AI agents are software systems that can interpret goals, use tools and take actions with limited direct instruction at each step. In commerce, an agent can search for products, compare options, assemble an order and, when authorized, initiate or complete payment on a person’s behalf.
This shift changes how trust is established. A conventional online purchase usually assumes that the customer is present at checkout. Agentic commerce adds another actor: software acting under delegated authority. Banks, payment providers and merchants must assess the person, the agent, the instruction and the transaction as connected parts of one trust decision. Entersekt helps financial institutions connect authentication and risk decisioning across digital payment journeys.
AI agents are software systems that use models, data and connected tools to pursue a goal through a sequence of actions. Unlike a conversational system that only returns an answer, an agent can select a next step, call an approved service, evaluate the result and continue until it reaches a defined outcome or requires human approval.
An agent may be fully autonomous for low-risk tasks, or it may pause at specific control points. The level of autonomy depends on the permissions, data access, tools and policies attached to it.
AI agents participate in commerce by moving parts of the buying journey from the customer’s interface to software. The agent can act as a shopping assistant, an purchasing representative for an organization, or an automated service that manages recurring needs.
The customer may be present for some steps and absent for others. That distinction matters because a payment can be legitimate only when the agent acts inside the scope of the customer’s instruction.
Agentic commerce changes who performs the actions and where control is applied. The customer remains the principal, but software may perform discovery, selection and payment execution.
| Dimension | Conventional online commerce | Agentic commerce |
|---|---|---|
| Decision maker | Person at checkout | Person delegates rules to an agent |
| Interaction pattern | Customer navigates merchant pages | Agent may use APIs, protocols or web interfaces |
| Trust question | Is the customer and payment valid? | Is the agent legitimate and acting within authority? |
| Control point | Often concentrated at checkout | Distributed across enrolment, delegation, execution and monitoring |
| Evidence | Order, payment and authentication records | Those records plus agent identity, instruction scope and intent evidence |
These differences do not remove existing payment controls. They add new questions about delegation, scope, agent identity and the relationship between the original instruction and the completed transaction.
Delegated authority is the permission a person or organization gives an AI agent to perform defined actions. A useful delegation states who granted the permission, what the agent may do, the limits that apply and when the permission expires or can be withdrawn.
Limits may cover the merchant, product category, amount, currency, frequency, delivery address or time period. A recurring purchase, for example, may be permitted only up to a cumulative budget and only from an approved merchant category.
Delegation should be treated as a security event. The initial approval may require strong user authentication, and later transactions may require risk checks or renewed approval when the request falls outside the original scope.
AI agent payments are secured through several controls that work together. No single protocol or credential answers every trust question.
Emerging payment work reflects these requirements. EMVCo’s draft framework for card-based agentic payments discusses shared intent services that can register, reference and manage consumer-authorized intent across the transaction lifecycle. Read the EMVCo framework announcement.
The main risks arise when the delegation chain is unclear, manipulated or broader than the customer intended. The risk surface includes the customer, agent, merchant, payment credential, integration layer and supporting identity services.
Here is an overview of agentic commerce fraud that describes these risks as a shift from a purely human checkout model toward a broader trust architecture based on identity, intent, authorization and transaction evidence.
Agentic commerce is developing through several complementary protocols and identity efforts rather than one universal standard. Their roles differ, so organizations should avoid treating a commerce protocol, a payment protocol and an identity credential as interchangeable.
| Technology or effort | Primary role |
|---|---|
| Agent Payments Protocol | Expresses and verifies payment intent, authorization and transaction evidence for agent-led payments. |
| Agentic Commerce Protocol | Connects merchants and AI shopping experiences through structured catalog and checkout interactions. |
| Trusted Agent Protocol | Helps merchants recognize approved agents and validate signed requests, identity and payment-related data. |
| EMVCo agentic payments work | Explores interoperable specifications for card-based agentic payments, intent management and related payment technologies. |
| Identity and authorization standards | Supply building blocks for authentication, authorization, signed claims, token protection and auditability. |
Visa’s Trusted Agent Protocol specifications describe signed, time-bound requests that can help merchants identify an approved agent, protect message integrity and reduce replay risk. NIST has also called for work on applying identity and authorization practices to software and AI agents.
Banks and payment providers should treat agent authority as a first-class part of payment risk. The practical starting point is to map where an agent is enrolled, what it can access, which actions it may perform and where a person must approve an exception.
Entersekt’s Context Aware™ Authentication approach applies risk signals to the action being performed, helping financial institutions decide when to allow, challenge or decline a sensitive interaction. This model is relevant to agentic commerce because trust may need to be reassessed after the initial delegation.
AI agents shift authentication from a single checkout event toward a sequence of trust decisions. A financial institution may authenticate the person during agent enrollment, verify the agent during a request, assess the transaction at execution and monitor activity afterward.
Fraud prevention must also evaluate intent. A valid customer and a valid payment credential do not automatically show that the specific purchase was authorized. Risk decisioning should compare the request with the customer’s instruction, account history, device context, merchant profile and agent behavior.
For online card payments, EMV 3-D Secure payments remain part of the broader payment security environment. Agentic flows may change the surrounding interaction, but issuers and merchants still need reliable authentication, authorization and fraud controls.
Yes, an AI agent can make a purchase without the customer being present at checkout when the customer has granted suitable authority in advance. The agent should still operate under defined limits, and the payment ecosystem should verify identity, intent, risk and transaction scope.
No. A recurring payment follows a predefined billing arrangement, while an AI agent may search, compare and select an item before payment. An agent can manage recurring purchases, but the authority, product rules and cumulative limits still need explicit controls.
No. Agentic commerce changes where authentication is applied. Authentication may occur when the customer grants authority, when the agent is recognized, when permissions change or when risk rises during payment execution.
An AI agent can pursue a goal through connected tools and actions, while a chatbot primarily exchanges messages. A shopping agent may query inventory, compare terms, create a cart and request payment, subject to the permissions attached to it.
User intent is important because it connects an agent’s action to the authority granted by the customer. Entersekt links authentication and risk signals to the action context, helping financial institutions assess if a payment remains consistent with the approved instruction.