Agentic Commerce Is Starting to Leave a Trail

For merchants, agentic commerce may be arriving through the checkout before anyone has formally decided to support it. Forter’s latest analysis of orders across its merchant network suggests that consumer agents are moving quickly from browsing to buying, including on websites built for human shoppers. That creates an immediate business question about how to recognize and serve customers whose purchases are carried out by software.

The fraud prevention and identity company examined agentic orders from August 1 through September 27. It reports that orders were running at 4.4 times their early-August level by the end of that period. Forter began detecting Meta Muse orders on September 21, and within eight days Muse had placed two-thirds as many orders as Forter had observed from all agents during the entire previous month.

Those figures warrant attention, with some caution about what they measure. They describe activity within Forter’s network, and changes in detection can affect the picture. They don’t establish agentic commerce’s share of overall e-commerce or prove that this pace of growth will continue. They do, however, give merchants evidence of transactions already taking place, with the potential to spread faster than their planning cycles anticipate.

Two routes to checkout

Agents have two broad routes to those transactions. Structured commerce integrations, such as OpenAI’s Agentic Commerce Protocol and Google’s Universal Commerce Protocol, let software exchange product and checkout information through defined interfaces. Browser automation takes a different route, navigating pages, filling forms and using checkout screens intended for people. Forter groups Muse, Instinct and Grok Bot under “screen-scraping agents,” although browser automation is the more useful description of their ability to act. Individual agents can use both structured integrations and browsers, depending on the merchant and the task.

A merchant’s decision to integrate with a particular platform therefore doesn’t determine whether agents will attempt to shop on its site. Browser-capable agents may arrive through existing storefronts, subject to the merchant’s access controls and checkout requirements. Businesses can find themselves handling agent-mediated purchases before they’ve established a policy for them.

Identity, consent and authority

For years, fraud prevention has relied in part on distinguishing humans from bots. As consumers delegate purchases, merchants need to ask which agent is showing up, whom it represents and what that person authorized it to do. Recognizing a legitimate agent provider answers only part of that question. A consumer might authorize an agent to compare flights without permitting it to book one, or permit a purchase only within a specific budget. Identity, consent and the scope of delegated authority have to remain connected to the action being taken.

Emerging protocols address parts of this problem. Forter’s proposed Trusted Agentic Commerce Protocol is designed to authenticate agents and convey information about the consumers, intent and consent behind their activity. Google’s Agent Payments Protocol uses signed mandates to carry evidence of purchase instructions and approvals. These efforts provide useful foundations, but merchants still have to decide what evidence they’ll accept and how their systems will respond when it’s incomplete.

What merchants can do now

A practical starting point is to ask checkout, payment and fraud providers what evidence of consumer authorization they can supply today. Where an integration delivers a signed mandate or other verifiable approval, merchants should arrange to retain that evidence alongside the order, linking the consumer’s authenticated account or credential reference, the verified agent identity, the purchase limits and the completed transaction. They should also record how the authorization was checked and whether the purchase fell within its scope. This gives customer service and dispute teams a record they can examine later. Merchants should protect that evidence and collect only what they need; they can’t preserve authorization information they never receive.

Browser agents may arrive without comparable evidence. Detecting an agent or processing its payment doesn’t establish what the consumer permitted it to do. For a higher-risk transaction, such as a costly, nonrefundable booking, a merchant could require direct consumer approval through a separate authenticated confirmation flow. It should record the final items, price and terms presented, the customer’s approval and the resulting order. That establishes evidence of approval for the specific purchase, even if the consumer’s original instructions to the agent remain unavailable. Fraud, payments and commerce teams should agree on when missing evidence calls for confirmation, review or rejection, and test those rules across both browser and integrated channels.

Customer service needs access to the same evidence, including a clear indication of what was verified and what remains unknown. If a customer says an agent bought the wrong item or exceeded its budget, the support team should be able to examine the available approval and transaction records without relying on the agent’s account of events. Authority to purchase also shouldn’t automatically confer authority to change a delivery address, accept a substitute or negotiate a refund. These post-purchase interactions extend the identity and consent problem into the service relationship, a central theme of our forthcoming Opus Research report.

Governing activity while standards evolve

Forter’s findings suggest that merchants may have to govern agent activity while the industry is still working toward broadly interoperable ways to establish authority. That leaves a period in which customers can delegate purchases more easily than merchants can verify the delegation. Businesses can act now by defining acceptable evidence, preserving it with the transaction and establishing clear escalation rules. The risk is already operational, even as the technical model continues to evolve.



Categories: Articles