Solutions Last updated:

How to Build an Agentic Payments Product: Licensing, Banking & Infrastructure

Jagelski & Partners scopes and routes the full infrastructure for a product where AI agents pay without a human approving each transaction: the regulated-activity analysis, operating entity, EMI, PI, or MiCA rails, safeguarding banking, and the mandate framework that proves an agent’s authority to spend. As of , the protocol layer has consolidated around x402 (contributed by Coinbase to the Linux Foundation in 2026) and Google’s Agent Payments Protocol (AP2), while the permission layer remains EMD2, PSD2, and MiCA. Operational readiness runs from months on partnered rails to 12 to 24 months for a proprietary EMI authorisation.

Not ready to book? Ask Emma first. She answers now, and if it needs a human she takes your details so the consultation starts ahead.

Coverage across the EU EMI and PI licensing map (Lithuania, Malta, Cyprus, Estonia, Ireland among the domiciles compared) and the MiCA CASP route for crypto-native agent rails.
Safeguarding accounts, stablecoin float custody, and merchant settlement rails pre-qualified across the partner network before the authorisation file lands.
End-to-end scoping: regulated-activity mapping (who holds funds, keys, and mandates), licence-versus-partnered-rail decision, protocol integration, and the compliance stack from strong customer authentication to DORA.

What You Need to Build an Agentic Payments Product

An agentic payments product needs five interlocking components: a regulated-activity analysis mapping who holds funds, keys, and mandates; an operating entity; a licence or a partnered rail (EMI, PI, agent model, or a MiCA CASP authorisation for crypto-native rails); safeguarding and settlement banking; and a mandate framework that proves the agent’s authority to spend, wired into the compliance stack. Of the five, the analysis leads, because the licence follows the money flow, not the technology.

In short: the most common failure pattern is shipping the agent before solving the mandate problem. An agent that spends without provable delegated authority is a fraud-liability machine: every disputed transaction lands on the operator, and no regulator will authorise a flow whose authorisation trail cannot be evidenced. Google’s AP2 exists precisely to standardise how an agent proves it holds authority to spend; the permission to move the money at all still comes from EMD2, PSD2, or MiCA. Jagelski & Partners maps the flow to the authorisation that fits, then sequences capital, formation, safeguarding banking, and the licence application in parallel.

Four questions make up the regulated-activity map. Who holds the fiat float while it waits to be spent: holding client funds for payment execution is a payment service needing an EMI or PI permission. Who controls the crypto asset in the same position: that is MiCA custody, or safeguarding under the e-money rules where the unit is an EMT.

Who converts between the unit and fiat: MiCA exchange services. And who issues the unit the agent spends: most crypto-native agent flows settle in stablecoins, and issuing one is MiCA Title IV territory with redemption at par and reserved issuer status.[1]

Unlike a conventional fintech build, the protocol layer is already standardised: x402 revives the HTTP 402 status code as a payment-required handshake and was contributed by Coinbase to the Linux Foundation in 2026, AP2 standardises mandate proof, and the card networks run their own agent rails through Visa Intelligent Commerce and Mastercard Agent Pay. A protocol integration is not a licence: the build decision is which permission sits behind the handshake.

Infrastructure Checklist

ComponentWhat It InvolvesTypical Timeline
Regulated-activity analysisWritten map of who holds funds, keys, and mandates per flow; determines EMI vs PI vs CASP vs partnered rail2 to 4 weeks (before everything else)
Operating entityRegistered company in the licensing domicile; holds the authorisation, customer contracts, and safeguarding obligations1 to 2 weeks
Licence or partnered railEMI (€350,000 capital) / PI (€20,000 to 125,000) / MiCA CASP (€50,000 to 150,000) / agent-model onboarding with a licensed principalWeeks (agent model) to 12 to 24+ months (proprietary EMI)
Safeguarding & settlement bankingSafeguarding account at a credit institution, operating rails, stablecoin float custody and redemption leg8 to 16 weeks (parallel)
Mandate & protocol layerx402 / AP2 integration, mandate issuance and revocation records, spend limits, audit trail8 to 16 weeks (parallel)
Compliance stackStrong customer authentication design, AML/CFT, Travel Rule on crypto legs, DORA controls, safeguarding audit6 to 10 weeks initial, then continuous

Sequencing follows the analysis: the activity map decides the route; the route decides the domicile and the capital; entity and file then gate banking. Mandate engine and protocol integration run in parallel with the regulatory file, but their design documents belong inside it: a regulator reviewing an agent-initiated flow asks precisely how authority is granted, capped, evidenced, and revoked.

Choosing the Right Jurisdiction

For the proprietary-licence route, jurisdiction choice determines the supervisory culture, the authorisation timeline, the tax treatment, and how naturally the payments licence pairs with a MiCA authorisation for the crypto side of the flow. Capital floors are EU-harmonised: €350,000 for an EMI under EMD2 Article 4, €20,000 to €125,000 for a PI under PSD2 Article 7, so the differentiation is supervisory, not financial.[2]

Jurisdiction Comparison

FactorLithuaniaMaltaCyprusEstoniaIreland
RegulatorBank of LithuaniaMFSACentral Bank of CyprusFinantsinspektsioonCentral Bank of Ireland
Licence typesEMI / PI / Small EMIEMI / PI (Class 3/4)EMI / PIEMI / PIEMI / PI
Realistic timeline15 to 22 months (gate operationally tight)12 to 16 months12 to 18 months15 to 24 months (selective)16 to 24 months
Corporate tax15 to 16%35% headline / ~5% effective15% from 2026 (12.5% FY25)22% distributed / 0% retained12.5% (trading)
MiCA pairingSeparate CASP authorisationSingle regulator covers crypto, payments, and securitiesSeparate CASP authorisationSeparate CASP authorisationSeparate CASP authorisation
EEA passportingYesYesYesYesYes

Choose Lithuania if the product wants the deepest EMI ecosystem in the EU: Lithuania remains the largest single EMI cluster by count, with the vendor, talent, and banking periphery that follows. Its supervisory cycle has changed materially: the Bank of Lithuania revoked at least nine EMI and PI licences between 2022 and Q2 2026, so the file must be built to the current bar, not the 2019 one. For the full mechanics, see the EMI licensing guide.

Choose Malta if the product is a crypto-fiat hybrid, which most agentic flows are. Malta and Estonia both put crypto, payments, and securities under one authority, which collapses the two-regulator coordination problem when an EMI licence and a MiCA authorisation must describe the same flow. Malta's edge over Estonia on this route is the depth of its crypto-fiat hybrid caseload rather than the supervisory structure itself. See the EMI licensing guide and the crypto licensing hub.

Choose Cyprus if a credible mid-tier domicile with a 12 to 18 month path fits, particularly where the team already operates in the forex-adjacent ecosystem Cyprus serves. Choose Estonia if the distributed-profits model (0% on retained earnings) matters to a reinvestment-heavy build and the team can pass a selective 15 to 24 month gate.

Build to the PSD3 shape. The PSD3 and Payment Services Regulation package will repeal EMD2 and fold EMIs into a sub-category of payment institutions; realistic market readiness is late 2027 to Q1 2028.[5] An authorisation filed in 2026 will straddle the transition, so the safeguarding architecture, the SCA design, and the group structure should be drafted against the incoming package as well as the current directives. The EMI licensing guide tracks the transition detail.

Setting Up Your Company

Company formation is the first operational step because the authorisation file, the safeguarding account, and every partner-rail contract require a registered entity. Under-capitalising the entity at incorporation is the formation mistake specific to payments builds: the own-funds must be deposited and evidenced before the file is submitted, and re-papering share capital mid-application costs review time.

In short: the entity that holds the authorisation must be formed in the licensing domicile, with the regulatory capital deposited in qualifying own-funds instruments before filing. Technology and holding companies can sit elsewhere. See the full company formation guide.

Formation by Jurisdiction

JurisdictionEntity typeFormation costTimelineMin. capital
LithuaniaUAB (Private Limited Company)EUR 1,500 to 2,700 all-in3 to 5 business daysEUR 1,000 (EMI/PI regulatory capital applies separately)
MaltaPrivate Limited Liability Company (Ltd)EUR 3,000 to 6,000 all-in3 to 7 working daysEUR 1,164.69 authorised; 20% paid up
CyprusPrivate Company Limited by Shares (Ltd)EUR 2,000 to 4,000 all-in5 to 10 working days (1 to 2 expedited)None (one share suffices)
EstoniaOÜ (Private Limited Company)€1,870 to 2,375 all-in1 business day (online with digital signature)€0.01 per shareholder

Formation figures are Year-1 all-in ranges as of and exclude regulatory capital. In every domicile the entity should exist before the authorisation project starts: the entity name anchors the file, the safeguarding account application, and the protocol-layer contracts.

Licensing Requirements

Who holds the funds determines the licence. Holding a fiat float for agent-initiated spending is e-money or payment-service territory: an EMI authorisation carries €350,000 initial capital under EMD2 Article 4 with ongoing own funds under Method D (2% of average outstanding electronic money, Article 5); a PI authorisation carries €20,000 to €125,000 under PSD2 Article 7 depending on the services.[2]

Crypto-native rails swap in MiCA: CASP authorisation at €50,000 to €150,000 by activity class, and Title IV issuer status where the product issues the stablecoin the agents spend.[1]

What separates the routes is legal, not technical. In ABC Projektai (Case C-661/22) the Court of Justice drew the e-money versus payment-service line, and the EBA has confirmed that transfers of e-money tokens on behalf of clients constitute a payment service, which is how a “crypto” agent flow can land back inside PSD2 territory.[3]

This page stays at decision level: the authorisation mechanics, domicile files, and fee schedules live in the dedicated EMI licensing guide and the crypto licensing hub.

Licence, or partnered rail?

A proprietary EMI is the deep route: 12 to 24+ months and a Year-1 outlay of €2.3 to 4.1 million for a mid-complexity greenfield build, plus the €350,000 capital. Launching on partnered rails is the fast route: operating as an agent or distributor of a licensed principal, or building on the card networks’ agent programmes, and graduating to a proprietary licence once volume justifies it. The trade-off is margin and control against time and capital; most agentic builds sequence partnered-rail launch first, proprietary file second, and design the mandate engine so it survives the migration.

Banking

Banks are structurally cautious about agent-initiated flows: the counterparty authorising each payment is software, the fraud-liability question is unsettled, and the flow pattern (thousands of small machine-triggered transactions) trips the same monitoring rules written for card fraud. Layer a stablecoin float on top and the desk inherits crypto due diligence as well; the safeguarding bar itself has risen across the EU supervisory cycle.

In practice the architecture has three legs. A safeguarding account at a credit institution holds client funds segregated under the statutory regime, and it is the hardest account to open: safeguarding banks are scarce and selective. Operating and settlement rails move the merchant-side money. And the stablecoin leg needs custody for the float plus a redemption path at par for EMT balances.

Specific to agentic payments are three settlement components: the agent-initiated collection leg (the x402-style handshake that pulls funds under a mandate), the float safeguarding leg, and the merchant settlement leg sized for machine-speed volume.

In short: budget 2 to 4 months for the banking stack and treat the safeguarding account as the critical path. Jagelski & Partners pre-qualifies safeguarding, operating, and stablecoin-custody institutions across the partner network before the authorisation file lands, because the safeguarding arrangement is a named exhibit in it. See the stablecoin issuer banking guide, the crypto-fiat settlement guide, and the banking overview.

Ongoing Compliance

Compliance is a permanent operating expense that scales with the float. For a licensed EMI the ongoing own-funds requirement alone is Method D’s 2% of average outstanding electronic money, and the operating stack (safeguarding audits, AML/CFT staffing, DORA controls,[4] SCA monitoring) runs from the low six figures annually for a lean licensed operation toward €500,000+ as volume grows, consistent with the €200,000 to 500,000 AML and DORA programme build inside a greenfield EMI budget.

On top sit the agentic-specific obligations: mandate issuance, capping, and revocation records for every agent authority; strong customer authentication design that survives the human-not-present flow; Travel Rule data under the Transfer of Funds Regulation on crypto legs;[6] and the incoming AML package (Regulation (EU) 2024/1624) with its harmonised customer due diligence.[7]

Two regulatory milestones deserve watching: the PSD3/PSR package (market readiness late 2027 to Q1 2028, EMD2 repealed)[5] and the AMLR application, both of which land inside the lifetime of any authorisation filed now.

Realistic Timeline and Costs

End-to-end, an agentic payments product reaches production in 3 to 6 months on partnered rails and 12 to 24+ months on a proprietary EMI or CASP authorisation. Mandate engine, protocol integration, and banking stack build in parallel with whichever regulatory route is chosen; on the proprietary route the safeguarding account is the usual critical path.

Cost Breakdown

PhaseTimelineNotesCost Range
Activity analysis & formation2 to 6 weeksRegulated-activity map + entity (EUR 1.5k to 6k across the four domiciles)EUR 7,000 to 30,000
Licensing routeWeeks to 24+ monthsPartnered-rail onboarding at the floor; proprietary EMI advisory and legal EUR 250k to 600k within a EUR 2.3 to 4.1m greenfield Year 1; MiCA CASP route betweenEUR 15,000 to 600,000
Banking & safeguarding8 to 16 weeks (parallel)Safeguarding set-up and first-year fees at the top of the range; stablecoin custody separateEUR 25,000 to 100,000
Mandate engine & protocol integration8 to 16 weeks (parallel)x402 / AP2 integration, mandate records, spend controls, audit trailEUR 40,000 to 150,000
Year-1 total3 to 24 monthsPartnered-rail build at the floor; mid-complexity greenfield EMI at the ceiling, plus EUR 350,000 regulatory capitalEUR 90,000 to 4.1 million

Figures are Year-1 ranges as of , in EUR, and exclude regulatory capital, safeguarded client funds, and the stablecoin float itself. From Year 2 the cost centre shifts to the own-funds formula and the compliance operation.

Frequently Asked Questions

Costs & Timeline

Jagelski & Partners scopes agentic payments builds from roughly EUR 90,000 Year-1 all-in on partnered rails (activity analysis, entity, rail onboarding, mandate engine, banking) to EUR 2.3 to 4.1 million for a mid-complexity greenfield EMI authorisation, plus the EUR 350,000 regulatory initial capital under EMD2 Article 4. A MiCA CASP route for crypto-native rails sits between, with EUR 50,000 to 150,000 capital by activity class.

The technology spread is narrow; the licensing route drives the budget. Figures as of .

Production in 3 to 6 months on partnered rails: agent-model onboarding with a licensed principal or the card networks’ agent programmes, with the mandate engine and banking built in parallel. A proprietary authorisation runs 12 to 16 months in Malta, 12 to 18 in Cyprus, 15 to 22 in Lithuania, and 15 to 24 in Estonia, with Ireland at 16 to 24.

Most builds sequence both: launch on partnered rails, file the proprietary application in parallel, and migrate once authorised.

Licensing

The licence follows who holds the funds, not the AI. Holding a fiat float that agents spend is e-money or payment-service territory: an EMI authorisation (EUR 350,000 capital under EMD2 Article 4) or a PI authorisation (EUR 20,000 to 125,000 under PSD2 Article 7). Crypto-native rails need MiCA: CASP authorisation for custody and exchange of the units, and Title IV issuer status if the product issues the stablecoin itself.

Operating as an agent or distributor of a licensed principal defers the licence entirely, at the cost of margin and control. The regulated-activity analysis settles the route before anything is filed.

No. EU payments law licenses the person providing the payment or crypto-asset service, and an AI agent is not a legal person: the operator whose infrastructure holds the funds, keys, or mandates carries the authorisation. What the agent does need is provable delegated authority: a mandate record showing what it may spend, within what caps, granted and revocable by an identified principal.

That is the layer Google’s AP2 standardises, and it is the first thing a supervisor examines in an agent-initiated flow. The licence question and the mandate question are separate, and a credible build answers both in writing.

For the proprietary route, the capital is EU-harmonised, so the choice is supervisory. Lithuania offers the largest EMI ecosystem with a tightened gate; Malta is the strongest crypto-fiat hybrid domicile, and like Estonia it puts payments, crypto, and securities under one authority; Cyprus is the credible mid-tier path at 12 to 18 months; Estonia rewards reinvestment-heavy builds with 0% tax on retained profits behind a selective gate.

Jagelski & Partners maps the flow architecture to the domicile in the first conversation, before any incorporation is filed.

Banking & Operations

Yes, and most crypto-native agent flows settle in stablecoins, which is why x402-style handshakes pair naturally with them. The regulatory consequences follow: an e-money token under MiCA Title IV must be redeemable at par with reserved issuer status, transfers on behalf of clients can constitute a payment service per the EBA’s reading, and Travel Rule data accompanies qualifying transfers under the Transfer of Funds Regulation.

The float itself needs custody and a redemption leg in the banking architecture. Spending a stablecoin is easy; holding and moving it for clients is the regulated part.

Through a three-leg architecture: a safeguarding account at a credit institution for client funds (statutorily required and the hardest to open), operating and merchant-settlement rails sized for machine-speed volume, and custody plus a par-redemption path for any stablecoin float. Banks are cautious because the paying counterparty is software and the fraud-liability question is unsettled, so the mandate and monitoring design goes into the bank file, not just the regulator’s.

Jagelski & Partners pre-qualifies all three legs across the partner network before the authorisation file is submitted; budget 2 to 4 months with safeguarding as the critical path.

Start Your Agentic Payments Assessment

Book a strategy call. Jagelski & Partners maps the regulated-activity flow, picks the licence-versus-rail route, and sequences entity, authorisation, safeguarding banking, and mandate engine for agentic payments products, from partnered-rail launch to proprietary EMI.

Initial consultations are free · Response within 24 hours

References

Show all references
  1. European Union, Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA), Title IV (electronic money tokens: issuance, redemption at par, and reserved issuer status), eur-lex.europa.eu, accessed .
  2. European Union, Directive 2009/110/EC (EMD2), Articles 4 and 5, and Directive (EU) 2015/2366 (PSD2), Article 7, eur-lex.europa.eu, accessed .
  3. Court of Justice of the European Union, Case C-661/22, ABC Projektai UAB v Lietuvos bankas, eur-lex.europa.eu; European Banking Authority, Asset-referenced and e-money tokens under MiCA, eba.europa.eu, accessed .
  4. European Union, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), eur-lex.europa.eu, accessed .
  5. Hogan Lovells, Final compromise texts of the Payment Services Regulation and the Payment Services Directive (PSD3) package, hoganlovells.com; EY, PSD3 impacts on payment and electronic money institutions, ey.com, accessed .
  6. European Union, Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, eur-lex.europa.eu, accessed .
  7. European Union, Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (AMLR), eur-lex.europa.eu, accessed .