Something significant shifted in payments this year. Visa and Mastercard — two organisations not known for moving quickly — both announced initiatives to give AI agents their own payment credentials. Visa's Intelligent Commerce programme and Mastercard's Agent Pay are designed to let autonomous software act as a financial principal: browsing, selecting, and transacting on a user's behalf without requiring the human to be present at the point of purchase. For most organisations, this barely registered. It should have stopped rooms full of senior leaders mid-conversation.
Agentic commerce — the model in which AI agents complete end-to-end purchasing journeys autonomously — has been a theoretical prospect for several years. What Visa and Mastercard have done is provide the financial plumbing that makes it commercially real. Once an agent can hold delegated payment authority, the bottleneck is no longer capability. It is trust, verification, and the infrastructure that brokers both. That is where the next competitive advantage in ecommerce will be won or lost.
What Agentic Commerce Actually Means in Practice
It is worth being precise about what we mean, because the term is doing a lot of work at the moment. An agentic commerce system is one in which a user delegates a purchasing goal — not a single transaction, but an outcome — to an AI agent. The agent then interprets that goal, researches options, compares suppliers, negotiates where possible, and completes payment. The user defines parameters: a budget ceiling, preferred brands, acceptable lead times. The agent handles everything else.
Consider a procurement manager at a mid-sized manufacturer who instructs an agent to 'replenish our fastener inventory before end of quarter, staying within the approved supplier list and keeping unit cost within five percent of last order.' That instruction, today, requires several hours of human effort across multiple systems. In an agentic commerce model, it becomes a background task. The agent queries supplier APIs, checks availability, validates pricing against the approved threshold, selects the optimal order, and processes payment using its delegated credentials — flagging the completed transaction for human review rather than human approval. The distinction matters enormously for operational efficiency.
The Trust Layer: Who Gets to Sit in the Middle
Here is where the commercially interesting tension emerges. When a human browses and buys, trust is established through well-worn mechanisms: the browser, the card network, the merchant's fraud stack, verified identity. When an agent transacts, none of those assumptions hold in the same way. The merchant cannot see a human. The agent may be acting on behalf of thousands of users simultaneously. The question of whether this agent is legitimate, authorised, and operating within the bounds its principal intended is non-trivial — and the answer to that question must come from somewhere.
That somewhere is the trust layer: the infrastructure that verifies agent identity, validates delegated authority, enforces spending parameters, and provides the audit trail that regulators, merchants, and consumers will ultimately require. Visa and Mastercard are staking a claim to parts of this layer through their credential frameworks. But the trust layer is not a single piece of infrastructure — it is a stack, and most of it remains unoccupied. Identity verification, merchant acceptance logic, policy enforcement, dispute resolution, and attribution all need to be solved. The organisations that build or control components of that stack will sit at the centre of every agentic transaction that flows through it. That is not a marginal position. That is the position Google held when it controlled search discovery.
Why Affiliate and Syndication Networks Become Critical Infrastructure
The implication that most ecommerce teams have not yet processed is this: if agents are making purchasing decisions, then the mechanisms by which agents discover, evaluate, and select products become the equivalent of search rankings and social feeds. Today, affiliate networks and product syndication platforms do the unglamorous work of connecting merchant catalogues to publisher audiences. They handle feed normalisation, tracking, commission attribution, and relationship governance. Those capabilities are, almost exactly, what an agentic commerce ecosystem needs — applied to a non-human buyer.
An AI shopping agent needs structured, reliable, machine-readable product data. It needs pricing signals it can trust. It needs to know which merchants have agreed to participate in agent-mediated transactions, what their fulfilment commitments are, and how disputes will be handled if something goes wrong. Affiliate and syndication infrastructure already solves versions of all of these problems for human-mediated channels. The networks that move quickly to extend their platforms toward agent compatibility — structured feeds, agent authentication, commission models that work without a cookie and a click — will find themselves positioned as essential middleware in a commerce model that could account for a substantial share of B2B and consumer transactions within a decade. This is not a peripheral opportunity. It is a fundamental repositioning of what that infrastructure is worth.
The Regulatory and Liability Questions No One Has Answered
It would be incomplete to discuss agentic commerce without acknowledging that the regulatory framework governing it is, at present, largely absent. When an AI agent makes a purchase that the principal later disputes — because the agent misinterpreted the parameters, or because fraud was involved, or because the merchant failed to deliver — who bears liability? The card networks are beginning to define their positions through their credential frameworks, but consumer protection law in the UK was written with human buyers in mind. The Financial Conduct Authority has not yet published guidance specific to AI-mediated financial transactions, and the Consumer Rights Act's assumptions about informed consent sit awkwardly against autonomous purchasing.
Organisations that begin building agentic commerce capabilities now — whether as merchants, intermediaries, or platform operators — should treat the regulatory gap as a design constraint rather than a loophole. Building auditable decision logs, explicit delegation frameworks, and clear dispute pathways into your architecture from the outset is both the ethical approach and the commercially sensible one. When regulation does arrive, and it will, the organisations that have already embedded compliance-ready infrastructure will face far lower adaptation costs than those that built fast and loose.
The practical question for senior leaders is not whether agentic commerce will become significant — the financial infrastructure to enable it now exists, and commercial incentives are aligned strongly enough that adoption will accelerate. The question is where your organisation sits in the emerging architecture, and whether that position is intentional or accidental.
For merchants, the immediate priority is ensuring your product data is structured, complete, and machine-readable enough to be evaluated by an agent rather than a human. For platform operators and technology leads, the more strategic question is whether your existing infrastructure — feeds, APIs, attribution, verification — could be extended to serve as trust layer components in an agentic transaction chain. The organisations that move now will be defining standards. Those that wait will be implementing them on someone else's terms. If you are unsure where to start, the most useful first step is an honest audit of your current data and integration architecture against the requirements of a non-human buyer. What you find will tell you a great deal about how ready you actually are.
What is the difference between Visa Intelligent Commerce and Mastercard Agent Pay?
Both initiatives aim to give AI agents delegated payment credentials, but they approach the problem from slightly different angles. Visa Intelligent Commerce focuses on embedding tokenised, parameter-bound credentials into agent frameworks so spending limits and merchant restrictions are enforced at the card level. Mastercard Agent Pay emphasises identity verification for the agent itself, establishing that the agent is operating on behalf of a verified human principal. In practice, they are complementary rather than competing standards, and most agentic commerce implementations are likely to need elements of both.
Can AI agents already make purchases on my behalf using these systems?
As of the launches announced in 2025, both Visa and Mastercard's frameworks are in early rollout phases, primarily available to selected partners and developer ecosystems. Consumer-facing agentic commerce at scale remains a near-term prospect rather than a present reality for most users. However, B2B procurement use cases, where structured APIs and pre-agreed supplier relationships already exist, are closer to deployment than consumer scenarios.
How does an AI agent verify it has the authority to spend on a user's behalf?
This is precisely the problem the trust layer must solve. Current frameworks use delegated credential tokens — essentially a scoped payment instrument that carries encoded spending rules and is cryptographically tied to an authorised principal. The agent presents this credential at the point of transaction, and the card network or intermediary validates that the transaction falls within the delegated parameters before authorising payment. Dispute or override mechanisms are still being defined by most networks.
What does 'machine-readable product data' actually mean for a merchant?
It means your product catalogue, pricing, availability, and fulfilment terms are exposed in a structured, standardised format that software can query and evaluate without human interpretation. This typically involves clean product feeds in formats like JSON-LD or structured XML, schema.org markup on your website, and stable APIs that return consistent, up-to-date data. Many merchants have acceptable human-facing product pages but poor machine-readable equivalents — that gap will become commercially significant as agentic buyers grow.
Will agentic commerce require merchants to integrate with new platforms or networks?
Almost certainly, yes, though the extent will depend on your market and transaction type. Merchants will likely need to register with agent-commerce networks or extend existing affiliate and syndication relationships to cover agent-mediated transactions. This will involve agreeing to new terms covering agent authentication, dispute resolution, and commission attribution. Early movers who establish these integrations proactively will have a catalogue discovery advantage over those who wait.
How should UK businesses think about data protection compliance in agentic transactions?
UK GDPR applies to personal data processed during an agentic transaction just as it does in human-mediated ones. The challenge is that an agent may query multiple merchant systems, comparison engines, and data sources before completing a purchase — each of those touchpoints potentially involves personal data about the principal. Organisations building agentic systems need to map data flows carefully, establish lawful bases for each processing activity, and ensure that delegation of purchasing authority is captured as an explicit and auditable user action.
What happens if an AI agent makes a purchase the user didn't intend or want?
This is an open question that existing consumer protection frameworks do not cleanly answer. The merchant has fulfilled a legitimate-looking order from a credentialled agent. The user may argue they did not authorise the specific purchase within the agent's parameters. Card network chargeback rules were not written for this scenario. Until specific regulation emerges, the practical safeguard is building human-review checkpoints into high-value or first-time transactions, and ensuring your agent architecture logs every decision with sufficient detail to reconstruct the reasoning.
Is agentic commerce only relevant to large enterprises, or should SMEs pay attention?
SMEs should pay attention, particularly those selling through B2B channels or marketplaces. Agentic procurement tools are likely to emerge first in categories where purchasing is repetitive, rule-bound, and currently labour-intensive — which describes a significant portion of SME supply chain activity. An SME that is not discoverable or compatible with agent-mediated purchasing may find itself excluded from procurement workflows it currently participates in via human buyers.
How does attribution and commission tracking work when there is no human click to track?
Traditional affiliate attribution relies on cookies and click events tied to a human session — neither of which exists in an agent transaction. The emerging model uses agent identity tokens and transaction-level attribution passed through the payment credential itself, allowing the network to associate a completed purchase with the agent pathway that sourced the product. This requires affiliate platforms to update their attribution logic, and merchants to accept token-based rather than cookie-based commission triggers.
What should a technology lead do right now to prepare their organisation for agentic commerce?
Start with an audit of your current API and data infrastructure against the requirements of a non-human buyer: structured product data, stable pricing APIs, machine-readable fulfilment terms, and clear authentication endpoints. Then assess your affiliate or syndication relationships to understand whether those partners are building agent-compatible capabilities. Finally, establish internal governance around what spending delegation your organisation is willing to accept or extend — because the policy decisions are as important as the technical ones, and they take longer to resolve.
Get in touch today
Book a call at a time to suit you, or fill out our enquiry form or get in touch using the contact details below