Agentic commerce stopped being a keynote topic some time in the first half of 2026. The proof is not a product launch. It is two paperwork-adjacent artifacts published within days of each other this September, from institutions that do not waste paper on speculation.
The first is an investment outlook. KPMG’s Pulse of Fintech H1 2026, its biannual read on where global fintech capital is heading, names agentic commerce among the top themes for the second half of 2026. The second is an industry playbook. The Autonomous Economy: How AI Agents, Stablecoins and Payment Infrastructure Are Shaping the Next Generation of Commerce, a whitepaper from the Singapore FinTech Association with Visa and StraitsX, synthesizing a July 29 roundtable that pulled in Grab, Stripe, AWS, Google Cloud, Aave, the Monad Foundation, OKX, Tazapay, Finmo and Cyber Sierra.
An accounting firm’s capital allocation thesis and a Southeast Asian industry roundtable do not usually move together. When they do, they are describing a consensus. And the consensus is worth reading closely, because what it funds it builds, and what it builds becomes the trust infrastructure every shopping agent inherits.
Read closely, both documents describe a system that is being engineered to answer exactly one question, asked at exactly one point in the transaction. Is this agent authorized to move this money, at settlement time. Both are silent on a different question, asked earlier: is the thing in the cart worth buying at all.
KPMG’s Thesis: The Money Goes Around the Agents
The KPMG outlook, published as its top fintech trends for H2’26, makes a call that is easy to skim past and should not be: investment in agentic commerce will concentrate around the agents, not in them.
“As agentic commerce, the use of AI agents to shop and make transactions on behalf of individuals and companies, continues to grow, there will likely be increasing investment in ancillary activities, including cybersecurity and digital identity management in order to ensure such transactions are approved, safeguarded, and well-protected from bad actors. Payments solutions and infrastructure focused on agentic commerce will likely also attract investment.”
Three words carry the whole thesis: approved, safeguarded, protected. ETEnterpriseAI’s summary of the report adds the expected shape of the flows: cybersecurity protecting agent-led transactions from fraud, digital identity systems establishing who authorized a transaction, and payment rails purpose-built for agents.
This is how infrastructure industries mature. The application layer, the agents themselves, is being fought over by OpenAI, Google, Meta, Anthropic and every retailer with a garden. The margin opportunity KPMG is flagging for its investor clients is everything the agents stand on: identity, authorization, fraud, settlement. The pick-and-shovel trade, updated for a buyer that never sleeps.
Note what all those shovels dig around. Not one of them touches the product.
The Whitepaper’s Real Contribution: Four Stages, Honestly Counted
The Singapore whitepaper’s most useful move is refusing the binary framing that has dominated agentic commerce commentary, the idea that the world flips from “humans pay” to “agents pay” at some future date. Instead it lays out four stages:
- AI-assisted commerce. The agent researches and recommends. A human still clicks pay.
- Human-delegated commerce. The human sets rules. The agent executes within them.
- Machine-to-machine transactions. An agent buys API access, data or compute against operational triggers.
- Fully autonomous commerce. Multiple agents negotiate and settle with each other directly.
The honesty is in the counting. Almost everything that markets itself as agentic commerce today, a shopping assistant with a human approving checkout, is stage one. Visa’s Adeline Kim told the roundtable that early adoption will concentrate in transactions that are high-frequency and low-risk rather than spreading evenly across all four stages at once. Grab’s head of product for payments, Karthikeyan Janakiraman, described the actual frontier: “Current agentic payment activity spans consumer-delegated purchases and machine-to-machine payments initiated on behalf of consumers. Wider adoption will require alignment across merchants, consumers and payment rails.”
That is a much more modest picture than the conference-keynote version. And it sets up the whitepaper’s most important structural idea.
From Approving a Purchase to Authorizing an Outcome
In conventional e-commerce, a person picks the product, picks the payment method, and clicks confirm. Agentic commerce compresses that into a single instruction, in the whitepaper’s own example: “purchase the best available option within this budget.” The agent decides everything else.
That handoff only works, the roundtable participants argue, if the system can distinguish three different things: what the user meant, what the agent was authorized to do, and what the agent actually did. Authority, in this model, runs along five axes:
- Who the agent is acting for
- What it can buy
- Where it can transact
- How much it can spend
- Under what conditions that authority stays valid
This is a genuinely good framework, and it deserves to outlive the whitepaper. It is also, read carefully, a framework entirely about the wallet. Every axis constrains the money. Scoping what an agent can buy means category and merchant allowlists, not quality floors. A mandate can say “groceries, under $200, from these stores.” No standard vocabulary exists for “and nothing whose reviews fail an authenticity filter.”
StraitsX’s own product answer to the five axes is a single-use virtual card, a credential scoped to one transaction rather than access to a full card number or account balance. Elegant. It answers “how much and under what conditions” as a product feature. The question of whether the transaction it approves is for a good product is somebody else’s problem, and the whitepaper never names who.
The Orchestration Layer, and Stablecoins’ Narrow Job
The whitepaper’s infrastructure chapter describes a three-function layer sitting between an agent’s intent and the underlying rails: authorization (is this agent allowed to transact), orchestration (which mechanism fits this transaction, given cost, speed and availability), and settlement (moving the value).
Card networks, bank rails and stablecoin settlement are explicitly not competing for the same job. A consumer purchase still needs to reach a merchant through existing card or bank networks. Cross-border adds currency and liquidity considerations. Stablecoins get a deliberately modest role, defined by three properties: settlement fast enough that an agent is not left waiting mid-workflow, programmability that lets payment execution sit inside an automated flow, and suitability for the smaller, more frequent transactions that conventional payment processes handle inefficiently.
The practitioners put it plainly. Aave’s John Teo: “Agentic commerce can be viewed across three layers: authorisation, settlement and liquidity. Agents need defined mandates, the ability to choose the most efficient payment method, and access to liquidity when required.” Monad’s Edwin Lau: agents at machine speed “can benefit from onchain, where mandate, guardrails and settlement execute together instantly.” StraitsX CEO Tianwei Liu: “The next thing is the speed of settlement, which is almost instantaneous, and the ability by design to be programmable.”
Mandate, guardrails, settlement. Three functions, flawlessly executed, at machine speed. All three are indifferent to whether the purchased item works.
Runtime Guardrails: The Governance Insight Worth Keeping
The whitepaper’s governance chapter contains its sharpest thinking. When an agent acts outside its authorized intent, how should responsibility be determined across the parties to the transaction? The proposed answer separates trust into three concrete layers: agent identity and access controls that establish which agent is requesting what; runtime controls that monitor behavior during execution rather than only reviewing it afterward; and transaction-level limits on amount, category and other parameters.
Stripe’s Akhil Sadarangani compressed the whole argument into two sentences: “For an agent to act on your behalf, you need trust. For there to be trust, you need very controlled guardrails.”
And Cyber Sierra’s Pramodh Rai supplied the industry’s most honest self-assessment: “None of the existing frameworks comprehensively address the current AI environment. Either a new framework has to develop, or the existing ones will have to evolve pretty fast. Otherwise, we’re all going to be blocked in pilot environments.”
Pause on that pairing. The most pointed voice in a payments roundtable is warning that governance gaps keep agentic commerce stuck in pilots, while proposing, as the fix, identity, monitoring and limits. The governance conversation is having the right argument about the wrong boundary. It polices the agent’s fidelity to instructions. It does not police the quality of the world the instructions are executed against.
The Blind Spot Both Documents Share
Here is the uncomfortable synthesis. KPMG says the money flows to approved, safeguarded, protected transactions. The whitepaper says trust requires identity, mandates, runtime guardrails and liability assignment. Combine them and you get the next five years of agentic commerce infrastructure: verified agent identity, scoped spending authority, per-transaction credentials, runtime anomaly detection, and settlement rails that execute instantly.
Every one of those systems treats the product decision as already solved. It arrives as an input. The agent decided to buy Product X; the trust stack’s only job is to make sure the payment is authorized and the money moves.
But where did Product X come from? A model’s judgment, formed from a retrieval pass over the public commerce corpus: listings, ratings, review text. That corpus is the least defended layer in the entire stack, which is a strange state of affairs given that it is also the cheapest to attack. Amazon’s own reporting has put blocked suspected fake reviews in the hundreds of millions per year. The FTC’s fake reviews rule has carried civil penalties north of $50,000 per violation since October 2024. And as we covered when the FTC and 22 state attorneys general sued Amazon on August 31 over its ad auctions, the placement layer itself is now a subject of federal litigation over whether sponsored positioning quietly inflated what shoppers paid.
Now layer that onto the four-stage model and watch the risk compound. At stage one, the human still sees the product page, and a decade of healthy skepticism still operates. At stage two, human-delegated commerce, the human sets rules and walks away. The transaction completes on rails that are, by design, faster and better verified than anything in human commerce. What fails silently is the only judgment the human actually delegated in spirit: buy me a good one.
A perfectly authorized transaction for a mediocre or misrepresented product is not a fraud event in this architecture. No runtime control fires. No liability clause triggers. The settlement is clean. The product is junk. The system reports success.
The Missing Axis: Quality Mandates
The five axes of authority need a sixth, and unlike stablecoin plumbing it requires no new rails: a verifiable quality floor on the products an agent is allowed to consider. Call it a quality mandate. It slots precisely into the whitepaper’s own model, as another condition under which authority stays valid:
- Filter before scoring. Compute trust only after manipulated and low-information reviews are removed, from the evidence quality of what remains, rather than from seller-stated averages or raw counts, the two inputs merchandising money buys most easily.
- Score persistence, not spikes. A rating that holds after filtering across a long window separates a stable property of a product from a purchased one. GoBuy Verified requires holding a filtered score of 80 or above across 90 days.
- Curate, do not drown. A short list of verified products per category removes the placement signal entirely from the agent’s field of view, the same signal the FTC is currently litigating.
- Expose it where agents live. Any agent can query filtered trust data over MCP at gobuy.ai/api/mcp before recommending or buying, with integration docs at gobuy.ai/agent-docs.
Notice that this is the same shape as the runtime-guardrail argument, applied one layer earlier. Identity checks establish which agent is requesting what; GoBuy’s Smart Score establishes what the shelf is hiding before the request matters. Payment guardrails run during the transaction; product trust has to run before it, at retrieval time, or it runs nowhere.
What to Watch
Four signals over the next two quarters. First, whether KPMG’s predicted H2 flows actually land in digital identity and cybersecurity startups, and whether any of them scope identity past the agent to the product corpus. Second, whether anyone at stage two, the delegated-purchase deployments now rolling out at major platforms, attaches a quality condition to spending mandates, which would be the first quality mandate in production. Third, whether the liability question the whitepaper raises, who pays when an agent exceeds its mandate, ever gets asked about the quieter failure, who pays when the agent stays perfectly within its mandate and buys garbage. Fourth, the holiday quarter, where bad bots have recently approached parity with human shoppers on retail traffic and every one of those bots is reading the same review corpus your agent trusts.
The financial establishment has decided agentic commerce is real enough to fund its plumbing, and it is right. Approved, safeguarded, protected: three things every agent transaction should be. None of them makes the product good. Verify the shelf before the rails verify you: start at gobuy.ai, and wire filtered trust scoring into any agent at gobuy.ai/agent-docs.