The Missing Layer in Agentic AI
Learn how merchants can prepare for agentic commerce by verifying AI agents, securing checkout authorization, and structuring product data for LLMs.


Key takeaways
- Agentic commerce is already here. Businesses need a reliable way to distinguish trusted agents from malicious automation.
- Businesses can act now. Classify agentic traffic, secure the path to checkout, and make data machine-readable.
- "Know your agent" has four parts. Authenticate the agent (including who published it), verify the human it acts for, authorize what it can do, and keep an auditable record of what it did, so when something goes wrong, you can prove what was authorized.
- The opportunity lies at checkout. Agents increasingly drive discovery, but humans still complete most purchases.
- Trust requires enforceable authority. Consent must be specific, limited, auditable, and revocable.
AI agents are already operating at enormous scale across the internet, yet most merchants still lack a reliable way to distinguish legitimate agents acting with a user’s authority from malicious, compromised, or unauthorized automation. That uncertainty creates a foundational trust problem: before a business can decide what an agent should be allowed to do, it must first establish who or what is actually interacting with it.
Is agentic commerce hype, or is it in production? Both. People use them to narrow down options, then get linked out to the merchant to buy. Merchants report completion rates hold up when that handoff happens. Agents are changing how people shop. Humans are still closing the loop at checkout. For now.
That gap between the agent that helps you decide and the agent that's allowed to buy for you is where this gets messy. It's also where you don't have to wait for the industry to sort itself out.
Control Your Traffic
You can't decide who to trust until you know who's showing up. Classify every visitor as a guest, a known account holder, or an agent, and then go a level deeper on that last bucket: is it a legitimate agent, or an identity to watch closely?
The tools to do this were originally built for human identities. Twenty years of fraud modeling has been trained to read device fingerprints, geolocation, and behavioral tells, but AI agents don't have any of that. The old heuristics go blind exactly when the stakes go up.
That's the gap that "know your agent" is trying to fill. However, the term already gets used as a bucket for things that need to be performed as distinct actions: agent trust, authentication, verification, authorization. Who published the agent, and where did it come from, is the hard part. Large web infrastructure providers with agent-publishing tools are the closest thing to an answer right now.
An agent can't do anything by itself. It takes both the person who initiated it and the actual agent being legit, and the binding between them must be provable. It’s a three-legged race and if any of the legs is fake, the whole thing falls over.
Ultimately, if you get the "who's here" wrong, every downstream call on permissions and risk inherits that blind spot.
Secure the Path to Checkout
Humans still close most checkouts. But as agents take on more of the transaction, the question everyone's circling is: what does consent look like when a human isn't confirming every step?Closing that gap means answering the question that's actually freaking everyone out: what does consent look like when a human isn't confirming every step?
Authorizing a single, human-confirmed transaction is easy. Standing or delegated authority (e.g., permission that persists across actions the human never individually confirms) is where it gets messy. Is trust a one-time moment, or does it travel with the agent? There's no standardized way to model the semantics of intent yet, no shared format for what a user actually authorized an agent to do, and the industry hasn't figured out how to harness it.
Scope compounds this. A $12 dish soap reorder and a $1,200 flight booking shouldn't carry the same authority, but most systems today don't draw that line. Tiered authorization is a logical solution, and would entail lightweight, short-lived permissions for small purchases, something closer to full re-authentication for big ones. Nobody's cracked the UX yet. The one non-negotiable: whatever duration a permission has, it stays modifiable by the consumer, with real transparency behind it.
This matters for checkout because every extra click and hand-off back to a human is a moment you lose the sale to whoever made it easier. Winning agentic checkout means making it easy for an agent to go from comparing to completing: structured checkout APIs, agent-friendly payment flows, tiered permissions that let small purchases move fast
It needs to be built on permissioning you can defend. What happens today if a human says "I didn't authorize that"? Right now, it looks like a chargeback. Nobody's panicking yet because the volume is low. But the question of who is responsible doesn't have a clean answer, and won't until disputes stop getting resolved differently by every platform. That's an ecosystem problem, not a company one, but it's a reason to build checkout on defensible permissioning now, not later.
Make Your Data "SEO-Ready" for LLMs
Agents can only recommend what they can read. Inconsistent formatting, missing structured fields, or a UI built only for human eyes are just 3 of many ways your content or inventory gets misread or skipped, and sends the buyer somewhere else.
Think of it as SEO for a crawler that's making real purchase decisions on someone's behalf, in real time. Clean, structured, machine-readable data is how you get considered at the comparison stage, and before the human ever gets linked out.
Stack all three and they compound: an agent that identifies itself cleanly, acts within a well-scoped permission, and reads your data without friction. That creates an agent that buys from you instead of somewhere else.
Still Everyone's Problem
Nailing these three gets you ahead of the field. It doesn't solve agentic trust for the industry.
Consent standards, liability frameworks, and tiered authorization guidelines are still being established, and no single company writes them alone. Agent-to-web authentication (Web Bot Auth, HTTP message signatures), payment-network intent frameworks (Visa, Mastercard's agentic programs), and delegated authorization patterns are just a slice of what’s actively being developed across the broader ecosystem.
In tandem, big institutions want defensive mechanisms; power users are already pushing autonomous action past what today's guardrails support. Any real fix has to work for both, which means it gets built at the ecosystem level.
That's not a reason to wait. It's the reason to develop and manage the fundamentals now, so you're built to plug into whatever standard the industry lands on instead of retrofitting later.
The modern
way of proving identity
Trusted by 2,000+ leading companies to reduce fraud and improve consumer


Frequently Asked Questions
The reality is that agents are already live in production for comparison shopping and search, but checkout capabilities lag behind discovery. Most completed transactions still route back through the merchant's own site rather than closing entirely inside an agent.
It's become a catch-all term, but it really breaks into three separate problems: authenticating that an agent is who it claims to be, verifying the agent publisher and provenance, and authorizing what the agent is allowed to do on a specific person's behalf.
Those models were trained on human behavioral baselines. Agents produce signals those models either misread as fraud, which hamstrings legitimate delegated traffic, or, worse, are engineered to evade. Either way, the one distinction that matters, authorized versus unauthorized automation, isn't something behavioral signals can carry.
No, and this is one of the industry's open questions. A small purchase probably warrants a lightweight, short-lived permission; a large or unusual one probably warrants something closer to full re-authentication. Tiered models are being explored, but nothing is standardized yet.
There's no consistent answer today. It typically plays out like a standard chargeback, but the outcome varies by platform because there's no shared standard for what an agent's authorization actually proves.

Keep reading
Read the article: Trust at Marketplace Speed: Why Authentication Is Becoming Persistent InfrastructureLearn why marketplace authentication must extend beyond login. Explore how persistent identity, cryptographic possession, and risk-based authentication can help marketplaces prevent account takeover, reduce friction, and maintain trust across the customer lifecycle.
Read the article: Beyond the OTP: What’s Driving the Next Generation of Authentication in Online GamingLearn why online gaming authentication is moving beyond passwords, SMS OTPs, and traditional MFA toward continuous, risk-based trust. Explore how persistent identity, cryptographic possession, device and network intelligence, and adaptive authentication can help gaming operators reduce fraud while creating a more seamless player experience.
Read the article: Stop Account Takeover Fraud Without Slowing Down Real Customers in the Contact CenterLearn how Prove for Amazon Connect helps banks and insurers prevent account takeover, authenticate callers, reduce handle time, and improve customer experience.