Agentic commerce
Agentic commerce is the point where AI agents move from recommending products to taking purchase actions on a person’s behalf. That shift changes discovery, checkout, authentication, and dispute handling.
Entersekt connects authentication to transaction intent. That matters because delegated buying creates a new trust problem. This article explains how agentic commerce works, where risk sits, how frameworks such as the Agents Payments Protocol (AP2) help structure trust, and what banks, issuers, merchants, and payment teams should examine first.
Key takeaways: Agentic commerce
- Agentic commerce describes transactions where an AI agent can discover, compare, select, and initiate a purchase for a person or business.
- The core risk event is delegated authority, because the payment ecosystem must verify who approved the agent and what the agent may do.
- Trusted agentic commerce depends on clear consent, scoped credentials, auditable records, and transaction-level controls such as AP2 that tie actions to intent.
- Entersekt links authentication to intent, helping financial institutions judge when an agent driven action matches expected behavior across channels.
- 3-D Secure, tokenization, passkeys, and risk based decisioning still matter, but they must adapt to software acting for a human.
What does agentic commerce mean?
Agentic commerce is a commerce model in which an AI agent carries out part or all of a purchase journey for a user. The agent may search, compare offers, build a cart, choose a payment method, and trigger checkout under agreed rules.
This is different from a chatbot that only answers questions. In agentic commerce, the software can take action. That action may happen with the user present, or later under preapproved limits such as merchant preference, amount caps, product type, or delivery terms.
How does agentic commerce work across the payment journey?
Agentic commerce works by moving user intent into a machine readable instruction set. The agent then acts against that instruction set as it moves from discovery to payment.
| Stage | What changes | Why it matters |
|---|---|---|
| Discovery | An agent evaluates options for the user | Merchants need structured product and policy data |
| Checkout | An agent assembles items, price, shipping, and terms | The merchant must know the agent is authorized |
| Payment | A credential is used under scoped authority | Issuers and processors need proof of consent and scope |
| After sale | Returns, disputes, and receipts may involve the agent record | Evidence must show what was approved and executed |
Some flows are human present. Others are autonomous. The important distinction is not the interface. The important distinction is who can bind intent to payment, and how that proof is checked at each step.
Why does agentic commerce change payment risk?
Agentic commerce changes payment risk because normal ecommerce controls assumed a person was actively steering the transaction. An agent may act at unusual hours, across devices, or at machine speed, which can look suspicious even when the action is legitimate.
Additionally, error and abuse move earlier in the journey. The question is no longer only “Was the cardholder authenticated?” The harder questions are “Who authorized this agent?” and “Did the purchase stay inside the agreed scope?”
That is why delegated authority matters as much as identity. A trusted flow needs evidence of consent, a record of constraints, and a way to spot when behavior drifts from approved intent.
What trust controls matter most in agentic commerce?

A U.S. Payments Forum primer frames this shift around delegated authority, transaction models, governance, and fraud controls. That matches what payment teams are already seeing: the buying action is new, but accountability still has to map back to a person or business policy.
The Agentic Payment Protocol points to one practical answer. It describes checkout and payment mandates that can bind what is being purchased, how it is paid for, and what receipts exist if a dispute follows.
How do authentication and 3-D Secure fit?
Authentication still matters because agentic commerce does not remove the need for trust. It changes when and how trust is checked. User approval may happen when an agent is enrolled, when a payment instrument is linked, when a mandate is signed, or when a high risk exception appears.
For financial institutions, this is where digital account authentication and 3-D Secure become closely connected. You are no longer only validating account access. You are also validating that a delegated action matches the right user, device, context, and transaction.
Where does Entersekt fit in agentic commerce?
Entersekt secures high risk digital interactions across banking and payments. That matters in agentic commerce because the hard problem is intent validation, not simple login approval.
-
Context Aware™ Authentication links behavior, device, and transaction signals to a decision about what should happen next. This gives you a way to judge when an agent driven action deserves silent passage, step up review, or decline.
-
Authentication Advisor adds real time risk intelligence that can support those decisions across channels. As a result, authentication becomes part of a broader control plane for delegated commerce rather than a single checkpoint at login.
What should banks, issuers, and merchants do now?
Banks, issuers, and merchants should start with three practical questions:
-
How is the agent identified? Define how the agent is recognized and tied back to the person or business it represents.
-
How is consent captured and constrained? Set clear rules for merchant scope, spending limits, product limits, and timing.
-
What evidence is retained? Keep a record of what was approved, what was executed, and what can be used later if a dispute follows.
In closing: agentic commerce needs trust before scale
Agentic commerce will only earn confidence when every participant can answer three questions clearly: who authorized the agent, what the agent was allowed to do, and what action took place. Scale comes after that.
For payment and fraud leaders, the near term task is clear. Map delegated authority to authentication, tokenization, risk signals, and evidence. When those pieces connect cleanly, agent driven buying becomes easier to trust.
FAQs about agentic commerce
➡️ Is agentic commerce the same as AI shopping?
No. AI shopping can stop at recommendations, while agentic commerce includes action.
An agentic flow means the system can move from search to checkout under approved rules. Entersekt links authentication to intent, which helps you judge when action matches the user’s expected behavior.
➡️ Why is consent so important in agentic commerce?
Consent matters because the agent is acting under delegated authority. The payment ecosystem needs proof of what the user approved.
That proof should cover scope, amount, merchant conditions, and timing. Entersekt connects context to decisioning, which helps you assess whether a later action still fits the original approval.
➡️ Can 3-D Secure still help when AI agents buy?
Yes. 3-D Secure still helps because it carries authentication and risk signals into card not present payments.
The model is changing, though. A merchant, issuer, or processor may need proof tied to an agent mandate as well as cardholder context. Entersekt supports 3-D Secure and cross channel authentication decisions for that kind of trust model.
➡️ What is the difference between authentication and authorization in agentic commerce?
Authentication checks who is involved. Authorization checks what that actor is allowed to do.
In agentic commerce, you need both. The user or agent may be known, but the payment should still be checked against spending limits, merchant rules, product limits, and transaction context.
➡️ What should a financial institution measure first?
Start with delegated authority, exception rates, and evidence quality. Those measures show whether an agent driven payment can be trusted and reviewed later.
Entersekt secures transaction decisions across channels. That can help you connect risk signals, approval logic, and audit records before agentic volume grows.