Thu. Oct 8th, 2026

What Is Agentic Commerce? AI Payments Explained

ByJohan Shamshad

October 8, 2026 #AI Payments

How AI agents move from recommending a purchase to spending real money — and why identity, permission, payment tokens and dispute evidence matter more than the chatbot interface.

Key takeaway
Agentic commerce is not simply “AI shopping.” The decisive change occurs when software can execute a transaction on a user’s behalf. At that point the payment system must prove four things: which agent acted, what the user authorized, how tightly the payment credential was scoped, and what evidence exists if the purchase is disputed.

The Short Version

  • Agentic commerce lets AI agents discover, compare, prepare, and potentially complete purchases for consumers or businesses.
  • Most live deployments in 2026 are still human-in-the-loop: the agent can assemble the transaction, but the user normally approves before money moves.
  • The hardest problem is no longer only “Is this really the cardholder?” It is “Did the cardholder authorize this agent to buy this item, from this merchant, for this amount, before this permission expired?”
  • The emerging solution is scoped payment credentials and signed mandates rather than giving an AI unrestricted access to a card number.
  • Cards, bank rails and stablecoins can all sit underneath agentic commerce. Stablecoins are useful for machine-to-machine and cross-border settlement, but they are not required for the model to work.

Agentic Commerce Is the Step After AI Shopping

Today, an AI assistant can already search for a flight, compare laptop specifications, build a grocery list, or tell a business which supplier offers the best price. Agentic commerce begins when that software moves from advice into action: it creates the cart, chooses the payment path, submits the order, and — if the user has granted enough authority — pays.

That sounds like a small interface change. It is actually a major payments change. Traditional e-commerce was designed around a human clicking buttons on a merchant website. Agentic commerce introduces a new actor into the transaction: software that is neither the merchant nor the cardholder, but is allowed to act for the cardholder within defined limits.

Visa describes agentic commerce as AI agents helping users discover products, make decisions and complete parts of the purchasing journey. Stripe similarly frames it as shopping in which agents find, compare and potentially purchase goods for customers. Adyen’s September 2026 guide adds an important reality check: most current deployments remain human-in-the-loop rather than fully autonomous.

Figure 1. Agentic commerce spans assisted shopping through standing autonomous authority; “agentic” does not automatically mean “fully autonomous.”

A Simple Example: “Book Me a Flight Under $650”

Suppose a user tells an AI agent: “Book me the cheapest nonstop flight to Chicago next Friday, departing after 6 p.m., total price under $650, and use my travel card.” A normal shopping assistant can search and recommend. An agentic system can go further.

1. Interpret the mandate. The system extracts the constraints: route, date, departure time, nonstop only, total price ceiling, and permitted payment method.

2. Search and compare. The agent queries merchants or commerce APIs, checks availability and evaluates total prices rather than headline fares.

3. Build the transaction. It selects an itinerary, adds required traveler information, and creates a checkout session.

4. Obtain payment authority. The payment layer creates a credential that may be restricted to a particular seller, maximum amount and short validity window.

5. Merchant validates. The airline or travel merchant remains responsible for the authoritative cart, taxes, fulfillment terms and acceptance decision.

6. Payment network authorizes. The processor/network/issuer evaluates the transaction just as it would other digital payments, but now with extra agent and intent signals.

7. Preserve evidence. The system records the mandate, checkout details and payment receipt so a later dispute can reconstruct what the user actually approved.

Figure 2. The extra layer in agentic payments is delegated permission: the transaction must be attributable to both a user and an authorized software agent.

The Payment Problem: Authentication Is Not Enough

E-commerce fraud systems were built primarily around identity and credential risk: is the card legitimate, is the buyer really the account holder, is the device suspicious, and is the transaction consistent with prior behavior? Agentic commerce adds a second axis: authority.

A payment can be technically authentic and still be wrong. The real user may have authenticated the AI agent, and the card may be valid, but the agent might purchase from the wrong merchant, exceed a spending limit, act after permission expired, accept an unwanted subscription, or misunderstand a constraint. That is why the next generation of payment controls is becoming more granular.

What a Payment System Must Prove

Question Traditional e-commerce Agentic commerce adds
Who initiated it? Consumer/device/account Named or registered AI agent acting for the consumer
Was the user authenticated? Password, device, wallet, 3DS, biometrics Same controls still matter
What was authorized? Usually one checkout or stored-card relationship Merchant, item, amount, category, frequency and time window may be explicit
What credential moved? Card number or tokenized card credential Scoped/delegated token that can be useless outside the mandate
What happens in a dispute? Merchant evidence + payment-network records Merchant evidence + agent identity + signed/linked authorization record

How the Industry Is Solving It

The 2026 agentic-commerce stack is being built by several layers at once. The names can be confusing because the protocols solve different problems rather than competing one-for-one.

Layer / standard What it actually does
OpenAI Agentic Commerce Protocol (ACP) Merchant/catalog and checkout integration for shopping in ChatGPT. Merchants retain their own order and payment stack and remain merchant of record.
Google Universal Commerce Protocol (UCP) A common commerce language spanning discovery, checkout and post-purchase interactions across agent and merchant systems. Google says the merchant remains seller/merchant of record.
Google Agent Payments Protocol (AP2) Payment-security layer built around linked checkout and payment mandates plus receipts that can serve as dispute evidence.
Visa Intelligent Commerce Card-network capabilities for agent credentials, controls, authentication, agent verification and trusted checkout.
Mastercard Agent Pay / Verifiable Intent Agent registration, network tokenization and explicit user-intent records for agent-initiated transactions.
Stripe Agentic Commerce Suite Delegated Checkout, Shared Payment Tokens, Link wallet support and machine-payment tools integrated into the merchant payment stack.

Why Scoped Payment Tokens Matter

The safest architecture is not to hand an AI agent an unrestricted card credential. Instead, the payment system can create a delegated token with narrowly defined authority. Stripe’s Shared Payment Tokens, for example, can be limited by seller, amount and time. OpenAI’s Delegated Payment Spec similarly uses a one-time delegated request with a maximum chargeable amount and expiry before handing a payment token into the merchant’s existing processor flow.

This is analogous to giving a human assistant a virtual card that works only at one airline, for no more than $650, and expires in 20 minutes. If the agent is compromised or simply misunderstands a prompt, the payment credential itself can reject purchases outside the mandate.

The important security shift
In ordinary card fraud, the central question is often whether the credential or account was stolen. In agentic commerce, a major new question is whether a legitimate credential was used outside the scope of delegated authority.

Who Is the Merchant of Record?

Agentic commerce does not automatically turn the AI provider into the retailer. Both OpenAI’s current ACP documentation and Google’s UCP model are designed so that the underlying merchant keeps control of the order, pricing, taxes, fulfillment and post-purchase relationship. In OpenAI’s checkout flow, the merchant validates the cart, calculates tax, runs its normal risk checks, charges through its payment processor and accepts or declines the order on its own systems.

That distinction matters for returns, refunds, warranties, chargebacks and consumer law. A shopper may experience the entire journey inside an AI interface while the legal seller remains the airline, marketplace, retailer or restaurant behind the transaction.

Fraud Changes Shape: From Stolen Credentials to Stolen or Misused Permission

  • Prompt injection: A malicious page, merchant description or external tool attempts to manipulate the agent into changing what it buys.
  • Permission drift: The user authorized “buy groceries under $100,” but the agent interprets that as a recurring or broader mandate.
  • Expired intent: The price, availability or user preference changes after the original instruction, but the agent still executes.
  • Merchant substitution: The agent chooses a seller that technically satisfies the request but violates an unstated preference or trust constraint.
  • Duplicate execution: Retries or multi-agent workflows accidentally generate more than one purchase.
  • Dispute ambiguity: The merchant can prove a valid payment token existed, but the consumer argues the software exceeded the intended mandate.

The Market Is Preparing Faster Than Consumers Fully Trust It

Checkout.com’s 2026 survey of more than 12,000 consumers and payments leaders shows a familiar technology-adoption gap. Forty-two percent of merchants said they were already testing agentic commerce, nine in ten said they were actively preparing, and 76% said payment providers would play a decisive role in scaling it. But trust remains a constraint: 27% of consumers said they trusted no organization to operate an AI shopping agent, 24% said they would never delegate purchases to AI, and a quarter said they would stop using an agent if a purchase were difficult to dispute.

Figure 3. Merchant readiness and consumer trust are moving at different speeds. The figures are from different survey questions and should be read as directional rather than directly comparable.

Do Agentic Payments Need Stablecoins?

No. Most consumer agentic purchases can run over cards, wallets or bank-linked payment methods. Visa and Mastercard are explicitly adapting existing card-network infrastructure for agent-initiated transactions, while Stripe’s Shared Payment Tokens can represent familiar consumer payment methods without exposing the underlying credentials to the AI agent.

Stablecoins become more interesting in a different part of the market: machine-to-machine commerce, cross-border settlement and very small programmatic payments. Mastercard’s Agent Pay for Machines is aimed at services that agents or devices may purchase continuously, including transactions measured in fractions of a cent. Stripe’s machine-payment framework can also use stablecoin-based processing while the business logic remains an API call rather than a human checkout page.

The key point is that agentic commerce describes who is deciding and executing the transaction. Stablecoins describe one possible asset or settlement rail. The two trends overlap, but neither requires the other.

What Is Actually Live in 2026?

The market is past the slide-deck stage, but not yet at universal autonomous shopping. OpenAI publishes ACP integrations and an Agentic Checkout specification, with Instant Checkout available to approved partners. Google’s UCP is rolling out across AI Mode and Gemini for participating merchants. Visa and Mastercard have live agent-payment programs and merchant integrations, while Stripe has moved from concept work into a dedicated Agentic Commerce Suite.

At the same time, Adyen’s September 2026 guide says the current reality is still mostly human-in-the-loop: agents find, compare and prepare the purchase, but the shopper normally gives the final approval. That may be a feature rather than a limitation. Full autonomy increases convenience, but it also raises the cost of mistakes and makes precise permission controls much more important.

Five Controls Retail Users Should Look For

  1. A hard spending limit: Prefer a maximum amount enforced by the payment credential itself, not only a natural-language instruction.
  2. Merchant or category boundaries: A travel agent should not be able to spend the same token at an unrelated merchant.
  3. Short expirations: A checkout permission issued for one purchase should not remain reusable indefinitely.
  4. Approval thresholds: Routine low-value purchases may be delegated, while unusual or expensive transactions should return to the user for confirmation.
  5. Revocation and receipts: Users need a fast way to cancel standing authority and a readable record showing what the agent was allowed to do and what it actually did.

What Merchants Need to Change

For merchants, agentic commerce is partly a payments project and partly a data-quality project. AI agents do not browse storefronts the way humans do. They prefer structured catalogs, explicit inventory, machine-readable shipping rules and APIs that return authoritative prices and order states.

  • Expose accurate product, inventory, shipping and return information in structured formats that agents can reliably parse.
  • Differentiate trusted registered agents from scraping bots and automated fraud rather than blocking all non-human traffic.
  • Preserve the merchant’s normal fraud, tax, fulfillment and compliance checks even when checkout occurs inside an AI interface.
  • Keep signed or auditable records of the agent identity, user mandate, cart state and payment credential used for each purchase.
  • Design customer support around a new dispute question: the customer may recognize the agent and the payment but deny that this specific purchase was authorized.

FAQ: AI Payments and Agentic Commerce

Is agentic commerce the same as an AI chatbot?

No. A chatbot can answer questions or recommend products without executing a transaction. Agentic commerce begins when the software can take commerce actions such as creating a cart, initiating checkout or paying within delegated authority.

Can an AI agent buy something without asking me every time?

Potentially, yes, if the user grants standing authority. Safer designs restrict that authority by amount, merchant, category, frequency and time, and can require fresh approval above a threshold.

Does the AI agent see my card number?

It does not need to. Emerging systems use tokenized or delegated credentials so the agent can cause a payment without receiving the reusable underlying card details.

Who handles refunds and returns?

In current OpenAI and Google models, the underlying merchant generally remains the merchant/seller of record and retains responsibility for order fulfillment and post-purchase operations.

Are agentic payments safer than normal checkout?

They can be safer in some respects because permissions can be tightly scoped, but they introduce new failure modes such as permission drift, prompt injection and ambiguous delegated intent.

Is crypto required?

No. Cards and wallets can power agentic commerce. Stablecoins are one optional rail, especially useful for programmatic, cross-border or machine-to-machine settlement.

The Bigger Shift: Checkout Becomes a Permission System

The most important change in agentic commerce is not that a chatbot can press the Buy button. It is that payment authorization becomes programmable. Instead of granting a merchant a reusable card credential or manually approving every checkout, a consumer may grant software a bounded mandate: buy this class of product, from these types of sellers, under this price, until this time, using this funding source.

If that model works, commerce can become dramatically more convenient. Travel rebooking, replenishment, bill optimization, business procurement and machine-to-machine services can move from recommendation to execution. But the same automation makes mistakes scalable. Trust will therefore depend less on how intelligent the agent sounds and more on whether the payment system can enforce limits, prove intent and unwind the transaction when something goes wrong.

Bottom line
Agentic commerce turns AI from a shopping assistant into a delegated economic actor. The winners will not simply be the companies with the smartest agents. They will be the platforms that make delegation precise, revocable, auditable and compatible with the consumer protections people already expect from digital payments.

Methodology and Sources

This article is an educational market-structure explainer based primarily on current developer documentation, payment-network materials and 2026 merchant/consumer research. Product availability and protocol specifications are evolving quickly. Percentages from surveys describe the cited samples and should not be treated as universal population estimates.

1. OpenAI Developers — Agentic Commerce Protocol 10. Mastercard — Agent Pay
2. OpenAI Developers — Agentic Checkout Spec 11. Mastercard — Vision for trusted agentic commerce
3. OpenAI Developers — Key concepts and Delegated Payment Spec 12. Mastercard — Agent Pay for Machines
4. Google for Developers — Universal Commerce Protocol 13. Stripe — Agentic Commerce primer
5. Google Merchant Center — About UCP and UCP-powered checkout 14. Stripe — Agentic Commerce Suite
6. Google Agentic Commerce — AP2 specification 15. Adyen — Agentic commerce guide
7. Visa — Intelligent Commerce 16. Checkout.com — Agentic Commerce 2026 report
8. Visa — What Is Agentic Commerce? 17. Checkout.com — Consumer demand and trust research
9. Visa — Agentic Payments from the Ground Up  

 

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *