Initial meeting

Sep 21, 2026

Strong Customer Authentication – Does SCA Really Prevent Agentic Payments?

There are currently many trending topics in the payment services industry. Two of them are Agentic Payments and Agentic Commerce. In these cases, AI agents are provided with their own budgets to automatically make purchases, enter into contracts, and ultimately make payments on behalf of users based on their prompts. Strong Customer Authentication (SCA), which is mandated by payment service regulations and is fundamentally enshrined in Section 55 of Germany’s Payment Services Supervision Act (ZAG), is currently viewed as one of the most prominent obstacles to Agentic Payments. The regulation requires payment service providers to implement strong customer authentication whenever the payer wishes to access their payment account online, initiate an electronic payment transaction, or perform an action via remote access that involves the risk of payment fraud or other misuse. Strong customer authentication requires that, before carrying out the action, the customer must satisfy at least two of three factors from the categories of knowledge (e.g., password), possession (e.g., card or cell phone), and inherence (e.g., fingerprint or retinal scan). It is often argued that the currently applicable SCA requirements under the Second Payment Services Directive (PSD2) prevent the implementation of Agentic Payments. The problem is perceived as follows: Agentic Payments are intended to run in the background without user involvement, whereas SCA is triggered on a transaction-by-transaction basis, requiring user authorization for each individual transaction. As a result, the AI agent cannot initiate payment transactions on its own. But is this statement accurate in its entirety?

When is Strong Customer Identification Not Required?

The requirement to perform an SCA is the general rule and is stipulated in Section 55(1) of the ZAG. The payment industry is calling for a solution to the conflict between SCA and agentic commerce, arguing that the regulation should no longer require SCA verification on a transaction-by-transaction basis, but rather uniformly at the order level when the user instructs the AI agent to execute agentic payments via a prompt. However, there are already numerous exceptions to SCA today, which are regulated in Articles 10 et seq. of Delegated Regulation (EU) 2018/389. Particularly relevant in practice for agentic payments is the exception for payments to trusted recipients. According to this provision, the payment service provider is not required to request SCA if the payee is on a list of trusted payees that the payer has created through their account-holding payment service provider. In such cases, payment service providers are only required to request SCA when the payer creates or modifies the list of trusted payees. In the context of Agentic Commerce, this exemption would be feasible insofar as the SCA request—as proposed by market participants—could be shifted to the moment the order is placed with the AI agent. The resulting restriction on the AI agent’s ability to select providers would simultaneously provide a certain level of security for the user, who could not give the AI agent unlimited discretion. From a consumer protection perspective, such a safety net is certainly not detrimental to users of AI with agentic payment functionality.

Additional Exceptions for Small-Value Payments and Specific Circumstances

The list of trusted recipients is not the only solution for addressing the issue of SCA requests for Agentic Payments—or, at least, for significantly reducing the frequency of such requests. Payment service providers are also not required to perform strong customer authentication when the payer wishes to initiate small-value transactions electronically that meet certain requirements. For this to apply, the amount of the payment transaction must not exceed 30 euros, and the total amount of all previous payment transactions initiated by the payer without SCA must not exceed 100 euros. In addition, no more than five electronic payment transactions may have been initiated since the last time strong customer authentication was performed. These exceptions are well-suited to significantly reduce the number of SCA requests in the case of Agentic Payments, provided that the transactions in question are micropayments. Delegated Regulation (EU) 2018/389 also provides for further exceptions that may apply in specific cases. For example, there are exceptions for transactions between the payer’s own accounts with the same payment service provider, for recurring payments, and for low-risk payment transactions. In this regard, whether the exceptions apply ultimately depends on the specific use case. When designing business models in the areas of Agentic Payments and Agentic Commerce, companies should definitely be familiar with the exemptions set forth in Delegated Regulation (EU) 2018/389 and take them into account when developing their products.

Attorney Dr. Lutz Auffenberg, LL.M. (London)

I.  https://fin-law.de

E. info@fin-law.de

subscribe to Newsletter

This Blog Article as Podcast?

    Contact

    info@fin-law.de

    to top