Mastercard to enable offline payments across Europe

xxx

Mastercard is now also taking action, stating that from February 2027 all newly issued cards across Europe will be enabled to make offline payments. By May 2027, all new and replacement payment terminals will also be required to support them.

Once the requirements are implemented across Europe, people will be able to use chip and PIN during an outage to pay for essentials at supermarkets, grocery stores, service stations and pharmacies, as well as at travel and ticket machines.

The online payments work by securely storing spending limits on a card’s chip. If a terminal loses its connection, the transaction can be approved locally, up to a limit of €200 set in advance by the cardholder’s bank. It is then submitted for clearing when the connection is restored.

The European rollout comes after successful implementation in Denmark, Sweden, Estonia and Latvia.

From: Mastercard to enable offline payments across Europe.

xxx

POST The Mathocalypse

I apologise for forgetting who it was who pointed me to this piece on the massive pile of mathematical proofs rleased by AI behmoths in recent weeks. I book marked it but only just got round to reading it. Even if you are not interested in mathmatics, the article raises some interesting questions.

The question that caught my eye was this: where’s the cryptography? Cryptography is a subfield that was extremely conspicuous by its absence from OpenAI’s list of 376 papers. The articles goes on to say that sources suggest that Big AI has begun discreetly investigating whether their latest internal models can break important cryptographic protocols.

 

Which brings me back to the lack of proofs about cryptography in the public releases. If your AI could break importsant cryptographic protocols, why would you tell anyone?

This is the “Zimmermann telegram” problem, well-known in security circles and something that I have written about before. Long story short, in 1917 while Britain was trying to persuade the U.S. to join the war against Germany, the German Foreign Secretary, Arthur Zimmermann, sent a telegram to the German ambassador in Mexico, Heinrich von Eckardt. The telegram instructed the ambassador to approach the Mexican government with a proposal to form a military alliance against America. It promised Mexico the land acquired the United States after the U.S.-Mexican War if they were to help Germany win the war. The telegram was encrypted, but as ithappens the British had already broken the code that the Germans used. The message was intercepted, decrypted and put on the desk of the British Foreign Secretary Arthur Balfour.

But what could he do with the information? Or, in more general terms, how can an attacker use intercepted information without revealing that there is a security flaw and that you have exploited it? Consider the options:

If the British had complained to the Germans, then the Germans would know that the British had the key to their code and they would switch to another code that the British might not be able to break for months, missing much vital military intelligence along the way. What’s more, the Americans would know that the British were tapping diplomatic traffic into the U.S.

If they did not reveal the contents, they might miss a the chance to bring the U.S. into the war.

Well, British Naval Intelligence’s clever solution was to leak the information in such a way as to make it look as if the leak had come from the Mexican telegraph company: since the German relay from Washington to Mexico used a different code, that the Americans already knew to be broken, this was entirely plausible and it had the desired outcome. On 29th March 1917, Zimmermann gave a speech confirming the text of the telegram. On April 2nd, President Wilson asked Congress to declare war on Germany, and on April 6th they complied.

The point of this story is that while stupid AI might reveal its hand, clever AI will not. Talk about an arms race. Let’s hope that our side’s AI gets there first.

Japan declares cyber space emergency as attacks soar

xxx

Japan’s financial services regulator has warned banks not to accept driving licences as proof of identity to open new accounts as the country reels from a series of cyber attacks that have hit rail operators, car manufacturers, karaoke chains and even the police.

The spiralling crisis prompted the ruling Liberal Democratic Party to convene an emergency meeting of the National Cybersecurity Strategy Headquarters on Friday, following reports of hacks at dozens of the country’s leading brands from car rental operator Times Car to convenience store chain Lawson as well as hospitals and other government facilities.

More than 20 major companies from barbecue chains to discounters have reported cyber attacks in recent weeks, warning that tens of millions of pieces of customer data may have been leaked.

The increasing frequency of the attacks has prompted alarm at the highest levels of the Japanese government. Masaaki Taira, head of the NCSH, declared that Japan was in “a state of emergency in cyber space”. Japanese cyber security minister Toshiharu Furukawa said the situation was “extremely critical”.

From: Japan declares cyber space emergency as attacks soar.

xxx

The dictator’s laboratory: Nayib Bukele is pushing AI hard

xxx

His last big technological wager—making El Salvador the first country to adopt bitcoin as legal tender, in 2021—fizzled. Ordinary people found no use for it. Mr Bukele treated it as a personal project, memorably saying he bought it from the bathroom. No one knows what becomes of the country’s stash if and when he leaves power.

From: The dictator’s laboratory: Nayib Bukele is pushing AI hard.

xxx

(10) Stablecoins in the EU – by Noelle Acheson

I was watching a recent video of a conversation between two of the industry observers that I always pay attention to: Noelle Acheson and Marieke Flament. I subscribe to both of their substacks and always take their comments very seriously. Apart from very jealous of their ability to wear such a depth of knowledge so lightly, I found myself engrossed in their discussion about EU stablecoin evolution and, more specifically, what a modern “money stack” should look like.

Marieke made the point that (and I am paraphrasing here) wholesale central bank digital currency (CBDC)  is a basic and uncontroversial platform for the next generation of financial services.

The 2026 Global Payments Report | McKinsey

The McKinsey Global Payments Report 2026 talks about the “emerging control layer” for agentic commerce and sets out five key capabilities needed to capute value around that layer. These are:

Agent credentials: cryptographic identities that bind software agents to human or corporate principals, defining clear authority boundaries and enabling instant revocation
mandate and consent engines;

Standardized protocols that specify what an agent is permitted to execute, including spending caps, approved counterparties, and active expiration windows;

Runtime policy guardrails: granular spending rules enforced at runtime, such as velocity throttles and category restrictions;

Agent wallets: programmatic liquidity containers that enable autonomous agents to hold operating balances and execute micropayments within defined parameters.

Transaction dispute frameworks: recourse mechanisms and clear liability allocations when an agent executes a transaction that technically complies with its mandate yet conflicts with user intent.

These infrastructure components generate recurring per-mandate fees, API call pricing, and risk underwriting premiums rather than transaction volume basis points.

Market participants are establishing complementary protocols in different layers of the transaction stack. Card network initiatives such as Visa’s Trusted Agent Protocol and Mastercard Agent Pay focus on machine identity and network dispute rules. At the same time, application standards such as Google’s Agent Payment Protocol and the Stripe and OpenAI Agentic Commerce Protocol govern runtime checkout interactions.

From: The 2026 Global Payments Report | McKinsey.

xxx

xxx

Banks: Own trust & identity

Remember back in section 2, page 14 when McKinsey recommended banks own the Identity layer? Section 3, page 25 is the only other time they mention it:

“Issue verifiable machine credentials, manage delegated authorization and consent mechanisms, and actively shape industry standards before protocols become fixed.”
That may work in countries where the top 3-5 banks have ~90% share. They can coordinate to offer a shared credential based on their internal KYC. But in the US, the top 10 banks have <60% share with a long tail of thousands of banks. The big banks tried to create an identity bureau at EWS in 2015-2019, but never launched. I never knew why, but liability may have been a contributing factor.

For the US, this recommendation seems gratuitous. No bank has enough consumer DDA share to do this on their own and doing it as an industry already failed. Bringing in the long tail might take forever (e.g., Fednow, Zelle). The biggest eCommerce acquirers and the card networks might get there sooner. So might Apple, at least for iPhone users.

From: Assessing the McKinsey Global Payments Report.

xxx

Attorney General Bonta’s Sponsored Bill to Return Stolen Digital Assets to Victims Signed into Law | State of California – Department of Justice – Office of the Attorney General

xxx

This gives law enforcement a mechanism to return stolen cryptocurrency even when it has been commingled with other funds, as is common in multi-victim fraud schemes and organized money laundering investigations in California

From: Attorney General Bonta’s Sponsored Bill to Return Stolen Digital Assets to Victims Signed into Law | State of California – Department of Justice – Office of the Attorney General.

xxx

UK urged to act as Polymarket takes bets on whether HSBC and Lloyds will fail | Banking | The Guardian

xxx

However, academics have warned these platforms are creating a serious moral hazard, giving market participants “an incentive to engage in corrupt, illegal, or dangerous actions in order to rig the outcome of the contract”.

From: UK urged to act as Polymarket takes bets on whether HSBC and Lloyds will fail | Banking | The Guardian.

xxx

Assessing the McKinsey Global Payments Report

xxx

Banks: Own trust & identity

Remember back in section 2, page 14 when McKinsey recommended banks own the Identity layer? Section 3, page 25 is the only other time they mention it:

“Issue verifiable machine credentials, manage delegated authorization and consent mechanisms, and actively shape industry standards before protocols become fixed.”
That may work in countries where the top 3-5 banks have ~90% share. They can coordinate to offer a shared credential based on their internal KYC. But in the US, the top 10 banks have <60% share with a long tail of thousands of banks. The big banks tried to create an identity bureau at EWS in 2015-2019, but never launched. I never knew why, but liability may have been a contributing factor.

For the US, this recommendation seems gratuitous. No bank has enough consumer DDA share to do this on their own and doing it as an industry already failed. Bringing in the long tail might take forever (e.g., Fednow, Zelle). The biggest eCommerce acquirers and the card networks might get there sooner. So might Apple, at least for iPhone users.

From: Assessing the McKinsey Global Payments Report.

xxx

Design a site like this with WordPress.com
Get started