State of play
The infrastructure for agentic payments is substantially built. The demand for it is not yet there. Every serious institution in payments has shipped something; consumers have not shown up to use it; and the legal question underneath the whole category — was the transaction authorised? — is unanswered in every jurisdiction on earth.
Three things are true simultaneously, and most commentary picks one and ignores the other two.
The rails exist. Visa, Mastercard and American Express have each shipped agent credential programmes with production transactions. Stripe shipped what amounts to an agentic operating system at Sessions 2026. Google runs live agent checkout inside Search. Nine protocols are in the field, three of them now under neutral foundation governance. This is not vapour.
Almost nobody is buying through it. OpenAI launched Instant Checkout with Stripe, Etsy, Walmart and Shopify in September 2025 and withdrew native in-chat checkout six months later after Etsy reported negligible volume and Walmart measured conversion at roughly one third of a plain handoff to its own site. Growth is decelerating off a small base: Shopify's AI-attributed orders went from 13× year-over-year in Q1 2026 to 3× in Q2.
What is working is the adjacent thing. People research with AI and buy themselves. That traffic converted 38% worse than baseline in March 2025 and 54% better by May 2026 — the single most robust trend in the dataset, measured across more than a trillion retail visits. The category's real near-term revenue is in discovery, not in delegation.
It is not protocol fragmentation, latency, or merchant integration. It is that 65% of consumers will let an AI compare prices and 9–14% will let it place the order. Every forecast in section 10 is a bet on when that number moves, and no infrastructure investment changes it directly.
Taxonomy: what counts as an agentic payment
Most published numbers in this category are wrong by a factor of ten because they blur three distinct things. Fix the definitions before reading any figure.
| Tier | What happens | Who measures it | Scale |
|---|---|---|---|
| A1 · Influenced | Shopper consulted an AI somewhere in the journey. Purchase may have happened anywhere. | Salesforce ($67B Cyber Week 2025), Bain "influenced" | Large |
| A2 · Referred | Human clicked out of an AI assistant and completed the purchase themselves on the merchant site. | Adobe, Shopify, eMarketer | Real, fast-growing |
| B · Executed | The agent completed checkout. A payment credential was passed by software. | Almost nobody publishes this | Negligible |
Tier B is the actual subject of this document, and it is the one with essentially no public dollar figure. The best on-record estimate comes from Google's Kapil Dabi: under 2% of total digital commerce. Every trillion-dollar 2030 forecast in section 10 is a projection of A2 + B combined, or of A1.
Orthogonal distinctions that matter
- Human-present vs human-not-present. The critical regulatory line. A human confirming at checkout keeps the transaction inside familiar SCA and consent frameworks. An agent transacting against a pre-authorised mandate does not. AP2 v0.2 (April 2026) was the first protocol version to formalise human-not-present.
- Buyer agent vs seller agent. Almost all attention is on the buying side. The selling side — merchant agents that negotiate, quote, and price dynamically — is where B2B volume will actually appear.
- Consumer retail vs B2B procurement vs machine-to-machine. Three different products. M2M (an agent paying $0.002 for an API call) shares almost no infrastructure with consumer retail beyond the word "payment", and has its own rails (x402, MPP), its own fraud profile, and its own unsolved tax problem (§09).
- Delegated vs autonomous. A delegated agent executes a specific instruction. An autonomous agent operates a standing budget. The legal literature calls the workable middle "bounded delegated authorisation" — authorised only within provable, pre-declared constraints.
The stack
Seven layers, and the common error is assuming a single protocol spans more than one of them. Nothing does. Steel marks technical/transport specifications; brass marks authority and money.
How one real transaction composes
Google / UCP stack — live in Search AI Mode and Gemini since May 2026. Agent reads the merchant's /.well-known/ucp and calls the Product Discovery capability over MCP, A2A or plain REST → UCP Checkout, Discount and Fulfillment capabilities build a priced cart, with OAuth 2.0 identity linking attaching the shopper's merchant account → AP2 issues a signed Checkout Mandate (what was agreed) and Payment Mandate (which instrument, what limits) as verifiable digital credentials → the mandate goes to the processor, instrument is Google Pay, PayPal, Affirm or Klarna → conventional card and BNPL settlement, with UCP Order Management returning state.
OpenAI / ACP stack. Product Feed → ChatGPT index → ACP Checkout API against the merchant's own endpoint → no cryptographic mandate object; authorisation is the user's in-product confirmation plus a scoped token → ACP Delegate Payment mints a single-use, merchant-bound token at the PSP → normal card processing, merchant of record unchanged. The absence of a mandate primitive is the substantive difference between the two camps, and it is a liability difference, not an engineering one.
Machine-to-machine — no cart at all. Agent requests a resource → server returns 402 Payment Required with requirements → client returns a signed stablecoin authorisation or tokenised card credential → resource plus receipt. This is the x402 and MPP world: API calls, data, crawls, MCP tool invocations.
Protocols
| Protocol | Sponsor | Launched | Governance | Layer & status |
|---|---|---|---|---|
| MCP | Anthropic | Nov 2024 | Agentic AI Foundation (Linux Foundation), donated 9 Dec 2025 | Agent↔tool. Spec 2026-07-28 made it stateless. ~89.8k stars; SDKs past 1B cumulative downloads. |
| A2A | Apr 2025 | Linux Foundation | Agent↔agent. v1.0.1, 28 May 2026. 150+ orgs; production at AWS, IBM, Microsoft, Salesforce, SAP. | |
| WebMCP | Microsoft + Google | 2025 | W3C Community Group draft — not standards track | Browser-native tool exposure. Chrome origin trial in v149 (Jun 2026). Publisher deployment near zero. |
| ACP | OpenAI + Stripe | 29 Sep 2025 | Founding-maintainer model; TSC 3 of 7 seats filled (OpenAI, Stripe, Meta). Neutral foundation promised, no date. | Commerce. Spec 2026-04-17, labelled beta. Checkout API + Delegate Payment API + Product Feed. |
| UCP | Google, Shopify, Etsy, Wayfair, Target, Walmart | 11 Jan 2026 | Google-convened Governing + Tech Council. Not in a neutral foundation. Tech Council expanded to 16 seats Apr 2026, adding Amazon, Meta, Microsoft, Salesforce, Stripe. | Commerce. Capability-based; transports A2A/MCP/REST; delegates payment to AP2. Live on Google surfaces with Nike, Sephora, Target, Ulta, Walmart, Wayfair. |
| AP2 | 16 Sep 2025 | FIDO Alliance, donated 28 Apr 2026 | Mandate. v0.2 added human-not-present. Verifiable Digital Credentials; Checkout + Payment Mandates, each Open and Closed stage. | |
| MPP | Stripe + Tempo | 18 Mar 2026 | Tempo Labs + Stripe. IETF individual draft draft-ryan-httpauth-payment — not WG-adopted. | Payment. Generalises HTTP 402 into a Payment auth scheme; method-agnostic via IANA registry; charge / session / subscription intents. Backward-compatible with x402. |
| x402 | Coinbase | May 2025 (v1) Dec 2025 (v2) | x402 Foundation (Linux Foundation), operational 14 Jul 2026, 40 members incl. Visa, Mastercard, Amex, AWS, Google, Stripe, Shopify, Circle | Payment. Client / resource server / facilitator; EIP-3009 gasless USDC on EVM, TransferChecked on Solana; CAIP-2 network IDs. |
| L402 | Lightning Labs | 2020s | Company-maintained | Payment. Macaroons + Lightning invoices. The design ancestor of the 402 family; materially smaller ecosystem. |
| Visa TAP | Visa + Cloudflare | 14 Oct 2025 | Visa; stated intent to align with IETF, OpenID Foundation, EMVCo | Identity. RFC 9421 HTTP Message Signatures, 8-minute validity window, nonce replay protection, Ed25519. No tagged release in ten months. |
| Verifiable Intent | Mastercard + Google | 5 Mar 2026 | FIDO Alliance, donated Apr 2026 | Mandate. Tamper-resistant record of what a user authorised, with selective disclosure. Protocol-agnostic. |
Where they actually compete
- ACP vs UCP at the cart layer. Same job, incompatible schemas, merchants asked to run both. Google shipped UCP 3.5 months after ACP with a broader retailer coalition and immediate distribution on Search.
- x402 vs MPP at the 402 layer. MPP is deliberately a superset — any payment method, backward-compatible with x402. x402 has the foundation, the members and the transaction history; MPP has card rails, including a Visa card-based specification and SDK published the same day MPP launched.
- AP2 vs ACP's implicit model. AP2 makes intent a signed credential with liability semantics. ACP leaves authorisation to platform UX. This is the most consequential unresolved split in the stack.
- WebMCP vs MCP servers vs NLWeb — three answers to "how does a site expose itself to an agent."
Consolidation, strongest signal first
- FIDO Alliance is becoming the mandate home. AP2 and Verifiable Intent both landed there on 28 April 2026, in an Agentic Authentication working group co-chaired by CVS Health, Google and OpenAI, with Visa and Mastercard chairing the Payments WG. It is the only venue where both commerce camps sit at one table.
- Linux Foundation is becoming the infrastructure home — MCP, A2A, x402.
- UCP's Tech Council absorbed the rival camp. Stripe now co-maintains ACP and holds a UCP seat; Meta sits on both.
- Counter-signal: governance consolidation is running well ahead of usage. x402 daily settlement volume was down 93% year-to-date as of 13 August 2026 despite 40 foundation members.
Rails and credentials
The networks' strategy is uniform: never let a raw card number reach a model. Everything is a scoped, revocable, agent-bound token with consumer-set limits.
Visa
Visa Intelligent Commerce, announced 30 April 2025, with launch partners including Anthropic, Microsoft, OpenAI, Perplexity, Samsung and Stripe. Three pillars: AI-ready tokenised credentials bound to a consumer-selected agent; consented spend insights; consumer-set limits and conditions. Only the consumer can activate the credential. Developer surface exposes tokenisation/authentication APIs, payment-instruction APIs, and an MCP server.
- 18 Dec 2025 — "hundreds" of agent-initiated production transactions; 100+ ecosystem partners, 30+ in sandbox, 20+ agents integrating. primary
- 8 Apr 2026 — Intelligent Commerce Connect: a network-, protocol- and vault-agnostic gateway supporting TAP, MPP, ACP and UCP through one integration. This is Visa declining to pick a protocol winner.
- 2 Jul 2026 — 30+ European issuers live, including Barclays, HSBC UK, ING, NatWest and Revolut, using TAP, an Agent Directory and Visa Payment Passkeys for SCA-compliant authentication.
- 18 Apr 2026 — Visa Core Rules now define "Agentic Payment Provider" and "Agentic Transaction" and add §4.1.24 Agentic Platform Requirements. Visa is the only network governing agents through binding published rules rather than product programmes. primary
Mastercard
Agent Pay, announced 29 April 2025, built on existing tokenisation. Agentic Tokens are dynamic credentials carrying the permissions and limits the consumer defines, with each transaction tied to a specific authorised interaction. The October 2025 Acceptance Framework is the clever part: merchants verify agent authenticity via Web Bot Auth at the CDN layer with no code change, and trusted agents submit a Dynamic Token Verification Code — an agentic token formatted to fit standard card payment fields, so no acquirer change is needed.
- Rollout: Citi and U.S. Bank first, all US cardholders by mid-Nov 2025; US, Australia, India and Hong Kong live by April 2026.
- 10 Jun 2026 — Agent Pay for Machines (AP4M): M2M, high-frequency, sub-cent micropayments settling across cards, bank accounts and stablecoins. 30+ participants including Adyen, Cloudflare, Coinbase, Stripe, Tempo. primary
- 3 Aug 2026 — completed acquisition of BVNK (stablecoin payments, ~$30B annual volume) for up to $1.8B.
- Mastercard's public Transaction Processing Rules and Chargeback Guide contain no agentic provisions. Governance is by product programme, not rulebook — the mirror image of Visa. absence of evidence
American Express
Agentic Commerce Experiences (ACE) developer kit, 14 April 2026: Agent Registration, Account Enablement, Intent Intelligence, Payment Credentials, Cart Context — of which only three had published specifications at launch. Paired with Agent Purchase Protection, the first and still only issuer-side liability commitment in the market.
Protection applies only to US cards, only to agents registered with Amex and integrated with ACE, and only where Amex received the Card Member-authenticated purchase intent from the agent. It covers transactions that deviate from that authenticated intent. It requires the customer to attempt a merchant return first. It excludes claims where "purchase intent is subjective or non-verifiable (e.g. 'best' or 'really nice')". Amex reserves the right to suspend agent-based purchases entirely, and full terms "will be made available in the future" — there is no published effective date.
The shape is the lesson: incumbents will insure their own closed loop, on their own credential, against their own registered agents. Nobody is insuring the ecosystem.
Stablecoin and crypto rails
The M2M story, and the one where the original thesis has partially unwound. Coinbase's x402 passed 100M+ cumulative transactions on Base within roughly three quarters. But sub-$1 transactions collapsed from 46% to 4% of volume while $1+ rose from 49% to 95% — the micropayment use case that justified the protocol is not what people use it for. Daily settlement volume was down 93% year-to-date by mid-August 2026, running around $40k/day against a Q4 2025 peak near $1M.
Meanwhile the institutional money arrived anyway: Stripe acquired Bridge ($1.1B, closed Feb 2025) and launched Tempo, an L1 that raised a reported $500M Series A at $5B; Circle shipped Agent Stack for USDC M2M payments in May 2026; Cloudflare launched a Monetization Gateway (Jul 2026) settling x402 at the edge, then Wallets (Aug 2026); Mastercard bought BVNK. Infrastructure conviction is running far ahead of measured demand.
Cross-industry governance
18 Aug 2026 — the Agentic Payments Alliance, convened by Rain with 25+ founding members including Visa, Mastercard, Fiserv, Circle, Solana, Remitly, Chainalysis, Fireblocks, Lithic, Sardine and Shift4. Scope: agent authorisation, fraud detection, loyalty, agent identity standards and regulatory advocacy. Five days old at the time of writing; nothing shipped.
Identity and trust
The foundational question — is this agent legitimate, and who is behind it? — has one real standards effort and a dozen commercial answers.
Web Bot Auth
The IETF webbotauth working group is chartered, in the Web and Internet Transport area, with scope explicitly covering AI agents. Bot reputation systems are expressly out of scope — worth knowing when a vendor markets "agent reputation" as standards-aligned.
The core specification, draft-meunier-webbotauth-httpsig-protocol, is still an individual draft with no formal IETF standing, co-authored by Cloudflare and Google — the two main implementers. Charter milestones (auth specs to IESG by 30 Apr 2026, operational BCP by 31 Aug 2026) appear to have slipped. widely deployed, pre-standard
Implementation reality: Cloudflare launched signed agents on 28 Aug 2025, with ChatGPT agent, Block's Goose, Browserbase and Anchor Browser as launch partners, and reworked its verified-bot taxonomy in July 2026 into eleven behaviour types plus a Direct vs Intermediary label — the structural answer to "is this a crawler or an agent acting for a person." Google began signing Google-Agent requests experimentally in May 2026 but does not sign every request. Both Visa TAP and Mastercard Agent Pay build on Web Bot Auth as their authentication foundation.
Know Your Agent
| Effort | What it is | Status |
|---|---|---|
| Experian Agent Trust | Human-to-agent binding, Agent Trust Token, agent registry with dynamic trust scoring. Collaborators: Visa, Cloudflare, Skyfire. | Announced 30 Apr 2026; GA unclear vendor |
| Skyfire KYAPay | JWT-format agent identity and payment tokens. IETF individual draft (co-author: Michael B. Jones, of JWT/OIDC). | Draft expired, replaced by an OAuth-profile successor no IETF endorsement |
| Visa Agent Directory | Registry backing TAP; used in the July 2026 European issuer go-live. | Live primary |
| Mastercard "Know Your Agent" | Agent Sign-Up registration; only registered agents transact, traceable via network tokens. | Live |
| Forter TACP | Trusted Agentic Commerce Protocol — JWE-based, keys at .well-known/jwks.json. Makes no reference to AP2 or ACP. | Proposal; no named adopters competing, not complementary |
| ERC-8004 | On-chain agent identity and reputation registry; cited by the IMF as an emerging standard. | Emerging |
IMF Note 2026/004, How Agentic AI Will Reshape Payments (April 2026), explicitly recommends that the public sector "establish Know-Your-Agent regulatory requirements, where mandated verifiable identities for financial bots are linked to legal entities." It also gives the best architectural frame in the literature: L1 intent/orchestration is probabilistic, L2 control/authorisation must be deterministic and mandate-based, L3 settlement is irreversible. The thesis — "the main risk does not come from probability-based reasoning itself, but from letting adaptive systems make irreversible payments without proper controls" — is confirmed empirically in §06.
Security and fraud
Two findings dominate. Attacks on the reasoning layer succeed while the cryptography holds perfectly. And the settlement layer — the part everyone assumed was solved — failed every test it was given.
Prompt injection is documented in the wild, with payment payloads
Palo Alto Unit 42, 3 March 2026, "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild" — the first confirmed real-world corpus. 22 distinct payload-engineering techniques across 7 attack categories. Payment-specific payloads observed: forced subscription to paid plans via JS injection, attempted $5,000 PayPal transfers to attacker-controlled accounts, forced purchases, and donation redirection through Stripe payment links. Delivery: 37.8% visible plaintext, 19.8% HTML attribute cloaking, 16.9% CSS render suppression; 85.2% used social-engineering framing. primary research
Cloud Security Alliance (26 Apr 2026) measured a 32% relative increase in malicious indirect-injection content between November 2025 and February 2026, and catalogues named incidents: GrafanaGhost (poisoned logs → exfiltration), OpenClaw (agent deleted user emails despite stop commands), and Flowise CVE-2025-59528 with 12,000–15,000 exposed instances.
Mandates protect execution, not decisions
Whispers of Wealth: A Systematic Red-Teaming Study of the Agent Payments Protocol (arXiv, May 2026) built a working four-agent AP2 system and ran 30 controlled trials. Indirect injection via product metadata achieved a 100% success rate (10/10) — injected products ranked first despite weaker relevance. Direct injection at credential access produced 20% cross-account data exposure.
Every attacked transaction remained cryptographically valid. The attacks operate at the reasoning layer, before mandate signing. As the paper puts it: AP2's cryptographic mandates protect what executes, not how decisions form. No amount of signature engineering fixes this; only out-of-band enforcement does — which is precisely the architectural argument for wallet-level spend caps.
The x402 settlement layer failed comprehensively
"When HTTP 402 Meets the Blockchain," USENIX Security 2026. The researchers tested 15 facilitators — all 15 violated at least one security rule, producing 49 violations mapping to 31 distinct vulnerabilities across four attack classes: free shopping, asset theft, service denial, gas abuse. Coverage: 119M+ transactions across Base and Solana, ~99% of observed x402 traffic, roughly 60,000 sellers and 360,000 buyers. Named: Coinbase, Thirdweb, PayAI, Mogami.
Specific defects included signature spoofing via malicious ERC-6492 metadata causing facilitators to approve arbitrary token transfers, settlement race conditions where service was released after off-chain verification but before on-chain confirmation, unbounded gas sponsorship, and missing reversal protections in Coinbase's SDK at ≤0.2.1. All parties acknowledged and mitigated. A second paper, "Five Attacks on x402," independently found authorisation flaws and replay-protection gaps across three SDKs. peer-reviewed
What is asserted but not demonstrated
- Card testing via agentic micropayments. Signifyd measures a real 175% year-over-year rise in card testing (North America, Jan–Apr 2026) — but does not attribute it to agents. The agent attribution comes entirely from vendor content using illustrative scenarios. unattributed
- Agent hijacking and synthetic agent identities. Akamai reports threat actors compromising legitimate assistants to abuse stored credentials, and LLM-generated synthetic identity accounts — unquantified. vendor
- MCP "rug pulls" — tool definitions mutating after approval. Well-described as a mechanism; no documented case of financial loss. no incident found
- UCP cart poisoning and returns-fraud hijacking — modelled by Unit 42 (Mar 2026), not observed. modelled
Traffic, and the vendor response
Akamai puts AI bots at 47.9% of commerce traffic as of December 2025, with over 70% of that being LLM development crawlers — top three OpenAI, ByteDance, Anthropic. Riskified and HUMAN found LLM-referred traffic 2.3× riskier than Google search traffic at a ticketing merchant and 1.8× at an electronics merchant — the most useful merchant-derived figure available.
Shipped products: Darwinium Agent Intent Intelligence (10 Mar 2026, GA immediately — edge-native, cryptographic identity validation via HTTP message signatures, explicit Visa TAP and Mastercard Agent Pay support) is the most concretely delivered. HUMAN AgenticTrust with Riskified, Forter Identity Monitoring, and Akamai's agentic framework follow. Notably, Signifyd and Sift have no identified shipped agent-identity product despite publishing extensively on the topic.
Cloudflare Wallets (4 Aug 2026, early access) gives agents an allowance, a merchant allow-list, and a maximum transaction size, enforced in infrastructure rather than in a system prompt. Widely described as "blocking prompt injection at the payment layer" — that framing is third-party, not a Cloudflare claim, though the architecture does match what the AP2 red-team result implies is necessary. framing unverified
AML
FATF's December 2025 horizon scan is the closest thing to a direct statement: criminals use AI to pattern transactions in ways rules-based systems cannot detect, and "autonomous AI agents may orchestrate these flows without human supervision" — note the modal; this is projected, not a documented typology. The FinCEN/OFAC stablecoin NPRM (8 Apr 2026) makes stablecoin issuers BSA institutions with SAR obligations at $5,000 and first-of-its-kind mandatory sanctions-compliance capability — and makes no mention of AI agents, autonomous payments, or micropayments.
Liability and disputes
Visa's own July 2026 report says it plainly: "Liability remains legally ambiguous. No jurisdiction has established clear precedent for how responsibility is distributed."
Where the loss actually falls today
| Party | Position as of August 2026 |
|---|---|
| Consumer | Bears it first. If the agent acted within granted authority the transaction is likely authorised — which removes Reg E / PSD2 unauthorised-transaction refund rights and, in the UK, likely falls outside APP reimbursement too. |
| Merchant | Bears the residual loss in practice. Receives a valid, tokenised, network-authenticated transaction, then absorbs the chargeback, fees and operational cost. The ACP Delegated Payment spec states it outright: "Settlement, refunds, chargebacks, and compliance remain with the merchant and their PSP." |
| Agent developer / model provider | No direct chargeback liability. Exposed only via consumer law, contract, and general negligence. The UK CMA is the sharpest: a business is responsible for what its AI agent does, including third-party-built agents, with penalties up to 10% of worldwide turnover. |
| Issuer | Exposed only where the transaction can be characterised as unauthorised — which is exactly what a valid mandate defeats. |
| Network | Sets authentication and token rules. Has published no agent-specific dispute liability rules. |
The five situations where law is simply silent
- Agent acts within granted scope but the consumer disputes the outcome — wrong item, wrong price, wrong timing.
- A compromised or prompt-injected agent spends within its legitimate limits.
- Delegation chains and sub-agents with no direct link back to the authorising human.
- Sub-cent, high-frequency M2M flows. Visa: "when an agent executes thousands of transactions per hour, the concept of a single disputed 'order' does not map to hundreds of sub-cent API calls."
- Stablecoin and x402 settlement — no CIT/MIT classification, no 3DS, no chargeback, no Reg E. Reversal generally requires law enforcement.
Why the chargeback machinery breaks
- The CIT/MIT binary fails. Agent transactions are neither cleanly Cardholder-Initiated nor Merchant-Initiated. Visa addressed this in its April 2026 rules; Mastercard's public rules are silent — and that asymmetry is itself a source of liability uncertainty.
- 3DS cannot run. Data-centre IPs trigger fraud signals, there are no behavioural biometrics, and an agent cannot receive an SMS OTP. What is used instead are repurposed workarounds: the 3DS Requestor-Initiated indicator and the Secure Corporate Payments exemption, the latter designed for enterprise procurement rather than consumer AI shopping.
- No agent-specific reason codes exist at any network. "Merchandise not as described" does not capture "agent exceeded mandate." The current taxonomy cannot distinguish consumer fraud, agent error and scope dispute.
- Monitoring programmes apply unchanged. Visa VAMP and Mastercard ECM thresholds do not adjust because an agent initiated the transaction — so merchants carry agent-driven dispute ratios into standard excessive-chargeback penalties.
Traditional chargeback evidence disappears. There is no click trail, no behavioural session data; the device fingerprint belongs to the agent's server, not the buyer; and the authorisation is often an ambiguous prompt. What a defence actually needs — proof of delegation, the timing and scope of approval, the parameters set, and whether the agent correctly interpreted the instruction — sits with the agent platform, which has no obligation and no incentive to hand it to the merchant or the issuer.
Darwinium's survey found no consensus on who should pay: 39% say AI providers, 20% customers, 14% merchants.
The academic answer
Remolina (SMU, April 2026) proposes a "bounded delegated authorisation" test — an agent action is authorised only within strictly defined, provable constraints, and anything beyond is an unauthorised payment. She recommends a new regulated category, Digital Assistant Payment Services, and mandatory PSP reimbursement where an agent exceeds its bounds. The EJRR paper (May 2026) frames the core problem as distributed responsibility across users, developers, platforms and agents, which traditional liability frameworks cannot allocate.
Regulation, by jurisdiction
No jurisdiction has enacted binding, agent-specific payments law. Every regime is applying human-designed authorisation frameworks by analogy.
European Union
PSD2 and the SCA RTS remain operative, with no agentic carve-out. The structural problem is that consent (Art. 64), SCA (Art. 97) and unauthorised-transaction liability (Arts. 73–74) all assume an identifiable human authorising a specific transaction. Industry has fallen back on repurposed machinery: MIT/recurring flows, the trusted-beneficiary and low-value SCA exemptions, delegated authentication, and 3DS requestor-initiated indicators.
PSD3 and the PSR concluded trilogue in November 2025, with Council approval of the final compromise in April 2026 and OJ publication expected in H2 2026. Application lands around 2028 (entry into force +21 months; Verification of Payee at +27). Relevant changes: SCA scope widened to creation of tokenised instruments and changes to spending limits; digital wallet operators performing SCA must enter outsourcing agreements with the PSP retaining full liability — the closest existing hook for agent-performed authentication; a new impersonation refund right; direct liability for technical service providers and scheme operators.
AI agents are not mentioned anywhere in PSD3 or the PSR. confirmed across two independent legal analyses
On the AI Act: payment agents are not per se high-risk. Annex III point 5(b) covers creditworthiness scoring, so a shopping agent that does not score credit sits outside it. The Digital Omnibus (political agreement 6 May 2026) pushed Annex III stand-alone high-risk from 2 Aug 2026 to 2 Dec 2027 and embedded high-risk to 2 Aug 2028, while Article 50 transparency obligations stay at 2 Aug 2026. Article 5 prohibitions on manipulative techniques have applied since February 2025 and are the live hook for agent-driven dark patterns. Academic critique: Art. 14 human oversight is impractical at transaction speed, and Art. 26 "deployer" is ambiguous between end user, agent platform and model provider.
Also live: DORA (applying since Jan 2025) is currently the most concrete binding constraint on a bank or PSP outsourcing to an external agent provider. The Product Liability Directive (EU) 2024/2853 expressly brings software and AI within "product," transposition due 9 Dec 2026. Note that the separate AI Liability Directive proposal was withdrawn — several secondary sources still treat its rebuttable presumption of fault as live law; it is not.
Neither the EBA nor the ECB has issued anything specific to agentic payments. The Eurosystem's March 2026 payments strategy does not mention AI agents.
United Kingdom — the most active jurisdiction
- 25 Mar 2026 — FCA payments priorities report committed to assess "whether change or development of regulation is needed to support agentic AI payments," naming PSRs 2017 consent, liability where agents initiate or route, and the inadequacy of standing authorities. A shift from the standing "existing frameworks suffice" posture.
- 9 Mar 2026 — CMA published both research and binding-in-effect guidance on consumer law and AI agents. Core holding: "you are responsible for what an AI agent does", including third-party-built agents. Penalties to 10% of worldwide turnover.
- 14 Jul 2026 — HM Treasury's Modernising payment services regulation consultation (closes 6 Oct 2026) asks directly whether consent, authentication and unauthorised-transaction liability requirements remain appropriate where AI agents initiate payments. High-level question only; no framework proposed. The accompanying AI Adoption Plan lists agentic payment readiness as high priority across three workstreams: liability frameworks, Know Your Agent verification, and authentication standards.
- The APP reimbursement gap. The PSR's mandatory reimbursement regime (£85,000 cap) covers authorised push-payment fraud, and expressly contemplates third parties executing on consumer authority. Whether an AI agent's execution counts as the consumer "personally authorising" is addressed nowhere. A scammed agent produces a payment that is neither cleanly authorised nor cleanly unauthorised — it falls between the two regimes.
United States — the statutory gap
EFTA and Reg E define an unauthorised transfer as one initiated by a person "without actual authority." Agentic commerce creates a category the statute did not contemplate: authorised access plus disputed execution. A consumer who grants an agent purchasing authority has arguably conferred actual authority even where the agent buys the wrong item at twice the price — which removes Reg E protection by statutory gap, not policy choice. Reg E §1005.2(m) also excludes transfers initiated by someone "furnished with the access device by the consumer," which cuts against the consumer. Reg Z Comment 12(b)(1)-2 treats card use by someone furnished the card as authorised, though §1026.12(c) merchant-dispute rights survive regardless.
The CFPB has issued no rule, interpretive rule or advisory opinion on AI agents or agent-initiated transfers. Claims circulating that a January 2026 CFPB advisory preserved dispute rights after delegation do not correspond to anything on the Bureau's advisory-opinion or final-rules pages. actively doubted
The only federal legislative vehicle is the AI AGENT Act discussion draft, released by Sen. Warner on 29 June 2026 and not introduced. It would let consumers authorise "custodial user agents," impose FRAND interoperability on large platforms, put agent-provider registration with the FTC and identity standards with NIST, and apply a fiduciary-style duty of care. It leaves liability for erroneous or over-scope agent action unresolved.
Asia
- Singapore is furthest ahead. On 5 Aug 2026 MAS confirmed in a Parliamentary reply that autonomous AI agents fall inside the forthcoming binding Guidelines on AI Risk Management — consulted November 2025, finalisation expected Q4 2026. The July 2026 SAFR information paper proposes a "governance checkpoint between every agent decision and its execution," while expressly disclaiming regulatory status. Singapore is the first major regulator to bring agentic AI expressly within binding supervisory scope.
- India. NPCI is developing a Unified Agent Protocol for agents on UPI (reported July 2026); mechanics unpublished, no RBI circular. The nearest existing construct is UPI Circle delegated payments. RBI's FREE-AI framework (Aug 2025) applies to Payment System Operators but is advisory only. India's mandatory two-factor authentication is the practical brake on autonomous execution.
- Japan. No AI-payment-specific regulation; function-by-function application of the Payment Services Act. An AI agent is not a legal person, and the label "agent" does not make it one in civil law. Unauthorised card-use relief is contractual, not statutory. A new Electronic Payment Instruments & Crypto-Asset Service Intermediary category was introduced in June 2026. The FSA's March 2026 AI discussion paper does not mention agents.
- China. Not covered by this research. Nothing here should be read as evidence either way. gap
Consumer protection: the doctrinal hole
Is an agent purchase a distance contract under the Consumer Rights Directive? The mechanical elements are satisfied. The unresolved questions are whether the consumer concluded it, and how the Art. 6 pre-contractual information duties are discharged when no human reads them. No EU regulator, court or Commission guidance addresses this — one of the clearest doctrinal gaps in the whole landscape.
Meanwhile, the CRD's new Article 11a mandatory withdrawal button applies from 19 June 2026 — a labelled "withdraw from contract here" function, continuously available for the 14-day period, on all devices without extra steps. Whether it must be machine-readable and agent-actionable is unaddressed. An agent that can buy but cannot cancel is an asymmetry no instrument currently covers.
Tax: the sub-cent problem
A small, specific, entirely unaddressed failure that scales with M2M volume.
An agent pays €0.02 for an API call in a 20% VAT jurisdiction. The VAT is €0.004. Standard two-decimal rounding takes that to €0.00. At agentic transaction volumes this is systematic leakage, not rounding noise.
Three things make it structural rather than fixable in an invoice template:
- The VAT Directive does not prescribe rounding rules — they are left to national law, so identical M2M flows produce divergent outcomes across member states. EN 16931 theoretically permits higher precision, but national implementations, tax portals and accounting systems default to cent-level amounts.
- Aggregation is unavailable. Telecoms solved sub-cent leakage decades ago by batching into monthly invoices against a persistent customer account. x402 is stateless by design — no account, no billing cycle, no way to link thousands of micro-vendors per agent per day.
- B2C by default. Implementing Regulation 282/2011 Art. 18 requires the supplier to treat a supply as B2C where no VAT identification number is communicated. Agent-to-agent flows communicate none — so destination-country VAT and OSS/IOSS obligations attach to flows the supplier cannot practically identify, and reverse-charge relief is lost.
No ViDA provision and no tax-authority guidance addresses this. In the US, the IRS has issued nothing on autonomous agents acting for taxpayers; each stablecoin transfer is a property disposition under Notice 2014-21, making every M2M payment a taxable event, and Form 1099-DA has no mechanism to identify the principal behind an agent wallet.
Market size and real adoption
The 2030 forecasts, and why they disagree by 5×
| Source | Figure | Geo | Definition used |
|---|---|---|---|
| McKinsey | $3–5T global; up to $1T US B2C retail | Global + US | "Agents shop, negotiate and transact." Does not separate referred from executed. Loosest definition, largest number. |
| Bain | $300–500B = 15–25% of US ecommerce | US | Initiated, influenced or completed by agents, excluding journeys that only use AI search/discovery. Tightest published definition. |
| Morgan Stanley | Base $190B; bull $385B | US | Autonomous personal shopping assistants. |
| eMarketer | $144B by 2029 = 9% of US online; 2026 = $20.6B (~1.5%) | US | Third-party AI platforms, including onsite and referred sales; excludes retailer-native tools. Most transparent methodology. |
| Juniper | $1.5T global | Global | No published definition. Notes 2025–26 are pilots only. |
| Gartner | >$15T B2B spend by 2028 | Global B2B | Note the verb: "intermediated," not executed. most cited, least substantiated |
The US 2030 range runs from $190B to $1T — a 5× spread driven almost entirely by definition, not by disagreement about adoption speed. Bain and Morgan Stanley, with tighter definitions, cluster at $190–500B.
What is actually happening — AI-referred traffic
Adobe's dataset (1T+ US retail visits) is the most robust longitudinal evidence in the category.
| Period | Traffic YoY | Conversion vs non-AI | Engagement |
|---|---|---|---|
| Oct 2024 | baseline | non-AI better by 128% | — |
| Mar 2025 | — | AI 38% worse | — |
| Holiday 2025 | +693% | — | — |
| Q1 2026 | +393% | AI 42% better (March) | +12% engagement, +48% time on site |
| May 2026 | +138% | AI 54% better | +53% revenue per visit; bounce 36% lower |
Two caveats Adobe itself carries: it has never published AI referrals as a share of total retail visits, and it publishes no agent-executed transaction data whatsoever. Note also the deceleration — +393% in Q1 to +138% in May.
What is not happening — agent-executed checkout
Shopify's AI-driven traffic and orders were 8× and 13× year-over-year in Q1 2026, then 3× in Q2 — off an undisclosed base. Consumer willingness is the ceiling, and the best-powered survey is unambiguous:
| Source | Would let an agent complete a purchase | Method |
|---|---|---|
| Accenture | 9% fully autonomous; 32% agent decides within bounds, human pays | 25,590 consumers, 16 countries, Jan 2026 strongest |
| Checkout.com / YouGov | 24% would never delegate; avg unsupervised authorisation £177 | 6 markets, Jun 2026 |
| RTB House | ~33% of US millennials; 42% with a 7-day return + $250 cap safeguard | 1,800+, Aug 2026 |
| Croud | 69% "open to AI purchasing on their behalf" | 2,000 US, field dates undisclosed headline-optimised |
The safeguard effect in the RTB House data is the most actionable finding here: a return window and a spend cap moved millennial willingness from ~33% to 42%. Trust infrastructure, not payment infrastructure, is what moves the number.
OpenAI Instant Checkout, 29 Sep 2025 → 6 Mar 2026. Launched with Stripe, Etsy and Shopify merchants; Etsy stock rose 16% on the news. Six months later OpenAI moved checkout out of the chat surface into Apps. Reasons on record: Etsy "did not end up seeing a large volume of sales"; Walmart measured conversion 3× lower for direct chatbot sales than for clickthrough; Instacart said "only a very small percentage of total orders today originate directly through AI agents." Roughly 30 Shopify merchants were live at the time of the pullback, against "over a million coming soon."
What survived: the ACP protocol, the Stripe partnership, and product discovery. What died: the assumption that consumers want to complete purchases inside a chat window. OpenAI never disclosed Instant Checkout GMV or transaction counts at any point.
B2B
No hard volume data exists — only forecasts and adoption-intent surveys. The honest picture is The Hackett Group's Q1 2026 procurement study: 43% of organisations actively pursuing AI deployment, but only 12% at large-scale implementation, and 69% accessing AI through capabilities embedded in existing procurement platforms rather than agentic purchasing. The study reports no percentage of purchase orders autonomously executed.
Company landscape
Agent wallets, vaults and payment SDKs
| Company | What | Funding |
|---|---|---|
| Basis Theory | PCI-compliant tokenisation vault; convenes the Agentic Commerce Consortium | $33M Series B, Oct 2025 |
| Catena Labs | "AI-native financial institution" for agents; founded by Circle co-founder Sean Neville | ~$48M total; $30M Series A, May 2026 |
| Crossmint | Wallets + stablecoin infrastructure for businesses and agents | $23.6M, Mar 2025 |
| Skyfire | Agent identity + payment; KYAPay protocol | $9.5M total |
| Nekuda | Secure Agent Wallet + Agentic Mandates | $5M seed, May 2025 (Madrona, Amex Ventures, Visa Ventures) |
| Payman | Agent payment rails with human-in-the-loop approval; US bank partnership | $3M pre-seed totals unconfirmed |
| PayOS · Prava | Agent-card orchestration for issuers · tokenised card payments with passkey approval | aggregator only |
Checkout execution
| Company | What | Funding |
|---|---|---|
| Rye | Universal Checkout API — buys from sites with no prior merchant integration. Publishes SLA data: ~99% reliability on Amazon, 96% Shopify, 65% on non-integrated sites — the widest-cited quantification of the execution gap | ~$14M |
| Channel3 | Universal product graph + agent-side checkout middleware | $6M seed |
| Firmly | Unified "Buy Now" across agent channels | $5.2M, Nov 2025 |
| Zinc · CartAI · Henry Labs | Retailer purchasing API · white-label agentic cart · programmatic one-click checkout | Not disclosed |
Merchant enablement and discovery
| Company | What | Funding |
|---|---|---|
| FERMÀT | Shopper behaviour graph for human and agentic traffic | $45M Series B, Jun 2025 |
| Spangle AI | AI-generated storefronts; ex-Amazon founders | $15M Series A, Jan 2026 |
| ReFiBuy | Agentic commerce optimisation for brands | $13.6M seed, May 2026 |
| Catalog · Wildcard · Sitefire | Product data layer · SKU visibility in ChatGPT · generative engine optimisation | $3M · unconfirmed · undisclosed |
Note the incumbent PIM layer is repositioning fast: Salsify with an OpenAI integration, Syndigo with ACP-compliant feeds across 3,500+ retailers, Akeneo with an MCP server. And WooCommerce shipped MCP natively in core (WordPress 6.9 / Woo 10.3, hardened in 10.9), with ACP arriving via the Stripe extension — which closes most of the third-party plugin opportunity on the largest ecommerce platform by store count.
Billing, disputes, assurance
| Company | What | Outcome |
|---|---|---|
| Metronome | Usage-based billing; powered OpenAI, Anthropic, NVIDIA | Acquired by Stripe, Jan 2026 — reported ~$1B |
| Orb | Enterprise usage-based billing | Acquired by Adyen, $335M, Jun 2026 |
| Paid.ai | Outcome-based pricing for agents | $21M seed, Sep 2025 |
| Chargeflow · Justt | AI chargeback automation and representment | $35M Series A, Nov 2025 · $30M Series C, Dec 2024 |
| Klaimee | Audits agents; insurance-backed performance warranties. Certification + E&O + guarantee | $5.5M seed, Jul 2026 (YC) |
| Armilla | AI liability insurance; Lloyd's coverholder | $25M, Jan 2026 |
The two largest independent billing companies were both acquired within five months. Disputes remains the thinnest category — no dispute product scoped specifically to agent-initiated transactions has raised dedicated funding.
Corporate agent spend
Ramp ($750M Series F at $44B, Jun 2026) shipped AI Token Spend Controls built on Visa Intelligent Commerce. Mercury launched Agent Cards — virtual credit cards issued to individual AI agents — on 11 Aug 2026. Brex, Lithic, Marqeta and Highnote sit underneath. This category is closed to new entrants.
Consolidation
| Acquirer | Target | Price | Date |
|---|---|---|---|
| Mastercard | BVNK (stablecoin payments) | up to $1.8B | closed 3 Aug 2026 |
| Stripe | Bridge (stablecoin orchestration) | $1.1B | closed Feb 2025 |
| Stripe | Metronome (billing) | ~$1B reported | Jan 2026 |
| Adyen | Talon.One (promotions) | €750M | Apr 2026 |
| Adyen | Orb (billing) | $335M | Jun 2026 |
| PayPal | Cymbio | undisclosed | Jan 2026 |
No pure-play agentic-payments startup has been acquired. The M&A is all in adjacent, revenue-generating categories — stablecoin rails and billing. That is a signal about where value is currently provable.
Open problems
Where the infrastructure genuinely does not exist yet, ranked by how structurally hard they are to close.
- Reasoning-layer attacks defeat cryptographic mandates. The AP2 red-team result is unrebutted: 100% injection success with every transaction remaining cryptographically valid. No signature scheme fixes this. The only known mitigation is enforcement outside the model — wallet-level caps, allow-lists, out-of-band limits — which is why Cloudflare Wallets and Mercury Agent Cards matter more than they appear to.
- Nobody holds the evidence. The mandate, the prompt, the reasoning trace and the merchant response are scattered across parties with no obligation to share and active incentives not to. A neutral, tamper-evident record of delegated authority does not exist. This is the precondition for solving disputes, insurance, and regulatory audit simultaneously.
- Liability is unallocated in every jurisdiction. Not disputed — unallocated. There is no case law anywhere testing agent-initiated payment authorisation, no agent-specific reason code at any network, and no scheme liability shift. The merchant absorbs by default.
- An agent can buy but cannot cancel. Returns, cancellations and the new EU withdrawal button are not machine-actionable. The buy side of agentic commerce is roughly ten times more built out than the unwind side.
- Consumer trust is the binding constraint and no infrastructure investment touches it. 9% autonomous willingness. The only measured lever is safeguards — the return-window-plus-cap experiment moved millennials from 33% to 42%.
- Sub-cent tax is unhandled (§09) — small, specific, mandatory, and growing with M2M volume.
- The long tail has no path. WooCommerce is 35–44% of ecommerce sites by count and got native MCP in core; PrestaShop, Magento, 1C-Bitrix and custom builds have no vendor doing this for them. Non-US rails — UPI, PIX, QRIS — are absent from every protocol, all of which assume US card rails.
- M2M has no dispute concept at all. Stablecoin settlement has no chargeback, no Reg E, no CIT/MIT classification. Reversal generally requires law enforcement. As Visa notes, a single disputed "order" does not map to hundreds of sub-cent API calls.
Timeline
- 25 Nov 2024 Anthropic releases MCP.
- 9 Apr 2025 Google releases A2A.
- 29–30 Apr 2025 Mastercard Agent Pay and Visa Intelligent Commerce announced a day apart — the moment the networks entered.
- May 2025 Coinbase releases x402 v1.
- 28 Aug 2025 Cloudflare launches signed agents / Web Bot Auth.
- 16 Sep 2025 Google launches AP2 with ~60 partners.
- 29 Sep 2025 OpenAI Instant Checkout + ACP with Stripe and Etsy. Etsy stock +16%.
- 14 Oct 2025 Visa TAP with Cloudflare — agent identity via RFC 9421.
- 9 Dec 2025 MCP donated to the Agentic AI Foundation.
- 18 Dec 2025 Visa reports "hundreds" of production agent transactions.
- Jan 2026 Stripe completes the Metronome acquisition.
- 11 Jan 2026 Google launches UCP with Shopify, Etsy, Wayfair, Target and Walmart — a rival cart standard 3.5 months after ACP.
- 5 Mar 2026 Mastercard + Google publish Verifiable Intent.
- 6 Mar 2026 OpenAI withdraws native in-chat checkout. The category's reality check.
- 18 Mar 2026 Stripe + Tempo launch MPP; Visa publishes a card-based MPP spec the same day.
- 8 Apr 2026 Visa Intelligent Commerce Connect — protocol-agnostic gateway.
- 14 Apr 2026 Amex Agent Purchase Protection — the first and only issuer liability commitment.
- 18 Apr 2026 Visa Core Rules define "Agentic Transaction" — first binding network rules.
- 28 Apr 2026 AP2 and Verifiable Intent donated to FIDO Alliance. Google and OpenAI co-chair the new working group — the rival camps in one room.
- May 2026 UCP checkout goes live across Google Search and Gemini with Nike, Sephora, Target, Ulta, Walmart, Wayfair.
- 10 Jun 2026 Mastercard Agent Pay for Machines.
- 14 Jul 2026 x402 Foundation operational at the Linux Foundation, 40 members.
- 14 Jul 2026 HM Treasury opens the UK payments consultation asking the agentic authorisation question directly.
- 3–5 Aug 2026 Mastercard closes BVNK; Cloudflare Wallets enters early access; MAS confirms agents fall inside binding Singapore rules.
- 13 Aug 2026 x402 daily settlement volume reported down 93% year-to-date.
- 18 Aug 2026 Agentic Payments Alliance formed — Visa, Mastercard, Fiserv, Circle and 20+ others.
Glossary
- ACP
- Agentic Commerce Protocol. OpenAI + Stripe. Checkout and delegated-payment APIs; no cryptographic mandate object.
- Agentic token
- A network-issued payment credential bound to a specific agent, with consumer-set limits, revocable in real time.
- AP2
- Agent Payments Protocol. Google, now at FIDO. Signed Checkout and Payment Mandates as verifiable digital credentials.
- AP4M
- Mastercard Agent Pay for Machines. M2M sub-cent payments across cards, accounts and stablecoins.
- Bounded delegated authorisation
- Proposed legal test: an agent's act is authorised only within provable, pre-declared constraints. Beyond them it is an unauthorised payment.
- CIT / MIT
- Cardholder-Initiated / Merchant-Initiated Transaction. The binary that agent payments fit neither side of.
- Facilitator
- In x402, the party that verifies a payment payload and settles on-chain. All 15 tested failed at least one security rule.
- HTTP 402
Payment Required. Reserved and unused for ~30 years; now the basis of x402, MPP and L402.- Human-not-present
- An agent transacting autonomously against a pre-authorised mandate. Formalised in AP2 v0.2, April 2026.
- KYA
- Know Your Agent. Verifying agent identity and the legal entity behind it. Endorsed as a regulatory requirement by the IMF, April 2026.
- Mandate
- A signed, scoped record of what a human authorised an agent to do — merchant, amount ceiling, time window, category.
- MPP
- Machine Payments Protocol. Stripe + Tempo. Generalises HTTP 402 into a payment-method-agnostic auth scheme; superset of x402.
- SCA
- Strong Customer Authentication. The EU requirement built around a human act at initiation — the source of most agentic friction.
- Scoped token
- Single-use payment credential bound to amount, expiry and merchant. ACP's Delegate Payment mints these.
- TAP
- Visa Trusted Agent Protocol. Agent identity via RFC 9421 HTTP Message Signatures; not a payment protocol.
- UCP
- Universal Commerce Protocol. Google, Shopify et al. Capability-based commerce; delegates payment to AP2.
- Web Bot Auth
- IETF work on cryptographic authentication of automated clients. Widely deployed, still an individual draft.
- x402
- Coinbase's HTTP-402 stablecoin payment protocol, now at the Linux Foundation. USDC-centric, EIP-3009 gasless transfers.