- Key insight: Visa is collaborating with Bluefin on new card security as more issuers and merchants forge agentic-commerce strategies.
- What's at stake: While plastic cards are likely safe, agentic commerce poses security threats for omnichannel shopping that includes a mix of digital and in-store environments.
- Expert quote: "The greater risk is indirect and omnichannel. An AI agent will generally initiate a purchase remotely using stored or tokenized credentials. However, that purchase may subsequently be collected, amended, exchanged or refunded at a physical location." –Serpil Hall, Datos Insights
While humans would appear to be central characters in brick and mortar shopping, the rise of new forms of
Bluefin has partnered with Visa to combine security tools in a way that's designed to improve card technology at physical points of sale, or "card present" payments. The card present security partnership is not directly designed for agentic AI, but can be used to protect omnichannel commerce, or a shopping experience that takes place in stores and online, according to Bluefin.
For Visa, the Bluefin collaboration comes amid a broader push into cybersecurity at the card network, including updating its Visa Vulnerability Agentic Harness framework and adding new advisory services to Visa's
A new encryption
Visa's Bluefin partnership combines Bluefin's card-present security, including point-to-point encryption, terminal integration and other technology, with Visa's payment processing and tokenization – a process that replaces card identification with a substitute.
The tokenization shields personal card data from the AI agent, in effect giving the agent access to only the "instructions" that the user wants the AI agent to view.
"So the AI agent can act with permission, but it can't see the credential and what's inside of it," said Miles, who also is on the Electronic Transactions Association's AI committee. "It's a form of P2P encryption for AI."
Bluefin and Visa's offering has launched with selected certified Ingenico Lane series point of sale devices and is designed for retail, hospitality, petroleum, healthcare, higher education and other enterprises. In addition to working with Bluefin, Visa made other moves to expand the card network's AI strategy from detecting vulnerability to more actionable capabilities. The card network has enabled corrective actions to address AI-related vulnerabilities into a business' workflow. Visa's agentic harness framework has also added support for Anthropic and OpenAI models, along with other models.
In another update, Visa's consulting and analytics unit added AI Cyber Leadership Education, which provides executive workshops and certification courses focused on cybersecurity and artificial intelligence; a Cybersecurity Maturity Assessment designed to evaluate an organization's current cybersecurity capabilities; and Cyber Risk Prioritization and Roadmap, which sells guidance for prioritizing risk and developing remediation plans.
Visa's primary competitor,
Agent AIs at the store
Even as humans shop and make payments in traditional stores, there is a growing role for agentic AI. AI agents will directly address and resolve the most enduring pain points of the physical shopping journey, including personalized discovery, real-time in-store navigation, interactive product engagement via smart shelves and, ultimately, a frictionless, checkout-free environment, according to the technology firm klover.ai. "Agents will merge the tangible benefits of physical retail with the data-driven precision of online commerce," klover.ai said.
Klover.ai also said the move to in-store agentic commerce is contingent on an "invisible" revolution in back-end operations, noting operational AI agents will create autonomous supply chains, deliver hyper-accurate demand forecasting, and empower frontline associates with real-time data, turning them into high-value customer consultants. "Many people have accepted that a retail interaction is not separate from e-commerce," Bluefin's Miles said. "But if you're going to combine in-store and out-of-store, you're opening up exposure to digital attacks."
The security threat for in-store agentic commerce is related to the mixing of channels rather than AI fraud infiltrating the actual card's embedded technology.
"Agentic commerce is unlikely to reverse the security benefits of EMV or cause a direct resurgence in traditional counterfeit-card fraud," Serpil Hall, strategic advisor for fraud and AML at Datos Insights, told American Banker. "The greater risk is indirect and omnichannel. An AI agent will generally initiate a purchase remotely using stored or tokenized credentials. However, that purchase may subsequently be collected, amended, exchanged or refunded at a physical location."
The Bluefin and Visa Acceptance Solutions collaboration addresses an important part of the physical infrastructure risk, according to Hall. "The offering combines PCI-validated point-to-point encryption, tokenization, terminal integration and device-lifecycle management," Hall said "These capabilities should reduce exposure of payment data at the point of interaction and simplify the management of secure card-present payments."











