eg

Agentic Commerce Is Not Solved: Where It Still Breaks.

Agentic commerce is not a solved problem, and a merchant planning for agent traffic should plan around its failure modes rather than its projections. Returns, disputes, order accuracy and the absence of a settled agent-to-merchant protocol are all unresolved, and each one lands on operations rather than on the vendors publishing the forecasts.

That matters because almost every source available on the topic in mid-2026 is either a vendor launch announcement from Adyen or Google, or a consultancy outlook from McKinsey or Deloitte, and neither format concedes a limit. The launches themselves are catalogued in what shipped in 2026.

This article catalogues the limits in the order they reach a merchant's cost base, and then separates the preparation work that pays off whichever protocol wins from the commitments that are still bets.

What is actually settled about agentic commerce, and what is not?

The mechanics of an agentic purchase are settled enough to demonstrate: an agent can read a catalogue, compare candidate items, assemble a basket and present a payment credential at a merchant checkout. Two things are not settled: what happens after that purchase, and which protocol carries the handoff.

In this article, an agentic purchase is one where a software agent selects and buys an item on instructions a person delegated earlier, without that person viewing the product page. The path runs in five steps: the agent reads the catalogue, selects an item, constructs a basket, authorises payment, and the merchant writes an order record. Later sections return to the steps that break. For the underlying concept, start with what agentic commerce actually is.

What ships today is evidenced by vendor launches rather than by adoption data. Adyen announced Adyen Agentic in June 2026 and positioned it as a translation layer between AI agents and merchant checkout. Google released agentic shopping tooling for retailers in January 2026. McKinsey published on the agentic commerce opportunity in October 2025 and returned to the theme in May 2026. Deloitte covered agentic retail in Asia-Pacific in January 2026. Those are vendor statements and consultancy views rather than measured outcomes. No published adoption or transaction volume figure is available.

Launch announcements and outlooks are written before there is anything to post-mortem. That is why the published material reads as solved.

Four areas remain unresolved, and this article treats them as the real planning constraints: protocol, liability, order accuracy and returns.

Working todayNot resolved
Agent reads a product catalogue and compares itemsWhich protocol carries the catalogue and checkout handoff
Agent constructs a basket and presents a payment credentialWho is liable when the purchase was not what the shopper meant
Merchant writes an order record from an agent requestWhether the selected item matches the shopper's actual intent
Vendors sell infrastructure for all of the aboveWhat the returns and dispute cost of the channel is

No agent-to-merchant protocol has won, so every integration today is a bet

More than one agent-to-merchant protocol is in play. The clearest evidence is commercial rather than technical: a product category now exists to translate between them. Adyen's June 2026 launch of Adyen Agentic is marketed as exactly that translation layer. Trade coverage in January 2026 discussed emerging protocols as a plural. Nobody builds a translator for a protocol that has already won.

This article names no protocol, sponsor or version, because none could be verified from available sources. What can be described is the work a protocol has to do. It has to specify how an agent discovers a catalogue and reads current price and availability, how the agent proves who it is and on whose behalf it is acting, how a basket is handed from the agent to the merchant checkout, how payment is authorised for a shopper who is not present at the checkout, and how order confirmation travels back to the agent so the shopper learns what was bought. Competing protocols can differ on any of those five responsibilities. The ones that differ on agent identity and payment authorisation are the ones that create rework, because both touch systems a merchant cannot casually rebuild.

The merchant cost of fragmentation is parallel integrations, order reconciliation per channel, and engineering time spent on work that may be discarded when one protocol wins. That cost is not being priced publicly by anyone selling into the category.

The ownership problem is quieter and worse. Because no protocol has won, the choice is usually made by whichever team integrates first. That means a decision with multi-year rework consequences gets made by an engineering roadmap rather than by whoever carries the budget for redoing it.

Who is liable when an agent buys the wrong thing?

Dispute and chargeback rules were built around a cardholder who saw what they bought, and an agentic purchase removes that assumption. No published rule set resolves the gap yet, so the merchant holds an unpriced liability until one does.

The mechanism matters here. In an agentic purchase the person does not authorise a transaction. They authorise a mandate: an instruction with a scope, a budget and often a time window. That mandate produces a scoped or tokenised credential, which the agent then presents at checkout. The individual transaction is authorised by the agent working inside that mandate, which means no human looks at a total and approves it.

That breaks dispute adjudication in a specific way. "I did not authorise this purchase" is a claim a merchant defends with evidence of intent. The ordinary evidence is a person's own session: the pages they viewed, the options they chose, the checkout they completed. A merchant contests a chargeback by submitting a representment file. When the instruction was a standing intent expressed to an agent, that file contains the agent's request and the merchant's response, and not much else. Whether that satisfies a card-not-present dispute reason code is not a question any verified rule statement currently answers. This article does not assert an answer.

Spending limits and mandate scope are the only controls in wide discussion, and both are blunt. A limit stops an expensive wrong purchase and does nothing about a cheap one. A scope stops the wrong category and does nothing about the wrong variant inside the right category.

The consequence in merchant terms is a dispute rate on a new channel that nobody can forecast, defended with evidence that no longer exists, against an exposure that has no internal owner because the channel predates the org chart entry for it.

Order accuracy breaks wherever the catalogue is ambiguous

An agent buys what the data says rather than what the shopper meant. A person browsing resolves ambiguity silently by looking at a photograph. For an agent, every ambiguity becomes a wrong order. Three ambiguities break most reliably: variant attributes, stock accuracy and conditions that never enter the feed.

Selection works by comparing structured attributes. The agent reads the product feed and the schema.org Product markup on the page, filters candidates against the instruction it was given, and picks. When an attribute is absent, the agent either drops the candidate or infers a value. When an attribute is stale, it selects confidently on something untrue. When feed and page disagree, which of the two the agent believes is a property of the agent rather than a decision the merchant made. The field-level fix is set out in product feeds for AI agents.

Variant ambiguity is the largest surface. Size, fit, colour naming, bundle contents and regional specification are routinely carried by imagery and marketing copy rather than by a variant attribute. A shopper resolves them in a glance. An agent cannot, because it works from GTIN or SKU plus a partial attribute set. Stock is the second: an agent selects on an availability field and a stated lead time, where an experienced shopper would have distrusted both and checked. The third category is conditions that live nowhere machine-readable at all, including shipping restrictions by destination, final-sale terms and compatibility caveats that exist only in a page's fine print.

None of this presents as a technology failure. It presents as an operations cost, in the form of wrong items picked, packed, shipped and then sent back. No published mis-pick or order-accuracy rate exists for agentic purchases, so the size of the cost is currently unknown rather than small.

Returns get worse when nobody looked at the product first

An agentic purchase removes the last check that prevents a return, which makes returns the failure mode with the clearest cost line. A shopper looking at a product page performs a final verification: the photograph, the size chart, the delivery date, the returns terms. Remove the viewing and the verification goes with it. The reverse logistics bill arrives at the merchant regardless of which agent made the error.

No returns-rate data for agentic purchases has been published by any vendor, consultancy or platform in the available material. The reasoning here is mechanical rather than measured, and a decision-maker should treat it that way.

The cost components are ones the business already tracks: return shipping, inspection, restocking labour, and write-down on goods that cannot be resold at full price once opened. This lands worst on categories where fit and judgement drive the purchase: fashion, footwear, furniture and anything compatibility-dependent. Consumables and replenishment purchases barely feel it, because the shopper's instruction and the correct item are the same thing.

Every unresolved problem in agentic commerce settles in the same place: the merchant's operations budget, not the vendor's roadmap.

That produces an outcome worth naming before it happens. An agent channel can raise revenue and lower contribution margin at once. A dashboard tracking the first will show a success for several quarters before the second is attributed to it.

Bot mitigation cannot yet tell a shopping agent from a scraper

Most storefronts run bot mitigation that treats automated clients as hostile. That mitigation has no reliable way to separate an agent buying on a customer's behalf from a scraper harvesting prices. Both error directions cost money: block a paying shopper, or admit the automated traffic those rules were built to block.

Classification works on signals an agent cannot supply honestly. Mitigation keys on user agent strings, IP reputation and hosting-provider ranges, request rate and pattern, and behavioural signals such as mouse movement, scroll depth and time on page. A legitimate shopping agent arrives from cloud infrastructure, declares itself as software, moves through a catalogue faster than a person, and generates no behavioural signal at all. That is a precise description of the traffic bot mitigation exists to stop. The agent is meant to complete the purchase without a human present, so a CAPTCHA resolves nothing.

The alternative is an allowlist, which trades one exposure for another. Allowlisting by user agent or IP range means anything that can present those values inherits purchase access. The rules it weakens are the ones that protect against price scraping and inventory hoarding on limited stock. Telling those clients apart in the first place starts with what your own server logs already record.

A durable answer needs verifiable agent identity, most plausibly through request signing: cryptographic proof of which agent is calling, which principal delegated the authority, and what that delegation covers. That is the agent-to-merchant protocol question again, and it arrives at a different team.

Ownership is the immediate problem. Whether legitimate agents can buy from a storefront today is decided by whoever last configured the web application firewall, as a side effect of a rule written for a different threat.

When an agent does the choosing, most merchandising levers stop working

Merchandising, promotion mechanics and brand storytelling are aimed at a human forming a judgement. An agent selecting on structured attributes ignores nearly all of them. What survives is whatever is machine-readable, and that compresses differentiation toward price and specification.

An agent builds its selection criteria from two inputs: the shopper's instruction, and the attributes available to compare. Price, availability, delivery terms, returns terms and rated specifications are legible to it. Imagery, page layout, the sequence in which options are revealed, cross-sell and narrative are not, because none of them exist as a field. A promotion may depend on a shopper adding a second item after seeing a suggestion. When the basket is assembled from an instruction, that promotion has no mechanism at all.

McKinsey raised the sharper version of this in May 2026, in a piece on human-centred luxury in the agentic age. That is a consultancy view rather than a finding. It is worth citing because it identifies where the pressure lands first: the considered and premium end, where the purchase was never a specification comparison and the entire value proposition assumes someone is looking.

The unresolved part is that no established practice exists for competing on anything other than machine-readable fields. Nobody has published a working answer, which makes any current answer a hypothesis rather than a plan.

What should a merchant do before the protocols settle?

Split the preparation work in two. Everything that improves how machines read your catalogue pays off whichever protocol wins, and everything that binds you to one agent protocol or payment flow should wait. That division is the planning instrument, not a forecast.

Safe nowStill a bet
Feed accuracy: variant attributes, availability, lead timeProtocol-specific integration to a single agent protocol
Machine-readable delivery and returns termsDelegated payment authority and scoped credentials
An agent identification policy decided deliberately, not by firewall defaultAgent-specific pricing or promotion logic
Instrumentation: agent-attributable traffic, order accuracy, return rate by channelRestructuring merchandising around one agent's ranking behaviour

The left column is safe because every item improves the existing business on its own terms. Unambiguous variant data reduces returns from human shoppers too. Accurate availability reduces cancellations. A deliberate bot mitigation policy is better than an accidental one whether or not an agent ever arrives. The same split, framed as what a platform has to change, is in what ecommerce platforms must change, and how much of it you control depends on the platform underneath.

Rows move from the right column to the left on a measured trigger rather than an announced one. For protocol integration, the trigger is your payment provider or platform supporting more than one agent protocol without bespoke work, which converts the choice from a commitment into a configuration. For delegated payment authority, the trigger is a published dispute framework that states how an agentic purchase is adjudicated, because until then you are accepting a liability you cannot size.

Instrument first, because the trigger has to be observable. That means agent-attributable traffic separated from human sessions, order accuracy tracked as a rate rather than as individual complaints, and return rate reported by channel. Without those three, an agent channel's true margin stays invisible for exactly as long as it takes to become expensive.

This week, have whoever owns the product feed audit it the way an agent reads it: unambiguous variant attributes, accurate availability, machine-readable delivery and returns terms. In parallel, ask whoever owns bot mitigation which automated clients are currently blocked and how a legitimate shopping agent would be identified, because that decision is being made by default today. Hold protocol-specific integration and delegated payment authority until either your payment provider supports more than one agent protocol, or an agent channel sends enough attributable traffic to justify the rework.

The trigger is measured traffic, not a published forecast.

Frequently asked questions

What is actually settled about agentic commerce, and what is not?
The mechanics of an agentic purchase are settled enough to demonstrate: an agent can read a catalogue, compare candidate items, assemble a basket and present a payment credential at a merchant checkout. Two things are not settled: what happens after that purchase, and which protocol carries the handoff. Four areas remain unresolved and are the real planning constraints: protocol, liability, order accuracy and returns.
Who is liable when an agent buys the wrong thing?
No published rule set resolves it yet, so the merchant holds an unpriced liability until one does. Dispute and chargeback rules were built around a cardholder who saw what they bought. In an agentic purchase the person authorises a mandate with a scope, a budget and often a time window, and no human looks at a total and approves it. The representment file a merchant would normally submit contains the agent's request and the merchant's response, and not much else.
Why does order accuracy break when an agent does the buying?
An agent buys what the data says rather than what the shopper meant. Three ambiguities break most reliably: variant attributes such as size, fit, colour naming and bundle contents that are carried by imagery rather than by a variant field; stock accuracy, where an agent trusts an availability field an experienced shopper would have checked; and conditions that live nowhere machine-readable, including shipping restrictions, final-sale terms and compatibility caveats in the fine print.
Why would returns get worse with agentic purchases?
An agentic purchase removes the last check that prevents a return. A shopper looking at a product page performs a final verification of the photograph, the size chart, the delivery date and the returns terms. Remove the viewing and the verification goes with it. No returns-rate data for agentic purchases has been published, so this reasoning is mechanical rather than measured. It lands worst on fashion, footwear, furniture and anything compatibility-dependent.
What should a merchant do before the agentic commerce protocols settle?
Split the work in two. Everything that improves how machines read the catalogue pays off whichever protocol wins: feed accuracy, machine-readable delivery and returns terms, a deliberate agent identification policy, and instrumentation. Everything that binds you to one agent protocol or payment flow should wait, including protocol-specific integration and delegated payment authority. The trigger to move is measured traffic, not a published forecast.