
Who Approved That Buy?
Agentic commerce needs proof of intent, not just a rule that ran.
A purchasing agent can execute quickly. It cannot invent the authority behind the purchase.
An AI purchasing agent completes a $2,400 office-supply order. No person clicked buy.
The agent saw a reorder threshold, read an approved vendor list, found budget headroom, and executed a policy set three weeks earlier. On the surface, it did exactly what it was asked to do. The hard question begins after the order is placed: did the company authorize this particular purchase, from this particular seller, at this particular price, in this particular condition?
Commerce has always relied on a small but important moment of proof. A person with authority sees an item, a price, and a counterparty, then agrees. That moment is specific, current, and attributable. Agentic commerce replaces it with standing instructions and a loop. The convenience is real. So is the gap between a rule that once made sense and an action that happens later in a changed world.
The short version is simple: when an agent acts under parameters set weeks ago, every pricing error, supplier compromise, policy breach, and disputed order turns into a three-way argument among the customer, platform, and merchant. The business needs a record that shows what the human delegated, what the agent assembled, and why the action was still within scope. In 2026, the infrastructure for that record exists. The trap is continuing to operate as if it does not.
The authorization moment is missing.
A defensible purchase has three properties. It is specific, this item and price from this counterparty. It is contemporaneous, meaning the authority applies when the transaction happens rather than at an unrelated time. And it is attributable, meaning a real person or business can be connected to the decision. Delegated agents can weaken all three at once.
Consider three illustrations, not case reports. First, an agent reorders from an approved supplier for months. The supplier is breached and begins shipping counterfeits. The agent follows its parameters perfectly and keeps ordering. The customer authorized the supplier when it was trustworthy, not the supplier in its compromised state. Second, a bad price feed makes an unacceptable unit price look like a bargain. The agent burns a monthly budget cap in days, while the user, merchant, and platform each hold one part of the mistake. Third, a supply disruption makes an item unavailable. The agent keeps trying because the inventory rule still says to reorder, while the seller keeps accepting because the order still arrives.
None of those failures require a rogue model. They are ordinary commerce changes arriving after a standing instruction was created. The trail can show the logic the system ran, but a log of logic is not the same thing as current consent. That distinction becomes expensive the moment a dispute asks who had authority, who had knowledge, and who had a reason to stop the transaction.
Liability already has addresses.
The uncertainty sits inside the transaction, not outside the organization that deployed the system. The Air Canada chatbot decision remains a useful baseline: the tribunal did not allow the company to treat its own system as a separate entity responsible for promises made to a customer. A business that puts an agent into a commercial flow should expect the same basic question, what did you allow it to do and what record proves it?
The dispute can also begin from the merchant side. In Amazon's case against Perplexity, the merchant's position is that an agent shopping on behalf of users can itself be an unauthorized actor on the storefront. That is not a final answer to every agent-shopping question. It is evidence that authorization is contested in both directions. Buyers need to prove that an agent was allowed to spend. Merchants need to know that a visitor is a legitimate commercial agent rather than an unverified bot.
This is why the record cannot be a post-hoc reconstruction. An incident may involve a compromised vendor, stale permission, altered price, bad inventory signal, or policy exception. In each case, the party with the clearest evidence of scope, counterparty, transaction details, and escalation behavior is in a better position to explain its action. The party holding only a configuration screen from last quarter has a much weaker story.
Operationally, that means authorization should be treated like a living control, not a one-time checkbox. The business has to decide who can widen a cap, who can add a merchant, who can override an exception, and who receives the alert when the context changes. It also has to separate the people who set a commercial objective from the people who may release a payment. That division of responsibility is familiar in procurement. Agentic commerce makes it necessary to express it in a form a machine can enforce and a reviewer can read.
The industry built the missing piece.
The payments industry has spent the last two years restoring the proof moment that delegated buying removed. Google's Agent Payments Protocol, known as AP2, structures purchases around cryptographically signed mandates. An intent mandate records the human's instruction, such as eligible vendors, category, spend cap, and scope. A cart mandate records the specific basket an agent assembled. Together, they bind the purchase to an authorization chain that can be inspected later, instead of asking a dispute team to infer meaning from an old rule.
The same pattern appears across the ecosystem. Mastercard describes Verifiable Intent as a tamper-resistant record of what a user approved before an agent acts. Visa's Intelligent Commerce uses agent-specific payment capability tied to user controls, while its Trusted Agent Protocol is designed to help merchants recognize authorized agents instead of treating all automation as equal. The technology differs, but the commercial principle is shared: authority should survive the handoff from person to agent to merchant.
The limits matter too. Standards are not universal, integrations are still forming, and a signed record cannot rescue a category that needs human approval by law or policy. But the statement "the necessary authorization machinery does not exist" is no longer credible. It exists now, which makes the choice to run without it more visible to risk, finance, and eventually customers.
The practical design question is not which acronym wins. It is whether a company can map its own buying rules onto the chain. Can it express the scope of an instruction? Can it bind a material cart to that instruction? Can the merchant verify the entity making the request? Can a human review exceptions before a payment leaves? A platform that answers those questions cleanly gives the business a usable operating model. A platform that only promises autonomous checkout transfers the hard work to the incident review.

The point is not to make buying slower.
Good controls make the ordinary route fast and the consequential route visible. They let an agent reorder the boring, bounded work while a person reviews the price spike, unknown seller, changed compliance status, or unusual category before it becomes an irreversible commitment.
That is not a concession to weak technology. It is how a capable system earns permission to handle more of the workflow over time.
Four guardrails, now with rails.
The operating controls are familiar. The difference is that payments and verification infrastructure can now carry them across the transaction rather than leaving them in policy documents.
Scope and expiry
Set explicit vendors, categories, caps, and an end date for every standing delegation. Reconfirm material authority on a thirty, sixty, or ninety-day schedule.
Intent mandate
Decision-grade evidence
Log why the agent acted, including trigger, inputs, price, counterparty, budget state, and exception handling. Preserve the decision, not only the timestamp.
Cart mandate
Human gates on changed conditions
Pause when vendor ownership, price model, compliance status, or data integrity changes. Require a fresh decision when the facts no longer match the original instruction.
Verified agent and seller checks
Hard stops for regulated work
Keep a person at the final approval in regulated, age-gated, financial, or healthcare contexts. Documentation strengthens the process; it does not erase the requirement.
Recorded human approval
Build the evidence before volume makes it urgent.
A team can turn this into a practical launch review. First, write the bounded instruction in language a procurement owner would recognize: categories, approved merchants, spend caps, quantity limits, expiry, and escalation point. Second, decide what transaction record must exist before an order is released. Third, list the conditions that invalidate the original authorization. Fourth, test a dispute before the system handles meaningful volume. If a reviewer cannot reconstruct a purchase in minutes, the deployment is not ready to scale.
The test should use believable variation, not a perfect happy path. Substitute an unapproved seller. Raise the price just above the expected range. Let a credential expire. Change the quantity. Feed the agent an inventory record that conflicts with a vendor confirmation. Then ask the operating owner what must happen in each case. A mature design will produce a legible answer: proceed within the mandate, request a renewed mandate, route to a human, or stop. A vague design will reveal itself by falling back on the phrase that the agent followed its instructions.
This approach also gives commercial teams an advantage. Rather than treating agent traffic as a mysterious new channel, merchants can make their own authorization requirements explicit, verify trusted agents, and route unclear cases into a review path. Buyers can delegate predictable replenishment while maintaining boundaries that suppliers and finance teams understand. The point is not to eliminate every pause. It is to reserve the pauses for the moments that actually change the obligation.
The best designs make their safety visible to the reader of a receipt. A customer can see the delegated scope. A merchant can see the credential. A risk team can see the signed transaction record. And a human can still take over when the agent meets a condition that exceeds the authority it was given. That clarity is more valuable than a promise that the system will always act sensibly.
The revenue trap is a sequencing problem.
Autonomous reorders, delegated shopping, and faster checkout can create real commercial value. Gartner has forecast that machine customers could influence or participate in $30 trillion in purchases by 2030. That is a reason to learn the channel, not a reason to skip its operating foundations.
The cautionary example is not that agent buying has no demand. OpenAI's Instant Checkout launch and subsequent retailer-app shift showed that a low-friction purchase can still collide with the merchant's need to control the checkout, the customer relationship, and the authorization path. CNBC's reporting on the transition described Walmart's finding that purchases completed in chat converted less well than those routed through its own flow. Some friction was carrying information and permission that the system still needed.
Start with autonomous volume and add authorization later, and the organization can become dependent on revenue before it can explain the risk it has accepted. Start with mandates, verified agents, human gates, and decision records, and the commercial opportunity grows on a foundation that can withstand a customer complaint, vendor failure, insurance review, or audit. The difference is not speed versus caution. It is whether the record travels with the purchase.
That sequencing gives leaders a useful scorecard for the next launch. A bounded pilot can be valuable even before every protocol is available, provided that it has a named owner, limits a real category of spend, records the full decision path, and has a tested stop condition. A broad deployment without those elements is not a bolder experiment. It is a commitment whose terms will only become clear when something goes wrong. The aim is to let the company learn quickly without asking customers, merchants, or finance teams to absorb an invisible liability in the meantime.
Questions readers ask
Who is liable when an AI agent makes an unauthorized or mistaken purchase?+
An AI agent does not become the legal owner of the decision. The organization that deploys it should expect to answer for its controls and records. The Air Canada chatbot decision is a useful warning: the business remained responsible for information supplied by its system. For agentic commerce, a strong authorization record makes the dispute reviewable; a vague configuration history makes it much harder to defend.
What is an AP2 mandate?+
Google's Agent Payments Protocol uses cryptographically signed mandates to connect a human's instruction to an agent's purchase. An intent mandate records the scope of the delegation, while a cart mandate records the specific transaction assembled by the agent. Together, they create evidence that can travel with a delegated purchase.
How can a merchant tell whether a purchasing agent is legitimate?+
Merchant-side verification is now an explicit part of the emerging infrastructure. Visa's Trusted Agent Protocol is designed to help merchants distinguish authorized commercial agents from malicious automation, while agent-specific payment credentials can bind an agent's payment capability to user-defined controls. The objective is not to trust every bot, it is to know which agent has a verifiable authority chain.
Can autonomous purchasing work in regulated industries?+
It can support low-risk work, but regulated or consequential categories need clear human checkpoints where law or policy requires them. Mandates and audit trails improve documentation; they do not remove the need for a person to approve a healthcare, financial, age-gated, or otherwise regulated decision when the decision itself requires human judgment.
Should a company wait for standards to mature before using agentic commerce?+
No. The safer sequence is to use scoped, expiring delegation, decision-grade logging, event-triggered human gates, and platforms that support verifiable mandates before autonomous volume becomes material. The exposure comes from scaling on an old assumption stack, not from starting with bounded automation.

Authorization is the product feature.
If the record cannot travel with the purchase, the purchase should not travel alone.