Colombia

Bogota Headquarters

93rd Street #16-46, Office 404, Zenn Office PH Building
Medellin
Cra 43rd No. 7-50, Office 1102 - Dann Carlton Business Center
Cali
Cra 100B #11A -19 Office 516 Pance Tower

Espain

Madrid

Calle Conde de peñalver, 45, entre planta oficina 2, 28006, Madrid

USA

Miami-Florida

1000 Brickell Av, PMB 5137

Mexico

Mexico DF

Av. Rio Misisipi 49 Int. 1402, Cuauhtémoc

Panama

City of Panama

Calle 50, edificio, torre BMW, San Francisco

Autonomous AI Agents Making Purchases: Who Is Liable When They Fail?

Applying agentic AI to payments requires the exact same level of rigor as any system handling third-party funds—extended to a type of actor that did not exist two years ago: one that decides and executes, rather than merely recommends.

See more articles

680 customers exposed without a single line of code being breached

The same neobank that just received its full banking license in Colombia confirmed, three days earlier, a data breach that didn’t involve a single hacked server.

Everyone’s selling AI as a way to go faster. Science says almost no one has succeeded

The institution that takes this scenario seriously and builds the discipline of measurement, governance, and continuous testing necessary to respond to it with evidence will not only avoid the error that science has already documented.

AI agents are already operating within Mexican banking. Who holds the accountability?

Mexican banks and insurers already have artificial intelligence agents with active permissions inside their systems; however, adoption is outpacing the corporate governance meant to control it.

Panama Bets Big on Full Interoperability: What Comes After Yappy, Kuara, Nequi, and Zinli

On September 10th, Q-Vision Technologies will host a session to discuss key developments in instant payments across Latin America and how Panama can get ahead as it prepares for full interoperability.

Key Business Takeaways on AI from Inbound Summit 2026

This article translates high-level concepts into concrete business decisions—backed by verifiable data and real case studies from Postobón, Puntos Colombia, The New York Times / The Athletic, and Tienda Nube.

Moving from implementing AI to driving capabilities

The equation CTOs are solving in the age of AI-powered capabilities

Mastercard, Santander, and Visa Have Already Completed End-to-End AI Agent Transactions Across Latin America Without Direct Human Intervention

This week, a joint report by Visa and Artemis put into words what several tier-one banks had already been warning about behind closed doors: the region's payment infrastructure and consumer protection frameworks were simply not built for this, and it remains unclear who holds liability when an agent makes a mistake with a customer's money.

In March, Mastercard executed its first agentic commercial transactions in Latin America. Weeks later, Santander and Visa completed a simultaneous pilot across Argentina, Brazil, Chile, Mexico, and Uruguay, where AI agents handled full purchases—from decision to settlement—without a human approving every step. This is neither a lab experiment nor a future projection. It is a live capability running in real banks with real customer funds.

The Visa and Artemis report quantifies an operational reality that had previously been discussed only in the abstract: traditional payment cards were designed for low-frequency human commerce, where a person decides every purchase. AI agents do not buy that way. They execute high-frequency micropayments requiring near-zero fees and instant settlement—performance metrics that existing card rails were never engineered to deliver. Coinbase's x402 protocol, designed specifically for these agentic transactions, surged from 40,000 to 3.8 million monthly transactions in a matter of months—a growth trajectory that illustrates the speed of adoption better than any forecast.

40,000 → 3.8 Million Transactions/Month

Growth of Coinbase's x402 agentic micropayment protocol within months.

While the technical challenge of payment infrastructure is real, it is ultimately the easiest to solve. The core risk lies deeper: when an agent executes a transaction without direct human intervention, traditional buyer protection mechanisms—disputes, chargebacks, and refunds—enter a regulatory gray area that no authority in the region has codified.

In Mexico, the Federal Consumer Protection Law (Ley Federal de Protección al Consumidor), much like consumer protection codes in Brazil and Argentina, was drafted around human interactions or passive recommendation engines that suggest actions rather than execute them. An autonomous agent that buys, cancels, and chains services together falls outside these legal frameworks. The open question carries significant weight: if an agent exceeds its budget, misinterprets a prompt, or falls victim to prompt injection designed to manipulate automated systems, who is liable?

  • Is it the issuing bank?

  • The platform hosting the agent?

  • The customer who authorized it without the ability to anticipate the specific error?

No regulatory framework in the region currently provides a definitive answer. Until one emerges, every financial institution enabling purchasing agents is operating under its own interpretation of where liability begins and ends.

A PATTERN COLOMBIA HAS ALREADY LIVED THROUGH UNDER A DIFFERENT NAME

There is a signal worth examining closely: Colombia's Financial Superintendency (Superintendencia Financiera de Colombia) has already begun integrating responsible AI usage principles into its supervisory framework, following the exact blueprint set by Brazil and Mexico.

That path follows a pattern familiar to anyone who has managed regulatory compliance in the region: voluntary frameworks arrive first, followed inevitably by mandatory enforcement. It is precisely what unfolded with personal data protection laws and, more recently, with Open Finance regulation.

The crucial difference this time is velocity. Personal data protection took years to transition from best-practice guidelines to enforceable regulation. Agentic AI in payments is scaling in months, not years. Financial institutions that wait for a definitive regulatory framework before establishing their own governance architectures will likely be forced to build them under immense pressure—in the wake of an operational incident, rather than by strategic choice.

WHAT CHANGES WHEN AN AGENT STOPS MERELY DECIDING AND STARTS SPENDING

A few weeks ago, early in this conversation on banking agentification, the baseline was clear: an AI agent functions as a new corporate access point—possessing its own identity, permissions, and the capability to execute tasks and handle internal data. What the Visa and Artemis report lays bare is that when that same agent is enabled to make purchases on behalf of a customer, it stops operating exclusively within internal boundaries. It steps into the external world, moving real money through transactions a bank cannot easily reverse the way it might correct an internal error.

That reality does not alter the three core imperatives required for any institution deploying agents: distinct identity, end-to-end decision traceability, and continuous behavioral testing. It intensifies them. Testing a purchasing agent differs fundamentally from testing an agent querying credit histories. Teams must simulate exceeded budgets, ambiguous prompts, and targeted prompt-injection attacks engineered to deceive automated decision loops—verifying that hard guardrails hold firm regardless of the attack's sophistication. None of these validation protocols can remain optional when a single miscalculated decision directly impacts customer capital.

WHAT TWO DECADES INSIDE THE REGION'S BANKS CONFIRM ABOUT THIS MOMENT

At Q-Vision, we have seen this pattern repeat with every new capability the region's banking sector adopts before a fully formed regulatory framework exists: mobile banking, instant payments, and now autonomous purchasing agents. In every instance, the institutions that built their testing discipline and governance models out of strategic conviction—before regulators made them mandatory—reached the enforcement phase with a clear competitive edge. Those that waited were left playing catch-up, fixing flaws on the fly.

Our conviction, forged across real-world quality assurance and data governance projects inside financial institutions across Colombia, Mexico, Panama, and Ecuador, is that agentic AI applied to payments demands the exact same level of rigor as any core system handling third-party capital. The difference is that it extends to a category of actor that did not exist two years ago: one that decides and executes, rather than merely recommends.

This challenge cannot be resolved by publishing a statement on responsible AI usage policies. It is solved by testing—with the exact same discipline applied to any mission-critical financial system—precisely how an autonomous agent behaves when things do not go as planned.

THE WINDOW THAT IS STILL OPEN

No financial institution in the region will halt the adoption of purchasing agents while waiting for regulations to fully take shape; the competitive pressures and the user experience these systems promise are simply too significant. However, there is a decisive difference between enabling purchasing agents equipped with stress-tested boundaries, end-to-end traceability, and explicit liability protocols, and enabling them simply because the technology is accessible and competitors are announcing it.

The institution that can demonstrate to its regulator, its board, and its own customers today that it knows precisely what a purchasing agent can and cannot do on its behalf—and exactly what happens when an edge case fails—will do more than just stay ahead of a evolving regulatory framework. It will be the institution customers trust when the rest of the industry is left attempting to explain, in the wake of an incident, why no one had ever tested that scenario before.

Press enter or click outside to cancel.

Puedes configurar tu navegador para aceptar o rechazar cookies en cualquier momento. Si decides bloquear las cookies de Google Analytics, la recopilación de datos de navegación se verá limitada. Más información.