Atlas / GOVERN & LEAD / Frontier & Horizon / Agentic Commerce
DEEP-DIVE · FRONTIER & HORIZON

Agentic Commerce Protocols: UCP, ACP, AP2 and the Payment Rails

In 2026 AI agents became a sales channel, carried by a first generation of open protocols for discovery, checkout and payment authorization. How the stack fits together, what a merchant has to expose, how mandates and scoped tokens bound what an agent can spend, and where liability and fraud stand.

TL;DR
  • Agent checkout on a person's behalf moved from demo to production between late 2025 and 2026. The plumbing is a layered stack: discovery and checkout protocols such as Google and Shopify's UCP and OpenAI and Stripe's ACP, an authorization layer such as Google's AP2 for verifiable mandates, and card-network schemes that tokenize and recognize agent payments.
  • The protocols are complementary rather than rival, and the card networks participate in all of them, so merchants should expect to support several. The durable investment is underneath: machine-readable catalogs, real-time price and inventory, an API checkout path and policies an agent can read.
  • Authority is bounded by design: a human mandate defines what the agent may buy, and payment credentials are scoped to one merchant, one amount and a short time. Liability rules and fraud models for agent-initiated purchases are still settling, so start with reversible, low-value transactions and keep the evidence trail.

Agents became a sales channel

The agent economies deep-dive separates the speculative end of this space, agents negotiating and settling with one another, from the narrow part that is real. This article is about the real part. Between September 2025 and early 2026, assistants gained the ability to complete purchases for their users inside the conversation, payment networks shipped agent-specific tokens, and retailers began publishing their catalogs and checkout capabilities in forms agents can consume. By 2026 a customer asking an assistant to reorder printer ink or find and book a table was, for a growing number of merchants, a customer arriving through a new channel.

Gartner's machine customers framing captures the strategic consequence. When the buyer is an agent comparing structured offers, the levers that win shift from visual merchandising and brand experience toward accurate structured data, reliable fulfillment, clear policies and an API that works the first time. Merchants who are invisible to agents lose those transactions without ever seeing the shopper.

The protocol stack

The ecosystem produced several protocols in quick succession, which looks like a standards war and mostly is not. Each covers a different layer:

ProtocolBackersLayerWhat it standardizes
UCP (Universal Commerce Protocol)Google and Shopify; launched January 2026 with more than twenty partners including Walmart, Target, Etsy, Stripe, Visa, Mastercard and American ExpressDiscovery and checkoutMerchant capability profiles, so an agent can see supported services such as product search, checkout and returns before transacting
ACP (Agentic Commerce Protocol)OpenAI and Stripe; powering in-assistant checkout since September 2025Checkout through fulfillmentCheckout sessions and a shared payment token; an April 2026 release added catalog feeds, carts, orders, authentication and MCP integration
AP2 (Agent Payments Protocol)Google with more than sixty launch partners; contributed to the FIDO Alliance in April 2026Authorization and trustVerifiable mandates that prove what the user authorized, carried with the transaction
Network schemesVisa, Mastercard and othersPayment railAgent-specific tokens and ways for merchants to recognize trusted agents rather than treating them as bots
x402Coinbase and othersMachine micropaymentsPaying for API calls and digital resources over HTTP with stablecoins

The layers compose. A summary that circulated among practitioners in 2026 is roughly right: AP2 handles trust, UCP and ACP handle checkout, the card networks handle the rail, and x402 handles the edges. Underneath, MCP and A2A, covered in the agent interoperability deep-dive, carry much of the traffic. The networks' stance is the clearest signal of how this plays out: Mastercard said early in 2026 that it participates in all of the major protocols, which is what an industry expecting several to coexist would do.

Anatomy of an agent purchase

  USER  "reorder the usual ink, under $60, deliver by Friday"
    |   signs a mandate: merchant category, cap, deadline
    v
  AGENT discovers merchants and offers
    |   capability profiles + catalog feeds (UCP / ACP)
    v
  AGENT builds a cart, checks price, stock, delivery, policy
    |
    v
  CHECKOUT  via the merchant's protocol endpoint
    |   payment credential scoped to THIS merchant,
    |   THIS amount, a short time window, single use
    v
  NETWORK  recognizes a trusted agent, applies risk checks
    |
    v
  MERCHANT  fulfils; order status flows back to the agent
    |
  EVIDENCE  mandate + cart + authorization kept for disputes
An agent purchase in 2026: the human sets the mandate, protocols carry discovery and checkout, and a narrowly scoped payment credential means a mistake costs at most one bounded transaction.

The safety in this flow comes from scoping, not from the agent's good judgment. The shared payment token in ACP is bound to a specific merchant and amount, time-limited and single-use; card networks' agentic tokens work in a similar way. A mandate records what the user actually authorized, so the agent cannot quietly widen it. If the agent misunderstands, the damage is one bounded, disputable purchase rather than open access to a card.

What merchants must expose

For a merchant, protocol support is the visible part of a deeper readiness question. Agents need machine-readable product data with real identifiers and attributes, not just marketing copy; real-time price and inventory, because an agent that buys an out-of-stock item at a stale price creates a dispute; an API checkout path that does not depend on a browser session; and return, shipping and warranty policies in structured form, since an agent comparing offers will read them. Those are the same foundations the context layer deep-dive describes for internal agents, pointed outward.

Protocols are adapters; your catalog is the asset. Supporting UCP or ACP is weeks of integration work once the underlying data and checkout APIs are clean. If they are not, no protocol will help. Invest in the catalog, pricing and order APIs first, and treat each protocol as a thin adapter you can add as demand appears.

Expect to support more than one protocol, and to see different shares of traffic through each assistant ecosystem. Commerce platforms and payment providers increasingly offer the adapters, which shifts the merchant's work toward data quality and operations. Measure the new channel like any other: conversion, returns and disputes for agent-initiated orders, broken out by agent.

Being chosen by an agent

Supporting a checkout protocol only matters if agents pick your offer in the first place, and agents choose differently from people. They read structured attributes rather than banner images, compare total cost including shipping and returns, weigh delivery promises against what the user said, and favor merchants whose data has been accurate before. Several practical consequences follow.

Visibility in AI assistants is also a marketing question that sits beyond checkout: what the assistant says about your products and brand when it summarizes options. Marketing teams have started to track it, sometimes under the label generative engine optimization. For an architect the overlap is the data: the same accurate, structured, consistently published product information serves both the summary and the transaction.

Trust, fraud and liability

Agent commerce scrambles assumptions fraud teams rely on. Bot detection was built to block automated buyers; now some automated buyers are legitimate customers. Network schemes for recognizing trusted agents, and signatures that let an agent prove which platform it runs on, exist to separate good agents from scrapers and fraud bots, and merchants need to decide which agents they accept. Risk models trained on human behavior will misfire on agent behavior until they see enough of it.

Liability is the least settled part. When an agent buys the wrong thing, who absorbs the loss: the user who delegated, the platform whose agent misread the request, the merchant, or the issuer? Mandates and their evidence trail are the industry's answer in progress, because a signed record of what the user authorized is what a dispute will be decided on. Until rules mature, design for reversibility: low-value, returnable purchases first, clear confirmation for anything above a threshold, and evidence retained for every transaction.

The buyer side

The same rails serve enterprise buyers. Procurement agents that reorder supplies within a contract, book travel inside policy or buy software seats against a budget are a natural next step, and they need the controls the agent control plane deep-dive describes: an identity for the agent, a mandate that encodes policy, spending limits enforced outside the model, approval above thresholds and an audit trail finance can reconcile. Virtual cards and scoped tokens make this practical today for bounded categories; open-ended autonomous procurement remains, for now, the speculative end of the spectrum.

The mandate is the control. Whether the agent is a consumer's or a company's, the decisive artifact is the mandate: what may be bought, from whom, up to what amount and by when. Make it explicit, machine-enforced and retained, and most of the remaining risk becomes manageable.

The architect view

Agentic commerce is the first place where agent interoperability standards are carrying real money at scale, and it has moved faster than most of the agent stack because it rides on payment infrastructure that already knows how to tokenize, authorize and dispute. For sellers it is a channel decision; for buyers it is a delegation decision; for both, the protocols matter less than the data and controls underneath.

Four commitments apply. Sellers should make catalogs, pricing, inventory, policies and checkout available as clean APIs, then add protocol adapters as the channel grows. Everyone should bound agent spending with explicit mandates and scoped credentials, never with instructions in a prompt. Fraud and risk teams should build an agent policy: which agents are accepted, how they are recognized and how their orders are scored. And legal and finance should track the liability rules as they settle, keeping the evidence that disputes will turn on.

On the radar this is trial for consumer-facing merchants, where the traffic is already arriving, and assess for most others. The cost of being ready is mostly the cost of good commerce data, which pays for itself whether agents become the main channel or merely a significant one.

← Cyber-Capable Models: When Frontier AI Becomes Dual-Use ALL OF FRONTIER & HORIZON