The useful agent-commerce story today starts at checkout.
Visa says AI agents are now completing purchases with participating merchants in live European environments, not only controlled demos. The July 2 announcement describes agents browsing products, selecting items, and initiating purchases at merchant websites on behalf of cardholders, within consumer-defined parameters. Visa says the program involves more than 30 European issuers and merchants including lastminute.com, Frasers, Cleverbridge, and BrickDepot.
That is the public signal worth taking seriously.
The agent did not stay inside a chat window. It reached a merchant, carried a user instruction, touched payment authentication, and moved a purchase process forward.
Once that happens, the interesting question changes. A normal website can treat automated traffic as a bot problem. A payment network has to ask a harder question: which machine is this, who sent it, what is it allowed to do, what consumer instruction sits behind the action, and what record survives if the merchant, issuer, customer, regulator, or fraud team asks what happened?
Visa’s answer is infrastructure language. Its Trusted Agent Protocol and Agent Directory are designed to help merchants recognize verified AI agents across platforms and distinguish trusted commerce traffic from unverified traffic. Its Payment Passkeys are used to authenticate transactions and link each one to a verified user and explicit instruction. Visa says the protocol can provide time-bound, purpose-specific signatures designed to resist replay and relay, and can pass agent intent, consumer-recognition data, and payment information to merchants.
Mastercard is working the same problem from another angle. Its Verifiable Intent framework, co-developed with Google, is meant to create a tamper-resistant record of what a user authorized when an AI agent acts. Mastercard’s framing for that work: when a consumer delegates to an agent, the user’s intent becomes less visible at the moment of transaction. If something goes wrong, the system needs a record of what was actually authorized.
FIDO Alliance work on agentic authentication and payments points in the same direction. Its April 2026 announcement describes a working group forming to develop authentication and delegation standards for AI agents. The direction matters even if the standards are not finished.
Commerce used to have a visible ritual. You tapped the card. You clicked buy. You signed. Imperfect, but legible. Agent commerce breaks that ritual into pieces. The user may express intent earlier. The agent may browse later. The merchant may meet the machine before the person. The issuer still has to authenticate. The dispute system still needs a record. The fraud system still has to decide whether the action was authorized.
The interface becomes institution when the machine can buy.
For operators, the point is practical. The product is not only the agent that shops. It is the witness layer around the agent: identity, instruction, scope, authentication, replay protection, merchant recognition, receipt, dispute trail, and rollback path. Without that layer, agent commerce turns into a permission fog. With it, there is at least a record people can inspect.
And speaking of records, NIST’s agent work makes the same move outside payments. NIST describes its evaluation-probe project as automated verifiers inside agentic workflows, checking outputs against trusted source documents and accumulating machine-readable audit trails. A separate NIST NCCoE agent-identity concept paper asks how software and AI agents should be identified, authenticated, authorized, logged, and bound back to human authorization.
That is the shared pattern. The agent age is forcing institutions to turn invisible permission into visible proof.
Verification bottleneck
Verification is becoming the scarce institutional function.
- Agent commerce is moving faster than ordinary checkout rituals, bot filters, fraud review, cardholder-intent records, merchant policies, and dispute systems were built to absorb.
- Merchants, issuers, payment networks, agent platforms, consumers, regulators, and fraud teams now have to verify agent identity, user intent, transaction scope, payment authentication, replay resistance, and post-transaction evidence.
- Watch next: whether agent-commerce standards create interoperable receipts, or whether every platform builds its own permission island.
- Caveat: these are company and standards-body claims about early deployments and developing protocols. Treat them as market/infrastructure signals, not proof that agent commerce is already solved or safe at scale.
Opportunities
Where value may appear: agent-commerce receipt tools.
This is idea fodder only, not legal, financial, compliance, cybersecurity, or investment advice. Someone could build practical review packets, merchant checklists, test harnesses, or small consulting products that help teams answer the boring questions before an agent spends money.
What agent is calling? What user authorized it? What was the exact instruction? What limits applied? Which merchant saw which signature? What did the issuer authenticate? What happened when the cart changed? What record exists for fraud review or a dispute?
That is the work now. If the machine can buy, the checkout needs a witness.
Sources
- Visa, “Visa and Banks Across Europe Reach the Next Phase of Agentic Commerce, Unlocking Secure Access to Merchants,” July 2, 2026: https://www.visa.co.uk/about-visa/newsroom/press-releases.3457328.html
- Visa Developer, “Trusted Agent Protocol”: https://developer.visa.com/capabilities/trusted-agent-protocol
- Mastercard, “When AI starts buying for you, trust becomes the product,” March 5, 2026: https://www.mastercard.com/global/en/news-and-trends/stories/2026/verifiable-intent.html
- FIDO Alliance, “FIDO Alliance to Develop Standards for Trusted AI Agent Interactions,” April 28, 2026: https://fidoalliance.org/fido-alliance-to-develop-standards-for-trusted-ai-agent-interactions/
- NIST, “Building Evaluation Probes into Agentic AI”: https://www.nist.gov/programs-projects/building-evaluation-probes-agentic-ai
- NIST NCCoE, “Accelerating the Adoption of Software and AI Agent Identity and Authorization,” draft concept paper, February 2026: https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf
