TL;DR: AI agents are already completing real purchases with delegated payment credentials, and that shifts fraud detection from noisy human behaviour to clean, legitimate-looking transactions, according to WorkOS. The security model now depends on agent identity, scoped delegation, and transaction-level consent, because review cycles built for human intent cannot reliably catch hijacked agent actions.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “How to secure agentic commerce transactions”.
Key questions
Q: What breaks when AI agents can buy on behalf of users without scoped delegation?
A: A broad shopping permission turns into open-ended purchasing authority.
Q: Why do delegated payment credentials increase fraud risk in agentic commerce?
A: Because the transaction can look legitimate even when the intent is compromised.
Q: What are the signs that agentic commerce controls are too loose?
A: The main warning signs are uncapped spending, no merchant allow list, no expiry on delegation, and confirmation prompts that do not show the exact item, merchant, and amount.
Practitioner guidance
- Define agent-specific identities Authenticate each AI agent as its own actor and require proof of user delegation alongside every transaction request.
- Scope delegated commerce permissions Limit commerce delegation by product category, merchant allow list, per-transaction amount, session amount, daily amount, and expiry so the agent cannot generalise a single shopping instruction into open-ended authority.
- Require step-up consent for high-risk actions Force explicit user confirmation before purchases, subscriptions, refunds, new merchants, or any transaction that expands the original scope, and show the exact items and payment method being used.
Bottom line: Agentic commerce fails when delegated authority outgrows the user's actual intent, because the transaction may still look legitimate to ordinary fraud controls.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic commerce creates an identity problem, not just a fraud problem: the merchant can no longer rely on device fingerprints or shipping anomalies when the actor already holds trusted payment credentials. That is a structural shift, because the transaction now looks ordinary even when the intent has been hijacked. The implication for the field is that authorisation must move from human checkout heuristics to delegated identity and consent state.
A few things that frame the scale:
- Gartner predicts that by the end of 2026, 40% of enterprise apps will feature task-specific AI agents.
A question worth separating out:
Q: How should security teams handle accountability for unauthorised agent purchases?
A: They should preserve a full audit chain from user delegation to agent action to merchant acceptance. That evidence does not solve liability by itself, but it makes disputes, chargebacks, and governance decisions traceable instead of speculative when the legal framework catches up.
👉 Read our full editorial: Agentic commerce security demands identity, delegation, and consent controls