The financial establishment finally showed up to agentic commerce this month, and it arrived carrying documents instead of rulebooks. In the space of two weeks, two separate coalitions of the world’s largest payment institutions published their answers to the same underlying question: what should happen when autonomous software starts spending human money. One answer is a set of voluntary principles. The other is a how-to guide with survey data attached. Neither one is a liability regime, and the market can tell the difference: the clearest checkout-level measurement we have says AI agents are involved in just 3% of merchant transactions.
That number, from Checkout.com’s Agentic Commerce 2026 report, is not a technology problem. The rails are built. Stripe made every hosted checkout page agent-ready, covering more than 7.8 million businesses. Shopify switched agent checkout on by default for eligible merchants. Meta’s Muse shops through Stripe Link at more than a million businesses. The 3% is what happens when execution infrastructure outruns responsibility infrastructure. This month’s announcements from the banking world acknowledge that gap. They do not close it.
What the six banks actually published, and what they left out
On September 22, 2026, NatWest, Bank of America, ING, Capital One, Commonwealth Bank of Australia and ASB Bank jointly published “Building Trust in Agentic Commerce”, the first coordinated attempt by financial institutions to define how autonomous agents should behave when spending money on behalf of humans.
The paper outlines five principles:
- Transparency: agents should disclose when they are acting autonomously
- Safety: transactions should carry appropriate authentication and authorization
- Privacy and data protection: agents should handle consumer data responsibly
- Consumer choice: consumers should be able to control and override agent behavior
- Interoperability: agent systems should work across platforms
As Forkast’s analysis put it, the principles “read as sensible and vague in equal measure.” Bank of America’s head of digital payments described the guardrails as “a framework for responsible innovation.” NatWest’s chief digital officer called them “a starting point for industry collaboration.” Both are diplomatic framings for a document that establishes no compliance requirements, no enforcement mechanisms, and no penalties for non-adherence.
Read the five principles again and notice the missing sixth: accountability. There is no requirement that an agent’s purchase decision be logged, reconstructable, or auditable after the fact. No requirement that the evidence the agent consulted at the moment of choice be preserved. The paper is the institutional acknowledgment that agentic commerce exists. It is not the architecture that makes it safe.
The Amex playbook: education, plus the industry’s only real risk-transfer commitment
Three days before the six-bank story spread, on October 6, American Express released the Amex Business Playbook for Agentic Commerce, a free merchant guide covering how to get found and recommended by AI, how to make AI-driven transactions work, and how to stay trusted “when AI narrows the choices.” Alongside it, Amex is standing up a pilot Merchant AI Advisory Council, and its new Trendex survey of 502 US business leaders (conducted by Teneo, August 10-18) quantifies the readiness gap:
- 83% of surveyed businesses view agentic commerce as an opportunity
- 64% say the pace of AI innovation is difficult to keep up with
- Only 41% are actively experimenting with or implementing it
- 86% expect to need at least moderate support from payment providers to prepare
- 62% expect agent shopping to have a moderate or significant impact within a year
Anna Marrs, Amex’s Group President of Global Merchant & Network Services, did not undersell the moment: “We believe agentic commerce could be the most significant change in shopping and purchasing behavior since the start of e-commerce.”
But the more consequential Amex announcement is older. In April 2026, alongside the ACE Developer Kit, the network announced Amex Agent Purchase Protection™, an industry-first intention to protect eligible Card Members and Merchants from charges related to errors by registered AI agents. It remains the only direct attempt by any network to address agent-error liability, and its conditions are a map of everything still unfinished: the agent must be registered, the Card Member’s purchase intent must be authenticated, and the “Cart Context” technical specifications that would let Amex see what the agent actually ordered are still under development.
Translation: the one network offering to underwrite the agent’s mistake can only do it for agents it can identify, acting on intent it can verify, in carts it can inspect. Risk transfer without observability is a blank check no risk officer will sign.
The 93% question nobody wants to answer
The reason all of this matters is a single statistic from PYMNTS Intelligence’s September 2026 research, drawn from a survey of more than 2,000 US consumers and 60 merchants: 93% of merchants believe the AI or agent provider should bear the financial loss when an agent makes an incorrect purchase. Two companion numbers sharpen it: 80% expect providers to verify an agent’s authority before transacting, and only 28% are willing to offer agents their full product range on current terms.
The AI providers have not volunteered to eat those losses. Neither have the banks, in their voluntary principles. Neither have the card networks: Visa’s TAP and Mastercard’s Agent Pay give merchants the signaling to know an agent is transacting, but as Forkast’s liability-gap analysis documents, neither protocol re-allocates liability for non-fraudulent errors, and EMVCo’s draft agentic payments framework from September 2026 leaves the liability question explicitly unresolved.
So the loss sits where gravity puts it: on the merchant, by default. The chargeback system was designed to adjudicate disputes between humans and merchants. There is no clean reason code for “agent error,” no way to distinguish a generative model’s misunderstanding from a cardholder-authorized purchase. The Electronic Fund Transfer Act and Regulation E were written for human-initiated transactions; whether granting an agent access to payment credentials even constitutes valid consumer authorization remains legally unresolved, with the CFPB and the Federal Reserve so far silent.
Federal Reserve Governor Christopher Waller came closest to naming the problem in his September 29 Sibos speech: “The biggest barrier to scaling agentic commerce, particularly the agent-delegated model, is building sufficient trust among buyers and sellers.” His careful framing, “market participants broadly agree that agentic commerce is in an early phase, but it could significantly reshape commerce and payments if adoption scales,” carries the same conditional twice: if adoption scales. Adoption scales when someone prices the risk.
The trust gap is a stakes gap, and it is about products, not payments
The consumer numbers tell you exactly where the ceiling is. Amex’s Trendex survey of 2,005 US adults found 66% are likely to use an AI agent to research the best price and 61% for product recommendations in the next twelve months. But comfort collapses at the exact moment the product gets expensive: 52% would let an agent buy everyday low-cost items like groceries; only 15% would let one buy high-value items like electronics and appliances.
Forrester’s Consumer Pulse data points the same direction, with only 24% of US online adults saying they trust AI agents to make routine purchases on their behalf. PYMNTS counts roughly 132 million American adults using AI to help with retail purchases, while 59% of those AI-assisted purchases still end on Amazon. People let the agent do the reading. Then they go press buy themselves, at the checkout they already trust. As Lindsay Walker of Hedera’s AI Studio told The AI Conference in San Francisco: “Agentic commerce is not a reality yet.” What exists is agent-assisted shopping.
Here is the part the payment industry’s framing misses. Consumers are not worried about the money mechanics of an agent purchase. A mischarged card is refundable; the rails handle that. What they fear at $800 and not at $8 is buying the wrong thing: the product that arrives not as described, the listing whose four-point-eight stars were purchased rather than earned. The 52-to-15 collapse is a product-trust measurement wearing a payment survey’s clothes.
Why liability and product truth are the same problem
Follow any future agent-error dispute to its adjudication and you hit the same wall: to assign blame, someone has to reconstruct what the agent saw when it decided. Today that trail ends at the listing’s star rating. If the rating was manufactured, what looks like an agent error was actually merchant-side manipulation executed through an agent, and no network rule currently distinguishes those two cases. The 93% consensus that providers should pay assumes you can tell an honest mistake from induced error. You cannot, without an evidence snapshot.
This is why “Cart Context” is the most strategically important unfinished spec in payments. Amex cannot underwrite what it cannot inspect. And once carts carry context, the natural next question is what evidence the agent consulted: which reviews, from which corpus, verified how, at what score, under which decision policy. Decision provenance is the input every liability regime will eventually require, and almost nobody is generating it today.
The cheaper move is upstream. Every error prevented before checkout is a dispute that never needs adjudicating, which is why verification is the silent prerequisite for the risk-transfer economy everyone says they want. An agent that consults a trust layer before purchasing: review authenticity filtered, seller history checked, price stability confirmed, a Smart Score 0-100 anchored to the quality of evidence rather than the quantity of stars, is an agent whose error rate drops into the range where underwriting it becomes affordable. GoBuy’s MCP server exists at gobuy.ai/api/mcp precisely so agents can run that check as a step before checkout, and every response carries its own audit trail: score provenance, evidence snapshot, pillar sub-scores. That is the accountability layer the six-bank principles skipped, delivered as infrastructure.
It is also how the 15% number moves. High-value purchases are exactly where review manipulation pays best for bad sellers and where verified product quality pays best for good ones. A GoBuy Verified badge, earned by products scoring 80+ sustained over 90 days, is the kind of durable signal that makes an $800 delegated purchase feel like an $8 one.
What a real liability regime will need
Whenever the voluntary principles harden into rules, the regime that emerges will require most of the following, and every item is buildable today:
- Agent registration: cryptographic identity for the acting agent, the direction Visa TAP, Mastercard’s Agent Pay scoring, and the personal agent protocol have started
- Authenticated intent: proof the human authorized this purchase class, not just this session
- Cart context: machine-readable record of what was ordered, against what listing state
- Decision provenance: which evidence the agent consulted, at what scores, from what snapshot
- Agent-error reason codes: so chargeback infrastructure can distinguish delegation failure from fraud
- A pre-purchase verification step: because the cheapest dispute is the one that never becomes a transaction
The first three are payments-industry work. The fourth and sixth belong to the trust layer, and they are where GoBuy has positioned itself: not as another checkout rail, but as the evidence standard the rails will need when they start assigning blame.
The pragmatic read
For merchants: the six-bank principles and the Amex playbook are worth reading as previews of the compliance questions coming in 2027, and the 28%-willing-to-expose-full-catalog number means the merchants who solve agent-verifiability early will get disproportionate access to the delegated-purchase channel as it opens.
For agent builders: your liability story is your evidence story. An agent that can show its work, and that consults independent verification before committing a user’s money, is an agent a network can register, a merchant can admit, and a user can trust with the $800 basket.
For everyone else: watch the reason codes. The day a card network ships a standardized “agent error” reason code is the day the liability gap stops being a negotiating position and starts being a product feature. Until then, the agent will keep doing the research, the human will keep pressing buy, and the 3% will move slowly for a reason nobody’s playbook disputes.
GoBuy is the trust layer before the buy: fake reviews filtered out, authentic reviews weighted up, and a Smart Score 0-100 built on review quality, seller history, and price stability. If you’re building a shopping agent, integrate the GoBuy MCP server and give it the evidence trail, and the liability story, that regulators and networks are about to start demanding. Start at gobuy.ai or read the agent docs.