Join our Newsletter — 33% off our NHI Course

What breaks when shopping is delegated to AI agents?

The main failure is that many fraud controls assume a human browser session will leave enough behavioural evidence to judge intent. When an agent acts on behalf of a shopper, those signals shrink or disappear, so merchants must shift to delegated-authorisation checks, token governance, and transaction-context scoring.

What changes when a shopper is no longer the one “clicking”?

Shopping is not just a purchase event, it is also an intent event. Once an AI agent can browse, compare, and commit on behalf of a person, the merchant must decide whether the request is merely automated or truly delegated. That changes how trust is established, how consent is verified, and which signals are allowed to stand in for human intent.

The biggest break is not in checkout mechanics but in attribution. A browser session used to carry enough context for fraud teams to infer device continuity, interaction rhythm, and user presence. With an agent, those cues are weaker, more uniform, or absent, so controls built around human behaviour lose precision.

That is why merchants should treat delegated shopping as an authorisation problem first, and a fraud-scoring problem second. The important question becomes whether the agent has a valid mandate for this purchase, under what scope, for how long, and with what transaction limits.

Which control assumptions stop working?

Several common assumptions become unreliable when an agent is the actor. Human-friendly signals such as mouse movement, typing cadence, and session fingerprints no longer prove the decision-maker’s presence. If the merchant still scores those signals as if they were evidence of a shopper’s direct action, the model can misclassify legitimate delegated activity as suspicious, or miss abuse that looks syntactically normal.

Token handling also becomes more sensitive. If the agent is acting through a delegated token, the token’s scope, lifetime, audience, and revocation path matter more than the user interface session that originally triggered it. That shifts the operational burden toward token governance, constrained delegation, and careful separation between user consent and agent permission.

Transaction context matters as well. The merchant needs more than “same account, same cart, same device” logic. Price sensitivity, merchant category, shipping change, payment instrument change, velocity, and repetition across items become more important because they help distinguish a valid agent instruction from abuse of a broad mandate.

For a deeper discussion of AI agent authorisation, the core shift is from identity as a login event to authority as a bounded decision. The same principle appears in zero trust for AI agents, where every action must be re-verified against policy rather than assumed from a past session.

Why does delegated commerce create a new fraud model?

Fraud teams are used to looking for signals of impersonation, takeover, or abnormal session behaviour. Delegated shopping introduces a different problem: the request may be authentic, but the actor is not human in the traditional sense. That creates ambiguity around intent, consent, and accountability, especially when the agent can be instructed once and then operate across multiple sessions.

This also changes the blast radius of a compromise. If an attacker steals an agent token or abuses a poorly scoped delegation, the damage may look like ordinary purchasing activity until the spend, merchant mix, or delivery pattern is reviewed in aggregate. In practice, abuse becomes easier when the mandate is broad and the merchant has no way to distinguish approved automation from illicit automation.

That is why observable delegation is so important. Merchants need enough context to answer three questions: who granted authority, what the agent may do, and whether the current action still fits the original mandate. Without that, fraud controls either over-block legitimate automation or under-detect opportunistic abuse.

NHIMG’s agentic commerce identity guide is useful here because it frames payment as a mandate problem, not only a checkout problem. The same is reinforced by agentic AI identity, where delegation, registration, and retirement determine whether the actor still deserves trust.

Risk and Threat Considerations

Delegated shopping weakens controls that depend on human behavioural evidence and opens the door to overbroad automation. The main risk is not just false positives, it is that a valid-looking agent action can carry too little evidence for a fraud team to judge whether the mandate was legitimate or already abused.

Failure mechanism: A merchant accepts delegated actions without sufficiently binding them to scope, purpose, and transaction context, so stolen, replayed, or over-permissioned agent tokens can produce purchases that resemble normal automation.

Impact: Legitimate delegated purchases may be blocked, while abusive agents can create spend, fulfilment, refund, and dispute losses before the merchant has a reliable way to distinguish authorised automation from fraud.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 define the specific risk controls and attack patterns relevant to this topic.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-04 — Insecure Authentication Delegated shopping depends on trustworthy agent authentication and token use.
NHI-05 — Overprivileged NHI Shopping agents need tightly scoped permissions to prevent abusive purchases.
NHI-07 — Long-Lived Secrets Long-lived delegated tokens increase the abuse window for shopping agents.
Recommendation — Use bounded, phishing-resistant agent authentication and reject broad, reusable credentials. Apply least privilege and revoke any agent access that exceeds the purchase mandate. Shorten token lifetime and rotate delegated credentials aggressively.
OWASP Agentic AI Top 10 ASI03 — Identity & Privilege Abuse Shopping agents can be abused when authority is broader than intended.
ASI09 — Human-Agent Trust Exploitation Fraud models can be fooled when human intent is inferred from agent activity.
Recommendation — Constrain agent authority per action and require approval for higher-risk purchases. Validate that delegated actions still match the user's intent and transaction context.

Practitioner Guidance

What to verify: Treat the mandate as the primary control object. Verify who authorised the agent, what it can buy, how much it can spend, whether substitutions are allowed, and how quickly the delegation can be revoked.

What good looks like: Each purchase decision should be explainable from delegated authority plus transaction context, not from a vague “this session looked normal” score. Good controls make scope, expiry, and revocation observable to fraud operations and customer support.

Decision rule: If the transaction cannot be tied to a bounded delegation with clear limits, downgrade trust and require step-up review or a narrower re-authorisation path. If it can be tied to a valid mandate, score it against context and abuse patterns, not human interaction heuristics.

Practitioner takeaway: The control shift is from proving a person was present to proving the agent was still authorised for this specific action. That is the boundary merchants should design, monitor, and revoke against.