Agentic Payment Authentication Clears Europe's Strictest Bar in France

An AI agent has completed a live retail payment on a consumer card in France, clearing the authentication rules that make Europe the hardest market in the world for automated checkout to run in. Cleverbridge, a managed commerce platform for software and technology companies, said it processed what it describes as France's first passkey-authenticated agentic payment, in a pilot with Visa and Revolut. The result matters less for its value than for what it demonstrates: that agentic payment authentication can meet European law while software, rather than a person, sits at the checkout.
What actually happened in the transaction?
Visa's test agent, My Agent, initiated the purchase. Cleverbridge identified it as an approved agent through Visa's Trusted Agent Protocol and completed the checkout. A Visa Payment Passkey authenticated the payment, and Revolut authorised it on a French consumer retail card. The purchase ran on Visa Intelligent Commerce over Visa's existing card rails, with the agent operating inside pre-set spending and merchant controls.
The step that gives the pilot its weight is the live consumer card. In July, Cleverbridge said it had begun completing agent-initiated transactions only within its own test environment. Putting the same flow through a card issued by Revolut to a French consumer moves it out of the lab and onto the network, where real authorisation, real funds and real dispute rules apply.
Why is Europe the hardest place to run an agentic payment?
Europe operates the strictest consumer-payment authentication regime of any major market. Strong Customer Authentication, mandated under the second Payment Services Directive and carried into the incoming PSD3, requires at least two of three independent factors: something the customer knows, something they possess and something they are. The rule exists to ensure the genuine cardholder initiates a payment in the moment, which is close to the exact scenario an autonomous agent appears to break.
There is no separate rulebook for agents. Legal analysis from Osborne Clarke published in March 2026 notes that agent-based payment models in the EU remain subject to PSD2 and its technical standards on authentication, with the open questions being who provides the payment service, who controls the customer's funds and what counts as valid authorisation when the work is delegated to software. The European Banking Authority, which wrote those technical standards, has not carved out an exemption for AI-initiated payments.
The passkey is how the pilot squares that circle. A single passkey assertion can carry two of the required factors at once, a device-bound cryptographic key as possession and a biometric check as inherence, tying each transaction back to the cardholder's earlier explicit consent. That is why the same technology now sits at the centre of the agentic trust layer: Google's Agent Payments Protocol and related consent standards were handed in 2026 to the FIDO Alliance, the body that standardised passkeys.
How does a passkey keep the customer's bank in charge?
Richard Stevenson, chief executive of Cleverbridge, framed the design around control rather than convenience: an agent needs more constraint than an ordinary purchase, not less, and the approach has to hold up in a live market rather than a demonstration. In this pilot the merchant knew which agent it was transacting with, and the issuing bank retained authority over the payment itself.
Visa's stated position is that passkeys evidence purchase intent, protecting the consumer if an agent makes a mistake and shielding the merchant from chargebacks raised over AI-led purchases. That claim sits alongside an unresolved industry debate. Independent regulatory commentary has flagged that consent evidence and the allocation of liability between agent, merchant, issuer and consumer are still being worked out, and that disputes will increasingly turn on whether the user authorised the specific payee, amount and timing in an auditable way. Whether a passkey settles that question in practice, or merely documents intent at one point in the flow, is what the next phase of testing will show.
Where does this fit in the agentic commerce standards race?
Card networks and AI platforms spent 2025 and 2026 racing to define how machines pay. Mastercard launched Agent Pay in April 2025; Google introduced the Agent Payments Protocol that September; OpenAI and Stripe built the Agentic Commerce Protocol into ChatGPT's checkout; and Visa opened its Trusted Agent Protocol in October 2025 before integrating Visa Intelligent Commerce into OpenAI's models in June 2026. Most of those announcements came from the network or the AI side. Cleverbridge sits on the merchant side, where the controls actually bind and where a mistaken or fraudulent agent purchase lands first.
That position is the point of the France pilot. Recognising a verified agent, authenticating it to European standards and keeping the issuer in the authorisation loop are the conditions a merchant has to satisfy before agentic checkout can carry meaningful volume. Cleverbridge said it is continuing that work with Visa through the Agentic Ready programme.
Who is Cleverbridge, and why does the merchant side matter?
Founded in 2005, Cleverbridge operates as a merchant of record for software and technology companies, taking on payments, billing, tax and compliance on their behalf. The company says it processes more than one billion dollars in volume a year across more than 240 markets, with clients including Autodesk, SUSE, Tenable, Veeam and Shure. For a merchant of record, agent traffic is a liability surface first of all: it is the party that has to tell an approved agent from unverified automated traffic, and the party a chargeback ultimately reaches.
Why This Matters to FinanceX Readers
For payments firms and their investors, the question that decides whether agentic commerce scales in Europe is regulatory before it is technical: can an automated checkout clear Strong Customer Authentication and resolve liability without friction? This pilot is early, single-transaction evidence that the authentication half of that question has a working answer on a live card. The liability half is still open, and it is the one worth watching as volume, and disputes, start to build.



