By NHI Mgmt Group Editorial TeamBased on OneSpan: “Securing identity in the age of agentic commerce” (November 21, 2025)

TL;DR: Agentic commerce shifts shopping, negotiation, and payment into AI-driven flows, making verifiable digital identity and privacy-preserving consent the control plane for trust, according to OneSpan and cited industry research. The governance challenge is no longer just human authentication friction; it is proving whether an agent is acting within guardrails across identity, policy, and transaction execution.


At a glance

What this is: This is an analysis of agentic commerce that says digital identity, not passwords, becomes the core trust control when AI agents shop and transact on behalf of users.

Why it matters: IAM teams need to plan for delegated, machine-executed commerce flows where authentication, consent, and merchant trust must work across humans, agents, and payments.

By the numbers:

  • Global ecommerce fraud losses were approximately USD 44 bln in 2024, with forecasts exceeding USD 100 bln by 2029.
  • TransUnion found that companies lost nearly 8% of their revenues to fraud in the past year.

Context

Agentic commerce is the next commerce model after storefront and ecommerce: AI agents compare options, negotiate, and execute transactions on behalf of users. That changes the identity problem from who logged in to which identity, policy, and consent signals can survive machine-led decision-making.

The security gap is not just fraud at checkout. It is the absence of a portable trust layer that can distinguish a human, a trusted agent, and a bot without breaking the user experience or exposing reusable credentials.

For IAM and payments teams, that makes digital identity the control plane for commerce trust. The article’s core claim is that scale, reach, and delegated action now depend on verifiable credentials, merchant-readable claims, and explicit guardrails.


Key questions

Q: How should organisations secure payments when AI agents can buy on behalf of users?

A: They should separate user authentication, agent delegation, and purchase approval into distinct controls. That means phishing-resistant authentication for the human, explicit policy for the agent’s scope, and verifiable claims that the merchant can validate at transaction time. Without that separation, a delegated agent becomes just another opaque buyer with too much power.

Q: Why do passwords and CAPTCHAs break down in agentic commerce?

A: Passwords and CAPTCHAs assume the human is present at every trust decision. In agentic commerce, that assumption fails because the agent may complete discovery, comparison, negotiation, and payment before a person can intervene. Reusable credentials also create a large blast radius if shared across tools or agents.

Q: What are the signs that an agentic commerce trust model is too weak?

A: Warning signs include agents using human credentials, merchants lacking machine-readable policy terms, repeated step-up prompts at checkout, and unclear responsibility when an agent makes an unintended purchase. Those signals show the identity layer is not carrying consent and authority cleanly enough for delegated execution.

Q: What should security teams compare when designing identity for AI-led commerce?

A: They should compare human login controls, delegated credentials, and merchant-side verification of agent authority. The right model is not a product choice, but a governance choice about where trust is established, how it is expressed to machines, and when human approval is still required.


Technical breakdown

Why delegated commerce needs verifiable identity

Agentic commerce moves execution from a human user interface to an agent that can compare, negotiate, and pay. That breaks the old assumption that authentication proves the person behind every action. In this model, identity has to travel with the user, the business, and the agent, so relying parties can verify not only who initiated the session but which delegated authority is being exercised. The technical shift is from static account login to portable, cryptographically backed claims that can be read by merchant systems and policy engines.

Practical implication: Model identity as a delegated transaction credential, not a login event.

Why passwords and CAPTCHAs do not scale to agentic commerce

Passwords and CAPTCHAs are poor fits for environments where agents may act on behalf of people at machine speed. Sharing usernames and passwords with agents simply spreads trust, while CAPTCHAs only force awkward proof-of-human workarounds that degrade the customer experience. The article points instead to the FIDO model and modern digital credentials, where authentication can be phishing-resistant and still support attributes that help a merchant or relying party evaluate trust. That is an architectural change, not a UX tweak.

Practical implication: Retire shared credentials as a delegation method and move trust into cryptographic credentials with attributes.

How merchant trust signals become machine-readable

In agentic commerce, merchants cannot rely on visual storefront cues or human judgment alone. Agents need catalogues, policy terms, and claims they can parse programmatically, which means trust moves into machine-readable metadata and verifiable assertions. That creates a new dependence on interoperability: if credentials, personhood attributes, and delegation APIs cannot be consumed across ecosystems, the commerce flow fragments. The identity layer becomes a policy exchange layer, where the merchant, the agent provider, and the credential issuer all have to speak the same trust language.

Practical implication: Publish machine-readable claims and delegation terms that agents can evaluate before transaction execution.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic commerce turns digital identity into the commerce control plane. The article is not really about authentication UX, it is about where trust decisions move when agents transact on behalf of people. Once the agent, not the shopper, is doing comparison, negotiation, and execution, identity has to carry consent, policy, and merchant trust in a form machines can verify. Practitioners should treat identity as the transaction fabric, not just the sign-in gateway.

Shared human credentials are the wrong abstraction for delegated machine action. Password sharing, email-based magic links, and CAPTCHA-based bot separation all assume the user is the actor making each decision. That assumption fails when an agent can complete the work faster than a human can review it. The implication is not simply stronger authentication, but a redesign of delegation so reusable human credentials never become the trust anchor for autonomous purchase flows.

Agentic commerce introduces a new identity blast radius around consent. In human ecommerce, the main governance question was whether the account holder really initiated the transaction. In agentic commerce, the harder question is whether the agent stayed within the guardrails the user intended when it selected products, negotiated terms, and completed payment. That makes verifiable delegation, not login success, the meaningful trust boundary.

Personhood attributes will become a core trust primitive for commerce ecosystems. The article points to a future where merchants must distinguish humans, trusted agents, and bots without degrading conversion. That is a governance problem as much as a technical one, because the ecosystem now needs interoperability between identity issuers, authentication platforms, and merchant policy engines. Practitioners should expect digital identity proofing, delegation, and privacy-preserving claim exchange to converge.

Agentic commerce will expose the limits of customer experience metrics that ignore identity assurance. Faster checkout is useful only if the trust model still holds under delegated execution. As commerce shifts into assistants, the real measure is whether identity, consent, and policy can survive machine-scale automation without forcing users back into password resets, shared secrets, or manual intervention. Teams should measure trust quality at the transaction layer, not just sign-in conversion.

From our research library:

What this signals

Digital identity becomes the trust layer for machine-led commerce. Once agents can select products, negotiate terms, and execute payment, the useful question is no longer whether the user authenticated but whether the delegation path remains bound to consent and policy. Teams should prepare for identity assurance to move into transaction metadata, merchant claims, and agent authority records.

Agentic commerce exposes a governance gap that password-centric programmes were never built to cover. Systems designed around reusable human credentials cannot reliably distinguish a trusted agent from a borrowed account or an automated bot. That is why delegated authority, attribute-bearing credentials, and merchant-readable terms matter more than another layer of login friction.

According to the 2026 Infrastructure Identity Survey, 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege. That is a warning sign for commerce teams that are already letting machine actors accumulate authority faster than governance can review it.


For practitioners

  • Define delegated commerce policies Specify which purchases, thresholds, counterparties, and payment actions an agent may execute without human intervention, and route exceptions to explicit approval.
  • Adopt phishing-resistant authentication for humans Use passkeys and other phishing-resistant methods for remaining human logins so account takeover and credential reuse do not become the fallback path into commerce flows.
  • Publish machine-readable trust terms Expose catalogues, policies, and verification claims in formats that agents can parse before selection and checkout, so trust checks happen before transaction execution.
  • Support delegation-specific credentials Separate person credentials from agent credentials and use attribute-bearing credentials that prove authority, scope, and origin without requiring shared passwords.

Key takeaways

  • Agentic commerce changes identity from a login problem into a delegation and consent problem because agents can now act on behalf of users across discovery, negotiation, and payment.
  • The article highlights a scale problem, with ecommerce fraud losses at approximately USD 44 bln in 2024 and forecasts above USD 100 bln by 2029.
  • Practitioners should move toward verifiable digital credentials, machine-readable policy terms, and phishing-resistant human authentication before agent-led transactions become normal.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI01 — Agent Goal HijackAgent-led commerce depends on keeping delegated goals inside user-defined guardrails.
ASI03 — Identity & Privilege AbuseThe article centres on authority, delegation, and misuse of human credentials by agents.
Recommendation — Define and enforce bounded transaction goals so commerce agents cannot drift beyond intended scope. Separate human and agent authority so delegated privilege cannot be reused as shared access.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article argues that passwords and shared credentials do not work well for agent-led transactions.
NHI-10 — Human Use of NHIThe article warns against humans sharing passwords with agents as a delegation shortcut.
Recommendation — Replace reusable human credentials with cryptographic authentication designed for delegated agent use. Prevent credential sharing patterns that let agents operate through borrowed human identities.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article requires governance over agent authority, consent, and accountability in commerce flows.
Recommendation — Establish governance for agent delegation, approval boundaries, and accountability before transactions execute.

Key terms

  • Agentic Commerce: Agentic commerce is a buying and transaction model where software agents act on behalf of a person. The identity challenge is not just proving who owns the account, but constraining what the agent may do, for how long, and under what revocation and audit rules.
  • Delegated Identity: Delegated identity is when one actor acts on behalf of another with explicit permission and bounded authority. In AI-assisted commerce, it requires clear consent, limited scope, and traceable records so the retailer can distinguish authorised delegation from unauthorised automation.
  • Personhood Attribute: A verifiable claim that helps distinguish a human user from a bot or autonomous system. In commerce, personhood attributes support privacy-preserving trust decisions without exposing passwords, and they help systems decide when a human must be present versus when an agent may continue.
  • Machine-Readable Trust: Machine-readable trust is trust expressed as structured, verifiable signals that systems and people can evaluate automatically. It replaces static documents with live evidence, but only works when the underlying assertions are current, attributable, and validated.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org