AP2 has left Google: what FIDO governance changes

Published . Every claim links to a primary source.

Short answer: On 28 April 2026, Google donated the Agent Payments Protocol to the FIDO Alliance and released AP2 v0.2 the same day. AP2 is the third agentic standard to leave the vendor that created it, after MCP and A2A. The detail that matters is where it went. MCP and A2A went to the Linux Foundation, an open-source foundation. AP2 went to FIDO, an authentication standards body whose Payments Technical Working Group is chaired by Mastercard and Visa. The layer that decides whether an agent was authorized to spend your money is now being standardized by the card networks.

What actually happened on 28 April 2026

Two announcements landed the same day, and they are best read together.

Google published a short post from Stavan Parikh, VP and GM of Payments, announcing that it was donating the Agent Payments Protocol to the FIDO Alliance. Its stated reason: transferring ownership ensures AP2 remains platform-agnostic and community-led, while accelerating adoption of secure agentic payments. The same post announced AP2 v0.2 on GitHub, and mentioned Verifiable Intent, an AP2-compatible standard co-developed with Mastercard that is also being donated to FIDO.

The FIDO Alliance published the fuller picture. It is not simply accepting a repository. It formed an Agentic Authentication Technical Working Group, chaired by members from CVS Health, Google and OpenAI, and vice-chaired by members from Amazon, Google and Okta. In parallel, it is developing agent-initiated commerce specifications inside its Payments Technical Working Group, chaired by members from Mastercard and Visa. Google contributed AP2 and Mastercard contributed Verifiable Intent as the initial technical foundation for that work.

The third donation, and the one that broke the pattern

Three of the standards this site tracks have now left the company that created them. The dates make the trend hard to miss.

StandardCreated byDonated toDate
A2AGoogleLinux Foundation23 Jun 2025
MCPAnthropicAgentic AI Foundation (Linux Foundation)9 Dec 2025
AP2GoogleFIDO Alliance28 Apr 2026

The first two went to the Linux Foundation. The third did not, and that is the part worth thinking about rather than filing under another donation.

The Linux Foundation is where open-source implementations converge: it hosts the code, the governance is maintainer-led, and its centre of gravity is developers. The FIDO Alliance is a different animal. It publishes open technical specifications, but it also certifies interoperable products and runs market enablement programmes. It is the body that made passkeys work at internet scale. Its members are banks, networks, platforms and security vendors.

So AP2 did not move to a code foundation. It moved to a certification-and-trust body whose payments working group is chaired by Mastercard and Visa.

Why the card networks wanted this layer

We wrote in June that the networks were claiming the acceptance and trust layer above the open protocols rather than competing with them. The FIDO move is the same strategy expressed through governance rather than product.

Think about what AP2 actually decides. It does not move money and it does not run a checkout. It answers one question: can this agent prove that a human authorized this specific spend, under these limits? That is an authorization and evidence problem, not a transport problem. It is also precisely the question a card network has spent decades answering for human-initiated payments, and the question a regulator will ask first when an agent-initiated charge is disputed.

Mastercard is explicit about the framing. Pablo Fourez, its Chief Digital Officer, described the goal as creating a shared record of user intent that the entire payments ecosystem can rely on. A shared record of intent is a chargeback defence, an audit trail and a liability allocation, all at once. Whoever standardizes it sets the terms of the dispute.

What FIDO says it will build

The Alliance framed the work around three areas, which is a useful map of where the gaps are:

  • Verifiable user instructions, so a user can authorize an agent through phishing-resistant mechanisms without exposing credentials.
  • Agent authentication, so a service can verify that an agent is acting for an authenticated user and inside defined parameters, and tell a legitimate agent from an unauthorized one.
  • Trusted delegation for commerce, so agent-initiated transactions execute inside user-controlled boundaries with verifiable authorization.

Andrew Shikiar, the Alliance executive director and CEO, put the motivation plainly: To scale this safely, people need to trust that these actions are secure, authorized and truly reflect their intent. The press release also cites a McKinsey estimate that agentic commerce could reach five trillion dollars globally by 2030 as the reason the timeline is tight. Treat that figure as what it is, an analyst projection quoted by an interested party, not a measurement.

Human Not Present, the technical change that will matter

AP2 v0.2 is easy to skim past, and it should not be. The headline addition is Human Not Present payments: an agent executing a payment autonomously, on the strength of instructions the user pre-authorized, with no human at the moment of purchase.

Every fraud and liability model in card payments is built on a distinction between card present and card not present. Human Not Present is a third category, and it does not fit either. The user was present when they granted the mandate, and absent when the money moved. That is a new question for issuers, acquirers and regulators, and the FIDO working groups now own it.

What to do with this

If you are choosing what to implement, the practical read is narrow but useful. Governance is a durability signal, not a feature. A protocol governed by one vendor can be redirected by that vendor, as ACP and Instant Checkout demonstrated in March 2026. A protocol under a multi-vendor body with certification machinery is a safer multi-year bet, even when the specification text is identical.

For the authorization layer specifically, the direction of travel is now clear enough to plan around: the standard will be shaped inside FIDO, with Mastercard and Visa in the chairs, and it will converge with the networks own trust products such as Visa TAP and Mastercard Agent Pay. Build for a world where proving intent is a compliance requirement rather than a differentiator.

For a broader view of how the layers fit together, see how AI agents pay and the full standards comparison.

Frequently asked questions

Who owns AP2 now?
The FIDO Alliance. Google announced the donation on 28 April 2026, stating that transferring ownership keeps AP2 platform-agnostic and community-led. The specification work continues inside the FIDO Alliance Payments Technical Working Group.
What is in AP2 v0.2?
Released the same day on GitHub, v0.2 adds Human Not Present payments: an agent can execute a payment autonomously from pre-authorized user instructions. Google gives the example of securing a limited-run ticket the moment it goes on sale.
What is Verifiable Intent?
A Mastercard framework co-developed with Google and designed to work with AP2. It creates a tamper-proof record of user-authorized agent actions. Mastercard contributed it to the FIDO Alliance alongside AP2.
Does this change anything for a merchant today?
Not in your integration, no. The specification is the same and the GitHub repository is the same. What changes is the risk profile: a protocol under multi-vendor governance is less likely to be retired or unilaterally redirected by a single company. That is a reason to weight AP2 more heavily in a multi-year plan.
Why does it matter that FIDO is not the Linux Foundation?
Both are credible neutral homes, but they optimize for different things. The Linux Foundation is where open-source implementations converge. FIDO certifies interoperable products and its payments group is chaired by Mastercard and Visa, so the incumbents shape the authorization layer from inside rather than from a competing standard.

Stay current on the standards

A note when a standard moves (ACP, UCP, AP2, MCP, x402). No spam.

Unsubscribe anytime.