The pitch, as it's circulated since the Global Fintech Fest in September, sounds like a new kind of payment rail: AI agents, acting on your behalf, moving money on UPI without you tapping approve on every transaction. NPCI calls it the Unified Agent Protocol. The coverage since has leaned hard on the autonomy angle — your ChatGPT or Gemini assistant quietly handling the grocery reorder, the subscription renewal, the recurring bill, while you do something else entirely.

Look at what the protocol is actually assembled from, and the autonomy is real but the plumbing isn't new. NPCI isn't building a fourth payment network alongside UPI. It's wiring two features that already exist — UPI Circle and Reserve Pay — into a single delegation layer an AI agent can sit behind, and putting a number on how far that delegation can go.

What's actually new here

UPI Circle lets a primary account holder hand payment authority to a secondary person — originally built for a parent letting a teenager pay, or a professional letting an assistant handle routine transactions. Banks cap full delegation under Circle at ₹15,000 a month. Reserve Pay, separately, lets a customer block funds in advance against a future purchase, typically up to around ₹10,000, held for as long as 90 days.

The Unified Agent Protocol's contribution is making the "secondary user" in that first mechanism a piece of software instead of a person, and standardising how an AI agent authenticates itself, requests a payment and receives a go/no-go — rather than every fintech building its own bespoke integration with every bank. That standardisation is the genuinely useful part. It's an API contract, not a new rail.

MechanismWhat it already didWhat the Agent Protocol adds
UPI CircleHuman delegates to a second human, capped at ₹15,000/monthSecond "user" can be an AI agent instead of a person
Reserve PayBlocks funds in advance for a future purchase, ~₹10,000, up to 90 daysAgent can trigger the block and the release without a human tap
Unified Agent Protocol—Standard API so any bank or fintech can plug an agent in without a custom build

That's the honest scope: a ₹15,000 monthly ceiling, inherited wholesale from a feature built for human delegation, now also available to a language model. Framing that as AI agents "unleashed" on UPI overstates what changed.

The pilots are real, and small

What's not vaporware is who's already building on it. NPCI and Razorpay ran a pilot with OpenAI letting ChatGPT complete grocery purchases over UPI as early as October 2025, and followed it with similar pilots involving Anthropic and Sarvam AI through 2026. Razorpay says it has completed a proof-of-concept letting both Google's Gemini and Anthropic's Claude initiate agentic payments, with consumer-facing rollout described as weeks away as of this writing. Separately, a startup called Phronetic AI shipped PayCentral, billed as India's first dedicated agentic payment platform, letting agents generate dynamic payment links, manage refunds and reconcile accounts without a human in the loop.

Pilot / productPartnersStatus
ChatGPT grocery pilotNPCI, Razorpay, OpenAILive since October 2025
Agentic payments PoCRazorpay, Google Gemini, Anthropic ClaudePoC complete, consumer rollout pending
Anthropic / Sarvam pilotsNPCI, RazorpayRunning through 2026
PayCentralPhronetic AI, AvenuesAIShipped, live

The use cases on offer so far are deliberately unglamorous: grocery reorders, subscription renewals, routine digital purchases. That's a feature, not a limitation of ambition — it's the same ₹15,000 ceiling showing up as a design constraint. Nobody is pitching an agent booking a flight or settling a large one-off bill under this framework, because the delegation limit the protocol inherited was never sized for that. It's also a sensible place to start precisely because the failure mode of a grocery reorder going wrong is a refund, not a financial catastrophe — exactly the kind of low-stakes category a new trust mechanism should be tested on before anyone extends it to a transaction size where a mistake actually hurts.

That restraint is worth noting because the surrounding industry has not shown the same caution. Agentic commerce as a phrase has attracted a wave of products promising far more autonomy than any bank has actually agreed to underwrite, and NPCI choosing to bolt its rollout onto an existing, already-regulated delegation limit — rather than inventing a new one — is the more conservative of the two paths available to it.

What NPCI still has to answer

The things that make this a protocol and not just a product demo — rule-based payment limits, identity checks on the agent itself, and liability provisions when an agent pays the wrong amount or the wrong party — are described by NPCI as features it "aims to include," not features that currently exist in a published, bank-auditable spec. That distinction matters more here than in most fintech rollouts, because the liability question in agentic payments is genuinely unresolved industry-wide: if an AI agent authorises a payment on a hallucinated instruction, or a bad actor manipulates an agent's context into approving a transfer, who eats the loss — the bank, the platform running the agent, or the account holder who delegated authority to it in the first place? UPI Circle's existing dispute mechanics were built around a human secondary user who can be asked what they meant to do. An AI agent cannot answer that question the same way.

None of that is a reason to doubt the pilots are real — OpenAI, Anthropic and Google don't run proof-of-concepts with a national payments body for a press release. It is a reason to treat "launch" as provisional until NPCI publishes the liability framework rather than just the delegation limit. A spending cap tells you how much money is at risk. It doesn't tell you who's responsible when the cap doesn't stop the wrong payment from going through.

India isn't the only one writing this rulebook

The identity problem NPCI is still working through is the same one the rest of the industry is racing to solve from the other direction. Visa's Trusted Agent Protocol, introduced with more than ten partners in late 2025, tackles agentic commerce from the card-network side: it gives merchants a way to cryptographically verify that an incoming checkout request actually comes from a legitimate AI agent rather than a bot scraping a storefront, using agent-specific signatures rather than a spending cap as the safety mechanism. Visa's India and South Asia head, Suresh Sethi, has framed the company's pitch to Indian merchants and banks explicitly around that gap — telling reporters that agentic commerce depends on verified agent identities, authentication, tokenisation, biometrics and cyber resilience, and that for Visa the task isn't just moving money but building trust in the movement itself.

That's a useful contrast, because it shows two different starting points for the same unsolved problem. Visa's protocol tries to answer "is this really an AI agent and not an impersonator" before a transaction happens. NPCI's protocol, so far, answers "how much can this agent spend" and leaves the identity and liability questions for later. Mastercard, Cloudflare and OpenAI itself have each published competing pieces of agentic-commerce infrastructure over the same few months, and none of them agree yet on where the trust boundary should sit — with the merchant, the bank, the agent platform or the payment network. NPCI inheriting a ₹15,000 human-delegation limit and calling it a protocol looks less like India falling behind that conversation and more like India picking the cheapest, fastest-to-ship piece of it first, and leaving the harder architecture — the part Visa is spending real engineering effort on — for a second version.

The honest read

The Unified Agent Protocol is a real and sensible piece of infrastructure: standardising agent-to-bank authentication on UPI so every fintech doesn't reinvent it is useful plumbing, and letting an agent handle a ₹15,000-a-month envelope of routine, pre-approved purchases is a plausible, low-risk place to start. What it is not, yet, is AI agents getting free rein on India's payment rails — the ceiling, the dispute mechanics and the liability rules are all inherited from a feature designed for a different kind of delegate, and NPCI's own language about identity checks and liability provisions it "aims to include" is an admission those pieces aren't finished. The pilots with OpenAI, Anthropic and Google are the part of this story that's unambiguously true today. The rest is a protocol still being written around them.