TL;DR: AI agents are already completing real purchases with delegated payment credentials, and that shifts fraud detection from noisy human behaviour to clean, legitimate-looking transactions, according to WorkOS. The security model now depends on agent identity, scoped delegation, and transaction-level consent, because review cycles built for human intent cannot reliably catch hijacked agent actions.
At a glance
What this is: This analysis says agentic commerce is already live enough that AI agents can complete real purchases, but the security model breaks when delegated credentials and transaction intent are no longer aligned.
Why it matters: It matters because IAM, PAM, and fraud teams need controls for agent identity, scoped delegation, and step-up consent before agent-driven transactions become routine.
Context
Agentic commerce is the use of AI agents to search, select, and complete purchases on behalf of a user. The governance gap is that the transaction may be technically authorised while the intent behind it is no longer visible to legacy fraud and access controls.
In this model, the merchant, payment network, and identity stack all need to understand who the agent is, what the user delegated, and when that delegation expires. Without that separation, a compromised agent can act inside ordinary behaviour bounds and evade the signals traditional e-commerce defences were built to detect.
That makes this an identity problem as much as a payments problem. The central question is no longer whether a purchase was authenticated, but whether the specific agent, scope, and consent state were valid at the moment of action.
Key questions
Q: What breaks when AI agents can buy on behalf of users without scoped delegation?
A: A broad shopping permission turns into open-ended purchasing authority. Without category limits, merchant allow lists, amount ceilings, and expiry, the agent can legally do far more than the user intended, and fraud controls lose the ability to distinguish authorised convenience from delegated overreach.
Q: Why do delegated payment credentials increase fraud risk in agentic commerce?
A: Because the transaction can look legitimate even when the intent is compromised. Saved addresses, trusted payment tokens, and familiar merchants remove the noisy signals fraud teams rely on, so a hijacked agent can complete purchases that appear normal while still being unauthorised in practice.
Q: What are the signs that agentic commerce controls are too loose?
A: The main warning signs are uncapped spending, no merchant allow list, no expiry on delegation, and confirmation prompts that do not show the exact item, merchant, and amount. If the user could not explain why the agent was allowed to make a purchase, the control model is too broad.
Q: How should security teams handle accountability for unauthorised agent purchases?
A: They should preserve a full audit chain from user delegation to agent action to merchant acceptance. That evidence does not solve liability by itself, but it makes disputes, chargebacks, and governance decisions traceable instead of speculative when the legal framework catches up.
Technical breakdown
Why delegated payment credentials change the threat model
Traditional checkout fraud is built around suspicious human behaviour: mismatched devices, unfamiliar addresses, abnormal purchase timing, or stolen card use. Agentic commerce changes that because the agent already carries trusted payment tokens, saved addresses, and purchase history. That means the fraud signal shifts from obvious anomaly to legitimate-looking execution by an identity that already fits the merchant's normal patterns. The merchant is no longer validating a person at checkout so much as deciding whether a delegated non-human actor is still within the authorised boundary.
Practical implication: Treat delegated payment credentials as a distinct identity surface, not as a simple extension of consumer checkout risk.
How scoped delegation limits agent authority
Agentic commerce needs more than a single spending cap. Delegation has to be scoped by category, merchant allow list, per-transaction limit, session limit, daily limit, and expiry. That is effectively an authorisation policy for a non-human identity, not a one-off user preference. The article's point is that 'shop for me' and 'spend anywhere you like' are materially different trust grants, and security fails when the platform collapses them into one broad permission. This is classic entitlement design, but applied to an AI executor that can act continuously once granted access.
Practical implication: Define delegation as a bounded entitlement with category, merchant, amount, and time constraints rather than a broad shopping token.
Where transaction-level consent interrupts prompt injection
Prompt injection becomes more dangerous in commerce because an agent can be manipulated into adding items, changing merchants, or shifting scope while still operating with valid credentials. Step-up consent creates a control boundary by forcing the user to confirm the exact transaction before money moves or a binding commitment is made. In effect, the agent may be compromised at the planning layer, but the user still has a chance to catch the altered outcome at the final approval point. That boundary only works if the confirmation message is specific, not generic.
Practical implication: Require explicit per-transaction confirmation for money movement, new merchants, subscriptions, and any change that expands the original scope.
Threat narrative
Attacker objective: The attacker wants to use a trusted agent identity to complete purchases or drain value while bypassing normal fraud detection.
- Entry occurs when an attacker compromises delegated agent credentials, spoofs a legitimate agent, or injects malicious instructions into an agent shopping flow.
- Escalation happens when the agent continues to operate with trusted payment tokens, saved addresses, and shopping history that make its actions look normal to fraud systems.
- Impact is realised when the agent completes purchases, drains balances, or executes fraudulent transactions that appear authorised on the surface.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Agentic commerce creates an identity problem, not just a fraud problem: the merchant can no longer rely on device fingerprints or shipping anomalies when the actor already holds trusted payment credentials. That is a structural shift, because the transaction now looks ordinary even when the intent has been hijacked. The implication for the field is that authorisation must move from human checkout heuristics to delegated identity and consent state.
Delegation scope is the control surface that matters most: a spending cap alone is too blunt for agentic commerce. The article shows why category, merchant, session, and time boundaries are all part of the permission model, which means commerce delegation is closer to entitlement governance than simple payment token handling. Practitioners should recognise that vague delegation creates policy drift the moment an agent starts selecting alternatives.
Transaction-level consent is the missing guardrail for prompt injection: hidden instructions on a product page can alter an agent's behaviour without changing the token it uses. Step-up confirmation works only when the user sees the exact merchant, item, amount, and payment method before the transaction closes. That makes consent a runtime control boundary, not a formality at account setup.
Auditability will determine whether agentic commerce can be governed at scale: if a disputed purchase cannot be traced from user delegation to agent action to merchant confirmation, accountability collapses after the fact. The industry needs a forensic chain that preserves who delegated what, which agent acted, what was shown to the user, and what the merchant verified. Practitioners should treat evidence retention as part of the control plane.
Identity and payments are converging around a new named concept: delegated transaction authority: this is the point where a user's intent, a non-human actor's credentials, and a merchant's acceptance rules must all align for the transaction to be legitimate. Once that authority becomes transferable, expirable, and scope-bound, commerce controls start to resemble NHI governance more than traditional consumer fraud management. Practitioners should design for that convergence now.
From our research library:
- Gartner predicts that by the end of 2026, 40% of enterprise apps will feature task-specific AI agents.
- Read next: AI Agent Authorisation Guide
What this signals
Delegated transaction authority: agentic commerce only becomes governable when the user, the non-human actor, and the merchant all agree on the same scope and duration of authority. That is a stronger model than generic checkout authentication because the control has to bind intent, identity, and transaction context together.
Access review thinking is too slow for agentic commerce if the agent can act, buy, and move on before a human review cycle catches up. The governance boundary has to move to issuance time and transaction time, not after the fact.
According to the 2026 Infrastructure Identity Survey, 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege. That is the same governance failure agentic commerce exposes when delegated authority is broader than the user would ever grant a person.
For practitioners
- Define agent-specific identities Authenticate each AI agent as its own actor and require proof of user delegation alongside every transaction request. Do not let the agent pass through a user's session as if it were the same identity.
- Scope delegated commerce permissions Limit commerce delegation by product category, merchant allow list, per-transaction amount, session amount, daily amount, and expiry so the agent cannot generalise a single shopping instruction into open-ended authority.
- Require step-up consent for high-risk actions Force explicit user confirmation before purchases, subscriptions, refunds, new merchants, or any transaction that expands the original scope, and show the exact items and payment method being used.
- Preserve end-to-end transaction evidence Log delegation issuance, agent identity, each merchant interaction, the confirmation prompt, and the merchant's validation result so disputes can be reconstructed after the fact.
Key takeaways
- Agentic commerce fails when delegated authority outgrows the user's actual intent, because the transaction may still look legitimate to ordinary fraud controls.
- The core risk is not only theft of credentials but the reuse of trusted payment context that makes malicious purchases appear normal.
- Scoped delegation, step-up consent, and auditable transaction chains are the controls that turn agent purchasing from an uncontrolled trust extension into something governable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Agentic commerce hinges on whether the agent is authenticated as itself. |
| NHI-05 — Overprivileged NHI | Broad shopping permissions create the overreach this article warns about. | |
| NHI-10 — Human Use of NHI | The user is exercising a non-human actor to complete purchases on their behalf. | |
| Recommendation — Authenticate each agent as its own actor and bind every transaction to that identity. Constrain delegated commerce scope so agents cannot buy outside approved bounds. Separate human intent from agent execution and require explicit approval at spend boundaries. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The central risk is a trusted agent being abused through delegated credentials. |
| Recommendation — Map commerce flows to agent identity and privilege abuse controls to detect scope misuse. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Agentic commerce is an authorisation problem for delegated non-human access. |
| Recommendation — Apply entitlement checks to every agent transaction and verify the current delegation scope. | ||
Key terms
- Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.
- Delegated Authority Model: A delegated authority model defines who is allowed to approve, review, or execute control-related decisions across the enterprise. It helps ensure requests reach the correct responsible party, especially when control owners, managers, and process owners sit in different teams, regions, or systems.
- Step-Up Consent: Step-up consent is a second approval required before a higher-risk action is allowed. For AI agents, it is used when the requested operation exceeds the original consent boundary, such as moving from read-only access to write, delete, or administrative actions.
- Transfer Audit Trail: A transfer audit trail is the evidence set that shows who approved a movement, who signed it, and what authority justified the action. It is essential when tokenized assets are part of regulated workflows because the ledger alone rarely proves whether the right person acted under the right control.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org