For thirty years digital commerce has assumed a human at the keyboard. That assumption is breaking. When Google announced its Agent Payments Protocol in September 2025, it framed the problem plainly: "While today's payment systems generally assume a human is directly clicking 'buy' on a trusted surface, the rise of autonomous agents and their ability to initiate a payment breaks this fundamental assumption."2
The economic stakes are large. One forecast estimates that agentic commerce could orchestrate as much as $1 trillion of US retail revenue by 2030 and $3-5 trillion globally, with agents handling around 18% of US business-to-consumer spend in its moderate scenario1. Consumers expect the shift too: in Global Payments' research across seven countries, respondents expected AI agents to make 15% of their purchases within five years, up from 9% a year earlier5.
The rails are being laid
Three developments define the emerging infrastructure. First, open protocols: AP2 launched with more than 60 organisations, including networks, wallets and processors, and represents each purchase as a chain of cryptographically signed mandates, an Intent Mandate capturing what the user asked for and a Cart Mandate recording exactly what was approved, to create a "non-repudiable audit trail"2. Second, network services: Visa launched Intelligent Commerce Connect in April 2026, a single integration for agent-initiated payments supporting four agent protocols with tokenisation, spend controls and authentication4. Third, tokenised credentials bound to a specific agent, merchant scope and consent policy, so the agent never holds the underlying card number.
Three questions every agent payment must answer
How AP2 frames the problem, and what it means for banks
| Question | AP2 definition | Implication for the bank |
|---|---|---|
| Authorisation | Proving that a user gave an agent the specific authority to make a particular purchase | Issue and verify mandates; link them to strong customer authentication |
| Authenticity | Enabling a merchant to be sure that an agent's request accurately reflects the user's true intent | Validate the agent's identity and the integrity of the cart |
| Accountability | Determining accountability if a fraudulent or incorrect transaction occurs | Redesign disputes, chargebacks and liability allocation |
Note: Definitions quoted from Google Cloud's AP2 announcement; implications are SCIKIQ analysis.
Source: Google Cloud, “Announcing Agent Payments Protocol (AP2)” (2025)
Trust is the bottleneck, and banks' opportunity
Consumers are experimenting faster than they are delegating. Visa's inaugural agentic commerce Trust Index, based on 2,065 US consumers, found that 72% had used an AI assistant but only 23% trusted generative AI to execute payment transactions independently3. Trust rose sharply with guardrails and brands: 39% would trust AI-initiated payments with an override capability, and 61% would trust Visa specifically to manage agentic transactions3. Global Payments' research found that 50% of consumers were concerned about payment security and a third wanted to approve each transaction5.
The trust ladder
US consumers' attitudes to AI in payments, 2026 (%)
“Trust will be foundational to driving agentic commerce adoption, much like it was for e-commerce and mobile payments.” — Oliver Jenkyn, Group President, Visa
Comfort is climbing quickly for low-risk purchases. Between the two waves of Global Payments' research, the share comfortable letting AI buy cinema tickets rose from 32% to 82%, meal delivery from 30% to 78% and subscriptions from 27% to 69%5. Delegation will spread category by category, starting where the downside of a mistake is small.
The threat to the balance sheet
Agentic commerce is not only a payments story. The same agents that compare prices will compare interest rates. Published analysis estimates that consumer use of AI agents could reduce global banking profit pools by about $170 billion, or 9%, if banks do not adapt, as agents sweep idle balances out of the roughly $23 trillion held in near-zero-rate checking accounts6. EY found that 14% of consumers have already allowed AI to select a financial provider for them7. When a machine is choosing, loyalty built on inertia evaporates.
Corporate and SME banking will feel it first
Much of the commentary focuses on consumers buying trainers or groceries, but the larger and faster shift may be in business banking. In business purchasing, agentic commerce implies procurement agents negotiating, ordering and paying on behalf of companies, and treasury agents moving liquidity between accounts and providers to optimise yield and cost. For transaction banks, this means payment initiation, cash positioning and supply-chain finance will increasingly be consumed programmatically, by software that compares providers continuously. Banks whose cash-management products are only accessible through portals and file uploads risk being bypassed by those that expose rich, real-time APIs.
Being the customer's agent, not just the agent's bank
There is also an offensive play. EY found that 21% of consumers already use AI agents for financial product recommendations and 11% are prepared to let AI manage their finances with minimal human input7. A bank-provided agent that monitors bills, moves surplus cash, flags better deals and executes within limits the customer sets would turn the deposit-flight threat into a retention tool. It would also sit inside a regulated perimeter with established complaint, redress and data-protection obligations, a point of difference against unregulated third-party agents. The bank that becomes the customer's trusted agent keeps the relationship even when commerce happens elsewhere.
Four decisions for bank leaders
- Authentication. Extend strong customer authentication to agent mandates: know which agent is acting, for whom, under what limits, and verify the mandate at each step.
- Liability. Work with networks and regulators on how disputes and chargebacks apply when an agent misreads intent or is manipulated, and price the risk.
- APIs. Expose products (payments, balances, credit, savings) through secure, well-documented APIs that agents can consume, with consent and policy enforced in the bank's own infrastructure.
- Brand. Be the trusted credential and the trusted agent. Consumers already say named financial brands make them more comfortable; banks should make that trust machine-readable.