# How Should Businesses Secure AI Agents in Agentic Commerce in 2026?

Paige Thornton · September 29, 2026

> What Agentic Commerce Security Actually Means Agentic commerce security is the set of technical, financial, contractual, and operational controls...

## What Agentic Commerce Security Actually Means

Agentic commerce security is the set of technical, financial, contractual, and operational controls needed when an AI agent can search for products, compare offers, negotiate, place an order, authorize payment, or perform other commercial actions with limited human supervision. The risk is broader than prompt injection: a manipulated agent could disclose personal data, choose an unintended product, accept fraudulent terms, expose credentials, initiate a payment, or create disputes that merchants and banks cannot explain. By 29 September 2026, banks, payment networks, governments, and technology vendors are still defining the control model, so businesses should treat agentic commerce as a high-variance transition rather than a settled protocol. The defensible objective is not to make an autonomous agent perfectly trustworthy; that cannot presently be demonstrated across open-ended commerce tasks. It is to constrain permissions, verify intent, authenticate every consequential action, preserve an audit trail, and provide fast human intervention. Businesses that apply these controls early can automate purchasing safely without treating broad agent autonomy as equivalent to customer approval.

**Also worth reading:** [How Can Businesses Control Agentic AI Costs Without Slowing Deployment?](https://zdnetinside.com/knowledge/how_can_businesses_control_agentic_ai_costs_without_slowing_deployment.php) · [What is an AI Software Systems Consultant and how can they help businesses navigate the evolving landscape of agentic AI and data-driven decision-making?](https://zdnetinside.com/knowledge/what_is_an_ai_software_systems_consultant_and_how_can_they_help_businesses_navigate_the_evolving_landscape_of_agentic_ai_and_data-driven_decision-making.php) · [What are agentic AI policy enforcement frameworks and how do enterprises implement them for secure autonomous operations?](https://zdnetinside.com/knowledge/what_are_agentic_ai_policy_enforcement_frameworks_and_how_do_enterprises_implement_them_for_secure_autonomous_operations.php)

## Why Traditional E-Commerce Controls Are Not Enough

A conventional checkout controls fields, payment pages, identity systems, and fraud rules. An agent changes the order of those controls because software interprets natural-language intent, retrieves external information, and selects actions across systems that were not designed for machine-to-machine purchasing. Mastercard’s work with Flybits and Rogers, six global banks collaborating on trusted-commerce principles, and the Qualcomm–Mastercard partnership all point toward a future in which identity, consent, and payment authorization become machine-verifiable rather than dependent only on a browser session. However, a trusted payment token does not prove that the agent selected the correct item, while strong identity does not guarantee benign tool use. Prompt injection can arrive through a product page, merchant catalog, email, invoice, or search result, making untrusted content part of the agent’s decision path. Security must therefore cover the model, instructions, tools, data, transaction policy, and external environment.

A practical security model should separate four questions: who instructed the agent, what the agent was permitted to do, what it actually did, and whether the resulting transaction is reversible. Current agent frameworks can record tool calls and use approval gates, but those features differ considerably by platform. The relevant threshold is task reversibility: actions such as drafting an email or searching a catalog can often be automatic, while changing a shipping address, issuing a refund, entering a bank account, or spending above a chosen limit should require stronger verification. As regulation of agentic AI remains earlier and less settled than generative-AI policy, organizations also need contractual rules for disputed purchases, data processing, vendor liability, and customer recourse rather than assuming that existing consumer law answers every agent-created problem.

## The Control Stack for Autonomous Purchases

The strongest approach combines preventive, detective, and recovery controls. Preventive controls include least-privilege credentials, short-lived tokens, allowlisted merchants and payment methods, spending ceilings, constrained product categories, and explicit approval policies. Detective controls monitor tool calls, instruction changes, abnormal prices, repeated attempts, new-device behavior, and deviations from a customer’s normal purchasing pattern. Recovery controls provide immediate agent suspension, card or token revocation, transaction holds, merchant cancellation windows, customer notifications, and a usable dispute process. For example, an agent allowed to spend up to $500 without confirmation might still require step-up verification above $100, reject a first-time payee, or stop when the price differs from the approved listing by more than 10%. Those figures are policy examples, not universal regulatory limits; a bank should choose thresholds from its fraud exposure and customer expectations.

The transaction itself needs verifiable evidence linking customer intent, agent identity, merchant identity, policy decisions, and the final amount. That record should use tamper-evident logging and synchronized timestamps so an investigator can reconstruct which instruction, data source, tool, and approval occurred. It should also record rejected actions, because an agent repeatedly attempting a prohibited transaction can indicate prompt injection or credential compromise. Payment tokens, passkeys, selective disclosure, and verifiable credentials may support this process, but none should be marketed as a complete answer to agent security. Mastercard and its partners are developing consumer-controlled commerce benchmarks, while Antom has introduced an agentic payment service; these efforts can improve authorization and provenance, yet organizations must test how they behave when an agent interacts with a hostile website or receives misleading product information.

## A Practical 90-Day Security Program

A business can begin by inventorying every place an agent may touch commerce, including shopping assistants, customer-service bots, procurement tools, browser agents, ERP integrations, and payment connectors. Assign an owner to each use case and classify actions by reversibility, financial value, privacy sensitivity, and external visibility. During the first 30 days, remove shared credentials, restrict agents to read-only access where possible, disable payment initiation by default, and log all prompts, retrievals, tool calls, and outputs. By day 60, introduce an approval gateway for purchases above a defined amount or outside an approved merchant list, then test direct prompt injection, indirect injection through web content, credential theft, false product claims, altered totals, and attempts to bypass policy. By day 90, conduct a transaction-focused red-team exercise and a failure exercise in which the agent, payment service, or approval service is unavailable.

The program should use measurable acceptance thresholds rather than a subjective claim that the system is “secure.” A pilot might permit no live payment until 100% of test transactions produce complete identity and audit records, all 20 high-risk scenarios are blocked, and every attempted policy bypass triggers an alert. Payment declines or customer cancellations should also be reviewed because a system that blocks everything may appear secure while creating unacceptable operational cost. One practical service target is to verify high-risk requests within 30 seconds, notify the customer before execution, and provide an immediate revocation path. These are deployment targets, not published industry standards. Pilot agents with synthetic or capped accounts first, compare them with a conventional checkout process, and obtain legal review for consumer disclosures, data transfers, automated decisions, and contract formation.

## Comparing the Main Security Options

Organizations generally need a mix of conventional application security, agent gateways, payment controls, and human supervision. The choice depends on how much authority the agent receives, not simply on whether it uses a large language model.

| Feature | Controlled agent platform | General-purpose autonomous agent | Human-assisted checkout |
| --- | --- | --- | --- |
| Purchase authority | Predefined products, merchants, and limits | Potentially broad but bounded by tool policy | Customer confirms each checkout |
| Identity controls | Short-lived tokens with customer delegation | Agent identity plus delegated user credentials | Existing customer authentication |
| Prompt-injection exposure | Reduced through isolated tools and allowlists | Higher because tools and sources may be open-ended | Lower because the customer evaluates the final transaction |
| Auditability | Strong when every tool call is logged | Variable and difficult across vendor systems | Standard checkout record plus human decision |
| Operational cost | Moderate platform and integration cost | Potentially lower setup but higher testing and incident cost | Highest human time, lowest agent autonomy |
| Best fit | Repeat purchases within clear policy | Bounded discovery tasks that end in approval | High-value, unusual, or sensitive purchases |

A general-purpose agent should not receive unrestricted access to a bank account simply because it performs useful catalog research. Human-assisted checkout is slower and less elegant, but it remains the safer default for high-value purchases. Controlled agent platforms offer the best middle path when an organization can encode narrow policies and maintain continuous monitoring. Security should be evaluated per scenario, since a customer-support agent reading an order status has a different risk profile from a procurement agent placing a $40,000 order.

## Common Mistakes That Create False Confidence

One common mistake is treating prompt filtering as the primary defense. A language model may identify some manipulation, but attackers can place instructions inside ordinary product descriptions, support messages, PDFs, images, or dynamically generated pages. Another mistake is allowing the agent to hold a reusable payment credential rather than issuing narrowly scoped, short-lived authorization. Businesses also err by showing customers an after-the-fact summary instead of obtaining confirmation before a consequential action, or by measuring only successful orders and ignoring blocked attempts. Finally, testing on clean demonstrations gives a misleading result because real commerce agents interact with inconsistent websites, changing prices, authentication prompts, and adversarial content.

The most consequential mistake is confusing authorization with intent. A valid token proves that a credential was presented, not that the user wanted a specific subscription, renewal, shipping destination, or recurring charge. Contracts should state whether recurring purchases are allowed, how cancellation works, whether an agent may negotiate, and which party bears responsibility for incorrect selections. Merchants should also avoid dark patterns designed to redirect an agent from the requested item to a higher-margin product, because this can create consumer-protection disputes even if the payment itself is technically authorized. Security review should therefore include commerce integrity, fair pricing, accessibility, and customer recourse, rather than focusing exclusively on cyberattack prevention.

## Costs, Timelines, and When Organizations Should Act

There is no standard market price for securing agentic commerce because the required controls depend on the existing identity stack, payment rails, cloud environment, model provider, and level of autonomy. A small team can create a limited pilot with an agent gateway, centralized logs, test accounts, spending caps, and human approvals at little direct software cost beyond model usage and staff time. Production deployments usually add implementation, security testing, compliance review, observability, incident response, and vendor integration expenses. Public announcements do not provide comparable prices for Mastercard, Flybits, Rogers, Qualcomm, or Antom offerings, so a stated cost such as $25,000 or $100,000 would be unsupported without a quote.

Companies should act now if an agent can initiate purchases, move money, access customer records, or alter orders. Research visible by 29 September 2026 shows continuing development from banks, payment firms, marketplaces, and security projects rather than a finished universal standard. Waiting may reduce technical risk, but it also allows customer and employee workflows to expand until legacy permissions become difficult to unwind. Immediate action is especially warranted for financial services, healthcare, travel, utilities, subscriptions, and business procurement, where mistakes can cause direct loss or sensitive disclosure. Retailers should act before connecting agents to payment providers, while enterprises should first inventory internal agentic systems because these may already operate without formal procurement approval.

## The Recommended Security Position for 2026

The best position for most organizations is controlled agentic commerce: AI agents handle discovery and routine execution, but consequential actions pass through deterministic policy checks and customer verification. Begin with narrow permissions and reversible tasks, add approval gates based on amount and risk, authenticate the user with modern controls such as passkeys where supported, and use short-lived or scoped payment authorization. Record the user’s objective, agent identity, relevant data sources, policy decision, price, merchant, final action, and any exception. Require human review for new merchants, first-time destinations, recurring charges, sensitive data, and transactions above the customer’s chosen threshold.

Do not wait for an industry certification that may not yet exist. The practical standard is evidence that risks are bounded and incidents can be stopped. Revisit the design whenever the model changes, a new tool is connected, a payment partner changes, or observed behavior drifts outside approved patterns. Agentic commerce can become a useful operating model, but public trust will depend on whether firms make delegation explicit, prevent agents from acting beyond the customer’s apparent intent, and give people a credible way to intervene. Until independent assurance matures, controlled autonomy is more credible than unrestricted autonomy, and well-governed agent transactions should be treated as a new class of governed digital action rather than another checkout button.

## Quick answers

### Is agentic commerce the same as using an AI chatbot for shopping?

No. A shopping chatbot that only recommends products is one part of agentic commerce. Agentic commerce can also include comparing offers, negotiating, completing checkout, authorizing payment, arranging recurring purchases, or managing orders with limited human involvement.

### What is the biggest security risk in autonomous shopping?

The largest practical risk is misuse of delegated authority, especially through prompt injection from untrusted web content. An attacker may try to change a product, destination, payment amount, or policy instruction while preserving the appearance of a normal customer request.

### Should every AI purchase require human approval?

No, but high-value, irreversible, or unusual transactions should normally require stronger approval than routine, reversible actions. Organizations can set limits by amount, merchant, product category, destination, recurrence, and customer risk rather than using one universal approval rule.

### Do trusted payment tokens make agentic purchases safe?

No. Trusted tokens can reduce payment-account fraud and improve transaction traceability, but they do not prove that the agent selected the intended product or acted on a genuine preference. Identity, authorization, intent verification, merchant controls, and dispute handling remain necessary.

### How much does agentic commerce security cost?

There is no universal price because a read-only shopping pilot can use existing cloud and logging tools, while a production purchasing system may require payment integration, identity infrastructure, monitoring, testing, and compliance work. The dominant variable is usually engineering and assurance effort rather than the base software subscription.

Canonical: https://zdnetinside.com/knowledge/how_should_businesses_secure_ai_agents_in_agentic_commerce_in_2026.php
Markdown: https://zdnetinside.com/knowledge/how_should_businesses_secure_ai_agents_in_agentic_commerce_in_2026.php/index.md
