What happened
The National Payments Corporation of India (NPCI) is developing a registry to authenticate and monitor artificial‑intelligence agents that can initiate Unified Payments Interface (UPI) transactions. The framework would initially cover routine payments and may later expand to conditional purchases and investments. The proposal has ignited a legal debate about who should be held responsible when an autonomous AI system makes a payment error or acts without user consent.
LawBeat’s column notes that NPCI is drafting a registry that would authenticate AI agents before they are allowed to initiate UPI payments on behalf of users. The registry is intended to ensure that only vetted agents can transact, starting with low‑value, routine payments and potentially expanding to more complex financial actions such as conditional purchases or investments.
The article cites two Indian legal experts—Alok Prasanna Kumar of Vidhi Centre for Legal Policy and Nikhil Narendran of Trilegal—who differ on how existing law should address AI‑driven transactions. Kumar argues for an AI‑specific liability regime modeled on absolute liability principles used for nuclear and hazardous substances, while Narendran believes existing statutes can be applied if responsibility is traced to the deploying entity or developer.
The piece also references comparable international efforts, including the UK Jurisdiction Taskforce’s 2026 statement and the EU ’s high‑risk , to contextualise India’s emerging policy conversation.
Why it matters
If AI agents can move money autonomously, existing Indian statutes may be ill‑equipped to assign liability, creating risk for consumers, developers, and financial institutions. The discussion highlights a broader regulatory gap as AI moves from advisory tools to agents that can act independently, a shift that could affect billions of rupees in daily transactions. Clarifying responsibility is essential to protect users, encourage responsible AI deployment, and prevent systemic financial risk.
The ability of AI agents to move funds autonomously raises consumer protection concerns: a malfunctioning or malicious agent could cause unauthorized transfers, fraud, or systemic disruptions in the UPI ecosystem, which processes billions of transactions daily.
Legal clarity is needed to determine who bears the burden of loss—whether it is the end‑user who set the objective, the developer who built the model, or the financial institution that deployed the agent. Without clear rules, parties may be reluctant to adopt AI‑driven payment solutions, slowing innovation in the Indian fintech sector.
India’s approach could set a precedent for other emerging markets grappling with similar AI‑agent liability questions, influencing global discussions on and financial regulation.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
crm_get_transaction(id='4092').Impossibility results in algorithmic fairness (e.g. Kleinberg et al., Chouldechova) show what?
What to watch next
Key developments to monitor include the finalization of NPCI’s AI‑agent registry, any legislative or regulatory amendments that codify liability for autonomous AI actions, and the rollout timeline for pilot implementations. Stakeholders will also watch for guidance from the Indian Ministry of Electronics and Information Technology and potential court cases that test the proposed liability frameworks.
The release of NPCI’s formal registry guidelines, including technical standards, authentication mechanisms, and transaction limits.
Potential amendments to the Indian Contract Act, the Information Technology Act, or new AI‑specific legislation that address liability for autonomous AI actions.
Pilot projects or sandbox trials that test AI‑agent payments in a controlled environment, providing data on risk and compliance.
Legal challenges or court rulings that interpret existing statutes in the context of AI‑driven financial transactions.