Stripe’s president of technology and business, Will Gaybrick, went on a16z’s podcast this month and said the quiet part out loud. Checkout pages will go away. Speaking with general partner David George in an episode released August 17, 2026, Gaybrick argued that as AI agents take over commerce, payment stops being a page a human clicks through and becomes an API endpoint an agent calls on their behalf. Triggered by intent, not clicks.
The infrastructure for exactly this already exists. Stripe co-built the Agentic Commerce Protocol with OpenAI, and ACP now powers Instant Checkout inside ChatGPT. When OpenAI launched the feature, ChatGPT users in the US could buy directly from Etsy sellers, with more than a million Shopify merchants, including Glossier, Vuori, Spanx and SKIMS, lined up to follow. Stripe says any merchant already processing payments through it could enable agentic payments by changing as little as one line of code. No cart. No redirect. A prompt and a purchase.
Most coverage of the interview treated it as a UX story: friction removed, conversion improved, the funnel flattened into a sentence. That framing misses what the checkout page actually was. It was not primarily a payment form. It was the last checkpoint in e-commerce where a human being audited the transaction with their own eyes. Its disappearance is a structural event for trust, and the industry is spending billions preparing every layer of the new stack except the one that just lost its last human witness.
What the Checkout Page Actually Did
Strip away the payment fields and look at what happens behaviorally on a checkout page, or in the moments right before it.
The buyer sees the final price, with shipping and tax resolved, and checks it against their expectation. They glance at the delivery date. Many of them, a meaningful share of hundreds of millions of shoppers, scroll back up to the reviews one last time. They look for the recent ones, the three-star ones, the ones that mention the flaw the listing glossed over. They hunt for a coupon code. And they experience the small, commercially decisive moment of reconsideration: do I actually want this?
None of this is friction in the pejorative sense. It is verification, performed by the only party with skin in the game: the person about to pay. Every anti-fraud system, every verified-purchase badge, every review filter in the modern stack exists downstream of one primitive fact, which is that at checkout, a human was present and paying attention.
Gaybrick’s forecast removes that presence. In the ACP world, the sequence is: the user states intent in a chat, the agent selects a product from structured data, the agent calls a payment API. The human sees a confirmation. Depending on the flow and the merchant, they may approve it with a tap. What they almost never do is visit a page that renders the product, the price, the seller, and the review corpus together, at the last moment before money moves.
The industry’s answer to this, so far, is to verify everything about the buyer. Identity credentials for agents, signed purchase mandates, behavioral analysis of sessions. All of it answers the question: is a real human behind this purchase? Almost nothing in the new stack answers the other question, the one the checkout page used to answer for free: is this product worth buying?
The Machine Internet the Purchase Is Landing Into
To understand why this matters now, look at what the purchase environment has become while everyone was optimizing funnels.
Imperva’s 2026 Bad Bot Report, published in April, documents a threshold crossing that deserves more attention than it gets. Automated traffic accounted for more than 53 percent of all web traffic in 2025, up from 51 percent the year before, while human activity fell to 47 percent and continues declining. As the report puts it, this is not a short-term spike driven by an attack cycle; it reflects a structural change in how the internet operates. Businesses are no longer serving customers alone. They are serving machines.
Cloudflare, which sits in front of a large share of the retail web, puts automated traffic at roughly 57 percent of the requests it sees. HUMAN Security’s 2026 State of AI Traffic report found automated traffic grew eight times faster than human traffic over the past year, with retail and e-commerce absorbing more of that growth than almost any other sector.
The malicious slice is growing too. Imperva found bad bots alone made up 40 percent of internet traffic in 2025, a three-point jump year over year, and that 27 percent of bot attacks now target APIs directly, bypassing the pages humans see entirely. The report’s analysis of the shift is precise: bots increasingly interact with the same APIs that power authentication, payments, search, and inventory systems, and these interactions “often appear legitimate, with well-formed requests and successful authentication, but the difference lies in intent and scale.”
For a sense of scale, cybersecurity firm F5 examined a single PlayStation 5 restock and found automated reseller bots generated roughly 11 million add-to-cart requests in the first hour against about 88,000 from actual customers. That is not a fair fight. It is barely a fight.
Here is the synthesis that matters for this article. As payment collapses into an API call, the purchase is moving onto exactly the terrain where the machine internet’s bad actors already operate: APIs, at machine speed, with well-formed requests that look legitimate. The checkout page is dying precisely as the environment it lived in becomes majority-machine. Whatever verification the human used to perform has to be rebuilt somewhere, deliberately, or it simply stops happening.
The Identity Arms Race: Billions for the Buyer, Nothing for the Product
To be fair, the industry recognizes the machine-internet problem. It is solving half of it with genuine urgency.
The identity camp is betting on proof of humanity. World’s Concert Kit, built on the World ID credential, lets sellers reserve inventory for verified humans. Its first deployment, an April 2026 San Francisco show featuring Anderson .Paak and St. Vincent, blocked more than 100,000 automated requests while roughly 1,000 verified fans claimed tickets. World says the network now covers more than 18 million verified humans across 160 countries, and World ID has been used over 450 million times. The same credential is spreading into contracts, dating, and video calls through integrations with Docusign, Tinder, and Zoom.
The behavior camp is betting that actions speak. Cloudflare launched Precursor in mid-2026, a continuous behavioral validation engine that monitors mouse movement, timing, and navigation patterns across an entire session rather than judging once at the door. HUMAN Security scores the intent behind sessions, analyzing more than a quadrillion interactions a year to separate an agent genuinely checking out for its owner from a script pointed at a limited drop by a reseller.
Platforms are improvising in parallel. Amazon sued Perplexity in November 2025 over its Comet browser’s shopping agent, which Amazon said disguised itself as a normal browser; a preliminary injunction was granted in March 2026, and the Ninth Circuit overturned it on appeal this month, so the question of who controls agent access to retail sites is still working through the courts. eBay took the unilateral route, updating its user agreement in early 2026 to prohibit “buy-for-me agents, LLM-driven bots, or any end-to-end flow that attempts to place orders without human review” without prior approval.
Notice what every one of these systems verifies. The World ID orb confirms a human exists. Precursor confirms a session behaves like one. ACP’s signed mandates confirm the human authorized the purchase. Stripe’s Link wallets for agents, which issue one-time-use cards so an AI shopper never exposes the raw card number, confirm the money is legitimately controlled.
The entire arms race authenticates the buyer side of the transaction. Not one system in it examines the product. And the product enters the new flow carrying the same signals it carried in the old one: a star rating and a review count, signals that a marketplace mints, that review farms inflate at industrial scale, and that, as the Columbia-Yale ACES audit we covered earlier this month demonstrated, AI agents obey with machine precision. The audit found agents respond strongly to platform endorsement badges and weigh review counts and average ratings heavily, precisely the inputs cheapest to purchase in bulk.
Verified buyer, verified authorization, verified payment, unverified product. The checkout page at least let the human perform the product audit themselves. Its death hands that job to the agent, and the agent currently consults the same corrupted corpus the human was trying to scroll past.
Where Product Trust Has to Live Now: Before the API Call
If the checkout page is gone, product verification cannot live at checkout. It has to move upstream, into the agent’s decision context, in the interval between “I need a new espresso machine” and the payment call. That interval is where the next phase of e-commerce trust gets built, and it has requirements the old page never had.
- Machine-native. The trust signal has to be callable by an agent mid-reasoning, not rendered for an eye. Exposing product trust over MCP, as GoBuy does at gobuy.ai/api/mcp, means any shopping agent can query independent trust data before it executes, in the same step as price and availability.
- Quality-based, not volume-based. Agents weigh review counts heavily; review counts are the cheapest signal to buy. A score computed from review quality and authenticity, like GoBuy’s Smart Score from 0 to 100, removes the poisoned input instead of re-weighting it.
- Filtered before scored. Manipulated reviews must be removed from the corpus before any score is computed. Re-weighting polluted input still propagates the pollution.
- Sustained, not snapshot. A star rating can move with a purchased burst. A badge that requires holding 80 or above across 90 days, like GoBuy Verified, makes burst manipulation economically pointless.
- Curated, not exhaustive. Agents already collapse demand onto a few SKUs based on unstable model biases. Returning the top 7 verified products per category gives the agent fewer, cleaner inputs than ten thousand sorted listings and shrinks the attack surface for position and badge gaming.
The deeper point is architectural. In the page era, trust was a UX property: badges on a screen, read by humans, at the end of a funnel. In the intent era, trust is an API property: a signal in the agent’s context, consulted before the transactional call. Companies that built their entire trust posture on what humans see at checkout have no equivalent in a flow where the machine never loads the page. The checkout optimization industry, the A/B testers and the cart-abandonment email writers, optimized a surface that the next customer’s agent will never render. Gaybrick’s blunt version, as reported: agents don’t care how pretty your funnel looks.
The Bottom Line
The checkout page had a good twenty-year run as the place where e-commerce paused and let a human check the math. The payments industry, led by Stripe’s ACP and its siblings, Google’s AP2, Visa’s Trusted Agent Protocol, Mastercard’s Agent Pay, is now efficiently disassembling it, because a prompt-to-purchase flow is genuinely better for buyers and sellers in every way except one: it removes the last moment of human verification from the transaction.
The industry’s response has been to industrialize verification of everything except the thing being bought. Identity credentials, behavioral engines, signed mandates, and one-time cards now guarantee that a real human authorized a real agent to spend real money on a product nobody has verified. In an internet that is already 53 percent machine, where a quarter of bot attacks target APIs directly and 11 million bot add-to-carts can hit a single restock against 88,000 human ones, that is not a rounding error. That is the load-bearing gap in the entire agentic commerce buildout.
The checkout page is not coming back. Product verification has to move to where the decision now happens: inside the agent, before the call.
Trust what your agent buys, not just who authorized it. See independent product trust at gobuy.ai. Developers building shopping agents can wire the trust layer in directly at gobuy.ai/agent-docs.