The Missing Layer in Agentic AI
Learn how merchants can prepare for agentic commerce by verifying AI agents, securing checkout authorization, and structuring product data for LLMs.


Key takeaways
- Agentic commerce is already here. Businesses need a reliable way to distinguish trusted agents from malicious automation.
- Businesses can act now. Classify agentic traffic, secure the path to checkout, and make data machine-readable.
- "Know your agent" has four parts. Authenticate the agent (including who published it), verify the human it acts for, authorize what it can do, and keep an auditable record of what it did, so when something goes wrong, you can prove what was authorized.
- The opportunity lies at checkout. Agents increasingly drive discovery, but humans still complete most purchases.
- Trust requires enforceable authority. Consent must be specific, limited, auditable, and revocable.
AI agents are already operating at enormous scale across the internet, yet most merchants still lack a reliable way to distinguish legitimate agents acting with a user’s authority from malicious, compromised, or unauthorized automation. That uncertainty creates a foundational trust problem: before a business can decide what an agent should be allowed to do, it must first establish who or what is actually interacting with it.
Is agentic commerce hype, or is it in production? Both. People use them to narrow down options, then get linked out to the merchant to buy. Merchants report completion rates hold up when that handoff happens. Agents are changing how people shop. Humans are still closing the loop at checkout. For now.
That gap between the agent that helps you decide and the agent that's allowed to buy for you is where this gets messy. It's also where you don't have to wait for the industry to sort itself out.
Control Your Traffic
You can't decide who to trust until you know who's showing up. Classify every visitor as a guest, a known account holder, or an agent, and then go a level deeper on that last bucket: is it a legitimate agent, or an identity to watch closely?
The tools to do this were originally built for human identities. Twenty years of fraud modeling has been trained to read device fingerprints, geolocation, and behavioral tells, but AI agents don't have any of that. The old heuristics go blind exactly when the stakes go up.
That's the gap that "know your agent" is trying to fill. However, the term already gets used as a bucket for things that need to be performed as distinct actions: agent trust, authentication, verification, authorization. Who published the agent, and where did it come from, is the hard part. Large web infrastructure providers with agent-publishing tools are the closest thing to an answer right now.
An agent can't do anything by itself. It takes both the person who initiated it and the actual agent being legit, and the binding between them must be provable. It’s a three-legged race and if any of the legs is fake, the whole thing falls over.
Ultimately, if you get the "who's here" wrong, every downstream call on permissions and risk inherits that blind spot.
Secure the Path to Checkout
Humans still close most checkouts. But as agents take on more of the transaction, the question everyone's circling is: what does consent look like when a human isn't confirming every step?Closing that gap means answering the question that's actually freaking everyone out: what does consent look like when a human isn't confirming every step?
Authorizing a single, human-confirmed transaction is easy. Standing or delegated authority (e.g., permission that persists across actions the human never individually confirms) is where it gets messy. Is trust a one-time moment, or does it travel with the agent? There's no standardized way to model the semantics of intent yet, no shared format for what a user actually authorized an agent to do, and the industry hasn't figured out how to harness it.
Scope compounds this. A $12 dish soap reorder and a $1,200 flight booking shouldn't carry the same authority, but most systems today don't draw that line. Tiered authorization is a logical solution, and would entail lightweight, short-lived permissions for small purchases, something closer to full re-authentication for big ones. Nobody's cracked the UX yet. The one non-negotiable: whatever duration a permission has, it stays modifiable by the consumer, with real transparency behind it.
This matters for checkout because every extra click and hand-off back to a human is a moment you lose the sale to whoever made it easier. Winning agentic checkout means making it easy for an agent to go from comparing to completing: structured checkout APIs, agent-friendly payment flows, tiered permissions that let small purchases move fast
It needs to be built on permissioning you can defend. What happens today if a human says "I didn't authorize that"? Right now, it looks like a chargeback. Nobody's panicking yet because the volume is low. But the question of who is responsible doesn't have a clean answer, and won't until disputes stop getting resolved differently by every platform. That's an ecosystem problem, not a company one, but it's a reason to build checkout on defensible permissioning now, not later.
Make Your Data "SEO-Ready" for LLMs
Agents can only recommend what they can read. Inconsistent formatting, missing structured fields, or a UI built only for human eyes are just 3 of many ways your content or inventory gets misread or skipped, and sends the buyer somewhere else.
Think of it as SEO for a crawler that's making real purchase decisions on someone's behalf, in real time. Clean, structured, machine-readable data is how you get considered at the comparison stage, and before the human ever gets linked out.
Stack all three and they compound: an agent that identifies itself cleanly, acts within a well-scoped permission, and reads your data without friction. That creates an agent that buys from you instead of somewhere else.
Still Everyone's Problem
Nailing these three gets you ahead of the field. It doesn't solve agentic trust for the industry.
Consent standards, liability frameworks, and tiered authorization guidelines are still being established, and no single company writes them alone. Agent-to-web authentication (Web Bot Auth, HTTP message signatures), payment-network intent frameworks (Visa, Mastercard's agentic programs), and delegated authorization patterns are just a slice of what’s actively being developed across the broader ecosystem.
In tandem, big institutions want defensive mechanisms; power users are already pushing autonomous action past what today's guardrails support. Any real fix has to work for both, which means it gets built at the ecosystem level.
That's not a reason to wait. It's the reason to develop and manage the fundamentals now, so you're built to plug into whatever standard the industry lands on instead of retrofitting later.
The modern
way of proving identity
Trusted by 2500+ leading companies to reduce fraud and improve consumer


Frequently Asked Questions
The reality is that agents are already live in production for comparison shopping and search, but checkout capabilities lag behind discovery. Most completed transactions still route back through the merchant's own site rather than closing entirely inside an agent.
It's become a catch-all term, but it really breaks into three separate problems: authenticating that an agent is who it claims to be, verifying the agent publisher and provenance, and authorizing what the agent is allowed to do on a specific person's behalf.
Those models were trained on human behavioral baselines. Agents produce signals those models either misread as fraud, which hamstrings legitimate delegated traffic, or, worse, are engineered to evade. Either way, the one distinction that matters, authorized versus unauthorized automation, isn't something behavioral signals can carry.
No, and this is one of the industry's open questions. A small purchase probably warrants a lightweight, short-lived permission; a large or unusual one probably warrants something closer to full re-authentication. Tiered models are being explored, but nothing is standardized yet.
There's no consistent answer today. It typically plays out like a standard chargeback, but the outcome varies by platform because there's no shared standard for what an agent's authorization actually proves.

Keep reading
Read the article: Attackers Have Industrialized the Moment of Urgency: The Hidden Cost of OTP Nobody Talks AboutDiscover the hidden costs of SMS OTPs, from fraud and failed delivery to customer abandonment, and how passkeys and persistent authentication reduce risk.
Read the article: How to Achieve More B2B Customer Growth With Prove Pre-Fill® for BusinessProve Pre-Fill® for Business provides a comprehensive solution for organizations that want to onboard businesses by delivering faster onboarding, a decrease in abandonment, and a reduction in fraud (relative to attack rate).
Read the article: Account Takeovers: The Silent Revenue KillerAccount takeover (ATO) fraud is rapidly becoming one of the biggest threats facing digital marketplaces and gig platforms. Learn how ATO attacks work, why they are accelerating, the latest fraud trends and statistics, and how continuous identity verification helps organizations prevent account takeovers while protecting revenue, customer trust, and user experience.