Visa and Mastercard have each rolled out infrastructure allowing AI agents to make autonomous payments: Visa Intelligent Commerce on one side, Mastercard Agent Pay on the other. Hundreds of real transactions initiated by agents have already been completed with partners. According to a Visa survey, nearly half of US shoppers already use AI for at least one step of their purchases, and traffic to retail sites generated by AI tools is said to have surged over the past year.
We have written extensively about agents capable of taking action. Here is the action that changes everything, because it involves real money: buying on your behalf.
What has changed technically
Until recently, an assistant could search for a product, compare prices, and advise you. Then it stopped, and you had to leave the conversation to finalise the purchase yourself. That limit is now gone.
The bottleneck was not the model's capability, it was identity. For a payment to go through, a merchant, a bank, and a network must all recognise that the person paying is authorised to do so. Yet an agent is neither you nor a fraudster: it is a category the system had no name for.
The answer rests on tokenisation. Rather than handing your card numbers to an agent, it is issued a dedicated token with a defined scope: what amount, what type of purchase, from whom, until when. The agent can pay within those limits and nothing beyond.
This is exactly the logic we described regarding the integration between a password manager and an AI: granting permission to use a resource without handing over the resource itself.
What it is actually for
Three use cases recur in the players' descriptions.
Automatic replenishment. Routine purchases where the decision adds nothing: cleaning products, consumables, subscriptions. Here, delegation removes a chore with no stakes.
Conditional purchasing. You set a threshold, and the agent triggers when the price drops below it. This is what price alerts already did, with the final step automated.
Complex booking. A trip combining several services, where comparing manually takes hours.
These three cases share a common trait: the decision criterion is explicit and verifiable. This is probably where delegation is most defensible.
An agent that can pay becomes a high-value target. The entire attack surface we described with agentjacking takes on a direct financial dimension here: if a product page or a poisoned email can influence the instructions the agent believes it must follow, the stakes are no longer a mistaken order but a debit. Scoped tokens reduce exposure without eliminating it. The question of who reimburses in the event of an unintended purchase by an authorised agent has no clear answer yet, and it ties into the void we described regarding liability.
What changes for merchants
A deeper shift is emerging, and it concerns the entire e-commerce economy.
If an agent compares and chooses, advertising, digital shelf placement, and product page design lose part of their effect. An agent is not swayed by a photo. It compares criteria.
That might look like good news for the consumer, and it partly is. But the question becomes: by what criteria does the agent choose, and who defined them? If the platform providing the agent takes a commission on certain merchants, the objectivity of the recommendation becomes questionable. This is the classic intermediary problem, transposed to an advisor that speaks with the voice of neutrality.
What will slow things down
Three real obstacles, and it would be naive to underestimate them.
Trust. Delegating a search is risk-free. Delegating a payment requires a leap. Available surveys show broad interest in purchase assistance, and far more reluctance about full automation.
Merchant buy-in. A merchant has no obvious interest in letting an agent compare its prices against a neighbour's in an interface it does not control.
The legal framework. Consumer law rests on informed consent given by a person. A purchase triggered by software according to criteria set three weeks earlier fits poorly into that framework. The right of withdrawal, pre-contractual information, proof of consent: all of it needs rethinking.
What to take away
Agentic commerce is no longer a prospect: the infrastructure exists, real transactions have begun. What remains uncertain is the pace of adoption, and it will depend less on technology than on trust.
The sensible advice, if you test these tools, is the same as for any delegation: start with what you are willing to lose. Replenishing everyday products is a measured risk. A broad mandate over your primary payment method is another. The convenience is real, and it is paid for in exposure surface — a trade-off everyone should make knowingly rather than by default.