Agentic commerce
Agentic commerce is shopping in which an AI agent handles some or all of a purchase on a person's behalf. The agent can search for products, compare options, build a cart, pay, and deal with what comes after the order, like returns or delivery changes. The person sets the goal and the limits. The agent works inside them.
It's a step beyond conversational commerce, where a shopper uses chat to browse but still makes the final choice. In agentic commerce, the AI acts as the buyer's representative, and that changes how merchants, payment networks, and support teams need to operate.
How agentic commerce works
Most agentic purchases fall into one of two modes. In a human-present purchase, the agent does the research and builds the cart, and the person approves the basket before paying. In a human-not-present purchase, the person authorizes a task ahead of time ("buy two tickets when they go on sale, under $200 each") and the agent completes it later without asking again.
The second mode is where most of the new risk sits. Nobody is at checkout to catch a mistake, so the original instructions and the limits attached to them do most of the work.
Behind the scenes, the agent needs a way to talk to the merchant's checkout, a way to prove it's legitimate, and a way to show what the person actually approved. Each of those is being handled by a different set of standards.
The protocols behind agentic purchases
There's no single standard yet. The Agentic Commerce Protocol (ACP), an open standard created by Stripe, OpenAI, and Meta, defines how an agent opens and completes a checkout session with a business. Google's Universal Commerce Protocol, announced in January 2026, aims to cover the full journey from product discovery to post-purchase support.
Payment authorization is handled separately. Google's Agent Payments Protocol (AP2) uses signed records called mandates. An intent mandate captures what the person asked for, including limits like price and timing. A cart mandate captures the exact items and price they approved. Together they create a record that can be checked if a purchase is disputed. Google donated AP2 to the FIDO Alliance in April 2026.
The card networks are focused on agent identity. Visa's Trusted Agent Protocol lets an approved agent sign its requests so a merchant can tell it apart from a malicious bot, and Mastercard Agent Pay requires agents to be registered and verified before they can pay. The market is still shifting, too. In March 2026, OpenAI stepped back from its in-chat Instant Checkout and let merchants run their own checkout instead.
Why agentic commerce matters for brands
Merchants built their fraud rules, checkout flows, and support processes around a person clicking the buttons. When software does the clicking, each of those systems has to answer new questions. Is this agent who it says it is? Did the customer actually give it permission? Who's responsible when the order turns out to be wrong?
Blocking agent traffic outright means turning away orders that start inside AI assistants. Accepting it without checks means taking on fraud and dispute risk. Most brands will land somewhere in between, with clear rules about what an agent can do on its own and when a human has to confirm.
Common risks in agentic commerce
The most common problem is a correct purchase of the wrong thing. An agent told to "find something warm for the trip" can buy a perfectly reasonable jacket the customer never wanted. The purchase was authorized, so no fraud system flags it, but it still turns into a return or a dispute.
Impersonation is the second risk. A fraudster who can pass as a trusted agent inherits the trust merchants extend to agents. Signed requests raise the bar, but they move the risk onto how well agent credentials are protected. Prompt injection adds another path, since an agent reading product pages or reviews can be steered by instructions hidden in that text.
Liability is still unsettled. The protocols describe audit trails, but they mostly don't say who absorbs the loss when an authorized agent makes a bad purchase: the customer, the agent platform, the merchant, or the card issuer.
What agentic commerce means for customer service
For many brands, the harder work starts after the sale. An agent that can buy can also contact support to change an address, cancel an order, request a return, or dispute a charge. Someone has to decide what that software is allowed to do.
The key question is delegation. Permission to buy a jacket doesn't mean permission to redirect a different order or send a refund to a new card. Support teams need a clear delegated authorization policy that spells out which actions an agent can take on its own, which need a quick confirmation from the customer, and which have to go to the account holder directly.
Disputes are the hardest case. When a customer says they never approved a purchase, support needs to see what the agent was told and whether the order matched. Logging every agent request along with its proof of permission makes those conversations far easier to resolve.
For a deeper dive, download Decagon's guide to agentic AI for customer experience.

