Home / Companies / Basis Theory / Blog / September 2026

September 2026 Summaries

3 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
Agent-initiated payments are emerging across consumer commerce, API usage, invoice settlement, and data purchases, but fragmented card, wallet, processor, and crypto protocols create operational and risk-management challenges for merchants. Merchants considering acceptance should identify which payment rails and credentials they can process, verify how consumer authorization mandates are established and recorded, assess regulatory and regional compliance requirements, and understand differing dispute and settlement rules, particularly between card payments and final stablecoin transfers. Most agent-payment models rely on a consumer-approved mandate that sets spending, merchant, currency, and time limits, with credentials issued against that authorization and linked to evidence of the consumer’s approval. Merchants are advised to retain mandate and transaction references, establish acceptance policies before transactions arrive, test dispute-response processes, and avoid becoming dependent on a single processor or protocol. The text argues that portable credential vaults and payment-orchestration systems can help merchants manage protocol fragmentation while preserving flexibility as agentic-payment standards continue to develop.
Sep 08, 2026 1,399 words in the original blog post.
3D Secure (3DS) is used in only about 3% of U.S. e-commerce transactions as of 2025, largely because there is no regulatory mandate comparable to Europe’s PSD2 requirements and merchants fear additional authentication steps may reduce checkout completion. The protocol enables card issuers to verify online cardholders through frictionless or step-up authentication and can shift chargeback liability from merchants or platforms to issuers after successful authentication. Although U.S. businesses commonly rely on basic fraud and address-verification checks, 3DS can offer value when deployed selectively rather than universally, particularly for transactions with ambiguous fraud scores, soft declines requiring further authentication, and high-risk sectors such as airlines. Modular, processor-agnostic 3DS implementations can separate authentication from authorization, allowing platforms to authenticate selected payments before authorization or retry soft-declined transactions after issuer verification, potentially improving approval rates while managing fraud exposure.
Sep 03, 2026 811 words in the original blog post.
A Merchant of Record is the legally recognized seller that processes consumer payments and appears on card statements, while merchants may either retain this role using payment service providers or outsource it to non-MOR platforms at the cost of checkout control and customer-data ownership. The growth of agentic commerce, in which AI agents help discover or complete purchases, complicates this choice because consumer-led transactions still depend on human checkout flows, whereas agent-led purchases require efficient, secure APIs or MCP endpoints that software agents can use directly. For merchants seeking to remain the Merchant of Record, programmable payment vaults can tokenize and isolate sensitive card data, allowing agents to reuse stored credentials or send new payment information directly to a secure vault rather than through merchant systems. This approach can reduce PCI-DSS exposure and data-leak risks while preserving customer relationships, payment-provider flexibility, and control over revenue and transaction data.
Sep 01, 2026 1,250 words in the original blog post.