Join our Newsletter — 33% off our NHI Course
Home› Guides› Agentic Commerce Identity Guide: AI Agents That Buy
Guide Agentic AI Security

Agentic Commerce Identity Guide: AI Agents That Buy

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 5 min read
On this page

AI agents are starting to buy things on people's behalf: booking travel, reordering supplies, purchasing tickets the moment they go on sale. That raises identity questions the payments industry has never had to answer at scale. How does a merchant know an agent is legitimate? How does anyone prove the customer actually authorised this purchase, with these limits? Who is liable when an agent buys the wrong thing, or is tricked into it? Since 2025, card networks, payment providers, AI companies and standards bodies have launched protocols to answer these questions. This guide explains the identity model behind agentic commerce, the main initiatives, and what merchants, payment teams and security teams should do now. The area is changing quickly; check the linked sources for the current position.

Key takeaways

  • Agentic commerce needs three things proven: the agent's identity, the user's authorisation (intent and limits) and the payment credential's binding to that agent and mandate.
  • Emerging approaches use signed agent requests, verifiable mandates and agent-specific tokenised payment credentials rather than sharing card details or passwords with agents.
  • In April 2026 the FIDO Alliance launched agentic authentication and payments working groups, with Google contributing the Agent Payments Protocol (AP2) and Mastercard contributing Verifiable Intent.
  • Merchants should prepare to recognise legitimate agents, apply step-up for high-risk purchases, and avoid treating all automated traffic as hostile or all of it as trusted.

The identity problem in agentic commerce

  • Who is the agent? A merchant sees automated traffic and must tell a legitimate shopping agent from a bot or fraudster.
  • Who authorised it, and for what? "Buy concert tickets under £100 for Friday" is different from "buy anything". The authorisation needs limits and must be verifiable.
  • Is the human present? Some purchases happen while the user watches; others happen later, autonomously, based on earlier instructions.
  • Which credential pays? Sharing a real card number or account password with an agent is dangerous; the credential should be specific to the agent, merchant and mandate.
  • Who is liable? Dispute and chargeback rules were written for human purchases.

Main initiatives

InitiativeOriginFocus
Agent Payments Protocol (AP2)Announced by Google in September 2025; contributed to the FIDO Alliance in April 2026 with a v0.2 releaseVerifiable mandates recording what a user authorised an agent to buy, including "human not present" purchases
Verifiable IntentCo-developed by Google and Mastercard; contributed to the FIDO AllianceA tamper-evident record of user-authorised agent actions
FIDO Alliance working groupsAnnounced 28 April 2026Agentic Authentication and Payments technical working groups developing interoperable standards
Agentic Commerce Protocol (ACP)OpenAI and Stripe, September 2025Checkout between a buyer's agent and a merchant, using scoped payment tokens
Universal Commerce Protocol (UCP)Google and Shopify with partners, January 2026Commerce lifecycle for agents, from discovery to checkout
Card network programmesVisa (Trusted Agent Protocol, Intelligent Commerce) and Mastercard (Agent Pay)Agent identification at the merchant and tokenised credentials bound to agents

Adoption and detail are changing month by month, and several of these are drafts or early programmes. See the Agent Identity Standards Tracker for status.

Principles for secure agentic payments

  • Never give agents raw credentials. Use tokenised, agent-specific credentials with merchant, amount and time limits.
  • Make authorisation explicit and verifiable. Capture the user's intent as a signed mandate with clear limits.
  • Step up for risk. Require real-time user approval, using phishing-resistant authentication, for purchases outside the mandate or above thresholds.
  • Identify the agent. Merchants and payment providers should be able to verify which agent is acting and who operates it.
  • Keep an audit trail linking mandate, agent, transaction and approval, for disputes and fraud investigation.

Threats to watch

  • Prompt injection on product pages steering agents to other sellers or higher prices. See the Browser and Computer-Use Agent Guide.
  • Malicious agents impersonating legitimate ones to exploit merchant trust.
  • Mandate abuse: agents exceeding the user's intent, or attackers modifying mandates.
  • Account takeover of the user's agent account, giving attackers purchasing power.
  • Refund and promotion abuse at machine scale.

What to do now

Merchants

  • Review how your bot management treats AI agent traffic; plan to identify legitimate agents rather than blocking all automation.
  • Track which agent protocols your payment providers support.
  • Keep step-up authentication for high-risk transactions and account changes. See the CIAM Guide.

Payment and fraud teams

  • Update fraud models for agent-initiated transactions.
  • Review dispute processes for agent purchases.

Enterprises deploying purchasing agents

  • Give procurement agents their own identities and scoped payment instruments with limits.
  • Require approval above thresholds and for new suppliers. See the AI Agent Authorisation Guide.
  • Apply segregation of duties: the agent that prepares a purchase should not also approve it. See the SoD Guide.

Standards and references

Related NHI Mgmt Group resources: Agent Identity Standards Tracker · Agentic AI Identity Guide · CIAM Guide · Browser and Computer-Use Agent Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org