Retail has spent the last twenty years getting better at recognising the customer. Accounts, devices, loyalty IDs, payment credentials and behavioural signals all helped answer a basic commercial question: who is this person, and can we trust the transaction?
Agentic commerce changes the shape of that problem. The customer may still own the account and the payment method, but the entity discovering, comparing and eventually acting may be software working on their behalf. That introduces a second identity into the relationship, along with a new layer of authority that most commerce systems were never designed to understand.
The distinction matters because recommendation and action are not the same thing. An AI assistant can suggest three products with almost no commercial consequence; the same assistant can cross a very different line when it redeems loyalty points, accepts a substitution or charges a stored card without asking again. The model may be equally intelligent in both cases, but the amount of authority delegated to it has changed materially.
That is why I think the defining infrastructure problem in agentic commerce will be trust rather than intelligence. The technology is moving quickly toward being able to shop for us. The harder work is deciding when a merchant, payment provider or loyalty platform should accept that an agent is genuinely authorised to act.
Commerce now has to understand delegated identity
Digital commerce has historically treated identity as a direct relationship between customer and merchant. Even when marketplaces, wallets or social platforms sit in the middle, the underlying model is still familiar: authenticate the person, validate the credential and assess whether the behaviour looks legitimate.
An agent introduces a different arrangement. The merchant now needs to know the customer, the agent representing them and the authority connecting the two. If that chain is unclear, a technically valid transaction can still be commercially wrong.
This becomes obvious in everyday examples. I may be perfectly comfortable allowing an agent to reorder household essentials within a monthly budget, choose from brands I already buy and accept small price movements without interrupting me. I may be much less comfortable allowing the same agent to spend loyalty currency, place a high-value order with a new merchant or substitute an item where the difference actually matters.
The important point is that authority will rarely be binary. Customers will delegate in degrees, depending on category, value, merchant, risk and personal preference. Commerce therefore needs to move from simple identity toward delegated identity: not only who the customer is, but what another entity is allowed to do for them.
That sounds like a technical distinction, but it will become a customer-experience one very quickly. If the rules are too loose, trust collapses; if they are too restrictive, the customer is dragged back into every transaction and much of the convenience disappears.
Trust will have to develop in levels
I find it useful to think about delegated authority as a progression rather than an on/off switch. At the first level, the agent only researches and recommends; one step further, it can prepare the basket or transaction but still needs approval before anything consequential happens.
From there, autonomy can increase within explicit boundaries. An agent might be allowed to execute repeat purchases under a set value, use approved merchants or choose delivery options while still requiring confirmation for a new category, a large price change or the use of loyalty value.
That progression gives us a practical Agentic Trust Ladder: Recommend → Prepare → Confirm → Execute Within Limits → Act Autonomously. The useful thing about the ladder is that it describes trust, not technical capability; an agent may be able to operate at the far end long before the customer, merchant or payment provider is prepared to let it.
The appropriate position on that ladder will also vary by context. Reordering detergent is not the same as buying jewellery, and booking a familiar hotel is not the same as changing an insurance product. The same customer may want high autonomy in one part of life and almost none in another.
For retailers, this means consent will need to become much more precise than a generic permission to “use an AI assistant.” Spend limits, merchant rules, product categories, payment methods, substitution rights, loyalty access and revocation all become part of the commercial relationship. The infrastructure underneath may be complex, but the customer expectation will be simple: let the agent handle the ordinary, and return control when the decision actually matters.
Payments and loyalty will force the issue
The trust problem becomes harder to ignore once value moves. A recommendation can be wrong and still be recoverable; a payment, points redemption or subscription creates a financial consequence that somebody eventually has to own.
Payments therefore become the moment where agentic commerce stops being an interesting interface story and becomes part of the economic plumbing. The merchant needs confidence that the agent is authorised, the payment provider needs to understand the nature of that delegation, and the customer needs a credible way to challenge an action that exceeded the agreed boundary.
Loyalty creates a similar problem because points and benefits are often treated internally as marketing mechanics while customers experience them as accumulated value. An agent that can see a points balance should not automatically be able to spend it, just as access to a stored card should not imply unrestricted authority to transact.
The complication is that an agent may make a decision that is mathematically sensible and still feel wrong to the customer. It might redeem points because the expiry date is approaching, spend a little more to reach a tier threshold or choose a promotion that optimises the immediate basket while ignoring what the customer was saving those benefits for.
These are not edge cases once agents begin acting rather than merely advising. They are examples of why delegated authority needs to be explicit, machine-readable and revocable, with enough transaction context to show what the agent was allowed to do at that moment.
For commercial leaders, this is where trust architecture starts to look less like a security project and more like core commerce infrastructure. The businesses that make delegated transactions feel safe and effortless will have a conversion advantage over those that repeatedly force the customer back into the journey to prove the agent is legitimate.
Fraud will look less like fraud
Fraud systems have spent years learning to identify behaviour that does not resemble the customer. Agentic commerce introduces a new complication: legitimate behaviour may also stop looking like the customer.
A human shopper might browse for ten minutes, compare a few products and transact from a familiar device. An authorised agent may compare hundreds of options in seconds, operate through infrastructure hosted elsewhere and complete transactions with a consistency that traditional fraud rules would have treated as suspicious.
Trying to make legitimate agents behave more like people defeats the point. The better question is whether the agent itself is trusted, whether the delegation is valid and whether the transaction sits inside the permissions that were granted.
That changes the signal set. Identity still matters, but it is no longer enough on its own; provenance, delegated authority, permission scope and transaction context become part of the decision. A merchant may trust its own agent deeply, a bank-issued agent under a different set of controls, and an unknown third-party agent only enough to see public product information.
This will inevitably create false-decline risk while the ecosystem adjusts. A crude security model can end up blocking the very behaviours that make an agent useful, sending the human back through passwords, SMS codes or CAPTCHA-style challenges until the supposed convenience starts to feel like theatre.
The commercial consequence is easy to underestimate. If one merchant can recognise a trusted agent and complete the transaction smoothly while another repeatedly interrupts it, the difference will show up in conversion, repeat behaviour and eventually customer preference. Security and customer experience start to converge because trust becomes the mechanism that removes friction safely.
Human intervention should be selective, not ceremonial
“Human in the loop” is a reassuring phrase, but it can hide lazy design. If every autonomous journey ends with the customer reviewing the entire transaction and pressing Confirm, the agent has mostly automated preparation rather than decision-making.
A better model is selective intervention. Routine purchases inside established limits should pass quietly, while unusual price movements, unfamiliar merchants, high-value transactions, material substitutions or low-confidence decisions should bring the customer back into the process with enough context to make one useful choice.
The quality of that handoff matters. An agent saying, “Your usual product is unavailable; this alternative is 8 percent more expensive and has similar reviews, but the ingredients differ slightly,” gives the customer something meaningful to decide. A generic request to review the basket again simply hands the work back.
This is not only a UX issue. Human attention becomes another scarce resource in the system, and businesses that use it well can make autonomous commerce feel both convenient and controlled. The design challenge is to protect the moments where judgment matters without turning every exception into a full restart of the journey.
That principle also helps with liability. If authority changes with context, the system needs a record of what was delegated, where the boundary sat and when human approval became necessary. Accountability can only work if it travels with authority.
Trust may become a more durable moat than intelligence
The current race in agentic commerce is naturally focused on model capability. Better reasoning, better recommendations and broader automation are easy to demonstrate, and they make for compelling product launches.
I am less convinced that intelligence will remain the scarce asset. Models will improve quickly, capabilities will spread and the ability to build a competent shopping agent will become less distinctive over time.
Trust is harder to replicate because it accumulates across relationships and infrastructure. A merchant that can reliably recognise customers, agents and permissions can remove friction others cannot; a payment provider that understands delegated authority can approve with greater confidence; an agent provider that consistently respects boundaries earns the right to act more autonomously.
That creates a commercial flywheel. Greater trust allows more authority, more authority creates more convenience, and more successful use gives every participant better evidence about where autonomy works safely.
This is why I increasingly think “agentic commerce” may be slightly misleading as a strategic label. The deeper shift is toward delegated commerce: customers allowing software to exercise commercial judgment on their behalf, while merchants decide how much of that judgment they are prepared to accept.
The technology is already proving that AI can shop. The harder question is whether commerce can build enough trust around identity, permission, payment and accountability to let it act without making the customer nervous or dragging them back into every decision.
If that trust architecture works, autonomous commerce can become almost invisible. If it does not, we will have remarkably intelligent agents spending much of their time waiting for humans to approve them.
