“Find a carry-on that fits this airline’s limits, arrives by Friday and costs no more than $150” is already a useful request for an AI shopping assistant. “Buy it for me” changes the problem. The system now has to interpret your constraints, choose a seller, confirm the final price, use a payment method and leave enough evidence to explain what happened.
This is agentic commerce: an AI agent does more than recommend products. With permission, it can perform parts of the transaction on a shopper’s behalf. The important question is not whether the agent sounds trustworthy. It is whether the shopping and payment system limits what the agent can do, verifies the buyer’s intent and makes every consequential step visible and accountable.
For the broader distinction between an assistant and an agent that can act, see what an AI agent phone is—and what the label does not promise.
The short answer: trust the controls, not the conversation
You can reasonably let an AI agent help you search, compare and prepare a cart today. Letting it pay without a final review requires stronger safeguards. A safer system should use a narrowly scoped payment credential, bind authorization to the exact purchase or clear rules, authenticate the agent and user, show the real merchant and total, record the transaction, and provide a practical route for cancellation, returns and disputes.
No single feature makes an agent trustworthy. A polished explanation can still be wrong. A payment token can protect a card number while the agent chooses the wrong size. A signed approval can prove that you authorized a cart without proving that the recommendation was unbiased. Trust therefore has several layers.
| Question | Control to look for | What it does not prove |
|---|---|---|
| Who is acting? | Registered agent identity and signed requests | That the recommendation is good |
| What did I authorize? | Item-, merchant-, amount- and time-bound approval | That the product matches your unstated preferences |
| Can it expose my card? | Single-use or scoped payment token | That the order itself is correct |
| Can I see what happened? | Final preview, receipt and audit trail | That recovery will be effortless |
| Who fixes a problem? | Named merchant, support path, return and dispute terms | That every loss will be reimbursed |
What agentic commerce actually changes
Traditional online shopping usually keeps the human in the loop at checkout. You browse a storefront, inspect the cart and press the final button. An agentic flow can distribute those steps among several systems:
- Discovery: the agent translates your request into product criteria and searches catalogs or websites.
- Evaluation: it compares price, availability, delivery, seller terms and product attributes.
- Cart preparation: it selects a variant, quantity, shipping address and delivery method.
- Authorization: you approve that cart, or you previously gave the agent limited authority to act when stated conditions are met.
- Payment: a wallet, payment provider or card network supplies a constrained credential rather than handing the model an unrestricted card number.
- Aftercare: the merchant fulfills the order while the agent or commerce interface reports status and may help with cancellation, returns or support.
Not every product described as agentic reaches the last step. Some agents only recommend. Some build a cart and hand you to a normal checkout. Others can initiate payment after an explicit confirmation. Fully delegated purchasing—such as buying when a price falls below a threshold—requires a durable, verifiable record of the conditions you approved.
The trust stack behind an agent payment
1. Verifiable intent
A vague instruction is a poor payment authorization. “Get me good headphones” omits the budget, condition, seller, delivery date, return requirements and whether substitutions are allowed. The safest design turns those preferences into explicit constraints and binds approval to them.
Google’s Agent Payments Protocol (AP2) illustrates this approach with cryptographically signed “mandates.” In a human-present flow, a user approves the final cart. In a delegated flow, the user signs an intent in advance with conditions such as price and timing. The proposal is important because it treats authorization as evidence that other parties can verify, rather than as a sentence that only the AI interprets.
A mandate or similar record is not a guarantee that the model understood every preference. It is a way to make the approved scope precise and auditable.
2. A payment credential with boundaries
An agent should not need a reusable card number in its prompt, memory or logs. Modern proposals instead use tokenized credentials. A token represents a payment method but can be limited to a merchant, amount, currency, time window or use count.
Stripe says its Shared Payment Tokens can be scoped to a specific business, limited by time or amount and revoked. OpenAI’s Delegated Payment specification likewise describes a single-use payment token with allowances, while the merchant and its payment provider still process the transaction. Mastercard’s Agent Pay program builds on network tokenization for agent-initiated payments.
These controls reduce the damage if a credential is intercepted or an agent tries to reuse it. They do not prevent a correctly authorized payment for the wrong product. Product selection and payment security remain separate problems.
3. Recognizable agents and authenticated messages
A merchant needs to distinguish an approved shopping agent from a scraper, inventory hoarder or malicious bot. Visa’s Trusted Agent Protocol uses signed messages to communicate agent identity and commerce intent. Mastercard’s acceptance framework similarly describes registered agents, agentic tokens and cryptographic verification.
This helps answer “which agent sent the request?” and “was the request altered?” It does not answer “should this particular agent be allowed to spend this user’s money?” That requires user authorization, transaction limits and risk checks as well.
4. Merchant authority and a complete receipt
The merchant should remain the authoritative source for inventory, taxes, shipping choices, discounts and the final total. In OpenAI’s Agentic Checkout specification, the merchant returns the cart state, accepts or declines the order, processes payment and handles fulfillment. This separation matters: the language model can propose a purchase, but it should not invent the amount that gets charged.
Before payment, the interface should show the merchant, exact item and variant, quantity, item price, shipping, tax, discount, total, delivery estimate and return constraints. After payment, you need an order identifier and a receipt that can be matched to the authorization.
Where agent shopping can still go wrong
The agent can misunderstand a normal request
Language leaves gaps. “Cheap,” “soon” and “similar” are not transaction rules. An agent may optimize the easiest measurable condition—lowest price, for example—while missing durability, seller reputation or a return deadline. A confident rationale does not correct a bad interpretation.
Product information can be incomplete, stale or strategically presented
Prices, inventory and delivery estimates change. Product feeds may omit compatibility details. Sponsored placement can affect what gets surfaced. The agent should identify its seller and sources, state when facts were checked, distinguish advertisements from organic recommendations and avoid claiming that it compared “the whole market” unless that is demonstrably true.
A webpage can try to manipulate the agent
A shopping agent reads external material that the merchant or a third party controls. Malicious text can be designed to look like instructions to the model—a form of indirect prompt injection. NIST describes agent hijacking as untrusted data causing an agent to take unintended actions and has demonstrated successful attacks in simulated tool-using environments.
Payment approval must therefore be enforced outside the model. Security guidance from OWASP recommends least-privilege tools, explicit approval for high-impact actions, validation of tool calls, short-lived authorization, action previews and audit trails. A website’s text should never be able to widen a spending limit or suppress a confirmation screen.
Secure payment does not settle recommendation conflicts
An agent platform may earn referral revenue, a merchant may pay for placement, or a payment method may offer the platform better economics. Those incentives can coexist with a technically secure transaction. Users still need disclosure of sponsorship, ranking factors and material commercial relationships.
Responsibility can be fragmented
The agent may recommend the item, a wallet may supply the credential, a processor may move the money and a separate merchant may fulfill the order. When something fails, the user needs to know which party handles an incorrect item, duplicate charge, fraud claim, late delivery or return. Protocols can improve traceability, but consumer rights and dispute outcomes still depend on the payment method, merchant terms and applicable law.
A safer way to use an AI shopping agent
Match autonomy to consequence. Browsing is easy to reverse; a payment is not. Start with a low-risk flow and increase authority only after the system has earned it through correct, observable behavior.
- Begin with search and comparison. Let the agent gather options, but verify the decisive specifications on the merchant’s page.
- State hard constraints. Specify the maximum all-in price, acceptable merchants, exact variant, condition, delivery deadline and return requirements. Say whether substitutions are allowed.
- Keep final confirmation on. Require a fresh review for the first purchases, expensive goods, subscriptions, travel, regulated products and anything difficult to return.
- Use a constrained payment method. Prefer a single-use or merchant- and amount-bound token. Do not paste a card number or security code into a chat.
- Check the final state, not the agent’s summary. Review seller, item, quantity, address, shipping, tax, recurring terms and total in an authoritative checkout view.
- Save evidence. Keep the instruction, approval, receipt and merchant order number. Turn on transaction alerts.
- Review access after the task. Revoke unnecessary payment permissions, disconnect accounts you no longer use and delete sensitive shopping memory when the service provides that control.
For recurring or unattended buying, add tighter limits: one product category, approved sellers, a per-purchase ceiling, a monthly ceiling, an expiry date and an alert for every order. Do not grant a general “buy whatever seems useful” permission.
Questions to ask before enabling payment
- Will I approve every order, or can the agent buy while I am absent?
- Is approval bound to the exact cart or to explicit price, merchant and time limits?
- Does the agent receive a token, or can it access reusable payment credentials?
- Can the token be revoked, and does it expire automatically?
- Who is the merchant of record and who provides customer support?
- Does the final screen show taxes, shipping, recurring charges and return restrictions?
- Are sponsored products or payment incentives disclosed?
- Can I inspect the agent’s actions and retrieve a receipt later?
- What happens if inventory, price or delivery changes after I gave instructions?
- Which steps use cloud services, and what shopping, identity and payment data are retained?
- Can I cancel the task before payment and the order after payment?
- What protections apply to an unauthorized, duplicate or incorrect transaction in my country?
If the service cannot answer the questions about authorization, credentials and responsibility, keep it in recommendation mode.
FAQ
Is agentic commerce the same as shopping with a chatbot?
No. A chatbot may only answer questions or recommend products. Agentic commerce begins when software can take transaction-related actions such as creating a cart, supplying order details or initiating payment on the user’s behalf.
Should an AI agent store my credit card number?
It should not need the raw number in its conversational memory. A safer design lets a wallet or payment provider hold the credential and gives the transaction a constrained token. Never send a card number, password or verification code through an ordinary chat message.
Can an AI agent buy something without asking me each time?
Some systems are being designed for delegated purchases under pre-approved conditions. That should require precise limits, an expiry, transaction alerts and a verifiable authorization record. For high-cost, unusual or hard-to-reverse purchases, final human confirmation remains the safer default.
Does tokenization make agent shopping safe?
It makes payment credentials harder to expose or reuse, especially when the token is limited by merchant, amount and time. It does not ensure that the agent selected the right product, represented the seller fairly or understood your intent.
Who is responsible if the agent buys the wrong item?
That depends on the service terms, merchant, payment method and local law. Before buying, identify the merchant of record and the support, cancellation, return and dispute paths. A clear audit trail helps establish what you instructed and approved, but it does not predetermine liability.
The practical verdict
An AI agent does not deserve financial trust because it speaks naturally or usually makes good recommendations. It deserves limited authority only when the surrounding system makes misuse difficult: explicit intent, least privilege, scoped credentials, authenticated messages, an authoritative final cart, independent policy checks, strong confirmation and a usable audit trail.
For now, the sensible default is graduated trust. Let the agent do the repetitive work of finding and comparing. Let it prepare a purchase when the terms are clear. Let it pay only within boundaries you can see, verify and revoke.
Disclosure and sources
This article evaluates published agentic-commerce protocols and security guidance. Product availability, supported merchants, regions and consumer protections can change. Protocol descriptions do not constitute independent security certification, and this article does not provide legal or financial advice.
- Google: Agent Payments Protocol (AP2), September 16, 2025.
- OpenAI: Instant Checkout and the Agentic Commerce Protocol, September 29, 2025.
- OpenAI: Delegated Payment Spec, accessed September 29, 2026.
- Stripe: Introducing our agentic commerce solutions, October 7, 2025.
- Visa: Trusted Agent Protocol merchant specifications, accessed September 29, 2026.
- Mastercard: Agent Pay Acceptance Framework, 2025.
- NIST CAISI: Strengthening AI Agent Hijacking Evaluations, updated December 19, 2025.
- OWASP: AI Agent Security Cheat Sheet, accessed September 29, 2026.
