Agentic Commerce: What Happens to Payments When the Buyer Is an AI
Every layer of the card payment stack rests on one assumption so old it stopped being visible: a human is present at checkout. Authentication proves a human is who they claim to be. Fraud models score whether behavior looks like a real person. Chargeback rules arbitrate what a reasonable cardholder intended. Interchange prices the risk that the human was not who, or where, they appeared to be. AI agents that research, compare, and complete purchases on a customer's behalf break that assumption at every one of those layers simultaneously, and the industry has spent the past year repricing it in real time.
The convenient framing, the one in most vendor decks, is that agentic commerce is a new checkout button: the same transaction with a different finger pressing buy. The evidence points somewhere less comfortable. Agentic commerce is a liability regime change. The question the stack was built to answer, did this human authorize this payment, becomes a question the stack has no machinery for: did this human authorize this agent to make this specific purchase under these specific conditions. Everything interesting in the space, the network token programs, the mandate protocols, the fraud-model rebuilds, the fights over who eats the chargeback, is downstream of that substitution.

The Mandate Problem Is the Whole Problem
Start with the scenario every payments lawyer has now gamed out. A customer tells an agent to find a flight under a certain price. The agent, operating with the customer's stored credential, books a flight that technically matches the instruction but misses the intent: wrong airport, brutal layover, non-refundable fare. The customer disputes. Who is liable: the customer who gave a vague instruction, the agent platform whose software interpreted it, the merchant who accepted a payment from software, or the issuer who approved it?
Under current rules, the answer is a mess, because the dispute framework only has two categories that come close. Either the transaction was unauthorized, which it was not, the customer provisioned the credential to the agent, or it is buyer's remorse, which it also is not, the buyer never chose this flight. The transaction sits in a category the rules do not name: authorized agent, unauthorized outcome. This is the mandate problem, and it is the load-bearing problem of agentic commerce: proving, cryptographically and after the fact, that the agent had authority for this purchase, at this price, from this merchant, at this time, and not merely general access to a card number.
The serious infrastructure work of the past eighteen months is all mandate machinery. Google's Agent Payments Protocol, announced in September 2025 with more than sixty partners including Mastercard, PayPal, and American Express, is built around signed digital mandates: a cryptographically verifiable record of what the user asked for and what the agent was permitted to do, generated before the transaction and auditable after it. OpenAI and Stripe's Agentic Commerce Protocol, which powers Instant Checkout in ChatGPT, scopes a shared payment token to a specific merchant and transaction context, so the credential the agent holds is useless outside the purchase it was minted for. The design instinct is identical across both camps: never give the agent the card, give it a narrow, provable, revocable slice of authority. Delegation is being rebuilt as a first-class payment primitive, which is precisely what the executive framing of agentic AI as delegated authority predicts: the technology question is capability, but the deployment question is always mandate scope.

This is a Premium Article
Sign up for a Premium membership to read this article and get full access to strategic intelligence on technology and business.
Already a member? Sign in