When AI Becomes the Customer: Payments in the Age of Agentic Commerce

AI agents can now search, compare, and transact for consumers. The technology is ready to buy—but is the payment ecosystem ready to trust them?
Hristian Drensky
CEO Morefin
September 11, 2026

Key Takeaways

  • Agentic commerce introduces an AI agent between the customer and the merchant.
  • Authentication alone is insufficient; businesses must also verify the customer's intent.
  • AI-initiated payments require clear spending limits, scoped credentials and auditable mandates.
  • Merchants need to distinguish trusted purchasing agents from malicious bots.
  • Payment infrastructure must preserve enough context to resolve errors and disputes.
  • Payment orchestration can become the control layer connecting identity, intent, risk, routing and accountability.

Your Next Customer May Not Be Human

Imagine giving an AI assistant a simple instruction:

"Find the best direct flight to Barcelona, book a hotel close to the conference and keep the total below €1,500."

The agent searches multiple platforms, compares prices and conditions, selects the suppliers, and completes both purchases.

The customer never visits a checkout page. They do not manually enter their card details. They may not even see the final merchant before the transaction occurs.

The payment succeeds — but several important questions remain.

Did the customer authorize those exact purchases? Was the €1,500 limit inclusive of taxes and fees? Could the agent choose any hotel? Was it allowed to accept a non-refundable rate? Who is responsible if the agent misunderstood the request?

Digital commerce was built around a person making a decision at checkout. Agentic commerce separates the person defining the objective from the system executing the transaction. That separation changes the meaning of payment authorization.

What Is Agentic Commerce?

Agentic commerce is a model in which AI agents act on behalf of consumers or businesses to discover products, compare alternatives, make decisions and potentially complete transactions. It represents a progression from assistance to action.

Traditional commerce Customer → Merchant → Payment provider The customer chooses the product, enters the checkout and authorizes the payment.

AI-assisted commerce Customer → AI recommendation → Customer approval → Merchant → Payment provider AI supports the decision, but the customer remains present at checkout.

Agentic commerce Customer sets intent → AI agent discovers and decides → Agent initiates payment → Merchant fulfils The customer defines the objective and the agent executes it within a set of permissions.

Where the purchase decision gets made — and who is making it

The critical difference is agency. An AI assistant provides information. An AI agent takes action — which may include:

  • Choosing a merchant
  • Comparing commercial terms
  • Building a shopping basket
  • Selecting a payment method
  • Initiating a transaction
  • Managing subscriptions
  • Reordering products
  • Requesting cancellations or refunds

The agent therefore becomes a new operational participant in the payment flow. For the model to scale, it cannot remain an invisible one.

Who Authorizes an AI-Initiated Payment?

Existing online payment flows usually rely on a recognizable moment of authorization: the customer clicks "Pay," completes an authentication challenge, stores a card for future use, or accepts a recurring-payment agreement.

Agentic commerce makes this moment less obvious. An agent may execute a transaction hours, days or months after the customer provided the original instruction. It may also receive discretion over the merchant, timing, product or final price.

There are several possible levels of authority:

Transaction-specific authority "Buy this exact product from this merchant for €80." The product, merchant and amount are already known. The agent has very limited discretion.

Conditional authority "Buy these headphones if their price falls below €250." The customer defines the conditions but may not be present when the transaction takes place.

Delegated authority "Manage my business travel and book the best options within the approved budget." The agent may choose between multiple suppliers, dates, products and prices.

The broader the delegation, the harder it is to prove a transaction reflects genuine intent.

The broader the delegation, the harder it becomes to demonstrate that a specific transaction reflects the customer's genuine intent.

A reliable authorization model for agentic commerce must therefore be:

  • Explicit
  • Limited in scope
  • Time-bound
  • Revocable
  • Connected to a verified identity
  • Linked to the resulting transaction
  • Visible to the relevant payment participants

The central question is no longer simply whether a credential was valid. It is whether the agent was permitted to use that credential in that particular way.

Authentication Is Not the Same as Verifiable Intent

Authentication answers one question: "Is this really the customer?"

Agentic commerce requires an additional answer: "Did the customer authorize this agent to take this specific action under these conditions?"

Google highlights this gap directly when introducing its Agent Payments Protocol:

"Who authorized that spending?"

The protocol's answer is a system of digital mandates that records the user's intent, the limits placed on the agent, and the payment resulting from the instruction. (Google Developers)

A strong agentic payment flow should establish a clear chain of evidence:

Identity → Delegation → Limits → Agent decision → Transaction → Receipt

What a payment record needs to prove an AI-initiated transaction was authorized

The customer's mandate could specify:

  • Maximum transaction value
  • Total spending limit
  • Approved merchants
  • Permitted merchant categories
  • Currency and geography
  • Product requirements
  • Expiration date
  • Frequency
  • Refundability conditions
  • Whether human confirmation is required

Mastercard describes the principle succinctly:

"When AI starts buying for you, trust becomes the product."

Its Verifiable Intent framework is designed to create tamper-resistant evidence of what a user authorized when an AI agent acts on their behalf. (Mastercard)

This distinction is fundamental. Authentication proves identity. Verifiable intent connects that identity to a defined permission and a specific outcome.

How Does a Merchant Recognize a Trusted Agent?

Merchants have spent years learning to block automated traffic. Bot-protection systems are designed to stop credential attacks, inventory abuse, scraping, automated fraud and unapproved resellers. A legitimate shopping agent may initially resemble the same traffic merchants have been trained to reject.

A merchant receiving an agentic request needs to determine:

  • Is this a recognized agent or an anonymous bot?
  • Which company operates it?
  • Is it acting for an authenticated customer?
  • Does it have genuine commercial intent?
  • What authority has the customer delegated?
  • Can it transmit payment information securely?
  • Can its actions be audited later?

Visa's Trusted Agent Protocol is designed to help merchants verify approved AI agents through cryptographic signatures and structured intent information. Visa's position is that merchants should be able to:

"Trust AI agents as much as they trust their best customers and networks."

The protocol helps distinguish trusted agents with commercial intent from malicious automation, while allowing agents to communicate customer and payment information securely. (Visa)

This creates a new requirement for merchant infrastructure. Businesses must recognize not only the customer and payment method, but also the agent acting between them.

How AI Changes Payment Fraud

Agentic commerce will not replace existing payment fraud. It will add new layers to it.

  • Agent impersonation — A malicious bot may pretend to be a registered purchasing agent to bypass merchant controls.
  • Manipulated mandates — A customer's original instruction could be altered before execution, changing the allowed merchant, value or product.
  • Prompt injection — Content encountered by the agent could manipulate its behaviour and cause it to disclose information or initiate an unintended purchase.
  • Credential misuse — An agent or connected service could attempt to reuse a credential beyond its authorized purpose.
  • Compromised agent accounts — A criminal gaining access to a trusted agent may inherit the spending authority delegated to it.
  • Machine-speed abuse — Automated systems can execute high volumes of transactions before traditional monitoring teams have time to respond.
  • Disputed intent — A customer may argue that the agent misunderstood an instruction, selected the wrong product, or exceeded its authority.

Traditional fraud models ask whether the person behind a transaction appears legitimate. Agentic risk models must ask additional questions:

  • Is the agent legitimate?
  • Is the mandate authentic?
  • Is it still valid?
  • Does the purchase fit within its limits?
  • Is the behaviour consistent with the customer's instruction?
  • Does the transaction require human confirmation?

The transaction itself is no longer the full unit of analysis. The payment must be evaluated together with the identity, mandate, agent and surrounding context.

Who Is Responsible When Something Goes Wrong?

Consider a customer who asks an agent to purchase "a refundable flight under €500." The agent books a €480 ticket carrying a substantial cancellation penalty.

Who failed?

  • Did the customer give an ambiguous instruction?
  • Did the agent misunderstand the meaning of "refundable"?
  • Did the merchant present the conditions unclearly?
  • Should the agent platform have requested confirmation?
  • Should the payment have required stronger evidence of customer approval?

Potential accountability may be distributed across the customer, the AI-agent provider, the merchant, the payment provider, the issuer, the card or payment network, and a wallet or identity provider.

There is not yet one universal liability model for all agentic transactions. Responsibility will depend on the jurisdiction, payment method, contractual relationships, authorization evidence and circumstances of the purchase.

What is already clear is that accountability cannot depend on reconstructing a natural-language conversation after a dispute. The payment ecosystem needs a shared record of:

  • What the customer requested
  • What authority was delegated
  • Which limits applied
  • What the agent selected
  • What the merchant presented
  • What the agent submitted
  • What was ultimately authorized

Without this evidence, disputes risk becoming arguments about what an AI system believed the customer meant.

What Payment Teams Should Do Now

Agentic commerce is still developing, but merchants do not need to wait for every standard to be finalized before preparing.

1. Learn to recognize agentic traffic

Merchant systems should be able to distinguish verified purchasing agents from ordinary bots and malicious automation.

2. Preserve the transaction context

Payment records may need to include agent identity, agent provider, mandate reference, customer-consent evidence, transaction limits, human-confirmation status, and relevant risk signals.

3. Use scoped payment credentials

Agents should not receive unrestricted access to a customer's underlying payment credentials. Stripe's emerging agentic-commerce model uses shared payment tokens that are scoped to a single transaction and limited in time. Its wider recommendation is equally important:

"Build for the customer behind the agent." (Stripe)

4. Establish confirmation thresholds

Human approval may be required when the spending limit is exceeded, the merchant changes, the final conditions differ from the mandate, a transaction is non-refundable, the purchase carries unusual risk, or the agent's confidence is low.

5. Adapt fraud decisioning

Agent-specific signals should complement — not replace — existing identity, device, behavioural and transaction-risk controls.

6. Prepare for agentic disputes

Customer-service and dispute teams must be able to explain what the agent was authorized to do and why the transaction was approved.

7. Avoid dependence on one protocol

Agentic standards are evolving. Payment architecture should remain flexible enough to support multiple agents, wallets, payment methods and trust frameworks.

The Role of Payment Orchestration

Agentic commerce is not simply another payment method. It introduces a new category of transaction context.

Payment orchestration can become the control layer connecting agent identity, customer identity, verifiable intent, tokenized credentials, authentication, fraud and risk systems, PSP and acquirer routing, monitoring, reconciliation, and dispute evidence.

When an AI-initiated transaction arrives, the orchestration layer should help answer:

  1. Is the agent recognized and trusted?
  2. Is the customer's mandate authentic and valid?
  3. Does the transaction fit within its limits?
  4. Is additional customer confirmation required?
  5. Which credential should be used?
  6. Which provider and route are appropriate?
  7. Which contextual evidence must be retained?

This is intelligently controlled autonomy. Businesses need the flexibility to let agents act, the visibility to understand those actions, and the controls to intervene when necessary.

The Strategic Opportunity

Agentic commerce should not be viewed only as a fraud or compliance problem. It also creates significant commercial opportunities:

  • Higher-intent customer traffic
  • Lower checkout abandonment
  • Automated procurement
  • Smarter travel and expense management
  • Automated subscription management
  • Continuous inventory replenishment
  • Personalized purchasing
  • Machine-to-machine services
  • New microtransaction business models

The checkout may no longer be a page visited by a customer. It may become a secure exchange of identity, intent, commercial conditions and payment credentials between intelligent systems.

Merchants optimized only for human browsing and manual checkout risk becoming invisible to the next generation of customers.

Conclusion: Trust Becomes the Product

AI agents are becoming customers in everything except the legal sense. They can discover products, compare terms, make decisions and initiate transactions. But autonomy without accountability will not scale.

The future of agentic commerce depends on four foundations:

  • Trusted agent identity
  • Verifiable customer intent
  • Controlled payment credentials
  • Clear accountability and recourse

The question is no longer whether AI can complete a purchase. The real question is whether every participant can prove that the purchase was authorized, correctly executed and recoverable when something goes wrong.

In the age of agentic commerce, the most important part of the transaction will not be who clicked "Pay" — but whether the system can prove why the payment happened.

Is Your Payment Infrastructure Ready for Agentic Commerce?

MoreFin helps businesses build the payment visibility, control and decisioning required for the next generation of digital commerce.

Speak with MoreFin about preparing your payment stack for intelligent, agent-initiated transactions.

Let’s Build the Right
Flow for You

Ready to elevate your digital payments? Our team is here to tailor a custom, high-performance infrastructure that scales with your ambitions. Let’s build your next competitive advantage - together.