By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: Prove IdentityPublished July 14, 2026

TL;DR: The growing governance gap around agentic commerce and trust infrastructure is underscored by questions over who is responsible when an AI agent completes a transaction on a consumer’s behalf, according to Prove Identity. The deeper issue is accountability: existing identity controls were built to verify people, not autonomous transaction execution.


At a glance

What this is: Prove Identity’s Executive Advisory Board is aimed at clarifying accountability when an AI agent completes a transaction for a consumer.

Why it matters: This matters because agentic commerce creates identity, authorisation, and liability questions that cut across consumer IAM, fraud controls, and emerging AI governance programmes.

👉 Read Prove Identity's article on accountability in agentic commerce


Context

Agentic commerce creates a trust problem that traditional consumer identity programmes were not designed to answer. When software can complete a transaction on behalf of a person, identity verification alone does not resolve who authorised the action, who is accountable for the outcome, or how the event should be governed across fraud, IAM, and policy controls.

The article frames Prove Identity's board as a response to that gap, with the central question being responsibility when an AI agent acts for a consumer. For practitioners, the immediate issue is not whether the transaction can be authenticated, but whether the governance model can distinguish human intent, delegated execution, and downstream liability.


Key questions

Q: How should organisations govern transactions completed by consumer AI agents?

A: They should treat each agent action as delegated authority with explicit scope, expiry, and audit requirements. The consumer's identity proofing may establish who owns the account, but it does not define what the agent may do. Governance needs transaction-level policy, evidence of intent, and a clear accountability path for disputes and exceptions.

Q: Why do traditional IAM controls fall short in agentic commerce?

A: Traditional IAM controls assume the authenticated user is the actor making the decision. In agentic commerce, that assumption breaks because a software agent can select actions and execute them after the person has stepped away. The result is a governance gap between user authentication and delegated execution.

Q: What do teams get wrong about identity proofing for AI-assisted purchases?

A: They often assume stronger identity proofing automatically solves transaction trust. It does not. Proofing confirms a person or account, but agentic commerce also needs controls over mandate scope, permissible actions, and evidence that the agent stayed within the user's instruction.

Q: Who is accountable when an AI agent acts outside its intended scope?

A: The organisation is accountable, but operational responsibility should sit with a named owner and a governance process that can explain the agent’s purpose, access, and recorded actions. Without that, autonomous behaviour becomes unassignable risk rather than managed automation.


Technical breakdown

Why agentic commerce breaks consumer identity assumptions

Consumer identity systems assume the person who authenticates is the person who initiates and completes the transaction. Agentic commerce splits those roles. A human may authorise a purchase intent once, then an AI agent selects the merchant, timing, and execution path without the human present. That changes the security model from authenticating a user session to governing delegated execution, consent scope, and auditability of the action chain. Identity proofing alone does not explain whether the agent stayed inside its mandate or whether the consumer would recognise the transaction as legitimate.

Practical implication: Practitioners need policy and evidence models that capture delegated intent, not just login success.

Trust infrastructure for agentic commerce needs transaction-level accountability

Trust infrastructure in this context is not only about verifying an identity at the front door. It has to preserve evidence across the transaction lifecycle, including intent capture, permission boundaries, and attributable action logs. Without that, disputes become hard to resolve because the system can prove a session occurred, but not necessarily that the consumer authorised the agent's specific choice. This is especially important when transactions cross multiple services or payment steps, where delegated authority can drift from the original consumer instruction.

Practical implication: Security and fraud teams should require transaction traces that show who authorised what, when, and under which delegated scope.

Human digital behaviour signals still matter, but they are not enough on their own

The article points to Prove Identity's decade of human digital behaviour signals as a differentiator for trust decisions. Those signals can help detect whether the interaction pattern looks consistent with a real consumer, but they do not remove the need to govern agent activity directly. In agentic commerce, behavioural confidence around the person and control confidence around the agent are separate problems. Treating them as one leaves a policy blind spot where a well-matched human identity can still mask over-broad delegated action.

Practical implication: Use human behaviour signals as one input, but separate them from the control framework governing agent permissions.


NHI Mgmt Group analysis

Agentic commerce creates a delegated-identity problem, not just a verification problem. The article is really about what happens when a consumer's intent is executed by a software actor that can choose timing and action path. That shifts governance from authenticating a person to constraining delegated execution, and those are not the same control plane. Practitioners should treat this as a consumer identity and fraud governance issue with AI-specific consequences, not as a simple extension of login assurance.

Identity proofing does not answer accountability when an AI agent completes a transaction. A system can establish that the consumer exists and that a session is legitimate, yet still fail to prove that the downstream purchase, transfer, or instruction was specifically authorised. That gap is where dispute handling, liability assignment, and fraud investigation become difficult. The practical conclusion is that transaction accountability must be designed into the identity fabric, not bolted on after the fact.

Human behavioural intelligence and agent governance solve different parts of the trust problem. A decade of consumer digital signals may help identify the human behind the mandate, but it does not govern what the agent can do after the mandate is issued. That distinction matters because the governance failure is not only impersonation, but mandate expansion. Teams should separate human assurance from agent permissioning in their operating model.

Agentic commerce will force consumer identity, fraud, and AI governance teams into one operating conversation. Traditional ownership boundaries break down when an AI agent can initiate and complete commercial activity on behalf of a person. The issue spans customer identity, payment risk, authorisation policy, and audit evidence. Practitioners should expect the governance model to move from isolated controls to shared accountability across security, product, and risk functions.

From our research:

  • 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate, according to AI Agents: The New Attack Surface report.
  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
  • That governance gap is why practitioners should also review OWASP Agentic AI Top 10 alongside their consumer identity and fraud controls.

What this signals

Mandate drift is the core risk in agentic commerce. The consumer may intend the transaction, but the software agent can still expand, reorder, or repeat actions outside that intent. That is a governance problem for IAM, fraud, and product teams together, not a narrow authentication issue.

With 80% of organisations reporting AI agents have already acted beyond intended scope, per the AI Agents: The New Attack Surface report, the same behavioural drift that concerns enterprise security also applies to consumer transactions. The programme response needs explicit delegated scope, not just stronger identity checks.

Agentic trust needs a new evidence model: practitioners should be able to show what the consumer authorised, what the agent decided, and what downstream system accepted. Without that three-part record, investigations will default to assumption rather than proof.


For practitioners

  • Define delegated transaction scope Require explicit policy for what an AI agent may buy, transfer, or submit on a consumer's behalf, including amount limits, merchant constraints, and expiry conditions. This should be auditable as a mandate, not inferred from a login session.
  • Separate human proofing from agent authorisation Keep identity verification for the consumer distinct from runtime authorisation for the agent. A strong consumer signal does not justify broad agent access, so encode separate decision points for person assurance and delegated action approval.
  • Capture transaction evidence end to end Log the originating instruction, the agent's decision path, the action taken, and the confirmation returned by downstream systems. This gives fraud, disputes, and compliance teams a defensible record of delegated intent and execution.
  • Map liability before agentic commerce scales Work with legal, fraud, and product stakeholders to define who is accountable when a consumer's AI agent acts outside expected scope. Without that mapping, control failures will turn into dispute and liability ambiguity.

Key takeaways

  • Agentic commerce exposes a delegated identity gap because consumer authentication does not automatically govern software execution.
  • The key risk is accountability drift, where a verified consumer can still be separated from the transaction choices an AI agent makes.
  • Practitioners should build explicit mandate scope, evidence capture, and liability mapping before agentic purchasing scales.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack surface, NIST AI RMF and NIST CSF 2.0 set the technical controls, and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10Agentic commerce introduces delegated action and tool-use risks for AI systems.
NIST AI RMFGOVERNThe article centers on governance and accountability for AI-assisted action.
NIST CSF 2.0PR.AC-4Delegated transaction authority depends on access and authorisation control.
GDPRArt.5Consumer identity and transaction telemetry can implicate personal data processing.

Review access boundaries for AI-driven transactions and enforce least privilege at the policy layer.


Key terms

  • Agentic Commerce: Agentic commerce is a buying and transaction model where software agents act on behalf of a person. The identity challenge is not just proving who owns the account, but constraining what the agent may do, for how long, and under what revocation and audit rules.
  • Delegated Identity: Delegated identity is when one actor acts on behalf of another with explicit permission and bounded authority. In AI-assisted commerce, it requires clear consent, limited scope, and traceable records so the retailer can distinguish authorised delegation from unauthorised automation.
  • Transaction Accountability: The ability to show who authorised a transaction, what was permitted, and what action was actually executed. For AI-mediated commerce, accountability must connect intent, execution, and downstream acceptance so disputes can be resolved without guesswork.

What's in the full article

Prove Identity's full article covers the operational detail this post intentionally leaves for the source:

  • The board's stated remit for deciding who is responsible when an AI agent completes a transaction.
  • Prove Identity's positioning on human digital behaviour signals and how they relate to trust decisions.
  • The article's broader framing of trust infrastructure for agentic commerce and executive governance.
  • Context around the Executive Advisory Board and the company's stated direction for the topic.

👉 Prove Identity's full post covers the Executive Advisory Board and its trust infrastructure focus.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org