Visa TAP
Trusted Agent Protocol — the authentication layer for agentic commerce. Scored under the LISR Agentic Custody Readiness (ACR) framework. Assessed against Linkmerica's dated monitoring record, June 11 – July 12, 2026.
ACR Score
HIGH RISK| ACR Category | Score | Risk Bar |
|---|---|---|
| Session Key Support | 7.5 | |
| Programmable Guardrails | 7.0 | |
| Audit Log Generation | 6.5 | |
| Multi Party Approval | 7.5 | |
| Protocol Compatibility | 8.0 | |
| Quantum Resistance Readiness | 6.9 |
Six structural agentic custody properties. Category weights and internal scoring math are proprietary.
- Visa's sole agent key directory is a documented architectural single point of failure — the federated model was designed but remains unimplemented as of July 2026
- One long-lived cryptographic key per agent with no disclosed session-key, time-scoping, or automatic expiration mechanism
- Protocol does not enforce spend limits, velocity controls, or transaction-type restrictions — guardrails are delegated to merchant-side implementation
- No independent third-party security audit of TAP's cryptographic implementation found in the monitoring record
- No disclosed post-quantum cryptography roadmap — EMV 3DS heritage predates NIST PQC standards
- Regulatory frameworks for agent-initiated transaction disputes remain undeveloped; chargeback liability shift exists but agent accountability is unclear
- TAP protocol specification is publicly available on GitHub, enabling independent technical review and community audit
- 100+ global partners and 20+ live production integrations, including tier-1 processors (Fiserv, Stripe, Adyen, Worldpay), demonstrate operational maturity
- Akamai edge security integration (December 2025) provides CDN-layer dual-identity verification as defense-in-depth
- Chargeback liability shift mechanism, mirroring the established 3DS framework, incentivizes merchant-side security investment
Analyst Assessment
This is the third ACR score published under LISR v1.0 (AP4M: 6.9/HIGH July 8; AP2: 6.4/HIGH July 13) and reflects monitoring from June 11 through July 12, 2026. Visa TAP scores 7.2/HIGH, materially higher than AP2 despite TAP's production maturity and open-source specification. The elevated risk stems not from undisclosed controls (the primary driver of AP4M and AP2 scores) but from a documented, named architectural single point of failure: Visa's centralized agent key directory. The original TAP specification described a federated directory model that remains unimplemented 13+ months into production deployment. TAP also lacks session-key-equivalent mechanisms (unlike AP2's Intent Mandates) and protocol-native guardrails, relying instead on persistent per-agent keys and merchant-side policy enforcement. The concentration of key issuance, revocation authority, and operational continuity in a single entity creates custody risk qualitatively distinct from distributed or undisclosed models. Enterprises adopting TAP for agentic commerce should architect compensating controls for directory dependency, implement external approval workflows, and monitor Visa's federated directory roadmap closely.
What this score does not mean: LISR assesses documented and disclosed controls. It cannot detect undisclosed implementation defects. See what a tier does not mean.