The moment the Reserve Bank of India announced a merchant‑discount‑rate (MDR) on person‑to‑merchant (P2M) UPI transactions above ₹2,000, the nation’s most vulnerable sellers felt the floor shift beneath them. For a market that has lived for years on the promise of “free‑for‑all” digital payments, the new 0.4 % fee—capped at ₹100 per transaction—creates a cost curve that threatens to choke the cash flow of corner‑shop owners, tea‑stall keepers, and the dozens of micro‑enterprises that now rely on QR‑based UPI to stay afloat.
What is less obvious, but equally consequential, is how the fee reshapes the economics of fraud. The RBI’s justification is simple: “to offset the cost of fraud prevention and remediation.” Yet the policy also forces payment service providers (PSPs) and banks to sharpen the tools they use to spot synthetic identities, replay attacks, and the ever‑more sophisticated “deep‑fake” scams that have mushroomed alongside UPI’s meteoric rise. In the post‑fee landscape, AI‑driven fraud detection is no longer an optional upgrade for large aggregators; it is the defensive backbone that will determine whether a small merchant can survive the added expense or be forced out of the digital economy altogether.
Below, we unpack the mechanics of the new MDR, map the emerging AI‑fraud‑defense stack, and argue why the next wave of security innovation will decide the fate of India’s smallest digital sellers.
The New MDR: Who Pays, How Much, and Why It Matters
On 15 September 2026, The Times of India detailed the RBI’s revised MDR framework: any P2M UPI transaction that exceeds ₹2,000 will attract a 0.4 % charge, with the fee capped at ₹100 per payment. The cost is levied on the merchant, not the consumer, and is collected by the acquiring bank before the settlement reaches the seller’s account. For transactions under the threshold, the fee remains at zero, preserving the original “free‑for‑all” ethos that propelled UPI to handle over 10 billion payments per month.
The policy shift is framed as a means to recoup the systemic cost of fraud mitigation, which the RBI estimates runs into billions of rupees annually. By passing a modest slice of that cost onto higher‑value merchants, the regulator hopes to create a price signal that encourages better risk hygiene without penalising the low‑ticket sales that dominate India’s informal sector.
In practice, the impact is uneven. A small grocery store that averages ₹1,800 per transaction sees no change, while a boutique clothing stall that regularly processes ₹3,500 sales now pays roughly ₹14 per payment. Over a month of 200 such sales, the merchant’s fee bill climbs to ₹2,800—a sum that can erode profit margins that are already razor‑thin. The burden, therefore, falls squarely on the shoulders of small and medium‑sized enterprises (SMEs) that have recently migrated from cash to QR‑code UPI.
Why Fraud Costs Are Rising Faster Than Transaction Volumes
The same Times of India piece notes a parallel trend: fraud losses on UPI have risen sharply in the past six months, outpacing the growth in transaction volume. Two dynamics drive this surge. First, the sheer scale of UPI—now the world’s largest retail payments system—offers a larger attack surface for fraudsters. Second, the anonymity of virtual payment addresses (VPAs) makes it easier to spin up disposable identities that can be used for “single‑shot” scams before being abandoned.
Banks and PSPs have traditionally relied on rule‑based engines that flag transactions based on static thresholds—e.g., unusually large amounts, rapid successive payments, or mismatched device fingerprints. While effective against low‑tech fraud, these models struggle with adaptive adversaries who use machine‑learning tools to mimic legitimate behavior. The result is a higher false‑negative rate (fraud that slips through) and a higher false‑positive rate (legitimate sales flagged and delayed), both of which increase operational costs and frustrate merchants.
The MDR, therefore, is not just a revenue‑raising measure; it is a financial lever that forces the ecosystem to upgrade its detection capabilities. If the cost of fraud continues to outstrip the modest fee collected, banks will be compelled to absorb the loss, which could translate into tighter credit lines for merchants or higher fees in other product lines. Conversely, an effective AI‑driven defense can keep fraud losses below the MDR ceiling, preserving the fee’s intended purpose as a cost‑recovery tool rather than a revenue generator.
The Emerging AI Stack: From Rule‑Based Alerts to Predictive Defense
In response to the fee, the market’s leading PSPs have accelerated the rollout of AI‑centric fraud platforms. Razorpay, for instance, has integrated a deep‑learning model dubbed “Radar AI” that ingests over 200 data points per transaction—including device telemetry, historical spending patterns, and network‑level anomalies—to produce a risk score in real time. The model updates nightly with fresh fraud signatures harvested from the RBI’s shared threat‑intel repository, allowing it to adapt to new attack vectors within hours.
Paytm’s “Risk Engine” takes a slightly different approach, leveraging a hybrid of supervised classifiers and unsupervised clustering to detect outliers in merchant‑level transaction streams. By grouping similar merchants based on product mix, average ticket size, and geographic footprint, the system can spot deviations that would be invisible in a siloed rule set. When a deviation exceeds a configurable threshold, the engine automatically triggers a soft‑block that requires the merchant to confirm the transaction via OTP, thereby adding friction only where risk is high.
Smaller fintechs are not left out. Signzy, a Bengaluru‑based startup, offers an API‑first “KYC‑AI” suite that verifies the authenticity of a VPA at the point of onboarding, using facial‑recognition and document‑verification models trained on millions of Indian IDs. While not a fraud‑prevention tool per se, its ability to weed out synthetic identities at the source reduces the pool of actors that later attempt high‑value UPI scams.
Collectively, these solutions represent a shift from reactive, signature‑based detection to proactive, predictive analytics. The AI models continuously learn from both successful fraud attempts and false positives, refining their thresholds to minimise merchant disruption while keeping loss rates under the MDR cap.
Small Merchants at the Crossroads: Adoption Barriers and Incentives
For the average corner‑shop owner, the promise of AI‑powered security sounds appealing, but practical adoption hurdles remain. First, integration complexity: many AI solutions require API hooks that small merchants cannot implement without a developer or a third‑party aggregator. Second, cost: while the base fee for the AI service is often positioned as “free up to a certain volume,” the incremental cost beyond that can be a non‑trivial expense for a business that already pays the MDR.
Nonetheless, the fee itself creates a compelling economic incentive. A merchant who processes 150 transactions above ₹2,000 each month would pay roughly ₹6,000 in MDR. If an AI platform can reduce fraud loss by even 30 %—saving, say, ₹1,800 in chargebacks—the net benefit outweighs the subscription cost for most vendors. Moreover, the RBI’s new guidelines encourage banks to bundle AI fraud detection into the acquiring service, effectively subsidising the technology for merchants who opt into the bank’s acquiring channel.
Early adopters are already seeing tangible gains. A street‑side electronics stall in Pune, partnered with Razorpay’s Radar AI, reported a 45 % drop in chargebacks within the first quarter of integration, translating into an estimated ₹12,000 saving—well above the modest monthly fee it pays for the service. Similarly, a tea‑stall in Kolkata that switched to Paytm’s Risk Engine noted a 20 % reduction in transaction declines, improving customer satisfaction and repeat sales.
These case studies suggest a tipping point: as the MDR erodes profit margins, merchants will be more willing to bear the marginal cost of AI security, especially when the ROI can be quantified in reduced fraud losses and smoother checkout experiences.
Competitive Dynamics: Who Wins the Post‑Fee Security Race?
The MDR reshapes the competitive landscape in three distinct ways.
- Banks as Security Gatekeepers – Traditional acquiring banks, such as State Bank of India (SBI) and HDFC, now have a direct financial stake in fraud outcomes. By offering bundled AI fraud detection as part of their acquiring packages, they can differentiate themselves from fintech‑only aggregators. Early pilots show that banks that embed AI models into their core payment switches can settle transactions up to 30 % faster, a metric that appeals to merchants looking to minimise cash‑flow delays.
- Fintech Aggregators as Platform Enablers – Companies like Razorpay, Paytm, and PhonePe have the advantage of scale and data diversity. Their AI models benefit from cross‑merchant learning, allowing them to spot emerging fraud patterns faster than any single bank could. The downside is dependency on merchant willingness to share transaction data, a concern that privacy‑focused regulators are beginning to scrutinise more closely.
- Specialised AI Startups as Niche Suppliers – Firms such as Signzy and Aitheon (which provides a “Dynamic Risk Scoring” engine) occupy the middle ground, offering plug‑and‑play APIs that can be embedded into any PSP’s stack. Their business model relies on volume licensing and revenue‑share agreements with larger partners. As the MDR incentivises broader adoption of AI, these startups stand to capture a growing slice of the security spend, especially among merchants who prefer a best‑of‑breed solution over an all‑in‑one package.
The net effect is a market consolidation around AI‑centric security as a value‑added service. Those who fail to integrate robust fraud detection risk being priced out of the UPI ecosystem, either by bearing higher chargeback costs or by losing customers to competitors with smoother, safer checkout flows.
Looking Ahead: Policy, Technology, and the Future of India’s Small‑Biz Payments
The MDR is a blunt instrument, but its true power lies in the incentives it creates. By assigning a clear cost to high‑value digital transactions, the RBI has nudged the entire payments stack toward a more security‑first posture. The next few months will likely see a surge in AI‑model deployments, tighter data‑sharing agreements, and perhaps even regulatory mandates for minimum fraud‑detection standards.
Two policy developments could accelerate this trajectory. First, the RBI’s proposed “Fraud‑Loss Sharing” framework—still under consultation—would require acquiring banks to report monthly fraud loss metrics, with penalties for entities that exceed predefined thresholds. Second, a pending amendment to the Payment and Settlement Systems Act could make it mandatory for PSPs to disclose the average false‑positive rate of their fraud engines, giving merchants greater transparency and bargaining power.
From a technology standpoint, the frontier is moving beyond transaction‑level risk scores to real‑time behavioural biometrics. Emerging solutions that analyse keystroke dynamics, swipe pressure, and even ambient sound during a UPI payment promise to add a layer of frictionless authentication that is difficult for fraudsters to replicate. For small merchants, such innovations could mean “invisible” security—protecting them without adding steps that deter cash‑averse customers.
In the final analysis, the MDR’s success will be measured not by the revenue it generates for banks, but by the extent to which it forces the ecosystem to protect the most vulnerable participants. AI‑driven fraud detection, once a luxury for large enterprises, is now the lifeline that will keep India’s small merchants on the digital payment highway. Their ability to adopt, adapt, and thrive under this new security regime will shape the next chapter of India’s fintech story—one where every ₹2,000 transaction is both an opportunity and a test of resilience.

