Agentic Commerce: When the Buyer Is Software
Agentic Commerce: When the Buyer Is Software
For thirty years, every payment innovation assumed the same thing: a human at the moment of purchase. That assumption just expired. AI agents can now discover, compare, and complete purchases on a person's behalf — Visa wired its network into ChatGPT in June, Mastercard's first agentic transaction cleared its network last fall, and a machine-to-machine micropayment economy is forming underneath both. This report maps the architecture, the land grab, the unresolved liability gap, and what merchants should actually do about it.
In this report
The core thesis
Agentic commerce is not a new checkout button; it's a new party to the transaction. When software initiates a purchase on instructions given hours or weeks earlier, the foundational question of payments — is this transaction authorized? — splits in two: is the credential valid, and is the agent operating with legitimate authority? Answering that second question requires infrastructure that didn't exist two years ago: agent identity, scoped permissions, machine-readable consent, and dispute attribution for purchases no human clicked.
Our thesis is that this identity-and-trust layer — not the shopping experience — is where the economics will concentrate. The card networks understand this perfectly, which is why Visa and Mastercard are racing to make their token infrastructure the recognition layer every agent transaction must pass through: whoever authenticates the agents taxes the flow. Consumer demand is real but gated by trust — surveys show roughly 45% of consumers comfortable letting agents purchase for them while 95% hold at least one concern — and the binding constraint is not technology but the unresolved question of who eats the loss when an agent errs. Our view: agentic commerce follows the adoption arc of e-commerce itself — trust infrastructure first, habit second, volume third — with McKinsey-scale projections (as much as $1 trillion in US agent-driven transactions by 2030) plausible as a destination and aggressive as a timeline.
The question that built the card networks was "is this card real?" The question that builds the next layer is "is this buyer real — and is it allowed to be buying this?" The second question is worth as much as the first was.
What changed, concretely
The timeline compressed dramatically over fourteen months. Mastercard announced Agent Pay in April 2025 — with Microsoft, IBM, and payment-infrastructure partners — and its CEO confirmed the first agentic transaction on its network in Q3 2025. Visa built Intelligent Commerce: scoped tokenized credentials, agent-aware authentication, a Trusted Agent Protocol for distinguishing legitimate agents from malicious bots, and a partner roster spanning the major AI platforms. Google shipped an open agent-payments protocol (AP2) with dozens of partners including the networks themselves; OpenAI co-developed a checkout protocol with Stripe, whose shared payment tokens now interoperate with both networks' frameworks. Then in June 2026, Visa announced its OpenAI integration — embedding tokenization, agent identification, real-time authorization, and fraud monitoring directly into ChatGPT's commerce experiences — days after Mastercard expanded its merchant-facing Agent Suite. Agents that could only recommend in 2024 can now, with permission, transact.
The token architecture: identity for software
The technical foundation is an evolution of the tokenization the networks built for mobile wallets — with the token's job expanded from hiding the card number to encoding the relationship. An agentic token binds together: the underlying credential (never exposed to the agent or merchant), the specific agent authorized to use it, the scope (merchant categories, specific merchants, even a single trip window), the limits (spend caps, transaction counts, expiration), and the consent policy the owner set. A grocery agent's token cannot book flights; a $200-cap token cannot clear $500; and revocation is instant — pull the authorization and the next attempt dies at the network. Consent flows, biometric confirmation, and behavioral risk signals wrap around the token, and agent identity travels in the transaction record so a dispute can later establish which software did what under whose permission.
This is, notably, the same intellectual move we've tracked across modern risk infrastructure — from synthetic-identity defense to cash-flow underwriting: trust shifting from static artifacts to verified behavior and scoped permissions. The agent economy simply makes the shift explicit, because with software there was never an artifact to trust in the first place.
The land grab: networks, platforms, protocols
Four layers are being contested simultaneously, and the strategic map matters more than any single announcement:
| Layer | Who's fighting | The prize |
|---|---|---|
| Agent platforms | OpenAI, Google, Anthropic, Microsoft, Perplexity | Owning the consumer relationship where intent forms |
| Protocols | Google's AP2/UCP, OpenAI–Stripe's checkout protocol, Visa's Trusted Agent Protocol | Setting the standard everyone must speak |
| Network trust layer | Visa Intelligent Commerce vs. Mastercard Agent Pay | Being the credential every agent transaction must pass |
| Processing & risk | Stripe, processor platforms, bot-verification and fraud vendors | Routing, verifying, and pricing the new risk |
Two observations cut through the noise. First, the networks are playing the same game that won them the last era: don't own the interface, own the trust toll beneath every interface — which is why both have partnered with essentially every AI platform rather than picking champions. Second, the early interoperability signals are genuinely encouraging: the major protocols are converging (the networks joined Google's open protocol; Stripe's tokens speak to both networks), suggesting the ecosystem learned from past format wars that fragmentation starves everyone. For the incumbents this is offense and defense — the rewards-and-chargebacks moat we analyzed in the pay-by-bank report must be rebuilt for buyers who feel no loyalty to points, and the networks would rather rebuild it themselves than let someone else.
The second economy: machine-to-machine payments
Beneath consumer agentic shopping, a stranger and possibly larger economy is forming: machines paying machines. Agents consuming APIs, data, and compute need to settle constantly, instantly, and in fractions of a cent — a shape of payment card rails never served. Mastercard's June 2026 Agent Pay for Machines targets exactly this: high-frequency, low-value, programmatic payments with credentialing and guaranteed settlement across multiple payment types. Meanwhile crypto-settled micropayment rails have already demonstrated the demand at startling scale — one open protocol reported over 169 million machine payments in its first year, settling in a few hundred milliseconds for fractions of a cent, overwhelmingly agents buying compute, data, and API calls. The honest read: consumer agentic purchases are settling on card rails (protections, disputes, habit), machine-to-machine flows are gravitating to instant programmatic rails — and the networks, tellingly, are investing to straddle both rather than defend one. The boundary between those two worlds is where the next decade's payment margins will be decided.
The liability gap
Now the unglamorous problem that will actually determine adoption speed. Chargeback rules — the consumer-protection machinery we detailed in the chargeback playbook — assume a human pressed the button. When an autonomous agent buys the wrong thing, the liability chain among agent platform, merchant, issuer, and consumer is, in the candid words of industry practitioners, not yet settled. The networks' frameworks preserve chargeback rights and encode agent identity for attribution, which is the right foundation — fifty years of dispute machinery is precisely the asset instant, irreversible alternatives lack — but the allocation rules are being written in real time. Industry research consistently ranks trust and liability, not technical capability, as the number-one barrier; and there is a real risk that small merchants absorb a disproportionate share of early agent-error disputes while the rules crystallize. Watch the first wave of agent-purchase dispute rulings the way one watched early e-commerce fraud-liability shifts: the side that ends up holding agent risk will shape who deploys agents, and how cautiously.
What merchants should build now
- Machine-readable everything. Agents buy what they can parse: clean structured product data, accurate availability and pricing feeds, schema-marked content. Being unreadable to agents will increasingly mean being invisible to their owners' money.
- Agent-verified payment acceptance. As processors expose network agent frameworks, support them — a merchant that can distinguish a credentialed agent from a scraper both captures the sale and blocks the abuse.
- Dispute-ready documentation. Agent transactions carry identity and consent metadata; merchants who capture and store it will win the disputes the era's ambiguity will generate.
- Fraud posture upgraded for machine speed. The same AI-vs-AI arms race running through fraud generally now runs through checkout: legitimate agents, malicious bots, and everything between arrive at machine velocity, and static defenses won't hold.
- No premature bets. Interoperability momentum means merchants needn't pick a protocol winner — build the clean data layer and the verified-payment capability, and let the standards fight resolve above you.
Scenarios and what we're watching
| Scenario | Shape of the world | Signposts |
|---|---|---|
| Base case — trust-gated ramp | Agent purchases grow steadily in structured categories (reorders, travel, subscriptions); liability rules crystallize by precedent; card rails hold consumer flows while machine payments boom separately | Dispute-rule announcements; agent share of e-commerce in reorder categories; machine-payment volume growth |
| Bull case — the interface flip | Agents become the default shopping interface for a major consumer segment; merchant discovery reorients from search ads to agent legibility; the trillion-dollar 2030 projections land on schedule | ChatGPT/assistant commerce conversion data; merchant structured-data adoption surging; ad-spend migration |
| Bear case — the trust stall | High-profile agent-error and agent-fraud incidents freeze consumer delegation; frameworks retreat to human-confirmation for every purchase; agentic commerce plateaus as assisted (not autonomous) shopping | Publicized agent-purchase failures; issuers tightening agent-token issuance; consumer-comfort surveys rolling over |
What we're watching: the liability allocations in early dispute rulings (the whole game); agent-initiated share of transactions in reorder-heavy categories (the leading adoption edge); the machine-payment volume curve (the second economy's pulse); consumer-comfort survey trends against the 45/95 baseline; and whether the interoperability consensus holds or fractures into walled gardens. The deepest continuity is worth stating plainly: every era of payments has been won by whoever made strangers safe to transact with. The stranger, this time, is software — and the trust business is being built, at speed, right now.
Frequently asked questions
Commerce in which an AI agent — not a human at checkout — discovers, compares, and completes purchases on someone's behalf within permissions they set. It became production reality across 2025–2026 as card networks, AI platforms, and processors shipped frameworks for authenticating agents and authorizing agent-initiated payments.
Through scoped, tokenized credentials rather than raw card numbers: a token bound to a specific agent, merchant scope, spend limit, and consent policy — revocable instantly. Visa Intelligent Commerce and Mastercard Agent Pay (Agentic Tokens) are the flagship network implementations.
The great unresolved question. Frameworks preserve chargeback rights and encode agent identity for attribution, but liability allocation among agent platform, merchant, issuer, and consumer is still being worked out — and research consistently ranks trust and liability as the top adoption barrier.
Yes, at the infrastructure level: machine-readable product data, agent-verified payment acceptance as processors expose it, bot verification, and dispute-ready documentation. No need to bet on a protocol winner — the standards are converging — but agents can't buy what they can't parse.
Key takeaways
- Agentic commerce adds a new party to the transaction — and splits "authorized?" into credential and agent authority.
- Scoped agentic tokens encode agent, merchant scope, limits, and consent — trust as permissions, not artifacts.
- The networks are racing to own the trust toll beneath every AI interface; interoperability is (so far) winning.
- A machine-to-machine micropayment economy is forming beneath consumer flows — different rails, different physics.
- Liability, not technology, gates adoption; merchants should build legibility and verification now.
Keep reading
This report is for general information only and does not constitute financial, legal, or investment advice. Product names, partnership details, and statistics are drawn from publicly reported sources and evolve rapidly in this market.