TL;DR: The growing governance gap around agentic commerce and trust infrastructure is underscored by questions over who is responsible when an AI agent completes a transaction on a consumer’s behalf, according to Prove Identity. The deeper issue is accountability: existing identity controls were built to verify people, not autonomous transaction execution.
NHIMG editorial — based on content published by Prove Identity: Identity Sector Moves to Close Trust Gap in Agentic Commerce
Questions worth separating out
Q: How should organisations govern transactions completed by consumer AI agents?
A: They should treat each agent action as delegated authority with explicit scope, expiry, and audit requirements.
Q: Why do traditional IAM controls fall short in agentic commerce?
A: Traditional IAM controls assume the authenticated user is the actor making the decision.
Q: What do teams get wrong about identity proofing for AI-assisted purchases?
A: They often assume stronger identity proofing automatically solves transaction trust.
Practitioner guidance
- Define delegated transaction scope Require explicit policy for what an AI agent may buy, transfer, or submit on a consumer's behalf, including amount limits, merchant constraints, and expiry conditions.
- Separate human proofing from agent authorisation Keep identity verification for the consumer distinct from runtime authorisation for the agent.
- Capture transaction evidence end to end Log the originating instruction, the agent's decision path, the action taken, and the confirmation returned by downstream systems.
What's in the full article
Prove Identity's full article covers the operational detail this post intentionally leaves for the source:
- The board's stated remit for deciding who is responsible when an AI agent completes a transaction.
- Prove Identity's positioning on human digital behaviour signals and how they relate to trust decisions.
- The article's broader framing of trust infrastructure for agentic commerce and executive governance.
- Context around the Executive Advisory Board and the company's stated direction for the topic.
👉 Read Prove Identity's article on accountability in agentic commerce →
Agentic commerce identity: who is accountable when AI completes transactions?
Explore further
Agentic commerce creates a delegated-identity problem, not just a verification problem. The article is really about what happens when a consumer's intent is executed by a software actor that can choose timing and action path. That shifts governance from authenticating a person to constraining delegated execution, and those are not the same control plane. Practitioners should treat this as a consumer identity and fraud governance issue with AI-specific consequences, not as a simple extension of login assurance.
A few things that frame the scale:
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate, according to AI Agents: The New Attack Surface report.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: Who is accountable when an AI agent acts outside its intended scope?
A: The organisation is accountable, but operational responsibility should sit with a named owner and a governance process that can explain the agent’s purpose, access, and recorded actions. Without that, autonomous behaviour becomes unassignable risk rather than managed automation.
👉 Read our full editorial: Agentic commerce trust gaps are exposing identity accountability