- Agent checkout on a person's behalf moved from demo to production between late 2025 and 2026. The plumbing is a layered stack: discovery and checkout protocols such as Google and Shopify's UCP and OpenAI and Stripe's ACP, an authorization layer such as Google's AP2 for verifiable mandates, and card-network schemes that tokenize and recognize agent payments.
- The protocols are complementary rather than rival, and the card networks participate in all of them, so merchants should expect to support several. The durable investment is underneath: machine-readable catalogs, real-time price and inventory, an API checkout path and policies an agent can read.
- Authority is bounded by design: a human mandate defines what the agent may buy, and payment credentials are scoped to one merchant, one amount and a short time. Liability rules and fraud models for agent-initiated purchases are still settling, so start with reversible, low-value transactions and keep the evidence trail.
Agents became a sales channel
The agent economies deep-dive separates the speculative end of this space, agents negotiating and settling with one another, from the narrow part that is real. This article is about the real part. Between September 2025 and early 2026, assistants gained the ability to complete purchases for their users inside the conversation, payment networks shipped agent-specific tokens, and retailers began publishing their catalogs and checkout capabilities in forms agents can consume. By 2026 a customer asking an assistant to reorder printer ink or find and book a table was, for a growing number of merchants, a customer arriving through a new channel.
Gartner's machine customers framing captures the strategic consequence. When the buyer is an agent comparing structured offers, the levers that win shift from visual merchandising and brand experience toward accurate structured data, reliable fulfillment, clear policies and an API that works the first time. Merchants who are invisible to agents lose those transactions without ever seeing the shopper.
The protocol stack
The ecosystem produced several protocols in quick succession, which looks like a standards war and mostly is not. Each covers a different layer:
| Protocol | Backers | Layer | What it standardizes |
|---|---|---|---|
| UCP (Universal Commerce Protocol) | Google and Shopify; launched January 2026 with more than twenty partners including Walmart, Target, Etsy, Stripe, Visa, Mastercard and American Express | Discovery and checkout | Merchant capability profiles, so an agent can see supported services such as product search, checkout and returns before transacting |
| ACP (Agentic Commerce Protocol) | OpenAI and Stripe; powering in-assistant checkout since September 2025 | Checkout through fulfillment | Checkout sessions and a shared payment token; an April 2026 release added catalog feeds, carts, orders, authentication and MCP integration |
| AP2 (Agent Payments Protocol) | Google with more than sixty launch partners; contributed to the FIDO Alliance in April 2026 | Authorization and trust | Verifiable mandates that prove what the user authorized, carried with the transaction |
| Network schemes | Visa, Mastercard and others | Payment rail | Agent-specific tokens and ways for merchants to recognize trusted agents rather than treating them as bots |
| x402 | Coinbase and others | Machine micropayments | Paying for API calls and digital resources over HTTP with stablecoins |
The layers compose. A summary that circulated among practitioners in 2026 is roughly right: AP2 handles trust, UCP and ACP handle checkout, the card networks handle the rail, and x402 handles the edges. Underneath, MCP and A2A, covered in the agent interoperability deep-dive, carry much of the traffic. The networks' stance is the clearest signal of how this plays out: Mastercard said early in 2026 that it participates in all of the major protocols, which is what an industry expecting several to coexist would do.
Anatomy of an agent purchase
USER "reorder the usual ink, under $60, deliver by Friday"
| signs a mandate: merchant category, cap, deadline
v
AGENT discovers merchants and offers
| capability profiles + catalog feeds (UCP / ACP)
v
AGENT builds a cart, checks price, stock, delivery, policy
|
v
CHECKOUT via the merchant's protocol endpoint
| payment credential scoped to THIS merchant,
| THIS amount, a short time window, single use
v
NETWORK recognizes a trusted agent, applies risk checks
|
v
MERCHANT fulfils; order status flows back to the agent
|
EVIDENCE mandate + cart + authorization kept for disputes
The safety in this flow comes from scoping, not from the agent's good judgment. The shared payment token in ACP is bound to a specific merchant and amount, time-limited and single-use; card networks' agentic tokens work in a similar way. A mandate records what the user actually authorized, so the agent cannot quietly widen it. If the agent misunderstands, the damage is one bounded, disputable purchase rather than open access to a card.
What merchants must expose
For a merchant, protocol support is the visible part of a deeper readiness question. Agents need machine-readable product data with real identifiers and attributes, not just marketing copy; real-time price and inventory, because an agent that buys an out-of-stock item at a stale price creates a dispute; an API checkout path that does not depend on a browser session; and return, shipping and warranty policies in structured form, since an agent comparing offers will read them. Those are the same foundations the context layer deep-dive describes for internal agents, pointed outward.
Expect to support more than one protocol, and to see different shares of traffic through each assistant ecosystem. Commerce platforms and payment providers increasingly offer the adapters, which shifts the merchant's work toward data quality and operations. Measure the new channel like any other: conversion, returns and disputes for agent-initiated orders, broken out by agent.
Being chosen by an agent
Supporting a checkout protocol only matters if agents pick your offer in the first place, and agents choose differently from people. They read structured attributes rather than banner images, compare total cost including shipping and returns, weigh delivery promises against what the user said, and favor merchants whose data has been accurate before. Several practical consequences follow.
- Completeness beats persuasion. A product with every attribute filled, consistent identifiers and accurate availability is more likely to match a precise request than one with better copy and missing fields.
- Price and stock must be live. An agent that finds a discrepancy at checkout abandons the order, and assistant platforms can learn which merchants to avoid.
- Policies are part of the offer. Clear, structured return windows and delivery guarantees let an agent satisfy constraints like "must arrive by Friday" or "only if returnable"; vague ones lose to competitors who state them.
- Reliability compounds. Fulfillment accuracy, low dispute rates and fast order-status updates are signals platforms can use, so operational quality turns into discoverability.
Visibility in AI assistants is also a marketing question that sits beyond checkout: what the assistant says about your products and brand when it summarizes options. Marketing teams have started to track it, sometimes under the label generative engine optimization. For an architect the overlap is the data: the same accurate, structured, consistently published product information serves both the summary and the transaction.
Trust, fraud and liability
Agent commerce scrambles assumptions fraud teams rely on. Bot detection was built to block automated buyers; now some automated buyers are legitimate customers. Network schemes for recognizing trusted agents, and signatures that let an agent prove which platform it runs on, exist to separate good agents from scrapers and fraud bots, and merchants need to decide which agents they accept. Risk models trained on human behavior will misfire on agent behavior until they see enough of it.
Liability is the least settled part. When an agent buys the wrong thing, who absorbs the loss: the user who delegated, the platform whose agent misread the request, the merchant, or the issuer? Mandates and their evidence trail are the industry's answer in progress, because a signed record of what the user authorized is what a dispute will be decided on. Until rules mature, design for reversibility: low-value, returnable purchases first, clear confirmation for anything above a threshold, and evidence retained for every transaction.
The buyer side
The same rails serve enterprise buyers. Procurement agents that reorder supplies within a contract, book travel inside policy or buy software seats against a budget are a natural next step, and they need the controls the agent control plane deep-dive describes: an identity for the agent, a mandate that encodes policy, spending limits enforced outside the model, approval above thresholds and an audit trail finance can reconcile. Virtual cards and scoped tokens make this practical today for bounded categories; open-ended autonomous procurement remains, for now, the speculative end of the spectrum.
The architect view
Agentic commerce is the first place where agent interoperability standards are carrying real money at scale, and it has moved faster than most of the agent stack because it rides on payment infrastructure that already knows how to tokenize, authorize and dispute. For sellers it is a channel decision; for buyers it is a delegation decision; for both, the protocols matter less than the data and controls underneath.
Four commitments apply. Sellers should make catalogs, pricing, inventory, policies and checkout available as clean APIs, then add protocol adapters as the channel grows. Everyone should bound agent spending with explicit mandates and scoped credentials, never with instructions in a prompt. Fraud and risk teams should build an agent policy: which agents are accepted, how they are recognized and how their orders are scored. And legal and finance should track the liability rules as they settle, keeping the evidence that disputes will turn on.
On the radar this is trial for consumer-facing merchants, where the traffic is already arriving, and assess for most others. The cost of being ready is mostly the cost of good commerce data, which pays for itself whether agents become the main channel or merely a significant one.