UPI processes more real-time payments than any system on earth, and every one of those payments currently has the same safety feature built in: a person, looking at a screen, deciding to authorise it. The National Payments Corporation of India has now built the infrastructure to remove that step. Reuters reported in early September that NPCI has developed a framework called the Unified Agent Protocol, which lets registered AI agents initiate and execute UPI payments without per-transaction human approval.
The framework isn't being built from nothing. It extends two things NPCI already runs — UPI Circle, which lets one person delegate payment authority to another (a parent funding a child's account, for instance), and Reserve Pay, an existing mandate-based payment tool. The Unified Agent Protocol takes that same delegation logic and extends it from a person you trust to software acting on your behalf.
The one number that's public
Reporting on the framework puts a specific ceiling on what a fully delegated agent can do: ₹15,000 a month. Below that cap, an agent can apparently transact without stopping to ask. It's a strikingly small number for a country whose digital payments infrastructure is being pitched internationally as a model for financial inclusion — enough to cover recurring low-value purchases like groceries or subscriptions, not enough to make a real dent if something goes wrong. That looks less like an oversight than a deliberate first move: cap the blast radius tightly, see what actually happens when agents start spending unsupervised, and widen the number later once the failure modes are understood.
What's missing from the public reporting is almost everything else. Who counts as a "registered" agent? What happens above ₹15,000 — does the agent simply stop, or does it fall back to requesting approval? Can a user set a lower personal cap, or is ₹15,000 the number regardless of what an individual would prefer? None of that has been disclosed, which means the framework as reported is a ceiling with no floor yet built underneath it.
The registry is the part that actually matters
The more consequential piece of this — and the one still under construction — is the AI-agent registry NPCI is reportedly building alongside the protocol. UPI's entire trust model depends on knowing who's on the other end of a payment: a verified merchant, a KYC'd individual, a bank. An unsupervised AI agent breaks that model unless something new stands in for identity verification, and a registry is NPCI's answer — a vetting layer that decides which companies and which agents are allowed to initiate payments at all.
That's a much harder problem than a spending cap. A rupee limit is a number in a config file. A registry that can reliably distinguish a legitimate shopping assistant from a compromised or malicious agent, at the scale UPI operates, is a standing piece of infrastructure that has to keep working correctly forever, not just at launch. Nothing reported so far describes how NPCI plans to audit registered agents on an ongoing basis, or what happens when one starts behaving unexpectedly after it's already been cleared.
Where this surfaced, and who's saying what
The protocol was a visible theme at the Global Fintech Fest in Mumbai, held September 8–11, alongside tokenization and quantum-security discussions. NPCI managing director and CEO Dilip Asbe has been explicit about where the organisation sees this going, framing AI as central to "the next wave of UPI" — not just for agentic payments but for fraud and mule-account detection, and for extending credit based on a user's digital footprint. He's also pushed the broader ecosystem to build domain-specific small language models rather than relying on general-purpose ones, a preference that fits the pattern of Indian digital-public-infrastructure projects favouring purpose-built, auditable systems over black-box ones.
The likely first use case, per the reporting, is narrow and low-stakes by design: frequent, small purchases like groceries, where an e-commerce platform's agent reorders something a user already buys regularly. NPCI itself has flagged where this goes next — agents acting on sale alerts, or executing instructions at a price threshold the user set in advance. That second category edges toward something closer to autonomous trading behaviour than shopping, and it's a long way from a ₹15,000-a-month grocery cap.
What would actually make this safe
Three things would need to be true before agentic UPI payments look like a system rather than an experiment. The registry needs to be operational and auditable before agents go live at any meaningful scale — not launched in parallel with it. The ₹15,000 cap, or whatever cap eventually ships, needs to be user-adjustable downward, because a fixed ceiling set by NPCI is a blunt instrument for a country with an enormous range of account balances and risk tolerances. And there needs to be a disclosed process for what happens when an agent does something a user didn't intend — a dispute and reversal path built for autonomous transactions, not retrofitted from the human-approved-transaction dispute process UPI already has.
None of that exists in the public record yet. What exists is a working protocol, a live spending cap, and a CEO publicly committed to a timeline that treats this as inevitable rather than optional. The interesting question isn't whether AI agents end up moving money on UPI — NPCI has already answered that. It's whether the registry, the audit trail and the recourse mechanism get built with the same urgency as the protocol itself, or whether they arrive the way safety infrastructure usually does: after the first incident makes it unavoidable.