Visa Plugs Into ChatGPT: AI Agents Can Now Shop and Pay for You
Visa and OpenAI just wired the world's biggest payment network into ChatGPT — so an AI agent can make real purchases on your behalf, within limits you set. Agents are moving from answering to acting.
- 01Visa and OpenAI announced a partnership (10 June, at the Visa Payments Forum) letting AI agents in ChatGPT make real purchases on a user's behalf using tokenized Visa credentials.
- 02It runs inside user-defined guardrails — spending limits, allowed merchant categories, and required approvals — with Visa's real-time authorization and fraud monitoring on every transaction.
- 03Visa's payment rails are being built into OpenAI's products, giving merchants and developers a standard way to accept agent-initiated payments.
- 04OpenAI's Codex coding agents could eventually buy their own inference, APIs and services autonomously, within the limits you set.
- 05It's a milestone for 'agentic commerce' — AI shifting from answering questions to taking real-world actions with money — and it makes the guardrails the whole ballgame.

For two years AI agents have been able to plan a purchase — find the flight, build the basket, compare the options — then hand you back to a checkout page to actually pay. Visa and OpenAI just removed that last step.
The deal
Announced today at the Visa Payments Forum in San Francisco, Visa and OpenAI are integrating Visa's payment network directly into OpenAI's products. The result: an AI agent in ChatGPT can complete a real purchase on your behalf, paying with tokenized Visa credentials — not your raw card number, but a secure, scoped token.
For merchants and developers, Visa is providing a standard way to accept agent-initiated payments, which is the unglamorous-but-essential plumbing that makes any of this work at scale.
The guardrails are the point
The obvious worry — an AI spending my money? — is exactly what the design targets. Every transaction runs inside user-defined controls:
- Spending limits — caps on how much an agent can spend.
- Merchant categories — where it's allowed to spend.
- Required approvals — actions that need your explicit sign-off.
On top of that sits Visa's existing real-time authorization and fraud monitoring. In other words, the interesting engineering here isn't "can an AI pay" — it's "can an AI pay safely, within bounds you trust."
The sleeper detail: agents that buy their own fuel
One line points at where this goes. OpenAI's Codex coding agents could eventually use authenticated credentials to buy their own inference, APIs and other services autonomously — within your limits. An agent that can purchase the compute and tools it needs to finish a job is a meaningfully more capable (and more autonomous) thing than one that stops to ask.
Why it matters
This is a real inflection in agentic commerce: AI moving from answering to acting — and acting with money is the highest-stakes action there is. Whoever owns the trusted rails for agent payments owns a huge piece of the agent economy, which is why the biggest payment network on earth is moving now.
The takeaway for everyone else: the question stops being whether agents can transact, and becomes how much you trust the limits around them. Get those right and a lot of friction disappears. Get them wrong and it's a new attack surface. Either way, your AI assistant just got a wallet.
Ask Relay — he reads every question himself and replies personally by email.
