The strangest detail in last week’s biggest agentic commerce announcement is easy to skim past. On August 18, 2026, the stablecoin payments infrastructure company Rain launched the Agentic Payments Alliance, and the founding member list includes both Visa and Mastercard. Not one network migrating toward the other’s approach. Both of them, at the same table, alongside Fiserv, Circle, Solana, Remitly, Fireblocks, Chainalysis, Shift4, Sardine, Lithic, Uniswap Labs, and roughly fifteen more, twenty-six organizations in total by the release’s own count.
Card networks spend their existence competing on acceptance, routing, and interchange. When they jointly join a pre-standards coalition on agent payments, the signaling is louder than the press release. The industry has decided that AI agents executing purchases is a when, not an if. Visa CEO Ryan McInerney said exactly that on an earnings call, in nearly those words: “Agentic commerce is a when, not an if,” adding that “this will happen, and it will be a positive tailwind for Visa.”
What nobody at the table is standardizing is the thing the agents will actually buy. Walk the whole stack, layer by layer, and a pattern emerges: eighteen months of furious, genuine protocol-building around the transaction, and a decision layer that still consumes seller-reported star ratings with no independent verification anywhere in the loop. The rails are being jointly governed. The cargo is unverified.
The Demand Side Stopped Being Theoretical
The standardization sprint is not speculative architecture. The traffic is already here, and Adobe’s measurement of it is the best dataset in the industry, built on direct observation of more than one trillion visits to US retail sites.
Between July 2024 and February 2025, Adobe recorded a 1,200 percent increase in traffic to US retail sites from generative AI sources. Then the 2025 holiday season arrived and the curve held. Adobe Analytics measured AI-driven retail traffic up 693.4 percent year over year in November and December, the largest jump of any industry. Travel rose 539 percent, financial services 266 percent, tech and software 120 percent, media and entertainment 92 percent. Retail led every sector, all year: 769 percent growth in November, 673 percent in December.
The part that converts budgets into board approval is what happens after the click. Adobe found that AI referrals converted 31 percent better than other traffic sources during the holidays, nearly double the prior year’s gap. Revenue per visit from AI traffic was up 254 percent year over year. On Thanksgiving, AI-referred shoppers converted 54 percent more than everyone else; on Black Friday, 38 percent more. These visitors spent 45 percent more time on site, viewed 13 percent more pages, and were 33 percent less likely to bounce.
And they trust the channel. In Adobe’s companion survey of more than 1,000 US consumers, 81 percent of shoppers using AI assistants said the tools improved their shopping experience. Sixty-five percent said AI made them more confident in their purchase. Sixty-eight percent said they were less likely to return a product after using AI to buy it, and overall holiday returns fell 1.2 percent year over year.
Read that last pair together, because it is the quiet headline of the whole dataset. Consumers are becoming more confident and less likely to return purchases specifically because an AI system endorsed the choice. The endorsement is only as good as the product data the model consumed. Which brings us to the stack.
Eighteen Months, Five Protocols, One Direction
Map every major agentic commerce infrastructure effort of the past year and a half and it sorts cleanly into layers. The compression is remarkable: payments interoperability took card networks decades of litigation and consortium politics. The agent versions took quarters.
Context and tool access. Anthropic’s Model Context Protocol became the de facto way agents reach external systems mid-reasoning, and every serious commerce agent now lives or dies by its tool layer. MCP is openly specified, multi-vendor, and machine-native by construction.
Payments and checkout. Stripe and OpenAI co-built the Agentic Commerce Protocol, which now powers Instant Checkout inside ChatGPT across Etsy sellers and more than a million Shopify merchants. Google shipped the Agent Payments Protocol, AP2, with early partners including Coinbase, Stripe, and Telus. Visa launched its Trusted Agent Protocol and Mastercard launched Agent Pay. Each specifies how an agent discovers an offer, obtains authorization, and executes payment, with signed mandates and scoped credentials replacing the checkout page.
Agent identity and authorization. Proof-of-humanity credentials like World ID, behavioral validation engines like Cloudflare’s Precursor, and scoped payment credentials like Rain’s Agent Control Layer and Scoped Cards, which give agents card credentials that are deliberately limited in what they can spend and where. Rain, notably, is a principal member of both Visa and Mastercard, issuing cards accepted at more than 175 million merchant locations across 200-plus countries and territories.
Industry alignment. And now the Agentic Payments Alliance, which is the layer above the protocols: a working coalition to test standards for agent identity and authorization, share fraud research, and coordinate on regulatory questions before, in Rain CEO Farooq Malik’s words, “those decisions get made in isolation.”
Four layers, each with a genuinely multi-party standard or coalition taking shape. Now find the layer where the agent decides which product to buy.
The One Layer Nobody Convened
The decision layer does have one universal, machine-readable, seemingly trust-related standard. It is schema.org’s Product type, the structured markup that publishers embed so search engines and AI systems can ingest product data cleanly. And its only trust-bearing field is aggregateRating, defined by the spec itself, verbatim, as “the overall rating, based on a collection of reviews or ratings, of the item.”
Sit with what that sentence actually specifies. The rating is computed by the entity publishing the markup, from a review corpus that entity hosts and moderates, with no external verification, no authenticity filtering, and no provenance. The single machine-readable trust signal that the entire discovery ecosystem ingests is a self-reported number from the party with the strongest financial interest in the number being high.
This is not an abstract concern. It is the documented mechanism of the fake review economy: the FTC has spent the past two years running rulemaking and enforcement actions against review manipulation, and review farms now generate five-star corpora at industrial scale using open-weight models. The Columbia-Yale ACES audit we covered this month demonstrated the downstream effect precisely: AI agents weigh review counts and average ratings heavily and respond strongly to platform endorsement badges. In other words, the fields agents obey most are exactly the fields that schema.org leaves self-reported: aggregateRating, reviewCount, and whatever “Best Seller” badge the marketplace injects.
The result is an asymmetry you can state in one sentence. To move money, an agent needs a signed mandate, a scoped credential, an identity check, and a fraud-scored session, all governed by multi-party standards. To recommend the product the money buys, it needs one unaudited floating-point number written by the seller.
Why Payments Standardized First
The ordering is not an accident, and understanding it explains why the gap will not close on its own.
Money is fungible and liability is assignable. Card networks spent fifty years building exactly the machinery this transition needs: interchange rules, chargeback logic, dispute resolution, fraud scoring, and the legal frameworks underneath them. Extending that machinery to agent-initiated transactions is hard but tractable, and the economic incentive is concentrated: whoever owns the agent rails owns a toll position on every machine-executed purchase. That is why four competing protocol families shipped in a year and why twenty-six organizations, including two archrivals, joined a single coalition within months. The prize is enormous and the players are few enough to fit in one room.
Product truth has the opposite economics. It is not fungible: verifying a hedge trimmer’s review corpus shares nothing with verifying a vitamin’s. Liability for a bad recommendation currently lands nowhere, since the agent platform, the marketplace, and the seller all point at each other. The incentive is diffuse across millions of merchants and billions of products. And the party best positioned to publish trust signals, the marketplace, is precisely the party whose ad business benefits from sponsored answers.
Mastercard’s own framing, from Sherri Haymond, executive vice president and global head of Digital Commercialization, accidentally describes the hole: the risk in a moment like this is not that the industry moves too slowly, she said, but “that innovation outpaces alignment.” That is exactly what has happened to the decision layer. The innovation arrived: agents already compare products, weigh reviews, and execute purchases. The alignment did not. There is no coalition for product truth, no protocol for review authenticity, no schema field for independent verification. There is just aggregateRating, minted by the seller.
McKinsey’s projection, the figure the Alliance itself cites, puts agentic commerce at $3 trillion to $5 trillion globally by 2030. At that scale, the self-reported star rating stops being a cosmetic weakness and becomes the single point of failure for the entire machine-purchase economy. Every protocol above it verifies identity, authorization, and payment integrity, then the agent picks the SKU using a number nobody checks.
What a Product Trust Standard Would Require
If the industry ever convenes the missing layer, the requirements fall out of everything above. They are also, not coincidentally, the design constraints we built GoBuy against:
- Independence. The signal cannot be minted by the seller or the marketplace. It has to come from a third party with no position in the ranking. This is the same structural insight that made credit ratings and audited financials possible, applied to products.
- Filter before scoring. Manipulated reviews must be removed from the corpus before any score is computed, because re-weighting polluted input still propagates the pollution. GoBuy’s Smart Score, 0 to 100, is computed from review quality and authenticity after fakes are filtered out, not from raw review volume, precisely because volume is the cheapest thing in the ecosystem to purchase.
- Temporally sustained verification. A snapshot rating can be bought in a burst. A badge that requires holding 80 or above across 90 days, like GoBuy Verified, makes burst manipulation economically pointless regardless of timing.
- Machine-native delivery. A trust signal for agents cannot live in rendered pixels. It has to be callable mid-reasoning, in the same context window as price and availability. That is why GoBuy exposes product trust over MCP at gobuy.ai/api/mcp: any shopping agent can query filtered trust data for a product before executing the transaction, and developers can wire it in directly at gobuy.ai/agent-docs.
- Curation over exhaustiveness. An agent consulting ten thousand sorted listings inherits ten thousand attack surfaces. Returning only the top seven verified products per category gives the decision layer fewer, cleaner inputs and shrinks the space where badge and position gaming operates.
None of this requires a standards body to bless it, which is the practical point. MCP made tool access interoperable bottoms-up, through adoption rather than committee. Product trust will standardize the same way: agents start querying an independent trust layer, developers integrate it, and eventually a machine-checkable trust score next to aggregateRating looks less like a nice-to-have and more like the missing field it always was.
The Bottom Line
The Agentic Payments Alliance deserves credit for what it is: twenty-six companies, including the two most powerful networks in money movement, agreeing to align agent commerce infrastructure in the open instead of fragmenting it. Visa’s CEO is right that this is a when, not an if. Adobe’s data says the when has already started, with AI traffic growing at hundreds of percent per year and converting better than every human channel.
But note what the alliance’s own scope confirms. Its work is agent authorization, fraud detection, loyalty, and regulatory advocacy. Product verification does not appear. Neither does it appear in ACP, AP2, TAP, or Agent Pay. The industry has built a beautifully standardized pipeline that verifies the buyer, the mandate, the card, and the session, and then lets the agent choose the product using a number the seller wrote about itself.
Three to five trillion dollars of machine-executed commerce will flow through that pipeline by the end of the decade. The trust standard for what gets bought does not exist yet. We are building it.
Before your agent spends your money, ask what it knows about what it’s buying. See independent product trust at gobuy.ai. Developers building shopping agents can wire the trust layer in at gobuy.ai/agent-docs.