Agentic Commerce Is Live. The Rules Are Not.
Aug 25, 2026
•
8 min read

The payments industry has been through waves of structural change before. PSD1, which came into force in 2009, established the foundations for a pan-European single market for payments. PSD2, which went live in January 2018, introduced Strong Customer Authentication (SCA), forcing every online merchant in Europe to adapt. 3D Secure became the layer that authenticated the human behind the card.
Each of these changes was significant. But they all shared one assumption: a human being was making the purchase.
Agentic commerce breaks that assumption entirely. And the industry may not be ready for what follows.
The Foundation: PSD1, PSD2, and SCA
PSD1, adopted in 2009, established the legal framework for a single European payments market. PSD2, which became applicable in January 2018, introduced SCA, the requirement for multi-factor authentication across European digital payments.
SCA changed the industry. It reduced fraud at the point of payment, but it also introduced friction, impacting conversion rates across Europe. The entire payments ecosystem, from card schemes to acquirers and PSPs to merchants, built its fraud frameworks, risk models, and checkout flows around one core assumption: a human at the keyboard would authenticate a transaction through something they know, something they own, or something they are.
Now that assumption is beginning to collapse.
The Shift: Agentic Commerce Changes Everything
Agentic commerce, where AI-powered agents shop, compare, and purchase on behalf of consumers, is already live. McKinsey projects that agentic commerce could generate $3 to $5 trillion globally by 2030, with Google's research projecting that over $1 trillion in US retail transactions could be influenced by AI agents by 2030. Visa predicts that AI agents will move from a niche capability to a mainstream purchasing tool beginning in 2026, and has already completed hundreds of real-world agent-initiated transactions through pilot programs with merchants, fintechs, and technology providers. Google launched its Universal Commerce Protocol in January 2026 with Walmart, Target, Shopify, and more than twenty partners backing it.
These initiatives demonstrate that agent-initiated, authenticated transactions are already taking place on existing payment infrastructure.
The problem is that the regulatory and operational infrastructure for agentic commerce lags far behind the commercial infrastructure. As of early 2026, there appears to be no dedicated regulatory framework specifically addressing autonomous AI purchasing. In the EU, the AI Act, PSD3, GDPR, and the Consumer Rights Directive all overlap without clearly answering the central question: when an AI agent makes an unauthorized or harmful purchase, who is liable? The AI Liability Directive acknowledges that the complexity and opacity of AI make it difficult for victims to identify the liable party, but it was designed for damage caused by AI-enabled products, not for AI acting as an economic agent in its own right. PSD3 is still being finalized, with the final text expected in H1 2026 and implementation not expected until late 2027 at the earliest.
To date, no comprehensive regulatory framework has been introduced specifically for autonomous AI purchasing.
Key Unanswered Questions
The Third Actor Problem
McKinsey identifies agentic commerce as the “third actor problem”: a non-human entity initiating transactions that existing law was never designed to accommodate. Unlike traditional e-commerce, where a consumer and merchant interact directly, agentic commerce introduces an AI intermediary. When something goes wrong—a misunderstood preference, a calculation error, an unintended purchase—the question of responsibility becomes ambiguous.
The liability could fall on the consumer who delegated authority to the agent, the AI provider that built and operates it, the merchant that accepted the transaction, or the payment processor that facilitated it. Currently, major retailers are answering this question themselves. Target updated its terms to state that customers must review all AI-generated activity and notify the company of unauthorized transactions, with an explicit disclaimer: “Target does not purport to guarantee that an Agentic Commerce Agent will act exactly as you intend in all circumstances.” Walmart mirrors this approach, updating its policies to acknowledge that generative AI features “may not be accurate, complete or up-to-date and may be misleading or contain errors.”
Both retailers appear to place the financial risk of AI agent errors on the customer—a temporary solution that does not resolve the deeper regulatory question. Industry groups and legal experts have warned that existing frameworks for dispute resolution, consumer disclosures, and transaction authorization may not fully address purchases initiated by AI agents, potentially requiring new compliance controls and consumer safeguards.
Authentication Without Presence
Today, dispute teams rely on established data points: 3D Secure results, device fingerprinting, IP addresses, and transaction metadata. These signals establish that a human being, in a specific location, using a known device, authorized and authenticated a transaction.
In agentic commerce, those signals are absent or altered. The device is the agent. The location is the agent's infrastructure. The behavioral indicators are machine-generated, not human. Future dispute teams may need to evaluate an entirely new layer of context, and the frequency of consumer disputes will likely increase, not from credential theft, but from unexpected or unwanted AI-initiated transactions.
For example, if an AI agent purchases a higher-priced product because it misunderstood a user's preferences, the consumer may view the charge as “unauthorized,” while the bank and merchant may view it as a valid agent-directed transaction. This may necessitate a broader recalibration of customer support flows, refund policies, and dispute resolution procedures.
Systems that can explain why a purchase occurred, what instruction the agent followed, and what conditions triggered the payment are likely to place firms in a stronger position when handling disputes. On the regulatory side, the CFPB has not yet updated Regulation E to address agentic commerce. As written, Regulation E would leave consumers without the dispute rights they rely upon for every other electronic transaction if contesting agentic purchases, regardless of where the mistake occurred.
Authentication of Agents, Not Just Humans
Authentication in agentic commerce requires a fundamental shift: verifying an agent rather than verifying a person. Before a transaction can be approved, it is important to authenticate the agent—that it is a valid agent and that it is associated with a specific entity on whose behalf it is permitted to act. Once an agent is authenticated, it is also prudent to ensure the agent is authorized for the particular transaction: whether the user has empowered it to implement that type of transaction, at what frequency, and at what dollar amount.
Companies must be able to demonstrate, through auditable records, the scope of the user's mandate (the specific action taken by the agent and the details of the resulting transaction). Traditional payment regulations generally assume a consumer is directly involved in initiating a transaction. Agentic commerce relies on AI systems acting under delegated authority, a model that existing regulatory frameworks do not yet fully address.
What This Means for Acquirers, PSPs, and Merchants
For Acquirers and PSPs
The commercial deployment of agentic commerce is happening now. The payment infrastructure has already been built to support it. Acquirers and PSPs that cannot handle agentic transactions may lose merchants to those that can.
The immediate challenge is operational: how do you process a transaction that carries an Agent Token instead of a cardholder signature? How do you validate intent data? How do you manage disputes when the evidence looks different from anything you have encountered before?
The deeper challenge is strategic. Agentic systems introduce a new attack vector for fraud. The threat model shifts from stolen credit cards to stolen or manipulated agents. Credential compromise or malware can be used to distort user preferences, resulting in transactions that technically follow preset rules but do not reflect user intent. Companies facilitating agentic payments will most likely need to bolster authentication and transaction-risk scoring protocols.
For Merchants
Agentic commerce changes the economics of discovery and the legal landscape of consent. If an agent visits a merchant site that the user has never visited and “clicks” to accept terms, it is unclear whether that constitutes binding consent to the terms by the user. Merchants would be well advised to ensure it is a human agreeing to the terms, or that the user has expressly authorized the agent to accept the terms on their behalf.
Merchants will need acquirers and PSPs that can handle agentic transactions and provide the governance and oversight needed to manage risk. Those that cannot may find themselves excluded from agent-mediated purchasing environments. The competitive pressure is already mounting, and the window to prepare is narrowing.
The Path Forward
The regulatory framework continues to evolve and has not yet fully caught up with the pace of commercial developments. PSD3 is still being finalized, with implementation not expected until late 2027 at the earliest. In the meantime, merchants and PSPs cannot afford to wait.
The industry needs partners who can do two things.
First, navigate the existing regulatory framework while adapting to agentic transactions. That means understanding the nuances of SCA, liability shifts, and dispute evidence in a world where the “customer” may not be present.
Second, build the governance and oversight layer for agentic commerce. The governance gap is not theoretical. Depending on the commercial arrangements in place, merchants may bear significant responsibility for fraudulent transactions in agent-led payment flows. PSPs and acquirers that can provide merchants with better tools, data, and risk management will be better positioned to support agentic commerce.
The payments industry has never had to answer this question before: when an AI agent initiates a transaction, who do you authenticate? The agent? The consumer? The platform?
The schemes have started defining it. Regulators are playing catch-up. The ecosystem will need to navigate whatever framework emerges, but they must be ready for the transactions that are already happening.
Preparing for the next era of commerce?
Talk to Griner: support@griner.io

