Skip to main content

folkfox

Skip to main content
Skip to content
FINTECH

Most of It Went Through the Mesh. They Counted What Stayed.

Twenty-three per cent of merchants can tell when an AI agent bought something from them. The header that would tell the other seventy-seven per cent has already been written down, in three separate published specifications.

Quick answerAgentic commerce means AI agents browsing and buying on a customer's behalf. Only 23 per cent of merchants can currently identify agent-driven purchases, even though published protocols already define how an agent should identify itself at checkout.
SECTION 01

Twenty-three per cent can see it. The rest are guessing#

agentic commerce attribution gap: an ink-drawn fox holding a sieve as coins pour straight through the mesh and only a few are caught
Most of it went through the mesh. They counted what stayed.

PYMNTS Intelligence, in research commissioned by Visa Acceptance Solutions and published on 2 September 2026, reports that only 23 per cent of merchants can clearly identify both AI-driven traffic and AI-driven purchases. A further 21 per cent can see agentic traffic arriving but cannot connect it to a completed sale. Size helps only slightly: 27 per cent of large merchants can identify agent-driven purchases against 19 per cent of small and medium businesses.

Fewer than one merchant in four can connect an AI agent to a completed sale. The remaining 56 per cent is the implied balance of the two reported figures.Sees traffic and purchases: 23%Sees traffic only: 21%Sees neither: 56%23%
Sees traffic and purchases 23%Sees traffic only 21%Sees neither 56%
Fewer than one merchant in four can connect an AI agent to a completed sale. The remaining 56 per cent is the implied balance of the two reported figures.

Merchants are not, however, sanguine about where this goes, and the scent of the thing is already on the trail. In the same study 61 per cent agreed AI-generated results will influence purchases more than traditional search, 58 per cent expect agents to choose payment methods based on fees and rewards, and 56 per cent expect agents to complete transactions themselves. Thirty-eight per cent expect agent purchases to exceed 15 per cent of sales within two years.

ChartMerchants broadly expect agents to take over the buying moment, while most cannot yet measure the agent traffic they already receive.AI beats search: 61Agents pick payment: 58Agents transact: 56Over 15% of sales: 3880%60%40%20%0%61%AI beats search58%Agents pick payment56%Agents transact38%Over 15% of sales
Merchants broadly expect agents to take over the buying moment, while most cannot yet measure the agent traffic they already receive.
SECTION 02

The survey predates the standard that answers it#

One detail changes how this research should be read, and it is not on the study's own landing page. The landing page states the sample, 1,185 retail merchants across the United States, Brazil and the United Arab Emirates, and names Visa Acceptance Solutions as commissioning sponsor, but publishes no fieldwork dates. Those appear elsewhere in PYMNTS's own coverage: the merchant survey was fielded in March 2026, part of a three-survey programme that also covered 5,241 consumers in March 2026.

So this agentic commerce finding is six months old at publication, in a field where six months is a long time. That matters specifically, not just generally, because the technical answer to the attribution problem was published in the interval. The merchants were asked whether they could identify agent purchases before the specifications that make agent purchases identifiable had settled.

SECTION 03

Three specifications already carry the answer#

The reason to be impatient with the 23 per cent figure is that identifying an agent at checkout is a solved problem on paper, and has been for most of the period agentic commerce has been discussed seriously. Three separate published specifications address it, and all three were public before this research appeared.

Agentic Commerce Protocol: the agent announces itself#

The Agentic Commerce Protocol is maintained by OpenAI and Stripe as founding maintainers, licensed Apache 2.0 and currently in beta. Its agentic checkout OpenAPI specification, versioned 2026-04-17, defines the header set a compliant agent sends, including Authorization, Idempotency-Key, Request-Id, Signature, Timestamp and User-Agent. The specification's own example User-Agent value is a ChatGPT client string. A merchant terminating that request has the agent's identity in the request headers, not inferred from behaviour.

AP2: mandates that record what was authorised#

AP2, the Agent Payments Protocol, at version 0.2.0, approaches the same problem from the authorisation side. It defines a Checkout Mandate capturing the specific items and purchase details negotiated between agent and merchant, and a Payment Mandate authorising the payment itself. Google's announcement lists more than sixty participating organisations including Accenture, Adobe, Adyen, American Express, Coinbase, Deloitte, Intuit, JCB, Mastercard and MetaMask. That is a broad enough coalition that no merchant should be planning as though agentic payments will remain unstandardised.

Visa Trusted Agent Protocol: signed requests#

Visa's Trusted Agent Protocol specifications define Signature-Input and Signature header fields carrying message-signature metadata and the signature itself. That is cryptographic attribution rather than heuristic detection: a merchant can verify that a request came from a recognised agent instead of guessing from user-agent strings and traffic shape. Visa has been building this out publicly through its own newsroom alongside the developer specification, which is worth watching because the card networks, not the model providers, set the rules that decide disputes.

Between them these three specifications cover identification, authorisation and verification, which is most of what agentic commerce reporting actually requires. The gap the research measures is therefore not a gap in what is possible. It is a gap in adoption, which is a very different problem with a very different remedy.

SECTION 04

The part the specifications do not settle: who pays#

Attribution is the measurable half of the problem, and the easier half to drag out of the undergrowth. The half that decides whether agentic commerce is safe to encourage is liability, and that is where practitioners are considerably sharper than the survey.

@AnjliAmin
They built the part that drives the sale and deliberately skipped the part that touches money. So when it works, the headline number is theirs. When it doesn't, when the agent picks the wrong item or the customer says they never agreed to that, the dispute and the chargeback fee land on the retailer.
5 September 2026View on X

The claim about basket sizes in that thread is one operator's report rather than published data, and should be treated as such. The structural argument underneath it does not depend on the number. If an agent selects the wrong item, or a customer disputes a purchase they say they never authorised, the chargeback lands on the merchant, who sits on the card network's hook rather than the model provider's. Upside is shared, downside is not.

This is precisely what AP2's mandate structure is designed to address, by creating a record of what the customer actually authorised before the agent acted. Whether that record survives contact with a dispute process built for human buyers is an open question, and not one any merchant should assume the answer to. Anyone enabling ai agent payments this year is making a bet on a dispute regime that has not yet been tested at volume.

SECTION 05

What to do before agentic checkout arrives properly#

A fox holding a sieve under a stream does not conclude the stream is empty. It changes the mesh, the way a fox that loses a quarry in the hedgerow changes where it waits rather than deciding the wood is empty. The merchants in this research are measuring with the wrong instrument and reporting the result as an absence.

The gap is not in what is possible. It is in what has been implemented, which is a different problem with a cheaper fix.

Start by logging what already arrives at the den door. Agent traffic is reaching most merchants now, and the 21 per cent who can see traffic without connecting it to purchases are one join away from the answer rather than one platform migration away. Capture the user-agent and signature headers the specifications define, and store them against the session and the order, so the connection exists when somebody finally asks for it.

Then decide the commercial questions agentic commerce specifications deliberately leave open. Whether ai shopping agents should be allowed to select payment method on fee and reward grounds, given 58 per cent of merchants expect exactly that. What happens to loyalty programmes when the buyer is not the person. Who carries a disputed agent purchase in your own terms. None of those are answered by adopting a protocol, and all of them will be answered by default if nobody chooses deliberately.

The unglamorous truth is that agentic commerce will arrive as a reporting problem long before it arrives as a revenue one. The merchants who can see it will be able to price it, argue about it and negotiate over it. The ones who cannot will be told what happened by somebody with an interest in the answer.

Questions

Frequently asked questions#

What is agentic commerce?

Agentic commerce is when an AI agent browses, selects and buys on a customer's behalf rather than the customer transacting directly. It covers agent-driven product discovery through to agent-completed checkout and payment.

Why can most merchants not see agent-driven purchases?

Largely because they have not implemented the identification the published specifications define. PYMNTS found 23 per cent can identify both agent traffic and purchases, with a further 21 per cent seeing traffic they cannot connect to a sale. The capability exists in protocol; adoption lags.

How does an AI agent identify itself at checkout?

The Agentic Commerce Protocol defines headers including User-Agent, Signature and Timestamp on the agentic checkout API. Visa's Trusted Agent Protocol defines Signature-Input and Signature fields for cryptographic verification, so a merchant can confirm rather than infer an agent's identity.

Who is liable if an AI agent buys the wrong thing?

On current arrangements the merchant generally carries the dispute and chargeback, since they sit within the card network's rules rather than the model provider's. AP2's mandate structure is designed to record what the customer authorised, but that record has not yet been tested at volume in dispute processes built for human buyers.

How current is the 23 per cent figure?

The merchant survey was fielded in March 2026 and published in September 2026, so it is roughly six months old. That matters here because agentic commerce specifications advanced during the interval, including an Agentic Commerce Protocol specification version dated April 2026.

Keep reading

Read more on this topic#

Can you tell which of your sales an agent made?

folkfox works on the measurement problem before it becomes a revenue problem.

Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.