Two numbers published inside the same 48 hours frame the entire agentic commerce market better than any product launch this year. The first: consumers now expect AI agents to make 15 percent of their purchases within five years, up from 9 percent when the same question was asked a year earlier. The second: at John Lewis, the British department store chain, searches originating from AI agents have risen from 0.3 percent to 2.5 percent of site search in twelve months, a near-ninefold increase that the retailer describes as accelerating. One is a forecast of where the basket is going. The other is a measurement of where the shelf already is.

Both arrived this week. The first comes from Global Payments’ Annual Agentic Commerce Report, released September 23, which surveyed roughly 8,000 consumers across the US, UK, France, Brazil, China, Singapore and Australia in August-September 2025 and 8,027 across the same markets in May 2026, giving the market something rare: a true year-over-year read on attitudes rather than a single snapshot dressed up as a trend. The second comes from Reuters reporting on the same week’s bank warnings, where John Lewis disclosed its agent-traffic figures as evidence that this is no longer speculative.

But buried under the doubling-comfort headlines is the number that should actually structure every product roadmap in this space. Consumers will let agents buy. They will not yet let agents buy anything expensive. And the reason they give for the ceiling, when you read the safeguard data closely, is not a payment problem at all.

What the report actually measured

Provenance matters in this genre, because agentic commerce surveys have become a growth industry of their own. This one has a defensible design: two waves, fielded by the specialist research agency The Lantern, in partnership with Global Payments, across seven markets on five continents, with consistent sampling between waves so the year-over-year deltas mean something.

The headline findings:

  • Consumers expect AI agents to make 15 percent of their purchases within five years, up from 9 percent a year ago.
  • 45 percent of Americans have already used, or would consider using, an AI shopping agent.
  • 69 percent use AI to find better deals when shopping; 63 percent rely on it to save time.

Cindy Turner, chief product officer at Global Payments, put the shift in one sentence: “Just a year ago, the idea of letting AI actually buy something for you still felt futuristic. Today, consumers are increasingly willing to hand over everyday purchases if it saves time, finds better value and keeps them in control.”

The phrase worth underlining is keeps them in control. Control is doing more work in that sentence than it appears to, and the rest of the report explains why.

Comfort is doubling, from the bottom of the basket

The most quoted section of the report shows comfort with agent-executed spending under $50 more than doubling year over year across everyday categories:

  • Cinema tickets: 32 percent to 82 percent
  • Meal delivery or pickup: 30 percent to 78 percent
  • Meal vouchers and gift cards: 28 percent to 77 percent
  • Subscriptions and memberships: 27 percent to 69 percent

A year ago, roughly seven in ten consumers were uncomfortable letting an agent buy a movie ticket. Today, more than eight in ten are fine with it. That is not gradual warming; that is a regime change in low-stakes purchasing, accomplished in twelve months.

Look at what these categories have in common, though. A bad outcome costs $50 and ruins an evening. The worst case is bounded, immediately visible, and cheap to correct. Consumers are not extending trust to agents in the abstract. They are extending it precisely as fast as the cost of being wrong stays small, knowable and quickly discovered. Trust in agentic commerce is being built from the bottom of the basket upward, purchase by purchase, and every category graduates only after its failure modes have been personally rehearsed.

The $100 ceiling is the real headline

Now the section fewer people will quote. For retail purchases, majorities of Americans are comfortable with agents transacting on their behalf, but with explicit limits:

  • 69 percent would let an agent spend up to $100 on groceries and everyday essentials
  • 69 percent would cap it at $100 on clothing and footwear
  • 64 percent would allow up to $100 on luxury clothing and footwear
  • 58 percent would cap electronics and gadgets at $100

Sit with the shape of that data. These are not exotic purchases. Groceries are the most habitual, lowest-risk, highest-frequency category in consumer life, and even there, the comfort zone tops out at $100, which is roughly one large cart at a US supermarket. Electronics, the category where review manipulation is most industrialized and a wrong purchase is most expensive to discover, draws the lowest ceiling of all.

The pattern is too consistent to be an artifact. Consumers are pricing the downside of agent error, category by category, and setting the cap where the pain of a wrong purchase starts to exceed the convenience of an autonomous one. The $100 ceiling is a rational market price for unverified product decisions. It is the aggregate answer to a question consumers were never directly asked: how much are you willing to lose to a choice you did not personally examine?

That question has a second answer hiding in the trust data. The concerns that survive the enthusiasm are payment security (50 percent), privacy and data use (46 percent), and the agent making the wrong purchasing decision (42 percent). Payment security dominates the headlines, but it is also the concern the industry is furthest along in solving: tokenization, virtual cards, per-transaction authorization and agent-scoped credentials are all shipping. The wrong-purchase concern, at 42 percent, is the one nobody has shipped an answer for, because its cause is not in the payment rail. It is in the evidence the agent consumed before the rail was ever invoked.

The safeguards consumers want, read carefully

When the survey asks what would make consumers comfortable, the answers rank like this:

  • 33 percent want to approve every transaction before payment
  • 28 percent want access to human support when issues arise
  • 26 percent want proof that AI systems cannot be hacked or manipulated

The first two are classical controls: approval gates and recourse. They slow autonomy down and give it a human escape hatch, and the emerging protocol stack is already building them, which we will get to.

The third is different in kind. “Proof that AI systems cannot be hacked or manipulated” is not a friction control. It is an integrity demand. And notice what it does not say: it does not say proof the payment cannot be hacked. Consumers, having lived through two decades of e-commerce, have largely internalized that the payment itself is defensible. What they have not internalized is that the choice can be attacked, because for most of e-commerce history the choice was theirs to make and the attack surface was their own skepticism.

Agents change that. An agent’s purchase decision is only as honest as the inputs it reads, and on a modern marketplace the dominant input is the review corpus: star ratings, review counts, review text. That corpus is precisely the layer that Amazon’s own enforcement reporting says requires blocking hundreds of millions of suspected fake reviews per year, the layer where incentivized and machine-written reviews concentrate on exactly the high-margin, high-competition product pages an agent will be steered toward. Manipulating a human shopper costs a fake review farm one impression per shopper. Manipulating an agent ecosystem that routes 15 percent of purchases costs the same farm one corrupted corpus, amortized across every agent that reads it. The attack surface did not shrink when shopping went agentic. It consolidated.

So the 26 percent are asking for something the payment chain structurally cannot give them. A perfectly secure checkout produces a perfectly authorized purchase of a perfectly misreviewed product. Payment security certifies the transfer of money. It certifies nothing about the quality of the information that decided where the money goes.

The rest of the stack arrived this month

To be fair to the industry, September 2026 will likely be remembered as the month the trust infrastructure for agentic commerce got assembled in public. Three pieces landed within days of each other, and together they cover most of the transaction lifecycle.

The first: six banks, including Bank of America, Capital One, ING and NatWest, published their joint principles paper on September 22, proposing an auditable record from customer instruction to payment outcome, and warning that agents face “risks spanning transparency, safety, privacy & data, choice, and interoperability” that grow “as greater autonomy is given to AI agents.” As we wrote yesterday, the audit trail is the right skeleton, but it certifies the plumbing, not the product.

The second: the Legal Context Protocol, launched in June by the American Arbitration Association and Integra Ledger with Google, IBM, Circle, Wayfair and UiPath among the founding contributors. It solves a problem nobody thought about until agents started buying things: what terms did the agent actually agree to? Merchants publish terms at a fixed address, agents cryptographically prove which version they saw, and a hash of the terms travels with the payment record. Its “buyer policy” construct is the most interesting part: a machine-readable declaration of spending caps, acceptable jurisdictions, accepted dispute bodies, and the commitment level above which a human must review before the agent signs. AAA CEO Bridget McCormack’s framing: “The agentic economy needs that same capacity delivered at machine speed.”

The third is quieter and more consequential: Target updated its terms of service in March so that once a customer authorizes an agent, any selection the agent makes is treated as the customer’s own. Budget approval is being converted into blanket consent, one merchant at a time. If the agent picks the wrong product, that is now legally your wrong product.

Put the three together and the gap becomes visible by elimination. Instruction and authorization: covered by the banks’ audit trail. Terms and dispute recourse: covered by the Legal Context Protocol. Liability: being reassigned to the consumer in fine print. Payment: tokenized, virtual-carded, and approval-gated. Product quality: unassigned. No protocol currently in production answers the question “was the product the agent chose actually any good, and was the evidence it relied on authentic?” The stack has been built from the payment backward, and it stops exactly at the point of decision.

Why the ceiling lifts one category at a time

Here is the analytical payoff of reading the Global Payments numbers as a system rather than a headline. The categories where comfort doubled fastest, cinema tickets and meal delivery, share two properties: the worst case is cheap, and the product quality signal is immediate and personal. You know within two hours whether the agent ordered the right dinner. The categories stuck behind a $100 ceiling, groceries in aggregate and especially electronics, are the ones where product quality is hard to verify personally and the evidence layer, reviews, is the most contaminated.

The implication is that the $100 ceiling is not a fixed cultural constant. It is a function of verification availability. Where consumers can verify outcomes cheaply, they delegate. Where they cannot, they cap. Raise the verifiability of the purchase decision itself, with independent, pre-vetted product evidence, and the ceiling has room to move. Leave the decision resting on raw marketplace review corpora, and the ceiling holds no matter how good the models get, because the models are not the thing consumers distrust. The evidence is.

That is the design problem this publication exists to work on. GoBuy filters manipulated and low-information reviews before anything is scored, computes Smart Score from 0 to 100 on the quality of the review evidence that survives, curates the top seven verified products per category rather than an infinite sponsored shelf, and requires a score of 80 or above sustained for 90 days before a product carries the GoBuy Verified badge. All of it is delivered over MCP at gobuy.ai/api/mcp, which means an agent can consult independent product evidence at decision time, and that consultation becomes a timestamped event in the very audit trail the banks just proposed. For humans who still do their own clicking, the Chrome extension puts the trust panel directly on the Amazon product page, before checkout rather than after regret.

In protocol terms: the Legal Context Protocol’s buyer policy has fields for spending caps and jurisdictions. It has no field for review-integrity thresholds. The first agent platform that adds one, “only purchase products whose evidence survives independent filtering,” converts the 26 percent’s demand for proof of incorruptibility from a survey answer into a shipping feature.

What to watch

  1. Whether the 15 percent expectation keeps its slope. A 9-to-15 jump in one year is a 67 percent increase in expected delegation. If wave three in 2027 shows the same slope, the five-year number lands early. If it flattens, the trust ceiling is binding harder than the adoption curve.
  2. The first agent policy with an evidence threshold. Watch buyer policies and agent terms-of-service for the first machine-readable “verified products only” constraint. That is the moment product trust becomes protocol.
  3. John Lewis at the next quarterly mark. Agent-originated search going from 0.3 to 2.5 percent in a year is the demand signal merchants cannot ignore. When it crosses 5 percent, retailer incentives to game agent-readable signals cross a threshold too.
  4. Bloomberg Intelligence’s trajectory. Its forecast has roughly $500 billion, about 20 percent of online commerce, running through agents by 2030, up from under 5 percent today, with another 6.2 percent fully autonomous. Every point of that curve is also a point on the review-manipulation opportunity curve, and they will move together.

The consumer has already priced the risk: fifteen percent of the basket, one hundred dollars at a time. The unbuilt layer is the one that lets them pay for trust instead of paying for caution. Independent product evidence, checked before the purchase instead of audited after the dispute, is how the ceiling rises.

Check what your agent is about to buy, before it buys it, at gobuy.ai. And if you build agents, give them evidence they can prove: gobuy.ai/agent-docs.