This year has accelerated the rollout of so-called "agentic commerce": AI agents that do more than advise — they complete purchases on behalf of users. Visa expects that millions of shoppers will allow AI agents near their finances during this year’s holiday season. The real turning point came in autumn 2025, when OpenAI and Stripe enabled instant payments inside ChatGPT: US users can buy without leaving a conversation, initially from Etsy and later from more than one million Shopify merchants.
2026: payment players and standards move into place
By early 2026 the sector moved into a phase of standardization and product launches. The Universal Commerce Protocol launched in January to harmonize how webshops and AI agents negotiate. Visa is building a framework called "Intelligent Commerce," while Mastercard rolled out an "Agent Suite" in the second quarter of 2026. Both approaches include a "Know Your Agent" concept — extending bank-style identity logic to software so merchants can distinguish an authorized agent from a fraudulent bot.
Adoption is growing quickly: according to nShift’s 2026 report, 58% of consumers already use AI for parts of the shopping process (price comparison, recommendations), and the model foresees that by 2030 up to a quarter of e‑commerce spending could flow through agents. Industry participants say that in 2026 the foundational protocols, payment rails and the first millions of merchants will define the market’s backbone.
How an agent authorization typically works
A typical setup has three elements: you set spending limits (for example, monthly 50,000 HUF, single purchase max 15,000 HUF), you narrow the shopping scope (only groceries, only specified stores, only previously approved items), and you set approval thresholds (the agent must ask before purchases above a given amount). Technically, these are often enforced with single‑use or dedicated virtual card numbers: the agent does not receive your main card details but a revocable, limited payment authorization. The merchant verifies the software via Know Your Agent checks.
On paper this is an elegant architecture, but in practice everything depends on whether users actually configure and respect these limits: leaving broad default permissions undermines control.
Liability and regulatory gaps
The thorny issue is liability: what if the agent makes a mistake — buys the wrong item, duplicates an order, picks a more expensive option, or spends at a fraudulent shop? As of 2026 no specific legal framework tailored to agentic purchases exists. Authorities have so far tried to apply existing consumer protection rules. The UK Competition and Markets Authority in spring 2026 signalled that the same consumer protection rights apply whether a human or an AI agent is behind a transaction, and that merchants cannot shift responsibility to the fact that they did not develop the software.
However, a "chargeback liability gap" has emerged in the payments chain: if an agent makes an erroneous purchase using your valid authorization and within your set limits, current rules may not treat it as an unauthorized transaction, so classical card chargebacks might not provide protection. In response, American Express has committed to reimbursing mistaken purchases made by AI agents registered with it, although this currently applies only in a closed, controlled environment. EU consumers remain protected by the 14‑day withdrawal right for online purchases even if someone else (an agent) filled the cart, but the return administration typically falls on the consumer.
Behavioural and competition risks
One major risk is behavioural: behavioural economics shows that the less painful payment feels, the more we spend. AI agents represent the endpoint of this trend — payment can happen without the user being present at the moment of purchase, removing frictions that used to slow impulse buys.
There is also a bias and competition risk: who guarantees that an agent chooses the objectively best deal rather than one with hidden payments behind it? The International Monetary Fund highlights competition, transparency and accountability as core regulatory challenges for agentic payments. Agents can also build extremely detailed consumer profiles, including intentions that never resulted in a purchase.
Practical rules if you try an agent
Rather than rejecting the technology, safe use is recommended. Five practical rules: 1) start small with a narrowly defined task and low limits, 2) always set approval thresholds above which the agent must ask you, 3) give the agent a separate virtual card with its own budget, never your main account, 4) review agent purchases monthly just as you would your bank statement, 5) keep savings separate — shopping can be delegated, but major financial decisions should not.
Closing thought: convenience versus control
The technology already knows how to buy things; what it does not know is what truly suits your taste, what feels good to you, or what level of spending is responsible for your finances. A well‑configured AI agent can bring convenience to everyday life, but legal, market and psychological risks mean retaining user control and watching regulatory developments remain essential.



