Aashna Jain

What is agentic commerce, and how do AI agents pay for things?

3 min readFor buildersBuilding on it18 of 23By Aashna JainLast updated 27 September 2026

Every checkout ever built assumes a human is sitting there, ready to type an OTP. That human is starting to leave the room.

WHO IS HOLDING YOUR CARD
you sets the rules, then walks away the AI agent holds a key, not your card the merchant accepts the order the network checks the key fits the rules

The agent never sees your card number. That is the whole design.

Why checkout breaks

Look at any payment flow and count the moments that assume a person. Typing the card number. Reading an OTP off a phone. Ticking the box. Clicking pay. An agent can fake its way through some of these, and that is precisely the problem. An agent filling in your real card details on a form it found on the internet is not the future of commerce. It is a fraud team's nightmare with a friendly name.

So the networks are building something cleaner. In April 2025, Mastercard launched Agent Pay and Visa announced Intelligent Commerce, within a day of each other. Both rest on the same idea: the agent never receives your card. It receives a token, a stand-in credential, tied to that specific agent and fenced in by the limits you set. That September, both joined an open protocol Google published for agent payments, which describes how an agent proves it actually has your permission.

The four questions nobody has fully answered

Approval has to move earlier. There is no human at the moment of purchase, so consent happens upfront: a mandate that says what the agent may buy, where, and up to how much. Everything interesting happens in how that mandate is written and checked.

Scope is a dial, not a switch. A token can be locked to one merchant, one amount, one category, one week. Turn the dial tight and the agent is safe and nearly useless. Turn it loose and it is useful and slightly terrifying.

Liability is the open wound. If your agent books the wrong flight, is that fraud, a merchant dispute, or the agent company's problem? Chargeback rules were written for people who can be asked "did you authorise this?", and agents make that question much harder to answer.

And merchants have to change sides. They spent a decade building walls to keep bots out. Now some bots are customers, and the job is letting the good ones in without opening the door to everyone else.

What to decide if you build checkout

Three things, and they outlast whichever AI model is doing the shopping this year. How will you recognise a legitimate agent? What does a customer's mandate look like inside your system? And when an agent-made purchase is disputed, whose word counts? Get those right and the model can change underneath you without breaking anything.

Giving an agent your card number is handing a new assistant your whole wallet on their first day. The sensible version is a company card with a limit, a list of approved shops, and a statement you can read. The networks are, in effect, building the company card.

Where you meet it

Every AI assistant that offers to "just book it for you". Every network announcement with the word "agentic" in it. Every checkout team quietly wondering whether that bot traffic is an attack or a customer, and slowly realising it might be both.

FAQ

Can AI agents already pay for things? Yes. The card networks' agent payment programmes are live in early markets and pilots.

Who is liable when an agent buys the wrong thing? The rules are still being written. Today it depends on the network, the provider and the mandate you gave.

Building this? A second pair of eyes on the architecture is what the advisory is for. →

Get the next one in your inbox.

New fundamentals and one memo every two weeks.

One memo every two weeks. Unsubscribe in one click. Delivered through Substack, so their terms and privacy policy apply.