Who Pays When AI Does The Shopping?
As AI agents move from recommending purchases to spending money on our behalf, in this Tech Insight, we ask how they will pay, what will stop them spending beyond their instructions and who will pick up the bill when they get it wrong.
From Finding Products To Paying For Them
An assistant that compares flights is useful, but booking one involves more than finding the lowest fare. For example, it must understand acceptable departure times, baggage requirements and cancellation terms, then have permission to commit somebody’s money.
The same issue arises when business software needs to purchase a market report or access a paid database. Asking an employee to approve every small purchase could remove much of the benefit of automation, while unrestricted access to company funds would create obvious risks.
Payment providers are therefore developing systems that allow agents to act within agreed boundaries, with records showing what the customer authorised and what the software actually bought.
How Can An Agent Spend Safely?
One approach to ensuring AI agents spend safely uses a restricted digital payment credential instead of giving an agent unrestricted card details. Stripe’s shared payment tokens, for example, can carry limits covering the amount, seller and expiry time, allowing a business to accept payment without receiving the customer’s original credentials directly.
However, protecting the card details does not establish whether the customer wanted a particular purchase. Google’s Agent Payments Protocol addresses this through digitally signed records of instructions and approvals, helping establish the connection between a person’s request and the eventual transaction.
To help these checks work consistently across different services, Google and Mastercard have contributed their payment and authorisation frameworks to the FIDO Alliance, an industry body that develops security standards. The aim is to establish a shared way of recording and checking what a customer has authorised, so that permission remains clear as an agent deals with different businesses and payment providers.
Checking Who The Agent Represents
This need for shared checks explains the collaboration announced this month by Visa, Mastercard and Ant International (the financial technology company behind the Alipay+ global payments network). Their proposed Know-Your-Agent framework should be able to link an agent to a verified operator, cardholder or business and support common security assessments and ongoing monitoring.
As Mastercard chief digital officer Pablo Fourez explained: “Interoperability across Know-Your-Agent frameworks is essential to making agentic commerce work at scale.”
The work is being developed through Singapore’s BuildFin.ai platform, with each network retaining its own verification and decision-making processes. The hope is that it could reduce repeated checks across payment services, but it doesn’t mean that every agent now has a universally accepted identity.
For merchants, recognising an authorised shopping agent also matters before checkout. With this in mind, Visa’s Trusted Agent Protocol is designed to help websites distinguish legitimate agents from unwanted automated traffic that their security systems might otherwise block.
When Software Buys Digital Services
An AI agent researching a market might need information from several paid databases, but only a small amount from each. Paying for individual requests could make more sense than taking out several monthly subscriptions, particularly if the agent can handle those small payments within a budget set by the business.
This is the idea behind x402, a set of rules that lets websites and software arrange payments automatically. When an agent requests paid information, the service responds with a “Payment Required” message and the payment details. The agent can then arrange payment and obtain the information without someone having to complete a checkout each time.
XDC Network, a blockchain network used to record transactions and transfer digital assets, uses this approach to let agents pay in USDC, a digital currency designed to track the value of the US dollar. However, these payments are not limited to cryptocurrency: x402 supports different payment methods, and its development is overseen by a Linux Foundation body backed by card networks, technology companies and cryptocurrency businesses.
Payment processing company Stripe is pursuing a similar approach through its Machine Payments Protocol, which supports conventional money and stablecoins. Examples include agents paying to use a browser or access information online, illustrating how the same technology that enables automated shopping could also help business software buy the resources it needs to finish a job.
What Happens When Something Goes Wrong?
It’s worth pointing out here that successful payment doesn’t necessarily mean successful purchasing. For example, an agent might stay within its budget but order an unsuitable product, misunderstand a cancellation policy or repeatedly buy data that does not help complete its task.
That makes the distinction between permission and judgement important. A payment system can enforce a spending limit, but businesses still need clear instructions, reliable purchasing records and arrangements for handling refunds and disputes.
Thankfully, UK policymakers are examining these questions through the Treasury’s consultation on modernising payment services regulation, published in July and open until 6 October. It considers how regulation should accommodate agentic payments while maintaining consumer protection, so proposed changes should not be mistaken for settled rules.
What Does This Mean For Your Business?
For businesses, the attraction is being able to hand over routine purchasing without having to approve every small transaction. An agent could buy information for a research task or reorder supplies, freeing employees to concentrate on work that needs their judgement. A sensible starting point would be a limited trial with approved suppliers and a fixed budget, with the agent referring anything outside those instructions to a person.
That trial should measure the work involved from the initial request through to checking the purchase and recording the expense. Staying within budget is useful, but the agent also needs to buy the right thing on acceptable terms and leave records that staff can understand. If employees repeatedly have to correct orders, chase refunds or work out why money was spent, the apparent time saving could quickly disappear.
For companies selling online, the same developments raise questions about how to serve a customer whose shopping is handled by software. For example, their payment provider should be able to explain how authorised agents are recognised, what evidence of customer approval is retained and how refunds or disputed purchases would be handled. Clear product descriptions, prices and cancellation terms will also help agents make suitable choices before payment takes place.
The longer-term opportunity here is to give software enough freedom to complete useful tasks while keeping spending accountable to the business. That depends on having controls that can be changed or withdrawn as circumstances change, and a named person responsible for reviewing the results. Confidence should grow from evidence that an agent makes sound purchases consistently, rather than simply from its ability to move money quickly.



