Agentic commerce is the next evolution of online shopping, where AI agents not only recommend products but also actively handle buying tasks on a user’s behalf.
These systems can research options, compare prices, evaluate reviews, make decisions based on preferences and budgets, complete purchases, track orders, and even optimize future buying decisions over time.
Unlike traditional e-commerce, where humans manually manage every step, agentic commerce uses autonomous AI to execute multi-step workflows with defined goals and permissions, creating a more personalized, efficient, and proactive shopping experience.
Where Is the Human?
The agentic commerce conversation is moving at extraordinary speed, but it is skipping the question that matters most: Who is actually behind the agent?
I do not mean which model, app, orchestration layer, or wallet. I mean, which verified human being is authorizing the action, accepting the consequences, and setting the limits?
Without that root, the rest of the architecture is a very elegant way to automate ambiguity. Unfortunately, there are many bad actors hiding behind autonomous agents, while the system treats the agent as if it were enough.
It is not enough.
That concern is no longer theoretical. As Steven Smith, Head of Protocol at Tools for Humanity, notes, “As agents become more capable and more human-like, they’re harder to distinguish from real people. The result is confusion, ambiguity, and risk across the digital economy.”
Delegation Cannot Become Disappearance
In ordinary digital commerce, there is clear human intent and a human (for the most part). You tap. You click. You approve. But in agentic commerce, that visible moment gets abstracted away.
The user sets instructions, the agent interprets them, and the transaction may happen later, elsewhere, and at machine speed. That is precisely why identity becomes more important, not less. If the human vanishes at the moment of execution, then fraud, repudiation, and abuse all become easier to scale.
Think about the obvious edge cases.
A sanctioned individual deploys an agent.
A fraudster uses synthetic identity material and lets an agent do the shopping, probing, or laundering.
A stolen account seeds a cloud of autonomous actions before the real user even knows what happened.
And when the mess surfaces, everyone points somewhere else. The user says it was not them, the merchant says the payment looked valid, the platform says the agent followed instructions, and the issuer is left sorting out intent after the fact.
Every Agent Needs a Verified Human Root
My view is that an AI agent operating in commerce needs to be tied back to a verified human in a way that is portable, privacy-preserving, and enforceable. Not a loose email association, not a device cookie, and not a platform-local account assertion, but a genuine trust credential bound to the person who stands behind the delegation.
That credential should be able to answer the minimum necessary questions without exposing the person’s entire identity file:
- Is this person verified?
- Are they cleared for this category of action?
- What spending or risk boundaries have they authorized?
That is where a reusable trust token becomes so powerful. It gives the ecosystem a human anchor without requiring every merchant, wallet provider, and agent platform to become a raw-data collector. It also protects the user from the false choice between privacy and safety. With selective disclosure, we can prove the facts needed for the transaction without spraying underlying documents across the internet.
That is a better security architecture and a better civil architecture at the same time.
The Winning Systems Will Treat Identity as Infrastructure
The winners in agentic commerce will not be the ones who move money fastest in a vacuum. They will be the ones who can prove, at scale, that an authorized human stands behind an action and that the action stayed within defined limits.
That requires identity to become infrastructure, not an afterthought bolted onto checkout. It also requires a neutral trust layer, so this proof is reusable across contexts rather than reinvented app by app.
I am optimistic because the path is visible now. The standards conversation has begun, and the industry understands that agent-initiated actions require clearer delegation and stronger evidence of authorization. But we should not confuse recognition with resolution.
The invisible gap in the AI economy persists. And until the agent is tethered to a verified human root, the market will remain vulnerable to exactly the kinds of abuse that could destroy trust before the category matures.