Earlier this year, Google introduced the Universal Commerce Protocol (UCP), an open standard designed to enable AI agents, businesses, and payment providers to communicate and transact through a shared framework. Then came Universal Cart, the company’s new intelligent shopping hub that brings products from across its ecosystem into a single, AI-powered destination.
If you rewind a bit further, Adobe reported that traffic from generative AI tools to U.S. retail sites jumped nearly 1,300% YoY during the 2024 holiday season, with strong growth carrying into the 2025 season.
Across these turns of events, it may be difficult to pinpoint exactly where consumer behavior and platform innovation started to feed into each other. But as AI agents, consumer platforms and payment providers race to connect with one another, merchants increasingly find themselves in the middle, responsible for managing transactions they have less and less influence over.
The Architectural Dilemma
More often than not, integration is largely being optimized at the level of connectivity between systems, rather than at the point where decisions are actually executed. AI platforms are steadily being enabled to communicate with payment providers. But the way a transaction is structured, routed, and controlled across systems has not been fundamentally reconsidered, further pushing the problem onto the merchant. This is where a key architectural question arises: where should agentic payment logic live?
If it is embedded in the shopping cart, the logic sits too close to the platform layer, increasing dependency and risk of lock-in. If it sits entirely with payment service providers, merchants retain execution but lose the ability to shape how transactions are routed across their own systems.
What is missing in both approaches is a neutral layer that can interpret intent and coordinate execution without being tied to either the interface where the purchase begins or the infrastructure where it is settled. In one case, routing is constrained by platform logic, and in the other, it’s fragmented from the merchant’s broader commerce stack.
Placing agentic logic at the payment layer becomes the third option. Rather than forcing merchants to choose between platform dependency and payment-provider dependency, it creates a point where transaction decisions remain under merchant control regardless of how the purchase is initiated or ultimately processed. Merchants can introduce agent-driven experiences without redesigning their payment infrastructure, while continuing to coordinate transactions across inventory, order management, and payment routing.
New Risks Call for Clear Separation
Agentic commerce is defined by greater autonomy for AI systems acting on behalf of customers. That autonomy, however, makes it harder to distinguish AI-initiated transactions from standard payment flows, exposing core systems to new operational uncertainty.
For instance, an AI agent could complete a purchase after dynamically comparing prices or applying budget constraints set by the user, but the resulting payment still enters the merchant’s system as a standard checkout event. Without separation, merchants lose visibility into how that transaction was initiated and whether it should be treated differently from a normal purchase.
This reinforces the case for planning agentic payment logic at the payment layer, where these flows can be isolated and managed independently. This means identifying AI-initiated transactions at the point of entry, allowing merchants to apply different routing decisions, payment providers, or controls, depending on the nature of the transaction. Think of limiting purchases above, say, $100 or barring luxury purchases if initiated by an agent. It also creates a space to test and adapt agent-driven purchases without affecting the stability of the broader payment system.
Setting Operational Boundaries
The indistinguishability of agentic transactions discussed earlier also creates a broader challenge of classification within existing fraud systems. Because AI agents closely resemble automated bots in their behavior, they are often treated as high-risk activity by default in environments already saturated with AI-driven fraud attempts, and quite reasonably so. Trust, therefore, cannot be inferred from behavior alone. It has to be explicitly signaled and recognized by each layer of the system.
This means the consumer must clearly authorize the agent to act on their behalf, and that permission must be recognizable not just to the payment provider but also to the merchant initiating the sale. At the same time, the merchant must also be able to confirm that the agent is operating under valid authorization, while also providing its own verifiable identity to the agent.
If you consider it this way, you’ll find that isolation alone is not sufficient without a corresponding model for controlling access to payment credentials. Since agents require some form of delegated permission to transact on a user’s behalf, permission must be structured in a way that is explicit, limited, and verifiable across the transaction flow. Credential handling therefore becomes a necessary extension of payment-layer logic. In effect, payment details are not exposed directly to the agent but are instead stored in secure environments and represented through tokenized credentials that act as controlled proxies for underlying transactions.
These tokens define the operational boundaries within which agentic payment logic can function. Rather than granting open-ended access to a payment method, they can encode limits such as spending thresholds, frequency, or validity windows, ensuring that agent-driven transactions remain strictly within predefined constraints. In this sense, what we can call “vaulting” is the mechanism through which these constraints become practically enforceable.
Hence, while the payment layer determines how transactions are identified and governed, tokenisation ensures that agents can only execute actions they have been explicitly authorized to perform.
Growing Amidst Rising Pressure
Up until a few years ago, the idea of autonomous agents making purchases on your behalf may have seemed like a distant possibility. But today, the U.S. B2C retail market for agentic commerce is forecast to reach approximately $1 trillion in revenue by 2030. For merchants, the significance of that scale lies not in the number itself, but in what it means for visibility and control inside their own systems.
The pressure to move quickly can cost merchants the clarity needed to understand what is actually happening in their own systems. Of all the power that granular visibility and control can vest upon merchants, the most valuable is the freedom and flexibility to start small, learn from early patterns, and scale in line with confidence.

