The real fight in agentic commerce isn't autonomy. It's authorization
The capability for AI agents to complete purchases has existed for some time. What has been missing is the infrastructure that enables businesses and consumers to trust those transactions.
The conversation about AI and shopping is happening in the wrong place.
Everyone wants to know whether agents will browse for us, compare prices for us and, eventually, buy for us without asking. It's a fair question. But it’s not the one that matters right now.
The more consequential shift is happening somewhere far less visible: inside payment networks, authorization protocols and the systems that decide whether software is allowed to spend money on our behalf.
The technical capability for an AI agent to complete a purchase has existed for some time. What has been missing is the infrastructure that allows businesses and consumers to trust those transactions: confirming an agent had permission to act, ensuring it stayed within agreed boundaries, and creating a verifiable record if something goes wrong.
Over the past few months, that infrastructure has started to emerge. The biggest moves in this space haven't come from AI labs building increasingly showy assistants. They've come from the companies that move money.
At its annual conference, for example, Stripe used the opportunity to introduce wallets that agents can spend from, alongside a partnership letting businesses sell directly inside AI search and chat environments.
Visa introduced an early protocol to help merchants tell a legitimate AI agent apart from a bot. Mastercard announced its own framework for registering and authenticating agents before a transaction is allowed to proceed. Agents are already showing up at volume. What's been missing is the infrastructure to handle what happens next.
The limitation was never autonomy. It was authorization.
Adobe research from early this year shows that AI traffic to US retail sites grew 393% YoY in the first quarter, with AI-referred visitors converting 42% better than non-AI traffic. Just a year before, that same traffic was converting 38% below standard channels.
That’s why the language from the payments industry has shifted so noticeably toward authorization, intent and trust. Mastercard's own leadership has made things explicit: how do you distinguish a legitimate agent from a malicious one? How do you confirm the consumer really authorized the purchase? How do you verify that the agent did what it was told?
Those aren't AI questions. They're identity and trust questions that just happen to involve AI.
Whoever defines the boundary captures the value
What's notable about the recent announcements is how consistent the underlying logic is across companies that otherwise compete directly. Visa's protocol and Mastercard's framework work the same way in principle: register the agent, verify intent and pass credentials only once trust is established.
Stripe's approach, issuing single-use payment credentials per task rather than exposing a customer's card details to an agent, solves the same problem from a different angle.
The protocols may look like back-office plumbing. Functionally, they're architecture for autonomous commerce. Every time a payments provider decides what counts as a verified agent, what data has to be passed to prove intent or how disputes get resolved, it's writing rules that shape who gets to participate and on what terms.
A consumer can be persuaded by an AI assistant to want something, but if the transaction can only execute through a specific track, with specific verification steps, then influence over the purchase decision and control over the purchase itself become two separate things. The company that captures the second captures the economics, regardless of who captured the first.
For merchants, this creates a concrete operational problem. If a transaction gets disputed, can the business prove what was authorized, by whom and under what constraints? These are the exact questions Visa, Mastercard and Stripe are quickly trying to answer; whoever answers them first effectively writes the rulebook everyone else follows.
The race that's already started
Autonomous shopping is imminent, and in some categories it’ll come faster than in others. Routine reordering and B2B procurement are likely to happen first. Other more considered, emotionally fueled purchases will take longer; trust has to be earned. Payment readiness is only part of it, however.
The commerce stack underneath, covering product data, pricing, inventory and checkout, needs to be structured and accessible enough for agents to actually operate it. Businesses that haven't addressed that layer will find the payments question is the least of their problems.
The infrastructure being built right now by payment providers won't just process agent-driven transactions. It will determine which businesses are visible to agents in the first place, which transactions are trusted by default and which get pushed into friction and manual review. The real battle isn’t over autonomy. It’s over who owns the infrastructure of trust.
We've featured the best ecommerce platform.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Share
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0
