
You wake up and find a package already on its way. Your AI assistant chose the product, selected the seller, and paid for it using permissions you gave. Weeks ago, the bank sees a valid transaction. The stores sees an authorized buyer. The AI company says the system followed your spending rules, but you never chose that product. You’ll start to see a shift of real agent counter. Not just me pressing the buy button on one of these platforms, but me empowering an agent on my behalf. Until now, an AI mistake can give you a bad answer. Soon the same mistake could move real money and when that happened, the hardest question may not be how to reverse the payment. It may be deciding who actually made the purchase.
The Shift to Agentic Commerce
The question is moving from science fiction into payment infrastructure. On June 10, 2026, Visa announced a collaboration with OpenAI designed to bring Visa payment into agentic commerce. The system gives an AI agent a tokenized payment credential linked to a real account along with boundaries set by the user. A person could ask for noise-canceling headphones under $150, restrict the search to trusted merchants, and require approval only when the price crosses a chosen limit. The agent could search, compare, select, and complete the purchase inside those rules. The final click—the moment that once proved a person had reviewed the order—is becoming optional.
Mastercard has already moved beyond demonstrations. In June 2026, Mastercard, ING, and Worldline reported a live end-to-end agent payment in Europe. Earlier that year, authenticated agent pay transactions were completed in Australia. Google is building the same future through its Universal Commerce Protocol and Agent Payment Protocol, allowing merchants, customer agents, and payment providers to exchange shopping instructions in a common machine-readable format. Merchants need to trust that if an agent is showing up at their digital doorstep, it’s actually there on your behalf and you’ve empowered it, and your bank needs to trust that when they get a request to authorize a transaction on your behalf that you really wanted that to happen.
The Scale of the Machine Economy
The scale behind this shift is enormous. Visa processes hundreds of billions of transactions across its network, while its fraud systems already evaluate more than 500 data points during checkout. Adding AI agents creates a new participant inside that machinery: software carrying its own identity credentials, permissions, and transaction history. Payment systems can verify the token, the spending limit, the merchant, and the recorded authorization. The harder part begins earlier inside the agent’s decision. It may have followed every financial rule while choosing the wrong item, trusting a manipulated listing, or misunderstanding what the user wanted. The payment can pass every security check and still begin with a corrupted choice.
Once agents can complete purchases, the market gains a new kind of customer. A human shopper notices photography, reviews, discounts, and brand familiarity. An AI shopper reads structured data, inventory, return windows, delivery estimates, seller history, product specifications, payment compatibility, and whatever signals its model has learned to rank. Merchants now have a reason to shape listings for machine interpretation as aggressively as they once shaped pages for search engines.
Protocols and Cryptographic Trails
Google’s Agent Payments protocol reveals how this machine economy may work. The user first creates an “intent mandate” describing the goal: find a specific product, stay within a budget, use approved sellers, meet a delivery date. After the agent chooses an offer, a second record captures the exact item, merchant, and price. A final payment mandate authorizes the transaction. Together, these records create a cryptographic trail showing what authority the agent received and what it eventually bought.
That trail could become the receipt for the entire decision. It also changes what competition looks like. A seller may win because its return policy is easier for an agent to pass. A product may rank higher because its metadata maps neatly onto users’ requests. Sponsored placement, platform partnerships, and preferred payment integrations could influence which options enter the agent’s shortlist before the user sees anything. The Web spent two decades competing for human attention. Agentic Commerce introduces competition for machine selection.
The Risks of Manipulation
A market designed for machines also creates a new target for manipulation. Indirect prompt injection allows an attacker to hide instructions inside material an AI agent is expected to read. The payload can sit inside webpage metadata, product text, reviews, tool responses, or code that remains invisible on the rendered page. The agent processes the instruction as part of its task and may quietly change its behavior. Researchers tested this directly against a shopping agent built around Google’s Agent Payment Protocol. In one experiment, a malicious merchant prompt altered the agent’s product ranking and pushed the attacker’s item above stronger alternatives. The system then generated a plausible explanation for the choice; the cryptographic mandates remained intact, but the reasoning that created them had already been steered.
Security agencies are treating this as an active systems problem. NIST describes agent hijacking as malicious instructions inserted into data an agent consumes, causing unintended actions. In a large public Red Team competition involving 272,000 attack attempts across 13 frontier models, researchers recorded 8,648 successful attacks. Every tested model was vulnerable. For a shopping agent, the attack can remain almost perfectly quiet. The selection was compromised, and the selection is the part nobody can easily see.
Responsibility and the Human Element
Once a manipulated decision becomes a valid transaction, responsibility fractures across the system. The user supplied the goal and granted spending authority. The AI company operated the agent. The merchant provided the listing. The payment network verified the credentials. The bank approved a transaction that matched the account’s normal rules. Each participant can produce evidence showing that its own step worked as designed. The legal system has already encountered an early version of this identity problem: are AI agents simply extensions of the user, or automated visitors with a separate identity?
The simplest safeguard is human approval. The agent prepares the order, the user checks it, and the payment moves only after confirmation. However, that protection weakens through repetition. Each successful transaction becomes evidence that close supervision can be reduced. Eventually, the agent stops feeling like software asking for permission; it begins to feel like the part of you that handles money. Scale that habit across millions of users, and commerce begins to change. People may know what they bought while losing sight of how the choice was formed.
The technology may work beautifully for months before anyone notices how much judgment has migrated into the background. Then one morning, a package appears that the system can explain perfectly. The credential was valid, the seller was approved, the price stayed within the limit, the agent followed the rules. Only the person standing at the door feels that something is missing. The most important question in this new economy may never be whether AI can spend our money. It may be whether we can still recognize our own decisions after it does.
The Question We Should Be Asking
The AI industry has spent enormous effort teaching machines how to understand language, reason about information and execute tasks.
The payments industry is now teaching those machines how to interact with financial systems.
The next challenge is trust.
Not just:
Can the agent pay?
But:
Should the agent pay?
Not just:
Was the transaction authorized?
But:
Was the decision authorized?
Not just:
Who owns the account?
But:
Who owns the decision?
Those questions will become increasingly important as AI agents move from assisting humans to acting on their behalf.






Recent Comments