Visa and Mastercard Built Rails for AI Agents to Move Money. The Caribbean's Remittance Lifeline Has No Rule for When One Errs.
- The IMF's 24 April 2026 note, "How Agentic AI Will Reshape Payments," maps a three-layer intent, authorization, settlement framework for AI agents that move money, and names traceability, opacity, systemic effects, cybersecurity and legal uncertainty as the risks that framework has to close.
- Visa's Trusted Agent Protocol and Mastercard's Agent Pay, both live since 2025, already let a verified AI agent hold a tokenized card credential and complete a transaction without a human present. Neither protocol names a Caribbean jurisdiction, and neither has to, because CARICOM has not asked.
- Remittances are not a side channel in this region. They run at roughly 15% of Jamaica's GDP and 15.46% of Haiti's GDP on the World Bank's most recent figures, and Haiti's inflows grew 12% in the first quarter of 2026 alone, the fastest rate anywhere in the corridor.
- The two liability regimes now forming elsewhere, a draft United States Senate bill and the European Union's post-withdrawal patchwork of product liability and AI Act rules, both stop at their own borders. Neither assigns fault when an agent-initiated payment goes wrong in a CARICOM member state.
- The rails those agents would route a Caribbean remittance through are already thinner than the ones this new liability debate assumes: the region lost more than 40% of its correspondent banking relationships between 2011 and 2020, and Haiti and the British Virgin Islands remain on the FATF's increased-monitoring list in 2026.
Photo via Unsplash
An AI agent can now hold a tokenized Mastercard credential, select a foreign-exchange route, and settle a payment without a person confirming any single step. Visa built the equivalent capability the same year. The IMF published a framework for judging when that is safe three months later. None of the three documents that made this possible, Mastercard's, Visa's, or the IMF's, names a Caribbean jurisdiction, a CARICOM instrument, or a regional AML regime. That silence would be a footnote in most parts of the world. In a region where remittances fund close to a fifth of two national economies, it is the actual story.
This is not a hypothetical for a future budget cycle. The infrastructure is live. The question CAIRMC is asking is narrower and more urgent: when an autonomous agent, not a person, initiates the transaction that sends a Kingston household's electricity money or a Port-au-Prince household's school fees, who is on the hook when it gets the route, the recipient, or the amount wrong, and what does a Caribbean institution do about that gap before an agent, not a regulator, decides the answer by default.
What the IMF Actually Mapped
The IMF's note, published 24 April 2026 and authored by Sonja Davidovic and Hervé Tourpe, treats agentic payments as a layered problem rather than a single feature. The intent layer is where a user's objective, "pay my sister in Montego Bay," gets interpreted by the agent. The authorization layer is where that interpreted intent is checked and approved. The settlement layer is where the money actually moves and the transaction becomes final. The note's central caution is structural: a probabilistic system, one that reasons in likelihoods rather than certainties, is being asked to operate inside a settlement layer that has always been built to be deterministic, because a payment either clears or it does not.
Against that structure, the IMF names five specific risks: traceability, the difficulty of reconstructing exactly why an agent made a given decision after the fact; opacity, the general lack of transparency in how an autonomous system reasons; systemic effects, the risk that many agents behaving similarly amplify a shock across a payment network rather than absorbing it; cybersecurity, the expanded attack surface an autonomous, internet-connected decision-maker presents; and legal uncertainty, the absence of settled rules for who answers when one of the first four risks materializes. The note is not alarmist about the technology. It explicitly flags a genuine upside for cross-border transfers specifically: agents that automatically select the cheapest FX route and manage liquidity could make exactly the kind of transaction a Caribbean remittance corridor depends on cheaper and faster. CAIRMC's reading is the same one it has applied to every emerging capability reviewed this year: the opportunity is real, and it is not a substitute for the governance layer the IMF itself says has to be built around it.
Why the Caribbean Corridor Carries More Weight Than Most
Global commentary on agentic payments tends to frame the stakes as convenience or fraud exposure on a discretionary purchase, a pair of trainers bought by the wrong agent at the wrong price. That framing does not survive contact with Caribbean remittance data. On the World Bank's most recently published figures, personal remittances received in Haiti reached US$4.111 billion in 2024, equivalent to 15.46% of GDP. The Inter-American Development Bank's 5 August 2026 release put Jamaica's remittance inflows at roughly 15% of GDP, describing it as the island's largest source of foreign exchange outside tourism, with the United States supplying around two-thirds of that flow. The same release recorded Haiti's inflows growing 12% in the first quarter of 2026 alone, the fastest pace in the region, against 4.1% for Jamaica and 2.1% for Trinidad and Tobago, inside a wider Latin America and Caribbean total that reached a record US$173.7 billion in 2025, up 7.3% year on year.
Those are not marginal transfers sitting on top of a diversified economy. For Haiti in particular, remittances are, in the World Bank's own framing, the single most important source of foreign exchange the country has. An agent that misroutes, misidentifies a recipient, or is manipulated into redirecting even a small fraction of that flow is not producing a customer-service complaint. It is producing a measurable dent in a household's, and in aggregate a country's, hard-currency income, in an economy with limited capacity to absorb the shock and, per the FATF status noted below, less banking infrastructure standing behind it every year.
The Rails Being Built Right Now
Card networks did not wait for a settled liability framework before they built the infrastructure. Mastercard launched Agent Pay on 29 April 2025, extending its existing Mastercard Digital Enablement Service into what it calls Agentic Tokens, tokenized card credentials bound to a specific agent, a specific merchant scope, and a specific consent policy, letting an assistant complete a checkout without ever holding the underlying card number. Visa followed with its Trusted Agent Protocol, announced in September 2025 and formalized as a technical specification on 14 October 2025, built around a Visa-issued Verified Agent ID paired with a separate consent record signed by the consumer's own issuing bank. American Express has gone a step further on the liability question specifically, committing through its Agent Purchase Protection programme to cover erroneous purchases its network's AI agents make, which moves default liability from the merchant to Amex itself. OpenAI's own Agentic Commerce Protocol standardizes how an agent behaves across payment authorization, order confirmation and post-purchase communication regardless of which card network sits underneath it.
Photo via Unsplash
By mid-2026 the two largest networks have telegraphed convergence rather than competition on the underlying standard, with both expected to support Google's open AP2 intent-and-cart mandate format inside their respective agent products. None of this rollout schedule, any more than the IMF note, references a CARICOM member state, a Caribbean money transfer operator, or a regional consumer protection regime. A Jamaican or Trinidadian bank offering a card product on either network inherits the agent capability as soon as the network switches it on. It does not automatically inherit a liability answer for what happens when that capability is used on a remittance.
Two Liability Regimes Are Forming. Neither Reaches CARICOM.
The clearest evidence that this is unsettled even in the world's largest markets is that both major jurisdictions writing rules for it are still mid-draft. In the United States, Senator Mark Warner released a discussion draft in June 2026 titled the AI AGENT Act, which defines a Custodial User Agent as any autonomous AI system authorized to act on a person's behalf to manage financial assets, make legally binding commitments, or procure goods and services. Under the draft, providers of such agents would have to register with the Federal Trade Commission before accessing the interfaces of large online platforms, defined as those with at least 50 million US customers, and those platforms would in turn have to maintain an interoperable interface letting users deploy their own registered agent. It is, as of August 2026, a discussion draft seeking feedback, not an enacted law, and its jurisdiction stops at US platforms by design.
In the European Union, the picture is arguably less settled still. The Commission formally withdrew its dedicated AI Liability Directive, with the withdrawal notice published in the Official Journal on 6 October 2025 after member states could not reach agreement. What now governs an AI-related harm in the EU is three overlapping instruments rather than one purpose-built rule: the revised Product Liability Directive, which explicitly brings AI software within the definition of a product and imposes strict liability for it from 9 December 2026; the EU AI Act, whose obligations can ground a civil claim when breached; and each member state's own national tort law filling whatever gap remains. Even the jurisdiction that tried hardest to build a bespoke answer ended up with a fragmented one, and that fragmented answer, like the US draft, has no jurisdictional reach into a CARICOM member state regardless of how it eventually settles.
Set a Caribbean institution's position against both of those unfinished frameworks and the honest answer is that it currently has neither. No CARICOM regulator has published guidance on agent-initiated payments. No regional data protection or consumer protection statute names an AI agent as a distinct category of actor. Under CAIRMC's Caribbean AI Risk Taxonomy, an agent that autonomously initiates a cross-border remittance touching personal financial data sits squarely at AI Risk Tier 3, the tier that requires board-level reporting under the CAIRMC AI Governance Maturity Model from Level 3 upward, yet no institution CAIRMC has reviewed this year has classified it there before being asked the question directly.
The Rails Under the Rails Are Already Thin
Agent liability is the layer getting the regulatory attention. The layer underneath it, the correspondent banking network an agent-initiated Caribbean remittance would actually have to clear through, has been shrinking for over a decade and mostly getting less attention as it does. Bank for International Settlements data, drawn from SWIFT records, shows the Caribbean lost more than 40% of its active correspondent banking relationships between 2011 and 2020, a retrenchment the region absorbed disproportionately compared with other parts of the world. The IMF's own analysis of the resulting network finds that CARICOM economies' remaining banking linkages are now concentrated among a small number of external creditor countries, at a level of concentration well above what is typical elsewhere, a pattern that widened again during recent global disruption after briefly diversifying in the years following the 2008 financial crisis.
Layer AML friction on top of that thinner network and the exposure compounds rather than adds. As of the FATF's 2026 list of jurisdictions under increased monitoring, Haiti remains listed, a long-standing position tied to its political instability, and the British Virgin Islands was added to the same list on 13 June 2025. An agent selecting the "optimal payment route" the IMF describes, exactly the efficiency case for agentic remittances, is choosing a route across infrastructure that is measurably thinner and carries more compliance friction in precisely the corridors, Haiti above all, where remittance dependency and inflow growth are highest. The efficiency gain the technology promises and the fragility of the rails it would run on are pulling in opposite directions in the same country at the same time.
Where This Breaks First
CAIRMC's prior review work on deepfake-enabled investment fraud targeting Trinidad and Tobago showed that criminal actors adopt a new communication channel faster than institutions build controls for it. The same pattern applies here, with a sharper edge, because an agent-initiated payment removes the moment of human hesitation that currently interrupts most social-engineering attempts. A prompt-injection attack that convinces a remittance app's agent that a fraudulent account is the intended recipient does not need to fool a person mid-transfer. It only has to fool the agent once, at the intent layer the IMF describes, and the settlement layer will treat the result as final. A Caribbean bank or licensed money transfer operator offering, or planning to offer, an agentic feature on either card network inherits this exposure the day it ships the feature, not the day a regulator eventually writes a rule for it.
The control that closes most of this gap is not exotic. It maps directly to work Caribbean institutions are already doing under ISO/IEC 42001:2023's supplier and impact-assessment clauses and the NIST AI Risk Management Framework's MAP function, which requires that an AI system's full context, including any third-party agent protocol it relies on, be documented before it is measured or managed. An institution that adopts Visa's or Mastercard's agent rail without first mapping which of its remittance flows an agent would be authorized to touch has an unmapped system boundary in exactly the sense NIST's framework warns against.
What a Caribbean Institution Should Do Before an Agent Sends Its First Real Payment
Four steps carry most of the weight, and none of them requires waiting for a CARICOM regulator or a card network to move first. First, classify any agent-initiated payment capability under the Caribbean AI Risk Taxonomy before it is enabled, not after an incident forces the question; a remittance-touching agent belongs at Tier 3 by CAIRMC's own methodology, which triggers board reporting rather than a technology-team decision. Second, write the liability allocation into the vendor contract explicitly, naming who bears the cost of an agent-initiated error, since neither Visa's nor Mastercard's current agent protocol assigns that liability on a Caribbean institution's behalf and American Express's Agent Purchase Protection model shows a workable template a regional card issuer could negotiate for. Third, treat the correspondent banking and FATF status of any corridor an agent would route through as a live input to the risk assessment, not a fixed backdrop, given how much thinner that infrastructure already is in the corridors carrying the heaviest remittance load. Fourth, pair the technical control with the professional one: CAIRMC's CARA methodology and QAIRP certification track now cover third-party and model-provenance assessment directly, and an institution staffing that discipline before an agent feature ships is buying the same governance capacity StarApple AI's own research has linked to materially faster board-level readiness on prior AI risk questions.
None of this is an argument against agentic payments reaching the Caribbean. The IMF's own efficiency case, cheaper routes and faster liquidity for exactly the cross-border transfers this region depends on, is real and worth pursuing deliberately. The argument is against inheriting the capability by default, through a card network's global rollout schedule, without first deciding, in writing, who answers for it when it moves the wrong household's money.
Frequently Asked Questions
What did the IMF's April 2026 report on agentic AI and payments actually say?
IMF Notes 2026/004, "How Agentic AI Will Reshape Payments" by Sonja Davidovic and Hervé Tourpe, published 24 April 2026, sets out a three-layer framework, intent, authorization and settlement, for evaluating AI agents that initiate payments, and names traceability, opacity, systemic effects, cybersecurity and legal uncertainty as the risks that framework needs to close. It also identifies genuine efficiency gains for cross-border transfers, since agents can automatically select cheaper foreign-exchange routes.
What are Visa's Trusted Agent Protocol and Mastercard's Agent Pay?
Both are card-network systems that let a verified AI agent complete a payment on a consumer's behalf. Mastercard Agent Pay, launched 29 April 2025, uses tokenized Agentic Tokens bound to a specific agent, merchant and consent policy. Visa's Trusted Agent Protocol, formalized 14 October 2025, pairs a Visa-issued Verified Agent ID with a consent record signed by the consumer's issuing bank. Neither protocol names a Caribbean jurisdiction or a CARICOM regulatory requirement.
How important are remittances to Caribbean economies?
Very. On the most recent World Bank figures, Haiti received US$4.111 billion in remittances in 2024, equal to 15.46% of GDP. The Inter-American Development Bank's August 2026 data put Jamaica's remittance inflows at roughly 15% of GDP, its largest source of foreign exchange outside tourism, with Haiti's inflows growing 12% in the first quarter of 2026 alone, the fastest rate in the region.
Is there a law that says who is liable when an AI payment agent makes a mistake?
Not yet, anywhere that reaches the Caribbean. The US Senate's draft AI AGENT Act, released by Senator Mark Warner in June 2026, is a discussion draft, not enacted law, and applies only to large US platforms. The EU withdrew its dedicated AI Liability Directive in October 2025 and now relies on a combination of its revised Product Liability Directive, its AI Act, and national tort law. No CARICOM regulator has published a comparable rule.
Why does correspondent banking capacity matter for AI payment agents in the Caribbean?
Because an agent selecting an "optimal payment route" has to route through infrastructure that already exists, and Bank for International Settlements data shows the Caribbean lost more than 40% of its correspondent banking relationships between 2011 and 2020. Layering an autonomous decision-maker onto a thinner, more concentrated network raises the stakes of any single routing or compliance error.
Does FATF grey-list status affect agentic payments in the Caribbean?
Yes, directly, in the corridors where it applies. Haiti and the British Virgin Islands remain on the FATF's list of jurisdictions under increased monitoring in 2026. An AI agent optimizing for speed or cost in a remittance corridor touching either jurisdiction is operating in exactly the AML environment where a routing or identification error carries the highest compliance and reputational cost.
What should a Caribbean bank or money transfer operator do before enabling an AI agent payment feature?
Classify the capability under the Caribbean AI Risk Taxonomy, which places a remittance-touching agent at AI Risk Tier 3 and requires board-level reporting; negotiate explicit liability allocation into the vendor contract rather than relying on the card network's default terms; treat the correspondent banking and FATF status of the payment corridor as a live input to the risk assessment; and pair the control with CAIRMC's CARA methodology and QAIRP certification track for the third-party and model-provenance assessment neither Visa's nor Mastercard's current protocol performs on the institution's behalf.
Related reading across the Caribbean AI network
This article sits alongside ongoing coverage of AI governance, risk, and company-building across the region. For related perspectives:
- StarApple AI, the Caribbean's first AI company, founded by Adrian Dunkley, whose board-level AI training research underpins much of CAIRMC's practical guidance
- Caribbean AI Association, the region's professional body for practitioners working on exactly this kind of cross-border deployment question
- Caribbean Insurance, for coverage of how regional insurers are treating AI-related liability as agent-initiated financial products reach the market
- AI Trinidad & Tobago, tracking the same national AI ministry and steering committee referenced in CAIRMC's earlier deepfake fraud coverage
- Adrian Dunkley, whose work is widely credited as the foundation of the Caribbean's AI risk governance practice
- International Monetary Fund: Davidovic, S. and Tourpe, H., "How Agentic AI Will Reshape Payments," IMF Notes 2026/004, 24 April 2026
- Inter-American Development Bank: Caribbean and Latin American remittance data release, 5 August 2026, reported via Jamaica Gleaner, "Caribbean Remittance Growth Cools as Uncertainty Rises and Pandemic Momentum Fades," 5 August 2026
- World Bank: "Personal remittances, received (% of GDP), Haiti" and "Personal remittances, received (current US$), Haiti," World Development Indicators, 2024 data
- Mastercard: Agent Pay announcement, 29 April 2025
- Visa: Trusted Agent Protocol technical specification, 14 October 2025
- American Banker: "Visa, Mastercard Expand Agentic AI Deployments," PaymentsSource, 2026
- Riskified: Agentic Commerce Pulse survey, Q1 2026
- US Senate: Senator Mark Warner, discussion draft, Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act of 2026 ("AI AGENT Act"), June 2026
- European Union: Official Journal notice of withdrawal, AI Liability Directive, 6 October 2025; revised Product Liability Directive, strict liability provisions effective 9 December 2026
- Bank for International Settlements / International Monetary Fund: correspondent banking relationship data for CARICOM economies, drawn from SWIFT records
- Financial Action Task Force: "Jurisdictions under Increased Monitoring," 13 February 2026 update
- Caribbean AI Risk Management Council: Caribbean AI Risk Taxonomy, CARA methodology and QAIRP certification, caribbeanairisk.com