TL;DR: Agentic commerce shifts shopping, negotiation, and payment into AI-driven flows, making verifiable digital identity and privacy-preserving consent the control plane for trust, according to OneSpan and cited industry research. The governance challenge is no longer just human authentication friction; it is proving whether an agent is acting within guardrails across identity, policy, and transaction execution.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “Securing identity in the age of agentic commerce”.
By the numbers:
- Global ecommerce fraud losses were approximately USD 44 bln in 2024, with forecasts exceeding USD 100 bln by 2029.
- TransUnion found that companies lost nearly 8% of their revenues to fraud in the past year.
Key questions
Q: How should organisations secure payments when AI agents can buy on behalf of users?
A: They should separate user authentication, agent delegation, and purchase approval into distinct controls.
Q: Why do passwords and CAPTCHAs break down in agentic commerce?
A: Passwords and CAPTCHAs assume the human is present at every trust decision.
Q: What are the signs that an agentic commerce trust model is too weak?
A: Warning signs include agents using human credentials, merchants lacking machine-readable policy terms, repeated step-up prompts at checkout, and unclear responsibility when an agent makes an unintended purchase.
Practitioner guidance
- Define delegated commerce policies Specify which purchases, thresholds, counterparties, and payment actions an agent may execute without human intervention, and route exceptions to explicit approval.
- Adopt phishing-resistant authentication for humans Use passkeys and other phishing-resistant methods for remaining human logins so account takeover and credential reuse do not become the fallback path into commerce flows.
- Publish machine-readable trust terms Expose catalogues, policies, and verification claims in formats that agents can parse before selection and checkout, so trust checks happen before transaction execution.
Bottom line: Agentic commerce changes identity from a login problem into a delegation and consent problem because agents can now act on behalf of users across discovery, negotiation, and payment.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic commerce turns digital identity into the commerce control plane. The article is not really about authentication UX, it is about where trust decisions move when agents transact on behalf of people. Once the agent, not the shopper, is doing comparison, negotiation, and execution, identity has to carry consent, policy, and merchant trust in a form machines can verify. Practitioners should treat identity as the transaction fabric, not just the sign-in gateway.
A few things that frame the scale:
- 54% of organisations are actively deploying AI agents across workflows, yet only 21% report a mature governance model for agentic AI.
A question worth separating out:
Q: What should security teams compare when designing identity for AI-led commerce?
A: They should compare human login controls, delegated credentials, and merchant-side verification of agent authority. The right model is not a product choice, but a governance choice about where trust is established, how it is expressed to machines, and when human approval is still required.
👉 Read our full editorial: Agentic commerce makes digital identity the control plane for trust