What Is the Agentic Commerce Protocol (ACP) and Why Should You Care?
arrow_backAll posts

1 June 2026

What Is the Agentic Commerce Protocol (ACP) and Why Should You Care?

Daniel Bamidele

Written by

Daniel Bamidele

We're moving from "click to buy" to "delegate to buy" and the rules being written right now will govern how AI agents handle your money for decades. Here's what ACP is, why it exists, and what's still dangerously unresolved.

Let's start with a little thought experiment.

Imagine you wake up on a Saturday morning, pour yourself a coffee, and mutter to your phone: "I need new running shoes. Something under £120, good for flat feet, preferably not neon green."

Then you put the phone down. Make breakfast. Watch something mindless on TV.

By the time you've finished your second cup, you have a notification. Your running shoes have been researched, compared, selected, purchased, and are on their way. You didn't visit a single website. You didn't fill out a single form. You didn't type in your card number with one hand while holding your toast with the other.

You didn't do anything.

Welcome to agentic commerce. And the thing quietly making it all work — the plumbing, the scaffolding, the unsung bureaucrat behind the curtain — is something called the Agentic Commerce Protocol, or ACP.

You've probably never heard of it. You probably won't think about it much even after it reshapes how billions of people spend their money. That's fine. Most people have never heard of HTTP either, and yet here we all are, reading things on the internet.

But you should care. Here's why.

First, Let's Talk About What's Actually Changing

For roughly 30 years, online shopping has followed the same basic choreography. You — a human being with eyes, opinions, and decision fatigue — navigate to a website. You browse. You compare. You read a suspiciously enthusiastic review from someone called "HappyShopper1984." You add things to a cart. You second-guess yourself. You abandon the cart. You come back three days later when you get a passive-aggressive reminder email. You buy the thing.

Every single step of that journey involves you. Your presence, your attention, your judgment. You are the buyer and the browser simultaneously.

That's all changing.

AI agents, software systems that can think, browse, decide, and transact on your behalf — are already in the wild. ChatGPT users can now buy directly from Etsy mid-conversation. Not "here's a link, go buy it yourself." Actually buy it. Complete the transaction. Done.

This isn't science fiction. This isn't a startup's fever dream. This is happening right now, in the actual marketplace, today.

And the economic implications are staggering. McKinsey and others are projecting that agentic AI could generate somewhere between $1 trillion and $5 trillion in global economic impact by 2030. That's not a typo. That's the kind of number that makes finance people go quiet for a moment.

So the question isn't whether AI agents will become a major commercial force. That ship has sailed, and it had a very large engine. The question is: how on earth do we make this work without it all turning into a spectacular, fraud-ridden, liability-soaked disaster?

Enter ACP.

So What Actually Is ACP?

The Agentic Commerce Protocol is an open standard — think of it as a shared language — co-developed by Stripe and OpenAI and released under an open-source Apache 2.0 licence. In plain English: it's a set of rules and tools that lets AI agents and online merchants talk to each other in a structured, trustworthy way.

Here's the problem it's solving.

Right now, if an AI agent wants to buy something on your behalf, it faces a genuinely absurd situation. It's like sending a very intelligent friend to a foreign country where they don't speak the language, don't have a recognised passport, and can't prove they actually have your permission to spend your money. The shop assistant — in this case, the merchant's website — has no idea who this person is, whether they're legitimate, or whether they've been sent by you or by some elaborate fraud operation.

Merchants are terrified of this. Not in an abstract, hypothetical way. In a very concrete "we could lose money and get chargebacks and not even know whose fault it is" way.

ACP fixes this by giving agents and sellers a shared vocabulary. A merchant can now expose their product catalogue, their pricing, their checkout process — all of it — in a format that an AI agent can actually read, understand, and navigate correctly. Not by scraping a website like a clumsy robot pushing its way through a revolving door. But through a clean, structured integration that the merchant has full control over.

The result? A merchant can sell through AI agents while still controlling their brand voice, their accepted payment methods, how fulfilment works, what the receipt looks like — everything they care about. The shopping experience still reflects them, even though the buyer is no longer human.

And crucially, this is a one-to-many integration. A merchant plugs in once, and suddenly they're accessible to multiple different AI agents across multiple platforms. That's a big deal. Without a standard like ACP, every merchant would have to build custom integrations for every AI platform separately. That's the kind of thing that makes software engineers weep openly.

The Bit That Actually Protects You: The Shared Payment Token

Now here's where it gets really interesting. And a little bit scary, if you think about it too hard.

When an AI agent is acting on your behalf, it needs to use your payment details. Your card. Your money. And to do that, it has to pass those details — somehow — to the merchant.

You can immediately see why this is nerve-wracking. In a normal transaction, your card details go from you to the merchant, with maybe a payment processor in the middle. But in agentic commerce, there could be many intermediaries. The AI agent itself. The model powering it. Maybe a third-party discovery tool. Maybe a browsing tool. Multiple software layers, all potentially touching your payment information as it travels from your agent to the merchant's checkout.

That's a lot of potential places for things to go wrong. Or to be stolen. Or to be quietly misused.

ACP addresses this through something called the Shared Payment Token. Instead of your actual card number — the raw PAN, as the payments industry calls it — flowing through all these intermediaries, a token is generated. A cryptographic stand-in. It carries the necessary information for the merchant to process your payment, but it doesn't expose your underlying card details.

The merchant gets what they need. Your actual credentials never go anywhere dangerous. And Stripe can run its fraud detection systems — Radar — against these transactions in real time, scoring them for risk just like it does with hundreds of millions of other transactions.

Think of it like this. When you valet park your car, you hand over a valet key — one that opens the door and starts the engine, but doesn't open the boot or the glovebox. You're giving them enough to do the job, without giving them access to everything. The Shared Payment Token is the valet key for your payment details.

But Wait — Who Consented to This?

Here's the question that should be nagging at you by now.

If an AI agent is browsing, deciding, and buying on your behalf, when exactly did you say it was okay? How does anyone know you actually wanted this specific product, from this specific merchant, for this specific price?

This is the consent problem, and it's one of the thorniest issues in agentic commerce.

Think about what happens in normal e-commerce. Before you buy anything, you see the product. You see the price. You see the merchant. You click a button that says "confirm purchase." There are multiple moments where you, as a human, are actively affirming: yes, I want this, I accept these terms, I am making a conscious choice.

In agentic commerce, you might have said, days earlier, something like "buy me running shoes under £120." The agent then makes dozens of micro-decisions on your behalf — which sites to browse, which reviews to trust, which product best matches your criteria, which merchant offers the best deal — and then executes the transaction without checking in with you at all.

That's the whole point. That's what makes it useful. But it's also where things can go sideways in fascinating and legally murky ways.

ACP and related protocols are grappling with this through mandate structures — essentially a codified record of what you authorised the agent to do. Not just "buy shoes" but: buy shoes, category: footwear, maximum spend: £120, merchant type: reputable retailer, time window: next 48 hours. A structured, logged consent that can be audited, referenced, and used to resolve disputes later.

Consider the scenario of buying pesto pasta ingredients. You tell your agent: pick up what I need, spend no more than £50. The agent's mandate is specific. It can buy groceries up to £50. It cannot, under any reasonable interpretation of that mandate, buy you a £25 pair of socks instead because it thought you might need them. The consent is scoped.

And when you later look at your bank statement and think "what on earth is this charge?" — that logged mandate becomes the evidence that yes, you did authorise this, here's the timestamp, here's the parameter you approved, here's the biometric confirmation from your device.

It's dispute resolution, pre-loaded.

The Elephant in the Room: Who Is the Agent Actually Working For?

Here's where the conversation gets genuinely uncomfortable.

When you use an AI agent to shop, the assumption is that it's working for you. Your interests. Your preferences. Your values. A loyal digital butler, tireless and objective, scouring the market on your behalf.

But is that actually guaranteed?

Recent research from Columbia Business School is unsettling on this point. In a study using a mock online store, AI shopping agents were meaningfully influenced by things like the placement of a product on a page, or whether it carried a sponsored label. Things that shouldn't matter to an objective evaluator — but apparently do.

Microsoft Research has flagged similar concerns: sellers who respond faster, or who make their listings more "agent-friendly" in ways that don't necessarily serve buyers, get more sales. The invisible hand of the market is already learning to tickle the AI.

And here's the subtler version of this problem. If your agent was trained on data that over-represents, say, a particular retailer — not because of any malicious intent, just because that retailer has a bigger web presence — then your agent is going to be biased toward that retailer in ways that neither you nor the agent can fully see or explain.

The protocol handles identity. It handles payment security. It handles consent. But loyalty — actual, verifiable, measurable loyalty to your interests rather than anyone else's — is still a work in progress.

This is precisely why organisations like Consumer Reports are joining this conversation. For 90 years, Consumer Reports has been the trusted voice that cuts through commercial noise and tells people what things are actually worth buying. Now they're asking: what does that role look like in a world where the buyer isn't even present? How do you ensure that the information your agent relies on is objective? How do you measure whether an agent is genuinely acting in your best interest, rather than subtly in someone else's?

These aren't small questions. They're the questions that will determine whether agentic commerce becomes a genuine revolution in consumer empowerment — or just a very sophisticated new layer of manipulation.

Why This Matters More Than You Think

We are, right now, at one of those rare inflection points where the norms and standards being set will shape the next several decades of commerce.

The rules governing credit card transactions were written decades ago. The liability frameworks. The consumer protections. The operating regulations. These weren't handed down from on high — they were negotiated, argued over, and eventually codified into the multilateral contracts that govern every card payment you've ever made.

We're doing the same thing right now for agentic commerce. In the next few years — possibly in the next few months — the protocols, standards, and rules being drafted will determine:

  • Who bears liability when an agent makes a wrong purchase

  • How your payment credentials are protected as they travel through AI systems

  • What information agents can be influenced by — and what's off-limits

  • Whether consumers can actually trust the agents acting on their behalf

  • What a "loyal" agent even means, legally and technically

ACP is one piece of this puzzle. Visa's Trusted Agent Protocol is another. There are cryptographic identity systems, agent-native payment rails for microtransactions, and a dozen other approaches all being developed simultaneously.

We are, quite genuinely, in a race to standardise the future of how money moves.

The Bottom Line

You don't need to understand the technical architecture of ACP to care about what it represents. You just need to understand the stakes.

Someone is going to write the rules for how AI agents spend your money. Those rules are being written right now. And the people writing them are making choices — about security, about transparency, about loyalty, about accountability — that will affect every online purchase you make for the rest of your life.

The question isn't whether to trust AI agents with your money. You're already being asked to. The question is whether the infrastructure being built around them deserves that trust.

For what it's worth: the fact that people are asking these questions at all — building protocols with consent structures, fraud detection, mandate logging, and consumer loyalty frameworks baked in from the start — is genuinely encouraging. The people designing these systems are thinking hard about the things that matter.

But so should you.

Because the agent shopping for your running shoes next Saturday? It's coming. And whether it's working for you or just on you will depend entirely on the standards we build — and demand — right now.

This piece draws on discussions from the Loyal Agents Initiative, a collaboration between Stanford HAI's Digital Economy Lab, Stanford CodeX, and Consumer Reports Innovation Lab, which is researching the standards, protocols, and governance frameworks emerging around agentic commerce.

This Is Exactly the Problem Roving Is Building For

Everything you just read, the identity questions, the mandate structures, the liability gaps, the consent problem, the fraud risk, it all points to one thing that does not yet properly exist.

A financial layer built specifically for AI agents.

Not a workaround. Not a card credential passed through a chain of intermediaries and hoped for the best. A proper banking infrastructure where every agent has its own verified financial identity, its own account, its own controlled spending card, and a complete audit trail of every single action it takes with your money.

That is what Roving is building.

Roving is the neo bank for the agentic economy. Give your AI agent a real bank account, smart virtual cards, spending rules it cannot override, global payment capability, and a verified KYA identity before it moves a single penny. Whether you are building agents, deploying them across a business, or just watching this space with growing interest, Roving is where the financial infrastructure for that future is being built right now.

Get early access at roving.money and be among the first to give your agents the financial identity they need to operate safely in the world.

If this piece made you think, drop a comment below. We want to hear from you.

Stay in the loop:

  • Follow us on LinkedIn for product updates, industry news and founder notes

  • Join our Discord community and be part of the conversation shaping the future of agentic finance

  • Share this with someone who needs to read it, the developer building an agent platform, the finance lead wondering about liability, or the curious friend who just handed their AI assistant access to their card

Comments

No comments yet. Be the first to share your thoughts.

Leave a comment

Comments are reviewed before publishing.