ANNOUNCEMENT: Wolters Kluwer and FairPlay AI Partner to Deliver End-to-End Fair Lending Optimization

Featured podcast on agentic commerce with two speakers
Featured podcast on agentic commerce with two speakers

When Your AI Starts Shopping for You, Who Approves the Purchase?

For thirty years, online shopping has been built around the assumption that the buyer is human.

A person searches. A person compares. A person clicks. A person agrees to the terms. A person enters a card number or selects a wallet. A person decides to buy.

Agentic commerce breaks that assumption.

Watch the Conversation

In the next version of commerce, an AI agent may discover the product, compare the options, fill the cart, initiate checkout, and handle post-purchase tasks on behalf of a consumer. That does not simply make shopping more convenient. It introduces a new actor into the transaction: software that can act on a consumer’s instructions.

That is why agentic commerce is not just a payments story. It is a trust story. More precisely, it is a story about delegated authority.

If a person tells an AI agent, “Find me the best flight to Miami under $1,000,” what exactly has that person authorized? Can the agent pick the airline? Can it choose the hotel? Can it accept a cancellation policy? Can it agree to a subscription, a service fee, or a nonrefundable booking? And if the agent makes a bad decision while technically following the instruction, who is responsible?

These are the questions at the center of agentic commerce. They are also the questions Visa is trying to answer.

On Model Citizens, FairPlay founder and CEO Kareem Saleh spoke with Marc Houben, Visa’s head of agentic commerce in the US, about the infrastructure that will be needed before consumers, merchants, banks, and platforms can trust AI agents to transact at scale.

The conversation made one thing clear: agentic commerce will not scale just because agents become more capable. It will scale only if the surrounding infrastructure can prove what the agent is, what it is allowed to do, what the consumer approved, and how the transaction can be controlled.

Agentic commerce introduces a new actor: the agent

In traditional ecommerce, the customer is the primary actor. The website may influence the customer, and the payment network may process the transaction, but the consumer is still the one moving through the purchase journey.

Agentic commerce changes that.

As Houben explained, there is now a new entity sitting between the cardholder and the merchant: the agent. That agent may discover products, fill a cart, complete checkout, or even take post-purchase actions on the consumer’s behalf.

That sounds like a small change, but it is not. The introduction of an agent changes the basic structure of online commerce.

Merchants have to decide whether to let agents browse, compare, and buy. Issuers have to understand whether a transaction came from a person, a bot, or a vetted AI platform. Consumers have to know what they have authorized. Platforms have to decide how much autonomy to give their agents. And regulators will eventually ask whether consumers were adequately protected when software began making economic decisions on their behalf.

In other words, the question is not simply, “Can AI shop for me?”

The better question is, “What kind of authority am I giving this system, and how do I know it will use that authority correctly?”

Websites were built for people, not software shoppers

One of the most interesting points in the conversation was that the current web was not built for agents.

Visa initially considered a world in which an agent might travel to a merchant’s website and complete a transaction through a guest checkout flow. But merchant websites are designed for human beings. They are full of pop-ups, banners, ads, menus, images, forms, checkout steps, and other interface elements that make sense for people but may create friction for software.

A human shopper can close a pop-up, interpret a promotion, decide whether to accept cookies, understand that an item is out of stock, or notice that a discount code failed. An agent may not handle those same moments reliably unless the site has been designed, scored, or integrated for agentic access.

That means agentic commerce may require more than better AI models. It may require a new layer of commerce infrastructure.

Merchants will need to make their products, prices, policies, and checkout flows legible to agents. AI platforms may develop protocols that allow merchants to connect directly into agentic environments. Payment networks may help merchants distinguish trusted agents from unknown automated traffic. And the industry may need new standards for how agents identify themselves, transmit intent, and complete transactions.

This is a much bigger shift than “AI makes shopping easier.” It means the architecture of ecommerce may have to evolve from human-readable websites to agent-readable commerce systems.

Visa’s answer is programmable trust

Visa’s approach to agentic commerce is built around a simple idea: if consumers are going to delegate purchasing authority to agents, that authority should be controlled, observable, and revocable.

That starts with tokenization.

Instead of giving an AI agent a raw card number, Visa’s framework can use an agentic token. The token replaces the card number and can carry information about the agentic nature of the transaction. It can also be scoped to a particular purpose, capped at a certain amount, and set to expire.

That matters because delegation should not be unlimited.

A consumer may be comfortable authorizing an agent to buy a $40 household item today. That does not mean the agent should be able to use the same payment credential to spend $4,000 next month. A consumer may authorize an agent to book a hotel within a specified budget. That does not mean the agent should be able to accept every fee, upgrade, or nonrefundable term without further confirmation.

Programmable payments make it possible to put boundaries around the agent’s authority.

But tokens alone do not answer the whole trust question. A token can limit what an agent is able to spend, but it does not by itself prove that the consumer intended to make a particular purchase. That is why authentication remains essential.

The system may require a one-time password, an issuer-side step-up, or biometric authentication before a transaction is completed. In plain English, the consumer can still be asked to confirm the purchase before the agent is allowed to proceed.

Together, these tools create a more controlled version of delegated commerce. The agent may be able to act, but it acts within limits. The transaction may be automated, but it is not invisible. The consumer may delegate execution, but the system can still preserve moments of consent.

In this vision of agentic commerce, trust is built into the transaction flow.

Merchants and issuers face different readiness problems

Agentic commerce creates different challenges for different parts of the ecosystem.

For merchants, the question is whether their products and checkout experiences are ready to be discovered and used by agents.

A merchant will need to understand how its catalog appears inside AI platforms. It will need to know whether agents can accurately interpret product details, prices, shipping terms, return policies, availability, and eligibility rules. It may need to redesign parts of its digital infrastructure so agents can interact with its systems without breaking the customer experience or creating fraud risk.

There is also a strategic question. If consumers start asking agents what to buy, the merchant’s website may no longer be the primary place where discovery happens. The agent may become a new acquisition channel, a new gatekeeper, or both.

For issuers, the questions are different.

Banks and card issuers will need to know when a transaction is coming from an AI platform. They will need indicators that help them assess fraud risk, authenticate the cardholder, and understand whether the transaction is consistent with the consumer’s instructions. They will also need to think about their top-of-wallet strategy in a world where consumers may not be choosing a card at checkout in the traditional way.

In today’s ecommerce environment, a consumer often chooses from cards, wallets, or payment options at the moment of purchase. In an agentic environment, the card may already be provisioned inside an AI platform. That changes the battle for payment preference.

The issuer’s question becomes: when an agent is ready to buy, is our card the one it uses?

The future is not fully autonomous yet

It is tempting to describe agentic commerce as a world where consumers simply hand over a goal and the AI handles everything. That future may arrive, but it is not the current state of the market.

Today, the industry is still closer to ecommerce than to full autonomy.

In many cases, the human remains in the loop. The agent may help discover products, compare options, or prepare a cart, but the consumer still approves the final purchase. In other cases, the merchant remains in the loop through platform integrations, policies, and checkout controls.

The near-term future of agentic commerce is not necessarily a world where an AI independently books an entire vacation, chooses every vendor, accepts every term, and completes every payment without human review. The more likely path is gradual delegation. Agents will begin with lower-risk, more constrained tasks. Over time, as the infrastructure improves and consumers become more comfortable, agents may be given more authority.

The adoption curve will probably not be uniform. Some categories will remain highly human for a long time. Consumers may want to personally approve expensive purchases, emotionally significant purchases, regulated products, financial products, or anything involving complex terms.

Other categories may become agentic much faster. Replenishment purchases, simple travel components, business procurement, software subscriptions, and developer workflows may be easier to automate because the intent is clearer and the choices are more structured.

The point is not that humans disappear from commerce. The point is that human involvement becomes more selective.

Developer agents may move faster than consumer shopping

One of the more revealing parts of the conversation came near the end, when Houben pointed to the developer ecosystem as a place where agentic payments could become especially interesting.

Software developers are already using coding agents and command-line tools to write code, generate assets, call services, and automate technical workflows. If those agents can also pay for APIs, cloud resources, software tools, data services, or other digital capabilities, the path to autonomous transactions may be shorter than in consumer retail.

That use case is different from asking an agent to plan a family vacation or choose a birthday gift. A developer agent may operate in a more structured environment. The purchases may be tied to a task. The service being purchased may have clear pricing. The value of automation may be obvious. And the user may be more comfortable granting bounded authority inside a professional workflow.

This is one reason agentic commerce may not arrive first in the places consumers expect. The first meaningful examples may not look like a personal shopping assistant buying clothes. They may look like a coding agent buying access to an API, a business agent procuring a service, or an enterprise workflow paying for a task-specific tool.

That would still be commerce. It would just be commerce happening inside software workflows rather than traditional storefronts.

The real issue is whether agents act in the user’s interest

The deepest question in agentic commerce is not whether an agent can complete a transaction. It is whether the agent is actually working for the user.

That question will become more important as agents gain more autonomy.

An agent may be technically accurate but still harmful. It may follow the user’s instruction but steer toward products that benefit the platform. It may disclose terms in a way that satisfies a formal requirement but does not meaningfully inform the consumer. It may perform well for some users but poorly for others. It may optimize for convenience while ignoring cost, fairness, privacy, or suitability.

Those are not simply payment questions. They are governance questions.

Agentic commerce will require systems that can answer questions such as:

Did the agent follow the user’s instructions?

Did it stay within the user’s mandate?

Did it disclose material terms?

Did it avoid unauthorized fees, subscriptions, or commitments?

Did it steer the consumer toward outcomes that served the platform more than the user?

Did it perform consistently across different consumers, merchants, products, and transaction types?

Did the system preserve meaningful human consent when consent was required?

These are validation questions. And they will matter before deployment, during launch, and after the system is operating in the real world.

Trust has to be tested

Every major shift in commerce introduces a new trust problem.

Ecommerce required consumers to trust websites with their card numbers. Mobile commerce required consumers to trust devices, apps, and wallets. Agentic commerce requires consumers to trust software with delegated authority.

The encouraging part is that the building blocks already exist. Tokenization, authentication, biometrics, issuer controls, transaction indicators, wallets, and trusted-agent directories can all help make agentic commerce safer and more reliable.

But building blocks are not enough.

The systems still have to be tested. The agents still have to be validated. The transaction flows still have to be monitored. And the ecosystem still has to prove that the software acting on behalf of consumers is actually acting within the authority those consumers intended to grant.

In agentic commerce, that means testing whether agents behave as expected, stay within scope, treat users consistently, and produce outcomes that can be explained, monitored, and trusted.

The future of commerce will not be defined only by faster checkout. It will be defined by how much authority people are willing to hand to machines — and whether those machines can prove they deserve it.

Frequently Asked Questions

What is agentic commerce?

Agentic commerce is a form of digital commerce in which an AI agent can help discover products, compare options, fill a cart, initiate checkout, complete a purchase, or handle post-purchase tasks on behalf of a consumer or business.

How is agentic commerce different from ecommerce?

In traditional ecommerce, the consumer usually drives the transaction directly. The consumer searches, compares, clicks, approves, and pays. In agentic commerce, software may perform some or all of those steps based on the consumer’s instructions.

What is an agentic token?

An agentic token is a payment token designed for transactions initiated by or through an AI agent. Instead of giving the agent a raw card number, the system can use a token that is limited to a specific purpose, capped at a certain amount, and set to expire.

Why does agentic commerce create new trust questions?

Agentic commerce creates new trust questions because the consumer is delegating both intent and execution to software. The system has to determine what the consumer authorized, what the agent is allowed to do, how the transaction should be authenticated, and who is responsible if something goes wrong.

What should merchants do to prepare for agentic commerce?

Merchants should make sure their products, prices, policies, and checkout flows can be understood by agents. They should also prepare for a world in which AI platforms become an important discovery channel and in which merchants need to distinguish trusted agents from unknown automated traffic.

What should issuers do to prepare for agentic commerce?

Issuers should prepare to receive clearer signals about agentic transactions, authenticate consumer intent, manage fraud risk, and think about how their cards remain preferred payment methods inside AI platforms and agentic workflows.

Why does agentic commerce matter for AI governance?

Agentic commerce matters for AI governance because agents may make or influence economic decisions on behalf of people. That means the agents need to be tested for accuracy, authorization, consistency, disclosure, steering, and compliance with the user’s instructions.

What role does FairPlay play in agentic commerce?

FairPlay helps validate AI systems and autonomous agents. In agentic commerce, that means testing whether agents follow instructions, stay within authorized limits, disclose material terms, avoid harmful steering, and produce outcomes that users, merchants, issuers, and regulators can trust.

FairPlay builds the evaluation layer for AI systems in financial services, from predictive models to autonomous agents. See how FairPlay evaluates AI systems.

Ready to get more out of your models?

Join leading financial institutions in deploying better AI faster.

Schedule a DemoChat With Us