Let me start with what agentic commerce actually is, because a lot of the coverage skips straight to the hype. You give an AI agent permission to buy on your behalf, it searches catalogs that have been made discoverable to agents, it finds what you asked for, and it completes the purchase, with no one clicking buy.
There are two protocols in play. OpenAI built the Agentic Commerce Protocol, or ACP, which is open source and covers how you start a purchase and how your catalog becomes searchable to agents. Google has the Universal Commerce Protocol, UCP. The big difference is loyalty. UCP builds it in, and Google already knows who the buyer is, because when you use Google you are almost always a logged-in user.
On ACP, unless the retailer has you signed into their app, they have no idea who you are. In my opinion UCP wins that one, and it is not close. Shopify have gone even further and turned their storefronts into agentic-ready checkouts by default.
Here is the part that gets merchants’ attention: today, taking part costs nothing. The promise is a new, lower-cost acquisition channel. Agent-to-agent, near instant, no extra staffing, just systems talking to systems. If it takes off, that is worth being ready for, which is why merchants, mostly in the US, are quietly getting ready in case it does.
So that is the trend. Now let me tell you why we are not rushing.
Agentic commerce: The skeptic’s argument
Over the course of my career in payments I have learned to be wary of anything the whole industry agrees is inevitable. On agentic commerce, there are still two problems that no protocol will fix.
The first is trust. Consumers do not trust an agent to hold their payment credentials yet. That is not a bug you patch in the next release. It is a human thing, and it does not move on a product roadmap.
The second is the bigger one: there is no consumer use case that is clearly better than what we already do. For an agent to be worth it, it has to be diametrically better than the thing you do today. The two examples everyone reaches for are grocery and travel, and neither really holds up.
Take groceries. You do one shop, online or in the store. What is the agent adding? Permission to press the reorder button for you every month? You can set up a recurring order yourself, and the second your preferences change (“not that, this instead”), you are describing an assistant, not commerce.
Travel is the same. You might tell Claude or Gemini or ChatGPT: “Find me a 5-star hotel in Dublin, has a gym, close to everything, on my loyalty program”. The thing is, I can also do that in the Marriott app in about 30 seconds. Loosen the brief and let an agent scan the whole web, and what comes back is mostly online-travel-agency listings. I would still check Booking.com and my own loyalty program myself, because I do not fully trust that I am being shown the best price.
Where agents add value
Where AI genuinely earns its place is discoverability: helping me find options, build an itinerary, compare. That is a good complement to search - but it’s still not quite a reason to hand over my card at the point of purchase.
If this feels familiar, it should. An analogy I’ll give is open banking. In Europe, open banking was meant to be the thing that finally challenged Visa and Mastercard, and it never did. That’s because the benefit landed almost entirely with merchants and there was nothing much in it for the consumer, so the incentives never lined up. Open banking has found a few niches where a merchant can insist on it, like paying rent, or an airline nudging you toward a bank transfer to dodge the card surcharge on an expensive flight. It’s useful in those edge cases, but also never how the world actually pays.
It’s worth noticing who is making the most noise on agentic payments: payments companies, AI companies, and a handful of retailers.
They are loud because they all benefit if this takes off, which does not make them wrong. It just means the one question that actually matters keeps getting skipped, which is what the consumer gets out of it while trust and legitimate use cases are both missing.
It’s why a lot of merchants and providers look at agentic commerce and still say: “let’s wait and see”.
Why merchants should still be agentic commerce-ready, and how to prepare
This is the part where I change my tune, because when it comes to agentic commerce, there is one piece that merchants should take seriously today - whatever one makes of the rest. That piece is tokenization.
Tokenization has been a part of online payments for almost as long as people have been buying things online. The basic principle is that you want to be able to store sensitive payment data while keeping it safe (or tokenized). For a long time, tokenization was managed largely through PSPs. In recent years, one of the biggest trends in payments has been the movement towards independent Token Vault providers which give merchants more flexibility and control.
Agentic commerce now adds another interesting layer.
If you want an agent to buy something for you, you have to give it permission. Scoped, restricted, time-limited permission.That permission lives in a token. But it is not the token you already know.
Traditional tokenization protects sensitive card data. It swaps the card number, the PAN, for a token so you are not holding PCI-sensitive data. The actor is a human shopper or a merchant with card-on-file, and the goal is breach prevention. The token is static and reusable.
Agentic tokenization is a different game. What you are tokenizing is no longer just the card. It is the payment data, the user’s intent, the mandate, the agent’s identity, and a set of delegated permissions: a spend cap, an expiry date, the merchant category codes the agent is allowed to use, and what it can actually buy. The same agent carries constantly changing rules depending on what you have authorized. It means that the token is no longer just protecting a number; it is carrying delegated authority and executing on its own inside the parameters you set. So its job grows from PCI compliance and breach prevention to autonomous execution and contextual trust.
Sit with what that means for a second. Today your token is a card-on-file. Tomorrow it holds your customer’s credentials, your permissions, your delegated authority. It stops being a security detail and becomes one of the most strategically important assets you own.
Which brings me to the question I would actually lose sleep over as a merchant: who holds that vault?
The importance of a provider-agnostic Token Vault for agentic commerce
If you only tokenize inside a single PSP, you have handed away your optionality. The day your business wants to enter a market that PSP does not cover well, or the day your cross-border costs start climbing, you are stuck - and now you are stuck on something far more valuable than card numbers.
Much like the case for using a Token Vault to begin with, this is all about control and optionality. Except agentic commerce now adds another, even more powerful layer. To be agentic-ready, you need to be token-ready, and to be token-ready, you need to have control over your tokens. If you’re tokenizing through a PSP, you are limited by what that PSP can support. If you have a Token Vault, then whichever PSP you work with you can support agentic use cases.
As a merchant, I would not bet the business on agentic commerce landing on schedule. But the pace at which AI is moving makes the importance of being prepared all the more real. If you’re selling across geographies, you need a tokenization strategy that meets your needs today which can also evolve to the agentic requirements of tomorrow.
That is how we think about it at Payrails. Own your tokens, keep them portable with Token Vault, and the question of whether agentic commerce turns out to be a revolution or a niche stops being existential. If it lands, you are ready for it. And if it does not, you are still better off for having more freedom and control over how you manage payments.
In a market full of people and companies selling the dream, that is the one piece of “ready” I would get right now.

.webp)



