Resources | Entersekt

AI agents

Written by Entersekt | Mar 21, 2026, 11:00:00 AM

AI agents are software systems that can interpret goals, use tools and take actions with limited direct instruction at each step. In commerce, an agent can search for products, compare options, assemble an order and, when authorized, initiate or complete payment on a person’s behalf.

This shift changes how trust is established. A conventional online purchase usually assumes that the customer is present at checkout. Agentic commerce adds another actor: software acting under delegated authority. Banks, payment providers and merchants must assess the person, the agent, the instruction and the transaction as connected parts of one trust decision. Entersekt helps financial institutions connect authentication and risk decisioning across digital payment journeys.

What are AI agents?

AI agents are software systems that use models, data and connected tools to pursue a goal through a sequence of actions. Unlike a conversational system that only returns an answer, an agent can select a next step, call an approved service, evaluate the result and continue until it reaches a defined outcome or requires human approval.

An agent may be fully autonomous for low-risk tasks, or it may pause at specific control points. The level of autonomy depends on the permissions, data access, tools and policies attached to it.

How do AI agents participate in commerce?

AI agents participate in commerce by moving parts of the buying journey from the customer’s interface to software. The agent can act as a shopping assistant, an purchasing representative for an organization, or an automated service that manages recurring needs.

  1. Discovery: The customer describes a goal, such as finding a product that meets a price, delivery or specification requirement.
  2. Evaluation: The agent searches catalogues, checks availability, compares terms and filters results against the customer’s instructions.
  3. Selection: The agent recommends an option or selects one under rules that the customer has approved.
  4. Checkout: The agent creates a cart, submits delivery details and requests a payment method.
  5. Payment: A merchant, payment service provider or card network validates the request, checks risk and processes an authorized payment credential.
  6. After-sales activity: The agent may track delivery, request a refund or manage a recurring purchase, subject to its permissions.

The customer may be present for some steps and absent for others. That distinction matters because a payment can be legitimate only when the agent acts inside the scope of the customer’s instruction.

What makes agentic commerce different from online shopping?

Agentic commerce changes who performs the actions and where control is applied. The customer remains the principal, but software may perform discovery, selection and payment execution.

Dimension Conventional online commerce Agentic commerce
Decision maker Person at checkout Person delegates rules to an agent
Interaction pattern Customer navigates merchant pages Agent may use APIs, protocols or web interfaces
Trust question Is the customer and payment valid? Is the agent legitimate and acting within authority?
Control point Often concentrated at checkout Distributed across enrolment, delegation, execution and monitoring
Evidence Order, payment and authentication records Those records plus agent identity, instruction scope and intent evidence

These differences do not remove existing payment controls. They add new questions about delegation, scope, agent identity and the relationship between the original instruction and the completed transaction.

What is delegated authority in agentic commerce?

Delegated authority is the permission a person or organization gives an AI agent to perform defined actions. A useful delegation states who granted the permission, what the agent may do, the limits that apply and when the permission expires or can be withdrawn.

Limits may cover the merchant, product category, amount, currency, frequency, delivery address or time period. A recurring purchase, for example, may be permitted only up to a cumulative budget and only from an approved merchant category.

Delegation should be treated as a security event. The initial approval may require strong user authentication, and later transactions may require risk checks or renewed approval when the request falls outside the original scope.

How are AI agent payments secured?

AI agent payments are secured through several controls that work together. No single protocol or credential answers every trust question.

  • Agent identity: The merchant or payment participant needs a way to distinguish an approved agent from an unknown automation tool or malicious bot.
  • User identity: The ecosystem needs evidence that the agent is acting for a real person or organization.
  • Delegated authority: The payment request should carry or reference the user’s approved limits and purpose.
  • Payment credentials: Tokenized or restricted credentials can reduce the value of exposed payment data.
  • Intent binding: The final payment should be linked to the item, amount and terms that the customer approved.
  • Runtime risk assessment: Identity and intent should be checked alongside device, behavior, merchant, transaction and account signals.
  • Evidence and revocation: Participants need records of what was approved and a way to stop authority when risk changes.

Emerging payment work reflects these requirements. EMVCo’s draft framework for card-based agentic payments discusses shared intent services that can register, reference and manage consumer-authorized intent across the transaction lifecycle. Read the EMVCo framework announcement.

What are the main risks of AI agents in commerce?

The main risks arise when the delegation chain is unclear, manipulated or broader than the customer intended. The risk surface includes the customer, agent, merchant, payment credential, integration layer and supporting identity services.

  • Impersonated agents: A merchant may mistake malicious automation for an approved agent.
  • Instruction drift: The final order may differ from the customer’s original constraints because of incorrect data, manipulated content or a faulty decision.
  • Excessive permissions: An agent may retain access longer than necessary or act above its approved limits.
  • Credential misuse: A stolen or misdirected payment credential may be used outside the intended context.
  • Prompt or tool manipulation: An attacker may influence the agent’s inputs, connected tools or retrieved content.
  • Privacy exposure: The agent may process identity, behavioral, location and payment information across several parties.
  • Dispute uncertainty: Participants may lack clear evidence showing what the customer approved and what the agent executed.

Here is an overview of agentic commerce fraud that describes these risks as a shift from a purely human checkout model toward a broader trust architecture based on identity, intent, authorization and transaction evidence.

Which standards and protocols support agentic commerce?

Agentic commerce is developing through several complementary protocols and identity efforts rather than one universal standard. Their roles differ, so organizations should avoid treating a commerce protocol, a payment protocol and an identity credential as interchangeable.

Technology or effort Primary role
Agent Payments Protocol Expresses and verifies payment intent, authorization and transaction evidence for agent-led payments.
Agentic Commerce Protocol Connects merchants and AI shopping experiences through structured catalog and checkout interactions.
Trusted Agent Protocol Helps merchants recognize approved agents and validate signed requests, identity and payment-related data.
EMVCo agentic payments work Explores interoperable specifications for card-based agentic payments, intent management and related payment technologies.
Identity and authorization standards Supply building blocks for authentication, authorization, signed claims, token protection and auditability.

Visa’s Trusted Agent Protocol specifications describe signed, time-bound requests that can help merchants identify an approved agent, protect message integrity and reduce replay risk. NIST has also called for work on applying identity and authorization practices to software and AI agents.

What should banks and payment providers prepare for?

Banks and payment providers should treat agent authority as a first-class part of payment risk. The practical starting point is to map where an agent is enrolled, what it can access, which actions it may perform and where a person must approve an exception.

  1. Define the trust model: Identify the customer, agent provider, merchant, payment provider and relying party for each use case.
  2. Set narrow permissions: Bind authority to specific actions, limits, merchants, devices or time periods.
  3. Authenticate meaningful events: Use strong authentication when an agent is enrolled, permissions change or a high-risk instruction is issued.
  4. Bind payment to intent: Check that the final amount, merchant and purchase terms remain inside the approved instruction.
  5. Share relevant risk signals: Connect device, behavior, account, transaction and channel context across the journey.
  6. Monitor after approval: Continue assessing activity because a valid initial approval does not guarantee that later behavior is safe.
  7. Record evidence: Retain the delegation, limits, approvals, agent identity, decision and transaction outcome.

Entersekt’s Context Aware™ Authentication approach applies risk signals to the action being performed, helping financial institutions decide when to allow, challenge or decline a sensitive interaction. This model is relevant to agentic commerce because trust may need to be reassessed after the initial delegation.

How do AI agents affect authentication and fraud prevention?

AI agents shift authentication from a single checkout event toward a sequence of trust decisions. A financial institution may authenticate the person during agent enrollment, verify the agent during a request, assess the transaction at execution and monitor activity afterward.

Fraud prevention must also evaluate intent. A valid customer and a valid payment credential do not automatically show that the specific purchase was authorized. Risk decisioning should compare the request with the customer’s instruction, account history, device context, merchant profile and agent behavior.

For online card payments, EMV 3-D Secure payments remain part of the broader payment security environment. Agentic flows may change the surrounding interaction, but issuers and merchants still need reliable authentication, authorization and fraud controls.

Frequently asked questions about AI agents in commerce

➡️ Can an AI agent make a purchase without the customer being present?

Yes, an AI agent can make a purchase without the customer being present at checkout when the customer has granted suitable authority in advance. The agent should still operate under defined limits, and the payment ecosystem should verify identity, intent, risk and transaction scope.

➡️ Are AI agent payments the same as automatic recurring payments?

No. A recurring payment follows a predefined billing arrangement, while an AI agent may search, compare and select an item before payment. An agent can manage recurring purchases, but the authority, product rules and cumulative limits still need explicit controls.

➡️ Does agentic commerce eliminate the need for authentication?

No. Agentic commerce changes where authentication is applied. Authentication may occur when the customer grants authority, when the agent is recognized, when permissions change or when risk rises during payment execution.

➡️ What is the difference between an AI agent and a chatbot?

An AI agent can pursue a goal through connected tools and actions, while a chatbot primarily exchanges messages. A shopping agent may query inventory, compare terms, create a cart and request payment, subject to the permissions attached to it.

➡️ Why is user intent important in agentic commerce?

User intent is important because it connects an agent’s action to the authority granted by the customer. Entersekt links authentication and risk signals to the action context, helping financial institutions assess if a payment remains consistent with the approved instruction.

Sources and related articles