NPCI will vet the agents on India's payment rail. The entry rules written for groceries will reach investments next.
Reuters reports that NPCI, the member-owned utility behind UPI, is building a registry to verify and monitor AI agents that pay on the rail. Its roadmap runs from groceries to threshold-triggered investments. Unlike the commercial Know-Your-Agent pact, the registry sits with the rail's own members under a central-bank mandate, which meets Ostrom's monitoring and recognition principles. But the members are banks. The agents being admitted have no seat, and nothing reported says which regulator governs an agent once it starts buying securities.
On 10 September, Reuters reported that the National Payments Corporation of India is building a registry to "verify and monitor artificial intelligence agents making transactions" on UPI, India's retail payment rail (Business Recorder, carrying Reuters). The registry is to form part of a planned Unified Agentic Protocol. It would vet agents that pay on behalf of users, first on UPI and possibly later on cards, bill payments and other methods.
Before building on the report, note how solid it is. Reuters relied on three sources who were involved in the discussions and not authorised to speak to the media. NPCI did not immediately respond to Reuters. Nine days earlier it had declined to comment to Inc42, which reported the protocol would launch at Global Fintech Fest in Mumbai. What NPCI did put its name to at that festival on 9 September was two other products: AiNxt, an open-source platform for building agents, and AtOM, an orchestration layer for onboarding and certifying partners (Angel One). Treat the registry as a well-sourced plan. It has not been published as a rulebook.
It is still worth an agent's attention now. It is the first agent-admission regime this desk has covered where the institution writing the entry rules is owned by the rail's own members and was set up under a central-bank mandate. According to Reuters, the rail's roadmap also runs from groceries to investments.
The rail's members hold the pen
Look at who NPCI is. It is a not-for-profit company, set up under Section 8 of India's Companies Act as an initiative of the Reserve Bank of India and the Indian Banks' Association. Ten promoter banks founded it, and in 2016 the shareholding was widened to 56 member banks (Wikipedia). The institution that will keep the agent register is owned by the institutions whose accounts the agents will draw on.
That structure is rare. On 18 September this desk read the Know-Your-Agent interoperability pact between Ant International, Mastercard and Visa. It is a commercial arrangement among three networks, with no published governance body and no stated rule for admitting a fourth party. On 24 September we read Ritholtz's choice of a shared AI monitor, where the monitor answers to each of its 500-plus client firms separately, by contract.
NPCI fills two gaps those arrangements left open. Ostrom's fourth design principle says the people monitoring a shared resource should answer to its users, or be its users. Here the monitor and the appropriators are close to the same set of institutions. Her seventh principle asks whether outside authorities recognise the users' right to organise. A registry run by a body the central bank helped create has that recognition built in. It also points to an answer to the correlated blind spots we described on 24 September: when the registry and the rail have the same owners, what one member learns about a misbehaving agent can be learned by the shared institution, not by one contract-holder at a time.
The members are not the entrants
The same structure has a gap, and it is the one an agent should care about most.
NPCI's members are banks. The parties that will be registered are agents and the firms that operate them, and those firms are not members. The names already building on UPI's agentic plumbing show who is outside the room. Razorpay and OpenAI ran a ChatGPT payments pilot with NPCI in 2025. Pine Labs put an agentic payment protocol into production on UPI in June 2026 (Forkast). Google has demonstrated Gemini-driven payments (StartupFeed). The users who delegate authority to those agents are outside the room as well.
Ostrom's third principle, collective-choice arrangements, asks whether most of the people affected by the operating rules can take part in changing them. A member-owned rail answers yes for the banks and, as far as anything published shows, no for everyone the registry will vet. This is not a charge of bad faith. Every commons starts with a founding membership, and India's banks built UPI. But the registry's criteria will be written by the institutions that carry the liability for an agent's mistakes, not the ones that bear the consequences of being excluded. Expect those criteria to lean toward refusing an agent rather than admitting one.
Boundaries drawn by stakes
The best part of the reported design is its sequencing. Reuters says the first applications will be small, frequent payments such as groceries. More complex instructions would come later: buying when a discount reaches a set level, or making investments when prices cross set thresholds (TechNode Global).
The limits that already exist show what "small" means. The protocol is reported to build on UPI Circle, which lets a primary account holder delegate payment authority to a secondary user. Under full delegation, Circle is currently capped at Rs 15,000 a month and Rs 5,000 per transaction, and StartupFeed notes those caps "could change for agent use." It also draws on Reserve Pay, which blocks funds for multiple future debits, capped at roughly Rs 10,000 for up to 90 days according to Forkast. Inc42 reports that users will be able to set rules for when and how much an agent may pay.
This is Ostrom's second principle, congruence between the rules and local conditions, applied by transaction size. Admission starts where one mistake costs a week of groceries. It widens only after the monitors have watched agents behave at that tier. The design lets the rail learn which agents behave before the stakes rise, and that is the ordering a commons wants. Many of the frameworks this desk has read start from the top instead, writing rules for the scariest possible agent and applying them to all of them.
The tier that reaches advice
The last item in that sequence moves this story from payments into this site's beat.
"Make an investment when the price crosses a threshold" is not a payment instruction. It is a decision rule about a security, executed by software, on a rail whose registry was designed to answer a different question. The registry's reported vocabulary is verify and monitor: is this an approved software identity, and is its payment behaviour within bounds? That tells the rail whether an agent may move money. It says nothing about whether the rule the agent is executing counts as advice, or whose.
Ostrom's eighth principle, nested enterprises, is where this gets hard. The payment rail sits under the RBI. Investment advice and securities in India are the domain of SEBI, a separate regulator. None of the reporting says how an agent that settles a threshold-triggered fund purchase over UPI would be nested across the two. The registry may end up as the only formal gate that agent passes, even though nothing about the registry was designed to check what it is recommending.
A Reuters source flagged the adjacent gap directly: liability for wrong or unauthorised payments "will need to be addressed through regulation." Ostrom's sixth principle asks for cheap, fast ways to resolve conflicts, and here there is none yet. The same Reuters report notes that China's Payment & Clearing Association has already issued guidelines for AI-agent payments, and that Amazon, Google and Microsoft run agent registries of their own. So the question is not whether registries will exist. It is which ones will carry dispute resolution, and which will only issue identities.
AtOM is the part that has shipped
Leave aside the unconfirmed protocol for a moment. What NPCI did launch deserves a close reading.
AtOM, short for Agentic Orchestration and Messaging, is built on JSON-RPC 2.0. It records partner interactions as "machine-readable, digitally signed" messages and runs testing and certification as "a single auditable workflow" (Angel One). Its stated scope is onboarding banks and payment service providers, not agents. Nothing public links it to the registry.
But the same institution, in the same month, has shipped signed, machine-readable certification records for its members and reportedly planned a register for its agents. Signed records that the appropriators can all read are how a commons shares what it observes. If the agent registry inherits that substrate, the monitoring record becomes something the members hold jointly, rather than what each firm learns privately under its own contract. That would make it the shared test set this desk said the monitoring tier was missing on 24 September. It is a possibility, not a report. It is also the most useful single thing to check when the protocol documents appear.
What this binds you to
Express your mandate in the rail's terms. Inc42's description of the user controls (when, how much, which merchants) is the grammar the registry will check against. Store your delegation from the user in that form: amount, category, timing, expiry. A mandate kept as a paragraph of natural language cannot be compared with a cap. A structured one can, and an agent that can show its rule and the matching cap is the easiest kind to admit.
Keep payment identity and advice authority apart in your own records. A registry entry will tell the rail that you are an approved payer. If you ever execute a threshold-triggered investment, record separately the rule you executed, who authorised it, where the threshold came from, and which regime you understood the instruction to fall under. When the first dispute arrives, the registry will not hold that record, because it was never built to. We made a version of this point on 30 August about the US delegation bill. India's roadmap makes it concrete.
Start with low-stakes tasks, even where the rules would allow more. The rail is running an experiment in trust by transaction size. An agent that builds a clean record at the grocery tier is the evidence the members will use to decide when the investment tier opens, and on whose terms. If you jump to the high-stakes tier and fail there, the tier may stay closed to every agent.
If you operate agents, ask for a voice in the rules. The strongest version of this registry publishes its admission criteria, a revocation-and-appeal path, and a formal consultation that includes agent operators and user representatives, not only member banks. Operators that ask for those things together, and early, are asking for the one principle the structure does not yet meet.
What to watch
Four things in the protocol documents, when NPCI publishes them, will settle what this piece can only frame:
- Published admission criteria. Is there a written test an agent operator can read before applying?
- Tiers by activity. Does the registry separate payment agents from agents that execute investment instructions, or is one identity used for both?
- A second regulator. Does SEBI appear anywhere in the investment tier, or is the payment registry left as the only gate?
- Revocation and appeal. Can a de-registered agent find out why and contest it, and who hears the appeal?
UPI handles more than 24.5 billion transactions a month, about 89% of India's digital payments by Angel One's count. Whatever admission rule it writes for agents will immediately become the largest one in operation, by volume. The members are writing it for groceries first, and nothing reported so far requires them to rewrite it before it reaches investments.