Secure Agentic Voice Commerce: The Architecture That Turns AI Conversations into Secure Transactions

Secure Agentic Voice Commerce with Pay by Call and PBC 3DS enabling AI voice agents to complete secure authenticated payments

AI can already understand, recommend and increasingly act. The next frontier is enabling it to complete an economic transaction securely, authentically and accountably—without breaking the voice conversation.

The contact centre is approaching one of the most significant changes in its history.

For decades, automation in customer service was primarily about efficiency. Interactive Voice Response systems reduced the need for human intervention. Chatbots automated repetitive enquiries. Conversational AI then made those interactions more natural, allowing machines to understand language, context and intent with increasing sophistication.

Agentic AI introduces a fundamentally different proposition.

An AI agent is not valuable merely because it can converse. Its defining characteristic is its ability to take action in pursuit of an objective: consult enterprise systems, reason across multiple steps, select an appropriate course of action and execute a process.

This distinction matters enormously for customer service.

Gartner predicts that by 2029 agentic AI could autonomously resolve 80% of common customer-service issues without human intervention, potentially reducing operational costs by 30%. At the same time, Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027 because of escalating costs, unclear business value or inadequate risk controls.

Those two forecasts are not contradictory.

They point to the same conclusion:

The success of agentic AI will not ultimately depend on how intelligently an AI system can talk. It will depend on what it can safely accomplish after the conversation.

And in a very large number of interactions between organisations and customers, accomplishing the requested outcome ultimately requires a transaction.

This is the context in which Pay by Call proposes a new category:

Secure Agentic Voice Commerce

Secure Agentic Voice Commerce is not simply a voicebot connected to a payment gateway.

It is an architectural model designed to transform an economic intention expressed during a live voice interaction into a secure, authenticated, traceable and executable transaction, while keeping sensitive payment credentials outside the AI and general contact-centre environment.

From Conversational AI to Agentic Voice Commerce

A sophisticated conversational platform can already perform tasks that would have appeared extraordinary only a few years ago.

It can understand why a customer is calling.

It can identify the customer’s objective and retrieve contextual information from CRM, ERP, reservation, billing or knowledge-management systems.

It can explain alternatives.

It can calculate an outstanding balance.

It can propose a repayment plan.

It can modify a booking.

It can recommend an upgrade.

It can identify the most appropriate product.

It can negotiate within predefined parameters.

This is an enormous technological achievement.

But it is still possible for the entire journey to fail at the most economically important moment.

The payment.

Imagine an AI agent dealing with an airline passenger who needs to change a flight.

The agent understands the request, searches availability, identifies a suitable alternative, calculates the fare difference and obtains the passenger’s agreement.

Then it says:

“I’ll send you a payment link so that you can complete the transaction.”

At that precise moment, the supposedly agentic process ceases to be agentic.

The customer leaves the conversation.

An SMS or email is opened.

A browser is launched.

Another interface appears.

The customer may have to identify the merchant again, understand another checkout, enter credentials and complete authentication.

The AI has understood the customer’s intention.

But it could not execute it.

That discontinuity—the boundary between conversational intelligence and trusted economic execution—is the problem Secure Agentic Voice Commerce is intended to solve.

A Definition of Secure Agentic Voice Commerce

We propose the following definition:

Secure Agentic Voice Commerce is an architecture for conversational commerce in which a voice-based AI agent can understand an economic intention, establish verifiable user authorisation, initiate and coordinate a transaction, protect sensitive payment credentials, invoke authentication where required and receive the transaction outcome in order to continue the conversation—all within a transactional journey governed by the voice interaction.

An important distinction should be made immediately.

Secure Agentic Voice Commerce is not currently a formal standard defined by EMVCo, PCI SSC, the card schemes or European regulation.

It is a technological and architectural category proposed by Pay by Call to describe a problem emerging from the convergence of three previously distinct domains:

Agentic AI. Contact Centres. Payments.

The need for such a category becomes clearer when we examine what actually creates value in an agentic system.

The Agentic Value Equation

We can express agentic value through a simple conceptual relationship based on four interdependent factors:

Agentic Value = Intelligence × Execution Capability × Trust × Continuity

The important characteristic of this equation is that it is multiplicative rather than additive.

It is not enough for three variables to achieve exceptional values.

If any one of them falls to zero, the effective agentic value of the overall system also falls to zero, regardless of how advanced the remaining three may be.

A highly intelligent AI system that perfectly understands the customer but cannot perform the required action remains, functionally, an assistant.

A system capable of executing transactions but without sufficient security, authorisation or accountability creates unacceptable risk.

And a technically intelligent, secure and executable architecture that repeatedly breaks the customer journey can still fail to convert intention into outcome.

The objective is therefore not to maximise one isolated capability.

It is to combine all four.

Intelligence

Can the system understand what the customer is trying to achieve?

Execution capability

Can it actually perform the action required to achieve that objective?

Trust

Can every participant be confident that the action is authorised, authenticated, secure and accountable?

Continuity

Can the journey reach its intended outcome without unnecessary channel breaks or loss of context?

This fourth factor is especially important in voice.

Because voice is not simply another user interface.

It is a real-time, contextual interaction.

Once a customer has explained a problem, evaluated alternatives and reached a decision, the commercial value of that accumulated context is considerable.

Breaking the conversation at the moment of payment risks destroying precisely what the AI has spent the previous minutes constructing.

Intent Becomes a Security Primitive

One of the fundamental changes introduced by agentic commerce is that user intent becomes less obvious.

Traditional commerce contained very visible manifestations of intention.

A customer handed a card to a merchant.

A shopper clicked a “Buy” button.

A user confirmed a checkout.

In agentic commerce, delegation changes that model.

A customer may tell an AI agent:

“Find me a flight to London under €250 that arrives before 7 p.m. and book it if you find one.”

The user is no longer directly selecting every intermediate step.

The agent interprets instructions, evaluates conditions and may ultimately execute the transaction.

This creates an important question:

How can the ecosystem prove that the transaction executed by the agent corresponds to what the consumer actually authorised?

Mastercard has identified this as a foundational issue for agentic commerce. In 2026 it introduced Verifiable Intent, co-developed with Google, to create a tamper-resistant record of what a user authorised when an AI agent acts on their behalf. Mastercard describes the model as linking identity, intent and action into a privacy-preserving, auditable record.

The principle has particular relevance to conversational commerce.

A voice interaction contains more than a structured purchase instruction.

There may be questions.

Negotiation.

Alternative products.

Changes in amount.

Changes in conditions.

Clarifications.

Customer consent therefore needs to become something more precise than a vague indication that “the customer wanted to pay”.

A robust architecture should be able to associate the customer’s authorisation with the relevant:

merchant, amount, currency, purpose, transaction reference and final action.

This is the transition from:

Conversational Intent

to:

Verifiable Transactional Intent.

Verifiable Intent Is Necessary—but It Is Not the Same as Secure Payment

Proving what the customer authorised solves only one part of the problem.

The next boundary is payment data.

Telephone environments are unusually complex because sensitive card information can potentially pass through multiple systems.

The telephony infrastructure.

SIP networks.

Call-recording platforms.

CCaaS systems.

Agent desktops.

Speech-to-text engines.

Transcription tools.

Analytics systems.

Observability platforms.

CRMs.

And, increasingly, large language models.

This is why payment security in voice cannot be treated merely as a prompt-engineering issue.

It is not enough to tell an AI model:

“Do not remember the card number.”

The architecture should ideally ensure that the card number never reaches the AI model in the first place.

That distinction is fundamental.

Security should not depend on the behaviour of the model. It should be enforced by the architecture.

PCI SSC explicitly states that PCI DSS applies wherever payment card account data is stored, processed or transmitted. VoIP traffic containing account data is therefore within scope for applicable PCI DSS controls. PCI SSC also states that sensitive authentication data such as CVV must not remain in digital audio recordings after authorisation and recommends suppressing or redacting such audio during payment-data entry whenever possible.

The arrival of generative and agentic AI makes this architectural separation even more important.

A conversational system should receive the meaning of the transaction.

It does not need to receive the payment credentials themselves.

PCI DSS Is Essential. But PCI DSS Is Not the Whole Answer.

This distinction is fundamental to understanding Secure Agentic Voice Commerce.

PCI DSS and cardholder authentication address different problems.

PCI DSS provides a framework for protecting payment account data within systems that store, process or transmit it. Telephone environments present particular challenges because audio, VoIP, call recording and contact-centre infrastructure can significantly expand the systems involved in handling payment information.

EMV 3-D Secure addresses another part of the problem.

EMVCo describes EMV 3DS as a technology through which merchants and card issuers exchange transaction and contextual information in order to authenticate consumers and help prevent card-not-present fraud. The protocol supports both frictionless risk-based authentication and challenge flows where additional cardholder verification is necessary.

In simple terms:

PCI DSS protects payment credentials.

EMV 3DS helps authenticate the cardholder.

A truly secure agentic voice architecture therefore needs to address both dimensions.

Protecting the PAN does not prove who authorised the transaction.

Authenticating the cardholder does not justify allowing sensitive credentials to circulate through an AI platform or general contact-centre environment.

Secure Agentic Voice Commerce requires these capabilities to work together.

From MOTO to ATO: Authenticated Telephone Order

This leads us to reconsider one of the oldest concepts in card-not-present payments:

MOTO — Mail Order / Telephone Order.

For decades, MOTO has been used to describe certain transactions initiated through mail or telephone channels.

In Europe, its relationship with Strong Customer Authentication is especially important.

PSD2 requires SCA when the payer initiates an electronic payment transaction. However, the European Banking Authority has clarified that remote non-electronic payment transactions initiated and executed through mail or telephone orders may be outside the SCA requirement. Crucially, this does not mean that every transaction associated with a telephone call automatically qualifies as MOTO. The EBA has separately clarified, for example, that merely manually keying card details into a payment terminal does not automatically make the transaction an out-of-scope MOTO operation.

This nuance matters greatly.

The industry should not treat “telephone” as an automatic synonym for “non-authenticated”.

The technology now exists to move beyond that historical assumption.

This is why Pay by Call proposes the concept:

ATO — Authenticated Telephone Order

ATO is not intended to create a new legal payment category under PSD2, nor is it presented as an EMVCo-defined transaction type.

It is an architectural concept.

ATO describes a telephone-originated commercial journey in which the interaction can incorporate robust cardholder authentication rather than relying solely on the traditional characteristics of MOTO.

The conceptual difference is significant:

MOTO primarily describes how the order originates.

ATO describes how trust can be added to its execution.

In an ATO architecture, the commercial intention can originate in the conversation while card credentials are collected inside a controlled PCI environment and authentication is coordinated where required before the transaction outcome is returned to the conversational system.

The call remains the commercial context.

But the transaction gains a level of authentication traditionally associated with digital commerce.

EMV 3DS Is Already Evolving Beyond the Conventional Browser Checkout

It is important not to think of EMV 3DS exclusively as a browser-redirection technology.

The protocol has evolved considerably.

EMVCo documents frictionless flows, challenge flows, out-of-band authentication, Split-SDK capabilities and decoupled authentication. Particularly relevant to the future of voice, EMVCo explicitly identifies situations such as voice assistants where conventional redirect-based authentication may not be possible, and also describes decoupled authentication scenarios involving MOTO transactions.

This matters because the future of voice payments should not be analysed using only the architecture of yesterday’s web checkout.

The authentication ecosystem itself is becoming more flexible.

When an issuer requires a challenge, the customer may still authenticate through an issuer-controlled environment—for example through a mobile banking application, one-time password or other approved mechanism.

What matters architecturally is that this authentication does not necessarily require the merchant to abandon the voice journey and recreate the entire commercial process as a separate Pay-by-Link checkout.

The authentication interaction may involve another trusted issuer-controlled mechanism.

But the commercial transaction can remain governed by the voice conversation.

That difference is crucial.

The Role of PBC 3DS

This is the architectural problem addressed by PBC 3DS, Pay by Call’s international patent-pending technology.

Its purpose is to enable EMV 3DS authentication to be orchestrated within a payment journey whose primary commercial channel remains voice.

PBC 3DS is not intended to replace the issuer.

It does not replace the Access Control Server.

It does not replace the merchant’s PSP.

And Pay by Call does not need to become the merchant’s acquiring institution.

Instead, the technology provides a specialised orchestration layer connecting the voice transaction context with the authentication and payment infrastructure.

The relevant transaction parameters can remain associated with the voice interaction:

the merchant,

the amount,

the currency,

the payment purpose,

the transaction reference,

and the customer’s confirmed intention.

Authentication can then be performed according to the issuer’s decision and the applicable EMV 3DS flow.

The result returns to the transactional orchestration layer and, ultimately, to the AI agent.

The agent does not need the card number.

It needs the result.

Authenticated.

Authorised.

Declined.

Challenge required.

Timed out.

Failed.

That is a fundamentally different architecture from simply sending the customer away to an independent checkout page.

The Six Layers of Secure Agentic Voice Commerce

A mature Secure Agentic Voice Commerce architecture can be understood as six complementary layers.

1. Conversational Intelligence

The AI establishes what the customer wants to achieve.

It may interact with CRM, ERP, booking, inventory, billing or knowledge systems.

It understands the situation.

It evaluates alternatives.

It prepares the economic action.

This is where most of today’s discussion about conversational AI takes place.

But it is only the first layer.

2. Verifiable Intent and Consent

Before executing an economically meaningful action, the system needs to transform natural-language conversation into an unambiguous transactional instruction.

What is being purchased?

From which merchant?

For what amount?

Under which conditions?

Did the customer actually authorise the action?

As AI systems become more autonomous, this layer becomes increasingly important.

Mastercard’s Verifiable Intent initiative demonstrates that the wider payments industry is already treating provable user intention as a critical element of agentic commerce.

3. Secure Credential Capture

When sensitive payment information is required, it should cross a clear architectural boundary.

Card credentials should be captured within a dedicated PCI-controlled environment rather than exposed to the AI model, recording platform, agent desktop, CRM or general contact-centre systems.

In the Pay by Call model, this function is provided by the PaybyCall PCIaaS platform.

The AI continues to understand the commercial process.

But sensitive credentials are segregated from the conversational intelligence layer.

This principle could be described as:

Maximum transactional context, minimum credential exposure.

4. Authentication

PBC 3DS introduces the authentication orchestration layer.

The relevant transaction information can be provided to the merchant’s payment infrastructure so that EMV 3DS can be invoked when applicable.

The issuer can then perform its risk assessment.

A frictionless authentication may be sufficient.

Or a challenge may be required.

EMVCo’s architecture allows the issuer to determine the appropriate level and method of authentication according to transaction risk and applicable requirements.

5. Payment Processing

An important principle of Secure Agentic Voice Commerce is that the secure execution layer does not necessarily need to replace the existing payments stack.

The merchant can continue using its chosen PSP and acquiring relationship.

This creates a clean separation of responsibilities:

The AI understands and orchestrates the conversation.

Pay by Call protects payment credentials and manages secure voice execution.

PBC 3DS coordinates authentication.

The PSP/acquirer processes the payment.

The issuer evaluates risk, authenticates and authorises according to its role.

This separation is strategically important.

The aim is not to build a monolithic platform.

It is to create a trusted transactional layer between conversational intelligence and payment infrastructure.

6. Outcome and Conversational Continuity

Finally, the conversational platform receives the information it actually needs.

Not the PAN.

Not the CVV.

Not sensitive authentication data.

The outcome.

The AI can then say:

“Your payment has been authorised. I have updated the reservation and I’m sending you the confirmation now.”

At this point the agent has done something fundamentally different from a chatbot.

It has completed an economic objective.

The conversation has become a transaction.

Why Pay by Link Is Not Always the Final Architecture

Pay by Link is a useful technology.

It will remain useful.

For asynchronous interactions—where there is no live customer conversation—it may be entirely appropriate.

The architectural problem appears when Pay by Link is used as the default conclusion to an otherwise synchronous agentic journey.

Imagine what has already happened before the link is sent.

The customer has explained the problem.

The AI has understood it.

Context has been established.

Alternatives have been evaluated.

The customer has reached a decision.

Commercial intent may now be at its highest point.

And precisely then, the architecture tells the customer to leave.

Open an SMS.

Open an email.

Open a browser.

Recognise another domain.

Load another interface.

Enter information.

Authenticate.

Perhaps return to the call.

Perhaps not.

This is not merely an aesthetic UX issue.

It is an architectural discontinuity between intent and execution.

Digital commerce research consistently demonstrates the effect of friction on transaction completion. These figures should not be mechanically applied to telephone Pay-by-Link journeys, since online shopping and live voice interactions are different environments. The relevant principle, however, is universal: every additional transition introduces another opportunity for confusion, interruption or abandonment.

Agentic architecture is supposed to remove unnecessary discontinuities.

A payment journey that systematically creates one at the moment of execution deserves to be reconsidered.

Agentic Payments Have Already Moved Beyond Theory

The broader payments industry is moving rapidly in this direction.

Mastercard launched Agent Pay to enable AI agents to initiate and complete transactions, and has subsequently expanded its approach around agentic trust and Verifiable Intent. Mastercard now describes explicit permissions, verifiable user intent and auditable decision-making as central elements of trusted agentic commerce.

In June 2026, Worldline, ING and Mastercard announced the execution of an end-to-end agentic payment in production in Europe. The transaction demonstrated that merchant AI-agent-initiated and authenticated payments could operate across acceptance, acquiring, authentication and issuer processing infrastructure.

Visa is developing its own agentic-commerce infrastructure through Visa Intelligent Commerce. Its initiatives include credentialing, tokenisation, authentication, controls and mechanisms for trusted agent identification. In June 2026, Visa also announced a strategic collaboration with OpenAI intended to support secure payments within agentic-commerce experiences.

Visa itself makes the underlying economic point particularly clearly: AI that can search and compare is valuable, but agentic commerce becomes materially different when the agent can securely complete the transaction rather than merely recommend it.

The direction of travel is therefore no longer speculative.

AI agents are moving from:

Discovery

to:

Decision

to:

Execution.

The next question is how that transformation should work in voice.

Voice Requires Its Own Transaction Architecture

Most public discussion around agentic commerce understandably focuses on digital commerce.

Browsers.

Applications.

Marketplaces.

Wallets.

Merchant APIs.

Agent-to-merchant protocols.

But voice is architecturally different.

A live voice environment contains real-time audio.

Telephony.

SIP.

Call recording.

Speech recognition.

Text-to-speech.

Transcription.

Quality-management systems.

Human agents.

AI agents.

DTMF.

Contact-centre routing.

PCI scope.

And a customer who expects the conversation to remain coherent from beginning to end.

This means that the architecture of a web checkout cannot simply be copied into the telephone channel.

Voice needs a specialised transactional boundary.

A mechanism that allows the AI to remain intelligent without becoming exposed to payment credentials.

A mechanism that allows payments to remain secure without destroying conversational continuity.

A mechanism that connects the contact centre to authentication and payment infrastructure without forcing every participant into the same compliance domain.

That is the role of Secure Agentic Voice Commerce.

From Cost Centre to Transactional Engine

The consequences go beyond payment technology.

For decades, contact centres have largely been managed as service-cost environments.

Average Handling Time.

Cost per Contact.

First Contact Resolution.

Containment.

Waiting time.

Agent utilisation.

These remain important metrics.

But agentic AI introduces another way of measuring value.

When an AI agent can understand a customer’s objective, propose a solution and securely execute the economic outcome, the contact centre becomes more than a customer-service channel.

It becomes a transactional environment.

An airline can manage a disruption and charge for a change.

A hotel can amend a reservation and collect an upgrade.

A utility can negotiate an outstanding bill and take payment.

An insurer can explain a renewal and complete the premium transaction.

A collections operation can negotiate an arrangement and secure the first instalment.

A public administration can explain a fee or public charge and facilitate its payment.

The relevant KPI begins to change.

Instead of asking only:

Did we resolve the conversation?

organisations can increasingly ask:

Did we securely complete the outcome the customer was trying to achieve?

That is a much more powerful definition of resolution.

The Real Meaning of “Agentic”

There is an important risk that the word agentic becomes little more than another marketing label.

Gartner has explicitly warned about “agent washing”: relabelling assistants, automation or chatbots as agentic systems without giving them meaningful autonomous capabilities.

A useful distinction is therefore:

A chatbot talks.

An assistant helps.

An agent acts.

And when the context is commerce:

A commercial agent must eventually be capable of producing an economic outcome.

That is why secure payment should not be regarded as a peripheral feature added to the end of a voicebot.

For many use cases, it is part of the infrastructure that determines whether the system is genuinely agentic at all.

The complete sequence becomes:

Conversation → Intent → Authorisation → Authentication → Execution → Outcome

Secure Agentic Voice Commerce is the architecture that allows these stages to become part of one governed journey.

Security Through Separation of Responsibilities

One of the most important principles of this architecture is defined by what the AI does not need to do.

The AI does not need to see the card number.

It does not need to store CVV.

It does not need to become a PSP.

It does not need to perform issuer authentication itself.

It does not need to absorb the entire PCI environment into the conversational platform.

Its responsibility is intelligence and orchestration.

Specialised infrastructure should perform the functions for which it has been designed.

That produces a cleaner architectural model:

AI Agent → conversation, context and intent

Pay by Call → PCIaaS and secure voice-payment execution

PBC 3DS → authentication orchestration

PSP / Acquirer → payment processing

Issuer → risk, authentication and authorisation

AI Agent → outcome communication and next action

This is an architecture based on minimum exposure and maximum interoperability.

The AI receives what it needs to continue the journey.

And it is deliberately denied what it does not need.

Pay by Call as the Transaction Execution Layer

This is why Pay by Call should not be understood as another PSP.

Its architectural position is different.

Pay by Call provides a specialised PCIaaS security and transaction-execution layer for voice payments.

Beneath that layer, the merchant can continue to use its existing PSP or banking infrastructure.

Above it, the organisation can use its preferred telephony, CCaaS, contact-centre or conversational-AI platform.

The objective is not to replace the customer’s technology stack.

It is to provide a capability that is frequently missing from it.

In architectural terms:

Pay by Call connects conversational intelligence with secure transactional execution.

PBC 3DS extends that architecture by adding the authentication capability required to move from merely protected telephone payments towards authenticated voice commerce.

That is the bridge from conventional telephone payments to ATO.

And ultimately from ATO to Secure Agentic Voice Commerce.

The Next Frontier of Customer Experience Is Not Better Conversation. It Is Better Execution.

For years, progress in conversational AI was judged mainly by the quality of the response.

Could the system understand natural language?

Could it respond fluently?

Could it maintain context?

Could it sound human?

Those questions remain relevant.

But they no longer define the frontier.

The next question is:

What can the system securely accomplish?

As autonomous agents become more capable, trust needs to increase at the same rate as autonomy.

That is why the payments industry is investing in agent identity, tokenisation, verifiable intent, authorisation, authentication, controls and traceability. Mastercard’s work on Verifiable Intent and Visa’s growing Agentic Commerce infrastructure both reflect the same underlying principle: trust cannot simply be assumed when software begins to spend money on behalf of people. It must be architected into the transaction.

Voice cannot remain outside that transformation.

Millions of commercially significant interactions still take place through contact centres, voicebots and telephone channels.

The objective should not be to make those conversations end just before economic execution.

It should be to allow the conversation to reach its natural conclusion.

Secure Agentic Voice Commerce

The evolution can therefore be summarised in four stages.

Conversational AI enabled machines to converse.

Agentic AI enables machines to act.

Agentic Commerce enables agents to participate in economic transactions.

Secure Agentic Voice Commerce brings that capability to the voice channel while incorporating payment-data protection, verifiable intention, authentication, traceability and conversational continuity.

This is the category Pay by Call proposes.

Not because the future of commerce will be exclusively voice-based.

It will not.

But because wherever a voice conversation generates a genuine economic intention, there should be an architecture capable of taking that intention safely to completion.

The strategic question for conversational-AI providers, CCaaS platforms, BPOs, contact centres, merchants and enterprises building autonomous agents is becoming increasingly simple:

Your AI agent can talk.

Can it transact?

Because the contact centre of the future will not be merely conversational.

It will be transactional.

And for that model to scale, the transaction must be:

secure, authenticated, verifiable, interoperable and native to the conversation.

That is Secure Agentic Voice Commerce.