New batches starting this week Β· Limited seats

Agentic Commerce Explained: How AI Agents Buy, Pay and Transact Safely

Agentic commerce lets AI agents search, build carts and pay on a user's behalf. This explainer covers AP2 mandates, the Agentic Commerce Protocol, card-network agent programmes, UPI agentic payment pilots in India and the engineering patterns that keep agent payments safe.

Agentic commerce flow: user intent, signed mandate, agent shops, limits and confirmation, audited payment
Last updated Β· 14 min read Β· 3,057 words

Agentic commerce is shopping and purchasing carried out by AI agents on behalf of a person or a business: the agent searches, compares, builds a cart and, within limits the user has set, pays. The hard part is not getting an agent to click "buy". It is proving afterwards that a real person authorised that exact purchase, within that exact limit, so that merchants, banks and payment networks can trust the transaction and settle disputes fairly. That is why the field is being shaped by payment protocols such as Google's Agent Payments Protocol (AP2), the Agentic Commerce Protocol (ACP) from OpenAI and Stripe, card-network programmes from Visa and Mastercard, and, in India, UPI pilots built on Reserve Pay.

What is agentic commerce?

Checkout pages, OTP screens, fraud models and dispute processes all assume the person who clicked "pay" owns the account and meant to spend. An AI shopping agent breaks that assumption. If you are new to agents, start with what agentic AI is; this article focuses on what changes when an agent touches money.

Three kinds of agent payments are worth separating:

  • Human-present purchases. The agent researches and builds the cart; the user confirms in real time.
  • Delegated purchases (human not present). The user sets rules in advance (budget, merchant, category, time window) and the agent buys when the conditions are met.
  • Machine-to-machine payments. An agent pays for an API call, a dataset or content, often in tiny amounts, with no checkout page at all.

The core problems agentic payments must solve

1. Proving user intent and authorisation

With an agent in the middle, "did the customer authorise this?" splits in two: did the user authorise the agent, and did the agent stay within that authorisation? A chat transcript is weak evidence because it can be edited, summarised wrongly or misread. Evidence must be signed, tamper-evident and specific.

2. Spending limits

"Buy me headphones" is not a limit. A safe system turns vague instructions into hard constraints: a maximum per transaction, a cap per period, allowed merchants or categories, and an expiry. The payment layer must enforce them, because a prompt can be ignored, misread or manipulated.

3. Merchant trust

Merchants have spent years blocking bots; now some bots are legitimate buyers. A merchant needs to tell an accountable shopping agent apart from a scraper or credential-stuffing tool, and to know which user it represents.

4. Disputes and liability

If the agent orders the wrong size, buys twice or is tricked by a malicious listing, who pays: the user, the agent platform, the merchant, the payment provider or the bank? Card and UPI rules predate agents. The new protocols produce evidence to answer it; the commercial and regulatory answers are still being settled.

5. Fraud

Agents add attack paths such as prompt injection hidden in product pages, fake merchants built to attract agents, stolen agent credentials and replayed authorisations. They also remove an old defence: a human noticing that something looks wrong. See AI guardrails for input-side defences; the payment side needs its own controls, described below.

The protocols and programmes, and who stewards them

For the wider protocol landscape (MCP, A2A, AG-UI and others), see our sibling explainer on AI agent protocols. Below are the commerce-specific ones, as their stewards describe them. All are young and still changing.

Agent Payments Protocol (AP2)

Google announced AP2 in September 2025 as an open protocol for agent-led payments, built with a large group of payments and technology companies. Its central idea is the mandate: a cryptographically signed digital contract, backed by verifiable credentials, that records what the user instructed.

  • An Intent Mandate captures the user's request and conditions, such as a product, a price limit and a time window.
  • A Cart Mandate records the exact items and price approved, creating an unchangeable record of what was bought for how much.

In a human-present flow, the user signs the Cart Mandate after seeing the cart. In a human-not-present flow, the user pre-signs an Intent Mandate and the agent produces the cart when the rules are met. AP2 was designed as an extension of the A2A protocol, can also work with MCP, and is payment-method agnostic; Google also announced an A2A x402 extension, developed with Coinbase and others, for stablecoin and crypto payments.

Status: in April 2026 Google donated AP2 to the FIDO Alliance for community-led governance and released version 0.2 with human-not-present payments. Mastercard contributed a related standard, Verifiable Intent, intended as a tamper-proof record of the actions a user authorised an agent to take.

Agentic Commerce Protocol (ACP)

ACP was co-developed by OpenAI and Stripe, launched in September 2025 and released under the Apache 2.0 licence, with OpenAI and Stripe as founding maintainers. It defines how merchants expose products and checkout to AI agents while remaining the seller, keeping control of pricing, fulfilment and the customer relationship. Its launch payment primitive was Stripe's Shared Payment Token, which lets an agent platform start a payment without seeing the buyer's card details and is limited to a specific merchant and cart total. Other payment providers can adopt ACP too.

Status: ACP first powered Instant Checkout in ChatGPT for US users. In March 2026 OpenAI said that version was not flexible enough, let merchants use their own checkout and refocused on product discovery, with merchants sharing catalogues through ACP.

Card-network agent programmes

  • Mastercard Agent Pay (April 2025) is built around Agentic Tokens: tokenised card credentials that register, verify and identify agent transactions, tying each payment to an authorised agent interaction and the cardholder's limits.
  • Visa Intelligent Commerce brings payment credentials, spend controls, authentication and commerce signals into agent-led buying. Its Trusted Agent Protocol (October 2025, with Cloudflare) uses HTTP Message Signatures so merchants can recognise approved agents and block malicious bots.

AWS AgentCore Payments

AWS added payments to Amazon Bedrock AgentCore, previewed earlier in 2026 and generally available from August 2026. It targets agents paying for paid APIs, MCP servers and content, integrates with Coinbase and Stripe Privy wallets, supports x402 and the Machine Payment Protocol (MPP), enforces configurable payment limits at the infrastructure layer and reports through AgentCore Observability.

InitiativeStewardLayerKey idea
AP2Google; donated to the FIDO Alliance (2026)Authorisation evidenceSigned Intent and Cart Mandates
ACPOpenAI and Stripe (Apache 2.0)Merchant catalogue and checkoutMerchant stays seller; scoped payment tokens
Mastercard Agent PayMastercardCard networkAgentic Tokens tied to agent and limits
Visa Intelligent CommerceVisaCard network, agent recognitionCredentials, spend controls, signed agent identity
AgentCore PaymentsAWSAgent platformWallets, limits, observability
UPI Reserve Pay pilotsNPCI with Razorpay and AI platformsIndian real-time paymentsOne-time consent, limit per merchant

India: UPI, NPCI and agentic payments

  • October 2025: Razorpay, NPCI and OpenAI announced an agentic payments pilot in ChatGPT, with Axis Bank and Airtel Payments Bank as banking partners and BigBasket among the first merchants, built on UPI Circle and UPI Reserve Pay.
  • February 2026: at the India AI Impact Summit, Razorpay and NPCI announced UPI agentic payments on Anthropic's Claude, with Zomato, Swiggy and Zepto as initial merchants, also a pilot with a limited user group.

UPI Reserve Pay is based on NPCI's Single Block Multiple Debit framework. The user consents once and sets a spending limit for a merchant; that amount is reserved in their bank account; the merchant can debit several times within the limit without a fresh UPI PIN. The user can see the block and revoke consent. It is a mandate in UPI form, enforced by the bank rather than by the agent.

In September 2026, press reports citing Reuters said NPCI was preparing a broader framework, reported as a "Unified Agent Protocol", for registered agents to make small routine UPI payments within user-set limits. NPCI had not formally confirmed details then, so treat limits, liability and timelines as unknown until NPCI publishes them.

RBI expectations, in general terms. RBI requires digital payments to be authenticated by at least two factors unless exempted, and its Authentication Mechanisms for Digital Payment Transactions Directions, 2025 (compliance from April 2026) encourage newer, risk-based factors. Its FREE-AI report (August 2025) set out principles for responsible AI in finance. Designs should start from explicit consent, strong authentication at delegation, limits, transparency and a clear complaint path. Personal data also falls under the DPDP Act; see DPDP Act for AI applications.

Engineering patterns for safe agent payments

User --consent + limits--> Mandate (signed)
  |
  v
Agent --search/compare--> Merchant catalogue
  |
  v
Cart built --> Policy check (limit, merchant,
  |            category, expiry, velocity)
  |-- over threshold --> Human confirms
  v
Payment with scoped token / UPI Reserve Pay
  |
  v
Audit log: mandate + cart + payment + result

Store the user's authorisation as a signed, structured object, not a sentence in the prompt. It names the user, the agent, allowed merchants or categories, maximum amounts, a validity period and how to revoke it. Scope the agent's payment credential to that mandate: a token valid for one merchant and one cart total is far safer than raw card details. This is an identity problem as much as a payments one; see AI agent identity and access for delegation and least privilege.

Per-transaction and per-period limits

Enforce limits in deterministic code or at the payment provider, outside the model: per-transaction amount, cumulative spend per period, transaction velocity, merchant allow-lists and blocked categories. If the model proposes something outside policy, the call fails. The model never "decides" that an exception is reasonable.

Human confirmation at the right moments

Ask for confirmation when the amount crosses a threshold, the merchant is new, the cart differs from the stated intent or the agent is unsure. Show item, quantity, seller, total including delivery and payment source in plain language. The trade-offs are covered in human-in-the-loop AI.

Audit trails

Record the mandate, the tools the agent called, the cart shown, any confirmation, the payment reference and the merchant's response, linked by one trace ID. AI observability tooling gives you traces; payments need them tamper-evident and retained as long as your obligations require.

Want to build agents that call tools, enforce policy and keep audit trails, not just chat? Cloudsoft's AI, GenAI and Agentic AI course covers agents, tool calling, MCP, guardrails and evaluation with hands-on labs.

B2B procurement agents vs consumer shopping agents

AspectConsumer shopping agentB2B procurement agent
Who authorisesOne person, often on a phoneApproval chain under a delegation-of-authority policy
Payment methodCards, UPI, walletsPurchase orders, invoices, corporate cards, bank transfers
LimitsPersonal budget per merchant or periodCost-centre budgets, contract prices, approved suppliers
Main riskWrong item, overspend, fraud on the userOff-contract buying, collusion, split orders to dodge approval
SystemsMerchant apps, payment gatewayERP, procurement suite, supplier portals, accounts payable
Evidence neededConsent and cart record for disputesFull audit trail for internal audit and tax

Consider a bank's procurement team that wants an agent for routine IT purchases such as accessories and software renewals. The agent compares quotes from approved suppliers, checks contract prices and drafts a purchase order. It must not add suppliers, exceed the cost-centre budget or split a large order to stay under an approval threshold. Orders above a set value go to a human approver, and the agent's work links to the ERP record. Our generative AI in banking guide covers the control environment such a team works within.

An illustrative Indian e-commerce example

Consider a mid-sized Indian grocery retailer that wants to accept orders from AI assistants. This is a hypothetical design, not a description of any real company.

  1. Catalogue for agents. The retailer publishes structured product data: SKUs, pack sizes, prices including GST, delivery slots by PIN code and stock, so agents never scrape the website. The groundwork is covered in AI in retail and e-commerce.
  2. Consent. A customer asks their assistant to handle weekly staples. The first time, they are handed to their UPI app to set up a Reserve Pay block with a monthly limit for this merchant, authorised with their UPI PIN.
  3. Each order. On Saturday the agent builds a cart from the usual list, checks stock and delivery slot, and validates it against policy: within the limit, allowed categories only, no costly substitutes.
  4. Exceptions. If a substitute is a different brand or much dearer, the agent asks first. Restricted categories such as medicines are blocked from delegated buying entirely.
  5. Payment and notice. The order is debited against the reserved amount; the customer is notified and can revoke the block at any time.
  6. Disputes. If the customer says "I didn't order this", support pulls the trace: consent record, cart, policy result, payment reference and delivery proof.

The model only understands the request and assembles a sensible cart. Everything that touches money runs on deterministic systems the bank, UPI rails and retailer already operate.

Risks to plan for

  • Prompt injection and manipulated listings that push an agent towards a seller or a higher price.
  • Over-broad delegation: long-lived, high-limit mandates that users forget about.
  • Mistakes that look authorised: wrong variant, duplicate order, wrong address.
  • Unclear liability between agent platform, merchant, payment provider and bank, especially across borders.
  • Standards churn: keep a payment abstraction so you can swap protocols and providers.

Taking a design like this from prototype into a real retailer or bank is the kind of work Forward Deployed Engineers do; Cloudsoft's FDE PRO program is built around that delivery path.

Note: this article explains technology and published industry initiatives for engineers. It is not financial or legal advice. Payment rules, liability and regulatory requirements depend on your jurisdiction, payment partners and contracts; check current official guidance and take qualified advice before launching payment features.

FAQ

What is agentic commerce?

Agentic commerce is buying and selling carried out by AI agents on behalf of a person or business. The agent searches, compares, builds a cart and pays within limits the user has authorised, either with the user confirming in real time or under rules set in advance.

What is the Agent Payments Protocol (AP2)?

AP2 is an open protocol announced by Google in September 2025 for payments made by AI agents. It uses signed mandates, such as Intent Mandates and Cart Mandates, as verifiable proof of what the user authorised. In April 2026 Google donated AP2 to the FIDO Alliance.

How is ACP different from AP2?

The Agentic Commerce Protocol, co-developed by OpenAI and Stripe, focuses on how merchants expose products and checkout to AI agents while staying the seller. AP2 focuses on proving user authorisation through signed mandates. They address different layers.

Can AI agents make UPI payments in India?

Yes, in pilots. Razorpay and NPCI have run agentic payment pilots with ChatGPT (announced October 2025) and Claude (announced February 2026), built on UPI Reserve Pay, where the user sets a spending limit for a merchant once and can revoke it at any time.

What is UPI Reserve Pay?

UPI Reserve Pay is based on NPCI's Single Block Multiple Debit framework. The user authorises a spending limit for a merchant once, the amount is reserved in their account, and the merchant can debit multiple times within that limit without a fresh UPI PIN each time.

Who is liable if an AI agent buys the wrong thing?

It depends on the payment method, platform terms, merchant policies and local rules, and much of this is still being settled. Signed mandates, cart records and audit trails exist so disputes can be resolved on evidence. This is not legal advice.

How do you stop an AI shopping agent from overspending?

Enforce limits outside the model: scoped payment tokens or reserved amounts, per-transaction and per-period caps, merchant allow-lists, human confirmation above a threshold, and instant revocation. Never rely on prompt instructions alone.

If you want to build agents that act safely on real systems, from tool calling and MCP to guardrails, human approvals and evaluation, join Cloudsoft's agentic AI training in Hyderabad, in our Ameerpet classroom or live online. Call +91 96660 19191 for a free demo.

Share𝕏infβœ‰
EnrollWhatsAppCall us