At the Goldman Sachs Communacopia + Technology Conference on September 8, Visa CEO Ryan McInerney compressed the entire state of agentic commerce into one sentence: “We are seeing adoption for shopping, but not yet for autonomous payments.” Pressed on the barrier, he offered a single word. “The barrier to that, if I had to describe it in one word, would be trust.”

He is right, and the numbers behind him are blunt. Three quarters of consumers Visa surveyed do not trust agentic platforms to make autonomous payments with their money and financial information. Sixty-one percent said they would trust an agent to pay if Visa were involved, a figure that tops 70 percent among people who use large language models at least weekly, per PYMNTS’ coverage of the remarks.

The next day, September 9, Mastercard launched Agent Connect, a single-integration fabric for connecting merchants, AI agents, digital platforms and payment providers around “trusted, user-authorized transactions.” Visa is spending $2.4 billion to acquire BioCatch and push fraud prevention upstream to identity, because, in McInerney’s words, “identity has become a critical area of vulnerability.”

The payments industry has diagnosed the disease correctly. It has also prescribed its favorite medicine: credentials, tokens, delegation and authorization rails. All of that armor protects the same thirty seconds of the shopping journey, the checkout. What it does not touch is the hour before checkout, where the agent decides which two or three products you will be choosing between. And the consumer data published this same week shows that when people say they do not trust AI shopping, most of them are talking about that hour, not those thirty seconds.

There are two trust gaps in agentic commerce. The first is transactional: is this really the agent my customer authorized, and is the money safe. The second is epistemic: is what the agent knows about products true. The first gap is being closed by the most capitalized institutions on earth. The second, the one that decides what actually gets bought, has no incumbent, no standard and no auditor.

The Migration Is Real, and It Is Finally Measured

Start with the demand side, because this week it stopped being anecdotal. PYMNTS Intelligence now counts 49.6 million US adults who begin retail product research with AI, including 39 million who have stopped relying primarily on the traditional search channel where they once started. Adobe Analytics, reported by Reuters, measured 41 percent of US shoppers using generative AI for online shopping in June 2026. Shopware has observed 15 times more traffic arriving at online stores from AI tools in the first quarter of 2026 than in the same stretch of 2025. In Europe, McKinsey finds 63 percent of shoppers already use AI tools to compare brands and prices before buying. Morgan Stanley puts the endpoint at $190 billion to $385 billion of US e-commerce spending through AI assistants by 2030.

The migration also changes what gets bought, which is the fact most coverage underweights. Among AI-assisted purchasers in the PYMNTS data, 43 percent found a better price, 27 percent chose a different brand and 26 percent bought a different product than they otherwise would have. AI recommendations introduced 10.8 million consumers to a retailer they had never used and moved 15.9 million toward a different brand. Consumers who followed AI to a new retailer spent an average of $1,430 on AI-assisted purchases over three months, against $931 for typical AI retail researchers, and those who made an unplanned AI-influenced purchase averaged $1,564.

When a channel reliably changes the seller, the brand, the product and the price, it is no longer a channel. It is the decision maker. Which makes the integrity of its inputs a first-order consumer protection question, not a search engine optimization topic.

Humans Keep the Buy Button, for Now

The delegation numbers draw the frontier precisely. Per PYMNTS, 48 percent of online shoppers used AI to research their most recent purchase, and 56 percent would allow an agent to search and compare products. But only 37 percent would allow one to authorize payments, and 35 percent would give one access to saved payment methods. Among consumers already interested in agentic AI, 49 percent would delegate both routine and larger research-driven purchases, and among users of dedicated AI platforms, 58 percent actually prefer checkout to happen inside the AI environment.

So the buy button is migrating, slowly, and toward whoever solves trust at the moment of payment. That is the race Visa and Mastercard are running, and it explains a week of announcements. It does not explain what happens before the button, because that is not the race either network is in.

What Consumers Actually Mean When They Say Trust

Here is the detail in the fine print of the industry’s own research. Visa’s Earning Trust work finds nearly nine in ten shoppers want transparency into how an agent makes decisions, about half would stop using an agent if they lost control over it, and 85 percent want control over the data it can access. Consumer Reports argues that agents should serve shoppers rather than advertisers and should disclose conflicts of interest that could shape recommendations.

Read those findings carefully. They are not primarily about credentials, tokens or biometrics. They are about the recommendation itself: how was it formed, whose interests shaped it, what did it read. A shopper who asks “do I trust this agent with my card” is asking a transactional question. A shopper who asks “do I trust this agent’s claim that this is the best air fryer” is asking an epistemic one, and the second question is the one nine in ten of them are asking.

The legal system has noticed the shape of the problem but not the substance. Baker McKenzie’s guidance observes that US law still has few cases explicitly addressing AI agents, leaving open who is responsible when an agent-mediated purchase goes wrong. Note the phrasing everyone defaults to: when a purchase goes wrong. A recommendation that was quietly rigged, then completed flawlessly, never goes wrong in the legal sense. It just succeeds on your behalf.

The Point of No Return Has Moved Upstream

The most important structural number in this whole debate comes from Acosta Group, whose president of Connected Commerce, John Carroll, calls AI tools “the new gatekeepers of the shopper journey.” His firm finds shoppers working with an agent may see only two or three options, where a digital shelf displays more than twenty five.

That is the whole game in one statistic. INSEAD researchers Nathan Furr and Andrew Shipilov have documented that people using AI are less likely to search for a specific brand and more likely to ask for the best product for a need. So the shopper’s decision is effectively complete at the moment the shortlist is printed. Everything after that, the comparison the human glances at, the checkout the network armors, is execution of a decision that was already made by whatever fed the ranking.

This is why armoring checkout while leaving the shortlist unverified is a category error. Corruption at the shortlist stage purchases the outcome. Corruption at the checkout stage merely steals the payment. The payments industry is building vault doors for a building whose front gate is open.

What the Shortlist Is Made Of

Follow an agent’s product knowledge to its sources and you find the same contaminated aquifer every time: star ratings, review counts, review volumes and AI-generated review summaries, plus bestseller badges and sponsored placements, the full anatomy we walked in yesterday’s look at the house-referee problem on Amazon.

The contamination is documented by the platforms themselves. Amazon’s own trust accounting says it proactively blocked more than 275 million suspected fake reviews in 2024. Pangram’s detector analysis of 30,000 front-page Amazon reviews found 3 percent now AI-generated, after the FTC’s rule made fake AI reviews expressly illegal. The FTC’s August consumer alert on brushing scams shows the supply side still manufacturing verified-looking purchase histories.

Now watch what the new infrastructure does with that aquifer. Mastercard’s expanded Agent Suite makes “merchant-defined information, including product details, pricing, availability and fulfillment options” accessible to agents, with merchants retaining “control over how that information is used, represented and acted upon.” BCG says retailers need product information that is factual and machine-readable. Both are correct, and both describe legibility, not verification. A merchant-defined feed is the seller’s own claim, laundered into an agent’s context with a network’s logo on the pipe. The agent reads it as ground truth because nothing in the stack is built to do otherwise.

Even the merchants are telling you where the boundary sits. In PYMNTS’ merchant research, 46 percent said pricing and the final price paid are the functions they are least willing to let agents handle, and nearly half put autonomous checkout, multi-merchant bundling or dispute management in the “later or never” category. Thirty-one percent plan to invest within a year in automated product search and comparison, against 26 percent for checkout. Everyone is converging on the discovery layer first, because that is where the money is being made right now, and it is exactly the layer running on unverified review data.

The Asymmetry, Stated Plainly

Transactional trust has an entire institutional apparatus behind it: card networks with zero-liability regimes, chargebacks, tokenization, a $2.4 billion identity-acquisition pipeline, and now dedicated agent rails from two networks plus the OpenAI-Stripe Agentic Commerce Protocol. When a fraudulent transaction happens, machinery exists to detect and reverse it.

Epistemic trust has none of that. When a manipulated review corpus steers an agent to recommend an inferior product, no chargeback reverses the decision. No token flags it. No dispute process exists, because no purchase rule was broken. The victim does not even know they are a victim, which is the defining property of the attack: it is invisible at checkout by construction, as we saw when OpenAI pulled back its standalone Instant Checkout experience, because the industry keeps rediscovering that consumers will not delegate the buy button to a system whose judgment they cannot inspect.

Visa itself made the argument this week without noticing: McInerney said clients now want fraud prevention to move upstream, addressing identity risk before it becomes a fraudulent transaction. Agreed. Trust in agentic commerce needs to move upstream one step further than that, past the agent’s identity, to the product knowledge the agent acts on. Identity tells the merchant who is calling. Nothing currently tells the shopper, or the agent, whether the call’s contents deserve belief.

What Closing the Second Gap Looks Like

The requirements fall out of the data. Consumers want transparency into how decisions are formed, so the inputs must be inspectable. Agents need machine-native access, so the layer must speak their protocols. And because review spam is the cheapest attack surface, the filter must run before the score, not after. That is the layer GoBuy operates:

  • Filter before scoring. Smart Score runs 0 to 100 on review quality and authenticity, computed only after manipulated and low-information reviews are removed, so purchased rating volume stops being an input to what agents and humans trust.
  • Curation over firehose. Top seven verified products per category instead of thousands of ranked listings, which removes the placement auction and the twenty-five-option shelf from the agent’s discovery path.
  • Persistence as the test. The GoBuy Verified badge requires holding a filtered score of 80 or above for 90 days, separating stable product quality from a purchased window engineered around a shopping event.
  • Machine-native delivery. Agents query the filtered trust layer over MCP at gobuy.ai/api/mcp before recommending or assembling any cart, and the Chrome extension injects the same trust panel directly onto Amazon product pages, so the human inspecting the shortlist sees the same evidence the agent saw.

A shortlist assembled that way is auditable in exactly the sense Visa’s nine-in-ten respondents are asking for: you can see what was removed, what was weighted and what held its score over time.

What to Watch

Four signals over the next two quarters. First, whether Visa’s and Mastercard’s agentic trust frameworks grow any product-data verification beyond merchant-defined feeds, or whether verification remains permanently someone else’s problem. Second, whether Consumer Reports’ disclosure standard for agent conflicts becomes policy, a rule, or stays a position paper while conversational placements stay invisible. Third, the first systematic study measuring agent recommendation bias against contaminated review corpora, which will put a number on what this piece could only describe. Fourth, the crossover: 58 percent of dedicated AI platform users already prefer in-environment checkout, and when that preference meets usable agent rails, purchases will complete inside AI surfaces faster than anyone audits what those surfaces recommend.

The money will be safe. The question is whether the decision will be sound. Verify the shortlist before you, or anything acting for you, buy: gobuy.ai, with agent integration docs at gobuy.ai/agent-docs.