Agentic Commerce & Payments for Enterprise Merchants
Published - 12 March 2026
Revised - 07 September 2026
Libby James is the founder and Managing Director of Merchant Advice Service. Since 2016, she has worked directly with businesses and payment providers across merchant accounts, card processing, payment gateways and complex provider requirements.
Libby specialises in high-risk, declined and harder-to-place merchants, as well as businesses requiring specialist payment methods, integrations or international support. She writes and reviews Merchant Advice Service content, drawing on practical experience gained from real merchant enquiries and provider relationships.
Quick Summary: Agentic commerce is moving from AI-led product discovery towards transactions in which software agents can initiate or complete purchases within defined permissions. For enterprise merchants, the immediate issue is not whether to deploy an AI shopping agent. It is whether existing payment infrastructure can recognise agent-led transactions, manage consent and authentication, support tokenised credentials, control routing and produce an auditable record of what happened.
MAS View: Agentic commerce is becoming a payment-infrastructure question before it becomes a checkout-design question. Enterprises that understand their existing payment architecture now will be better placed to adopt new agentic channels without surrendering control of payments, customer data or provider choice.
Agentic commerce describes buying journeys where artificial-intelligence agents can do more than recommend products. Depending on the model and permissions involved, an agent may search, compare, select and eventually initiate or complete a transaction on behalf of a consumer or business.
For enterprise commerce and payments teams, that changes the question from “How will AI change ecommerce?” to something much more practical:
Can our existing payment infrastructure support transactions where software becomes an active participant in the purchase?
That requires enterprises to think about payment credentials, customer consent, authentication, fraud, routing, checkout ownership, transaction data and the relationship between the merchant and its payment providers.
Agentic commerce is no longer only a theoretical payments discussion.
During 2026, card networks, payment companies, banks and commerce platforms have continued developing infrastructure designed to distinguish agent-led transactions from conventional ecommerce payments and allow agents to transact within defined permissions.
In March 2026, Santander and Mastercard announced a live end-to-end payment executed by an AI agent in a controlled European banking environment. Mastercard has subsequently expanded Agent Pay activity across Europe, while payment companies including Stripe have developed token-based infrastructure intended to allow agents to initiate payments without exposing underlying card credentials.
This does not mean every enterprise merchant needs to rebuild its checkout immediately. It does mean payments teams should start understanding which parts of their current architecture could become constraints if agent-led commerce develops into a meaningful acquisition channel.
Merchant Advice Service uses the following framework when thinking about enterprise readiness for agent-led payments:
Checkout → Credentials → Consent → Authentication → Routing → Risk → Reporting → Portability
| Area | What enterprise merchants should assess |
|---|---|
| Checkout | Can transactions be initiated through APIs or other machine-readable commerce flows without relying entirely on a human-facing checkout? |
| Credentials | How are payment credentials tokenised, stored and made available without exposing sensitive underlying payment data? |
| Consent | Can the business evidence what the customer authorised the agent to do, including any transaction, merchant or spending limits? |
| Authentication | Can the payment stack distinguish a permitted agent-led transaction from bot activity, account takeover or unauthorised automation? |
| Routing | Does the merchant retain control over PSP, acquirer and payment-method routing as new agentic channels emerge? |
| Risk | How will fraud rules, authorisation logic, disputes and transaction monitoring respond to new agent-led behaviour? |
| Reporting | Will transaction data clearly show how a payment was initiated, authenticated, routed and completed? |
| Portability | Can the business change providers or architecture later without losing critical tokens, customer relationships or payment flexibility? |
MAS View: Enterprise readiness for agentic commerce is less about choosing an AI shopping tool and more about whether the existing payment infrastructure can recognise, authenticate, control and report agent-initiated transactions without giving up merchant control.
Traditional ecommerce usually assumes that a person participates directly in product selection and checkout. The customer navigates the website, chooses a payment method and completes the required authentication.
Agentic commerce can separate those stages.
An AI agent may discover the product, evaluate different sellers, construct the basket and initiate the transaction while operating within permissions previously granted by the customer.
That creates a different payment problem.
The merchant may need to understand not only who is paying, but also:
This is why agentic commerce touches much more than the front-end customer experience.
Allowing software agents unrestricted access to underlying card credentials would create obvious security and control problems.
Tokenisation offers a different model. Payment credentials can be represented by tokens with controls around where, how or for how long they may be used.
Network and payment-provider developments increasingly point towards token-based models designed specifically for agent-led transactions.
For established businesses, the immediate question should therefore be how mature the existing tokenisation architecture already is.
Businesses should understand:
For a deeper explanation, read our guides to network tokenisation and why agentic commerce may require multi-tokenisation.
Agentic transactions create an important distinction between customer identity and transaction execution.
The customer may still own the account and payment credential, but software could be taking the action that causes the purchase to occur.
Enterprise merchants therefore need to consider how the payment environment will establish:
This is not simply a technical question. It can affect fraud, customer service, disputes, chargebacks and the evidence available to payment providers.
Enterprise merchants already monitor payment authorisation performance closely. Agent-led transactions could introduce additional data, credentials and authentication patterns into that environment.
If issuers, networks, gateways or fraud systems cannot confidently understand a transaction, legitimate purchases may be declined alongside fraudulent ones.
This makes transaction recognition and good-quality payment data strategically important.
Enterprises preparing for agent-led commerce should understand how their existing provider handles authentication, tokenisation, fraud signals and issuer-facing transaction data, alongside the wider techniques discussed in our guide to improving enterprise payment authorisation rates.
Agentic commerce should not automatically require a business to move to multiple PSPs or introduce an orchestration platform.
However, businesses should be cautious about building a new commerce channel that makes them more dependent on a single payment route.
If agent-led transactions develop differently across payment networks, wallets, PSPs, acquirers and markets, larger merchants may need the ability to route transactions based on factors including geography, payment method, risk, cost and performance.
A flexible payment orchestration layer can help enterprises retain more control over that decision-making.
The strategic objective is not complexity for its own sake.
It is avoiding an architecture that becomes expensive or disruptive to change later.
Enterprise merchants do not necessarily need to change payment providers because agentic commerce is developing.
They should, however, understand their provider's roadmap.
Useful questions include:
The answers are particularly important for businesses making long-term decisions about gateways, APIs, token vaults or ecommerce architecture today.
The strongest reason to review payment infrastructure is not the arrival of a particular AI product. It is discovering that the existing architecture has become difficult to adapt.
Potential warning signs include:
These issues may already affect ordinary ecommerce today. Agentic commerce simply gives enterprise merchants another reason to identify them before they become more expensive to solve.
Businesses considering a significant change to their payment architecture may also find our guides to payment API integration and changing payment provider with a custom API useful.
Some of the earliest commercially useful agentic-payment models are likely to be environments where the rules of the transaction can be clearly defined.
An agent could identify approved suppliers, compare pricing and reorder products within procurement policies, spending limits and predefined commercial rules.
Agents could search travel inventory, compare options and make bookings within corporate travel policies or customer instructions.
Agent-led systems could monitor usage and initiate permitted purchases or replenishment transactions where clear consent and billing rules exist. Businesses operating recurring models should also consider the wider issues covered in our subscription payment processing guide.
Agentic commerce may become particularly relevant to marketplaces because agents could compare multiple sellers, products, delivery conditions and payment options within one buying journey. Marketplace operators still need to consider the underlying questions around seller onboarding, payment flows and payouts covered in our marketplace payment gateway guide.
Longer term, agent-led commerce may extend beyond consumer shopping into software or connected systems purchasing services or resources programmatically within defined rules.
The opportunity comes with risks that extend beyond conventional ecommerce fraud.
| Risk | Enterprise consideration |
|---|---|
| Unauthorised agent action | Can the merchant evidence what the customer allowed the agent to do? |
| Agent impersonation | How will legitimate agents be distinguished from malicious automated traffic? |
| Payment disputes | What evidence will explain the customer's intent and the agent's action? |
| Credential exposure | Can tokenisation prevent agents from accessing unrestricted payment credentials? |
| Checkout disintermediation | How much control does the merchant retain if discovery and checkout move outside its website? |
| Provider dependency | Does adopting an agentic-payment model make future PSP migration harder? |
| Data fragmentation | Can transactions still be reconciled and analysed across different commerce channels? |
Most businesses do not need to launch an agentic checkout simply because the technology exists.
They do need to understand whether decisions being made about payment infrastructure today will leave them flexible enough to support new commerce channels tomorrow.
A practical readiness review should include:
Not necessarily.
Changing provider purely because agentic commerce is developing could create unnecessary cost and implementation work.
The better starting point is to understand whether the existing provider and payment architecture can support the direction the business expects to travel.
A provider review becomes more relevant where agentic commerce exposes wider limitations such as poor API flexibility, restricted token portability, limited routing control, weak international support or an infrastructure roadmap that no longer fits the merchant.
For larger merchants, any comparison should therefore look beyond headline transaction pricing.
The provider needs to fit the commercial model, payment architecture, integrations, geographic requirements, risk profile and future technology strategy of the business.
Agentic commerce is unlikely to replace conventional ecommerce overnight. But it is creating a new transaction model that enterprise payment teams can no longer treat purely as an AI experiment.
The most important preparation is not choosing the latest agentic platform.
It is making sure the underlying payment environment remains adaptable.
Tokenisation, consent, authentication, routing, fraud controls, APIs, reporting and provider portability are the foundations that will determine how easily an enterprise can participate as the market develops.
Businesses with flexible payment infrastructure will have more choice about when and how they adopt agent-led commerce. Businesses locked into brittle payment architectures may discover that the biggest obstacle is not artificial intelligence at all — it is their existing payment stack.
Merchant Advice Service provides independent information and guidance about merchant accounts, payment gateways and payment-provider selection. We are not a payment processor, acquirer or card scheme.
MAS may receive a commission or referral fee from some payment providers where a business proceeds following an introduction. This does not determine the educational content, frameworks or provider-selection principles used in this guide.
Agentic-commerce technology, card-network standards and payment-provider capabilities are developing quickly. Businesses should confirm current functionality, geographic availability, commercial terms and technical requirements directly with the relevant provider before making infrastructure decisions.
Written or reviewed by Libby James, founder of Merchant Advice Service and specialist in merchant payments and complex provider requirements.