commerce. Nine participants signed up: ADCB, ADIB, Al Ansari Exchange, Emirates Islamic, Emirates NBD, Mashreq, Tabby, Wio and Ziina. Before agent-initiated payments go live, each issuer needs agent token lifecycle, authentication at token setup, agent-aware risk rules, customer controls and a dispute evidence trail.

That’s the short answer. The rest of this post breaks down what each piece involves, what Visa has already shown in Europe, and where the open questions still are. If you’re at one of the nine, or at an issuer hoping to join a later wave, this is the build list.

What is Visa Agentic Ready and who is in the UAE cohort?

Visa describes Agentic Ready as a programme “designed to help financial institutions prepare for the next phase of commerce”, where AI agents help consumers find, choose and complete purchases. It launched first in Europe on 17 March 2026, building on Visa Intelligent Commerce, and then rolled out to other regions. The UAE launch on 20 May was part of the wider CEMEA rollout.

In its first phase, the programme lets issuers test and validate agent-initiated transactions in a controlled, production-grade environment. Visa’s UAE release doesn’t publish a go-live timetable, so treat any specific date you hear as unconfirmed.

The UAE participants, as named by Visa:

ParticipantType (our description)
Abu Dhabi Commercial Bank (ADCB)Conventional bank
Abu Dhabi Islamic Bank (ADIB)Islamic bank
Al Ansari ExchangeExchange house
Emirates IslamicIslamic bank
Emirates NBDConventional bank
MashreqConventional bank
TabbyBuy now, pay later
WioDigital bank
ZiinaPayments app

That spread matters. A BNPL provider, an exchange house and a large retail bank will have very different token platforms, fraud stacks and app experiences, so “readiness” is not one template.

The UAE already has a reference point. In December 2025, Visa and Aldar announced what they called the first live implementation of Visa Intelligent Commerce in the region: a customer paid real estate service charges in the Live Aldar app, with an AI agent confirming details and completing the payment. The card was an Emirates NBD-issued Darna Visa credit card, tokenized through Visa’s Token Management Service.

What did Visa show in Europe that UAE issuers should copy?

Europe is a few months ahead, and Visa has been specific about how it works there. On 2 July 2026, Visa announced live agent transactions with dozens of European issuers, moving beyond controlled storefronts. Two details stand out:

  • Issuers participate through Visa Payment Passkeys. Visa says passkeys give a trusted, compliant way to authenticate transactions initiated by AI agents, and that this supports European Strong Customer Authentication requirements.
  • Merchants participate through the Trusted Agent Protocol (TAP) and Agent Directory. TAP gives merchants a consistent signal of agent identity so they can tell verified agents from ordinary bot traffic.

Visa’s consumer explainer adds the token angle: when an AI agent sets up a new payment token on your behalf, Visa Payment Passkeys can authenticate you at that moment, tying the token to your consent, device and identity.

UAE issuers have their own CBUAE authentication and consumer protection expectations, so don’t assume the European design maps one to one. But the architecture (passkey at token setup, token bound to an agent, merchant-side agent recognition) is the clearest template available.

What does an issuer actually have to build?

Here’s the build list we’d work through, in roughly the order dependencies force on you.

CapabilityWhy it mattersWhat “ready” looks like
Agent token lifecycleAgents should hold tokens, never PANsProvision, suspend and delete tokens per agent; see which agent holds which token
Authentication at token setupThis is where cardholder consent is provenPasskey or equivalent strong authentication when an agent token is created; step-up for unusual purchases
Agent-aware risk rulesAgent traffic looks different from human trafficAuthorization rules and fraud models that recognise agent-initiated transactions and apply their own thresholds
Customer controls in the appCustomers need to see and stop agentsPer-agent view, spend limits, merchant category limits, one-tap revoke
Consent and evidence recordDisputes will hinge on what was authorisedStore what the customer allowed, which agent acted, and what it executed, linked to the transaction
Ops and supportCall centres will get “my AI bought this” callsScripts, dispute triage paths and fraud-ops playbooks for agent transactions

None of this is exotic on its own. Most issuers already run tokenization for wallets and card-on-file, and fraud teams already tune rules by channel. The work is in connecting them: the token knows which agent it belongs to, the risk engine knows the token is an agent token, and the app shows the customer the same picture.

Who is liable when an agent’s purchase is disputed?

This is the part to be honest about. We have not found a published Visa or Mastercard rule that specifically assigns chargeback liability for agent-initiated purchases, and industry commentary in 2026 still describes it as an open coordination problem. Existing dispute processes weren’t built to tell a human buyer from an agent.

That doesn’t mean you wait. Whatever rules emerge, they’ll need the same evidence: what the cardholder authorised, what limits applied, what the agent actually did, and when the customer was told. Issuers who capture that cleanly from day one will be in a better position on both sides of a dispute, as issuer defending a customer and as the party the acquirer pushes back on.

How do agent protocols fit around the issuer?

Issuers mostly sit behind the network, but your teams will hear protocol names constantly. Quick map:

  • Card network rails (Visa Intelligent Commerce, Mastercard Agent Pay) are where your tokens and authentication live.
  • Checkout and authorization protocols such as AP2, UCP and OpenAI’s commerce protocol carry the agent’s mandate and checkout flow between agent and merchant.
  • Settlement protocols like x402 move value for machine-to-machine payments, mostly outside card rails today.

Our agentic payment protocols comparison explains how the layers stack. If your issuer also acquires or runs a merchant checkout, our sister practice covers the card-data angle in PCI DSS scope for agentic commerce.

How should an issuer sequence the work?

  1. Inventory what you already have. Token platform, authentication methods, fraud rules by channel, dispute tooling. Most of the build reuses these.
  2. Define the agent token model. One token per agent per card? What metadata do you keep? How does revocation work?
  3. Settle authentication at token setup. Decide your passkey or step-up approach and check it against your CBUAE obligations.
  4. Write agent-specific risk rules. Start conservative: lower limits, tighter merchant categories, step-up on anomalies.
  5. Ship customer controls. Visibility and revoke first, fine-grained limits second.
  6. Build the evidence trail and dispute playbook. Test it with mock disputes before real ones arrive.
  7. Run controlled test transactions inside the programme, then expand.

Book an issuer agentic readiness sprint

If you’re one of the nine UAE participants, or an issuer planning to join a later wave, we run a fixed-scope issuer agentic readiness sprint. We review your token platform, authentication and fraud stack against the agentic flow, design the agent token model and risk rules, and specify the consent and evidence record your dispute team will need. You leave with a build plan your product, fraud and engineering teams can execute, mapped to UAE regulatory expectations.

See our agentic payments consulting service or get in touch to scope a sprint.

Frequently Asked Questions

What is Visa Agentic Ready?

Visa Agentic Ready is a global Visa programme that prepares card issuers for payments initiated by AI agents on a cardholder's behalf. It launched first in Europe in March 2026 and in the UAE on 20 May 2026. The first phase lets issuers test and validate agent-initiated transactions in a controlled, production-grade environment before wider rollout.

Which UAE banks and fintechs are in Visa Agentic Ready?

Visa's UAE announcement named nine participants: ADCB, ADIB, Al Ansari Exchange, Emirates Islamic, Emirates NBD, Mashreq, Tabby, Wio and Ziina. The mix covers conventional and Islamic banks, a digital bank, an exchange house, a buy-now-pay-later provider and a payments app, so readiness work looks different for each of them.

What does an issuer need to build for agentic payments?

At minimum: token provisioning and lifecycle for agent credentials, strong cardholder authentication when an agent token is created, authorization risk rules that recognise agent traffic, in-app controls so customers can see and revoke agents, and a consent and evidence record that supports disputes. Most of this extends existing tokenization and fraud stacks rather than replacing them.

Who is liable when an AI agent's card purchase is disputed?

There is no settled answer yet. We have not found a published Visa or Mastercard rule that assigns chargeback liability for agent-initiated purchases specifically, and industry commentary still treats it as open. Issuers should capture what the cardholder authorised, which agent acted and what it executed, so they can defend either side of a dispute.

Does Agentic Ready replace Visa Intelligent Commerce?

No. Visa describes Agentic Ready as building on Visa Intelligent Commerce, its suite of APIs and tools for agent commerce. In the UAE, the first live Visa Intelligent Commerce implementation in the region was announced with Aldar in December 2025, using an Emirates NBD-issued card and Visa's Token Management Service.

Get Started for Free

Schedule a free consultation with our payment infrastructure team. 30-minute call, actionable results in days.

Every engagement is scoped by our principal architect, Adrian Vale: 20+ years in production engineering, 40+ professional certifications. Meet Adrian

Talk to an Expert