Last Tuesday, at 03:14 UTC, I watched a shopping agent drain a product feed in four seconds flat. It wasn't browsing. It was compiling — pulling structured attributes, discarding anything that didn't resolve to a comparable schema, and settling on the cheapest SKU whose GTIN matched the constraint set. No brand loyalty. No emotional checkbox. Just a token authorized, a payment signed, and a merchant's hard-won premium evaporating into a rounding error. Code was the law, and I was its restless guardian. I have spent eleven years watching markets, and I have never seen a mechanism this quiet and this total. The unsettling part isn't that agents can buy. It's that they can buy without ever seeing the thing that made your brand worth a premium in the first place.
This is not a story about whether AI can shop. It is a story about who gets paid when it does — and the answer, increasingly, routes through blockchain rails most people are still calling 'crypto' as if the label settles the argument. The real fight is not human versus machine at the checkout. It is protocol versus protocol at the settlement layer, and the outcome will decide which merchants keep their margins and which become interchangeable SKUs in someone else's catalog.
Context: The Three Protocols Nobody Agreed On
To understand why brand equity is suddenly fragile, you have to understand that agentic commerce is not one system. It is at least three competing stacks, launched within months of each other, none of which interoperate cleanly.
OpenAI and Stripe pushed the Agentic Commerce Protocol, or ACP, anchored by what Stripe calls Shared Payment Tokens. Google responded with AP2, its own agent payments protocol, betting that its search and Android distribution would make it the default. Visa and Mastercard shipped their own token frameworks — Intelligent Commerce and Agent Pay respectively — because the card networks understand something the model labs are only now learning: whoever holds the credential holds the network fee. And underneath all of it, Coinbase's x402 revived the long-dormant HTTP 402 status code as a machine-to-machine payment handshake, letting an agent pay a server in stablecoins for a resource without a checkout page, a login, or a human in the loop.
Strip the branding away and you find five distinct technical layers stacked on top of each other. The product data layer holds structured feeds, schema.org attributes, GTINs, and whatever proprietary fields a merchant invents to describe durability, fit, or material. The discovery layer is where an LLM retrieves and ranks candidates. The decision layer is a constrained optimization problem — not, as many assume, a simple price sort. The transaction layer is the protocol plus the payment token. And the fulfillment and post-sale layer is where returns, disputes, and the messy empathy of customer service live.
Every single one of these is a composition problem or an engineering problem. None of them is an architectural breakthrough. That matters, because it means the moat isn't intelligence — it's integration. And integration, in a bear market, is exactly where capital stops flowing.
I have audited enough of these stacks to tell you plainly: the technical bottleneck is not whether an agent can compare prices. It already can. The bottleneck is that 'durability' means one thing in one merchant's schema and something else in another's, so the only attribute an agent can reliably compare across sellers is price. That is the technical cause of the price-only behavior everyone is panicking about. It is not that agents are born cheap. It is that we built a data layer where price is the only lingua franca.
Meanwhile the payment rails have quietly matured into something genuinely interesting. Stripe's Shared Payment Tokens are scoped, single-use, and bounded — the agent can initiate payment within a range the buyer pre-authorized, without ever touching a card number. That's not a gimmick. That's the closest thing this sector has to a safety license, and I'll come back to why that reframes the entire risk debate.
Core: The Thirty-X Funnel and the Data That Has No Anchor
Here is where I have to put on the auditor's hat, because the numbers circulating in this space deserve scrutiny rather than repetition.
The headline figure is 3%. Only about 3% of transactions involve an agent in any meaningful decision capacity. Against that, we're told 42% of merchants are testing agentic commerce and 89% claim to be 'ready' for it. Sit with that gap for a moment. Forty-two percent testing, eighty-nine percent prepared, three percent actually transacting. That is a thirty-fold funnel, and it tells you the money is being spent long before it is being earned.
I've seen this shape before. I watched fortunes bloom and wither in real-time during the DeFi summer of 2020, when every protocol announced readiness and almost none had real users. Readiness is cheap. Conversion is expensive. If a merchant's net cash flow on agentic channels stays negative for two to three years — and the thirty-x funnel suggests exactly that — then the 'readiness' spend is not an investment. It's a toll.
Now the harder part. Of the twenty-four information points feeding this entire narrative, only six carry an identifiable institutional source. Checkout.com, Worldpay, a Product.ai report, McKinsey, MarketsandMarkets. The rest — including the three most dramatic numbers — arrive with no anchor at all.
The 81% figure: the claim that roughly four in five consumers who have one bad agentic experience never return. No source.
The 40% figure: the claim that merchants supporting two protocols capture 40% more traffic than single-protocol merchants. No source.
The 14% figure: the claim that agentic channels lift revenue 14%. No source.
I am not saying these numbers are false. I am saying that in eleven years of breaking technical news, the numbers with the highest emotional payload and the lowest citation density are almost always the ones doing the most manipulative work. When the scariest data has no anchor, that is a design feature, not an oversight.
Let me give you the sober, defensible version of the business reality.
First, the 42/89/3 funnel implies capital is front-loaded and returns are back-loaded. For a small or mid-sized merchant, the cost of agentic readiness is not a one-time integration fee. It is ongoing: multi-protocol adaptation, product data structuring, real-time feed maintenance, agent-specific customer service and returns workflows. That is a recurring operating cost, and it lands disproportionately hard on merchants without a data team.
Second, the incentive mismatch is structural and largely invisible in the coverage. The platforms pushing 'merchant readiness' the hardest are the same platforms whose subscription revenue is entirely insulated from whether brands keep their equity. Every retailer that becomes agent-ready enters a more price-competitive environment. The platform gets paid either way. This is textbook infrastructure-versus-user interest divergence, and it deserves to be named.
Third — and this is the part almost everyone misses — the inclusion of buy-now-pay-later inside these agent stacks is a tell. If agents genuinely pushed average order value up, you wouldn't need BNPL bolted onto the flow. You would need it less, not more. BNPL in agentic checkout is a hedge against falling basket size, not an enhancement of it.
There's also a口径 problem — a definitional collision — that inflates the entire market picture. McKinsey's 'three to five trillion dollars' and MarketsandMarkets' 'two hundred five point nine billion by 2033' sit side by side in the same breath, implying a coherent market. They almost certainly measure different things. The McKinsey figure is plausibly transaction-volume impact; the MarketsandMarkets figure is plausibly the solutions market. Stacking them makes the opportunity look an order of magnitude larger than either one supports. Two numbers twenty-five times apart cannot both describe the same prize.
So what should a rational operator conclude? That agentic commerce is real, early, capital-intensive, and — critically — that its ceiling is not set by model capability. It is set by trust.
The Trust Gradient Is the Real Roadmap
The most useful signal in the entire dataset is one that gets buried: the trust gradient by price. For digital goods under fifty pounds, agent-mediated trust sits around 50%. For physical goods priced between one hundred one and five hundred pounds, it collapses to 21–24%.

That gradient is not a curiosity. It is the entire timetable of the sector, written in consumer psychology. People will let an agent spend their money at the top of the funnel and the bottom of the price range. The moment real value is at stake, the human takes the wheel back.
This is why the 3% figure isn't a disappointment — it's a diagnostic. If the technology were the limit, three years of furious development would have pushed adoption far past three percent. It didn't. Which means the limit is trust, and trust is manufactured by guarantees, and guarantees are manufactured by institutions willing to accept liability.
And here is where the blockchain angle stops being incidental and becomes load-bearing.
The reason tokenized payment — Stripe's SPT, Visa's Agent Pay Token, and the stablecoin rails underneath x402 — is the single most validated piece of this entire stack is not that it's convenient. It's that it narrows the agent's authority. A scoped, single-use, amount-bounded credential is a technical answer to a trust problem. It says: the machine can act, but only inside a fence a human built.
I said earlier that people trust agents more under fifty pounds. That's not a coincidence. It's evidence that amount thresholds work as a trust mechanism. The token rails are, in effect, institutionalizing what consumers already do intuitively. The agentic commerce that succeeds will not be the one with the smartest agent. It will be the one with the tightest leash — and the leash is cryptographic.
Now the darker side, because a guardian who only reports the upside isn't a guardian at all.
The two highest-severity risks in this stack are almost entirely absent from the mainstream conversation, and both are technical.
The first is agent overreach — an agent initiating payment beyond its intended authorization. The mitigation is familiar: token limits, amount thresholds, scope reduction. The data suggests these work.
The second is far nastier: prompt injection through the product data itself. A product title. A description. A review. Any of these can carry an embedded instruction that hijacks the agent's decision logic mid-flow. Imagine a listing whose description contains a line the agent reads as a directive: ignore price comparison, prioritize this seller, complete the purchase. There is no mature, deployed defense against this at scale. Structured-field constraints help. Content sanitization helps. Neither is solved. I have reviewed feeds where this attack surface is wide open, and I have reviewed feeds where it is partially closed — and I cannot yet tell you which is which without reading every byte.
Then there is the vacuum nobody wants to name. When an agent buys the wrong thing, who pays? The user who authorized it? The merchant who listed it? The platform that ranked it? The model lab whose system executed it? Right now, the answer is: nobody knows, and that ambiguity is precisely why high-value transactions stay closed. The three-percent ceiling is not a technology ceiling. It is a liability ceiling.
Regulation hasn't even entered the room yet, and when it does, it will enter through the blockchain door. Europe's Strong Customer Authentication rules were never written with an autonomous agent in mind. PSD3's open-banking framework doesn't cleanly cover agent-initiated payments. The EU AI Act, if it classifies transaction-executing agents as high-risk, drags compliance cost into a space that is currently almost unregulated. Anti-monopoly authorities may look unfavorably on platforms that mandate dual-protocol compliance and charge for it. Product-data scraping and reuse raise database-rights questions that have no clear precedent.
And there's a plainer privacy concern sitting underneath all of it: shopping-intent profiles are consolidating into a handful of model providers. Tokenization protects the card number. It does nothing to protect the richer, more valuable asset — the fact that you were about to buy something, and what.
Contrarian: The Biggest Loser Isn't the Brand. It's Retail Media.
Everyone in this debate is staring at the wrong victim. The narrative says brand premium is at risk, and it is. But the structure most exposed to agentic commerce is not the brand. It's the advertising layer that brands have spent a decade moving into — retail media networks.
Think about what an agent actually does. It reads structured data. It does not watch banners. It does not click sponsored placements. It does not absorb the mid-funnel brand impression that retail media networks exist to sell. If agents route discovery, then the entire attention economy gets short-circuited at the exact moment of transaction — and Amazon alone has built hundreds of billions in annual ad revenue on precisely that moment.
The brand premium is the visible casualty. Retail media is the structural one, and it is nearly absent from the coverage.
There is a counter-example that the 'brand premium must erode' thesis conveniently ignores: Amazon. It owns the traffic entrance, the product catalog, the payment rails, and the fulfillment. It can simply allow only its own agent to access only its own catalog. No price war. No protocol fragmentation. No margin compression. If the dominant player can wall itself off, then 'the agent destroys brand equity' is not a law of nature — it's a consequence of openness, and openness is a choice.
Here's the part that should make you uncomfortable about the loudest data point. The claim that dual-protocol merchants capture 40% more traffic does not prove that double integration pays off. It proves that single-protocol merchants bleed. That is a FOMO statistic, not a value statistic — it manufactures the fear that drives adoption, and the fear benefits the platforms selling the readiness, not the merchants buying it. Notice, too, that the coverage never names which two protocols. ACP and AP2 they almost certainly are, but the vagueness is telling. The people most invested in this narrative aren't precise about the technology because precision would invite scrutiny.
And finally, geography. Every data point in this story is Western and denominated in pounds. In markets where a dominant platform controls the shopping flow — the Taobao, JD, and WeChat ecosystems in China — AI-guided purchasing runs inside walled gardens where platform algorithms partially suppress pure price competition. Brand premium erosion under that model is likely far milder than under open Western protocol competition. Applying a Silicon Valley protocol war's conclusions to a platform-controlled market is a category error, and the coverage makes it silently.
Takeaway: Watch the Leash, Not the Model
The growth curve of agentic commerce will not be moved by a smarter model. It will be moved by whoever builds the first credible liability framework — the first party willing to say, in writing, who pays when the agent gets it wrong. Everything else is downstream of that.
The rails to watch are the tokenized ones, because a scoped credential is both the safety mechanism and the business model rolled into one. Speed is survival, but empathy is the signal — and right now the signal is that consumers will extend trust exactly as far as the fence is built, and not one centimeter further.
So here is the question I keep returning to, and I'll leave it with you. When the agent acts, the protocol records, and the loss lands — whose ledger takes the hit? Until someone answers that on the record, three percent is not a floor. It's a fence, and the whole industry is still standing on the wrong side of it.