AP2 has left Google: what FIDO governance changes
Published . Every claim links to a primary source.
Short answer: On 28 April 2026, Google donated the Agent Payments Protocol to the FIDO Alliance and released AP2 v0.2 the same day. AP2 is the third agentic standard to leave the vendor that created it, after MCP and A2A. The detail that matters is where it went. MCP and A2A went to the Linux Foundation, an open-source foundation. AP2 went to FIDO, an authentication standards body whose Payments Technical Working Group is chaired by Mastercard and Visa. The layer that decides whether an agent was authorized to spend your money is now being standardized by the card networks.
What actually happened on 28 April 2026
Two announcements landed the same day, and they are best read together.
Google published a short post from Stavan Parikh, VP and GM of Payments, announcing that it was donating the Agent Payments Protocol to the FIDO Alliance. Its stated reason: transferring ownership ensures AP2 remains platform-agnostic and community-led, while accelerating adoption of secure agentic payments
. The same post announced AP2 v0.2 on GitHub, and mentioned Verifiable Intent, an AP2-compatible standard co-developed with Mastercard that is also being donated to FIDO.
The FIDO Alliance published the fuller picture. It is not simply accepting a repository. It formed an Agentic Authentication Technical Working Group, chaired by members from CVS Health, Google and OpenAI, and vice-chaired by members from Amazon, Google and Okta. In parallel, it is developing agent-initiated commerce specifications inside its Payments Technical Working Group, chaired by members from Mastercard and Visa. Google contributed AP2 and Mastercard contributed Verifiable Intent as the initial technical foundation for that work.
The third donation, and the one that broke the pattern
Three of the standards this site tracks have now left the company that created them. The dates make the trend hard to miss.
| Standard | Created by | Donated to | Date |
|---|---|---|---|
| A2A | Linux Foundation | 23 Jun 2025 | |
| MCP | Anthropic | Agentic AI Foundation (Linux Foundation) | 9 Dec 2025 |
| AP2 | FIDO Alliance | 28 Apr 2026 |
The first two went to the Linux Foundation. The third did not, and that is the part worth thinking about rather than filing under another donation
.
The Linux Foundation is where open-source implementations converge: it hosts the code, the governance is maintainer-led, and its centre of gravity is developers. The FIDO Alliance is a different animal. It publishes open technical specifications, but it also certifies interoperable products and runs market enablement programmes. It is the body that made passkeys work at internet scale. Its members are banks, networks, platforms and security vendors.
So AP2 did not move to a code foundation. It moved to a certification-and-trust body whose payments working group is chaired by Mastercard and Visa.
Why the card networks wanted this layer
We wrote in June that the networks were claiming the acceptance and trust layer above the open protocols rather than competing with them. The FIDO move is the same strategy expressed through governance rather than product.
Think about what AP2 actually decides. It does not move money and it does not run a checkout. It answers one question: can this agent prove that a human authorized this specific spend, under these limits? That is an authorization and evidence problem, not a transport problem. It is also precisely the question a card network has spent decades answering for human-initiated payments, and the question a regulator will ask first when an agent-initiated charge is disputed.
Mastercard is explicit about the framing. Pablo Fourez, its Chief Digital Officer, described the goal as creating a shared record of user intent that the entire payments ecosystem can rely on
. A shared record of intent is a chargeback defence, an audit trail and a liability allocation, all at once. Whoever standardizes it sets the terms of the dispute.
What FIDO says it will build
The Alliance framed the work around three areas, which is a useful map of where the gaps are:
- Verifiable user instructions, so a user can authorize an agent through phishing-resistant mechanisms without exposing credentials.
- Agent authentication, so a service can verify that an agent is acting for an authenticated user and inside defined parameters, and tell a legitimate agent from an unauthorized one.
- Trusted delegation for commerce, so agent-initiated transactions execute inside user-controlled boundaries with verifiable authorization.
Andrew Shikiar, the Alliance executive director and CEO, put the motivation plainly: To scale this safely, people need to trust that these actions are secure, authorized and truly reflect their intent.
The press release also cites a McKinsey estimate that agentic commerce could reach five trillion dollars globally by 2030 as the reason the timeline is tight. Treat that figure as what it is, an analyst projection quoted by an interested party, not a measurement.
Human Not Present, the technical change that will matter
AP2 v0.2 is easy to skim past, and it should not be. The headline addition is Human Not Present payments: an agent executing a payment autonomously, on the strength of instructions the user pre-authorized, with no human at the moment of purchase.
Every fraud and liability model in card payments is built on a distinction between card present and card not present. Human Not Present is a third category, and it does not fit either. The user was present when they granted the mandate, and absent when the money moved. That is a new question for issuers, acquirers and regulators, and the FIDO working groups now own it.
What to do with this
If you are choosing what to implement, the practical read is narrow but useful. Governance is a durability signal, not a feature. A protocol governed by one vendor can be redirected by that vendor, as ACP and Instant Checkout demonstrated in March 2026. A protocol under a multi-vendor body with certification machinery is a safer multi-year bet, even when the specification text is identical.
For the authorization layer specifically, the direction of travel is now clear enough to plan around: the standard will be shaped inside FIDO, with Mastercard and Visa in the chairs, and it will converge with the networks own trust products such as Visa TAP and Mastercard Agent Pay. Build for a world where proving intent is a compliance requirement rather than a differentiator.
For a broader view of how the layers fit together, see how AI agents pay and the full standards comparison.
Frequently asked questions
Who owns AP2 now?
What is in AP2 v0.2?
What is Verifiable Intent?
Does this change anything for a merchant today?
Why does it matter that FIDO is not the Linux Foundation?
Stay current on the standards
A note when a standard moves (ACP, UCP, AP2, MCP, x402). No spam.